Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Preventivka

#1 Příspěvek od Lefiks »

Dobrý den,prosím o preventivku
Důvod: když zapnu PC, všechno přestane odpovídat
Logfile of random's system information tool 1.10 (written by random/random)
Run by Petr at 2015-05-17 11:44:58
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 59 GB (8%) free of 750 GB
Total RAM: 8153 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:45:04, on 17.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Petr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: ArcPluginIEBHO - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Arc\Plugins\ArcPluginIE.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll
O2 - BHO: Seznam.cz - {EA837F48-5AD1-443e-AE34-FFE03CBF3099} - C:\Users\Petr\AppData\Roaming\Seznam.cz\bin\core.4.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files\COMODO\GeekBuddy\launcher.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Arc Service (ArcService) - Perfect World Entertainment Inc - C:\Program Files (x86)\Arc\ArcService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Chromodo Update Service (ChromodoUpdater) - Comodo - C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13447 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {C1376307-745F-4449-94FA-59930D47DEA1}
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Gaming Keyboard\OSD.exe"
"C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
taskmgr.exe /3
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\Windows\system32\viakaraokesrv.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6608.0.1744235181\107123715" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.982.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.2.559101168\300501409" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.3.345967225\1257263437" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.4.1609293986\1776998640" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.5.1090279599\798851549" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.6.1616432742\613098311" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.11.224552853\708759625" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/StandardR4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_09/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultDisabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Enabled/*Win32kLockdown/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6608 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="6608.12.1376680522\1966911575" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 880 884 892 65536 888
"C:\Users\Petr\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe
C:\Windows\tasks\AutoKMSDaily.job - C:\Windows\AutoKMS.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d042414bcc1439.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineUA1d042414c0351a8.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\m68i5m0m.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin]
"Description"=Arc PlayNow plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\Arc\Plugins\npArcPluginFF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@raidcall.en/RCplugin]
"Description"=Raidcall plugin
"Path"=C:\Users\Petr\AppData\Roaming\raidcall\plugins\nprcplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\m68i5m0m.default\extensions\
jid1-4P0kohSJxU1qGg@jetpack
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-05-12 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-27 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-13 69760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-15 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}]
ArcPluginIEBHO Class - C:\Program Files (x86)\Arc\Plugins\ArcPluginIE.dll [2015-04-09 125448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-12 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-27 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-15 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443e-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Users\Petr\AppData\Roaming\Seznam.cz\bin\core.4.dll [2012-03-09 1089568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-27 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-27 194504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-03-21 472992]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-04-01 1426136]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-04-16 5595848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-05-15 2888384]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-04-17 31282304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4StoryPrePatch]
C:\Program Files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aeria Ignite]
C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [2013-06-06 1925656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
C:\Users\Petr\AppData\Local\Akamai\netsession_win.exe [2014-10-29 4673432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Petr\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2015-04-10 3632472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [2012-07-09 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSplay.exe]
C:\Users\Petr\AppData\Local\Temp\Rar$EXa0.058\GSplay.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2015-03-30 3978600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MKLOL]
C:\Program Files (x86)\MKJogo\MKLOL\MK.exe -auto []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msjpxrSrv]
C:\Windows\inf\msjpxr.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2014-10-02 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Snap]
C:\Program Files (x86)\USB 2.0 PC CAMERA\Camera Snap.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tvncontrol]
C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2013-09-17 2327248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Petr\AppData\Roaming\Dropbox\bin\Dropbox.exe [2015-04-02 43382072]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-08-09 5263504]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"VICTORY Gaming Keyboard"=C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [2013-11-11 270336]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"AdobeCEPServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [2013-03-13 1039248]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-12 5515496]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Start GeekBuddy.lnk - C:\Program Files\COMODO\GeekBuddy\launcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launcher.exe]
"Debugger=""C:\Program Files (x86)\AVG PC TuneUp 2014\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-05-17 11:44:58 ----D---- C:\rsit
2015-05-17 11:44:58 ----D---- C:\Program Files\trend micro
2015-05-16 16:39:50 ----D---- C:\Users\Petr\AppData\Roaming\Tera_Awesomium
2015-05-15 17:32:08 ----HD---- C:\VTRoot
2015-05-15 17:32:01 ----A---- C:\Windows\system32\drivers\fvstore.dat
2015-05-15 15:13:51 ----D---- C:\Program Files (x86)\SpeedFan
2015-05-15 14:56:49 ----A---- C:\Windows\ntbtlog.txt
2015-05-13 07:38:55 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 07:38:55 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 07:23:43 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 07:23:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 07:23:42 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 07:23:42 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 07:23:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 07:23:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 07:23:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 07:23:35 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 07:23:35 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 07:23:35 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 07:23:34 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 07:23:34 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 07:23:34 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 07:23:34 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 07:23:33 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 07:23:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 07:23:33 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 07:23:33 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 07:23:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 07:23:32 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 07:23:32 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 07:23:32 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 07:23:32 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 07:23:31 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 07:23:31 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 07:23:30 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 07:23:30 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 07:23:30 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 07:23:30 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 07:23:30 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 07:23:30 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 07:23:30 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 07:23:30 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 07:23:29 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 07:23:29 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 07:23:29 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 07:23:29 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 07:23:28 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 07:23:28 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 07:23:28 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 07:23:28 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 07:23:28 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 07:23:27 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 07:23:27 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 07:23:27 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 07:23:25 ----A---- C:\Windows\system32\services.exe
2015-05-13 07:23:12 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-13 07:23:12 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-13 07:23:12 ----A---- C:\Windows\system32\ntdll.dll
2015-05-13 07:23:12 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-13 07:23:10 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-13 07:23:10 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-13 07:23:10 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-13 07:23:10 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-13 07:23:10 ----A---- C:\Windows\system32\tdh.dll
2015-05-13 07:23:10 ----A---- C:\Windows\system32\kernel32.dll
2015-05-13 07:23:10 ----A---- C:\Windows\system32\advapi32.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-13 07:23:09 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\wow64.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\winsrv.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\wdigest.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\typeperf.exe
2015-05-13 07:23:09 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-13 07:23:09 ----A---- C:\Windows\system32\srcore.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\smss.exe
2015-05-13 07:23:09 ----A---- C:\Windows\system32\sechost.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\rstrui.exe
2015-05-13 07:23:09 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\logman.exe
2015-05-13 07:23:09 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\kerberos.dll
2015-05-13 07:23:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-13 07:23:09 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-13 07:23:09 ----A---- C:\Windows\system32\conhost.exe
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 07:23:08 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-13 07:23:08 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-13 07:23:08 ----A---- C:\Windows\system32\wow64win.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\sspicli.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\srclient.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\secur32.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\relog.exe
2015-05-13 07:23:08 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\lsass.exe
2015-05-13 07:23:08 ----A---- C:\Windows\system32\diskperf.exe
2015-05-13 07:23:08 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\credssp.dll
2015-05-13 07:23:08 ----A---- C:\Windows\system32\auditpol.exe
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 07:23:07 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-13 07:23:07 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-13 07:23:07 ----A---- C:\Windows\system32\msobjs.dll
2015-05-13 07:23:07 ----A---- C:\Windows\system32\msaudite.dll
2015-05-13 07:23:07 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-13 07:23:07 ----A---- C:\Windows\system32\adtschema.dll
2015-05-13 07:22:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 07:22:51 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 07:22:51 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 07:22:50 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 07:22:47 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 07:22:47 ----A---- C:\Windows\system32\jnwmon.dll
2015-05-13 07:22:47 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 07:22:46 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 07:22:46 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 07:22:44 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 07:22:44 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 07:22:43 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 07:22:43 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-13 07:22:43 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 07:22:43 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 07:22:42 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 07:22:42 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 07:22:42 ----A---- C:\Windows\system32\shimeng.dll
2015-05-12 16:08:32 ----D---- C:\Users\Petr\AppData\Roaming\AVAST Software
2015-05-12 16:07:16 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2015-05-12 16:07:16 ----A---- C:\Windows\system32\drivers\aswStm.sys
2015-05-12 16:07:16 ----A---- C:\Windows\system32\drivers\aswSP.sys
2015-05-12 16:07:16 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2015-05-12 16:07:16 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2015-05-12 16:07:15 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2015-05-12 16:07:15 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2015-05-12 16:07:15 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2015-05-12 16:07:11 ----A---- C:\Windows\system32\aswBoot.exe
2015-05-12 16:06:56 ----A---- C:\Windows\avastSS.scr
2015-05-12 16:05:58 ----D---- C:\Program Files\AVAST Software
2015-05-12 16:05:07 ----D---- C:\ProgramData\AVAST Software
2015-05-11 10:46:27 ----D---- C:\Users\Petr\AppData\Roaming\raidcall
2015-05-11 10:46:16 ----D---- C:\Program Files (x86)\RaidCall

======List of files/folders modified in the last 1 month======

2015-05-17 11:44:59 ----D---- C:\Windows\Temp
2015-05-17 11:44:58 ----RD---- C:\Program Files
2015-05-17 11:43:29 ----D---- C:\Users\Petr\AppData\Roaming\Skype
2015-05-17 11:41:42 ----D---- C:\Windows\system32\config
2015-05-17 11:38:46 ----D---- C:\Program Files (x86)\Steam
2015-05-16 18:00:38 ----D---- C:\Users\Petr\AppData\Roaming\uTorrent
2015-05-16 16:29:32 ----D---- C:\ProgramData\boost_interprocess
2015-05-16 00:24:52 ----D---- C:\Users\Petr\AppData\Roaming\Audacity
2015-05-15 17:32:01 ----D---- C:\Windows\system32\drivers
2015-05-15 17:20:02 ----SHD---- C:\Windows\Installer
2015-05-15 17:20:02 ----SHD---- C:\Config.Msi
2015-05-15 15:23:52 ----RD---- C:\Program Files (x86)
2015-05-15 15:23:18 ----D---- C:\Windows\Tasks
2015-05-15 15:23:17 ----D---- C:\Windows\system32\Tasks
2015-05-15 15:13:50 ----D---- C:\Windows\SysWOW64
2015-05-15 15:01:28 ----D---- C:\ProgramData\Origin
2015-05-15 14:56:49 ----D---- C:\Windows
2015-05-15 14:49:23 ----D---- C:\ProgramData\Skype
2015-05-14 18:57:41 ----D---- C:\Windows\Prefetch
2015-05-14 16:22:02 ----D---- C:\Windows\Microsoft.NET
2015-05-14 16:06:16 ----RSD---- C:\Windows\assembly
2015-05-14 15:40:01 ----D---- C:\Program Files (x86)\StarCraft II
2015-05-14 15:36:20 ----D---- C:\Program Files (x86)\Battle.net
2015-05-14 07:37:34 ----D---- C:\Windows\winsxs
2015-05-14 07:35:38 ----SHD---- C:\System Volume Information
2015-05-14 06:48:59 ----D---- C:\Windows\System32
2015-05-14 06:48:59 ----D---- C:\Windows\inf
2015-05-14 06:48:59 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-14 06:38:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-14 06:38:26 ----D---- C:\Windows\system32\cs-CZ
2015-05-14 06:38:26 ----D---- C:\Program Files\Internet Explorer
2015-05-14 06:38:25 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-14 06:38:24 ----D---- C:\Windows\system32\en-US
2015-05-14 06:38:22 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-14 06:37:50 ----D---- C:\Windows\AppPatch
2015-05-14 06:37:43 ----D---- C:\Program Files\Windows Journal
2015-05-14 06:37:38 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 06:37:34 ----D---- C:\Windows\system32\DriverStore
2015-05-14 06:37:33 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-14 01:19:48 ----D---- C:\ProgramData\Microsoft Help
2015-05-14 01:14:51 ----D---- C:\Windows\system32\MRT
2015-05-14 01:08:00 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 23:49:09 ----D---- C:\Windows\system32\catroot2
2015-05-12 16:05:07 ----HD---- C:\ProgramData
2015-05-10 16:59:43 ----D---- C:\Program Files (x86)\Heroes of the Storm
2015-05-07 15:17:40 ----D---- C:\Windows\system32\NDF
2015-04-26 21:42:01 ----D---- C:\Users\Petr\AppData\Roaming\vlc
2015-04-22 18:00:30 ----D---- C:\Program Files (x86)\Arc
2015-04-21 19:35:33 ----D---- C:\ProgramData\Package Cache
2015-04-21 10:37:07 ----N---- C:\Windows\system32\MpSigStub.exe
2015-04-18 01:19:28 ----D---- C:\Users\Petr\AppData\Roaming\.minecraft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-05-12 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-05-12 272248]
R0 BtHidBus;Bluetooth HID Bus Service; C:\Windows\System32\Drivers\BtHidBus.sys [2009-09-24 23304]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2014-07-16 386680]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2012-10-25 22680]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-05-12 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-05-12 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-05-12 442264]
R1 CFRMD;CFRMD; C:\Windows\system32\DRIVERS\CFRMD.sys [2013-05-07 37976]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2015-04-01 20696]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2015-04-01 797280]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2015-04-01 45880]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-04-16 246000]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-04-16 169792]
R1 HMD;COMODO livePCsupport Hardware Monitor Driver; C:\Windows\system32\DRIVERS\hmd.sys [2013-10-07 14888]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2015-04-01 104608]
R1 VirtDiskBus;3TB+ Unlock; C:\Windows\system32\DRIVERS\VirtDiskBus64.sys [2011-02-08 66160]
R2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver2.sys [2012-09-24 57512]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-05-12 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-05-12 89944]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-05-12 137288]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-04-16 159480]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-11-01 42696]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-28 10278912]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-28 368640]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-07-16 283064]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2012-08-07 65152]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2012-08-07 88832]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM); C:\Windows\system32\DRIVERS\vrtaucbl.sys [2014-07-17 66728]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-03-30 56448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2012-08-03 2206352]
S0 prohlp02;StarForce Protection Helper Driver v2; C:\Windows\System32\drivers\prohlp02.sys []
S0 prosync1;StarForce Protection Synchronization Driver v1; C:\Windows\System32\drivers\prosync1.sys []
S0 sfhlp01;StarForce Protection Helper Driver; C:\Windows\System32\drivers\sfhlp01.sys []
S1 prodrv06;StarForce Protection Environment Driver v6; C:\Windows\System32\drivers\prodrv06.sys []
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-11-02 310984]
S3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys []
S3 btnetBUs;Bluetooth PAN Bus Service; C:\Windows\System32\Drivers\btnetBus.sys [2009-09-24 27776]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2013-10-02 25640]
S3 FairplayKD;FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-07-17 25640]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-10-02 30528]
S3 IvtBtBUs;IVT Bluetooth Bus Service; C:\Windows\System32\Drivers\IvtBtBus.sys [2009-08-26 30344]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesDriver64.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbcamcl;Driver for video Device; C:\Windows\system32\DRIVERS\usbcamcl.sys []
S3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-28 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-08-06 361984]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-05-12 343336]
R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-04-01 5540424]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-04-16 1349576]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-07-18 9216]
R2 ChromodoUpdater;COMODO Chromodo Update Service; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [2015-03-26 2306248]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-03-30 417552]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-06-30 76152]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-07-02 5037888]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2012-08-03 27792]
S2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
S2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-02 116648]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2015-03-30 2490216]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 ArcService;Arc Service; C:\Program Files (x86)\Arc\ArcService.exe [2015-04-16 88584]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-04-01 2265816]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2014-11-17 182304]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-02 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2015-03-27 194032]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-13 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-30 119408]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2015-04-10 1931632]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2015-01-17 762320]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 CLPSLauncher;COMODO LPS Launcher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [2013-09-19 70352]
S4 GeekBuddyRSP;GeekBuddyRSP Server; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2013-09-17 2327248]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------
Naposledy upravil(a) Lefiks dne 17 kvě 2015 14:06, celkem upraveno 2 x.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Nedavejte logy do Code, spatne se to cte.

:???: Kdy problem zacal?

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#3 Příspěvek od Lefiks »

OTL logfile created on: 17.5.2015 12:47:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Petr\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17801)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

7,96 Gb Total Physical Memory | 4,97 Gb Available Physical Memory | 62,45% Memory free
15,92 Gb Paging File | 12,31 Gb Available in Paging File | 77,31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 732,42 Gb Total Space | 58,19 Gb Free Space | 7,94% Space Free | Partition Type: NTFS
Drive D: | 1130,50 Gb Total Space | 1116,09 Gb Free Space | 98,73% Space Free | Partition Type: NTFS

Computer Name: PETR-PC | User Name: Petr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2015.05.17 12:46:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
PRC - [2015.05.13 20:22:51 | 000,812,872 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015.05.12 16:07:36 | 005,515,496 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2015.05.12 16:06:54 | 000,343,336 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2015.04.16 13:59:18 | 001,349,576 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2015.03.26 08:41:16 | 002,306,248 | ---- | M] (Comodo) -- C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
PRC - [2014.07.02 11:45:04 | 004,606,784 | ---- | M] (TeamViewer GmbH) -- c:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe
PRC - [2014.07.02 11:45:03 | 013,115,712 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
PRC - [2014.07.02 11:45:03 | 005,037,888 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014.07.02 11:30:03 | 000,229,696 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
PRC - [2014.06.30 09:58:02 | 000,076,152 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013.11.11 17:42:50 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\OSD.exe
PRC - [2013.11.11 17:38:56 | 000,270,336 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE


========== Modules (No Company Name) ==========

MOD - [2015.05.12 16:07:10 | 040,540,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015.05.12 16:07:09 | 000,104,400 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2015.05.12 16:07:08 | 000,081,728 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2015.05.05 06:06:52 | 001,252,680 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.152\libglesv2.dll
MOD - [2015.05.05 06:06:52 | 000,080,712 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.152\libegl.dll
MOD - [2013.11.11 17:42:50 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\OSD.exe
MOD - [2013.11.11 17:38:56 | 000,270,336 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
MOD - [2013.09.05 01:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2013.03.08 07:17:18 | 001,425,920 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avformat-54.dll
MOD - [2013.03.08 07:17:18 | 000,188,416 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avutil-52.dll
MOD - [2013.03.08 07:17:18 | 000,096,256 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\swresample-0.dll
MOD - [2013.03.08 07:17:05 | 000,336,896 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\swscale-2.dll
MOD - [2013.03.08 07:17:04 | 007,816,192 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avcodec-54.dll
MOD - [2012.11.05 09:37:28 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\hiddriver.dll
MOD - [2012.11.05 09:09:48 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Gaming Keyboard\lan.dll


========== Services (SafeList) ==========

SRV:64bit: - [2015.05.13 07:23:35 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2015.05.13 07:23:12 | 001,254,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2015.05.12 16:06:54 | 000,343,336 | ---- | M] (Avast Software s.r.o.) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2015.04.16 13:59:18 | 001,349,576 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2015.04.01 18:48:32 | 005,540,424 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (CmdAgent)
SRV:64bit: - [2015.04.01 18:44:06 | 002,265,816 | ---- | M] (COMODO) [On_Demand | Stopped] -- C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)
SRV:64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012.08.06 12:24:22 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2012.08.03 07:27:50 | 000,027,792 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV:64bit: - [2012.07.28 04:09:45 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.04.06 16:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015.04.16 17:27:59 | 000,088,584 | ---- | M] (Perfect World Entertainment Inc) [On_Demand | Stopped] -- C:\Program Files (x86)\Arc\ArcService.exe -- (ArcService)
SRV - [2015.04.15 15:47:22 | 000,268,464 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015.04.10 07:22:29 | 001,931,632 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- C:\Program Files (x86)\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2015.03.30 19:44:13 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015.03.30 15:29:00 | 002,490,216 | ---- | M] (LogMeIn Inc.) [Auto | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2015.03.30 15:25:28 | 000,417,552 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2015.03.26 08:41:16 | 002,306,248 | ---- | M] (Comodo) [Auto | Running] -- C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe -- (ChromodoUpdater)
SRV - [2015.02.19 01:51:18 | 000,835,776 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015.02.18 19:11:32 | 000,315,488 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2015.01.17 19:03:18 | 000,762,320 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2014.11.17 19:24:23 | 000,182,304 | ---- | M] (EasyAntiCheat Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\EasyAntiCheat.exe -- (EasyAntiCheat)
SRV - [2014.07.18 20:13:20 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2014.07.14 18:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014.07.14 18:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014.07.02 11:45:03 | 005,037,888 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014.06.30 09:58:02 | 000,076,152 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014.04.12 00:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014.03.21 00:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013.09.19 11:14:46 | 000,070,352 | ---- | M] (Comodo Security Solutions, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe -- (CLPSLauncher)
SRV - [2013.09.17 12:00:52 | 002,327,248 | ---- | M] (Comodo Security Solutions, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe -- (GeekBuddyRSP)
SRV - [2011.08.30 15:55:54 | 000,160,256 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2015.05.12 16:07:10 | 000,442,264 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2015.05.12 16:07:10 | 000,272,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2015.05.12 16:07:10 | 000,093,528 | ---- | M] (Avast Software s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2015.05.12 16:07:10 | 000,089,944 | ---- | M] (Avast Software s.r.o.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2015.05.12 16:07:10 | 000,065,736 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2015.05.12 16:07:10 | 000,029,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2015.05.12 16:07:05 | 001,047,320 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2015.05.12 16:07:00 | 000,137,288 | ---- | M] (Avast Software s.r.o.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2015.04.16 13:59:28 | 000,246,000 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2015.04.16 13:59:27 | 000,159,480 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2015.04.16 13:59:26 | 000,169,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2015.04.01 18:49:46 | 000,020,696 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:64bit: - [2014.12.30 15:41:48 | 000,086,352 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\wolfk64.sys -- (wolfkr)
DRV:64bit: - [2014.11.02 12:43:00 | 000,310,984 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2014.11.01 17:52:44 | 000,042,696 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2014.07.17 21:36:53 | 000,066,728 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm)
DRV:64bit: - [2014.07.16 15:46:32 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014.07.16 15:43:34 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2013.10.07 07:17:38 | 000,014,888 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hmd.sys -- (HMD)
DRV:64bit: - [2013.10.02 04:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013.05.07 09:00:18 | 000,037,976 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | System | Running] -- C:\Windows\SysNative\drivers\CFRMD.sys -- (CFRMD)
DRV:64bit: - [2013.02.12 06:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2012.10.25 09:01:20 | 000,022,680 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger)
DRV:64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.07 09:09:00 | 000,088,832 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)
DRV:64bit: - [2012.08.07 09:09:00 | 000,065,152 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)
DRV:64bit: - [2012.08.03 07:27:44 | 002,206,352 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2012.07.28 06:07:45 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.28 03:14:47 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.11 03:40:58 | 000,082,560 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2012.04.11 03:40:58 | 000,042,624 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2012.03.30 16:49:08 | 000,056,448 | R--- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2012.03.05 16:04:30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.08.23 15:57:24 | 000,565,352 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.08 16:02:44 | 000,066,160 | ---- | M] (Giga-Byte Technology CO., LTD.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\VirtDiskBus64.sys -- (VirtDiskBus)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.09.24 13:38:48 | 000,027,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btnetBus.sys -- (btnetBUs)
DRV:64bit: - [2009.09.24 05:40:14 | 000,023,304 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BtHidBus.sys -- (BtHidBus)
DRV:64bit: - [2009.09.16 07:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t)
DRV:64bit: - [2009.08.26 11:16:52 | 000,030,344 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 19:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2014.07.17 19:55:35 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2013.10.02 06:10:39 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\etdrv.sys -- (etdrv)
DRV - [2013.10.02 05:59:46 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\GVTDrv64.sys -- (GVTDrv64)
DRV - [2012.09.24 01:54:02 | 000,057,512 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files (x86)\GIGABYTE\ET6\amd64\aoddriver2.sys -- (AODDriver4.2)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2004.05.13 15:00:04 | 000,111,808 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.05.13 13:19:36 | 000,079,488 | ---- | M] (Protection Technology) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\prodrv06.sys -- (prodrv06)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.09.06 14:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prosync1.sys -- (prosync1)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\..\SearchScopes,DefaultScope = {8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IESR02
IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\..\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: "URL" = http://us.search.yahoo.com/search?p={se ... chr-comodo
IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - prefs.js..extensions.trusted-ads.serp_about: "\"%2F*!%20serp-about%20-%20v0.1.10%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09debug%3A%20false%2C%0A%09extend%3A%20function(Child%2C%20Parent)%20%7B%0A%09%09var%20F%20%3D%20function()%20%7B%20%7D%3B%0A%09%09F.prototype%20%3D%20Parent.prototype%3B%0A%09%09Child.prototype%20%3D%20new%20F()%3B%0A%09%09Child.prototype.constructor%20%3D%20Child%3B%0A%09%09Child._super%20%3D%20Parent.prototype%3B%0A%09%7D%2C%0A%09log%3A%20function()%20%7B%0A%09%09if%20(Util.debug)%20%7B%0A%09%09%09var%20args%20%3D%20Array.prototype.slice.call(arguments)%3B%0A%09%09%09console.log.apply(console%2C%20args)%3B%0A%09%09%7D%0A%09%7D%0A%7D%3B%0A%2F%2Fshort%20alias%0Au%20%3D%20Util%3B%0A%0Afunction%20ENGINE%20()%20%7B%7D%0Afunction%20GoogleChrome%20()%20%7B%7D%0Afunction%20CORE()%20%7B%7D%0Afunction%20Firefox%20()%20%7B%7D%0Afunction%20IE%20()%20%7B%7D%0A%0AUtil.extend(ENGINE%2C%20CORE)%3B%0AUtil.extend(GoogleChrome%2C%20ENGINE)%3B%0AUtil.extend(Firefox%2C%20ENGINE)%3B%0AUtil.extend(IE%2C%20ENGINE)%3B%0D%0ACORE.prototype.ADS_HOST%20%3D%20document.location.protocol%2B%22%2F%2Fsearch.adtrustmedia.com%2Fsearch_safecontent.php%22%3B%0D%0A%0D%0ACORE.prototype.ALL_BLOCKS_SELECTOR%20%3D%20function()%7B%0D%0A%09return%20%7B%0D%0A%09%09orig%3A%20this.BLOCKS.TOP.origSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.origSel*%2F%2C%0D%0A%09%09cover%3A%20this.BLOCKS.TOP.coverSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.coverSel*%2F%0D%0A%09%7D%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.STYLES%20%3D%20%20function()%20%7B%0D%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0D%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20%7B%20%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%2304c%3B%20text-decoration%3Aunderline%3B%20font-size%3A17px%3B%7D%20%5C%0D%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23388222%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%7D%20%5C%0D%0A%09%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20visibility%3A%20hidden%3B%20overflow%3A%20hidden%3B%7D%20%5C%0D%0A%09.adtrCover-closeBtn%7B%20%5C%0D%0A%09%09cursor%3A%20pointer%3B%20%5C%0D%0A%09%09padding%3A%200%202px%202px%202px%3B%20%5C%0D%0A%09%09font-size%3A%2012px%3B%20%5C%0D%0A%09%09text-align%3A%20center%3B%20%5C%0D%0A%09%09position%3A%20absolute%3B%20%5C%0D%0A%09%09height%3A%2012px%3B%20%5C%0D%0A%09%09width%3A%2033px%3B%20%5C%0D%0A%09%09border%3A%201px%20solid%20lightblue%3B%20%5C%0D%0A%09%09background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0D%0A%09%09display%3A%20inline-block%3B%20%5C%0D%0A%09%09right%3A%201px%3B%20%5C%0D%0A%09%09top%3A%203px%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.adtrCover%20.closeAd%7B%20%5C%0D%0A%09%09text-decoration%3A%20underline%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0D%0A%09.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0D%0A%09.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0D%0A%09%3C%2Fstyle%3E%22%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.MENU_BTN_SPACE%20%3D%208%3B%0D%0ACORE.prototype.MIN_PADDING%20%3D%208%3B%0D%0A%0D%0ACORE.prototype._ads%20%3D%20%5B%5D%3B%0D%0ACORE.prototype.instanceId%20%3D%20''%3B%0D%0ACORE.prototype.affilateID%20%3D%20''%3B%0D%0ACORE.prototype.data%20%3D%20null%3B%0D%0ACORE.prototype.keyword%20%3D%20''%3B%0D%0ACORE.prototype.engineParams%20%3D%20%7B%7D%3B%0D%0ACORE.prototype.engineCode%20%3D%20''%3B%0D%0A%0D%0ACORE.prototype.start%20%3D%20function()%7B%7D%3B%0D%0A%0D%0ACORE.prototype.init%20%3D%20function(instanceId%2C%20affilateID%2C%20engineParams)%20%7B%0D%0A%09this.data%20%3D%20typeof(engineData)%20!%3D%20%22undefined%22%20%3F%20engineData%20%3A%20null%3B%0D%0A%09this.keyword%20%3D%20typeof(engineKeyword)%20!%3D%20%22undefined%22%20%3F%20engineKeyword%20%3A%20''%3B%0D%0A%0D%0A%09if(engineParams.delivPoint)%20%7B%20this.ADS_HOST%20%3D%20engineParams.delivPoint%3B%20%7D%0D%0A%0D%0A%09%24(%22head%22).append(this.coreStyles())%3B%0D%0A%09%24(%22head%22).append(this.STYLES())%3B%0D%0A%09this.instanceId%20%3D%20instanceId%3B%0D%0A%09this.affilateID%20%3D%20affilateID%3B%0D%0A%09this.engineParams%20%3D%20engineParams%3B%0D%0A%0D%0A%09this.suggModule%20%3D%20new%20this.SuggestionModule()%3B%0D%0A%09if(engineParams.suggConfig)%20%7B%0D%0A%09%09this.suggModule.setConfig(engineParams.suggConfig)%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09var%20currentKeyword%20%3D%20this.getCurrentKeyword().toLowerCase()%3B%0D%0A%0D%0A%09if(this.keyword)%7B%0D%0A%09%09this.keyword%20%3D%20decodeURIComponent(this.keyword)%3B%0D%0A%09%09this.keyword%20%3D%20this.keyword.replace(%2F%5C%2B%2Fg%2C%20'%20')%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09u.log('FROM%20PLUGIN%3A'%2C%20%7B'engineData'%3A%20this.data%2C%20'engineKeyword'%3A%20this.keyword%2C%20'currentKeyword'%3A%20currentKeyword%2C%20'engineParams'%3A%20engineParams%7D)%3B%0D%0A%0D%0A%09if%20(%20this.data%20%26%26%20(this.data%20!%3D%20'noPreload')%20%26%26%20(currentKeyword%20%3D%3D%20this.keyword)%20)%7B%0D%0A%09%09var%20suggAdData%20%3D%20this.suggModule.getAdsForKeyword(this.keyword)%3B%0D%0A%0D%0A%09%09this.data%20%3D%20suggAdData.concat(this.data)%3B%0D%0A%09%09u.log('suggAdData'%2C%20suggAdData%2C%20this.data)%3B%0D%0A%09%09if(%20this.data.length%20)%7B%0D%0A%09%09%09this.multipleTryToFindBlocks()%3B%20%2F%2Fchanged%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%20else%20%7B%0D%0A%09%09if(currentKeyword%20!%3D%20%22undefined%22)%20%7B%0D%0A%09%09%09this.keyword%20%3D%20currentKeyword%3B%0D%0A%09%09%09var%20requestUrl%20%3D%20this.getAdRequestUrl(currentKeyword)%3B%0D%0A%09%09%09this.sendAdRequest(requestUrl)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._domain_without_www%20%3D%20function(url)%20%7B%0D%0A%09var%20clean%20%3D%20url.replace(%2F%5Ewww%5C.%2F%2C'')%3B%0D%0A%09return%20clean%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getAdRequestUrl%20%3D%20function(keyword)%20%7B%0D%0A%09var%20domain%20%3D%20this._domain_without_www(document.location.host)%3B%0D%0A%09var%20requestUrl%20%3D%20this.ADS_HOST%20%2B%20%22%3F%22%20%2B%0D%0A%09%09%22adtype%3Dtext%22%20%2B%0D%0A%09%09%22%26method%3Djs%22%20%2B%0D%0A%09%09%22%26advert%3D1%22%20%2B%0D%0A%09%09%22%26referer%3D%22%20%2B%20encodeURIComponent(document.location.protocol%20%2B%22%2F%2F%22%2B%20document.location.host%2B%22%2F%22)%20%2B%0D%0A%09%09%22%26ta_affiliateid%3D%22%20%2B%20this.affilateID%20%2B%0D%0A%09%09%22%26ta_insid%3D%22%20%2B%20this.instanceId%20%2B%0D%0A%09%09%22%26kw%3D%22%20%2B%20encodeURIComponent(keyword)%20%2B%0D%0A%09%09this.getEngineIdentityParam()%3B%0D%0A%09return%20requestUrl%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getCurrentKeyword%20%3D%20function()%7B%0D%0A%09var%20keyword%20%3D%20''%3B%0D%0A%0D%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0D%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0D%0A%0D%0A%09if(spell.length)%7B%0D%0A%09%09keyword%20%3D%20spell.text()%3B%0D%0A%09%7D%20else%20if(input.length)%7B%0D%0A%09%09keyword%20%3D%20input.val()%3B%0D%0A%09%7D%0D%0A%09return%20keyword%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FTRY%20TO%20GET%20ADS%20BY%20NEW%20KEYWORD%0D%0A%2F%2F_requestInProcess%3A%20false%2C%0D%0ACORE.prototype.sendAdRequest%20%3D%20function(requestUrl)%20%7B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%0D%0A%09u.log('SEND%20REQUEST'%2C%20%5Bthis.keyword%2C%20requestUrl%5D)%3B%0D%0A%0D%0A%09%24.ajax(%7B%0D%0A%09%09url%3A%20requestUrl%2C%0D%0A%09%09dataType%3A%20'json'%2C%0D%0A%09%09error%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function()%20%7B%0D%0A%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%2C%0D%0A%09%09success%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function(data)%20%7B%0D%0A%09%09%09%09var%20suggAdData%20%3D%20scope.suggModule.getAdsForKeyword(scope.keyword)%3B%0D%0A%09%09%09%09data%20%3D%20suggAdData.concat(data)%3B%0D%0A%0D%0A%09%09%09%09if(!data.length)%20%7B%0D%0A%09%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%09%09return%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09u.log('REQUEST%20SUCCESS'%2C%20%5Bscope.keyword%2C%20scope.suggModule%2C%20data%5D)%3B%0D%0A%09%09%09%09scope.data%20%3D%20data%3B%0D%0A%09%09%09%09scope.clearDynamicBlocksData()%3B%0D%0A%09%09%09%09scope.makeCovers()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showAllOriginalAd%20%3D%20function()%20%7B%0D%0A%09u.log('showAllOriginalAd()')%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B').show()%3B%0D%0A%09if(block.adSel)%7B%0D%0A%09%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible!important%3B')%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FADS%20REPLACEMENT%20PROCESS%0D%0ACORE.prototype.makeCovers%20%3D%20function()%20%7B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%0D%0A%09%09if(!this.isAdExist(block))%20%7B%0D%0A%09%09%09if(this.isOfficialSiteBlock(block))%7B%0D%0A%09%09%09%09this.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%09continue%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09%2F%2FORIGINAL%20SELECTOR%20IS%20A%20DOM%20ELEMENT%0D%0A%09%09this._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09this.makeCover(block%2C%20blockName)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdExist%20%3D%20function(block)%20%7B%0D%0A%09var%20origSel%20%3D%20%24(block.origSel)%3B%0D%0A%09return%20origSel.length%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FPREPARE%20AND%20RENDER%20REPLACEMENT%20COVER%20(old%3A%20_prepareReplacement)%0D%0ACORE.prototype.makeCover%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('MAKE%20COVER'%2C%20blockName%2C%20%7BblockData%3A%20JSON.stringify(block.data)%7D)%3B%0D%0A%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(el.index('%23fakeAd')%20!%3D%20-1)%7B%0D%0A%09%09el%20%3D%20%24('%23fakeAd')%3B%0D%0A%09%7D%0D%0A%09var%20data%20%3D%20block.data%3B%0D%0A%0D%0A%09if%20(data.length)%20%7B%0D%0A%0D%0A%09%09var%20width%20%3D%20el.width()%3B%0D%0A%09%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%09%09%2F%2FREMOVE%20PREV%20BLOCK%0D%0A%09%09%24(block.coverSel).remove()%3B%0D%0A%0D%0A%09%09%2F%2FCREATE%20COVER%0D%0A%09%09var%20coverHeight%20%3D%20el.height()%3B%0D%0A%09%09if(block.newHeight)%7B%0D%0A%09%09%09coverHeight%20%3D%20block.newHeight%3B%0D%0A%09%09%09el.height(coverHeight)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09var%20cover%20%3D%20%24('%3Cdiv%20id%3D%22'%2B%20block.coverId%20%2B'%22%20class%3D%22adtrCover%22%20style%3D%22height%3A'%2B%20coverHeight%20%2B'px%3B%22%3E'%2B%20this._fillWithAds(block%2C%20blockName)%20%2B'%3C%2Fdiv%3E').css(%7B%0D%0A%09%09%09margin%3A%20this.getMargin(el)%2C%20padding%3A%20this.getPadding(el)%2C%0D%0A%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%7D)%3B%0D%0A%09%09cover.insertBefore(el)%3B%0D%0A%09%09el.addClass('hideOrig')%3B%0D%0A%09%09this.makeCoverMenu(block%2C%20cover%2C%20blockName)%3B%0D%0A%09%09this._compareRealAndCalcHeights(block)%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('showed%20without%20ad'%2C%20blockName)%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeCoverMenu%20%3D%20function(block%2C%20cover%2C%20blockName)%20%7B%0D%0A%20%20%20%20%20%20var%20clas%20%3D%20'atmAd'%3B%0D%0A%20%20%20%20%20%20var%20d%3B%0D%0A%0D%0A%20%20%20%20%20%20if%20(blockName%20%3D%3D%20'RIGHT')%20%7B%0D%0A%20%20%20%20%20%20%20%20clas%20%3D%20'atmAd-left'%3B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%3E%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%20else%20%7B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%3Cimg%20src%3D%22'%2Bdocument.location.protocol%2B'%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%20%2F%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FTABLE%0D%0A%20%20%20%20%20%20var%20t%20%3D%20%24(%22%3Ctable%20style%3D'visibility%3Ainherit%3B%20border-spacing%3A%201px%3B%20margin%3A%200px%3B%20border-collapse%3A%20collapse%3B%20%20background-color%3Agrey%3B%20z-index%3A100%3B'%20border%3D'1'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20style%3D'background-color%3Awhite%3B%20height%3A%2014px%3B%20padding%3A0px%203px%3B%20line-height%3A14px%3B'%3E%3Ca%20style%3D'width%3A58px%3B%20margin%3A0px%3B%20display%3Ablock%3B%20color%3Ablack%3B%20text-decoration%3Anone%3B%20text-align%3Aleft%3B%20font-weight%3Anormal%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20background-color%3Awhite%3B%20font-size%3A9px%3B'%20href%3D'https%3A%2F%2Fadtrustmedia.com%2Fwhyad.html'%20target%3D'_blank'%3EWhy%20this%20ad%3F%3C%2Fa%3E%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20class%3D'closeAd'%20style%3D'white-space%3Anowrap%3B%20color%3Ablack%3B%20background-color%3Awhite%3B%20cursor%3Apointer%3B%20padding%3A0px%203px%3B%20%20height%3A%2014px%3B%20line-height%3A14px%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A9px%3B'%3EClose%20this%20ad%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftable%3E%22)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20d.find('a.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20t.find('.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%20%20%20%20%20%20d.append(t)%3B%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FCLICK%20ON%20ATM%20AD%0D%0A%20%20%20%20%20%20d.find('.toggleTable').click(function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%24(this).next().toggle()%3B%0D%0A%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20d.appendTo(cover)%3B%0D%0A%0D%0A%20%20%20%20%20%20var%20self%20%3D%20this%3B%0D%0A%20%20%20%20%20%20function%20removeAd()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20cover.remove()%3B%0D%0A%20%20%20%20%20%20%20%20%20%20self.showOriginalAdForBlock(block)%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype._fillWithAds%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('FILL%20COVER'%2C%20blockName%2C%20%5Bblock.data%5D)%3B%0D%0A%09var%20block_content%20%3D%20''%2C%0D%0A%09%09data%20%3D%20block.data%3B%0D%0A%0D%0A%09block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09var%20adTopPadding%20%3D%20block.adTopPadding%3B%0D%0A%09%09if(i%3D%3D%3D0)%20%7B%0D%0A%09%09%09adTopPadding%20%3D%20adTopPadding%2F2%3B%0D%0A%09%09%09if(blockName%20%3D%3D%20'RIGHT')%20adTopPadding%20%2B%3D%20this.MENU_BTN_SPACE%3B%0D%0A%09%09%7D%0D%0A%09%09var%20offsiteClass%20%3D%20(data%5Bi%5D.origin%20%3D%3D%20%22suggestion%22)%20%3F%20'class%3D%22official-site%22'%20%3A%20%22%22%3B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20style%3D'padding-top%3A%20%22%2BadTopPadding%2B%22px'%22%20%2B%20offsiteClass%20%2B%20%22%3E%22%2B%0D%0A%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09return%20block_content%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._calcAdHeightForBlock%20%3D%20function(block)%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(!el.length)%20%7B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20width%20%3D%20el.width()%3B%0D%0A%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%0D%0A%09var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%20position%3Aabsolute%20!important%3B%20top%3A%20-10000px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%2F%2F%20var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%09%09%09).css(%7B%0D%0A%09%09%09%09%09margin%3A%20this.getMargin(el)%2C%0D%0A%09%09%09%09%09padding%3A%20this.getPadding(el)%20%2C%0D%0A%09%09%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%09%09%7D)%3B%0D%0A%0D%0A%0D%0A%09var%20block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%09var%20data%20%3D%20this.data%3B%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20data-index%3D'%22%2Bi%2B%22'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09div.html(block_content)%3B%0D%0A%09%24(this.MAIN_CONTAINER_SEL).append(div)%3B%0D%0A%0D%0A%09u.log('MAIN_CONTAINER_SEL'%2C%20%24(this.MAIN_CONTAINER_SEL).length)%3B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%09div.find('li').each(function(i%2C%20li)%7B%0D%0A%09%09li%20%3D%20%24(li)%3B%0D%0A%09%09var%20index%20%3D%20li.data('index')%3B%0D%0A%09%09if(!scope.data%5Bindex%5D.h)%20scope.data%5Bindex%5D.h%20%3D%20%7B%7D%3B%0D%0A%09%09scope.data%5Bindex%5D.h%5Bblock.origSel%5D%20%3D%20li.height()%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09%2F%2F%20div.remove()%3B%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._provideAdDataForBlock%20%3D%20function(block%2C%20blockName)%7B%0D%0A%09u.log('DATA%20FOR%20BLOCK'%2C%20blockName)%3B%0D%0A%0D%0A%09var%20addingLog%20%3D%20%5B%5D%3B%0D%0A%0D%0A%09var%20MAX_ADDITIONAL_PADDING%20%3D%2015%3B%0D%0A%0D%0A%09var%20providedIndexes%20%3D%20%5B%5D%3B%0D%0A%09var%20allData%20%3D%20this.data%3B%0D%0A%0D%0A%09var%20origEl%20%3D%20%24(block.origSel)%3B%0D%0A%09var%20blockHeight%20%3D%20origEl.height()%3B%0D%0A%09var%20adPadding%20%3D%20this.MIN_PADDING%3B%0D%0A%09var%20adHeightSumm%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'RIGHT')%20adHeightSumm%20%3D%20this.MENU_BTN_SPACE%3B%0D%0A%0D%0A%09this._calcAdHeightForBlock(block)%3B%0D%0A%0D%0A%09var%20indexesOfOtherBlocks%20%3D%20this._getDataIndexesOfOtherBlocks(block)%3B%0D%0A%0D%0A%09var%20allDataWasChecked%20%3D%20false%3B%0D%0A%09var%20i%20%3D%200%3B%0D%0A%09var%20numOfCheckedIndexes%20%3D%200%3B%0D%0A%0D%0A%09var%20maxOfAds%20%3D%20this.getMaxAdsForBlock(blockName)%3B%0D%0A%09var%20minOfAds%20%3D%20this.getMinAdsForBlock(blockName)%3B%0D%0A%0D%0A%09u.log('indexesOfOtherBlocks'%2C%20indexesOfOtherBlocks)%3B%0D%0A%09var%20numOfFreeIndexes%20%3D%20allData.length%20-%20indexesOfOtherBlocks.length%3B%0D%0A%09var%20ttt%20%3D%200%3B%0D%0A%09var%20adHeight%3B%0D%0A%09while(i%20%3C%20allData.length%20%26%26%20ttt%3C30%20%26%26%20providedIndexes.length%3CmaxOfAds)%7B%0D%0A%0D%0A%09%09var%20indexIsFree%20%3D%20(indexesOfOtherBlocks.indexOf(i)%20%3D%3D%20-1)%3B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09var%20anywayAd%20%3D%20this.isAdAnyway(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(indexIsFree%20%26%26%20acceptableAd)%7B%0D%0A%0D%0A%09%09%09adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%0D%0A%09%09%09%2F%2Fif%20we%20can%20fit%20ad%20to%20block%20then%20add%20it%0D%0A%09%09%09addingLog.push(%7B%0D%0A%09%09%09%09i%3A%20i%2C%0D%0A%09%09%09%09t%3A%20allData%5Bi%5D.t%2C%0D%0A%09%09%09%09free%3A%20(blockHeight-adHeightSumm)%2C%0D%0A%09%09%09%09adPad%3A%20(adHeight%2Bthis.MIN_PADDING)%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%09var%20enoughSpace%20%3D%20(blockHeight%20%3E%3D%20adHeightSumm%20%2B%20adHeight%20%2B%20adPadding)%3B%0D%0A%09%09%09if(enoughSpace%20%7C%7C%20providedIndexes.length%20%3C%20minOfAds%20%7C%7C%20anywayAd)%7B%0D%0A%09%09%09%09if(!enoughSpace)%7B%0D%0A%09%09%09%09%09u.log('add%20more%20ads%20couse%20min%20ads%20required%20in%20block'%2C%20blockName%2C%20providedIndexes.length)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09%09providedIndexes.push(i)%3B%0D%0A%09%09%09%7D%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09ttt%2B%2B%3B%0D%0A%09%09i%2B%2B%3B%0D%0A%09%7D%0D%0A%09u.log('addingLog'%2C%20addingLog)%3B%0D%0A%0D%0A%09var%20freeSpace%20%3D%20blockHeight%20-%20adHeightSumm%3B%0D%0A%09var%20additionalPadding%20%3D%20freeSpace%20%2F%20(providedIndexes.length)%3B%0D%0A%0D%0A%09u.log('blockHeight'%2C%20blockHeight%2C%20'adHeightSumm'%2C%20adHeightSumm%2C%20'freeSpace'%2C%20freeSpace)%3B%0D%0A%0D%0A%09u.log('additionalPadding'%2C%20additionalPadding%2C%20'acceptable'%2C%20(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200))%3B%0D%0A%09if(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09adPadding%20%2B%3D%20additionalPadding%3B%0D%0A%09%7D%20else%20if(providedIndexes.length%20%3C%20maxOfAds%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09var%20alreadyOccupiedAdIndexes%20%3D%20indexesOfOtherBlocks.concat(providedIndexes)%3B%0D%0A%09%09var%20shortestAdIndex%20%3D%20this._getShortestAdIndex(allData%2C%20alreadyOccupiedAdIndexes%2C%20block)%3B%0D%0A%09%09if(shortestAdIndex%20%3E%20-1)%7B%0D%0A%09%09%09adHeight%20%3D%20allData%5BshortestAdIndex%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09providedIndexes.push(shortestAdIndex)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09u.log('shortestAdIndex'%2C%20shortestAdIndex%2C%20'orig%20resize'%2C%20adHeightSumm%20-%20blockHeight)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('shortened%20block'%2C%20blockName%2C%20blockHeight%2C%20adHeightSumm)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20providedData%20%3D%20%5B%5D%3B%0D%0A%09for(var%20j%3D0%3B%20j%3CprovidedIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09providedData.push(allData%5BprovidedIndexes%5Bj%5D%5D)%3B%0D%0A%09%7D%0D%0A%09u.log('providedData'%2C%20providedData%2C%20'providedIndexes'%2C%20providedIndexes%2C%20'adPadding'%2C%20adPadding)%3B%0D%0A%09block.data%20%3D%20providedData%3B%0D%0A%09block.dataIndexes%20%3D%20providedIndexes%3B%0D%0A%09block.adTopPadding%20%3D%20adPadding%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getDataIndexesOfOtherBlocks%20%3D%20function(block)%7B%0D%0A%09var%20indexes%20%3D%20%5B%5D%3B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09if(this.BLOCKS%5Bi%5D.origSel%20!%3D%20block.origSel)%7B%0D%0A%09%09%09var%20otherBlockIndexes%20%3D%20this.BLOCKS%5Bi%5D.dataIndexes%3B%0D%0A%09%09%09for(var%20j%3D0%3B%20j%3CotherBlockIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09%09%09if(indexes.indexOf(otherBlockIndexes%5Bj%5D)%20%3D%3D%20-1)%7B%0D%0A%09%09%09%09%09indexes.push(otherBlockIndexes%5Bj%5D)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%09return%20indexes%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getShortestAdIndex%20%3D%20function(allData%2C%20excludedIndexes%2C%20block)%7B%0D%0A%09var%20minHeight%20%3D%201000000%3B%0D%0A%09var%20minHeightAdIndex%20%3D%20-1%3B%0D%0A%0D%0A%09for(var%20i%3D0%3B%20i%3CallData.length%3B%20i%2B%2B)%7B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(!acceptableAd)%20continue%3B%0D%0A%09%09if(excludedIndexes.indexOf(i)%20%3D%3D%20-1)%7B%0D%0A%09%09%09var%20adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09if(adHeight%20%3C%20minHeight)%7B%0D%0A%09%09%09%09minHeight%20%3D%20adHeight%3B%0D%0A%09%09%09%09minHeightAdIndex%20%3D%20i%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%09return%20minHeightAdIndex%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.clearDynamicBlocksData%20%3D%20function()%7B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5Bi%5D%3B%0D%0A%09%09block.data%20%3D%20%5B%5D%3B%0D%0A%09%09block.dataIndexes%20%3D%20%5B%5D%3B%0D%0A%09%09block.adTopPadding%20%3D%200%3B%0D%0A%09%09block.oldHeight%20%3D%20false%3B%0D%0A%09%09block.newHeight%20%3D%20false%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._replicateBlock%20%3D%20function(donor%2C%20recipient)%7B%0D%0A%09recipient.data%20%3D%20donor.data%3B%0D%0A%09recipient.dataIndexes%20%3D%20donor.dataIndexes%3B%0D%0A%09recipient.adTopPadding%20%3D%20donor.adTopPadding%3B%0D%0A%09recipient.oldHeight%20%3D%20%24(recipient.origSel).height()%3B%0D%0A%09recipient.newHeight%20%3D%20donor.newHeight%20%7C%7C%20%24(donor.origSel).height()%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._compareRealAndCalcHeights%20%3D%20function(block)%7B%0D%0A%09var%20cover%20%3D%20%24(block.coverSel)%3B%0D%0A%09var%20orig%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09cover.find('li').each(function(i)%7B%0D%0A%09%09var%20el%20%3D%20%24(this)%3B%0D%0A%09%09var%20title%20%3D%20el.find('h3%20a').text()%3B%0D%0A%09%09var%20calcSize%20%3D%20block.data%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09u.log(title%2C%20el.height()%2C%20calcSize)%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09u.log('block%20sizes'%2C%20%7B%0D%0A%09%09origReal%3A%20orig.height()%2C%0D%0A%09%09coverReal%3A%20cover.height()%2C%0D%0A%09%09newHeight%3A%20block.newHeight%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMaxAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20maxOfAds%20%3D%20100%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mxt)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mxr)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mxb)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.max_top_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.max_right_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.max_bottom_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20maxOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMinAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20minOfAds%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mnt)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mnr)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mnb)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.min_top_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.min_right_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.min_bottom_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20minOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.getPadding%20%3D%20function(el)%20%7B%0D%0A%09var%20right%20%3D%20el.css('padding-right')%2C%0D%0A%09%09left%20%3D%20el.css('padding-left')%3B%0D%0A%09return%20%5B0%2C%20right%2C%200%2C%20left%5D.join('%20')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMargin%20%3D%20function(el)%20%7B%0D%0A%09var%20margin%20%3D%20el.css('margin')%3B%0D%0A%09if(margin%20%3D%3D%3D%20'')%20%7B%0D%0A%09%09var%20top%20%3D%20el.css('margin-top')%2C%0D%0A%09%09%09right%20%3D%20el.css('margin-right')%2C%0D%0A%09%09%09bott%20%3D%20el.css('margin-bottom')%2C%0D%0A%09%09%09left%20%3D%20el.css('margin-left')%3B%0D%0A%09%09return%20%5Btop%2C%20right%2C%20bott%2C%20left%5D.join('%20')%3B%0D%0A%09%7D%0D%0A%09return%20margin%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getEngineIdentityParam%20%3D%20function()%20%7B%0D%0A%09return%20'%26e%3D'%2Bthis.engineCode%2B'_s'%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocksCycle%20%3D%20function(block%2C%20blockName%2C%20showOrigAd)%7B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09this.origAdCheckerCounter%5BblockName%5D%20%3D%200%3B%0D%0A%09this.origAdChecker%5BblockName%5D%20%3D%20setInterval(function()%7B%0D%0A%09%09if(self.isAdExist(block))%20%7B%0D%0A%09%09%09if(showOrigAd)%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7Delse%20if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09if(self.isOfficialSiteBlock(block))%7B%0D%0A%0D%0A%09%09%09%09self.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09self.origAdCheckerCounter%5BblockName%5D%2B%2B%3B%0D%0A%09%7D%2C%20100)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocks%20%3D%20function(showOrigAd)%20%7B%0D%0A%09this.origAdCheckerCounter%20%3D%20%7B%7D%3B%0D%0A%09this.origAdChecker%20%3D%20%7B%7D%3B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.multipleTryToFindBlocksCycle(block%2C%20blockName%2C%20showOrigAd)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FOfficial%20site%20feature%0D%0ACORE.prototype.isAdAcceptable%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20!(%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09%09)%20%7C%7C%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isElFake(%24(block.origSel))%0D%0A%09%09%09%09)%0D%0A%09%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdAnyway%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20(%0D%0A%09%09%09(%0D%0A%09%09%09%09this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09)%0D%0A%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteBlock%20%3D%20function(block)%7B%0D%0A%09return%20(block.name%20%3D%3D%20'TOP')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteAd%20%3D%20function(ad)%7B%0D%0A%09return%20(ad.origin%20%3D%3D%20%22suggestion%22)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeFakeOrigAd%20%3D%20function(block)%20%7B%0D%0A%09var%20parentEl%20%3D%20%24(block.parentSel)%3B%0D%0A%09if(!parentEl.length)%20%7B%0D%0A%09%09u.log('makeFakeOrigAd%20!parentEl.length')%3B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%09var%20origId%20%3D%20block.origSel.replace('%23'%2C%20'')%3B%0D%0A%09var%20fakeEl%20%3D%20%24('%3Cdiv%20id%3D%22fakeAd%22%3E')%3B%0D%0A%09parentEl.prepend(fakeEl)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isElFake%20%3D%20function(el)%7B%0D%0A%09return%20(el.index('%23fakeAd')%20!%3D%20-1)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.SuggestionModule%20%20%3D%20function(instanceId)%20%7B%0D%0A%09this.data%20%3D%20%7B%7D%3B%0D%0A%09this.enable%20%3D%20true%3B%0D%0A%09this.addedBookmarks%20%3D%20%7B%7D%3B%0D%0A%0D%0A%09this.setConfig%20%3D%20function(data)%7B%0D%0A%09%09this.data%20%3D%20data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getConfig%20%3D%20function()%7B%0D%0A%09%09return%20this.data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getAdsForKeyword%20%3D%20function(keyword)%7B%0D%0A%09%09if(!this.data%20%7C%7C%20!this.data.s)%20return%20%5B%5D%3B%0D%0A%09%09var%20suggestions%20%3D%20this.findSuggestionsForKeyword(keyword%2C%2010)%3B%0D%0A%09%09return%20this.generateAdData(suggestions)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.findSuggestionsForKeyword%20%3D%20function(keyword%2C%20maxAmount)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Cthis.data.s.length%20%26%26%20result.length%20%3C%3D%20maxAmount%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20this.data.s%5Bi%5D%3B%0D%0A%09%09%09if(this.isSuggestionMatched(sugg%2C%20keyword))%7B%0D%0A%09%09%09%09result.push(sugg)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.isSuggestionMatched%20%3D%20function(sugg%2C%20keyword)%7B%0D%0A%09%09keyword%20%3D%20keyword.toLowerCase()%3B%0D%0A%09%09var%20k%20%3D%20keyword.indexOf(sugg.k.toLowerCase())%20%3D%3D%3D%200%3B%0D%0A%09%09var%20s%20%3D%20sugg.s.toLowerCase().indexOf(keyword)%20%3D%3D%3D%200%3B%0D%0A%09%09return%20k%20%26%26%20s%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.generateAdData%20%3D%20function(suggestions)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Csuggestions.length%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20suggestions%5Bi%5D%3B%0D%0A%09%09%09var%20diplayUrl%20%3D%20(sugg.v)%20%3F%20sugg.v%20%3A%20sugg.u.replace(%2F.*%5C%2F%5C%2F(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%241')%3B%20%2F%2Fwww.sales.target.com%0D%0A%09%09%09var%20title%20%3D%20(sugg.t)%20%3F%20sugg.t%20%3A%20this.capitaliseFirstLetter(sugg.u.replace(%2F.*%5C%2F%5C%2F(www%5C.)%3F(%5B%5Cw.%5D%2B)%5C.(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%242'))%3B%20%2F%2FSales.target%0D%0A%0D%0A%09%09%09result.push(%7B%0D%0A%09%09%09%09%22t%22%3A%20title%2C%0D%0A%09%09%09%09%22c%22%3A%20sugg.u%2C%0D%0A%09%09%09%09%22u%22%3A%20diplayUrl%20%2B%20'%20-%20'%20%2B%20this.data.t%2C%0D%0A%09%09%09%09%22d%22%3A%20sugg.d%2C%0D%0A%09%09%09%09%22r%22%3A%201%2C%0D%0A%09%09%09%09%22origin%22%3A%20%22suggestion%22%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.capitaliseFirstLetter%20%3D%20function(string)%7B%0D%0A%09%09return%20string.charAt(0).toUpperCase()%20%2B%20string.slice(1)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.coreStyles%20%20%3D%20function()%20%7B%0D%0A%09var%20a%20%3D%20'%3Cstyle%20id%3D%22adtrCoreStyle%22%3E%5C%0D%0A%09%3C%2Fstyle%3E'%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0AENGINE.prototype.BLOCKS%20%3D%20%7B%0A%09%09'TOP'%3A%20%7B%0A%09%09%09origSel%3A%20'%23ad1%2C%20.gB%3Aeq(0)'%2C%0A%09%09%09coverSel%3A%20'%23gB5_top_atmcover'%2C%0A%09%09%09name%3A%20'TOP'%2C%0A%09%09%09coverId%3A%20'gB5_top_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23ad1%20iframe%2C%20.gB%3Aeq(0)'%0A%09%09%7D%2C%0A%0A%09%09'BOTTOM'%3A%20%7B%0A%09%09%09origSel%3A%20'%23ad2%2C%20.gB%3Aeq(1)'%2C%0A%09%09%09coverSel%3A%20'%23gB5_bot_atmcover'%2C%0A%09%09%09name%3A%20'BOTTOM'%2C%0A%09%09%09coverId%3A%20'gB5_bot_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23ad2%20iframe%2C%20.gB%3Aeq(1)'%0A%09%09%7D%0A%0A%7D%3B%0A%0A%0AENGINE.prototype.INPUT_SEL%20%3D%20'%23sv'%3B%0AENGINE.prototype.SPELL_SEL%20%3D%20'%23spell%20a%20b'%3B%0AENGINE.prototype.MAIN_CONTAINER_SEL%20%3D%20'%23abc'%3B%0AENGINE.prototype.engineCode%20%3D%20'a'%3B%0A%0AENGINE.prototype.STYLES%20%3D%20%20function()%7B%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%7D%20%5C%0A%09.adtrCover%20ol%20%7B%20margin-left%3A%204px%3B%20%7D%20%5C%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%200px%3B%20list-style-type%3A%20none%20!important%3B%20margin-left%3A%200px%20!important%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%200px%3B%7D%20%5C%0A%09%23tt21%20.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A16px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%2336C%3B%20text-decoration%3Aunderline%3B%20font-weight%3A%20normal%3B%7D%20%5C%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23999%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%20font-style%3A%20inherit%3B%7D%20%5C%0A%20%20%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20%5C%0A%20%20%20%20visibility%3A%20hidden%3B%20%5C%0A%20%20%20%20overflow%3A%20hidden%3B%20%5C%0A%20%20%7D%20%5C%0A%20%20.adtrCover-closeBtn%7B%20%5C%0A%20%20%20%20cursor%3A%20pointer%3B%20%5C%0A%20%20%20%20padding%3A%200%202px%202px%202px%3B%20%5C%0A%20%20%20%20font-size%3A%2012px%3B%20%5C%0A%20%20%20%20text-align%3A%20center%3B%20%5C%0A%20%20%20%20position%3A%20absolute%3B%20%5C%0A%20%20%20%20height%3A%2012px%3B%20%5C%0A%20%20%20%20width%3A%2033px%3B%20%5C%0A%20%20%20%20border%3A%201px%20solid%20lightblue%3B%20%5C%0A%20%20%20%20background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0A%20%20%20%20display%3A%20inline-block%3B%20%5C%0A%20%20%20%20right%3A%201px%3B%20%5C%0A%20%20%20%20top%3A%203px%3B%20%5C%0A%20%20%7D%5C%0A%20%20.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0A%20%20.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%20top%3A%20-99999px%3B%7D%20%5C%0A%20%20.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0A%20%20%3C%2Fstyle%3E%22%3B%0A%20%20return%20a%3B%0A%7D%3B%0A%0AENGINE.prototype.getCurrentKeyword%20%3D%20function()%7B%0A%09var%20keyword%20%3D%20''%3B%0A%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0A%09var%20url%20%3D%20document.location.href%3B%0A%09var%20match%20%3D%20url.match(%2F%5B%5C%23%7C%5C%3F%7C%5C%26%5Dq%3D(%5B%5E%26%5D*)%2F)%3B%0A%0A%09u.log(match)%3B%0A%09if(%2F%5C%2Fr%5C.htm%2F.test(url)%20%26%26%20match%20%26%26%20match.length%20%3E%200)%7B%0A%09%09%2F%2Fif%20it%20was%20related%20link%20used%0A%09%09keyword%20%3D%20match%5B1%5D%3B%0A%09%7D%20else%20%7B%0A%09%09%2F%2Fif%20normal%20search%20made%0A%09%09if(spell.length)%7B%0A%09%09%09keyword%20%3D%20spell.text()%3B%0A%09%09%7D%20else%20if(input.length)%7B%0A%09%09%09keyword%20%3D%20input.val()%3B%0A%09%09%7D%0A%09%7D%0A%09return%20keyword%3B%0A%7D%3B%0A%0AENGINE.prototype.isAdExist%20%3D%20function(block)%20%7B%0A%09var%20origIFrame%20%3D%20%24(block.adSel)%3B%0A%09return%20origIFrame.length%20%26%26%20(origIFrame.height()%20%3E%200)%3B%0A%0A%7D%3B%0A%0AENGINE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0A%09if(!el.length)%20return%3B%0A%09el.removeClass('hideOrig')%3B%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0A%7D%3B%0D%0A%0D%0A%0D%0AGoogleChrome.prototype.ff%20%3D%20function()%7B%0D%0A%09console.log('oogleChrome.prototype.ff')%3B%0D%0A%7D%3B%0D%0AFirefox.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09%24('.adtr').remove()%3B%0D%0A%7D%3B%0D%0Afunction%20IE%20()%20%7B%7D%0D%0Afunction%20Browser%20(affiliateID%2C%20instanceID)%20%7B%0A%09var%20browser%3B%0A%09%2F%2Fif%20called%20with%20a%20%22new%22%20keyword%0A%09if%20(this.constructor%20%3D%3D%20Browser)%20%7B%0A%09%09%2F%2Fpicking%20specific%20browser%0A%09%09browser%20%3D%20this.pickBrowser()%3B%0A%0A%09%09browser.affiliateID%20%3D%20affiliateID%3B%0A%09%09browser.instanceID%20%3D%20instanceID%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error(%22Browser%20is%20a%20constructor%20function%22)%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%0A%0ABrowser.prototype.pickBrowser%20%3D%20function()%20%7B%0A%09%2F%2Fchecking%20browser%0A%09var%20ischrome%20%3D%20typeof(chrome)%20%3D%3D%20'object'%2C%0A%09%09firefox%20%3D%20typeof(chrome)%20%3D%3D%20'string'%2C%0A%09%09ie%20%3D%20navigator.userAgent.indexOf(%22Trident%22)%20!%3D%3D%20-1%2C%0A%09%09browser%20%3D%20null%3B%0A%0A%09if%20(ischrome)%20%7B%0A%09%09browser%20%3D%20new%20GoogleChrome()%3B%0A%09%7D%20else%20if%20(firefox)%20%7B%0A%09%09browser%20%3D%20new%20Firefox()%3B%0A%09%7D%20else%20if%20(ie)%20%7B%0A%09%09browser%20%3D%20new%20IE()%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error('unknown%20browser')%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%3B%0A%0A%0A%0D%0A%2F%2Fsimply%20extending%20specific%20browser%20classes%20with%20basic%20class%2C%20which%20holds%20default%20browser%20methods%0A%0A%2F%2Freturns%20browser%20object%20(one%20of%20Chrome%2C%20FF%2C%20IE)%0A%0Aif(typeof(pc)%20!%3D%20'undefined')%7B%0A%09var%20affiliateID%20%3D%20pc.affiliateID%3B%0A%09var%20instanceID%20%3D%20pc.instanceId%3B%0A%09var%20engineParams%20%3D%20pc.engineParams%3B%0A%7D%0A%0Aif(%20typeof(affiliateID)%20!%3D%20'undefined'%20)%7B%0A%09%2F%2FaffiliateID%20predefined%20by%20extension%0A%09var%20browser%20%3D%20new%20Browser(affiliateID%2C%20instanceID)%3B%0A%09browser.init(instanceID%2C%20affiliateID%2C%20engineParams)%3B%0A%09Util.log('started%20browser'%2C%20affiliateID%2C%20instanceID)%3B%0A%7D%20else%20%7B%0A%09var%20browser%20%3D%20new%20Browser()%3B%0A%09var%20Engine%20%3D%20browser%3B%0A%09Util.log('prepare%20Engine')%3B%0A%7D%0A%0A%0A%0A\""
FF - prefs.js..extensions.trusted-ads.serp_ask: "\"%2F*!%20serp-ask%20-%20v0.1.8%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09debug%3A%20false%2C%0A%09extend%3A%20function(Child%2C%20Parent)%20%7B%0A%09%09var%20F%20%3D%20function()%20%7B%20%7D%3B%0A%09%09F.prototype%20%3D%20Parent.prototype%3B%0A%09%09Child.prototype%20%3D%20new%20F()%3B%0A%09%09Child.prototype.constructor%20%3D%20Child%3B%0A%09%09Child._super%20%3D%20Parent.prototype%3B%0A%09%7D%2C%0A%09log%3A%20function()%20%7B%0A%09%09if%20(Util.debug)%20%7B%0A%09%09%09var%20args%20%3D%20Array.prototype.slice.call(arguments)%3B%0A%09%09%09console.log.apply(console%2C%20args)%3B%0A%09%09%7D%0A%09%7D%0A%7D%3B%0A%2F%2Fshort%20alias%0Au%20%3D%20Util%3B%0A%0Afunction%20ENGINE%20()%20%7B%7D%0Afunction%20GoogleChrome%20()%20%7B%7D%0Afunction%20CORE()%20%7B%7D%0Afunction%20Firefox%20()%20%7B%7D%0Afunction%20IE%20()%20%7B%7D%0A%0AUtil.extend(ENGINE%2C%20CORE)%3B%0AUtil.extend(GoogleChrome%2C%20ENGINE)%3B%0AUtil.extend(Firefox%2C%20ENGINE)%3B%0AUtil.extend(IE%2C%20ENGINE)%3B%0D%0ACORE.prototype.ADS_HOST%20%3D%20document.location.protocol%2B%22%2F%2Fsearch.adtrustmedia.com%2Fsearch_safecontent.php%22%3B%0D%0A%0D%0ACORE.prototype.ALL_BLOCKS_SELECTOR%20%3D%20function()%7B%0D%0A%09return%20%7B%0D%0A%09%09orig%3A%20this.BLOCKS.TOP.origSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.origSel*%2F%2C%0D%0A%09%09cover%3A%20this.BLOCKS.TOP.coverSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.coverSel*%2F%0D%0A%09%7D%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.STYLES%20%3D%20%20function()%20%7B%0D%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0D%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20%7B%20%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%2304c%3B%20text-decoration%3Aunderline%3B%20font-size%3A17px%3B%7D%20%5C%0D%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23388222%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%7D%20%5C%0D%0A%09%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20visibility%3A%20hidden%3B%20overflow%3A%20hidden%3B%7D%20%5C%0D%0A%09.adtrCover-closeBtn%7B%20%5C%0D%0A%09%09cursor%3A%20pointer%3B%20%5C%0D%0A%09%09padding%3A%200%202px%202px%202px%3B%20%5C%0D%0A%09%09font-size%3A%2012px%3B%20%5C%0D%0A%09%09text-align%3A%20center%3B%20%5C%0D%0A%09%09position%3A%20absolute%3B%20%5C%0D%0A%09%09height%3A%2012px%3B%20%5C%0D%0A%09%09width%3A%2033px%3B%20%5C%0D%0A%09%09border%3A%201px%20solid%20lightblue%3B%20%5C%0D%0A%09%09background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0D%0A%09%09display%3A%20inline-block%3B%20%5C%0D%0A%09%09right%3A%201px%3B%20%5C%0D%0A%09%09top%3A%203px%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.adtrCover%20.closeAd%7B%20%5C%0D%0A%09%09text-decoration%3A%20underline%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0D%0A%09.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0D%0A%09.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0D%0A%09%3C%2Fstyle%3E%22%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.MENU_BTN_SPACE%20%3D%208%3B%0D%0ACORE.prototype.MIN_PADDING%20%3D%208%3B%0D%0A%0D%0ACORE.prototype._ads%20%3D%20%5B%5D%3B%0D%0ACORE.prototype.instanceId%20%3D%20''%3B%0D%0ACORE.prototype.affilateID%20%3D%20''%3B%0D%0ACORE.prototype.data%20%3D%20null%3B%0D%0ACORE.prototype.keyword%20%3D%20''%3B%0D%0ACORE.prototype.engineParams%20%3D%20%7B%7D%3B%0D%0ACORE.prototype.engineCode%20%3D%20''%3B%0D%0A%0D%0ACORE.prototype.start%20%3D%20function()%7B%7D%3B%0D%0A%0D%0ACORE.prototype.init%20%3D%20function(instanceId%2C%20affilateID%2C%20engineParams)%20%7B%0D%0A%09this.data%20%3D%20typeof(engineData)%20!%3D%20%22undefined%22%20%3F%20engineData%20%3A%20null%3B%0D%0A%09this.keyword%20%3D%20typeof(engineKeyword)%20!%3D%20%22undefined%22%20%3F%20engineKeyword%20%3A%20''%3B%0D%0A%0D%0A%09if(engineParams.delivPoint)%20%7B%20this.ADS_HOST%20%3D%20engineParams.delivPoint%3B%20%7D%0D%0A%0D%0A%09%24(%22head%22).append(this.coreStyles())%3B%0D%0A%09%24(%22head%22).append(this.STYLES())%3B%0D%0A%09this.instanceId%20%3D%20instanceId%3B%0D%0A%09this.affilateID%20%3D%20affilateID%3B%0D%0A%09this.engineParams%20%3D%20engineParams%3B%0D%0A%0D%0A%09this.suggModule%20%3D%20new%20this.SuggestionModule()%3B%0D%0A%09if(engineParams.suggConfig)%20%7B%0D%0A%09%09this.suggModule.setConfig(engineParams.suggConfig)%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09var%20currentKeyword%20%3D%20this.getCurrentKeyword().toLowerCase()%3B%0D%0A%0D%0A%09if(this.keyword)%7B%0D%0A%09%09this.keyword%20%3D%20decodeURIComponent(this.keyword)%3B%0D%0A%09%09this.keyword%20%3D%20this.keyword.replace(%2F%5C%2B%2Fg%2C%20'%20')%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09u.log('FROM%20PLUGIN%3A'%2C%20%7B'engineData'%3A%20this.data%2C%20'engineKeyword'%3A%20this.keyword%2C%20'currentKeyword'%3A%20currentKeyword%2C%20'engineParams'%3A%20engineParams%7D)%3B%0D%0A%0D%0A%09if%20(%20this.data%20%26%26%20(this.data%20!%3D%20'noPreload')%20%26%26%20(currentKeyword%20%3D%3D%20this.keyword)%20)%7B%0D%0A%09%09var%20suggAdData%20%3D%20this.suggModule.getAdsForKeyword(this.keyword)%3B%0D%0A%0D%0A%09%09this.data%20%3D%20suggAdData.concat(this.data)%3B%0D%0A%09%09u.log('suggAdData'%2C%20suggAdData%2C%20this.data)%3B%0D%0A%09%09if(%20this.data.length%20)%7B%0D%0A%09%09%09this.multipleTryToFindBlocks()%3B%20%2F%2Fchanged%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%20else%20%7B%0D%0A%09%09if(currentKeyword%20!%3D%20%22undefined%22)%20%7B%0D%0A%09%09%09this.keyword%20%3D%20currentKeyword%3B%0D%0A%09%09%09var%20requestUrl%20%3D%20this.getAdRequestUrl(currentKeyword)%3B%0D%0A%09%09%09this.sendAdRequest(requestUrl)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._domain_without_www%20%3D%20function(url)%20%7B%0D%0A%09var%20clean%20%3D%20url.replace(%2F%5Ewww%5C.%2F%2C'')%3B%0D%0A%09return%20clean%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getAdRequestUrl%20%3D%20function(keyword)%20%7B%0D%0A%09var%20domain%20%3D%20this._domain_without_www(document.location.host)%3B%0D%0A%09var%20requestUrl%20%3D%20this.ADS_HOST%20%2B%20%22%3F%22%20%2B%0D%0A%09%09%22adtype%3Dtext%22%20%2B%0D%0A%09%09%22%26method%3Djs%22%20%2B%0D%0A%09%09%22%26advert%3D1%22%20%2B%0D%0A%09%09%22%26referer%3D%22%20%2B%20encodeURIComponent(document.location.protocol%20%2B%22%2F%2F%22%2B%20document.location.host%2B%22%2F%22)%20%2B%0D%0A%09%09%22%26ta_affiliateid%3D%22%20%2B%20this.affilateID%20%2B%0D%0A%09%09%22%26ta_insid%3D%22%20%2B%20this.instanceId%20%2B%0D%0A%09%09%22%26kw%3D%22%20%2B%20encodeURIComponent(keyword)%20%2B%0D%0A%09%09this.getEngineIdentityParam()%3B%0D%0A%09return%20requestUrl%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getCurrentKeyword%20%3D%20function()%7B%0D%0A%09var%20keyword%20%3D%20''%3B%0D%0A%0D%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0D%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0D%0A%0D%0A%09if(spell.length)%7B%0D%0A%09%09keyword%20%3D%20spell.text()%3B%0D%0A%09%7D%20else%20if(input.length)%7B%0D%0A%09%09keyword%20%3D%20input.val()%3B%0D%0A%09%7D%0D%0A%09return%20keyword%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FTRY%20TO%20GET%20ADS%20BY%20NEW%20KEYWORD%0D%0A%2F%2F_requestInProcess%3A%20false%2C%0D%0ACORE.prototype.sendAdRequest%20%3D%20function(requestUrl)%20%7B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%0D%0A%09u.log('SEND%20REQUEST'%2C%20%5Bthis.keyword%2C%20requestUrl%5D)%3B%0D%0A%0D%0A%09%24.ajax(%7B%0D%0A%09%09url%3A%20requestUrl%2C%0D%0A%09%09dataType%3A%20'json'%2C%0D%0A%09%09error%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function()%20%7B%0D%0A%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%2C%0D%0A%09%09success%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function(data)%20%7B%0D%0A%09%09%09%09var%20suggAdData%20%3D%20scope.suggModule.getAdsForKeyword(scope.keyword)%3B%0D%0A%09%09%09%09data%20%3D%20suggAdData.concat(data)%3B%0D%0A%0D%0A%09%09%09%09if(!data.length)%20%7B%0D%0A%09%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%09%09return%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09u.log('REQUEST%20SUCCESS'%2C%20%5Bscope.keyword%2C%20scope.suggModule%2C%20data%5D)%3B%0D%0A%09%09%09%09scope.data%20%3D%20data%3B%0D%0A%09%09%09%09scope.clearDynamicBlocksData()%3B%0D%0A%09%09%09%09scope.makeCovers()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showAllOriginalAd%20%3D%20function()%20%7B%0D%0A%09u.log('showAllOriginalAd()')%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B').show()%3B%0D%0A%09if(block.adSel)%7B%0D%0A%09%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible!important%3B')%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FADS%20REPLACEMENT%20PROCESS%0D%0ACORE.prototype.makeCovers%20%3D%20function()%20%7B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%0D%0A%09%09if(!this.isAdExist(block))%20%7B%0D%0A%09%09%09if(this.isOfficialSiteBlock(block))%7B%0D%0A%09%09%09%09this.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%09continue%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09%2F%2FORIGINAL%20SELECTOR%20IS%20A%20DOM%20ELEMENT%0D%0A%09%09this._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09this.makeCover(block%2C%20blockName)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdExist%20%3D%20function(block)%20%7B%0D%0A%09var%20origSel%20%3D%20%24(block.origSel)%3B%0D%0A%09return%20origSel.length%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FPREPARE%20AND%20RENDER%20REPLACEMENT%20COVER%20(old%3A%20_prepareReplacement)%0D%0ACORE.prototype.makeCover%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('MAKE%20COVER'%2C%20blockName%2C%20%7BblockData%3A%20JSON.stringify(block.data)%7D)%3B%0D%0A%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(el.index('%23fakeAd')%20!%3D%20-1)%7B%0D%0A%09%09el%20%3D%20%24('%23fakeAd')%3B%0D%0A%09%7D%0D%0A%09var%20data%20%3D%20block.data%3B%0D%0A%0D%0A%09if%20(data.length)%20%7B%0D%0A%0D%0A%09%09var%20width%20%3D%20el.width()%3B%0D%0A%09%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%09%09%2F%2FREMOVE%20PREV%20BLOCK%0D%0A%09%09%24(block.coverSel).remove()%3B%0D%0A%0D%0A%09%09%2F%2FCREATE%20COVER%0D%0A%09%09var%20coverHeight%20%3D%20el.height()%3B%0D%0A%09%09if(block.newHeight)%7B%0D%0A%09%09%09coverHeight%20%3D%20block.newHeight%3B%0D%0A%09%09%09el.height(coverHeight)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09var%20cover%20%3D%20%24('%3Cdiv%20id%3D%22'%2B%20block.coverId%20%2B'%22%20class%3D%22adtrCover%22%20style%3D%22height%3A'%2B%20coverHeight%20%2B'px%3B%22%3E'%2B%20this._fillWithAds(block%2C%20blockName)%20%2B'%3C%2Fdiv%3E').css(%7B%0D%0A%09%09%09margin%3A%20this.getMargin(el)%2C%20padding%3A%20this.getPadding(el)%2C%0D%0A%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%7D)%3B%0D%0A%09%09cover.insertBefore(el)%3B%0D%0A%09%09el.addClass('hideOrig')%3B%0D%0A%09%09this.makeCoverMenu(block%2C%20cover%2C%20blockName)%3B%0D%0A%09%09this._compareRealAndCalcHeights(block)%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('showed%20without%20ad'%2C%20blockName)%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeCoverMenu%20%3D%20function(block%2C%20cover%2C%20blockName)%20%7B%0D%0A%20%20%20%20%20%20var%20clas%20%3D%20'atmAd'%3B%0D%0A%20%20%20%20%20%20var%20d%3B%0D%0A%0D%0A%20%20%20%20%20%20if%20(blockName%20%3D%3D%20'RIGHT')%20%7B%0D%0A%20%20%20%20%20%20%20%20clas%20%3D%20'atmAd-left'%3B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%3E%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%20else%20%7B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%3Cimg%20src%3D%22'%2Bdocument.location.protocol%2B'%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%20%2F%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FTABLE%0D%0A%20%20%20%20%20%20var%20t%20%3D%20%24(%22%3Ctable%20style%3D'visibility%3Ainherit%3B%20border-spacing%3A%201px%3B%20margin%3A%200px%3B%20border-collapse%3A%20collapse%3B%20%20background-color%3Agrey%3B%20z-index%3A100%3B'%20border%3D'1'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20style%3D'background-color%3Awhite%3B%20height%3A%2014px%3B%20padding%3A0px%203px%3B%20line-height%3A14px%3B'%3E%3Ca%20style%3D'width%3A58px%3B%20margin%3A0px%3B%20display%3Ablock%3B%20color%3Ablack%3B%20text-decoration%3Anone%3B%20text-align%3Aleft%3B%20font-weight%3Anormal%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20background-color%3Awhite%3B%20font-size%3A9px%3B'%20href%3D'https%3A%2F%2Fadtrustmedia.com%2Fwhyad.html'%20target%3D'_blank'%3EWhy%20this%20ad%3F%3C%2Fa%3E%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20class%3D'closeAd'%20style%3D'white-space%3Anowrap%3B%20color%3Ablack%3B%20background-color%3Awhite%3B%20cursor%3Apointer%3B%20padding%3A0px%203px%3B%20%20height%3A%2014px%3B%20line-height%3A14px%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A9px%3B'%3EClose%20this%20ad%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftable%3E%22)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20d.find('a.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20t.find('.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%20%20%20%20%20%20d.append(t)%3B%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FCLICK%20ON%20ATM%20AD%0D%0A%20%20%20%20%20%20d.find('.toggleTable').click(function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%24(this).next().toggle()%3B%0D%0A%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20d.appendTo(cover)%3B%0D%0A%0D%0A%20%20%20%20%20%20var%20self%20%3D%20this%3B%0D%0A%20%20%20%20%20%20function%20removeAd()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20cover.remove()%3B%0D%0A%20%20%20%20%20%20%20%20%20%20self.showOriginalAdForBlock(block)%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype._fillWithAds%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('FILL%20COVER'%2C%20blockName%2C%20%5Bblock.data%5D)%3B%0D%0A%09var%20block_content%20%3D%20''%2C%0D%0A%09%09data%20%3D%20block.data%3B%0D%0A%0D%0A%09block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09var%20adTopPadding%20%3D%20block.adTopPadding%3B%0D%0A%09%09if(i%3D%3D%3D0)%20%7B%0D%0A%09%09%09adTopPadding%20%3D%20adTopPadding%2F2%3B%0D%0A%09%09%09if(blockName%20%3D%3D%20'RIGHT')%20adTopPadding%20%2B%3D%20this.MENU_BTN_SPACE%3B%0D%0A%09%09%7D%0D%0A%09%09var%20offsiteClass%20%3D%20(data%5Bi%5D.origin%20%3D%3D%20%22suggestion%22)%20%3F%20'class%3D%22official-site%22'%20%3A%20%22%22%3B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20style%3D'padding-top%3A%20%22%2BadTopPadding%2B%22px'%22%20%2B%20offsiteClass%20%2B%20%22%3E%22%2B%0D%0A%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09return%20block_content%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._calcAdHeightForBlock%20%3D%20function(block)%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(!el.length)%20%7B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20width%20%3D%20el.width()%3B%0D%0A%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%0D%0A%09var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%20position%3Aabsolute%20!important%3B%20top%3A%20-10000px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%2F%2F%20var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%09%09%09).css(%7B%0D%0A%09%09%09%09%09margin%3A%20this.getMargin(el)%2C%0D%0A%09%09%09%09%09padding%3A%20this.getPadding(el)%20%2C%0D%0A%09%09%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%09%09%7D)%3B%0D%0A%0D%0A%0D%0A%09var%20block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%09var%20data%20%3D%20this.data%3B%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20data-index%3D'%22%2Bi%2B%22'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09div.html(block_content)%3B%0D%0A%09%24(this.MAIN_CONTAINER_SEL).append(div)%3B%0D%0A%0D%0A%09u.log('MAIN_CONTAINER_SEL'%2C%20%24(this.MAIN_CONTAINER_SEL).length)%3B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%09div.find('li').each(function(i%2C%20li)%7B%0D%0A%09%09li%20%3D%20%24(li)%3B%0D%0A%09%09var%20index%20%3D%20li.data('index')%3B%0D%0A%09%09if(!scope.data%5Bindex%5D.h)%20scope.data%5Bindex%5D.h%20%3D%20%7B%7D%3B%0D%0A%09%09scope.data%5Bindex%5D.h%5Bblock.origSel%5D%20%3D%20li.height()%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09%2F%2F%20div.remove()%3B%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._provideAdDataForBlock%20%3D%20function(block%2C%20blockName)%7B%0D%0A%09u.log('DATA%20FOR%20BLOCK'%2C%20blockName)%3B%0D%0A%0D%0A%09var%20addingLog%20%3D%20%5B%5D%3B%0D%0A%0D%0A%09var%20MAX_ADDITIONAL_PADDING%20%3D%2015%3B%0D%0A%0D%0A%09var%20providedIndexes%20%3D%20%5B%5D%3B%0D%0A%09var%20allData%20%3D%20this.data%3B%0D%0A%0D%0A%09var%20origEl%20%3D%20%24(block.origSel)%3B%0D%0A%09var%20blockHeight%20%3D%20origEl.height()%3B%0D%0A%09var%20adPadding%20%3D%20this.MIN_PADDING%3B%0D%0A%09var%20adHeightSumm%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'RIGHT')%20adHeightSumm%20%3D%20this.MENU_BTN_SPACE%3B%0D%0A%0D%0A%09this._calcAdHeightForBlock(block)%3B%0D%0A%0D%0A%09var%20indexesOfOtherBlocks%20%3D%20this._getDataIndexesOfOtherBlocks(block)%3B%0D%0A%0D%0A%09var%20allDataWasChecked%20%3D%20false%3B%0D%0A%09var%20i%20%3D%200%3B%0D%0A%09var%20numOfCheckedIndexes%20%3D%200%3B%0D%0A%0D%0A%09var%20maxOfAds%20%3D%20this.getMaxAdsForBlock(blockName)%3B%0D%0A%09var%20minOfAds%20%3D%20this.getMinAdsForBlock(blockName)%3B%0D%0A%0D%0A%09u.log('indexesOfOtherBlocks'%2C%20indexesOfOtherBlocks)%3B%0D%0A%09var%20numOfFreeIndexes%20%3D%20allData.length%20-%20indexesOfOtherBlocks.length%3B%0D%0A%09var%20ttt%20%3D%200%3B%0D%0A%09var%20adHeight%3B%0D%0A%09while(i%20%3C%20allData.length%20%26%26%20ttt%3C30%20%26%26%20providedIndexes.length%3CmaxOfAds)%7B%0D%0A%0D%0A%09%09var%20indexIsFree%20%3D%20(indexesOfOtherBlocks.indexOf(i)%20%3D%3D%20-1)%3B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09var%20anywayAd%20%3D%20this.isAdAnyway(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(indexIsFree%20%26%26%20acceptableAd)%7B%0D%0A%0D%0A%09%09%09adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%0D%0A%09%09%09%2F%2Fif%20we%20can%20fit%20ad%20to%20block%20then%20add%20it%0D%0A%09%09%09addingLog.push(%7B%0D%0A%09%09%09%09i%3A%20i%2C%0D%0A%09%09%09%09t%3A%20allData%5Bi%5D.t%2C%0D%0A%09%09%09%09free%3A%20(blockHeight-adHeightSumm)%2C%0D%0A%09%09%09%09adPad%3A%20(adHeight%2Bthis.MIN_PADDING)%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%09var%20enoughSpace%20%3D%20(blockHeight%20%3E%3D%20adHeightSumm%20%2B%20adHeight%20%2B%20adPadding)%3B%0D%0A%09%09%09if(enoughSpace%20%7C%7C%20providedIndexes.length%20%3C%20minOfAds%20%7C%7C%20anywayAd)%7B%0D%0A%09%09%09%09if(!enoughSpace)%7B%0D%0A%09%09%09%09%09u.log('add%20more%20ads%20couse%20min%20ads%20required%20in%20block'%2C%20blockName%2C%20providedIndexes.length)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09%09providedIndexes.push(i)%3B%0D%0A%09%09%09%7D%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09ttt%2B%2B%3B%0D%0A%09%09i%2B%2B%3B%0D%0A%09%7D%0D%0A%09u.log('addingLog'%2C%20addingLog)%3B%0D%0A%0D%0A%09var%20freeSpace%20%3D%20blockHeight%20-%20adHeightSumm%3B%0D%0A%09var%20additionalPadding%20%3D%20freeSpace%20%2F%20(providedIndexes.length)%3B%0D%0A%0D%0A%09u.log('blockHeight'%2C%20blockHeight%2C%20'adHeightSumm'%2C%20adHeightSumm%2C%20'freeSpace'%2C%20freeSpace)%3B%0D%0A%0D%0A%09u.log('additionalPadding'%2C%20additionalPadding%2C%20'acceptable'%2C%20(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200))%3B%0D%0A%09if(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09adPadding%20%2B%3D%20additionalPadding%3B%0D%0A%09%7D%20else%20if(providedIndexes.length%20%3C%20maxOfAds%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09var%20alreadyOccupiedAdIndexes%20%3D%20indexesOfOtherBlocks.concat(providedIndexes)%3B%0D%0A%09%09var%20shortestAdIndex%20%3D%20this._getShortestAdIndex(allData%2C%20alreadyOccupiedAdIndexes%2C%20block)%3B%0D%0A%09%09if(shortestAdIndex%20%3E%20-1)%7B%0D%0A%09%09%09adHeight%20%3D%20allData%5BshortestAdIndex%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09providedIndexes.push(shortestAdIndex)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09u.log('shortestAdIndex'%2C%20shortestAdIndex%2C%20'orig%20resize'%2C%20adHeightSumm%20-%20blockHeight)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('shortened%20block'%2C%20blockName%2C%20blockHeight%2C%20adHeightSumm)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20providedData%20%3D%20%5B%5D%3B%0D%0A%09for(var%20j%3D0%3B%20j%3CprovidedIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09providedData.push(allData%5BprovidedIndexes%5Bj%5D%5D)%3B%0D%0A%09%7D%0D%0A%09u.log('providedData'%2C%20providedData%2C%20'providedIndexes'%2C%20providedIndexes%2C%20'adPadding'%2C%20adPadding)%3B%0D%0A%09block.data%20%3D%20providedData%3B%0D%0A%09block.dataIndexes%20%3D%20providedIndexes%3B%0D%0A%09block.adTopPadding%20%3D%20adPadding%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getDataIndexesOfOtherBlocks%20%3D%20function(block)%7B%0D%0A%09var%20indexes%20%3D%20%5B%5D%3B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09if(this.BLOCKS%5Bi%5D.origSel%20!%3D%20block.origSel)%7B%0D%0A%09%09%09var%20otherBlockIndexes%20%3D%20this.BLOCKS%5Bi%5D.dataIndexes%3B%0D%0A%09%09%09for(var%20j%3D0%3B%20j%3CotherBlockIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09%09%09if(indexes.indexOf(otherBlockIndexes%5Bj%5D)%20%3D%3D%20-1)%7B%0D%0A%09%09%09%09%09indexes.push(

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#4 Příspěvek od Lefiks »

otherBlockIndexes%5Bj%5D)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%09return%20indexes%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getShortestAdIndex%20%3D%20function(allData%2C%20excludedIndexes%2C%20block)%7B%0D%0A%09var%20minHeight%20%3D%201000000%3B%0D%0A%09var%20minHeightAdIndex%20%3D%20-1%3B%0D%0A%0D%0A%09for(var%20i%3D0%3B%20i%3CallData.length%3B%20i%2B%2B)%7B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(!acceptableAd)%20continue%3B%0D%0A%09%09if(excludedIndexes.indexOf(i)%20%3D%3D%20-1)%7B%0D%0A%09%09%09var%20adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09if(adHeight%20%3C%20minHeight)%7B%0D%0A%09%09%09%09minHeight%20%3D%20adHeight%3B%0D%0A%09%09%09%09minHeightAdIndex%20%3D%20i%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%09return%20minHeightAdIndex%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.clearDynamicBlocksData%20%3D%20function()%7B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5Bi%5D%3B%0D%0A%09%09block.data%20%3D%20%5B%5D%3B%0D%0A%09%09block.dataIndexes%20%3D%20%5B%5D%3B%0D%0A%09%09block.adTopPadding%20%3D%200%3B%0D%0A%09%09block.oldHeight%20%3D%20false%3B%0D%0A%09%09block.newHeight%20%3D%20false%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._replicateBlock%20%3D%20function(donor%2C%20recipient)%7B%0D%0A%09recipient.data%20%3D%20donor.data%3B%0D%0A%09recipient.dataIndexes%20%3D%20donor.dataIndexes%3B%0D%0A%09recipient.adTopPadding%20%3D%20donor.adTopPadding%3B%0D%0A%09recipient.oldHeight%20%3D%20%24(recipient.origSel).height()%3B%0D%0A%09recipient.newHeight%20%3D%20donor.newHeight%20%7C%7C%20%24(donor.origSel).height()%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._compareRealAndCalcHeights%20%3D%20function(block)%7B%0D%0A%09var%20cover%20%3D%20%24(block.coverSel)%3B%0D%0A%09var%20orig%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09cover.find('li').each(function(i)%7B%0D%0A%09%09var%20el%20%3D%20%24(this)%3B%0D%0A%09%09var%20title%20%3D%20el.find('h3%20a').text()%3B%0D%0A%09%09var%20calcSize%20%3D%20block.data%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09u.log(title%2C%20el.height()%2C%20calcSize)%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09u.log('block%20sizes'%2C%20%7B%0D%0A%09%09origReal%3A%20orig.height()%2C%0D%0A%09%09coverReal%3A%20cover.height()%2C%0D%0A%09%09newHeight%3A%20block.newHeight%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMaxAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20maxOfAds%20%3D%20100%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mxt)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mxr)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mxb)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.max_top_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.max_right_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.max_bottom_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20maxOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMinAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20minOfAds%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mnt)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mnr)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mnb)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.min_top_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.min_right_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.min_bottom_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20minOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.getPadding%20%3D%20function(el)%20%7B%0D%0A%09var%20right%20%3D%20el.css('padding-right')%2C%0D%0A%09%09left%20%3D%20el.css('padding-left')%3B%0D%0A%09return%20%5B0%2C%20right%2C%200%2C%20left%5D.join('%20')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMargin%20%3D%20function(el)%20%7B%0D%0A%09var%20margin%20%3D%20el.css('margin')%3B%0D%0A%09if(margin%20%3D%3D%3D%20'')%20%7B%0D%0A%09%09var%20top%20%3D%20el.css('margin-top')%2C%0D%0A%09%09%09right%20%3D%20el.css('margin-right')%2C%0D%0A%09%09%09bott%20%3D%20el.css('margin-bottom')%2C%0D%0A%09%09%09left%20%3D%20el.css('margin-left')%3B%0D%0A%09%09return%20%5Btop%2C%20right%2C%20bott%2C%20left%5D.join('%20')%3B%0D%0A%09%7D%0D%0A%09return%20margin%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getEngineIdentityParam%20%3D%20function()%20%7B%0D%0A%09return%20'%26e%3D'%2Bthis.engineCode%2B'_s'%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocksCycle%20%3D%20function(block%2C%20blockName%2C%20showOrigAd)%7B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09this.origAdCheckerCounter%5BblockName%5D%20%3D%200%3B%0D%0A%09this.origAdChecker%5BblockName%5D%20%3D%20setInterval(function()%7B%0D%0A%09%09if(self.isAdExist(block))%20%7B%0D%0A%09%09%09if(showOrigAd)%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7Delse%20if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09if(self.isOfficialSiteBlock(block))%7B%0D%0A%0D%0A%09%09%09%09self.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09self.origAdCheckerCounter%5BblockName%5D%2B%2B%3B%0D%0A%09%7D%2C%20100)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocks%20%3D%20function(showOrigAd)%20%7B%0D%0A%09this.origAdCheckerCounter%20%3D%20%7B%7D%3B%0D%0A%09this.origAdChecker%20%3D%20%7B%7D%3B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.multipleTryToFindBlocksCycle(block%2C%20blockName%2C%20showOrigAd)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FOfficial%20site%20feature%0D%0ACORE.prototype.isAdAcceptable%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20!(%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09%09)%20%7C%7C%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isElFake(%24(block.origSel))%0D%0A%09%09%09%09)%0D%0A%09%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdAnyway%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20(%0D%0A%09%09%09(%0D%0A%09%09%09%09this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09)%0D%0A%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteBlock%20%3D%20function(block)%7B%0D%0A%09return%20(block.name%20%3D%3D%20'TOP')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteAd%20%3D%20function(ad)%7B%0D%0A%09return%20(ad.origin%20%3D%3D%20%22suggestion%22)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeFakeOrigAd%20%3D%20function(block)%20%7B%0D%0A%09var%20parentEl%20%3D%20%24(block.parentSel)%3B%0D%0A%09if(!parentEl.length)%20%7B%0D%0A%09%09u.log('makeFakeOrigAd%20!parentEl.length')%3B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%09var%20origId%20%3D%20block.origSel.replace('%23'%2C%20'')%3B%0D%0A%09var%20fakeEl%20%3D%20%24('%3Cdiv%20id%3D%22fakeAd%22%3E')%3B%0D%0A%09parentEl.prepend(fakeEl)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isElFake%20%3D%20function(el)%7B%0D%0A%09return%20(el.index('%23fakeAd')%20!%3D%20-1)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.SuggestionModule%20%20%3D%20function(instanceId)%20%7B%0D%0A%09this.data%20%3D%20%7B%7D%3B%0D%0A%09this.enable%20%3D%20true%3B%0D%0A%09this.addedBookmarks%20%3D%20%7B%7D%3B%0D%0A%0D%0A%09this.setConfig%20%3D%20function(data)%7B%0D%0A%09%09this.data%20%3D%20data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getConfig%20%3D%20function()%7B%0D%0A%09%09return%20this.data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getAdsForKeyword%20%3D%20function(keyword)%7B%0D%0A%09%09if(!this.data%20%7C%7C%20!this.data.s)%20return%20%5B%5D%3B%0D%0A%09%09var%20suggestions%20%3D%20this.findSuggestionsForKeyword(keyword%2C%2010)%3B%0D%0A%09%09return%20this.generateAdData(suggestions)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.findSuggestionsForKeyword%20%3D%20function(keyword%2C%20maxAmount)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Cthis.data.s.length%20%26%26%20result.length%20%3C%3D%20maxAmount%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20this.data.s%5Bi%5D%3B%0D%0A%09%09%09if(this.isSuggestionMatched(sugg%2C%20keyword))%7B%0D%0A%09%09%09%09result.push(sugg)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.isSuggestionMatched%20%3D%20function(sugg%2C%20keyword)%7B%0D%0A%09%09keyword%20%3D%20keyword.toLowerCase()%3B%0D%0A%09%09var%20k%20%3D%20keyword.indexOf(sugg.k.toLowerCase())%20%3D%3D%3D%200%3B%0D%0A%09%09var%20s%20%3D%20sugg.s.toLowerCase().indexOf(keyword)%20%3D%3D%3D%200%3B%0D%0A%09%09return%20k%20%26%26%20s%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.generateAdData%20%3D%20function(suggestions)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Csuggestions.length%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20suggestions%5Bi%5D%3B%0D%0A%09%09%09var%20diplayUrl%20%3D%20(sugg.v)%20%3F%20sugg.v%20%3A%20sugg.u.replace(%2F.*%5C%2F%5C%2F(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%241')%3B%20%2F%2Fwww.sales.target.com%0D%0A%09%09%09var%20title%20%3D%20(sugg.t)%20%3F%20sugg.t%20%3A%20this.capitaliseFirstLetter(sugg.u.replace(%2F.*%5C%2F%5C%2F(www%5C.)%3F(%5B%5Cw.%5D%2B)%5C.(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%242'))%3B%20%2F%2FSales.target%0D%0A%0D%0A%09%09%09result.push(%7B%0D%0A%09%09%09%09%22t%22%3A%20title%2C%0D%0A%09%09%09%09%22c%22%3A%20sugg.u%2C%0D%0A%09%09%09%09%22u%22%3A%20diplayUrl%20%2B%20'%20-%20'%20%2B%20this.data.t%2C%0D%0A%09%09%09%09%22d%22%3A%20sugg.d%2C%0D%0A%09%09%09%09%22r%22%3A%201%2C%0D%0A%09%09%09%09%22origin%22%3A%20%22suggestion%22%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.capitaliseFirstLetter%20%3D%20function(string)%7B%0D%0A%09%09return%20string.charAt(0).toUpperCase()%20%2B%20string.slice(1)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.coreStyles%20%20%3D%20function()%20%7B%0D%0A%09var%20a%20%3D%20'%3Cstyle%20id%3D%22adtrCoreStyle%22%3E%5C%0D%0A%09%3C%2Fstyle%3E'%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0AENGINE.prototype.MIN_PADDING%20%3D%2020%3B%0AENGINE.prototype.BLOCKS%20%3D%20%7B%0A%0A%09%09'TOP'%20%3A%20%7B%0A%09%09%09coverId%3A%20%22sponsoredTop-cover%22%2C%0A%09%09%09origSel%3A%20%22%23sponsoredTop%22%2C%0A%09%09%09coverSel%3A%20%22%23sponsoredTop-cover%22%2C%0A%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09name%3A%20'TOP'%2C%0A%09%09%09adSel%3A%20'%23sponsoredTop%20iframe'%2C%0A%09%09%09parentSel%3A%20%22%23results%22%0A%09%09%7D%2C%0A%09%09'BOTTOM'%20%3A%20%7B%0A%09%09%09coverId%3A%20%22sponsoredBottom-cover%22%2C%0A%09%09%09origSel%3A%20%22%23sponsoredBottom%22%2C%0A%09%09%09coverSel%3A%20%22%23sponsoredBottom-cover%22%2C%0A%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09name%3A%20'BOTTOM'%2C%0A%09%09%09adSel%3A%20'%23sponsoredBottom%20iframe'%0A%09%09%7D%0A%0A%7D%3B%0A%0A%0AENGINE.prototype.INPUT_SEL%20%3D%20%22input%5Bname%3D'searchfor'%5D%22%3B%0AENGINE.prototype.SPELL_SEL%20%3D%20'%23spellSuggest%20a'%3B%0AENGINE.prototype.MAIN_CONTAINER_SEL%20%3D%20'%23results'%3B%0AENGINE.prototype.engineCode%20%3D%20'm'%3B%0A%0AENGINE.prototype.STYLES%20%3D%20%20function()%7B%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%20width%3A%20100%25%7D%20%5C%0A%09.adtrCover%20ol%20%7B%20list-style-type%3A%20none%3B%20%7D%20%5C%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%200%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%200%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%20margin-bottom%3A%200px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%233300B5%3B%20text-decoration%3Aunderline%3B%20font-size%3A17px%3B%20font-weight%3A%20normal%3B%7D%20%5C%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%230E7744%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%20font-style%3A%20normal%3B%7D%20%5C%0A%09.adtrCover%20.ac%20%7Bfont-size%3A%20small%3B%7D%20%5C%0A%09.adtrCover%20.inner%20%7Bpadding%3A%200%204px%3B%7D%20%5C%0A%20%20%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20%5C%0A%20%20%20%20visibility%3A%20hidden%3B%20%5C%0A%20%20%20%20overflow%3A%20hidden%3B%20%5C%0A%20%20%7D%20%5C%0A%20%20.adtrCover-closeBtn%7B%20%5C%0A%20%20%20%20cursor%3A%20pointer%3B%20%5C%0A%20%20%20%20padding%3A%200%202px%202px%202px%3B%20%5C%0A%20%20%20%20font-size%3A%2012px%3B%20%5C%0A%20%20%20%20text-align%3A%20center%3B%20%5C%0A%20%20%20%20position%3A%20absolute%3B%20%5C%0A%20%20%20%20height%3A%2012px%3B%20%5C%0A%20%20%20%20width%3A%2033px%3B%20%5C%0A%20%20%20%20border%3A%201px%20solid%20lightblue%3B%20%5C%0A%20%20%20%20background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0A%20%20%20%20display%3A%20inline-block%3B%20%5C%0A%20%20%20%20right%3A%201px%3B%20%5C%0A%20%20%20%20top%3A%203px%3B%20%5C%0A%20%20%7D%5C%0A%20%20.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A20px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0A%20%20.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0A%20%20.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0A%20%20%3C%2Fstyle%3E%22%3B%0A%20%20return%20a%3B%0A%7D%3B%0A%0A%0A%0A%0AENGINE.prototype.isAdExist%20%3D%20function(block)%20%7B%0A%09var%20origIFrame%20%3D%20%24(block.adSel)%3B%0A%09return%20origIFrame.length%20%26%26%20(origIFrame.height()%20%3E%200)%3B%0A%0A%7D%3B%0D%0A%0D%0A%0D%0AGoogleChrome.prototype.ff%20%3D%20function()%7B%0D%0A%09console.log('oogleChrome.prototype.ff')%3B%0D%0A%7D%3B%0D%0AFirefox.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09%24('.adtr').remove()%3B%0D%0A%7D%3B%0D%0Afunction%20IE%20()%20%7B%7D%0D%0Afunction%20Browser%20(affiliateID%2C%20instanceID)%20%7B%0A%09var%20browser%3B%0A%09%2F%2Fif%20called%20with%20a%20%22new%22%20keyword%0A%09if%20(this.constructor%20%3D%3D%20Browser)%20%7B%0A%09%09%2F%2Fpicking%20specific%20browser%0A%09%09browser%20%3D%20this.pickBrowser()%3B%0A%0A%09%09browser.affiliateID%20%3D%20affiliateID%3B%0A%09%09browser.instanceID%20%3D%20instanceID%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error(%22Browser%20is%20a%20constructor%20function%22)%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%0A%0ABrowser.prototype.pickBrowser%20%3D%20function()%20%7B%0A%09%2F%2Fchecking%20browser%0A%09var%20ischrome%20%3D%20typeof(chrome)%20%3D%3D%20'object'%2C%0A%09%09firefox%20%3D%20typeof(chrome)%20%3D%3D%20'string'%2C%0A%09%09ie%20%3D%20navigator.userAgent.indexOf(%22Trident%22)%20!%3D%3D%20-1%2C%0A%09%09browser%20%3D%20null%3B%0A%0A%09if%20(ischrome)%20%7B%0A%09%09browser%20%3D%20new%20GoogleChrome()%3B%0A%09%7D%20else%20if%20(firefox)%20%7B%0A%09%09browser%20%3D%20new%20Firefox()%3B%0A%09%7D%20else%20if%20(ie)%20%7B%0A%09%09browser%20%3D%20new%20IE()%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error('unknown%20browser')%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%3B%0A%0A%0A%0D%0A%2F%2Fsimply%20extending%20specific%20browser%20classes%20with%20basic%20class%2C%20which%20holds%20default%20browser%20methods%0A%0A%2F%2Freturns%20browser%20object%20(one%20of%20Chrome%2C%20FF%2C%20IE)%0A%0Aif(typeof(pc)%20!%3D%20'undefined')%7B%0A%09var%20affiliateID%20%3D%20pc.affiliateID%3B%0A%09var%20instanceID%20%3D%20pc.instanceId%3B%0A%09var%20engineParams%20%3D%20pc.engineParams%3B%0A%7D%0A%0Aif(%20typeof(affiliateID)%20!%3D%20'undefined'%20)%7B%0A%09%2F%2FaffiliateID%20predefined%20by%20extension%0A%09var%20browser%20%3D%20new%20Browser(affiliateID%2C%20instanceID)%3B%0A%09browser.init(instanceID%2C%20affiliateID%2C%20engineParams)%3B%0A%09Util.log('started%20browser'%2C%20affiliateID%2C%20instanceID)%3B%0A%7D%20else%20%7B%0A%09var%20browser%20%3D%20new%20Browser()%3B%0A%09var%20Engine%20%3D%20browser%3B%0A%09Util.log('prepare%20Engine')%3B%0A%7D%0A%0A%0A%0A\""
FF - prefs.js..extensions.trusted-ads.serp_whitepages: "\"%2F*!%20serp-whitepages%20-%20v0.2.3%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09debug%3A%20false%2C%0A%09extend%3A%20function(Child%2C%20Parent)%20%7B%0A%09%09var%20F%20%3D%20function()%20%7B%20%7D%3B%0A%09%09F.prototype%20%3D%20Parent.prototype%3B%0A%09%09Child.prototype%20%3D%20new%20F()%3B%0A%09%09Child.prototype.constructor%20%3D%20Child%3B%0A%09%09Child._super%20%3D%20Parent.prototype%3B%0A%09%7D%2C%0A%09log%3A%20function()%20%7B%0A%09%09if%20(Util.debug)%20%7B%0A%09%09%09var%20args%20%3D%20Array.prototype.slice.call(arguments)%3B%0A%09%09%09console.log.apply(console%2C%20args)%3B%0A%09%09%7D%0A%09%7D%0A%7D%3B%0A%2F%2Fshort%20alias%0Au%20%3D%20Util%3B%0A%0Afunction%20ENGINE%20()%20%7B%7D%0Afunction%20GoogleChrome%20()%20%7B%7D%0Afunction%20CORE()%20%7B%7D%0Afunction%20Firefox%20()%20%7B%7D%0Afunction%20IE%20()%20%7B%7D%0A%0AUtil.extend(ENGINE%2C%20CORE)%3B%0AUtil.extend(GoogleChrome%2C%20ENGINE)%3B%0AUtil.extend(Firefox%2C%20ENGINE)%3B%0AUtil.extend(IE%2C%20ENGINE)%3B%0D%0ACORE.prototype.ADS_HOST%20%3D%20document.location.protocol%2B%22%2F%2Fsearch.adtrustmedia.com%2Fsearch_safecontent.php%22%3B%0D%0A%0D%0ACORE.prototype.ALL_BLOCKS_SELECTOR%20%3D%20function()%7B%0D%0A%09return%20%7B%0D%0A%09%09orig%3A%20this.BLOCKS.TOP.origSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.origSel*%2F%2C%0D%0A%09%09cover%3A%20this.BLOCKS.TOP.coverSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.coverSel*%2F%0D%0A%09%7D%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.STYLES%20%3D%20%20function()%20%7B%0D%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0D%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20%7B%20%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%2304c%3B%20text-decoration%3Aunderline%3B%20font-size%3A17px%3B%7D%20%5C%0D%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23388222%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%7D%20%5C%0D%0A%09%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20visibility%3A%20hidden%3B%20overflow%3A%20hidden%3B%7D%20%5C%0D%0A%09.adtrCover-closeBtn%7B%20%5C%0D%0A%09%09cursor%3A%20pointer%3B%20%5C%0D%0A%09%09padding%3A%200%202px%202px%202px%3B%20%5C%0D%0A%09%09font-size%3A%2012px%3B%20%5C%0D%0A%09%09text-align%3A%20center%3B%20%5C%0D%0A%09%09position%3A%20absolute%3B%20%5C%0D%0A%09%09height%3A%2012px%3B%20%5C%0D%0A%09%09width%3A%2033px%3B%20%5C%0D%0A%09%09border%3A%201px%20solid%20lightblue%3B%20%5C%0D%0A%09%09background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0D%0A%09%09display%3A%20inline-block%3B%20%5C%0D%0A%09%09right%3A%201px%3B%20%5C%0D%0A%09%09top%3A%203px%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.adtrCover%20.closeAd%7B%20%5C%0D%0A%09%09text-decoration%3A%20underline%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0D%0A%09.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0D%0A%09.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0D%0A%09%3C%2Fstyle%3E%22%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.MENU_BTN_SPACE%20%3D%208%3B%0D%0ACORE.prototype.MIN_PADDING%20%3D%208%3B%0D%0A%0D%0ACORE.prototype._ads%20%3D%20%5B%5D%3B%0D%0ACORE.prototype.instanceId%20%3D%20''%3B%0D%0ACORE.prototype.affilateID%20%3D%20''%3B%0D%0ACORE.prototype.data%20%3D%20null%3B%0D%0ACORE.prototype.keyword%20%3D%20''%3B%0D%0ACORE.prototype.engineParams%20%3D%20%7B%7D%3B%0D%0ACORE.prototype.engineCode%20%3D%20''%3B%0D%0A%0D%0ACORE.prototype.start%20%3D%20function()%7B%7D%3B%0D%0A%0D%0ACORE.prototype.init%20%3D%20function(instanceId%2C%20affilateID%2C%20engineParams)%20%7B%0D%0A%09this.data%20%3D%20typeof(engineData)%20!%3D%20%22undefined%22%20%3F%20engineData%20%3A%20null%3B%0D%0A%09this.keyword%20%3D%20typeof(engineKeyword)%20!%3D%20%22undefined%22%20%3F%20engineKeyword%20%3A%20''%3B%0D%0A%0D%0A%09if(engineParams.delivPoint)%20%7B%20this.ADS_HOST%20%3D%20engineParams.delivPoint%3B%20%7D%0D%0A%0D%0A%09%24(%22head%22).append(this.coreStyles())%3B%0D%0A%09%24(%22head%22).append(this.STYLES())%3B%0D%0A%09this.instanceId%20%3D%20instanceId%3B%0D%0A%09this.affilateID%20%3D%20affilateID%3B%0D%0A%09this.engineParams%20%3D%20engineParams%3B%0D%0A%0D%0A%09this.suggModule%20%3D%20new%20this.SuggestionModule()%3B%0D%0A%09if(engineParams.suggConfig)%20%7B%0D%0A%09%09this.suggModule.setConfig(engineParams.suggConfig)%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09var%20currentKeyword%20%3D%20this.getCurrentKeyword().toLowerCase()%3B%0D%0A%0D%0A%09if(this.keyword)%7B%0D%0A%09%09this.keyword%20%3D%20decodeURIComponent(this.keyword)%3B%0D%0A%09%09this.keyword%20%3D%20this.keyword.replace(%2F%5C%2B%2Fg%2C%20'%20')%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09u.log('FROM%20PLUGIN%3A'%2C%20%7B'engineData'%3A%20this.data%2C%20'engineKeyword'%3A%20this.keyword%2C%20'currentKeyword'%3A%20currentKeyword%2C%20'engineParams'%3A%20engineParams%7D)%3B%0D%0A%0D%0A%09if%20(%20this.data%20%26%26%20(this.data%20!%3D%20'noPreload')%20%26%26%20(currentKeyword%20%3D%3D%20this.keyword)%20)%7B%0D%0A%09%09var%20suggAdData%20%3D%20this.suggModule.getAdsForKeyword(this.keyword)%3B%0D%0A%0D%0A%09%09this.data%20%3D%20suggAdData.concat(this.data)%3B%0D%0A%09%09u.log('suggAdData'%2C%20suggAdData%2C%20this.data)%3B%0D%0A%09%09if(%20this.data.length%20)%7B%0D%0A%09%09%09this.multipleTryToFindBlocks()%3B%20%2F%2Fchanged%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%20else%20%7B%0D%0A%09%09if(currentKeyword%20!%3D%20%22undefined%22)%20%7B%0D%0A%09%09%09this.keyword%20%3D%20currentKeyword%3B%0D%0A%09%09%09var%20requestUrl%20%3D%20this.getAdRequestUrl(currentKeyword)%3B%0D%0A%09%09%09this.sendAdRequest(requestUrl)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._domain_without_www%20%3D%20function(url)%20%7B%0D%0A%09var%20clean%20%3D%20url.replace(%2F%5Ewww%5C.%2F%2C'')%3B%0D%0A%09return%20clean%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getAdRequestUrl%20%3D%20function(keyword)%20%7B%0D%0A%09var%20domain%20%3D%20this._domain_without_www(document.location.host)%3B%0D%0A%09var%20requestUrl%20%3D%20this.ADS_HOST%20%2B%20%22%3F%22%20%2B%0D%0A%09%09%22adtype%3Dtext%22%20%2B%0D%0A%09%09%22%26method%3Djs%22%20%2B%0D%0A%09%09%22%26advert%3D1%22%20%2B%0D%0A%09%09%22%26referer%3D%22%20%2B%20encodeURIComponent(document.location.protocol%20%2B%22%2F%2F%22%2B%20document.location.host%2B%22%2F%22)%20%2B%0D%0A%09%09%22%26ta_affiliateid%3D%22%20%2B%20this.affilateID%20%2B%0D%0A%09%09%22%26ta_insid%3D%22%20%2B%20this.instanceId%20%2B%0D%0A%09%09%22%26kw%3D%22%20%2B%20encodeURIComponent(keyword)%20%2B%0D%0A%09%09this.getEngineIdentityParam()%3B%0D%0A%09return%20requestUrl%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getCurrentKeyword%20%3D%20function()%7B%0D%0A%09var%20keyword%20%3D%20''%3B%0D%0A%0D%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0D%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0D%0A%0D%0A%09if(spell.length)%7B%0D%0A%09%09keyword%20%3D%20spell.text()%3B%0D%0A%09%7D%20else%20if(input.length)%7B%0D%0A%09%09keyword%20%3D%20input.val()%3B%0D%0A%09%7D%0D%0A%09return%20keyword%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FTRY%20TO%20GET%20ADS%20BY%20NEW%20KEYWORD%0D%0A%2F%2F_requestInProcess%3A%20false%2C%0D%0ACORE.prototype.sendAdRequest%20%3D%20function(requestUrl)%20%7B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%0D%0A%09u.log('SEND%20REQUEST'%2C%20%5Bthis.keyword%2C%20requestUrl%5D)%3B%0D%0A%0D%0A%09%24.ajax(%7B%0D%0A%09%09url%3A%20requestUrl%2C%0D%0A%09%09dataType%3A%20'json'%2C%0D%0A%09%09error%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function()%20%7B%0D%0A%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%2C%0D%0A%09%09success%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function(data)%20%7B%0D%0A%09%09%09%09var%20suggAdData%20%3D%20scope.suggModule.getAdsForKeyword(scope.keyword)%3B%0D%0A%09%09%09%09data%20%3D%20suggAdData.concat(data)%3B%0D%0A%0D%0A%09%09%09%09if(!data.length)%20%7B%0D%0A%09%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%09%09return%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09u.log('REQUEST%20SUCCESS'%2C%20%5Bscope.keyword%2C%20scope.suggModule%2C%20data%5D)%3B%0D%0A%09%09%09%09scope.data%20%3D%20data%3B%0D%0A%09%09%09%09scope.clearDynamicBlocksData()%3B%0D%0A%09%09%09%09scope.makeCovers()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showAllOriginalAd%20%3D%20function()%20%7B%0D%0A%09u.log('showAllOriginalAd()')%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B').show()%3B%0D%0A%09if(block.adSel)%7B%0D%0A%09%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible!important%3B')%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FADS%20REPLACEMENT%20PROCESS%0D%0ACORE.prototype.makeCovers%20%3D%20function()%20%7B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%0D%0A%09%09if(!this.isAdExist(block))%20%7B%0D%0A%09%09%09if(this.isOfficialSiteBlock(block))%7B%0D%0A%09%09%09%09this.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%09continue%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09%2F%2FORIGINAL%20SELECTOR%20IS%20A%20DOM%20ELEMENT%0D%0A%09%09this._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09this.makeCover(block%2C%20blockName)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdExist%20%3D%20function(block)%20%7B%0D%0A%09var%20origSel%20%3D%20%24(block.origSel)%3B%0D%0A%09return%20origSel.length%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FPREPARE%20AND%20RENDER%20REPLACEMENT%20COVER%20(old%3A%20_prepareReplacement)%0D%0ACORE.prototype.makeCover%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('MAKE%20COVER'%2C%20blockName%2C%20%7BblockData%3A%20JSON.stringify(block.data)%7D)%3B%0D%0A%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(el.index('%23fakeAd')%20!%3D%20-1)%7B%0D%0A%09%09el%20%3D%20%24('%23fakeAd')%3B%0D%0A%09%7D%0D%0A%09var%20data%20%3D%20block.data%3B%0D%0A%0D%0A%09if%20(data.length)%20%7B%0D%0A%0D%0A%09%09var%20width%20%3D%20el.width()%3B%0D%0A%09%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%09%09%2F%2FREMOVE%20PREV%20BLOCK%0D%0A%09%09%24(block.coverSel).remove()%3B%0D%0A%0D%0A%09%09%2F%2FCREATE%20COVER%0D%0A%09%09var%20coverHeight%20%3D%20el.height()%3B%0D%0A%09%09if(block.newHeight)%7B%0D%0A%09%09%09coverHeight%20%3D%20block.newHeight%3B%0D%0A%09%09%09el.height(coverHeight)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09var%20cover%20%3D%20%24('%3Cdiv%20id%3D%22'%2B%20block.coverId%20%2B'%22%20class%3D%22adtrCover%22%20style%3D%22height%3A'%2B%20coverHeight%20%2B'px%3B%22%3E'%2B%20this._fillWithAds(block%2C%20blockName)%20%2B'%3C%2Fdiv%3E').css(%7B%0D%0A%09%09%09margin%3A%20this.getMargin(el)%2C%20padding%3A%20this.getPadding(el)%2C%0D%0A%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%7D)%3B%0D%0A%09%09cover.insertBefore(el)%3B%0D%0A%09%09el.addClass('hideOrig')%3B%0D%0A%09%09this.makeCoverMenu(block%2C%20cover%2C%20blockName)%3B%0D%0A%09%09this._compareRealAndCalcHeights(block)%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('showed%20without%20ad'%2C%20blockName)%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeCoverMenu%20%3D%20function(block%2C%20cover%2C%20blockName)%20%7B%0D%0A%20%20%20%20%20%20var%20clas%20%3D%20'atmAd'%3B%0D%0A%20%20%20%20%20%20var%20d%3B%0D%0A%0D%0A%20%20%20%20%20%20if%20(blockName%20%3D%3D%20'RIGHT')%20%7B%0D%0A%20%20%20%20%20%20%20%20clas%20%3D%20'atmAd-left'%3B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%3E%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%20else%20%7B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%3Cimg%20src%3D%22'%2Bdocument.location.protocol%2B'%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%20%2F%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FTABLE%0D%0A%20%20%20%20%20%20var%20t%20%3D%20%24(%22%3Ctable%20style%3D'visibility%3Ainherit%3B%20border-spacing%3A%201px%3B%20margin%3A%200px%3B%20border-collapse%3A%20collapse%3B%20%20background-color%3Agrey%3B%20z-index%3A100%3B'%20border%3D'1'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20style%3D'background-color%3Awhite%3B%20height%3A%2014px%3B%20padding%3A0px%203px%3B%20line-height%3A14px%3B'%3E%3Ca%20style%3D'width%3A58px%3B%20margin%3A0px%3B%20display%3Ablock%3B%20color%3Ablack%3B%20text-decoration%3Anone%3B%20text-align%3Aleft%3B%20font-weight%3Anormal%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20background-color%3Awhite%3B%20font-size%3A9px%3B'%20href%3D'https%3A%2F%2Fadtrustmedia.com%2Fwhyad.html'%20target%3D'_blank'%3EWhy%20this%20ad%3F%3C%2Fa%3E%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20class%3D'closeAd'%20style%3D'white-space%3Anowrap%3B%20color%3Ablack%3B%20background-color%3Awhite%3B%20cursor%3Apointer%3B%20padding%3A0px%203px%3B%20%20height%3A%2014px%3B%20line-height%3A14px%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A9px%3B'%3EClose%20this%20ad%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftable%3E%22)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20d.find('a.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20t.find('.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%20%20%20%20%20%20d.append(t)%3B%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FCLICK%20ON%20ATM%20AD%0D%0A%20%20%20%20%20%20d.find('.toggleTable').click(function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%24(this).next().toggle()%3B%0D%0A%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20d.appendTo(cover)%3B%0D%0A%0D%0A%20%20%20%20%20%20var%20self%20%3D%20this%3B%0D%0A%20%20%20%20%20%20function%20removeAd()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20cover.remove()%3B%0D%0A%20%20%20%20%20%20%20%20%20%20self.showOriginalAdForBlock(block)%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype._fillWithAds%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('FILL%20COVER'%2C%20blockName%2C%20%5Bblock.data%5D)%3B%0D%0A%09var%20block_content%20%3D%20''%2C%0D%0A%09%09data%20%3D%20block.data%3B%0D%0A%0D%0A%09block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09var%20adTopPadding%20%3D%20block.adTopPadding%3B%0D%0A%09%09if(i%3D%3D%3D0)%20%7B%0D%0A%09%09%09adTopPadding%20%3D%20adTopPadding%2F2%3B%0D%0A%09%09%09if(blockName%20%3D%3D%20'RIGHT')%20adTopPadding%20%2B%3D%20this.MENU_BTN_SPACE%3B%0D%0A%09%09%7D%0D%0A%09%09var%20offsiteClass%20%3D%20(data%5Bi%5D.origin%20%3D%3D%20%22suggestion%22)%20%3F%20'class%3D%22official-site%22'%20%3A%20%22%22%3B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20style%3D'padding-top%3A%20%22%2BadTopPadding%2B%22px'%22%20%2B%20offsiteClass%20%2B%20%22%3E%22%2B%0D%0A%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09return%20block_content%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._calcAdHeightForBlock%20%3D%20function(block)%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(!el.length)%20%7B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20width%20%3D%20el.width()%3B%0D%0A%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%0D%0A%09var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%20position%3Aabsolute%20!important%3B%20top%3A%20-10000px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%2F%2F%20var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%09%09%09).css(%7B%0D%0A%09%09%09%09%09margin%3A%20this.getMargin(el)%2C%0D%0A%09%09%09%09%09padding%3A%20this.getPadding(el)%20%2C%0D%0A%09%09%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%09%09%7D)%3B%0D%0A%0D%0A%0D%0A%09var%20block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%09var%20data%20%3D%20this.data%3B%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20data-index%3D'%22%2Bi%2B%22'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bdata%5Bi%5D.t%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09div.html(block_content)%3B%0D%0A%09%24(this.MAIN_CONTAINER_SEL).append(div)%3B%0D%0A%0D%0A%09u.log('MAIN_CONTAINER_SEL'%2C%20%24(this.MAIN_CONTAINER_SEL).length)%3B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%09div.find('li').each(function(i%2C%20li)%7B%0D%0A%09%09li%20%3D%20%24(li)%3B%0D%0A%09%09var%20index%20%3D%20li.data('index')%3B%0D%0A%09%09if(!scope.data%5Bindex%5D.h)%20scope.data%5Bindex%5D.h%20%3D%20%7B%7D%3B%0D%0A%09%09scope.data%5Bindex%5D.h%5Bblock.origSel%5D%20%3D%20li.height()%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09%2F%2F%20div.remove()%3B%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._provideAdDataForBlock%20%3D%20function(block%2C%20blockName)%7B%0D%0A%09u.log('DATA%20FOR%20BLOCK'%2C%20blockName)%3B%0D%0A%0D%0A%09var%20addingLog%20%3D%20%5B%5D%3B%0D%0A%0D%0A%09var%20MAX_ADDITIONAL_PADDING%20%3D%2015%3B%0D%0A%0D%0A%09var%20providedIndexes%20%3D%20%5B%5D%3B%0D%0A%09var%20allData%20%3D%20this.data%3B%0D%0A%0D%0A%09var%20origEl%20%3D%20%24(block.origSel)%3B%0D%0A%09var%20blockHeight%20%3D%20origEl.height()%3B%0D%0A%09var%20adPadding%20%3D%20this.MIN_PADDING%3B%0D%0A%09var%20adHeightSumm%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'RIGHT')%20adHeightSumm%20%3D%20this.MENU_BTN_SPACE%3B%0D%0A%0D%0A%09this._calcAdHeightForBlock(block)%3B%0D%0A%0D%0A%09var%20indexesOfOtherBlocks%20%3D%20this._getDataIndexesOfOtherBlocks(block)%3B%0D%0A%0D%0A%09var%20allDataWasChecked%20%3D%20false%3B%0D%0A%09var%20i%20%3D%200%3B%0D%0A%09var%20numOfCheckedIndexes%20%3D%200%3B%0D%0A%0D%0A%09var%20maxOfAds%20%3D%20this.getMaxAdsForBlock(blockName)%3B%0D%0A%09var%20minOfAds%20%3D%20this.getMinAdsForBlock(blockName)%3B%0D%0A%0D%0A%09u.log('indexesOfOtherBlocks'%2C%20indexesOfOtherBlocks)%3B%0D%0A%09var%20numOfFreeIndexes%20%3D%20allData.length%20-%20indexesOfOtherBlocks.length%3B%0D%0A%09var%20ttt%20%3D%200%3B%0D%0A%09var%20adHeight%3B%0D%0A%09while(i%20%3C%20allData.length%20%26%26%20ttt%3C30%20%26%26%20providedIndexes.length%3CmaxOfAds)%7B%0D%0A%0D%0A%09%09var%20indexIsFree%20%3D%20(indexesOfOtherBlocks.indexOf(i)%20%3D%3D%20-1)%3B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09var%20anywayAd%20%3D%20this.isAdAnyway(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(indexIsFree%20%26%26%20acceptableAd)%7B%0D%0A%0D%0A%09%09%09adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%0D%0A%09%09%09%2F%2Fif%20we%20can%20fit%20ad%20to%20block%20then%20add%20it%0D%0A%09%09%09addingLog.push(%7B%0D%0A%09%09%09%09i%3A%20i%2C%0D%0A%09%09%09%09t%3A%20allData%5Bi%5D.t%2C%0D%0A%09%09%09%09free%3A%20(blockHeight-adHeightSumm)%2C%0D%0A%09%09%09%09adPad%3A%20(adHeight%2Bthis.MIN_PADDING)%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%09var%20enoughSpace%20%3D%20(blockHeight%20%3E%3D%20adHeightSumm%20%2B%20adHeight%20%2B%20adPadding)%3B%0D%0A%09%09%09if(enoughSpace%20%7C%7C%20providedIndexes.length%20%3C%20minOfAds%20%7C%7C%20anywayAd)%7B%0D%0A%09%09%09%09if(!enoughSpace)%7B%0D%0A%09%09%09%09%09u.log('add%20more%20ads%20couse%20min%20ads%20required%20in%20block'%2C%20blockName%2C%20providedIndexes.length)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09%09providedIndexes.push(i)%3B%0D%0A%09%09%09%7D%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09ttt%2B%2B%3B%0D%0A%09%09i%2B%2B%3B%0D%0A%09%7D%0D%0A%09u.log('addingLog'%2C%20addingLog)%3B%0D%0A%0D%0A%09var%20freeSpace%20%3D%20blockHeight%20-%20adHeightSumm%3B%0D%0A%09var%20additionalPadding%20%3D%20freeSpace%20%2F%20(providedIndexes.length)%3B%0D%0A%0D%0A%09u.log('blockHeight'%2C%20blockHeight%2C%20'adHeightSumm'%2C%20adHeightSumm%2C%20'freeSpace'%2C%20freeSpace)%3B%0D%0A%0D%0A%09u.log('additionalPadding'%2C%20additionalPadding%2C%20'acceptable'%2C%20(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200))%3B%0D%0A%09if(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09adPadding%20%2B%3D%20additionalPadding%3B%0D%0A%09%7D%20else%20if(providedIndexes.length%20%3C%20maxOfAds%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09var%20alreadyOccupiedAdIndexes%20%3D%20indexesOfOtherBlocks.concat(providedIndexes)%3B%0D%0A%09%09var%20shortestAdIndex%20%3D%20this._getShortestAdIndex(allData%2C%20alreadyOccupiedAdIndexes%2C%20block)%3B%0D%0A%09%09if(shortestAdIndex%20%3E%20-1)%7B%0D%0A%09%09%09adHeight%20%3D%20allData%5BshortestAdIndex%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09providedIndexes.push(shortestAdIndex)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09u.log('shortestAdIndex'%2C%20shortestAdIndex%2C%20'orig%20resize'%2C%20adHeightSumm%20-%20blockHeight)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('shortened%20block'%2C%20blockName%2C%20blockHeight%2C%20adHeightSumm)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20providedData%20%3D%20%5B%5D%3B%0D%0A%09for(var%20j%3D0%3B%20j%3CprovidedIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09providedData.push(allData%5BprovidedIndexes%5Bj%5D%5D)%3B%0D%0A%09%7D%0D%0A%09u.log('providedData'%2C%20providedData%2C%20'providedIndexes'%2C%20providedIndexes%2C%20'adPadding'%2C%20adPadding)%3B%0D%0A%09block.data%20%3D%20providedData%3B%0D%0A%09block.dataIndexes%20%3D%20providedIndexes%3B%0D%0A%09block.adTopPadding%20%3D%20adPadding%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getDataIndexesOfOtherBlocks%20%3D%20function(block)%7B%0D%0A%09var%20indexes%20%3D%20%5B%5D%3B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09if(this.BLOCKS%5Bi%5D.origSel%20!%3D%20block.origSel)%7B%0D%0A%09%09%09var%20otherBlockIndexes%20%3D%20this.BLOCKS%5Bi%5D.dataIndexes%3B%0D%0A%09%09%09for(var%20j%3D0%3B%20j%3CotherBlockIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09%09%09if(indexes.indexOf(otherBlockIndexes%5Bj%5D)%20%3D%3D%20-1)%7B%0D%0A%09%09%09%09%09indexes.push(otherBlockIndexes%5Bj%5D)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%09return%20indexes%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getShortestAdIndex%20%3D%20function(allData%2C%20excludedIndexes%2C%20block)%7B%0D%0A%09var%20minHeight%20%3D%201000000%3B%0D%0A%09var%20minHeightAdIndex%20%3D%20-1%3B%0D%0A%0D%0A%09for(var%20i%3D0%3B%20i%3CallData.length%3B%20i%2B%2B)%7B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(!acceptableAd)%20continue%3B%0D%0A%09%09if(excludedIndexes.indexOf(i)%20%3D%3D%20-1)%7B%0D%0A%09%09%09var%20adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09if(adHeight%20%3C%20minHeight)%7B%0D%0A%09%09%09%09minHeight%20%3D%20adHeight%3B%0D%0A%09%09%09%09minHeightAdIndex%20%3D%20i%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%09return%20minHeightAdIndex%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.clearDynamicBlocksData%20%3D%20function()%7B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5Bi%5D%3B%0D%0A%09%09block.data%20%3D%20%5B%5D%3B%0D%0A%09%09block.dataIndexes%20%3D%20%5B%5D%3B%0D%0A%09%09block.adTopPadding%20%3D%200%3B%0D%0A%09%09block.oldHeight%20%3D%20false%3B%0D%0A%09%09block.newHeight%20%3D%20false%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._replicateBlock%20%3D%20function(donor%2C%20recipient)%7B%0D%0A%09recipient.data%20%3D%20donor.data%3B%0D%0A%09recipient.dataIndexes%20%3D%20donor.dataIndexes%3B%0D%0A%09recipient.adTopPadding%20%3D%20donor.adTopPadding%3B%0D%0A%09recipient.oldHeight%20%3D%20%24(recipient.origSel).height()%3B%0D%0A%09recipient.newHeight%20%3D%20donor.newHeight%20%7C%7C%20%24(donor.origSel).height()%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._compareRealAndCalcHeights%20%3D%20function(block)%7B%0D%0A%09var%20cover%20%3D%20%24(block.coverSel)%3B%0D%0A%09var%20orig%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09cover.find('li').each(function(i)%7B%0D%0A%09%09var%20el%20%3D%20%24(this)%3B%0D%0A%09%09var%20title%20%3D%20el.find('h3%20a').text()%3B%0D%0A%09%09var%20calcSize%20%3D%20block.data%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09u.log(title%2C%20el.height()%2C%20calcSize)%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09u.log('block%20sizes'%2C%20%7B%0D%0A%09%09origReal%3A%20orig.height()%2C%0D%0A%09%09coverReal%3A%20cover.height()%2C%0D%0A%09%09newHeight%3A%20block.newHeight%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMaxAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20maxOfAds%20%3D%20100%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mxt)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mxr)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mxb)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.max_top_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.max_right_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.max_bottom_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20maxOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMinAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20minOfAds%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mnt)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mnr)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mnb)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.min_top_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.min_right_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.min_bottom_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20minOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.getPadding%20%3D%20function(el)%20%7B%0D%0A%09var%20right%20%3D%20el.css('padding-right')%2C%0D%0A%09%09left%20%3D%20el.css('padding-left')%3B%0D%0A%09return%20%5B0%2C%20right%2C%200%2C%20left%5D.join('%20')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMargin%20%3D%20function(el)%20%7B%0D%0A%09var%20margin%20%3D%20el.css('margin')%3B%0D%0A%09if(margin%20%3D%3D%3D%20'')%20%7B%0D%0A%09%09var%20top%20%3D%20el.css('margin-top')%2C%0D%0A%09%09%09right%20%3D%20el.css('margin-right')%2C%0D%0A%09%09%09bott%20%3D%20el.css('margin-bottom')%2C%0D%0A%09%09%09left%20%3D%20el.css('margin-left')%3B%0D%0A%09%09return%20%5Btop%2C%20right%2C%20bott%2C%20left%5D.join('%20')%3B%0D%0A%09%7D%0D%0A%09return%20margin%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getEngineIdentityParam%20%3D%20function()%20%7B%0D%0A%09return%20'%26e%3D'%2Bthis.engineCode%2B'_s'%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocksCycle%20%3D%20function(block%2C%20blockName%2C%20showOrigAd)%7B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09this.origAdCheckerCounter%5BblockName%5D%20%3D%200%3B%0D%0A%09this.origAdChecker%5BblockName%5D%20%3D%20setInterval(function()%7B%0D%0A%09%09if(self.isAdExist(block))%20%7B%0D%0A%09%09%09if(showOrigAd)%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7Delse%20if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09if(self.isOfficialSiteBlock(block))%7B%0D%0A%0D%0A%09%09%09%09self.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09self.origAdCheckerCounter%5BblockName%5D%2B%2B%3B%0D%0A%09%7D%2C%20100)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocks%20%3D%20function(showOrigAd)%20%7B%0D%0A%09this.origAdCheckerCounter%20%3D%20%7B%7D%3B%0D%0A%09this.origAdChecker%20%3D%20%7B%7D%3B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.multipleTryToFindBlocksCycle(block%2C%20blockName%2C%20showOrigAd)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FOfficial%20site%20feature%0D%0ACORE.prototype.isAdAcceptable%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20!(%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09%09)%20%7C%7C%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isElFake(%24(block.origSel))%0D%0A%09%09%09%09)%0D%0A%09%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdAnyway%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20(%0D%0A%09%09%09(%0D%0A%09%09%09%09this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09)%0D%0A%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteBlock%20%3D%20function(block)%7B%0D%0A%09return%20(block.name%20%3D%3D%20'TOP')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteAd%20%3D%20function(ad)%7B%0D%0A%09return%20(ad.origin%20%3D%3D%20%22suggestion%22)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeFakeOrigAd%20%3D%20function(block)%20%7B%0D%0A%09var%20parentEl%20%3D%20%24(block.parentSel)%3B%0D%0A%09if(!parentEl.length)%20%7B%0D%0A%09%09u.log('makeFakeOrigAd%20!parentEl.length')%3B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%09var%20origId%20%3D%20block.origSel.replace('%23'%2C%20'')%3B%0D%0A%09var%20fakeEl%20%3D%20%24('%3Cdiv%20id%3D%22fakeAd%22%3E')%3B%0D%0A%09parentEl.prepend(fakeEl)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isElFake%20%3D%20function(el)%7B%0D%0A%09return%20(el.index('%23fakeAd')%20!%3D%20-1)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.SuggestionModule%20%20%3D%20function(instanceId)%20%7B%0D%0A%09this.data%20%3D%20%7B%7D%3B%0D%0A%09this.enable%20%3D%20true%3B%0D%0A%09this.addedBookmarks%20%3D%20%7B%7D%3B%0D%0A%0D%0A%09this.setConfig%20%3D%20function(data)%7B%0D%0A%09%09this.data%20%3D%20data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getConfig%20%3D%20function()%7B%0D%0A%09%09return%20this.data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getAdsForKeyword%20%3D%20function(keyword)%7B%0D%0A%09%09if(!this.data%20%7C%7C%20!this.data.s)%20return%20%5B%5D%3B%0D%0A%09%09var%20suggestions%20%3D%20this.findSuggestionsForKeyword(keyword%2C%2010)%3B%0D%0A%09%09return%20this.generateAdData(suggestions)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.findSuggestionsForKeyword%20%3D%20function(keyword%2C%20maxAmount)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Cthis.data.s.length%20%26%26%20result.length%20%3C%3D%20maxAmount%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20this.data.s%5Bi%5D%3B%0D%0A%09%09%09if(this.isSuggestionMatched(sugg%2C%20keyword))%7B%0D%0A%09%09%09%09result.push(sugg)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.isSuggestionMatched%20%3D%20function(sugg%2C%20keyword)%7B%0D%0A%09%09keyword%20%3D%20keyword.toLowerCase()%3B%0D%0A%09%09var%20k%20%3D%20keyword.indexOf(sugg.k.toLowerCase())%20%3D%3D%3D%200%3B%0D%0A%09%09var%20s%20%3D%20sugg.s.toLowerCase().indexOf(keyword)%20%3D%3D%3D%200%3B%0D%0A%09%09return%20k%20%26%26%20s%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.generateAdData%20%3D%20function(suggestions)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Csuggestions.length%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20suggestions%5Bi%5D%3B%0D%0A%09%09%09var%20diplayUrl%20%3D%20(sugg.v)%20%3F%20sugg.v%20%3A%20sugg.u.replace(%2F.*%5C%2F%5C%2F(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%241')%3B%20%2F%2Fwww.sales.target.com%0D%0A%09%09%09var%20title%20%3D%20(sugg.t)%20%3F%20sugg.t%20%3A%20this.capitaliseFirstLetter(sugg.u.replace(%2F.*%5C%2F%5C%2F(www%5C.)%3F(%5B%5Cw.%5D%2B)%5C.(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%242'))%3B%20%2F%2FSales.target%0D%0A%0D%0A%09%09%09result.push(%7B%0D%0A%09%09%09%09%22t%22%3A%20title%2C%0D%0A%09%09%09%09%22c%22%3A%20sugg.u%2C%0D%0A%09%09%09%09%22u%22%3A%20diplayUrl%20%2B%20'%20-%20'%20%2B%20this.data.t%2C%0D%0A%09%09%09%09%22d%22%3A%20sugg.d%2C%0D%0A%09%09%09%09%22r%22%3A%201%2C%0D%0A%09%09%09%09%22origin%22%3A%20%22suggestion%22%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.capitaliseFirstLetter%20%3D%20function(string)%7B%0D%0A%09%09return%20string.charAt(0).toUpperCase()%20%2B%20string.slice(1)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.coreStyles%20%20%3D%20function()%20%7B%0D%0A%09var%20a%20%3D%20'%3Cstyle%20id%3D%22adtrCoreStyle%22%3E%5C%0D%0A%09%3C%2Fstyle%3E'%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0AENGINE.prototype.BLOCKS%20%3D%20%7B%0A%0A%09%09'TOP'%3A%20%7B%0A%09%09%09origSel%3A%20'%23serp_bigmap_top'%2C%0A%09%09%09coverSel%3A%20'%23serp_bigmap_top_atmcover'%2C%0A%09%09%09name%3A%20'TOP'%2C%0A%09%09%09coverId%3A%20'serp_bigmap_top_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23serp_bigmap_top%20iframe'%2C%0A%09%09%09parentSel%3A%20'%23right'%0A%09%09%7D%2C%0A%0A%09%09'BOTTOM'%3A%20%7B%0A%09%09%09origSel%3A%20'%23serp_bigmap_wide'%2C%0A%09%09%09coverSel%3A%20'%23serp_bigmap_bot_atmcover'%2C%0A%09%09%09name%3A%20'BOTTOM'%2C%0A%09%09%09coverId%3A%20'serp_bigmap_bot_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23serp_bigmap_wide%20iframe'%0A%09%09%7D%0A%0A%7D%3B%0A%0A%0AENGINE.prototype.INPUT_SEL%20%3D%20'%23key'%3B%0AENGINE.prototype.SPELL_SEL%20%3D%20'%23spell%20a%20b'%3B%0AENGINE.prototype.MAIN_CONTAINER_SEL%20%3D%20'%23serp_bigmap_wide'%3B%0AENGINE.prototype.engineCode%20%3D%20'w'%3B%0A%0AENGINE.prototype.isAdExist%20%3D%20function(block)%20%7B%0A%09var%20origIFrame%20%3D%20%24(block.adSel)%3B%0A%09return%20origIFrame.length%20%26%26%20(origIFrame.height()%20%3E%200)%3B%0A%7D%3B%0A%0AENGINE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0A%09if(!el.length)%20return%3B%0A%09el.removeClass('hideOrig')%3B%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0A%7D%3B%0A%0AENGINE.prototype.STYLES%20%3D%20%20function()%7B%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%20border%3A%201px%20solid%20%23CCC%3B%7D%20%5C%0A%09.adtrCover%20ol%20%7B%20list-style-type%3A%20none%3B%20%20margin-left%3A%200px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%20line-height%3A%2015px%3B%20margin%3A%200px%3B%20%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%234289B7%3B%20text-decoration%3Aunderline%3B%20font-weight%3A%20normal%3B%7D%20%5C%0A%09.adtrCover%20.kv.kva%20%7B%20height%3A15px%3B%7D%20%5C%0A%09.adtrCover%20.official-site%20%20.kv.kva%20%7B%20height%3Aauto%3B%7D%20%5C%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%234289B7%3B%20font-size%3A12px%20!important%3B%20height%3A16px%3B%20%7D%20%5C%0A%09.ac%20%7Bline-height%3A%2017px%3B%7D%5C%0A%20%20%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20%5C%0A%20%20%20%20visibility%3A%20hidden%3B%20%5C%0A%20%20%20%20overflow%3A%20hidden%3B%20%5C%0A%20%20%7D%20%5C%0A%20%20%23serp_bigmap_top%2C%20%23serp_bigmap_wide%7B%5C%0A%09visibility%3A%20hidden%20!important%3B%20%5C%0A%20%20%7D%5C%0A%20%20.adtrCover-closeBtn%7B%20%5C%0A%20%20%20%20cursor%3A%20pointer%3B%20%5C%0A%20%20%20%20padding%3A%200%202px%202px%202px%3B%20%5C%0A%20%20%20%20font-size%3A%2012px%3B%20%5C%0A%20%20%20%20text-align%3A%20center%3B%20%5C%0A%20%20%20%20position%3A%20absolute%3B%20%5C%0A%20%20%20%20height%3A%2012px%3B%20%5C%0A%20%20%20%20width%3A%2033px%3B%20%5C%0A%20%20%20%20border%3A%201px%20solid%20lightblue%3B%20%5C%0A%20%20%20%20background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0A%20%20%20%20display%3A%20inline-block%3B%20%5C%0A%20%20%20%20right%3A%201px%3B%20%5C%0A%20%20%20%20top%3A%203px%3B%20%5C%0A%20%20%7D%5C%0A%20%20.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0A%20%20.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0A%20%20.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0A%20%20%3C%2Fstyle%3E%22%3B%0A%20%20return%20a%3B%0A%7D%3B%0A%0A%0D%0AGoogleChrome.prototype.ff%20%3D%20function()%7B%0D%0A%09console.log('oogleChrome.prototype.ff')%3B%0D%0A%7D%3B%0D%0AFirefox.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09%24('.adtr').remove()%3B%0D%0A%7D%3B%0D%0AIE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09%24('%23adtr').remove()%3B%0D%0A%7D%3B%0D%0Afunction%20Browser%20(affiliateID%2C%20instanceID)%20%7B%0A%09var%20browser%3B%0A%09%2F%2Fif%20called%20with%20a%20%22new%22%20keyword%0A%09if%20(this.constructor%20%3D%3D%20Browser)%20%7B%0A%09%09%2F%2Fpicking%20specific%20browser%0A%09%09browser%20%3D%20this.pickBrowser()%3B%0A%0A%09%09browser.affiliateID%20%3D%20affiliateID%3B%0A%09%09browser.instanceID%20%3D%20instanceID%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error(%22Browser%20is%20a%20constructor%20function%22)%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%0A%0ABrowser.prototype.pickBrowser%20%3D%20function()%20%7B%0A%09%2F%2Fchecking%20browser%0A%09var%20ischrome%20%3D%20typeof(chrome)%20%3D%3D%20'object'%2C%0A%09%09firefox%20%3D%20typeof(chrome)%20%3D%3D%20'string'%2C%0A%09%09ie%20%3D%20navigator.userAgent.indexOf(%22Trident%22)%20!%3D%3D%20-1%2C%0A%09%09browser%20%3D%20null%3B%0A%0A%09if%20(ischrome)%20%7B%0A%09%09browser%20%3D%20new%20GoogleChrome()%3B%0A%09%7D%20else%20if%20(firefox)%20%7B%0A%09%09browser%20%3D%20new%20Firefox()%3B%0A%09%7D%20else%20if%20(ie)%20%7B%0A%09%09browser%20%3D%20new%20IE()%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error('unknown%20browser')%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%3B%0A%0A%0A%0D%0A%2F%2Fsimply%20extending%20specific%20browser%20classes%20with%20basic%20class%2C%20which%20holds%20default%20browser%20methods%0A%0A%2F%2Freturns%20browser%20object%20(one%20of%20Chrome%2C%20FF%2C%20IE)%0A%0Aif(typeof(pc)%20!%3D%20'undefined')%7B%0A%09var%20affiliateID%20%3D%20pc.affiliateID%3B%0A%09var%20instanceID%20%3D%20pc.instanceId%3B%0A%09var%20engineParams%20%3D%20pc.engineParams%3B%0A%7D%0A%0Aif(%20typeof(affiliateID)%20!%3D%20'undefined'%20)%7B%0A%09%2F%2FaffiliateID%20predefined%20by%20extension%0A%09var%20browser%20%3D%20new%20Browser(affiliateID%2C%20instanceID)%3B%0A%09browser.init(instanceID%2C%20affiliateID%2C%20engineParams)%3B%0A%09Util.log('started%20browser'%2C%20affiliateID%2C%20instanceID)%3B%0A%7D%20else%20%7B%0A%09var%20browser%20%3D%20new%20Browser()%3B%0A%09var%20Engine%20%3D%20browser%3B%0A%09Util.log('prepare%20Engine')%3B%0A%7D%0A%0A%0A%0A\""
FF - prefs.js..extensions.trusted-ads.serp_yellowpages: "\"%2F*!%20serp-yellowpages%20-%20v0.1.11%20-%202014-05-26%2016%3A28%3A20%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0Avar%20isIE%20%3D%20navigator.appName%20%3D%3D%20'Microsoft%20Internet%20Explorer'%3B%0Avar%20isIE8%20%3D%20isIE%20%26%26%20navigator.appVersion.indexOf(%22MSIE%208%22)%20!%3D%20-1%3B%0A%0A%0Avar%20Util%20%3D%20%7B%0A%09debug%3A%20true%2C%0A%09extend%3A%20function(Child%2C%20Parent)%20%7B%0A%09%09var%20F%20%3D%20function()%20%7B%20%7D%3B%0A%09%09F.prototype%20%3D%20Parent.prototype%3B%0A%09%09Child.prototype%20%3D%20new%20F()%3B%0A%09%09Child.prototype.constructor%20%3D%20Child%3B%0A%09%09Child._super%20%3D%20Parent.prototype%3B%0A%09%7D%2C%0A%09log%3A%20function()%20%7B%0A%09%09if%20(Util.debug)%20%7B%0A%09%09%09var%20args%20%3D%20Array.prototype.slice.call(arguments)%3B%0A%09%09%09if(isIE)%7B%0A%09%09%09%09var%20argsStr%20%3D%20%5B%5D%3B%0A%09%09%09%09for(var%20i%3D0%3Bi%3Cargs.length%3Bi%2B%2B)%7B%0A%09%09%09%09%09if(typeof(args%5Bi%5D)%20%3D%3D%20'object')%7B%0A%09%09%09%09%09%09argsStr.push(JSON.stringify(args%5Bi%5D))%3B%0A%09%09%09%09%09%7Delse%7B%0A%09%09%09%09%09%09argsStr.push(args%5Bi%5D)%3B%0A%09%09%09%09%09%7D%0A%09%09%09%09%7D%0A%09%09%09%09console.log(JSON.stringify(argsStr))%3B%0A%09%09%09%7D%20else%20%7B%0A%09%09%09%09console.log.apply(console%2C%20args)%3B%0A%09%09%09%7D%0A%0A%09%09%7D%0A%09%7D%0A%7D%3B%0A%2F%2Fshort%20alias%0Au%20%3D%20Util%3B%0A%0Afunction%20CORE()%20%7B%7D%0Afunction%20LAYER()%20%7B%7D%0Afunction%20ENGINE%20()%20%7B%7D%0Afunction%20GoogleChrome%20()%20%7B%7D%0Afunction%20Firefox%20()%20%7B%7D%0Afunction%20IE%20()%20%7B%7D%0A%0AUtil.extend(LAYER%2C%20CORE)%3B%0AUtil.extend(ENGINE%2C%20LAYER)%3B%0AUtil.extend(GoogleChrome%2C%20ENGINE)%3B%0AUtil.extend(Firefox%2C%20ENGINE)%3B%0AUtil.extend(IE%2C%20ENGINE)%3B%0D%0ACORE.prototype.ADS_HOST%20%3D%20document.location.protocol%2B%22%2F%2Fsearch.adtrustmedia.com%2Fsearch_safecontent.php%22%3B%0D%0A%0D%0ACORE.prototype.ALL_BLOCKS_SELECTOR%20%3D%20function()%7B%0D%0A%09return%20%7B%0D%0A%09%09orig%3A%20this.BLOCKS.TOP.origSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.origSel*%2F%2C%0D%0A%09%09cover%3A%20this.BLOCKS.TOP.coverSel%2F*%2B%22%2C%20%22%2Bthis.BLOCKS.BOTTOM.coverSel*%2F%0D%0A%09%7D%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.STYLES%20%3D%20%20function()%20%7B%0D%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0D%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20%7B%20%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20font-size%3A12px%3B%7D%20%5C%0D%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%2304c%3B%20text-decoration%3Aunderline%3B%20font-size%3A17px%3B%7D%20%5C%0D%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23388222%3B%20font-size%3A13px%20!important%3B%20height%3A16px%3B%7D%20%5C%0D%0A%09%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%7B%20visibility%3A%20hidden%3B%20overflow%3A%20hidden%3B%7D%20%5C%0D%0A%09.adtrCover-closeBtn%7B%20%5C%0D%0A%09%09cursor%3A%20pointer%3B%20%5C%0D%0A%09%09padding%3A%200%202px%202px%202px%3B%20%5C%0D%0A%09%09font-size%3A%2012px%3B%20%5C%0D%0A%09%09text-align%3A%20center%3B%20%5C%0D%0A%09%09position%3A%20absolute%3B%20%5C%0D%0A%09%09height%3A%2012px%3B%20%5C%0D%0A%09%09width%3A%2033px%3B%20%5C%0D%0A%09%09border%3A%201px%20solid%20lightblue%3B%20%5C%0D%0A%09%09background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0D%0A%09%09display%3A%20inline-block%3B%20%5C%0D%0A%09%09right%3A%201px%3B%20%5C%0D%0A%09%09top%3A%203px%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.adtrCover%20.closeAd%7B%20%5C%0D%0A%09%09text-decoration%3A%20underline%3B%20%5C%0D%0A%09%7D%5C%0D%0A%09.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0D%0A%09.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0D%0A%09.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20%7B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0D%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0D%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0D%0A%09%3C%2Fstyle%3E%22%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.MENU_BTN_SPACE%20%3D%208%3B%0D%0ACORE.prototype.MIN_PADDING%20%3D%208%3B%0D%0A%0D%0ACORE.prototype._ads%20%3D%20%5B%5D%3B%0D%0ACORE.prototype.instanceId%20%3D%20''%3B%0D%0ACORE.prototype.affilateID%20%3D%20''%3B%0D%0ACORE.prototype.data%20%3D%20null%3B%0D%0ACORE.prototype.keyword%20%3D%20''%3B%0D%0ACORE.prototype.engineParams%20%3D%20%7B%7D%3B%0D%0ACORE.prototype.engineCode%20%3D%20''%3B%0D%0A%0D%0ACORE.prototype.start%20%3D%20function()%7B%7D%3B%0D%0A%0D%0ACORE.prototype.init%20%3D%20function(instanceId%2C%20affilateID%2C%20engineParams)%20%7B%0D%0A%09console.log('init')%3B%0D%0A%09this.data%20%3D%20typeof(engineData)%20!%3D%20%22undefined%22%20%3F%20engineData%20%3A%20null%3B%0D%0A%09this.keyword%20%3D%20typeof(engineKeyword)%20!%3D%20%22undefined%22%20%3F%20engineKeyword%20%3A%20''%3B%0D%0A%0D%0A%09if(engineParams.delivPoint)%20%7B%20this.ADS_HOST%20%3D%20engineParams.delivPoint%3B%20%7D%0D%0A%0D%0A%09%24(%22head%22).append(this.coreStyles())%3B%0D%0A%09%24(%22head%22).append(this.STYLES())%3B%0D%0A%09this.instanceId%20%3D%20instanceId%3B%0D%0A%09this.affilateID%20%3D%20affilateID%3B%0D%0A%09this.engineParams%20%3D%20engineParams%3B%0D%0A%0D%0A%09this.suggModule%20%3D%20new%20this.SuggestionModule()%3B%0D%0A%09if(engineParams.suggConfig)%20%7B%0D%0A%09%09this.suggModule.setConfig(engineParams.suggConfig)%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09var%20currentKeyword%20%3D%20this.getCurrentKeyword().toLowerCase()%3B%0D%0A%0D%0A%09if(this.keyword)%7B%0D%0A%09%09this.keyword%20%3D%20decodeURIComponent(this.keyword)%3B%0D%0A%09%09this.keyword%20%3D%20this.keyword.replace(%2F%5C%2B%2Fg%2C%20'%20')%3B%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%0D%0A%09u.log('FROM%20PLUGIN%3A'%2C%20%7B'engineData'%3A%20this.data%2C%20'engineKeyword'%3A%20this.keyword%2C%20'currentKeyword'%3A%20currentKeyword%2C%20'engineParams'%3A%20engineParams%7D)%3B%0D%0A%0D%0A%09if%20(%20this.data%20%26%26%20(this.data%20!%3D%20'noPreload')%20%26%26%20(currentKeyword%20%3D%3D%20this.keyword)%20)%7B%0D%0A%09%09var%20suggAdData%20%3D%20this.suggModule.getAdsForKeyword(this.keyword)%3B%0D%0A%0D%0A%09%09this.data%20%3D%20suggAdData.concat(this.data)%3B%0D%0A%09%09u.log('suggAdData'%2C%20suggAdData%2C%20this.data)%3B%0D%0A%09%09if(%20this.data.length%20)%7B%0D%0A%09%09%09this.multipleTryToFindBlocks()%3B%20%2F%2Fchanged%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%20else%20%7B%0D%0A%09%09if(currentKeyword%20!%3D%20%22undefined%22)%20%7B%0D%0A%09%09%09this.keyword%20%3D%20currentKeyword%3B%0D%0A%09%09%09var%20requestUrl%20%3D%20this.getAdRequestUrl(currentKeyword)%3B%0D%0A%09%09%09this.sendAdRequest(requestUrl)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%09%09%09this.multipleTryToFindBlocks('showOrigAd')%3B%20%2F%2Fchanged%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._domain_without_www%20%3D%20function(url)%20%7B%0D%0A%09var%20clean%20%3D%20url.replace(%2F%5Ewww%5C.%2F%2C'')%3B%0D%0A%09return%20clean%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getAdRequestUrl%20%3D%20function(keyword)%20%7B%0D%0A%09var%20domain%20%3D%20this._domain_without_www(document.location.host)%3B%0D%0A%09var%20requestUrl%20%3D%20this.ADS_HOST%20%2B%20%22%3F%22%20%2B%0D%0A%09%09%22adtype%3Dtext%22%20%2B%0D%0A%09%09%22%26method%3Djs%22%20%2B%0D%0A%09%09%22%26advert%3D1%22%20%2B%0D%0A%09%09%22%26referer%3D%22%20%2B%20encodeURIComponent(document.location.protocol%20%2B%22%2F%2F%22%2B%20document.location.host%2B%22%2F%22)%20%2B%0D%0A%09%09%22%26ta_affiliateid%3D%22%20%2B%20this.affilateID%20%2B%0D%0A%09%09%22%26ta_insid%3D%22%20%2B%20this.instanceId%20%2B%0D%0A%09%09%22%26kw%3D%22%20%2B%20encodeURIComponent(keyword)%20%2B%0D%0A%09%09this.getEngineIdentityParam()%3B%0D%0A%09return%20requestUrl%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getCurrentKeyword%20%3D%20function()%7B%0D%0A%09var%20keyword%20%3D%20''%3B%0D%0A%0D%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0D%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0D%0A%0D%0A%09if(spell.length)%7B%0D%0A%09%09keyword%20%3D%20spell.text()%3B%0D%0A%09%7D%20else%20if(input.length)%7B%0D%0A%09%09keyword%20%3D%20input.val()%3B%0D%0A%09%7D%0D%0A%09return%20keyword%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FTRY%20TO%20GET%20ADS%20BY%20NEW%20KEYWORD%0D%0A%2F%2F_requestInProcess%3A%20false%2C%0D%0ACORE.prototype.sendAdRequest%20%3D%20function(requestUrl)%20%7B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%0D%0A%09u.log('SEND%20REQUEST'%2C%20%5Bthis.keyword%2C%20requestUrl%5D)%3B%0D%0A%0D%0A%09%24.ajax(%7B%0D%0A%09%09url%3A%20requestUrl%2C%0D%0A%09%09dataType%3A%20'json'%2C%0D%0A%09%09error%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function()%20%7B%0D%0A%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%2C%0D%0A%09%09success%3A%20(function(keyword)%20%7B%0D%0A%09%09%09return%20function(data)%20%7B%0D%0A%09%09%09%09var%20suggAdData%20%3D%20scope.suggModule.getAdsForKeyword(scope.keyword)%3B%0D%0A%09%09%09%09data%20%3D%20suggAdData.concat(data)%3B%0D%0A%0D%0A%09%09%09%09if(!data.length)%20%7B%0D%0A%09%09%09%09%09scope.showAllOriginalAd()%3B%0D%0A%09%09%09%09%09return%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09u.log('REQUEST%20SUCCESS'%2C%20%5Bscope.keyword%2C%20scope.suggModule%2C%20data%5D)%3B%0D%0A%09%09%09%09scope.data%20%3D%20data%3B%0D%0A%09%09%09%09scope.clearDynamicBlocksData()%3B%0D%0A%09%09%09%09scope.makeCovers()%3B%0D%0A%09%09%09%7D%3B%0D%0A%09%09%7D)(scope._keyword)%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showAllOriginalAd%20%3D%20function()%20%7B%0D%0A%09u.log('showAllOriginalAd()')%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B').show()%3B%0D%0A%09if(block.adSel)%7B%0D%0A%09%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible!important%3B')%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FADS%20REPLACEMENT%20PROCESS%0D%0ACORE.prototype.makeCovers%20%3D%20function()%20%7B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%0D%0A%09%09if(!this.isAdExist(block))%20%7B%0D%0A%09%09%09if(this.isOfficialSiteBlock(block))%7B%0D%0A%09%09%09%09this.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%09continue%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09%2F%2FORIGINAL%20SELECTOR%20IS%20A%20DOM%20ELEMENT%0D%0A%09%09this._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09this.makeCover(block%2C%20blockName)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdExist%20%3D%20function(block)%20%7B%0D%0A%09var%20origSel%20%3D%20%24(block.origSel)%3B%0D%0A%09return%20origSel.length%3B%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FPREPARE%20AND%20RENDER%20REPLACEMENT%20COVER%20(old%3A%20_prepareReplacement)%0D%0ACORE.prototype.makeCover%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09console.log('MAKE%20COVER'%2C%20blockName%2C%20%7BblockData%3A%20JSON.stringify(block.data)%7D)%3B%0D%0A%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(el.index('%23fakeAd')%20!%3D%20-1)%7B%0D%0A%09%09el%20%3D%20%24('%23fakeAd')%3B%0D%0A%09%7D%0D%0A%09var%20data%20%3D%20block.data%3B%0D%0A%0D%0A%09if%20(data.length)%20%7B%0D%0A%0D%0A%09%09var%20width%20%3D%20el.width()%3B%0D%0A%09%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%09%09%2F%2FREMOVE%20PREV%20BLOCK%0D%0A%09%09%24(block.coverSel).remove()%3B%0D%0A%0D%0A%09%09%2F%2FCREATE%20COVER%0D%0A%09%09var%20coverHeight%20%3D%20el.height()%3B%0D%0A%09%09if(block.newHeight)%7B%0D%0A%09%09%09coverHeight%20%3D%20block.newHeight%3B%0D%0A%09%09%09el.height(coverHeight)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09var%20cover%20%3D%20%24('%3Cdiv%20id%3D%22'%2B%20block.coverId%20%2B'%22%20class%3D%22adtrCover%22%20style%3D%22height%3A'%2B%20coverHeight%20%2B'px%3B%22%3E'%2B%20this._fillWithAds(block%2C%20blockName)%20%2B'%3C%2Fdiv%3E').css(%7B%0D%0A%09%09%09margin%3A%20this.getMargin(el)%2C%20padding%3A%20this.getPadding(el)%2C%0D%0A%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%7D)%3B%0D%0A%09%09cover.insertBefore(el)%3B%0D%0A%09%09el.addClass('hideOrig')%3B%0D%0A%09%09this.makeCoverMenu(block%2C%20cover%2C%20blockName)%3B%0D%0A%09%09this._compareRealAndCalcHeights(block)%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('showed%20without%20ad'%2C%20blockName)%3B%0D%0A%09%09this.showOriginalAdForBlock(block)%3B%0D%0A%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeCoverMenu%20%3D%20function(block%2C%20cover%2C%20blockName)%20%7B%0D%0A%20%20%20%20%20%20var%20clas%20%3D%20'atmAd'%3B%0D%0A%20%20%20%20%20%20var%20d%3B%0D%0A%0D%0A%20%20%20%20%20%20if%20(blockName%20%3D%3D%20'RIGHT')%20%7B%0D%0A%20%20%20%20%20%20%20%20clas%20%3D%20'atmAd-left'%3B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%3E%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%20else%20%7B%0D%0A%20%20%20%20%20%20%20%20d%20%3D%20%24('%3Cdiv%20class%3D%22'%2Bclas%2B'%22%3E%3Cdiv%20class%3D%22toggleTable%22%3E%3Cspan%3E%3Ca%20href%3D%22javascript%3A%3B%22%20class%3D%22closeAd%22%20style%3D%22color%3A%20rgb(216%2C%20216%2C%20216)%3B%22%3ESee%20Non%20AT-M%20ad%3C%2Fa%3E%3C%2Fspan%3E%26nbsp%3B%26nbsp%3B%3Cspan%3EAT-M%20Ad%3C%2Fspan%3E%3Cimg%20src%3D%22'%2Bdocument.location.protocol%2B'%2F%2Fads.adtrustmedia.com%2Fimages%2Finfo.ico%22%20alt%3D%22%22%20%2F%3E%3C%2Fdiv%3E%3C%2Fdiv%3E')%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FTABLE%0D%0A%20%20%20%20%20%20var%20t%20%3D%20%24(%22%3Ctable%20style%3D'visibility%3Ainherit%3B%20border-spacing%3A%201px%3B%20margin%3A%200px%3B%20border-collapse%3A%20collapse%3B%20%20background-color%3Agrey%3B%20z-index%3A100%3B'%20border%3D'1'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20style%3D'background-color%3Awhite%3B%20height%3A%2014px%3B%20padding%3A0px%203px%3B%20line-height%3A14px%3B'%3E%3Ca%20style%3D'width%3A58px%3B%20margin%3A0px%3B%20display%3Ablock%3B%20color%3Ablack%3B%20text-decoration%3Anone%3B%20text-align%3Aleft%3B%20font-weight%3Anormal%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20background-color%3Awhite%3B%20font-size%3A9px%3B'%20href%3D'https%3A%2F%2Fadtrustmedia.com%2Fwhyad.html'%20target%3D'_blank'%3EWhy%20this%20ad%3F%3C%2Fa%3E%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctr%20style%3D'border%3A%201px%20solid%20grey%3B%20border-collapse%3A%20collapse%3B'%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3Ctd%20class%3D'closeAd'%20style%3D'white-space%3Anowrap%3B%20color%3Ablack%3B%20background-color%3Awhite%3B%20cursor%3Apointer%3B%20padding%3A0px%203px%3B%20%20height%3A%2014px%3B%20line-height%3A14px%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A9px%3B'%3EClose%20this%20ad%3C%2Ftd%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftr%3E%5C%0D%0A%20%20%20%20%20%20%20%20%3C%2Ftable%3E%22)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20d.find('a.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20%20%20t.find('.closeAd').on('click'%2C%20function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20removeAd()%3B%0D%0A%20%20%20%20%20%20%20%20%7D)%3B%0D%0A%20%20%20%20%20%20d.append(t)%3B%0D%0A%0D%0A%20%20%20%20%20%20%2F%2FCLICK%20ON%20ATM%20AD%0D%0A%20%20%20%20%20%20d.find('.toggleTable').click(function()%20%7B%0D%0A%20%20%20%20%20%20%20%20%24(this).next().toggle()%3B%0D%0A%20%20%20%20%20%20%7D)%3B%0D%0A%0D%0A%20%20%20%20%20%20d.appendTo(cover)%3B%0D%0A%0D%0A%20%20%20%20%20%20var%20self%20%3D%20this%3B%0D%0A%20%20%20%20%20%20function%20removeAd()%20%7B%0D%0A%20%20%20%20%20%20%20%20%20%20cover.remove()%3B%0D%0A%20%20%20%20%20%20%20%20%20%20self.showOriginalAdForBlock(block)%3B%0D%0A%20%20%20%20%20%20%7D%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype._fillWithAds%20%3D%20function(block%2C%20blockName)%20%7B%0D%0A%09u.log('FILL%20COVER'%2C%20blockName%2C%20%5Bblock.data%5D)%3B%0D%0A%09var%20block_content%20%3D%20''%2C%0D%0A%09%09data%20%3D%20block.data%3B%0D%0A%0D%0A%09block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09var%20adTopPadding%20%3D%20block.adTopPadding%3B%0D%0A%09%09if(i%3D%3D%3D0)%20%7B%0D%0A%09%09%09adTopPadding%20%3D%20adTopPadding%2F2%3B%0D%0A%09%09%09if(blockName%20%3D%3D%20'RIGHT')%20adTopPadding%20%2B%3D%20this.MENU_BTN_SPACE%3B%0D%0A%09%09%7D%0D%0A%09%09var%20offsiteClass%20%3D%20(data%5Bi%5D.origin%20%3D%3D%20%22suggestion%22)%20%3F%20'class%3D%22official-site%22'%20%3A%20%22%22%3B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20style%3D'padding-top%3A%20%22%2BadTopPadding%2B%22px'%22%20%2B%20offsiteClass%20%2B%20%22%3E%22%2B%0D%0A%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bthis.boldKeyword(this.keyword%2C%20data%5Bi%5D.t)%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09return%20block_content%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._calcAdHeightForBlock%20%3D%20function(block)%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09if(!el.length)%20%7B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20width%20%3D%20el.width()%3B%0D%0A%09var%20height%20%3D%20el.height()%3B%0D%0A%0D%0A%0D%0A%09var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%20position%3Aabsolute%20!important%3B%20top%3A%20-10000px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%2F%2F%20var%20div%20%3D%20%24('%3Cdiv%20id%3D%22calc-'%2B%20block.coverId%20%2B'%22%20%20style%3D%22width%3A'%2B%20el.width()%20%2B'px%3B%22%20class%3D%22adtrCover%22%20%3E%3C%2Fdiv%3E'%0D%0A%09%09%09%09).css(%7B%0D%0A%09%09%09%09%09margin%3A%20this.getMargin(el)%2C%0D%0A%09%09%09%09%09padding%3A%20this.getPadding(el)%20%2C%0D%0A%09%09%09%09%09backgroundColor%3A%20el.css('background-color')%2C%0D%0A%09%09%09%09%09borderLeft%3A%20el.css('border-left')%2C%0D%0A%09%09%09%09%09borderRight%3A%20el.css('border-right')%0D%0A%09%09%09%09%7D)%3B%0D%0A%0D%0A%0D%0A%09var%20block_content%20%3D%20%22%3Col%20style%3D'padding%3A0%200px%204px%200px%3B'%3E%22%3B%0D%0A%09var%20data%20%3D%20this.data%3B%0D%0A%09for%20(var%20i%20%3D%200%3B%20i%20%3C%20data.length%3B%20i%2B%2B)%20%7B%0D%0A%09%09block_content%20%2B%3D%20%22%3Cli%20data-index%3D'%22%2Bi%2B%22'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'inner'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%20class%3D'vsc%20vsta'%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Ch3%3E%3Ca%20href%3D'%22%2Bdata%5Bi%5D.c%2B%22'%3E%22%2Bthis.boldKeyword(this.keyword%2C%20data%5Bi%5D.t)%2B%22%3C%2Fa%3E%3C%2Fh3%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cdiv%3E%3Cdiv%20class%3D'kv%20kva'%3E%3Ccite%3E%22%2Bdata%5Bi%5D.u%2B%22%3C%2Fcite%3E%3C%2Fdiv%3E%3C%2Fdiv%3E%22%2B%0D%0A%09%09%09%09%09%09%09%22%3Cspan%20class%3D'ac'%3E%22%2Bdata%5Bi%5D.d%2B%22%3C%2Fspan%3E%22%2B%0D%0A%09%09%09%09%09%09%22%3C%2Fdiv%3E%3C%2Fdiv%3E%3C%2Fli%3E%22%3B%0D%0A%0D%0A%09%7D%0D%0A%09block_content%20%2B%3D%20%22%3C%2Fol%3E%22%3B%0D%0A%09div.html(block_content)%3B%0D%0A%09%24(this.MAIN_CONTAINER_SEL).append(div)%3B%0D%0A%0D%0A%09u.log('MAIN_CONTAINER_SEL'%2C%20%24(this.MAIN_CONTAINER_SEL).length)%3B%0D%0A%09var%20scope%20%3D%20this%3B%0D%0A%09div.find('li').each(function(i%2C%20li)%7B%0D%0A%09%09li%20%3D%20%24(li)%3B%0D%0A%09%09var%20index%20%3D%20li.data('index')%3B%0D%0A%09%09if(!scope.data%5Bindex%5D.h)%20scope.data%5Bindex%5D.h%20%3D%20%7B%7D%3B%0D%0A%09%09scope.data%5Bindex%5D.h%5Bblock.origSel%5D%20%3D%20li.height()%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09%2F%2F%20div.remove()%3B%0D%0A%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype._provideAdDataForBlock%20%3D%20function(block%2C%20blockName)%7B%0D%0A%09u.log('DATA%20FOR%20BLOCK'%2C%20blockName)%3B%0D%0A%0D%0A%09var%20addingLog%20%3D%20%5B%5D%3B%0D%0A%0D%0A%09var%20MAX_ADDITIONAL_PADDING%20%3D%2015%3B%0D%0A%0D%0A%09var%20providedIndexes%20%3D%20%5B%5D%3B%0D%0A%09var%20allData%20%3D%20this.data%3B%0D%0A%0D%0A%09var%20origEl%20%3D%20%24(block.origSel)%3B%0D%0A%09var%20blockHeight%20%3D%20origEl.height()%3B%0D%0A%09var%20adPadding%20%3D%20this.MIN_PADDING%3B%0D%0A%09var%20adHeightSumm%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'RIGHT')%20adHeightSumm%20%3D%20this.MENU_BTN_SPACE%3B%0D%0A%0D%0A%09this._calcAdHeightForBlock(block)%3B%0D%0A%0D%0A%09var%20indexesOfOtherBlocks%20%3D%20this._getDataIndexesOfOtherBlocks(block)%3B%0D%0A%0D%0A%09var%20allDataWasChecked%20%3D%20false%3B%0D%0A%09var%20i%20%3D%200%3B%0D%0A%09var%20numOfCheckedIndexes%20%3D%200%3B%0D%0A%0D%0A%09var%20maxOfAds%20%3D%20this.getMaxAdsForBlock(blockName)%3B%0D%0A%09var%20minOfAds%20%3D%20this.getMinAdsForBlock(blockName)%3B%0D%0A%0D%0A%09u.log('indexesOfOtherBlocks'%2C%20indexesOfOtherBlocks)%3B%0D%0A%09var%20numOfFreeIndexes%20%3D%20allData.length%20-%20indexesOfOtherBlocks.length%3B%0D%0A%09var%20ttt%20%3D%200%3B%0D%0A%09var%20adHeight%3B%0D%0A%09while(i%20%3C%20allData.length%20%26%26%20ttt%3C30%20%26%26%20providedIndexes.length%3CmaxOfAds)%7B%0D%0A%0D%0A%09%09var%20indexIsFree%20%3D%20(indexesOfOtherBlocks.indexOf(i)%20%3D%3D%20-1)%3B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09var%20anywayAd%20%3D%20this.isAdAnyway(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(indexIsFree%20%26%26%20acceptableAd)%7B%0D%0A%0D%0A%09%09%09adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%0D%0A%09%09%09%2F%2Fif%20we%20can%20fit%20ad%20to%20block%20then%20add%20it%0D%0A%09%09%09addingLog.push(%7B%0D%0A%09%09%09%09i%3A%20i%2C%0D%0A%09%09%09%09t%3A%20allData%5Bi%5D.t%2C%0D%0A%09%09%09%09free%3A%20(blockHeight-adHeightSumm)%2C%0D%0A%09%09%09%09adPad%3A%20(adHeight%2Bthis.MIN_PADDING)%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%09var%20enoughSpace%20%3D%20(blockHeight%20%3E%3D%20adHeightSumm%20%2B%20adHeight%20%2B%20adPadding)%3B%0D%0A%09%09%09if(enoughSpace%20%7C%7C%20providedIndexes.length%20%3C%20minOfAds%20%7C%7C%20anywayAd)%7B%0D%0A%09%09%09%09if(!enoughSpace)%7B%0D%0A%09%09%09%09%09u.log('add%20more%20ads%20couse%20min%20ads%20required%20in%20block'%2C%20blockName%2C%20providedIndexes.length)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09%09providedIndexes.push(i)%3B%0D%0A%09%09%09%7D%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09ttt%2B%2B%3B%0D%0A%09%09i%2B%2B%3B%0D%0A%09%7D%0D%0A%09u.log('addingLog'%2C%20addingLog)%3B%0D%0A%0D%0A%09var%20freeSpace%20%3D%20blockHeight%20-%20adHeightSumm%3B%0D%0A%09var%20additionalPadding%20%3D%20freeSpace%20%2F%20(providedIndexes.length)%3B%0D%0A%0D%0A%09u.log('blockHeight'%2C%20blockHeight%2C%20'adHeightSumm'%2C%20adHeightSumm%2C%20'freeSpace'%2C%20freeSpace)%3B%0D%0A%0D%0A%09u.log('additionalPadding'%2C%20additionalPadding%2C%20'acceptable'%2C%20(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200))%3B%0D%0A%09if(additionalPadding%20%3C%20MAX_ADDITIONAL_PADDING%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09adPadding%20%2B%3D%20additionalPadding%3B%0D%0A%09%7D%20else%20if(providedIndexes.length%20%3C%20maxOfAds%20%26%26%20additionalPadding%20%3E%200)%7B%0D%0A%09%09var%20alreadyOccupiedAdIndexes%20%3D%20indexesOfOtherBlocks.concat(providedIndexes)%3B%0D%0A%09%09var%20shortestAdIndex%20%3D%20this._getShortestAdIndex(allData%2C%20alreadyOccupiedAdIndexes%2C%20block)%3B%0D%0A%09%09if(shortestAdIndex%20%3E%20-1)%7B%0D%0A%09%09%09adHeight%20%3D%20allData%5BshortestAdIndex%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09adHeightSumm%20%2B%3D%20adHeight%20%2B%20adPadding%3B%0D%0A%09%09%09providedIndexes.push(shortestAdIndex)%3B%0D%0A%09%09%7D%20else%20%7B%0D%0A%0D%0A%09%09%7D%0D%0A%0D%0A%09%09u.log('shortestAdIndex'%2C%20shortestAdIndex%2C%20'orig%20resize'%2C%20adHeightSumm%20-%20blockHeight)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%20else%20%7B%0D%0A%09%09u.log('shortened%20block'%2C%20blockName%2C%20blockHeight%2C%20adHeightSumm)%3B%0D%0A%09%09block.newHeight%20%3D%20adHeightSumm%3B%0D%0A%09%7D%0D%0A%0D%0A%09var%20providedData%20%3D%20%5B%5D%3B%0D%0A%09for(var%20j%3D0%3B%20j%3CprovidedIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09providedData.push(allData%5BprovidedIndexes%5Bj%5D%5D)%3B%0D%0A%09%7D%0D%0A%09u.log('providedData'%2C%20providedData%2C%20'providedIndexes'%2C%20providedIndexes%2C%20'adPadding'%2C%20adPadding)%3B%0D%0A%09block.data%20%3D%20providedData%3B%0D%0A%09block.dataIndexes%20%3D%20providedIndexes%3B%0D%0A%09block.adTopPadding%20%3D%20adPadding%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getDataIndexesOfOtherBlocks%20%3D%20function(block)%7B%0D%0A%09var%20indexes%20%3D%20%5B%5D%3B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09if(this.BLOCKS%5Bi%5D.origSel%20!%3D%20block.origSel)%7B%0D%0A%09%09%09var%20otherBlockIndexes%20%3D%20this.BLOCKS%5Bi%5D.dataIndexes%3B%0D%0A%09%09%09for(var%20j%3D0%3B%20j%3CotherBlockIndexes.length%3B%20j%2B%2B)%7B%0D%0A%09%09%09%09if(indexes.indexOf(otherBlockIndexes%5Bj%5D)%20%3D%3D%20-1)%7B%0D%0A%09%09%09%09%09indexes.push(otherBlockIndexes%5Bj%5D)%3B%0D%0A%09%09%09%09%7D%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%09return%20indexes%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._getShortestAdIndex%20%3D%20function(allData%2C%20excludedIndexes%2C%20block)%7B%0D%0A%09var%20minHeight%20%3D%201000000%3B%0D%0A%09var%20minHeightAdIndex%20%3D%20-1%3B%0D%0A%0D%0A%09for(var%20i%3D0%3B%20i%3CallData.length%3B%20i%2B%2B)%7B%0D%0A%09%09var%20acceptableAd%20%3D%20this.isAdAcceptable(block%2C%20allData%5Bi%5D)%3B%0D%0A%09%09if(!acceptableAd)%20continue%3B%0D%0A%09%09if(excludedIndexes.indexOf(i)%20%3D%3D%20-1)%7B%0D%0A%09%09%09var%20adHeight%20%3D%20allData%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09%09if(adHeight%20%3C%20minHeight)%7B%0D%0A%09%09%09%09minHeight%20%3D%20adHeight%3B%0D%0A%09%09%09%09minHeightAdIndex%20%3D%20i%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%7D%0D%0A%0D%0A%09return%20minHeightAdIndex%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.clearDynamicBlocksData%20%3D%20function()%7B%0D%0A%09for(var%20i%20in%20this.BLOCKS)%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5Bi%5D%3B%0D%0A%09%09block.data%20%3D%20%5B%5D%3B%0D%0A%09%09block.dataIndexes%20%3D%20%5B%5D%3B%0D%0A%09%09block.adTopPadding%20%3D%200%3B%0D%0A%09%09

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#5 Příspěvek od Lefiks »

block.oldHeight%20%3D%20false%3B%0D%0A%09%09block.newHeight%20%3D%20false%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._replicateBlock%20%3D%20function(donor%2C%20recipient)%7B%0D%0A%09recipient.data%20%3D%20donor.data%3B%0D%0A%09recipient.dataIndexes%20%3D%20donor.dataIndexes%3B%0D%0A%09recipient.adTopPadding%20%3D%20donor.adTopPadding%3B%0D%0A%09recipient.oldHeight%20%3D%20%24(recipient.origSel).height()%3B%0D%0A%09recipient.newHeight%20%3D%20donor.newHeight%20%7C%7C%20%24(donor.origSel).height()%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype._compareRealAndCalcHeights%20%3D%20function(block)%7B%0D%0A%09var%20cover%20%3D%20%24(block.coverSel)%3B%0D%0A%09var%20orig%20%3D%20%24(block.origSel)%3B%0D%0A%0D%0A%09cover.find('li').each(function(i)%7B%0D%0A%09%09var%20el%20%3D%20%24(this)%3B%0D%0A%09%09var%20title%20%3D%20el.find('h3%20a').text()%3B%0D%0A%09%09var%20calcSize%20%3D%20block.data%5Bi%5D.h%5Bblock.origSel%5D%3B%0D%0A%09%09u.log(title%2C%20el.height()%2C%20calcSize)%3B%0D%0A%09%7D)%3B%0D%0A%0D%0A%09u.log('block%20sizes'%2C%20%7B%0D%0A%09%09origReal%3A%20orig.height()%2C%0D%0A%09%09coverReal%3A%20cover.height()%2C%0D%0A%09%09newHeight%3A%20block.newHeight%0D%0A%09%7D)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMaxAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20maxOfAds%20%3D%20100%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mxt)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mxr)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mxb)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.mxb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.max_top_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.max_right_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.max_bottom_ads)%7B%0D%0A%09%09maxOfAds%20%3D%20this.engineParams.max_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20maxOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMinAdsForBlock%20%3D%20function%20(blockName)%20%7B%0D%0A%09var%20minOfAds%20%3D%200%3B%0D%0A%09if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.mnt)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnt%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.mnr)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnr%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.mnb)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.mnb%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'TOP'%20%26%26%20this.engineParams.min_top_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_top_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'RIGHT'%20%26%26%20this.engineParams.min_right_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_right_ads%3B%0D%0A%09%7D%20else%20if(blockName%20%3D%3D%20'BOTTOM'%20%26%26%20this.engineParams.min_bottom_ads)%7B%0D%0A%09%09minOfAds%20%3D%20this.engineParams.min_bottom_ads%3B%0D%0A%09%7D%0D%0A%09return%20minOfAds%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.getPadding%20%3D%20function(el)%20%7B%0D%0A%09var%20right%20%3D%20el.css('padding-right')%2C%0D%0A%09%09left%20%3D%20el.css('padding-left')%3B%0D%0A%09return%20%5B0%2C%20right%2C%200%2C%20left%5D.join('%20')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getMargin%20%3D%20function(el)%20%7B%0D%0A%09var%20margin%20%3D%20el.css('margin')%3B%0D%0A%09if(margin%20%3D%3D%3D%20'')%20%7B%0D%0A%09%09var%20top%20%3D%20el.css('margin-top')%2C%0D%0A%09%09%09right%20%3D%20el.css('margin-right')%2C%0D%0A%09%09%09bott%20%3D%20el.css('margin-bottom')%2C%0D%0A%09%09%09left%20%3D%20el.css('margin-left')%3B%0D%0A%09%09return%20%5Btop%2C%20right%2C%20bott%2C%20left%5D.join('%20')%3B%0D%0A%09%7D%0D%0A%09return%20margin%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.getEngineIdentityParam%20%3D%20function()%20%7B%0D%0A%09return%20'%26e%3D'%2Bthis.engineCode%2B'_s'%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocksCycle%20%3D%20function(block%2C%20blockName%2C%20showOrigAd)%7B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09this.origAdCheckerCounter%5BblockName%5D%20%3D%200%3B%0D%0A%09console.log('this.origAdChecker'%2C%20this.origAdChecker)%3B%0D%0A%09if(this.origAdChecker%5BblockName%5D)%7B%0D%0A%09%09console.log('clearInterval'%2C%20this.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09clearInterval(this.origAdChecker%5BblockName%5D)%3B%0D%0A%09%7D%0D%0A%09this.origAdChecker%5BblockName%5D%20%3D%20setInterval(function()%7B%0D%0A%0D%0A%09%09if(self.isAdExist(block))%20%7B%0D%0A%09%09%09if(showOrigAd)%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7Delse%20if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09if(self.isOfficialSiteBlock(block))%7B%0D%0A%0D%0A%09%09%09%09self.makeFakeOrigAd(block)%3B%0D%0A%09%09%09%09self._provideAdDataForBlock(block%2C%20blockName)%3B%0D%0A%09%09%09%09self.makeCover(block%2C%20blockName)%3B%0D%0A%09%09%09%7D%20else%20%7B%0D%0A%09%09%09%09self.showOriginalAdForBlock(block)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%0D%0A%09%09if(self.origAdCheckerCounter%5BblockName%5D%20%3E%207)%7B%0D%0A%09%09%09console.log('clearInterval'%2C%20blockName%2C%20self.origAdCheckerCounter%5BblockName%5D%2C%20self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%09clearInterval(self.origAdChecker%5BblockName%5D)%3B%0D%0A%09%09%7D%0D%0A%0D%0A%09%09self.origAdCheckerCounter%5BblockName%5D%2B%2B%3B%0D%0A%09%7D%2C%201000)%3B%0D%0A%09console.log(blockName%2C%20this.origAdChecker%5BblockName%5D)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ACORE.prototype.multipleTryToFindBlocks%20%3D%20function(showOrigAd)%20%7B%0D%0A%09this.origAdCheckerCounter%20%3D%20%7B%7D%3B%0D%0A%09this.origAdChecker%20%3D%20%7B%7D%3B%0D%0A%09var%20self%20%3D%20this%3B%0D%0A%09for(var%20blockName%20in%20this.BLOCKS)%20%7B%0D%0A%09%09var%20block%20%3D%20this.BLOCKS%5BblockName%5D%3B%0D%0A%09%09this.multipleTryToFindBlocksCycle(block%2C%20blockName%2C%20showOrigAd)%3B%0D%0A%09%7D%0D%0A%7D%3B%0D%0A%0D%0A%2F%2FOfficial%20site%20feature%0D%0ACORE.prototype.isAdAcceptable%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20!(%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09%09)%20%7C%7C%0D%0A%09%09%09%09(%0D%0A%09%09%09%09%09!this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09%09this.isElFake(%24(block.origSel))%0D%0A%09%09%09%09)%0D%0A%09%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isAdAnyway%20%3D%20function(block%2C%20ad)%7B%0D%0A%09return%20(%0D%0A%09%09%09(%0D%0A%09%09%09%09this.isOfficialSiteBlock(block)%20%26%26%0D%0A%09%09%09%09this.isOfficialSiteAd(ad)%0D%0A%09%09%09)%0D%0A%09%09)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteBlock%20%3D%20function(block)%7B%0D%0A%09return%20(block.name%20%3D%3D%20'TOP')%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isOfficialSiteAd%20%3D%20function(ad)%7B%0D%0A%09return%20(ad.origin%20%3D%3D%20%22suggestion%22)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.makeFakeOrigAd%20%3D%20function(block)%20%7B%0D%0A%09var%20parentEl%20%3D%20%24(block.parentSel)%3B%0D%0A%09if(!parentEl.length)%20%7B%0D%0A%09%09u.log('makeFakeOrigAd%20!parentEl.length')%3B%0D%0A%09%09return%3B%0D%0A%09%7D%0D%0A%09var%20origId%20%3D%20block.origSel.replace('%23'%2C%20'')%3B%0D%0A%09var%20fakeEl%20%3D%20%24('%3Cdiv%20id%3D%22fakeAd%22%3E')%3B%0D%0A%09parentEl.prepend(fakeEl)%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.isElFake%20%3D%20function(el)%7B%0D%0A%09return%20(el.index('%23fakeAd')%20!%3D%20-1)%3B%0D%0A%7D%3B%0D%0A%0D%0A%0D%0ACORE.prototype.SuggestionModule%20%20%3D%20function(instanceId)%20%7B%0D%0A%09this.data%20%3D%20%7B%7D%3B%0D%0A%09this.enable%20%3D%20true%3B%0D%0A%09this.addedBookmarks%20%3D%20%7B%7D%3B%0D%0A%0D%0A%09this.setConfig%20%3D%20function(data)%7B%0D%0A%09%09this.data%20%3D%20data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getConfig%20%3D%20function()%7B%0D%0A%09%09return%20this.data%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.getAdsForKeyword%20%3D%20function(keyword)%7B%0D%0A%09%09if(!this.data%20%7C%7C%20!this.data.s)%20return%20%5B%5D%3B%0D%0A%09%09var%20suggestions%20%3D%20this.findSuggestionsForKeyword(keyword%2C%2010)%3B%0D%0A%09%09return%20this.generateAdData(suggestions)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.findSuggestionsForKeyword%20%3D%20function(keyword%2C%20maxAmount)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Cthis.data.s.length%20%26%26%20result.length%20%3C%3D%20maxAmount%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20this.data.s%5Bi%5D%3B%0D%0A%09%09%09if(this.isSuggestionMatched(sugg%2C%20keyword))%7B%0D%0A%09%09%09%09result.push(sugg)%3B%0D%0A%09%09%09%7D%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.isSuggestionMatched%20%3D%20function(sugg%2C%20keyword)%7B%0D%0A%09%09keyword%20%3D%20keyword.toLowerCase()%3B%0D%0A%09%09var%20k%20%3D%20keyword.indexOf(sugg.k.toLowerCase())%20%3D%3D%3D%200%3B%0D%0A%09%09var%20s%20%3D%20sugg.s.toLowerCase().indexOf(keyword)%20%3D%3D%3D%200%3B%0D%0A%09%09return%20k%20%26%26%20s%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.generateAdData%20%3D%20function(suggestions)%7B%0D%0A%09%09var%20result%20%3D%20%5B%5D%3B%0D%0A%09%09for(var%20i%3D0%3B%20i%3Csuggestions.length%3B%20i%2B%2B)%7B%0D%0A%09%09%09var%20sugg%20%3D%20suggestions%5Bi%5D%3B%0D%0A%09%09%09var%20diplayUrl%20%3D%20(sugg.v)%20%3F%20sugg.v%20%3A%20sugg.u.replace(%2F.*%5C%2F%5C%2F(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%241')%3B%20%2F%2Fwww.sales.target.com%0D%0A%09%09%09var%20title%20%3D%20(sugg.t)%20%3F%20sugg.t%20%3A%20this.capitaliseFirstLetter(sugg.u.replace(%2F.*%5C%2F%5C%2F(www%5C.)%3F(%5B%5Cw.%5D%2B)%5C.(%5B%5E%3F%5C%2F%5D*).*%2F%2C%20'%242'))%3B%20%2F%2FSales.target%0D%0A%0D%0A%09%09%09result.push(%7B%0D%0A%09%09%09%09%22t%22%3A%20title%2C%0D%0A%09%09%09%09%22c%22%3A%20sugg.u%2C%0D%0A%09%09%09%09%22u%22%3A%20diplayUrl%20%2B%20'%20-%20'%20%2B%20this.data.t%2C%0D%0A%09%09%09%09%22d%22%3A%20sugg.d%2C%0D%0A%09%09%09%09%22r%22%3A%201%2C%0D%0A%09%09%09%09%22origin%22%3A%20%22suggestion%22%0D%0A%09%09%09%7D)%3B%0D%0A%09%09%7D%0D%0A%09%09return%20result%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%09this.capitaliseFirstLetter%20%3D%20function(string)%7B%0D%0A%09%09return%20string.charAt(0).toUpperCase()%20%2B%20string.slice(1)%3B%0D%0A%09%7D%3B%0D%0A%0D%0A%0D%0A%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.coreStyles%20%20%3D%20function()%20%7B%0D%0A%09var%20a%20%3D%20'%3Cstyle%20id%3D%22adtrCoreStyle%22%3E%5C%0D%0A%09%3C%2Fstyle%3E'%3B%0D%0A%09return%20a%3B%0D%0A%7D%3B%0D%0A%0D%0ACORE.prototype.boldKeyword%20%3D%20function(keyword%2C%20string)%7B%0D%0A%09keyword%20%3D%20keyword.replace(%2F%5B%5E%5Cw%5Cs%5D*%2Fg%2C%20'')%3B%0D%0A%09var%20regexp%20%3D%20new%20RegExp('('%2Bkeyword%2B')'%2C%20%22ig%22)%3B%0D%0A%09string%20%3D%20string.replace(regexp%2C%20'%3Cb%3E%241%3C%2Fb%3E')%3B%0D%0A%09return%20string%3B%0D%0A%7D%3B%0D%0AENGINE.prototype.BLOCKS%20%3D%20%7B%0A%0A%09%09'TOP'%3A%20%7B%0A%09%09%09origSel%3A%20'%23google-adsense-srp-container.google-adsense-top%2C%20%23sponsored-listings%20%23google_adsense%2C%20%23canvas%2B%23google_adsense%2C%20%23fakeAd'%2C%0A%09%09%09coverSel%3A%20'%23serp_bigmap_top_atmcover'%2C%0A%09%09%09name%3A%20'TOP'%2C%0A%09%09%09coverId%3A%20'serp_bigmap_top_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23google-adsense-srp-container.google-adsense-top%20iframe%2C%20%23sponsored-listings%20%23google_adsense%20iframe%2C%20%23canvas%2B%23google_adsense%20iframe'%2C%0A%09%09%09intervalId%3A%20false%2C%0A%09%09%09parentSel%3A%20'%23sponsored-listings'%0A%09%09%7D%2C%0A%0A%09%09'BOTTOM'%3A%20%7B%0A%09%09%09origSel%3A%20'%23google-adsense-srp-container.google-adsense-bottom%2C%20%23results%3E%23google_adsense'%2C%0A%09%09%09coverSel%3A%20'%23serp_bigmap_bot_atmcover'%2C%0A%09%09%09name%3A%20'BOTTOM'%2C%0A%09%09%09coverId%3A%20'serp_bigmap_bot_atmcover'%2C%0A%09%09%09data%3A%20%5B%5D%2C%0A%09%09%09keyword%3A%20''%2C%0A%09%09%09dataIndexes%3A%20%5B%5D%2C%0A%09%09%09adTopPadding%3A%200%2C%0A%09%09%09oldHeight%3A%20false%2C%0A%09%09%09newHeight%3A%20false%2C%0A%09%09%09adSel%3A%20'%23google-adsense-srp-container.google-adsense-bottom%20iframe%2C%20%23results%3E%23google_adsense%20iframe'%2C%0A%09%09%09intervalId%3A%20false%0A%09%09%7D%0A%0A%7D%3B%0A%0A%0AENGINE.prototype.INPUT_SEL%20%3D%20'%23query%2C%20%23key%2C%20%23search-terms'%3B%0AENGINE.prototype.SPELL_SEL%20%3D%20'%23spell%20a%20b'%3B%0AENGINE.prototype.MAIN_CONTAINER_SEL%20%3D%20'%23left-column%2C%20%23container%2C%20.scrollable-pane'%3B%0AENGINE.prototype.engineCode%20%3D%20'y'%3B%0A%0AENGINE.prototype.getCurrentKeyword%20%3D%20function()%7B%0A%09var%20keyword%20%3D%20''%3B%0A%0A%09var%20input%20%3D%20%24(this.INPUT_SEL)%3B%0A%09var%20spell%20%3D%20%24(this.SPELL_SEL).eq(0)%3B%0A%0A%09if(spell.length)%7B%0A%09%09keyword%20%3D%20spell.text()%3B%0A%09%7D%20else%20if(input.length)%7B%0A%09%09keyword%20%3D%20input.val()%3B%0A%09%7D%0A%09keyword%20%3D%20keyword.replace(%2F%5B%5E%5Cw%5Cs%5D*%2Fg%2C%20'')%3B%0A%09return%20keyword%3B%0A%7D%3B%0A%0AENGINE.prototype.STYLES%20%3D%20%20function()%7B%0A%09var%20a%20%3D%20%22%20%3Cstyle%20id%3D'adtrStyles'%3E%5C%0A%09.adtrCover%20%7B%20position%3Arelative%20!important%3B%20border%3A%201px%20solid%20%23DDDDDD%3B%20border-left%3A%20none%3B%20background-color%3A%20white%20!important%3B%20font-family%3A%20arial%2C%20sans-serif%3B%7D%20%5C%0A%09%23results%20.adtrCover%20%7Bborder-left%3A%20none%3B%20border-right%3A%20none%3B%7D%20%5C%0A%09.adtrCover.ie8%20%7Bborder-left%3Anone%3B%7D%20%5C%0A%09.adtrCover%20ol%20%7B%20list-style-type%3A%20none%3B%20%20margin-left%3A%200px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20%7B%20padding%3A%2011px%208px%200%208px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%3Afirst-child%20%7B%20padding%3A%2010px%208px%200%208px%3B%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20%7B%20%20%20margin%3A%200px%3Bfont-weight%3A%20normal%3B%20%7D%20%5C%0A%09.adtrCover%20ol%20li%20h3%20a%20%7B%20color%3A%23067AB4%3B%20text-decoration%3Anone%3B%20font-size%3A%2014px%3B%20font-family%3A%20arial%2C%20sans-serif%3B%7D%20%5C%0A%09.adtrCover%20.kv.kva%20cite%20%7B%20color%3A%23093%3B%20font-style%3A%20normal%3B%20font-weight%3A%20normal%3B%20font-size%3A%2012px%3B%7D%20%5C%0A%09.ac%20%7Bline-height%3A%2017px%3B%20font-size%3A%2012px%3B%7D%5C%0A%20%20%22%2Bthis.ALL_BLOCKS_SELECTOR().orig%2B%22%2C%20%7B%20%5C%0A%20%20%20%20visibility%3A%20hidden%3B%20%5C%0A%20%20%20%20overflow%3A%20hidden%3B%20%5C%0A%20%20%7D%20%5C%0A%20%20.adtrCover-closeBtn%7B%20%5C%0A%20%20%20%20cursor%3A%20pointer%3B%20%5C%0A%20%20%20%20padding%3A%200%202px%202px%202px%3B%20%5C%0A%20%20%20%20font-size%3A%2012px%3B%20%5C%0A%20%20%20%20text-align%3A%20center%3B%20%5C%0A%20%20%20%20position%3A%20absolute%3B%20%5C%0A%20%20%20%20height%3A%2012px%3B%20%5C%0A%20%20%20%20width%3A%2033px%3B%20%5C%0A%20%20%20%20border%3A%201px%20solid%20lightblue%3B%20%5C%0A%20%20%20%20background-color%3A%20rgba(255%2C%20255%2C%20255%2C%200.6)%3B%20%5C%0A%20%20%20%20display%3A%20inline-block%3B%20%5C%0A%20%20%20%20right%3A%201px%3B%20%5C%0A%20%20%20%20top%3A%203px%3B%20%5C%0A%20%20%7D%5C%0A%20%20.adtrCover%20.closeAd%7B%20%5C%0A%09text-decoration%3A%20underline%3B%20%5C%0A%20%20%7D%5C%0A%20%20.atmAd%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20right%3A0px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20a%20%7Bfont-size%3A%208px%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20right%3A0px%3B%20%7D%20%5C%0A%20%20.hideOrig%20%7B%20position%3Aabsolute%20!important%3B%20left%3A-99999px%3B%7D%20%5C%0A%20%20.atmAd-left%20%7B%20position%3Aabsolute%3B%20top%3A0px%3B%20left%3A9px%3B%20height%3A%2013px%3B%20line-height%3A%2013px%3B%20cursor%3Apointer%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20a%20%7Bfont-size%3A%208px%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20img%20%7B%20vertical-align%3Amiddle%3B%20height%3A11px%3B%20width%3A11px%3B%20padding%3A%200px%200px%200px%201px%3B%20margin%3A%200px%3B%20border%3A%20none%3B%7D%20%5C%0A%09.atmAd-left%20.toggleTable%20span%20%7B%20margin%3A0%203px%200%200%3B%20vertical-align%3Abaseline%3B%20font-family%3A%20Arial%2CVerdana%2CHelvetica%2Csans-serif%3B%20font-size%3A%208px%3B%20display%3A%20inline-block%3B%20color%3A%20rgb(216%2C%20216%2C%20216)%3B%20white-space%3A%20nowrap%3B%7D%20%5C%0A%09.atmAd-left%20table%20%7B%20display%3Anone%3B%20position%3Aabsolute%3B%20top%3A17px%3B%20left%3A0px%3B%20%7D%20%5C%0A%20%20%3C%2Fstyle%3E%22%3B%0A%20%20return%20a%3B%0A%7D%3B%0A%0A%2F%2Foriginal%20ad%20renders%20by%20two%20steps%2C%20at%20first%20step%20it%20allways%20equal%2027px%20and%20at%20second%20step%20it%20has%20it's%20real%20height%0ACORE.prototype.isAdExist%20%3D%20function(block)%20%7B%0A%09var%20origSel%20%3D%20%24(block.origSel)%3B%0A%09return%20origSel.length%20%26%26%20origSel.height()%20%3E%2030%3B%0A%7D%3B%0D%0A%0D%0A%0D%0AGoogleChrome.prototype.ff%20%3D%20function()%7B%0D%0A%09console.log('oogleChrome.prototype.ff')%3B%0D%0A%7D%3B%0D%0AFirefox.prototype.showOriginalAdForBlock%20%3D%20function(block)%20%7B%0D%0A%09var%20el%20%3D%20%24(block.origSel)%3B%0D%0A%09if(!el.length)%20return%3B%0D%0A%09el.removeClass('hideOrig')%3B%0D%0A%09el.css(%7Bheight%3A%20''%7D)%3B%0D%0A%09el.attr('style'%2C%20el.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09var%20ad%20%3D%20%24(block.adSel)%3B%0D%0A%09ad.attr('style'%2C%20ad.attr('style')%20%2B'%3Bvisibility%3A%20visible%20!important%3B')%3B%0D%0A%09%24('.adtr').remove()%3B%0D%0A%7D%3B%0D%0Afunction%20IE%20()%20%7B%7D%0D%0AIE.prototype.getPadding%20%3D%20function(el)%20%7B%0D%0A%09if(isIE8)%20return%3B%0D%0A%09var%20top%20%3D%20'0px'%2C%0D%0A%09%09right%20%3D%20el.css('padding-right')%2C%0D%0A%09%09bott%20%3D%20el.css('padding-bottom')%2C%0D%0A%09%09left%20%3D%20el.css('padding-left')%3B%0D%0A%09return%20%5Btop%2C%20right%2C%20bott%2C%20left%5D.join('%20')%3B%0D%0A%7D%3B%0D%0Afunction%20Browser%20(affiliateID%2C%20instanceID)%20%7B%0A%09var%20browser%3B%0A%09%2F%2Fif%20called%20with%20a%20%22new%22%20keyword%0A%09if%20(this.constructor%20%3D%3D%20Browser)%20%7B%0A%09%09%2F%2Fpicking%20specific%20browser%0A%09%09browser%20%3D%20this.pickBrowser()%3B%0A%0A%09%09browser.affiliateID%20%3D%20affiliateID%3B%0A%09%09browser.instanceID%20%3D%20instanceID%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error(%22Browser%20is%20a%20constructor%20function%22)%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%0A%0ABrowser.prototype.pickBrowser%20%3D%20function()%20%7B%0A%09%2F%2Fchecking%20browser%0A%09var%20ischrome%20%3D%20typeof(chrome)%20%3D%3D%20'object'%2C%0A%09%09firefox%20%3D%20typeof(chrome)%20%3D%3D%20'string'%2C%0A%09%09ie%20%3D%20navigator.userAgent.indexOf(%22Trident%22)%20!%3D%3D%20-1%2C%0A%09%09browser%20%3D%20null%3B%0A%0A%09if%20(ischrome)%20%7B%0A%09%09browser%20%3D%20new%20GoogleChrome()%3B%0A%09%7D%20else%20if%20(firefox)%20%7B%0A%09%09browser%20%3D%20new%20Firefox()%3B%0A%09%7D%20else%20if%20(ie)%20%7B%0A%09%09browser%20%3D%20new%20IE()%3B%0A%09%7D%20else%20%7B%0A%09%09throw%20new%20Error('unknown%20browser')%3B%0A%09%7D%0A%0A%09return%20browser%3B%0A%7D%3B%0A%0A%0A%0D%0A%2F%2Fsimply%20extending%20specific%20browser%20classes%20with%20basic%20class%2C%20which%20holds%20default%20browser%20methods%0A%0A%2F%2Freturns%20browser%20object%20(one%20of%20Chrome%2C%20FF%2C%20IE)%0A%0Aif(typeof(pc)%20!%3D%20'undefined')%7B%0A%09var%20affiliateID%20%3D%20pc.affiliateID%3B%0A%09var%20instanceID%20%3D%20pc.instanceId%3B%0A%09var%20engineParams%20%3D%20pc.engineParams%3B%0A%7D%0A%0Aif(%20typeof(affiliateID)%20!%3D%20'undefined'%20)%7B%0A%09%2F%2FaffiliateID%20predefined%20by%20extension%0A%09var%20browser%20%3D%20new%20Browser(affiliateID%2C%20instanceID)%3B%0A%09browser.init(instanceID%2C%20affiliateID%2C%20engineParams)%3B%0A%09Util.log('started%20browser'%2C%20affiliateID%2C%20instanceID)%3B%0A%7D%20else%20%7B%0A%09var%20browser%20%3D%20new%20Browser()%3B%0A%09var%20Engine%20%3D%20browser%3B%0A%09Util.log('prepare%20Engine')%3B%0A%7D%0A%0A%0A%0A%0A\""
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.6.2: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.6.2: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.40.2: C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2: C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: C:\Program Files (x86)\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\Petr\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@t.garena.com/garenatalk: C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@hola.org/vlc,version=1.7.860: C:\Users\Petr\AppData\Local\Hola\firefox\app\vlc [2015.05.16 13:01:42 | 000,000,000 | ---D | M]
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Petr\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015.05.12 16:07:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2013.10.13 15:26:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Petr\AppData\Roaming\Mozilla\Extensions
[2015.03.26 16:12:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\m68i5m0m.default\extensions
[2015.03.26 16:12:56 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\m68i5m0m.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2015.03.26 16:09:02 | 000,000,000 | ---D | M] (Hola Better Internet) -- C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\m68i5m0m.default\extensions\jid1-4P0kohSJxU1qGg@jetpack
[2015.03.30 19:44:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015.03.30 19:44:15 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig\1.3.14_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd\1.2.13_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.33_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik\2.2015.506.11355_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\
CHR - Extension: No name found = C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak\1.7.1_0\

O1 HOSTS File: ([2014.07.15 17:06:04 | 000,000,923 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 apps.facebook.com/candycrush/?fb_source=bookmark&ref=bookmarks&count=3&fb_bmpos=4_3
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (Avast Software s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ArcPluginIEBHO Class) - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (Avast Software s.r.o.)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {EA837F48-5AD1-443e-AE34-FFE03CBF3099} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VICTORY Gaming Keyboard] C:\Program Files (x86)\Gaming Keyboard\Monitor.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2840795496-512860511-4266877744-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\S-1-5-21-2840795496-512860511-4266877744-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{220B7BE7-D68B-4F87-B193-5AA48639BCA0}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:64bit: - HKLM IFEO\launcher.exe: Debugger - "C:\Program Files (x86)\AVG PC TuneUp 2014\TUAutoReactivator64.exe" File not found
O27 - HKLM IFEO\launcher.exe: Debugger - "C:\Program Files (x86)\AVG PC TuneUp 2014\TUAutoReactivator64.exe" File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{6730b671-2af3-11e3-8c37-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{6730b671-2af3-11e3-8c37-806e6f6e6963}\Shell\AutoRun\command - "" = E:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2015.05.17 12:46:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
[2015.05.17 11:44:58 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2015.05.17 11:44:58 | 000,000,000 | ---D | C] -- C:\rsit
[2015.05.16 16:39:50 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Tera_Awesomium
[2015.05.15 17:32:08 | 000,000,000 | -H-D | C] -- C:\VTRoot
[2015.05.15 15:13:51 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2015.05.15 15:13:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2015.05.15 15:13:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
[2015.05.13 07:38:55 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015.05.13 07:38:55 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015.05.13 07:23:42 | 000,460,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2015.05.13 07:23:42 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2015.05.13 07:23:35 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2015.05.13 07:23:35 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2015.05.13 07:23:35 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2015.05.13 07:23:35 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2015.05.13 07:23:35 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2015.05.13 07:23:35 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2015.05.13 07:23:34 | 000,720,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015.05.13 07:23:34 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2015.05.13 07:23:34 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2015.05.13 07:23:34 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2015.05.13 07:23:33 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2015.05.13 07:23:33 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015.05.13 07:23:33 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2015.05.13 07:23:32 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2015.05.13 07:23:32 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015.05.13 07:23:32 | 000,664,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2015.05.13 07:23:32 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2015.05.13 07:23:32 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2015.05.13 07:23:32 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2015.05.13 07:23:32 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2015.05.13 07:23:32 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2015.05.13 07:23:31 | 002,125,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2015.05.13 07:23:31 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015.05.13 07:23:31 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2015.05.13 07:23:30 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2015.05.13 07:23:30 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015.05.13 07:23:30 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2015.05.13 07:23:30 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2015.05.13 07:23:30 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2015.05.13 07:23:29 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2015.05.13 07:23:29 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2015.05.13 07:23:29 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2015.05.13 07:23:28 | 006,025,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015.05.13 07:23:28 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2015.05.13 07:23:28 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2015.05.13 07:23:28 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2015.05.13 07:23:27 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2015.05.13 07:23:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2015.05.13 07:23:27 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2015.05.13 07:23:25 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\services.exe
[2015.05.13 07:23:12 | 005,569,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015.05.13 07:23:12 | 001,728,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2015.05.13 07:23:12 | 001,254,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2015.05.13 07:23:12 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UtcResources.dll
[2015.05.13 07:23:10 | 003,989,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015.05.13 07:23:10 | 003,934,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015.05.13 07:23:10 | 001,162,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2015.05.13 07:23:10 | 000,879,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2015.05.13 07:23:10 | 000,879,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2015.05.13 07:23:10 | 000,635,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2015.05.13 07:23:09 | 001,461,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015.05.13 07:23:09 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015.05.13 07:23:09 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2015.05.13 07:23:09 | 000,404,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tracerpt.exe
[2015.05.13 07:23:09 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tracerpt.exe
[2015.05.13 07:23:09 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2015.05.13 07:23:09 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015.05.13 07:23:09 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2015.05.13 07:23:09 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2015.05.13 07:23:09 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sechost.dll
[2015.05.13 07:23:09 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2015.05.13 07:23:09 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2015.05.13 07:23:09 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2015.05.13 07:23:09 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\typeperf.exe
[2015.05.13 07:23:08 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2015.05.13 07:23:08 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015.05.13 07:23:08 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2015.05.13 07:23:08 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2015.05.13 07:23:08 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015.05.13 07:23:08 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2015.05.13 07:23:08 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2015.05.13 07:23:08 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe
[2015.05.13 07:23:08 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\typeperf.exe
[2015.05.13 07:23:08 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe
[2015.05.13 07:23:08 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2015.05.13 07:23:08 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2015.05.13 07:23:08 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2015.05.13 07:23:08 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskperf.exe
[2015.05.13 07:23:08 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskperf.exe
[2015.05.13 07:23:08 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2015.05.13 07:23:08 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2015.05.13 07:23:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2015.05.13 07:23:08 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2015.05.13 07:23:07 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2015.05.13 07:23:07 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2015.05.13 07:23:07 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2015.05.13 07:23:07 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2015.05.13 07:23:07 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2015.05.13 07:23:07 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2015.05.13 07:23:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2015.05.13 07:23:07 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2015.05.13 07:23:07 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2015.05.13 07:23:07 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2015.05.13 07:23:07 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2015.05.13 07:22:51 | 001,647,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2015.05.13 07:22:47 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InkEd.dll
[2015.05.13 07:22:47 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InkEd.dll
[2015.05.13 07:22:47 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jnwmon.dll
[2015.05.13 07:22:46 | 002,543,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdshext.dll
[2015.05.13 07:22:44 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2015.05.13 07:22:44 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2015.05.13 07:22:43 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2015.05.13 07:22:43 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdbinst.exe
[2015.05.13 07:22:42 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sdbinst.exe
[2015.05.13 07:22:42 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shimeng.dll
[2015.05.12 16:08:32 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\AVAST Software
[2015.05.12 16:07:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2015.05.12 16:07:16 | 000,442,264 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015.05.12 16:07:16 | 000,137,288 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015.05.12 16:07:16 | 000,089,944 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015.05.12 16:07:15 | 001,047,320 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2015.05.12 16:07:15 | 000,093,528 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015.05.12 16:07:11 | 000,364,472 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\SysNative\aswBoot.exe
[2015.05.12 16:06:56 | 000,043,112 | ---- | C] (Avast Software s.r.o.) -- C:\Windows\avastSS.scr
[2015.05.12 16:05:58 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2015.05.12 16:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2015.05.12 16:05:04 | 005,499,960 | ---- | C] (Avast Software s.r.o.) -- C:\Users\Petr\Desktop\avast_free_antivirus_setup_online.exe
[2015.05.11 10:46:27 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\raidcall
[2015.05.11 10:46:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall
[2015.05.11 10:46:19 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RaidCall
[2015.05.11 10:46:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RaidCall
[2015.05.10 17:43:56 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\TERA
[2015.05.10 16:49:22 | 001,761,992 | ---- | C] (ESET) -- C:\Users\Petr\Desktop\eset_nod32_antivirus_live_installer_.exe
[2015.05.01 20:14:57 | 000,000,000 | ---D | C] -- D:\Documents\MK-LOL
[2015.05.01 20:14:56 | 000,000,000 | ---D | C] -- D:\Documents\MKJogo
[2015.04.18 19:45:17 | 000,000,000 | ---D | C] -- D:\Documents\DayZ
[2015.04.18 19:45:17 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\DayZ
[1 C:\Users\Petr\AppData\Local\*.tmp files -> C:\Users\Petr\AppData\Local\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2015.05.17 12:52:49 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015.05.17 12:47:01 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.05.17 12:46:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
[2015.05.17 12:28:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA1d042414c0351a8.job
[2015.05.17 12:20:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015.05.17 12:19:47 | 000,446,095 | ---- | M] () -- C:\Users\Petr\Desktop\60a335d2ae9ab437917863b6e4f15189.jpg
[2015.05.17 11:46:25 | 000,020,880 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.05.17 11:46:25 | 000,020,880 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.05.17 11:37:12 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015.05.17 11:36:55 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1d042414bcc1439.job
[2015.05.17 11:36:38 | 000,000,198 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2015.05.17 11:36:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.05.17 11:35:55 | 2116,612,095 | -HS- | M] () -- C:\hiberfil.sys
[2015.05.16 01:03:18 | 000,057,124 | ---- | M] () -- C:\Windows\SysNative\drivers\fvstore.dat
[2015.05.16 00:21:16 | 003,202,017 | ---- | M] () -- C:\Users\Petr\Desktop\Manian - Welcome to the Club(Official Video).mp3
[2015.05.15 21:48:06 | 001,437,679 | ---- | M] () -- C:\Users\Petr\Desktop\The Kitty Cat Dance..mp3
[2015.05.15 18:38:51 | 004,274,208 | ---- | M] () -- C:\Users\Petr\Desktop\Different Heaven & EH!DE - My Heart.mp3
[2015.05.15 16:47:58 | 000,001,966 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2015.05.15 15:13:51 | 000,001,007 | ---- | M] () -- C:\Users\Petr\Desktop\SpeedFan.lnk
[2015.05.15 15:13:50 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2015.05.14 06:48:59 | 001,788,684 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015.05.14 06:48:59 | 000,816,158 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2015.05.14 06:48:59 | 000,657,196 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015.05.14 06:48:59 | 000,191,466 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2015.05.14 06:48:59 | 000,123,008 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015.05.14 06:43:22 | 005,080,792 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015.05.13 07:23:43 | 000,460,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2015.05.13 07:23:43 | 000,342,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2015.05.13 07:23:35 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2015.05.13 07:23:35 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2015.05.13 07:23:35 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2015.05.13 07:23:35 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2015.05.13 07:23:35 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2015.05.13 07:23:35 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2015.05.13 07:23:34 | 000,720,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015.05.13 07:23:34 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2015.05.13 07:23:34 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2015.05.13 07:23:34 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2015.05.13 07:23:33 | 002,052,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2015.05.13 07:23:33 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015.05.13 07:23:33 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2015.05.13 07:23:32 | 000,968,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2015.05.13 07:23:32 | 000,801,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015.05.13 07:23:32 | 000,664,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2015.05.13 07:23:32 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2015.05.13 07:23:32 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2015.05.13 07:23:32 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2015.05.13 07:23:32 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2015.05.13 07:23:32 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2015.05.13 07:23:31 | 002,125,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2015.05.13 07:23:31 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015.05.13 07:23:31 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2015.05.13 07:23:30 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2015.05.13 07:23:30 | 000,584,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015.05.13 07:23:30 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2015.05.13 07:23:30 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2015.05.13 07:23:29 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2015.05.13 07:23:29 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2015.05.13 07:23:29 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2015.05.13 07:23:28 | 006,025,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015.05.13 07:23:28 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2015.05.13 07:23:28 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2015.05.13 07:23:28 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2015.05.13 07:23:27 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2015.05.13 07:23:27 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2015.05.13 07:23:25 | 000,328,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\services.exe
[2015.05.13 07:23:12 | 005,569,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015.05.13 07:23:12 | 001,728,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2015.05.13 07:23:12 | 001,254,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2015.05.13 07:23:12 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UtcResources.dll
[2015.05.13 07:23:10 | 003,989,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015.05.13 07:23:10 | 003,934,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015.05.13 07:23:10 | 001,461,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015.05.13 07:23:10 | 001,162,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2015.05.13 07:23:10 | 000,879,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2015.05.13 07:23:10 | 000,879,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2015.05.13 07:23:10 | 000,635,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2015.05.13 07:23:10 | 000,503,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015.05.13 07:23:10 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2015.05.13 07:23:10 | 000,404,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tracerpt.exe
[2015.05.13 07:23:10 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tracerpt.exe
[2015.05.13 07:23:10 | 000,243,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2015.05.13 07:23:10 | 000,113,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sechost.dll
[2015.05.13 07:23:10 | 000,104,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2015.05.13 07:23:09 | 000,362,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2015.05.13 07:23:09 | 000,338,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2015.05.13 07:23:09 | 000,309,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015.05.13 07:23:09 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015.05.13 07:23:09 | 000,215,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2015.05.13 07:23:09 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2015.05.13 07:23:09 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2015.05.13 07:23:09 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2015.05.13 07:23:09 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2015.05.13 07:23:09 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015.05.13 07:23:09 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2015.05.13 07:23:09 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\typeperf.exe
[2015.05.13 07:23:09 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2015.05.13 07:23:09 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe
[2015.05.13 07:23:09 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\typeperf.exe
[2015.05.13 07:23:09 | 000,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe
[2015.05.13 07:23:09 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2015.05.13 07:23:09 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2015.05.13 07:23:09 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\diskperf.exe
[2015.05.13 07:23:09 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\diskperf.exe
[2015.05.13 07:23:09 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2015.05.13 07:23:08 | 000,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2015.05.13 07:23:08 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2015.05.13 07:23:08 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2015.05.13 07:23:08 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2015.05.13 07:23:08 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2015.05.13 07:23:08 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2015.05.13 07:23:07 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2015.05.13 07:23:07 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2015.05.13 07:23:07 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2015.05.13 07:23:07 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2015.05.13 07:23:07 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2015.05.13 07:23:07 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2015.05.13 07:23:07 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2015.05.13 07:23:07 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2015.05.13 07:23:07 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2015.05.13 07:23:07 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2015.05.13 07:23:07 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2015.05.13 07:23:07 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2015.05.13 07:23:07 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2015.05.13 07:22:51 | 001,647,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2015.05.13 07:22:47 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\InkEd.dll
[2015.05.13 07:22:47 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\InkEd.dll
[2015.05.13 07:22:47 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jnwmon.dll
[2015.05.13 07:22:46 | 002,543,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wpdshext.dll
[2015.05.13 07:22:46 | 001,195,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UMDF\WpdMtpDr.dll
[2015.05.13 07:22:44 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2015.05.13 07:22:44 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2015.05.13 07:22:43 | 000,342,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2015.05.13 07:22:43 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sdbinst.exe
[2015.05.13 07:22:43 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sdbinst.exe
[2015.05.13 07:22:42 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\shimeng.dll
[2015.05.12 16:07:10 | 000,442,264 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015.05.12 16:07:10 | 000,364,472 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\aswBoot.exe
[2015.05.12 16:07:10 | 000,272,248 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015.05.12 16:07:10 | 000,093,528 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015.05.12 16:07:10 | 000,089,944 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015.05.12 16:07:10 | 000,065,736 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015.05.12 16:07:10 | 000,029,168 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015.05.12 16:07:05 | 001,047,320 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2015.05.12 16:07:00 | 000,137,288 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015.05.12 16:06:56 | 000,043,112 | ---- | M] (Avast Software s.r.o.) -- C:\Windows\avastSS.scr
[2015.05.12 16:05:04 | 005,499,960 | ---- | M] (Avast Software s.r.o.) -- C:\Users\Petr\Desktop\avast_free_antivirus_setup_online.exe
[2015.05.11 10:46:20 | 000,001,007 | ---- | M] () -- C:\Users\Petr\Desktop\RaidCall.lnk
[2015.05.11 10:45:52 | 005,801,376 | ---- | M] () -- C:\Users\Petr\Desktop\raidcall_v7.3.6.exe
[2015.05.11 06:57:34 | 000,000,202 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
[2015.05.10 16:49:32 | 001,761,992 | ---- | M] (ESET) -- C:\Users\Petr\Desktop\eset_nod32_antivirus_live_installer_.exe
[2015.05.10 00:17:31 | 000,031,758 | ---- | M] () -- C:\Users\Petr\Desktop\11128363_859560794114166_7419899683097993934_n[1].jpg
[2015.05.01 20:14:56 | 000,000,058 | ---- | M] () -- C:\Windows\JQHApp.dat
[2015.05.01 15:17:03 | 000,124,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015.05.01 15:16:41 | 000,102,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015.04.26 18:17:03 | 000,000,000 | ---- | M] () -- C:\Users\Petr\AppData\Local\{F14FBD2C-5782-4B32-B391-94AB68EDC27E}
[2015.04.26 18:17:03 | 000,000,000 | ---- | M] () -- C:\Users\Petr\AppData\Local\{7881F437-35AC-4C2E-ADD8-710C7FF9620A}
[2015.04.21 18:50:03 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2015.04.21 18:09:57 | 000,341,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2015.04.20 17:26:53 | 000,029,695 | ---- | M] () -- C:\Users\Petr\Desktop\10489641_546008335526260_6762548785495902480_n.jpg
[2015.04.18 20:37:47 | 000,224,830 | ---- | M] () -- C:\Users\Petr\Desktop\Peťa Lefan.png
[1 C:\Users\Petr\AppData\Local\*.tmp files -> C:\Users\Petr\AppData\Local\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2015.05.17 12:52:49 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015.05.17 12:19:47 | 000,446,095 | ---- | C] () -- C:\Users\Petr\Desktop\60a335d2ae9ab437917863b6e4f15189.jpg
[2015.05.16 00:21:13 | 003,202,017 | ---- | C] () -- C:\Users\Petr\Desktop\Manian - Welcome to the Club(Official Video).mp3
[2015.05.15 21:48:04 | 001,437,679 | ---- | C] () -- C:\Users\Petr\Desktop\The Kitty Cat Dance..mp3
[2015.05.15 18:38:31 | 004,274,208 | ---- | C] () -- C:\Users\Petr\Desktop\Different Heaven & EH!DE - My Heart.mp3
[2015.05.15 17:32:01 | 000,057,124 | ---- | C] () -- C:\Windows\SysNative\drivers\fvstore.dat
[2015.05.15 15:13:51 | 000,001,007 | ---- | C] () -- C:\Users\Petr\Desktop\SpeedFan.lnk
[2015.05.15 15:13:50 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2015.05.12 16:07:43 | 000,001,966 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2015.05.12 16:07:16 | 000,272,248 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015.05.12 16:07:16 | 000,065,736 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015.05.12 16:07:15 | 000,029,168 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015.05.11 10:46:20 | 000,001,007 | ---- | C] () -- C:\Users\Petr\Desktop\RaidCall.lnk
[2015.05.11 10:45:28 | 005,801,376 | ---- | C] () -- C:\Users\Petr\Desktop\raidcall_v7.3.6.exe
[2015.05.10 21:17:10 | 000,031,758 | ---- | C] () -- C:\Users\Petr\Desktop\11128363_859560794114166_7419899683097993934_n[1].jpg
[2015.04.26 18:17:03 | 000,000,000 | ---- | C] () -- C:\Users\Petr\AppData\Local\{F14FBD2C-5782-4B32-B391-94AB68EDC27E}
[2015.04.26 18:17:03 | 000,000,000 | ---- | C] () -- C:\Users\Petr\AppData\Local\{7881F437-35AC-4C2E-ADD8-710C7FF9620A}
[2015.04.20 17:26:53 | 000,029,695 | ---- | C] () -- C:\Users\Petr\Desktop\10489641_546008335526260_6762548785495902480_n.jpg
[2015.04.18 20:37:47 | 000,224,830 | ---- | C] () -- C:\Users\Petr\Desktop\Peťa Lefan.png
[2015.01.09 17:28:00 | 000,001,075 | ---- | C] () -- C:\Users\Petr\Dokumenty – zástupce.lnk
[2014.08.29 03:47:43 | 000,000,498 | ---- | C] () -- C:\Users\Petr\Backup.lic
[2014.07.17 19:09:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2014.06.09 17:44:47 | 000,000,058 | ---- | C] () -- C:\Windows\JQHApp.dat
[2014.04.15 19:05:19 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.04.15 19:05:19 | 000,076,152 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.04.10 22:16:19 | 000,000,000 | -HS- | C] () -- C:\Users\Petr\AppData\Local\LumaEmu
[2014.02.19 19:02:43 | 000,045,270 | ---- | C] () -- C:\Users\Petr\AppData\Roaming\room_v3.dat
[2013.10.09 17:15:56 | 000,000,000 | ---- | C] () -- C:\Users\Petr\regbcm
[2013.10.02 06:23:02 | 000,000,593 | ---- | C] () -- C:\Users\Petr\Sdílený prostor.lnk
[2013.10.02 04:53:18 | 000,000,184 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2013.10.02 04:52:54 | 000,078,848 | ---- | C] () -- C:\Windows\KMSEmulator.exe
[2013.10.02 04:09:16 | 000,217,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013.10.02 02:30:33 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.10.02 02:23:27 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2013.10.02 02:12:18 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.10.02 02:12:18 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.10.02 02:12:18 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013.10.02 02:07:55 | 001,763,398 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.10.02 02:01:36 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini

========== ZeroAccess Check ==========

[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.02.13 07:22:33 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.02.13 07:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2015.04.18 01:19:28 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.minecraft
[2014.10.24 16:37:57 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.mono
[2014.01.26 19:34:28 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.technic
[2015.04.13 10:33:25 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Arc
[2015.05.16 00:24:52 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Audacity
[2015.05.12 16:08:32 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\AVAST Software
[2014.04.13 13:35:36 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\AVG
[2014.12.13 21:11:09 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Awesomium
[2014.08.29 13:57:45 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Battle.net
[2013.11.06 09:08:11 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\DAEMON Tools Lite
[2015.04.11 14:55:55 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Dropbox
[2014.09.17 17:32:46 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Enterbrain
[2014.01.17 18:56:11 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Fatshark
[2014.02.19 18:54:21 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Garena
[2014.02.19 18:48:20 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\GarenaPlus
[2014.01.25 22:05:39 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\LolClient
[2013.11.10 17:00:32 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade
[2013.11.19 15:25:23 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade Warband
[2013.11.11 17:32:29 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade With Fire and Sword
[2014.07.23 08:54:48 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\My Battle for Middle-earth Files
[2013.12.10 14:43:15 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Need for Speed World
[2014.04.13 13:35:01 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\OpenCandy
[2014.11.04 16:40:18 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Origin
[2015.02.11 19:24:10 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\puush
[2015.05.11 10:46:27 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\raidcall
[2014.09.16 20:59:14 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\RenPy
[2013.11.02 14:41:22 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\RIFT
[2014.01.25 00:26:12 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Riot Games
[2013.11.25 17:12:49 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Rogue Legacy
[2015.04.11 14:58:58 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Seznam.cz
[2014.05.06 07:21:34 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\skyz
[2014.04.10 14:38:56 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SpaceEngineers
[2014.11.02 16:49:22 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SpieleEntwicklungsKombinat
[2014.07.13 21:01:02 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs
[2014.12.09 17:42:14 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SPORE
[2014.11.18 17:40:33 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Steam
[2014.12.20 12:14:17 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\StunlockStudios
[2014.08.24 22:14:38 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\TeamViewer
[2015.05.16 16:40:21 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Tera_Awesomium
[2015.03.15 00:13:06 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\TS3Client
[2015.01.23 18:24:17 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Tunngle
[2013.10.10 17:35:09 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Unity
[2013.11.10 15:25:19 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Wargaming.net
[2015.01.08 22:46:27 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\WindOfLuckArena

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,032,568 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.10.02 03:26:57 | 000,000,948 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.10.02 03:26:57 | 000,000,952 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.10.02 04:53:18 | 000,000,198 | ---- | C] () -- C:\Windows\Tasks\AutoKMS.job
[2013.10.02 04:53:18 | 000,000,202 | ---- | C] () -- C:\Windows\Tasks\AutoKMSDaily.job
[2014.07.13 21:02:08 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2015.02.06 21:15:40 | 000,000,948 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d042414bcc1439.job
[2015.02.06 21:15:40 | 000,000,952 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d042414c0351a8.job

< >

< MD5 for: AGP440.SYS >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#6 Příspěvek od Lefiks »

< MD5 for: AUTOCHK.EXE >
[2010.11.20 15:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.20 15:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009.07.14 03:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 03:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010.11.20 14:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.20 14:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2009.07.14 01:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010.11.20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: CRYPTSVC.DLL >
[2015.02.03 05:50:56 | 000,190,976 | ---- | M] (Microsoft Corporation) MD5=00D0F7BA3B27126A3E25B540979A9F39 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22948_none_d492bbeccaa14239\cryptsvc.dll
[2012.06.02 06:52:32 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=063DD65889D21035311463337BD268E7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_788c7cc71232cc19\cryptsvc.dll
[2010.11.20 15:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2014.07.07 04:06:31 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=19D511CC455C19DE1ADF60E6C39C85B6 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18526_none_d41cb8b3b175406a\cryptsvc.dll
[2015.02.03 05:30:56 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=1CD76A83B9E8E9A5A3519B39E28354D9 -- C:\Windows\SysNative\cryptsvc.dll
[2015.02.03 05:30:56 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=1CD76A83B9E8E9A5A3519B39E28354D9 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18741_none_d4021b35b189f3e7\cryptsvc.dll
[2014.10.30 04:14:18 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=3031B5DC2A58A7BCE6651EA9B7DD6390 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22908_none_789f60191223613f\cryptsvc.dll
[2013.05.10 06:49:59 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=33ADF6E0853AB39EA1723BE82842C1D3 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_77d7a417f9359661\cryptsvc.dll
[2013.05.13 06:45:55 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=3897DFF247D9ED0006190349DE264E14 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_77d8a461f934afb8\cryptsvc.dll
[2013.07.09 16:47:30 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=434CCE8E7150CD1324C5FAA088D1D061 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_d45f6e88cac8f85b\cryptsvc.dll
[2012.06.02 07:32:25 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=456107D69D4EE850A559434F19EFEE65 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.21225_none_d2beeccacd6d6c07\cryptsvc.dll
[2015.02.03 05:12:14 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=49474B3E37969AF4B5C076F42B623AFF -- C:\Windows\SysWOW64\cryptsvc.dll
[2015.02.03 05:12:14 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=49474B3E37969AF4B5C076F42B623AFF -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18741_none_77e37fb1f92c82b1\cryptsvc.dll
[2013.10.05 04:25:30 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=509D31797A4B8A3D6ED78A330B19A919 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_d46d4138cabe2596\cryptsvc.dll
[2014.07.07 03:40:07 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=623E143F2DF17C0106A9988F5D7DC878 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18526_none_77fe1d2ff917cf34\cryptsvc.dll
[2014.07.07 04:06:07 | 000,190,976 | ---- | M] (Microsoft Corporation) MD5=63A15BA9875364C4147B226CB70468B3 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22736_none_d49b8778ca9af94c\cryptsvc.dll
[2014.07.07 04:06:07 | 000,190,976 | ---- | M] (Microsoft Corporation) MD5=63A15BA9875364C4147B226CB70468B3 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22908_none_d4bdfb9cca80d275\cryptsvc.dll
[2013.07.09 07:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=6B400F211BEE880A37A1ED0368776BF4 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_d431528fb165f7bc\cryptsvc.dll
[2013.07.09 15:57:37 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=6DB499DEFCC827317C5371164A7CDB27 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_7840d305126b8725\cryptsvc.dll
[2013.07.09 06:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=7CA1BECEA5DE2643ADDAD32670E7A4C9 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_7812b70bf9088686\cryptsvc.dll
[2012.06.04 09:52:35 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=7E7D2DACF65D750D466F36BD3D09AE20 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_d4ab184aca903d4f\cryptsvc.dll
[2013.05.10 07:49:28 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=7FDC4626B01106A8EF328C88C7C0DEE3 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_d3f63f9bb1930797\cryptsvc.dll
[2013.05.11 07:18:23 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=8122252F0A4ACFA92FA0C1D50D18493B -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_d4a24ea4ca968363\cryptsvc.dll
[2009.07.14 03:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_d1f48b0bb4805490\cryptsvc.dll
[2014.07.07 03:40:42 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=90BFC30E730A6760F1FEE2A55F8AB029 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22736_none_787cebf5123d8816\cryptsvc.dll
[2012.06.02 06:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=96C0E38905CFD788313BE8E11DAE3F2F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_77ddc9e5f93000db\cryptsvc.dll
[2012.06.02 07:41:28 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=9C01375BE382E834CC26D1B7EAF2C4FE -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_d3fc6569b18d7211\cryptsvc.dll
[2009.07.14 03:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
[2010.11.20 14:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
[2013.05.11 06:59:05 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=AC04D05309BB2C418D0D80B9FB014642 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_7883b3211239122d\cryptsvc.dll
[2015.02.03 05:31:49 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=B97E16D36DB7B7DD22C97857506FA58A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22948_none_787420691243d103\cryptsvc.dll
[2012.06.02 07:25:12 | 000,182,272 | ---- | M] (Microsoft Corporation) MD5=BAF19B633933A9FB4883D27D66C39E9A -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.17035_none_d22a7e2db457eb07\cryptsvc.dll
[2013.05.10 07:18:53 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=CA13C4F92BEE66DB48E58AB3223DDF6E -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_d4a14e5aca976a0c\cryptsvc.dll
[2013.05.13 07:51:01 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=D8129C49798CBBFB2E4351D4B7B8EF9C -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_d3f73fe5b19220ee\cryptsvc.dll
[2013.05.10 07:06:21 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=E122AA1C9A3CC46FF9DDDE46E5EB0C58 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_7882b2d71239f8d6\cryptsvc.dll
[2012.06.02 06:41:59 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=EA8C26ECF1656D9647EF044F115EC6DA -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.21225_none_76a05147150ffad1\cryptsvc.dll
[2013.10.05 03:52:03 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=F2D9242C3BBD1C36467FCAE1AE01733F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_784ea5b51260b460\cryptsvc.dll
[2012.06.02 06:45:21 | 000,139,264 | ---- | M] (Microsoft Corporation) MD5=F2FDE6C8DBAAD44CC58D1E07E4AF4EED -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.17035_none_760be2a9fbfa79d1\cryptsvc.dll

< MD5 for: EXPLORER.EXE >
[2011.02.26 08:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 07:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009.08.03 08:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 08:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 07:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 15:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 08:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 07:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 03:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 08:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 08:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 08:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: HAL.DLL >
[2009.07.14 03:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010.11.20 15:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.20 15:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll

< MD5 for: IASTORV.SYS >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys

< MD5 for: LSASS.EXE >
[2014.05.30 10:00:12 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=04F6C08B30C599D301CE8530A6F6A703 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22705_none_0505e8508c7f766f\lsass.exe
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_023e7e05767d22ad\lsass.exe
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_02bd4ae48fa2de68\lsass.exe
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
[2011.11.17 08:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
[2011.11.17 09:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=156F6159457D0AA7E59B62681B56EB90 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16915_none_028b374176436a30\lsass.exe
[2011.11.17 09:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=156F6159457D0AA7E59B62681B56EB90 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.17035_none_02756f8b7653d554\lsass.exe
[2015.01.14 08:04:46 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=1E31700D9C9E0FB79999D02A8437482C -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18717_none_04737e137368226b\lsass.exe
[2014.04.12 04:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=204F3F58212B3E422C90BD9691A2DF28 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18443_none_044f07757384196d\lsass.exe
[2014.04.12 04:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=204F3F58212B3E422C90BD9691A2DF28 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18496_none_041bf8b773a9f127\lsass.exe
[2014.04.12 04:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=204F3F58212B3E422C90BD9691A2DF28 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18526_none_0467aa1173712ab7\lsass.exe
[2014.04.12 04:19:05 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=204F3F58212B3E422C90BD9691A2DF28 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18637_none_045ddc5573785d26\lsass.exe
[2014.09.19 11:42:18 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=341655B216721D89CADE9DEA2F33872F -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18606_none_047d4bcf7360effc\lsass.exe
[2015.03.06 07:32:14 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=395CAE11172BEBB0253895E8B5F82BFA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22983_none_04ad6c288cc21d97\lsass.exe
[2015.01.29 05:18:39 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=43FE6F74D2D43443CF2279613FA0A516 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18738_none_045ede85737773a4\lsass.exe
[2015.05.13 07:23:42 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=4C3FAC816925F73A34AD52F1F7C0A7EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\lsass.exe
[2013.09.25 03:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=4D71227301DD8D09097B9E4CC6527E5A -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18270_none_042b9307739f26ed\lsass.exe
[2015.01.10 09:09:08 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=55C62F66528A7BF58EA964B70BCB3D96 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22920_none_04eb4ad28c9429ec\lsass.exe
[2015.01.27 05:56:02 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=5B63917A1BE4728D8111850CDEF252F1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22943_none_04d8abd88ca1add3\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22653_none_04cdd63a8ca9d24f\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22712_none_04f817868c8a465b\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22736_none_04e678d68c96e399\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22807_none_0507eaca8c7da644\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22843_none_04d8a9f28ca1b0ac\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22923_none_04ee4bb08c9175f1\lsass.exe
[2014.04.12 04:31:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=6598EBC4D209318EBD81F76833ECBEDB -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22925_none_04f04c448c8fa89f\lsass.exe
[2015.02.03 05:30:31 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=7554A1B82B4A222FD4CC292ABD38A558 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18741_none_044d0c937385de34\lsass.exe
[2012.08.24 19:43:36 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=77119F1F9B492B260030C34F9BE327FA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22099_none_04a88ce28cc4eb33\lsass.exe
[2012.06.04 09:51:10 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=79C908CAA6F43021EB05F4C733A927D1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_04f609a88c8c279c\lsass.exe
[2015.05.13 07:23:09 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=9262D6E2C239EDD6D87B080F2BCCEC9F -- C:\Windows\SysNative\lsass.exe
[2015.05.13 07:23:09 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=9262D6E2C239EDD6D87B080F2BCCEC9F -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\lsass.exe
[2015.03.06 07:41:46 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=B6C7729936AAF8E0697F0A7DCA82CED8 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18779_none_04349f1f7396fcbf\lsass.exe
[2014.09.19 11:47:37 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=B84317193B6A29F5F5DCF538C34FDCED -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22814_none_04fa1a008c887630\lsass.exe
[2015.05.13 07:23:42 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=BB9C1B746086558899935E3333CD4580 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\lsass.exe
[2012.06.02 07:30:31 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=BF63CE11A25F3509129888710D5111FC -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21225_none_0309de288f695654\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_044756c773895c5e\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17940_none_044c26dd7386a58a\lsass.exe
[2015.01.10 08:47:33 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C8152B86C0F12E61B0AD5C95751547D3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18714_none_04707d35736ad666\lsass.exe
[2015.04.15 15:54:02 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=CA4FC33FB22D92368A0B221092B46374 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\lsass.exe
[2015.02.03 05:50:23 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=CBB80CC43E683F929F8D5E50330F7BA6 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22948_none_04ddad4a8c9d2c86\lsass.exe
[2011.11.17 08:42:52 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D21BD47E528CD62E79311FB5DF0150E6 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21092_none_02bb2a0a8fa4d398\lsass.exe
[2015.05.13 07:23:09 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D52C700254E7FBD9BF6D817BA7BA5309 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\lsass.exe
[2015.04.15 15:54:02 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=DCCDD65A4E68360E5CF57AFC864C64E0 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\lsass.exe
[2015.01.15 10:09:15 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=E0105F3B5B1C4B0F5B3D788A13504EC6 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18719_none_04757ea773665519\lsass.exe
[2013.09.25 03:08:17 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=F021DAFB1F87616FCEBA159C2ED7042F -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22465_none_04c503168cb026a0\lsass.exe
[2014.05.30 10:07:57 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=F23812F9F7B130854E4BC0389F7C688C -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18489_none_0429c981739f213b\lsass.exe

< MD5 for: NDIS.SYS >
[2012.08.22 20:06:07 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=5E74508FCB5820B29EEAFE24E6035BCF -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.22097_none_06232d534c0a8d67\ndis.sys
[2012.08.22 20:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\SysNative\drivers\ndis.sys
[2012.08.22 20:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17939_none_05dc9a6832ba428a\ndis.sys
[2010.11.20 15:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
[2009.07.14 03:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011.03.11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2009.07.14 03:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
[2010.11.20 15:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.20 15:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011.03.11 08:19:21 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
[2011.03.11 08:23:06 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvraid.sys
[2011.03.11 08:25:53 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A5C82EB2F72AA004887F90B84A771F73 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SMSS.EXE >
[2015.04.15 15:54:02 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=0B6514A14631E41DE4D6D40D1C80BE68 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18798_none_0a0e1c38300e82ce\smss.exe
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
[2015.04.15 15:54:02 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=206A6B71AC09D9F7651F0A8B015676C7 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23002_none_0af2e09b48e8bf7e\smss.exe
[2014.04.12 04:31:44 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=3442A918386D4716D74C661543151746 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22653_none_0abdf375491039d3\smss.exe
[2014.04.12 04:31:44 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=3442A918386D4716D74C661543151746 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22780_none_0a9a84b9492b3ec8\smss.exe
[2014.04.12 04:31:44 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=3442A918386D4716D74C661543151746 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22908_none_0af90a3548e32446\smss.exe
[2014.04.12 04:31:44 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=3442A918386D4716D74C661543151746 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22921_none_0adc685748f9aac7\smss.exe
[2014.04.12 04:31:44 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=3442A918386D4716D74C661543151746 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22923_none_0ade68eb48f7dd75\smss.exe
[2013.03.19 04:57:17 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=498E2A20E145199709CD100CDBA8603D -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22280_none_0a9a7b3b492b4d05\smss.exe
[2015.02.03 05:30:42 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=63D3C30B497347495B8EA78A38188969 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18741_none_0a3d29ce2fec45b8\smss.exe
[2013.03.19 05:20:12 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=7180204786A9DED8723B2D8CF3CDD388 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.21490_none_08a94e494c0cfd0a\smss.exe
[2015.01.29 05:18:52 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=83C0199B7C06AC3C33212E1A0DC2260E -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18738_none_0a4efbc02fdddb28\smss.exe
[2015.02.03 05:50:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=8CD5A97B8D155718D357B2D9BC6B113D -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22948_none_0acdca854903940a\smss.exe
[2013.08.29 03:04:30 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=B2B31D4C79EFD883097FA24D02E79C12 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22436_none_0ad6905f48fd53a8\smss.exe
[2015.01.27 05:56:16 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=B75198D88A34994DE1E4D9F2286DF759 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22943_none_0ac8c91349081557\smss.exe
[2013.08.02 07:06:34 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=CB5DA3E44456D1084BCD87F5B1B3152B -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22411_none_0ae72ec548f19d13\smss.exe
[2015.05.13 07:23:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=CF8DC00FA29243A347AD4B605AFFF1E5 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23040_none_0ac5a057490afc94\smss.exe
[2015.05.13 07:23:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=DA5EF2CC0764BE7097BAFA9CAF903FE8 -- C:\Windows\SysNative\smss.exe
[2015.05.13 07:23:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=DA5EF2CC0764BE7097BAFA9CAF903FE8 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18839_none_0a4ffdf02fdcf1a6\smss.exe
[2013.03.19 05:06:33 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0371DE302FFFF8F086661611BE60848 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18113_none_0a5f8ec22fd235a9\smss.exe
[2013.08.02 02:59:09 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0970A4BC8395659C22BF53D0FADF16F -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18229_none_0a5ac2782fd4e6cb\smss.exe
[2013.03.19 05:19:03 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=FA64733BD65F52712F0545F56FDB4BE6 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.17273_none_0838504e32dc743c\smss.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2014.04.05 04:47:20 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=04ADD18EE5CC9FBEDAEC1DD1CD0CB45E -- C:\Windows\SysNative\drivers\tcpip.sys
[2014.04.05 04:47:20 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=04ADD18EE5CC9FBEDAEC1DD1CD0CB45E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18438_none_113260637d1284ef\tcpip.sys
[2012.10.03 19:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2013.09.08 04:30:37 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=40AF23633D197905F03AB5628C558C51 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_1118bb977d265d27\tcpip.sys
[2014.04.05 04:37:43 | 001,897,408 | ---- | M] (Microsoft Corporation) MD5=4F80944B03112F486212DC20BE166079 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22648_none_11b12f2896383dd1\tcpip.sys
[2010.11.20 15:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2013.01.04 07:41:01 | 001,893,224 | ---- | M] (Microsoft Corporation) MD5=5CFB7AB8F9524D1A1E14369DE63B83CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.17206_none_0f6a6af57fd59de6\tcpip.sys
[2013.01.03 07:57:12 | 001,876,824 | ---- | M] (Microsoft Corporation) MD5=692969AB90BDA19F56E27BF89A9260E2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21415_none_0fe8397098fc3d71\tcpip.sys
[2013.09.07 04:27:48 | 001,896,896 | ---- | M] (Microsoft Corporation) MD5=75F9106B74585D38C8FF6BB5CAD262D7 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_11ad2a34963bde27\tcpip.sys
[2009.07.14 03:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2013.07.06 07:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
[2013.01.03 08:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
[2013.01.04 07:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
[2012.10.03 19:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
[2013.11.26 13:34:34 | 001,897,408 | ---- | M] (Microsoft Corporation) MD5=F55B41AA6114568AC558ADBABDA85620 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22525_none_11c3cc3c962abcc3\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2014.03.04 13:08:14 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=6CE2AE073BD21C542FC2C707CAE944CC -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce748d1d04acf24f\winlogon.exe
[2014.03.04 11:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8bf35eb848572\winlogon.exe
[2014.07.17 04:07:24 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=8CEBD9D0A0A879CDE9F36F4383B7CAEA -- C:\Windows\SysNative\winlogon.exe
[2014.07.17 04:07:24 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=8CEBD9D0A0A879CDE9F36F4383B7CAEA -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_cdc47ed1ebad0e4e\winlogon.exe
[2014.07.16 05:23:23 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=98AA0BFEE089C7E5DADB94190D93456C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_ce434d9704d2c730\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WS2_32.DLL >
[2010.11.20 15:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.20 15:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2009.07.14 03:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2010.11.20 14:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.20 14:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
[2009.07.14 03:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[8 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[8 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[33 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[77 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2015.04.18 01:19:28 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.minecraft
[2014.10.24 16:37:57 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.mono
[2014.01.26 19:34:28 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\.technic
[2015.03.31 10:48:50 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Adobe
[2015.03.31 07:00:56 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Apple Computer
[2015.04.13 10:33:25 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Arc
[2013.10.02 02:28:31 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\ATI
[2015.05.16 00:24:52 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Audacity
[2015.05.12 16:08:32 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\AVAST Software
[2014.04.13 13:35:36 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\AVG
[2014.12.13 21:11:09 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Awesomium
[2014.08.29 13:57:45 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Battle.net
[2013.11.06 09:08:11 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\DAEMON Tools Lite
[2015.04.11 14:55:55 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Dropbox
[2014.09.17 17:32:46 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Enterbrain
[2014.01.17 18:56:11 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Fatshark
[2014.02.19 18:54:21 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Garena
[2014.02.19 18:48:20 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\GarenaPlus
[2014.08.29 03:44:45 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\InstallShield
[2014.01.25 22:05:39 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\LolClient
[2013.10.13 15:45:19 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Macromedia
[2009.07.14 17:36:38 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Media Center Programs
[2015.01.08 22:26:19 | 000,000,000 | --SD | M] -- C:\Users\Petr\AppData\Roaming\Microsoft
[2013.11.10 17:00:32 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade
[2013.11.19 15:25:23 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade Warband
[2013.11.11 17:32:29 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mount&Blade With Fire and Sword
[2013.10.13 15:26:35 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mozilla
[2014.07.23 08:54:48 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\My Battle for Middle-earth Files
[2013.12.10 14:43:15 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Need for Speed World
[2014.04.13 13:35:01 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\OpenCandy
[2014.11.04 16:40:18 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Origin
[2015.02.11 19:24:10 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\puush
[2015.05.11 10:46:27 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\raidcall
[2014.09.16 20:59:14 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\RenPy
[2013.11.02 14:41:22 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\RIFT
[2014.01.25 00:26:12 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Riot Games
[2013.11.25 17:12:49 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Rogue Legacy
[2014.03.17 22:16:21 | 000,000,000 | RH-D | M] -- C:\Users\Petr\AppData\Roaming\SecuROM
[2015.04.11 14:58:58 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Seznam.cz
[2015.05.17 14:02:25 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Skype
[2014.05.06 07:21:34 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\skyz
[2014.04.10 14:38:56 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SpaceEngineers
[2014.11.02 16:49:22 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SpieleEntwicklungsKombinat
[2014.07.13 21:01:02 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs
[2014.12.09 17:42:14 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\SPORE
[2014.11.18 17:40:33 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Steam
[2014.12.20 12:14:17 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\StunlockStudios
[2014.08.24 22:14:38 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\TeamViewer
[2015.05.16 16:40:21 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Tera_Awesomium
[2015.03.15 00:13:06 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\TS3Client
[2015.01.23 18:24:17 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Tunngle
[2013.10.10 17:35:09 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Unity
[2015.05.17 13:36:54 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\vlc
[2013.11.10 15:25:19 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Wargaming.net
[2015.01.08 22:46:27 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\WindOfLuckArena
[2013.10.02 04:42:42 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2014.07.15 20:53:24 | 001,592,398 | ---- | M] (TeamExtreme) -- C:\Users\Petr\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe
[2014.01.17 19:30:55 | 000,069,253 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
[2014.04.21 07:36:40 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Users\Petr\AppData\Roaming\.minecraft\mods\Minecraft-1.5.2.exe
[2015.04.02 20:38:14 | 043,382,072 | ---- | M] (Dropbox, Inc.) -- C:\Users\Petr\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2015.04.02 20:43:06 | 000,265,856 | ---- | M] (Dropbox, Inc.) -- C:\Users\Petr\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2015.04.02 20:38:20 | 001,032,456 | ---- | M] (Dropbox, Inc.) -- C:\Users\Petr\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2013.10.02 02:13:34 | 000,010,134 | R--- | M] () -- C:\Users\Petr\AppData\Roaming\Microsoft\Installer\{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}\ARPPRODUCTICON.exe
[2014.04.14 07:44:25 | 000,010,134 | R--- | M] () -- C:\Users\Petr\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2013.10.24 20:24:08 | 032,794,024 | ---- | M] (AVG) -- C:\Users\Petr\AppData\Roaming\OpenCandy\B0E0CF4F5C994B79A847E2175CD59C08\avg_tuht_stf_cs_2014_206_CZ.exe
[2013.05.16 15:25:04 | 001,062,472 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Seznam.cz\szninstall.exe
[2013.05.16 15:26:24 | 002,589,256 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Seznam.cz\sznsetup.exe
[2013.04.16 13:52:34 | 000,055,808 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Seznam.cz\bin\ffkill.exe
[2012.07.10 13:36:16 | 000,427,064 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Seznam.cz\bin\pomocnikListicky.exe
[2013.04.12 10:13:24 | 000,457,208 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
[2013.11.12 10:44:54 | 000,316,440 | ---- | M] (SplitmediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\encprobe.exe
[2013.03.18 15:57:47 | 000,148,992 | ---- | M] (SplitmediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\VHMultiWriterExt.exe
[2013.11.12 10:44:36 | 000,317,464 | ---- | M] (SplitmediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\VHMultiWriterExt2.exe
[2013.11.12 10:44:40 | 001,795,096 | ---- | M] (SplitMediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\VHScrCapDlg32.exe
[2013.11.12 10:44:37 | 000,032,280 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XDS.exe
[2013.11.12 10:40:55 | 002,600,264 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplit.Core.exe
[2013.11.12 10:44:45 | 000,114,712 | ---- | M] (SplitmediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplitBroadcasterSrc.exe
[2013.11.12 10:44:49 | 000,064,536 | ---- | M] (SplitmediaLabs Limited) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplitCleanUp.exe
[2013.11.12 10:40:55 | 000,036,680 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplitRegSrc.exe
[2013.11.12 10:44:47 | 000,039,448 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplitRegSrc40.exe
[2013.11.12 10:44:50 | 000,026,136 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplitUtils.exe
[2013.11.12 10:44:52 | 000,172,568 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\XSplit_Plugin_Installer.exe
[2013.11.12 10:44:43 | 000,328,216 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\xsplit_updater.exe
[2013.11.12 10:44:42 | 000,043,544 | ---- | M] (SplitMediaLabs) -- C:\Users\Petr\AppData\Roaming\SplitMediaLabs\XSplit\install\A86BEF5\x64\XGS64.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2015.05.15 15:13:50 | 000,000,045 | ---- | M] () -- C:\Windows\system32\initdebug.nfo

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Steam" = "C:\Program Files (x86)\Steam\steam.exe" -silent -- [2015.05.15 03:57:58 | 002,888,384 | ---- | M] (Valve Corporation)
"Skype" = "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun -- [2015.04.17 14:49:32 | 031,282,304 | R--- | M] (Skype Technologies S.A.)

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2015.05.17 12:52:49 | 000,000,512 | ---- | M] () MD5=F03AD7B260C309F1979748F55F38303D -- C:\PhysicalMBR.bin
[1 C:\*.tmp files -> C:\*.tmp -> ]

< >

< *crack* /s >
[2011.02.15 17:29:38 | 000,083,645 | ---- | M] () -- \Program Files (x86)\Mount&Blade With Fire and Sword\Sounds\Fire_Small_Crackle_Slick_op.ogg
[2014.12.13 23:22:11 | 000,000,159 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dino D-Day\dinodday\materials\decals\decal_bigcrack.vmt
[2014.12.13 23:21:05 | 000,699,256 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dino D-Day\dinodday\materials\decals\decal_bigcrack.vtf
[2014.12.13 23:21:21 | 000,000,134 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dino D-Day\dinodday\materials\overlays\tile_crack_stain001a.vmt
[2014.12.13 23:21:22 | 000,699,256 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dino D-Day\dinodday\materials\overlays\tile_crack_stain001a.vtf
[2014.10.26 14:24:14 | 000,003,132 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota_ugc\content\dota_addons\holdout_example\particles\creature_splitter\earthspirit_stone_cracks.vpcf
[2014.10.26 14:31:25 | 000,012,176 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota_ugc\game\dota_addons\holdout_example\particles\creature_splitter\earthspirit_stone_cracks.vpcf_c
[2013.12.02 23:53:24 | 000,000,100 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GarrysMod\garrysmod\addons\CSS Content Addon (Dec2013)\materials\concrete\prodwllecracked.vmt
[2013.12.02 23:53:24 | 000,174,968 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GarrysMod\garrysmod\addons\CSS Content Addon (Dec2013)\materials\concrete\prodwllecracked.vtf
[2015.05.10 17:02:38 | 001,099,940 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\BG\Extension_01\Original\EX01_BlackCrack_OBJ.gpk
[2015.05.10 17:06:29 | 001,755,067 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\ArcDeva_CrackDevice.gpk
[2015.05.10 17:34:21 | 000,020,724 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\ArcDeva_CrackDevice_ANI.gpk
[2015.05.10 17:28:56 | 008,695,706 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_BigStone.gpk
[2015.05.10 17:34:21 | 006,332,931 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_BigStone_ANI.gpk
[2015.05.10 17:17:45 | 003,335,217 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_NPC_OBJ.gpk
[2015.05.10 17:18:22 | 000,036,564 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_NPC_OBJ_ANI.gpk
[2015.05.10 16:50:27 | 000,685,163 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\Black_Crack_Wall.gpk
[2015.03.30 16:44:45 | 001,159,409 | R--- | M] () -- \Program Files\Adobe\Adobe After Effects CC\Support Files\Presets\Image - Special Effects\Cracked Tiles.ffx
[2013.04.22 21:21:22 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\en_US\VSTPlugins\DeCrackler1.dll
[2013.04.22 21:21:22 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\en_US\VSTPlugins\DeCrackler2.dll
[2013.04.22 21:21:22 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\en_US\VSTPlugins\DeCrackler6.dll
[2013.12.15 21:41:36 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\pt_BR\VSTPlugins\DeCrackler1.dll
[2013.12.15 21:41:36 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\pt_BR\VSTPlugins\DeCrackler2.dll
[2013.12.15 21:41:36 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\pt_BR\VSTPlugins\DeCrackler6.dll
[2013.12.15 21:41:38 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\ru_RU\VSTPlugins\DeCrackler1.dll
[2013.12.15 21:41:38 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\ru_RU\VSTPlugins\DeCrackler2.dll
[2013.12.15 21:41:38 | 000,816,640 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\Plug-ins\ru_RU\VSTPlugins\DeCrackler6.dll
[2007.02.07 01:00:00 | 000,174,904 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\cub_runway_cracked_dirt.dds
[2007.02.07 01:00:00 | 000,349,680 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\ger_cobble_crack.dds
[2007.02.07 01:00:00 | 000,349,680 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\ger_cobble_crack2.dds
[2007.02.07 01:00:00 | 000,349,680 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\ger_cobble_crack3.dds
[2007.02.07 01:00:00 | 000,349,680 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\pat_street_cracks.dds
[2007.02.07 01:00:00 | 000,349,680 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\area_specific\_textures\pat_street_cracks_b.dds
[2007.02.07 01:00:00 | 000,002,896 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\art\library\cut_scenes\manowar\textures\05_crack.dds
[2007.02.07 01:00:00 | 000,002,896 | ---- | M] () -- \Program Files\Freedom Force vs the 3rd Reich\Data\cut_scenes\manowar\textures\05_crack.dds
[2008.03.03 00:00:00 | 000,036,726 | ---- | M] () -- \Program Files\Sun Age\SFX\panels\transmission_crackle.ogg
[2009.01.19 15:27:44 | 000,083,645 | ---- | M] () -- \Users\Petr\Desktop\Můj Nightcore\Hry\Mount&Blade Warband\Sounds\Fire_Small_Crackle_Slick_op.ogg
[2015.05.17 13:43:14 | 000,001,139 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\ESET NOD32 ANTIVIRUS 7 CRACK (32 64 BIT) THADOGG – zástupce.lnk
[2015.03.30 18:41:14 | 002,437,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_01.wav
[2015.03.30 18:24:05 | 003,247,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_02.wav
[2015.03.30 18:27:42 | 003,247,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_03.wav
[2015.03.30 18:23:05 | 003,247,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_04.wav
[2015.03.30 18:41:14 | 002,437,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_05.wav
[2015.03.30 18:27:05 | 001,627,218 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_06.wav
[2015.03.30 18:42:01 | 001,281,054 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_07.wav
[2015.03.30 18:03:30 | 001,638,042 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\ORGANIC\Disintegration\Disintegration_Crackle_08.wav
[2015.03.30 18:31:45 | 006,363,338 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\VideoCopilot - MotionPulse BlackBox & Shockwave\MotionPulse_BlackBox_24-Bit_Wav\VELOCITY\Atmospheric\Atmospheric_Night_Crackle_01.wav

< *keygen* /s >

< *AntiWPA* /s >

< *loader* /s >
[2011.10.13 05:24:20 | 000,110,592 | ---- | M] () -- \AeriaGames\Downloader\Uploader.dat
[2011.10.13 05:24:20 | 000,110,592 | ---- | M] () -- \AeriaGames\Wolfteam\Uploader.dat
[2014.07.11 15:48:45 | 000,303,440 | ---- | M] () -- \AeriaGames\Wolfteam\avital\childprocfuncloader.xoe
[2014.07.11 15:48:45 | 000,310,608 | ---- | M] () -- \AeriaGames\Wolfteam\avital\parentprocfuncloader.xoe
[2011.11.14 18:51:36 | 000,110,592 | ---- | M] () -- \Game\SoftnyxGame\WolfTeamIS\uploader.dat
[2013.01.08 16:06:30 | 000,274,984 | ---- | M] () -- \Game\SoftnyxGame\WolfTeamIS\avital\childprocfuncloader.xoe
[2013.01.08 16:06:30 | 000,289,832 | ---- | M] () -- \Game\SoftnyxGame\WolfTeamIS\avital\parentprocfuncloader.xoe
[2011.12.12 17:17:34 | 000,022,616 | ---- | M] () -- \Game\SoftnyxGame\WolfTeamIS\Img\Downloader.bmp
[2015.04.02 11:20:32 | 000,196,104 | ---- | M] () -- \Program Files (x86)\Arc\HttpDownloader.dll
[2013.09.13 19:51:30 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2009.05.23 02:38:52 | 000,061,952 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.dll
[2009.05.22 21:27:34 | 000,004,608 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.tlb
[2014.09.03 01:27:24 | 000,268,432 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2014.09.03 01:27:24 | 000,019,096 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2015.03.26 08:42:28 | 000,597,464 | ---- | M] () -- \Program Files (x86)\Comodo\Chromodo\extensions\media_downloader.crx
[2013.02.01 01:16:50 | 000,065,344 | R--- | M] () -- \Program Files (x86)\Hi-Rez Studios\HiRezGames\smite\Binaries\Win32\PhysXLoader.dll
[2014.06.02 14:10:06 | 000,176,200 | ---- | M] () -- \Program Files (x86)\Cheat Engine 6.4\Kernelmoduleunloader.exe
[2014.06.26 13:50:38 | 000,000,132 | ---- | M] () -- \Program Files (x86)\Cheat Engine 6.4\Kernelmoduleunloader.exe.sig
[2010.08.27 19:43:08 | 000,071,008 | ---- | M] () -- \Program Files (x86)\Mafia II\pc\PhysXLoader.dll
[2013.12.20 02:37:56 | 000,065,344 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2013.12.20 02:37:56 | 000,067,904 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll
[2013.12.20 02:37:44 | 000,073,536 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2013.12.20 02:37:44 | 000,080,704 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader64.dll
[2015.05.11 10:48:02 | 000,473,188 | ---- | M] () -- \Program Files (x86)\RaidCall\flash\XOverlayMainLoader.swf
[2014.12.10 03:28:04 | 000,001,701 | ---- | M] () -- \Program Files (x86)\Steam\friends\broadcastuploaderrornotification.res
[2014.11.11 20:48:42 | 000,007,825 | ---- | M] () -- \Program Files (x86)\Steam\remoteui\static\libs\images\ajax-loader.gif
[2014.10.26 14:23:53 | 000,007,680 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota_ugc\game\bin\win32\pythoncomloader27.dll
[2014.10.26 14:23:43 | 000,008,192 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota_ugc\game\bin\win64\pythoncomloader27.dll
[2013.12.03 19:40:57 | 000,001,985 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GarrysMod\garrysmod\materials\spawnicons\models\pyro_overloader\overloader.png
[2015.03.11 12:53:35 | 000,185,184 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GunZ 2 The Second Duel\APEX_LoaderSHIPPING_x86.dll
[2015.03.11 12:57:16 | 000,064,352 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GunZ 2 The Second Duel\PhysXLoader.dll
[2013.06.23 21:49:46 | 000,134,144 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Skyrim\skse_loader.exe
[2013.06.23 21:49:44 | 000,116,224 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Skyrim\skse_steam_loader.dll
[2015.05.10 17:24:14 | 000,752,440 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\downloader.dll
[2015.05.10 16:39:48 | 000,068,688 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\TERA\Client\Binaries\PhysXLoader.dll
[2013.09.09 15:18:26 | 000,070,944 | ---- | M] () -- \Program Files (x86)\Swordsman_en\bin\physxloader.dll
[2014.11.12 13:48:16 | 000,066,912 | ---- | M] () -- \Program Files (x86)\Swordsman_en\physx\v2.8.4\physxloader64.dll
[2003.09.26 09:15:26 | 000,169,384 | ---- | M] () -- \Program Files (x86)\Valve\cstrike\models\qloader.mdl
[2014.11.16 00:19:56 | 000,690,467 | ---- | M] () -- \Program Files (x86)\Valve\cstrike\sound\vgaming_jb\trance\freeloader.mp3
[2003.09.26 15:19:52 | 000,352,548 | ---- | M] () -- \Program Files (x86)\Valve\valve\models\loader.mdl
[2003.09.26 15:24:16 | 000,012,764 | ---- | M] () -- \Program Files (x86)\Valve\valve\sound\ambience\loader_hydra1.wav
[2003.09.26 15:24:16 | 000,012,164 | ---- | M] () -- \Program Files (x86)\Valve\valve\sound\ambience\loader_step1.wav
[2013.10.25 01:00:22 | 000,099,328 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CC\Support Files\MXF_SDK_MetaMetadata_BinaryLoader_4.4.24.dll
[2013.10.25 01:00:22 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CC\Support Files\MXF_SDK_MetaMetadata_XSDLoader2_4.4.24.dll
[2013.10.25 01:00:22 | 000,148,480 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CC\Support Files\MXF_SDK_MetaMetadata_XSDLoader_4.4.24.dll
[2013.04.17 22:20:32 | 000,099,328 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CC\MXF_SDK_MetaMetadata_BinaryLoader_4.4.13.dll
[2013.04.17 22:20:32 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CC\MXF_SDK_MetaMetadata_XSDLoader2_4.4.13.dll
[2013.04.17 22:20:32 | 000,148,480 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CC\MXF_SDK_MetaMetadata_XSDLoader_4.4.13.dll
[2013.12.15 21:42:36 | 000,099,328 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\MXF_SDK_MetaMetadata_BinaryLoader_4.4.25.dll
[2013.12.15 21:42:36 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\MXF_SDK_MetaMetadata_XSDLoader2_4.4.25.dll
[2013.12.15 21:42:36 | 000,148,480 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\MXF_SDK_MetaMetadata_XSDLoader_4.4.25.dll
[2015.05.12 16:06:53 | 000,072,440 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
[2015.05.12 16:06:53 | 000,085,336 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader64.exe
[2015.05.12 16:06:39 | 000,105,464 | ---- | M] () -- \Program Files\AVAST Software\Avast\ng\aswSfLoader.exe
[2013.03.29 23:28:18 | 000,099,328 | ---- | M] () -- \Program Files\Common Files\Adobe\dynamiclinkmediaserver\7.0\MXF_SDK_MetaMetadata_BinaryLoader_4.4.13.dll
[2013.03.29 23:28:18 | 000,196,608 | ---- | M] () -- \Program Files\Common Files\Adobe\dynamiclinkmediaserver\7.0\MXF_SDK_MetaMetadata_XSDLoader2_4.4.13.dll
[2013.03.29 23:28:18 | 000,148,480 | ---- | M] () -- \Program Files\Common Files\Adobe\dynamiclinkmediaserver\7.0\MXF_SDK_MetaMetadata_XSDLoader_4.4.13.dll
[2014.09.03 01:27:24 | 000,364,176 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2014.09.03 01:27:24 | 000,019,096 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2013.08.22 19:01:26 | 000,061,528 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2011.10.15 13:18:08 | 000,002,941 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2011.10.15 13:18:08 | 000,000,411 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2011.10.15 13:18:10 | 001,138,236 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\modules\org-openide-loaders.jar
[2011.10.15 13:18:08 | 000,007,002 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2011.10.15 13:18:08 | 000,006,658 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2011.10.15 13:18:10 | 000,000,456 | ---- | M] () -- \Pylo\MCreator\jdk\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2014.09.20 20:37:07 | 000,000,404 | ---- | M] () -- \Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.144\deploy\assets\storeImages\layout\small_loader.gif
[2014.08.05 01:51:22 | 000,018,719 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja\2.2.0.18_0\js\configLoader.js
[2014.01.24 01:36:30 | 000,002,597 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja\2.2.0.18_0\js\scriptLoader.js
[2015.03.10 20:26:44 | 000,003,208 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\skin\ajax-loader.gif
[2014.08.13 13:14:30 | 000,009,418 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.33_0\img\gifloader.gif
[2015.02.25 15:30:10 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\093AJZT0\AdLoader[1].htm
[2015.01.17 20:31:34 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\093AJZT0\queryLoader[1].css
[2014.11.26 18:45:50 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\093AJZT0\queryLoader[1].js
[2014.04.08 20:46:39 | 000,112,122 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XL6URKB\AdLoader-7b473315d0084c71df83cdee72aab144.min[1].js
[2014.04.08 20:46:39 | 000,001,870 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XL6URKB\AdLoader[1].htm
[2014.05.29 07:02:49 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XL6URKB\AdLoader[2].htm
[2014.04.08 22:06:38 | 000,000,374 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XL6URKB\queryLoader[1].css
[2015.02.12 17:33:57 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XL6URKB\queryLoader[2].css
[2013.10.13 15:44:31 | 000,000,723 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3CYH2QSI\downloaderror[1].js
[2014.01.30 14:30:26 | 000,111,438 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\AdLoader-8123c724cc0668230ba8270eea997632.min[1].js
[2014.01.30 14:30:26 | 000,001,537 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\AdLoader[1].htm
[2014.12.10 21:48:33 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\AdLoader[2].htm
[2014.11.05 16:53:40 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\queryLoader[1].css
[2014.04.09 07:22:27 | 000,005,708 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\queryLoader[1].js
[2015.04.14 20:46:31 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IO5JO3FU\queryLoader[2].css
[2014.12.10 20:17:10 | 000,019,121 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\AdLoader-288a31a04e1398b1a794975bf93ce9a4.min[1].js
[2014.09.09 07:48:14 | 000,018,715 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\AdLoader-a5fa12058ddb9a8919d6906ba95d7c57.min[1].js
[2014.09.30 21:59:51 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\AdLoader[1].htm
[2014.10.28 19:07:18 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\AdLoader[2].htm
[2015.04.08 19:23:41 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\AdLoader[3].htm
[2014.10.03 15:05:01 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[1].css
[2014.09.04 20:12:52 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[1].js
[2014.10.14 19:56:21 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[2].js
[2015.01.04 04:15:03 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[3].js
[2015.01.17 20:31:35 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[4].js
[2015.02.05 18:37:10 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KULITNTQ\queryLoader[6].js
[2013.10.13 15:44:31 | 000,001,174 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWKUASJZ\downloader[1].js
[2014.09.09 07:48:13 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LV22DN8M\AdLoader[1].htm
[2015.05.10 00:19:41 | 000,003,687 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LV22DN8M\preloaderMusic[1].js
[2015.04.01 20:33:24 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LV22DN8M\queryLoader[1].css
[2014.08.06 18:40:59 | 000,018,544 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\AdLoader-0ee9685baf8ff395a7119d551063e2d4.min[1].js
[2014.05.29 15:35:11 | 000,017,912 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\AdLoader-3b8e790904fffcf74f96367cd382e261.min[2].js
[2014.05.28 22:23:28 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\AdLoader[1].htm
[2014.05.08 09:59:00 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\queryLoader[1].css
[2014.05.08 09:59:04 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\queryLoader[1].js
[2014.05.22 16:20:09 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\queryLoader[2].css
[2014.05.22 16:20:13 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\queryLoader[2].js
[2014.11.20 19:22:59 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1DHH3G9\queryLoader[3].css
[2014.06.03 19:37:59 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\AdLoader[1].htm
[2014.07.02 09:58:06 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\AdLoader[2].htm
[2015.05.13 17:23:44 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\AdLoader[3].htm
[2015.05.15 17:21:48 | 000,011,267 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\loader.min[1].js
[2014.06.05 21:12:12 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\queryLoader[1].css
[2014.06.05 21:12:16 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\queryLoader[1].js
[2015.02.05 18:37:09 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\queryLoader[2].css
[2015.01.13 20:38:22 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\AdLoader[1].htm
[2015.05.15 17:22:22 | 000,011,358 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\loader[1].js
[2014.09.04 20:12:48 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[1].css
[2014.10.14 19:56:21 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[2].css
[2014.10.03 15:05:01 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[2].js
[2015.01.04 04:15:03 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[3].css
[2014.11.05 16:53:40 | 000,005,505 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[3].js
[2015.05.06 16:36:03 | 000,000,353 | ---- | M] () -- \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\queryLoader[5].css
[2015.03.12 12:47:42 | 000,072,638 | ---- | M] () -- \Users\Petr\AppData\Local\Skype\Apps\login\images\loader.gif
[2015.03.12 12:47:42 | 000,003,032 | ---- | M] () -- \Users\Petr\AppData\Local\Skype\Apps\login\images\loader.png
[2015.03.12 12:47:42 | 000,006,012 | ---- | M] () -- \Users\Petr\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2015.03.12 12:47:42 | 000,021,956 | ---- | M] () -- \Users\Petr\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2015.03.12 12:47:42 | 000,009,772 | ---- | M] () -- \Users\Petr\AppData\Local\Skype\Apps\login\images\retina\loader@2x.png
[2013.10.02 04:03:03 | 000,111,756 | ---- | M] () -- \Users\Petr\AppData\Local\Temp\avnwldrtemp\networkloader.log
[2014.04.24 07:08:51 | 000,002,884 | ---- | M] () -- \Users\Petr\AppData\Local\Temp\mcmodinst38731291783134601751398316129368\com\sijobe\spc\core\SPCLoader.class
[2014.04.24 07:08:51 | 000,006,514 | ---- | M] () -- \Users\Petr\AppData\Local\Temp\mcmodinst38731291783134601751398316129368\com\sijobe\spc\util\DynamicClassLoader.class
[2014.04.24 07:08:53 | 000,002,884 | ---- | M] () -- \Users\Petr\AppData\Local\Temp\mcmodinst66391423660470211891398316133068\com\sijobe\spc\core\SPCLoader.class
[2014.04.24 07:08:53 | 000,006,514 | ---- | M] () -- \Users\Petr\AppData\Local\Temp\mcmodinst66391423660470211891398316133068\com\sijobe\spc\util\DynamicClassLoader.class
[2015.04.18 01:19:28 | 000,283,871 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-0.log
[2014.04.23 17:54:30 | 000,047,507 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-0.log.1
[2014.04.23 17:54:14 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-0.log.1.lck
[2015.01.21 19:26:39 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-0.log.lck
[2015.03.15 14:53:31 | 000,299,453 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-1.log
[2015.01.21 19:33:26 | 000,276,459 | ---- | M] () -- \Users\Petr\AppData\Roaming\.minecraft\ForgeModLoader-client-2.log
[2014.01.30 21:45:23 | 000,647,255 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-0.log
[2014.01.24 20:27:10 | 000,636,059 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-0.log.1
[2014.01.24 20:23:54 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-0.log.1.lck
[2014.01.30 21:35:50 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-0.log.lck
[2014.01.30 21:35:46 | 000,684,370 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-1.log
[2014.01.27 21:05:09 | 000,639,393 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\hexxit\ForgeModLoader-client-2.log
[2015.03.02 21:53:32 | 000,046,132 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\official-crafting-dead-mod\ForgeModLoader-client-0.log
[2015.03.02 21:52:50 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\official-crafting-dead-mod\ForgeModLoader-client-0.log.lck
[2014.12.24 23:56:22 | 000,053,952 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\official-crafting-dead-mod\ForgeModLoader-client-1.log
[2014.12.24 22:34:36 | 000,065,811 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\official-crafting-dead-mod\ForgeModLoader-client-2.log
[2015.01.08 18:05:24 | 000,063,356 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\tekkit\ForgeModLoader-0.log
[2015.01.08 18:03:28 | 000,001,980 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\tekkit\mods\ComputerCraft\org\luaj\vm2\luajc\JavaLoader.class
[2014.01.27 18:53:30 | 000,370,603 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\voltz\ForgeModLoader-client-0.log
[2014.01.27 18:25:35 | 000,000,000 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\voltz\ForgeModLoader-client-0.log.lck
[2014.01.27 18:25:21 | 000,415,820 | ---- | M] () -- \Users\Petr\AppData\Roaming\.technic\modpacks\voltz\ForgeModLoader-client-1.log
[2015.04.11 11:47:28 | 000,472,672 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\wolfteam_us_downloader.exe
[2015.05.17 13:44:21 | 000,000,993 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\wolfteam_us_downloader.exe – zástupce (2).lnk
[2015.05.17 13:43:13 | 000,000,993 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\wolfteam_us_downloader.exe – zástupce.lnk
[2015.04.13 10:31:35 | 000,000,656 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\Log\HttpDownloader.log
[2014.01.06 19:20:16 | 000,847,432 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\NyxLauncherIS\Full_Downloader.exe
[2011.12.06 19:39:36 | 000,022,616 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\NyxLauncherIS\Img\Downloader.bmp
[2014.08.31 17:31:39 | 000,169,384 | ---- | M] () -- \Users\Petr\GSplay\csko\cstrike\models\qloader.mdl
[2014.08.31 17:34:17 | 000,352,548 | ---- | M] () -- \Users\Petr\GSplay\csko\valve\models\loader.mdl
[2014.08.31 17:33:50 | 000,012,764 | ---- | M] () -- \Users\Petr\GSplay\csko\valve\sound\ambience\loader_hydra1.wav
[2014.08.31 17:33:49 | 000,012,164 | ---- | M] () -- \Users\Petr\GSplay\csko\valve\sound\ambience\loader_step1.wav
[2014.08.26 01:07:40 | 000,160,768 | ---- | M] () -- \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\APEX_Loader_x64.dll
[2014.08.26 00:58:09 | 000,142,848 | ---- | M] () -- \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\APEX_Loader_x86.dll
[2013.06.07 22:01:47 | 000,319,488 | ---- | M] () -- \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\wws_crashreport_uploader.exe
[2013.02.02 00:04:54 | 000,300,392 | ---- | M] () -- \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\LaunchPad.libs\wws_crashreport_uploader.exe
[2015.01.08 22:22:58 | 000,064,352 | ---- | M] () -- \Users\Public\Trazzy Entertainment\Wind of Luck Arena\Game\PhysXLoader.dll
[2013.03.09 08:52:18 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 20:35:48 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2013.03.09 08:17:04 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 20:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2013.03.09 08:52:18 | 000,364,168 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 20:35:48 | 000,370,512 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2013.03.09 08:17:04 | 000,268,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 20:12:34 | 000,249,680 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000100000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#7 Příspěvek od Lefiks »

[2009.07.14 14:25:34 | 002,202,645 | R--- | M] () -- \Windows\Setup\SCRIPTS\Windows7Loader.exe
[2015.04.27 22:30:14 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_da-dk_2f07472b2328d2ee.manifest
[2015.04.27 22:35:42 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_de-de_2c32dc6724ff2788.manifest
[2015.04.27 22:31:31 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_el-gr_d4c909fa14149016.manifest
[2015.04.27 21:23:13 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_en-us_d523b26013dd334d.manifest
[2015.04.27 22:33:11 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_es-es_d4ef0f44140424f2.manifest
[2015.04.27 22:30:39 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_fi-fi_740a13f1091e171c.manifest
[2015.04.27 22:35:50 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_fr-fr_77a6854306d63b54.manifest
[2015.04.27 22:33:17 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_hu-hu_bf17058aeb360a70.manifest
[2015.04.27 22:33:12 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_it-it_61ce7b89de0820d2.manifest
[2015.04.27 22:39:09 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ja-jp_03f3fa96d12332ad.manifest
[2015.04.27 22:37:42 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ko-kr_a75dd74bc393f9c3.manifest
[2015.04.27 22:28:34 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_nb-no_8ff058809bb9257f.manifest
[2015.04.27 22:34:16 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_nl-nl_8e2fa3be9ce52f54.manifest
[2015.04.27 22:33:02 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pl-pl_d46bfe4082079d08.manifest
[2015.04.27 22:33:22 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pt-br_d6bfe8e4809130ec.manifest
[2015.04.27 22:32:12 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pt-pt_d7a1b8508000a0c8.manifest
[2015.04.27 22:32:46 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ru-ru_1e44ca1464e22ef4.manifest
[2015.04.27 22:31:57 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_sv-se_ba3fb4895c0b394f.manifest
[2015.04.27 22:33:31 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_tr-tr_634cfed04ac73b40.manifest
[2015.04.27 22:39:03 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-cn_34aa1ccdfaff0d5f.manifest
[2015.04.27 22:33:20 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-hk_3355155bfbda7fef.manifest
[2015.04.27 22:38:06 | 000,004,431 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-tw_38a65a23f86fe9cf.manifest
[2015.04.27 22:32:42 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_9fc03df067ff8c4b.manifest
[2015.04.27 22:30:13 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_da-dk_3cfa1e175e45884a.manifest
[2015.04.27 22:35:17 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_de-de_3a25b353601bdce4.manifest
[2015.04.27 22:31:29 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_el-gr_e2bbe0e64f314572.manifest
[2015.04.27 21:23:03 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_en-us_e316894c4ef9e8a9.manifest
[2015.04.27 22:32:01 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_es-es_e2e1e6304f20da4e.manifest
[2015.04.27 22:30:34 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_fi-fi_81fceadd443acc78.manifest
[2015.04.27 22:35:27 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_fr-fr_85995c2f41f2f0b0.manifest
[2015.04.27 22:32:18 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_hu-hu_cd09dc772652bfcc.manifest
[2015.04.27 22:32:06 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_it-it_6fc152761924d62e.manifest
[2015.04.27 22:38:45 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ja-jp_11e6d1830c3fe809.manifest
[2015.04.27 22:37:26 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ko-kr_b550ae37feb0af1f.manifest
[2015.04.27 22:28:32 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_nb-no_9de32f6cd6d5dadb.manifest
[2015.04.27 22:33:38 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_nl-nl_9c227aaad801e4b0.manifest
[2015.04.27 22:31:57 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pl-pl_e25ed52cbd245264.manifest
[2015.04.27 22:32:24 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pt-br_e4b2bfd0bbade648.manifest
[2015.04.27 22:30:56 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_pt-pt_e5948f3cbb1d5624.manifest
[2015.04.27 22:31:34 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_ru-ru_2c37a1009ffee450.manifest
[2015.04.27 22:30:47 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_sv-se_c8328b759727eeab.manifest
[2015.04.27 22:32:41 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_tr-tr_713fd5bc85e3f09c.manifest
[2015.04.27 22:38:42 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-cn_429cf3ba361bc2bb.manifest
[2015.04.27 22:33:19 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-hk_4147ec4836f7354b.manifest
[2015.04.27 22:37:50 | 000,004,434 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_zh-tw_46993110338c9f2b.manifest
[2015.04.27 21:41:03 | 000,005,793 | ---- | M] () -- \Windows\SoftwareDistribution\Download\4cd9ee4dd600ff2423b7df10c650461c\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_9e79873c9a709a4e.manifest
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2009.07.14 03:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 03:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:28:57 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17135_none_66dcd6a595588d81\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:41:11 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17179_none_66b5981d957562a1\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 07:26:58 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17206_none_66fe4899953f502c\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:26:17 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21335_none_67667556ae762a72\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:36:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21386_none_67316604ae9dcf7e\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 16:12:39 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21416_none_677d175eae65090e\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:38:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_68a2edab92971725\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:38:44 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_68d8d569926ebeb2\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 04:12:19 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_68d20a7192733a4d\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.04.15 15:54:01 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:35:00 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_6957a248ab947a6d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:39:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_69239340abbb38d0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 07:32:07 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22209_none_6971452eab80a50e\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 08:20:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_695e76beab8ff095\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.29 04:18:31 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22436_none_694dd858ab9ba72a\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.03.04 13:03:17 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22616_none_69637bfcab8b6996\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.04.12 04:28:21 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22653_none_69353b6eabae8d55\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.04.15 15:54:01 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.03.11 15:00:59 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013.manifest
[2015.03.11 15:00:59 | 000,033,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013_winload.efi.mui_35ee487d
[2015.03.11 15:00:59 | 000,034,752 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013_winload.exe.mui_3bc5b827
[2015.03.11 15:00:59 | 000,029,624 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013_winresume.efi.mui_f412814e
[2015.03.11 15:00:59 | 000,030,136 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013_winresume.exe.mui_ff8b5358
[2015.03.11 15:01:04 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646.manifest
[2015.03.11 15:01:04 | 000,693,176 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646_winload.efi_75834aa0
[2015.03.11 15:01:04 | 000,619,056 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646_winload.exe_75835076
[2015.03.11 15:01:05 | 000,616,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646_winresume.efi_85cd069f
[2015.03.11 15:01:05 | 000,532,176 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646_winresume.exe_85cd1215
[2009.07.14 04:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 04:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2015.05.14 01:17:29 | 000,000,616 | ---- | M] () -- \Windows\winsxs\FileMaps\programdata_microsoft_diagnosis_asimovuploader_0413bca0c3dfdda4.cdf-ms
[2009.07.14 17:15:51 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2014.07.08 23:51:46 | 000,004,141 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_915f8df913af6c96.manifest
[2015.02.03 06:49:45 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_cs-cz_9144f07b13c42013.manifest
[2014.07.08 23:52:03 | 000,004,141 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22736_cs-cz_91de5cbe2cd52578.manifest
[2014.12.13 03:57:48 | 000,004,141 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22908_cs-cz_9200d0e22cbafea1.manifest
[2015.01.13 00:17:25 | 000,004,141 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22921_cs-cz_91e42f042cd18522.manifest
[2015.01.16 08:36:46 | 000,004,141 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22923_cs-cz_91e62f982ccfb7d0.manifest
[2015.01.27 07:32:05 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22943_cs-cz_91d08fc02cdfefb2.manifest
[2015.02.03 07:30:16 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22948_cs-cz_91d591322cdb6e65.manifest
[2015.03.17 08:28:02 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_91faa7482cc099d9.manifest
[2015.04.27 22:33:31 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_91cd67042ce2d6ef.manifest
[2009.07.14 04:13:42 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef.manifest
[2011.02.05 15:09:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.02.05 15:04:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2010.11.20 06:12:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011.02.05 19:34:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2014.08.19 05:35:45 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_b90bc95183772bd0.manifest
[2015.02.03 05:51:30 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_b9293c0383618646.manifest
[2011.02.05 15:09:57 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2014.08.19 05:26:49 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22780_none_b98696ee9ca07f56.manifest
[2014.12.12 08:29:00 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22908_none_b9e51c6a9c5864d4.manifest
[2015.01.12 05:50:53 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22921_none_b9c87a8c9c6eeb55.manifest
[2015.01.16 08:37:02 | 000,005,511 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22923_none_b9ca7b209c6d1e03.manifest
[2015.01.27 06:22:06 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22943_none_b9b4db489c7d55e5.manifest
[2015.02.03 06:17:47 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22948_none_b9b9dcba9c78d498.manifest
[2015.03.17 07:34:28 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23002_none_b9def2d09c5e000c.manifest
[2015.04.27 21:40:54 | 000,005,744 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_b9b1b28c9c803d22.manifest
[2009.07.14 04:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:45:38 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17135_none_0abe3b21dcfb1c4b\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:56:23 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17179_none_0a96fc99dd17f16b\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 06:43:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17206_none_0adfad15dce1def6\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:48:05 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21335_none_0b47d9d2f618b93c\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:44:10 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21386_none_0b12ca80f6405e48\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 06:39:49 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21416_none_0b5e7bdaf60797d8\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:45:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_0cba39e5da114d7c\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.04.15 15:54:01 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:46:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_0d04f7bcf35dc79a\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 06:43:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22209_none_0d52a9aaf32333d8\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 07:53:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_0d3fdb3af3327f5f\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.29 03:54:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22436_none_0d2f3cd4f33e35f4\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.03.04 12:35:49 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22616_none_0d44e078f32df860\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.04.12 04:03:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22653_none_0d169feaf3511c1f\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.04.15 15:54:01 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-libraryloader-l1-1-0.dll
[2015.05.13 07:23:08 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-libraryloader-l1-1-0.dll

< *minodlogin* /s >

< *tnod* /s >
[2014.04.26 12:11:54 | 000,001,852 | ---- | M] () -- \Pylo\MCreator\si\pylo\mcreator\FloatNode.class
[2014.04.26 12:11:54 | 000,001,846 | ---- | M] () -- \Pylo\MCreator\si\pylo\mcreator\IntNode.class
[2014.04.26 12:11:54 | 000,002,171 | ---- | M] () -- \Pylo\MCreator\si\pylo\mcreator\ListNode.class
[2014.04.26 12:11:54 | 000,001,852 | ---- | M] () -- \Pylo\MCreator\si\pylo\mcreator\ShortNode.class

< *AutoKMS* /s >
[2013.10.02 04:53:18 | 000,000,184 | ---- | M] () -- \Windows\AutoKMS.ini
[2013.10.02 06:34:25 | 000,000,983 | ---- | M] () -- \Windows\AutoKMS.log
[2015.05.17 11:36:38 | 000,000,198 | ---- | M] () -- \Windows\Tasks\AutoKMS.job
[2015.05.11 06:57:34 | 000,000,202 | ---- | M] () -- \Windows\Tasks\AutoKMSDaily.job

< *activator* /s >
[2013.03.16 12:26:48 | 000,000,350 | ---- | M] () -- \Pylo\MCreator\res\block\activator_rail.png

< *serial* /s >
[2013.02.13 15:09:51 | 000,020,800 | R--- | M] () -- \Program Files (x86)\Hi-Rez Studios\HiRezGames\smite\Binaries\Autoreporter.XmlSerializers.dll
[2008.09.17 16:33:08 | 000,000,592 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\VBSnippets\1033\Connectivity\EnumerateSerialPorts.snippet
[2008.09.17 16:33:08 | 000,001,178 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\VBSnippets\1033\Connectivity\ReadDatafromaSerialPort.snippet
[2008.09.17 16:33:08 | 000,001,492 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\VBSnippets\1033\Connectivity\UseaSerialPorttoDialaPhoneNumber.snippet
[2014.07.11 00:24:10 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2010.11.05 03:53:39 | 000,090,112 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2013.12.03 15:15:44 | 000,712,704 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\GarrysMod\bin\dmserializers.dll
[2014.12.28 17:48:13 | 000,712,704 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\bin\dmserializers.dll
[2013.10.25 03:28:54 | 000,814,504 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CC\Support Files\boost_serialization.dll
[2013.12.16 04:11:40 | 000,814,496 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CC\boost_serialization.dll
[2014.07.11 00:24:01 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2010.11.05 03:54:42 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2011.10.15 13:18:00 | 000,033,536 | ---- | M] () -- \Pylo\MCreator\jdk\bin\serialver.exe
[2015.03.14 11:19:19 | 000,003,072 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage
[2015.03.14 11:19:19 | 000,003,608 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2015.01.28 15:51:24 | 001,267,712 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage
[2015.01.28 15:51:24 | 000,016,384 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage-journal
[2015.03.14 11:19:19 | 000,003,072 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\Local Storage\http_www.serialzone.cz_0.localstorage
[2015.03.14 11:19:19 | 000,003,608 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2015.01.28 15:51:24 | 001,267,712 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\Local Storage\http_www.sledujuserialy.cz_0.localstorage
[2015.01.28 15:51:24 | 000,016,384 | ---- | M] () -- \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Local Storage\Local Storage\http_www.sledujuserialy.cz_0.localstorage-journal
[2015.03.14 11:19:19 | 000,003,072 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage
[2015.03.14 11:19:19 | 000,003,608 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2015.01.28 15:51:24 | 001,267,712 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage
[2015.01.28 15:51:24 | 000,016,384 | ---- | M] () -- \Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage-journal
[2014.01.09 19:00:10 | 001,387,928 | ---- | M] () -- \Users\Petr\Desktop\Můj Nightcore\Hry\Space Engineers v01.014.010\Bin\Sandbox.CommonLib.XmlSerializers.dll
[2014.01.09 19:00:10 | 001,387,928 | ---- | M] () -- \Users\Petr\Desktop\Můj Nightcore\Hry\Space Engineers v01.014.010\Bin64\Sandbox.CommonLib.XmlSerializers.dll
[2013.12.27 19:29:27 | 000,712,704 | ---- | M] () -- \Users\Petr\Desktop\Nepoužitelné hovadiny\Gmod server\steamapps\common\GarrysModDS\bin\dmserializers.dll
[2015.01.08 22:25:05 | 000,056,864 | ---- | M] () -- \Users\Public\Trazzy Entertainment\Wind of Luck Arena\Game\Data\resources\interface\fonts\QuebecSerial-Regular.ttf
[2013.07.08 14:43:52 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.24 01:43:20 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2014.07.11 00:24:10 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.10.16 08:12:14 | 000,310,784 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\91eb4f41130c65ef17f0fee1d3ab48fb\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.16 09:07:29 | 002,347,008 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\b1e0939384cc320d6ac7b8921ccc2877\System.Runtime.Serialization.ni.dll
[2014.10.16 08:14:19 | 000,396,288 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\2a07bf9a29a64827bf06e7853214fc0f\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.16 09:49:48 | 003,073,536 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\5015b90fbd31c9ba4fff989b2c79711b\System.Runtime.Serialization.ni.dll
[2015.01.22 18:43:20 | 000,306,176 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runt9064068c#\a94049de665f1854ea5df1a857b2c68f\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2015.01.22 18:43:20 | 000,000,440 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runt9064068c#\a94049de665f1854ea5df1a857b2c68f\System.Runtime.Serialization.Formatters.Soap.ni.dll.aux
[2015.01.22 18:44:39 | 002,855,424 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\187177229c00aec6dec613ea4b9ff209\System.Runtime.Serialization.ni.dll
[2015.01.22 18:44:39 | 000,000,996 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\187177229c00aec6dec613ea4b9ff209\System.Runtime.Serialization.ni.dll.aux
[2015.01.22 20:35:32 | 000,025,600 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.84e525b7#\ad0261438ff8f46e093faa717226ebef\System.Xml.Serialization.ni.dll
[2015.01.22 20:35:32 | 000,000,284 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.84e525b7#\ad0261438ff8f46e093faa717226ebef\System.Xml.Serialization.ni.dll.aux
[2015.01.24 01:52:02 | 000,366,080 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runt9064068c#\769e80c5193dedd5ef90a962c002d15a\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2015.01.24 01:52:02 | 000,000,440 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runt9064068c#\769e80c5193dedd5ef90a962c002d15a\System.Runtime.Serialization.Formatters.Soap.ni.dll.aux
[2015.01.24 15:55:57 | 003,597,312 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\cdca00d5c58d31de2503310a31ca096f\System.Runtime.Serialization.ni.dll
[2015.01.24 15:55:57 | 000,000,996 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\cdca00d5c58d31de2503310a31ca096f\System.Runtime.Serialization.ni.dll.aux
[2015.01.24 15:57:06 | 000,027,648 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.84e525b7#\85b2d15d965e64489744325c53d91db0\System.Xml.Serialization.ni.dll
[2015.01.24 15:57:06 | 000,000,284 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.84e525b7#\85b2d15d965e64489744325c53d91db0\System.Xml.Serialization.ni.dll.aux
[2014.04.12 01:48:40 | 001,051,888 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\6414876250E69FF3395387C6C7F05BEB\4.5.51209\System.Runtime.Serialization.dll.amd64
[2014.04.12 01:48:40 | 001,051,888 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\6414876250E69FF3395387C6C7F05BEB\4.5.51209\System.Runtime.Serialization.dll.x86
[2014.04.12 01:48:40 | 001,051,888 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\6414876250E69FF3395387C6C7F05BEB\4.5.51209\System.Runtime.Serialization.dll_gac_x86
[2014.04.12 01:48:40 | 000,133,432 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2014.04.12 00:08:06 | 000,029,472 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Json\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Json.dll
[2014.04.12 00:08:06 | 000,029,512 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Primitives\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Primitives.dll
[2014.04.12 00:08:06 | 000,029,976 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Xml\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Xml.dll
[2014.07.23 01:17:44 | 001,050,840 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.04.12 00:08:06 | 000,045,800 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2014.04.12 00:08:06 | 000,029,928 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.XmlSerializer\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Xml.XmlSerializer.dll
[2014.06.24 01:43:20 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2009.05.23 07:30:34 | 000,008,007 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.xml
[2010.11.05 03:53:33 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.07.11 00:24:11 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.23 01:17:44 | 001,050,840 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2014.04.12 01:48:40 | 000,133,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2014.04.12 00:08:06 | 000,029,472 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Json.dll
[2014.04.12 00:08:06 | 000,029,512 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2014.04.12 00:08:06 | 000,029,976 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2014.04.12 00:08:06 | 000,045,800 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2014.04.12 00:08:06 | 000,029,928 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.XmlSerializer.dll
[2014.06.24 01:43:09 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.05 03:54:38 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014.07.11 00:24:02 | 000,847,872 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.23 01:17:44 | 001,050,840 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2014.04.12 01:48:40 | 000,133,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2014.04.12 00:08:06 | 000,029,472 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Json.dll
[2014.04.12 00:08:06 | 000,029,512 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2014.04.12 00:08:06 | 000,029,976 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2014.04.12 00:08:06 | 000,045,800 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
[2014.04.12 00:08:06 | 000,029,928 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.XmlSerializer.dll
[2009.07.14 03:16:13 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2009.07.14 17:17:13 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2009.07.14 02:00:40 | 000,094,208 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_amd64_neutral_fdcfb86ce78678d1\serial.sys
[2009.06.10 22:37:50 | 000,038,400 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_amd64_neutral_6fb75ea318f84fe5\grserial.sys
[2009.07.14 03:16:13 | 000,015,360 | ---- | M] () -- \Windows\SysWOW64\serialui.dll
[2009.07.14 17:17:13 | 000,005,120 | ---- | M] () -- \Windows\SysWOW64\cs-CZ\serialui.dll.mui
[2009.07.14 17:17:19 | 000,011,776 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_1c215c9ac50719c5\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010.11.05 03:54:38 | 000,011,776 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_1e527062c1f59d5f\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010.11.05 03:54:38 | 000,011,776 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_1e468964c1feb99a\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010.11.05 03:54:38 | 000,011,776 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.22731_cs-cz_1ec35795db263fce\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2009.07.14 17:17:22 | 000,005,120 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_aa5fd338fd5bcb23\serialui.dll.mui
[2009.07.14 03:41:54 | 000,017,920 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_50f69335385bc360\serialui.dll
[2009.07.14 17:17:32 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_b96904386c2fe002\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:54:42 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_bb9a1800691e639c\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:54:42 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_bb8e310269277fd7\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:54:42 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.22733_cs-cz_bc0cffc7824d38b9\System.RunTime.Serialization.Resources.dll
[2009.07.14 17:17:25 | 000,009,728 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_20ab142d65ed6acc\serial.sys.mui
[2009.07.14 02:00:40 | 000,094,208 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_548ca258d20f4ada\serial.sys
[2009.06.10 22:40:06 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_a9d1bee515273f56\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 01:43:09 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.18523_none_a9a7e561157d82e9\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 01:43:05 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.22733_none_92db3ec72f23fc97\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.10 22:37:50 | 000,038,400 | ---- | M] () -- \Windows\winsxs\amd64_smartcrd.inf_31bf3856ad364e35_6.1.7600.16385_none_ce9ed3064deed3aa\grserial.sys
[2009.06.10 22:30:46 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.16385_none_5943b25a748cb06c\System.Runtime.Serialization.dll
[2012.10.06 12:53:01 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.17136_none_593e9c4e749147df\System.Runtime.Serialization.dll
[2012.10.06 12:56:09 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.21337_none_4270dea28e38c1d7\System.Runtime.Serialization.dll
[2010.11.05 03:52:16 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17514_none_5918bfde74e3f722\System.Runtime.Serialization.dll
[2012.10.05 12:52:38 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17966_none_591d933074dfaa5b\System.Runtime.Serialization.dll
[2014.03.09 23:48:51 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.18523_none_5919d8d674e2f3ff\System.Runtime.Serialization.dll
[2014.07.11 00:24:02 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.18532_none_591aefe874e1f3b5\System.Runtime.Serialization.dll
[2012.10.06 12:56:09 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22126_none_424bee728e8a9f53\System.Runtime.Serialization.dll
[2014.03.17 16:38:51 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22733_none_424d323c8e896dad\System.Runtime.Serialization.dll
[2014.07.08 01:36:29 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22743_none_424e32868e888704\System.Runtime.Serialization.dll
[2009.06.10 22:30:43 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_941abf24c884ab05\System.Runtime.Serialization.dll
[2012.10.06 12:53:00 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.17136_none_9415a918c8894278\System.Runtime.Serialization.dll
[2012.10.06 12:56:08 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.21337_none_7d47eb6ce230bc70\System.Runtime.Serialization.dll
[2010.11.05 03:52:08 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_93efcca8c8dbf1bb\System.Runtime.Serialization.dll
[2012.10.05 12:52:37 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_93f49ffac8d7a4f4\System.Runtime.Serialization.dll
[2014.03.09 23:48:50 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_93f0e5a0c8daee98\System.Runtime.Serialization.dll
[2014.07.11 00:24:01 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_93f1fcb2c8d9ee4e\System.Runtime.Serialization.dll
[2012.10.06 12:56:08 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_7d22fb3ce28299ec\System.Runtime.Serialization.dll
[2014.03.17 16:38:51 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_7d243f06e2816846\System.Runtime.Serialization.dll
[2014.07.08 01:36:29 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_7d253f50e280819d\System.Runtime.Serialization.dll
[2013.10.13 23:27:45 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8.manifest
[2013.10.13 23:27:45 | 000,017,792 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8_kdcom.dll_db5e7744
[2009.07.14 17:17:49 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_aa5fd338fd5bcb23_serialui.dll.mui_7d29d2a3
[2009.07.14 04:57:29 | 000,017,920 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_50f69335385bc360_serialui.dll_bea29328
[2009.07.14 17:17:47 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed_serialui.dll.mui_7d29d2a3
[2009.07.14 04:58:37 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a_serialui.dll_bea29328
[2009.07.14 04:15:17 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_6daa7ec5c65bf5bc.manifest
[2011.02.05 15:10:43 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16757_none_6dccf6b5c641c933.manifest
[2011.02.05 15:05:47 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.20897_none_6e2b53d0df7fd8c1.manifest
[2011.02.05 19:35:45 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8.manifest
[2011.02.05 15:11:05 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.21655_none_703aeff2dc87a23b.manifest
[2009.07.14 04:11:30 | 000,000,868 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.1.7600.16385_none_88b1c48f2026fe3f.manifest
[2009.07.14 04:26:23 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.16385_none_5943b25a748cb06c.manifest
[2012.10.06 20:44:48 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.17136_none_593e9c4e749147df.manifest
[2012.10.06 21:00:33 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7600.21337_none_4270dea28e38c1d7.manifest
[2010.11.20 06:21:24 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17514_none_5918bfde74e3f722.manifest
[2012.10.05 20:18:30 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17966_none_591d933074dfaa5b.manifest
[2014.07.02 08:30:52 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.18523_none_5919d8d674e2f3ff.manifest
[2014.07.14 04:24:48 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.18532_none_591aefe874e1f3b5.manifest
[2012.10.05 20:10:31 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22126_none_424bee728e8a9f53.manifest
[2014.07.02 08:30:44 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22733_none_424d323c8e896dad.manifest
[2014.07.14 04:13:57 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.22743_none_424e32868e888704.manifest
[2009.07.14 04:27:09 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_941abf24c884ab05.manifest
[2012.10.06 20:46:10 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.17136_none_9415a918c8894278.manifest
[2012.10.06 21:01:29 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.21337_none_7d47eb6ce230bc70.manifest
[2010.11.20 06:22:10 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_93efcca8c8dbf1bb.manifest
[2012.10.05 20:19:07 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_93f49ffac8d7a4f4.manifest
[2014.07.02 08:31:00 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_93f0e5a0c8daee98.manifest
[2014.07.14 04:24:58 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_93f1fcb2c8d9ee4e.manifest
[2012.10.05 20:11:10 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_7d22fb3ce28299ec.manifest
[2014.07.02 08:30:53 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_7d243f06e2816846.manifest
[2014.07.14 04:14:06 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_7d253f50e280819d.manifest
[2009.07.14 03:52:33 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.16385_none_a6aa149474833896.manifest
[2012.10.06 20:07:20 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.17136_none_a6a4fe887487d009.manifest
[2012.10.06 20:58:54 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.21337_none_8fd740dc8e2f4a01.manifest
[2010.11.20 05:06:16 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c.manifest
[2012.10.05 19:15:39 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285.manifest
[2014.07.02 07:57:49 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29.manifest
[2014.07.14 04:04:09 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf.manifest
[2012.10.05 19:17:50 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d.manifest
[2014.07.02 08:07:46 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7.manifest
[2014.07.14 04:04:27 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e.manifest
[2009.07.14 17:16:38 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0.manifest
[2012.10.06 22:42:01 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.17136_cs-cz_3450454183d3f023.manifest
[2012.10.07 00:05:03 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.21337_cs-cz_1d8287959d7b6a1b.manifest
[2012.10.05 22:12:17 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f.manifest
[2014.07.02 09:46:46 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43.manifest
[2014.07.14 06:02:27 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9.manifest
[2012.10.05 21:59:28 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797.manifest
[2014.07.02 10:08:13 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1.manifest
[2014.07.14 06:06:58 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48.manifest
[2009.07.14 03:51:52 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.16385_none_d6ed4a2e9c2a39c9.manifest
[2012.10.06 20:11:48 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.17136_none_d6e834229c2ed13c.manifest
[2012.10.06 21:03:01 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.21337_none_c01a7676b5d64b34.manifest
[2010.11.20 05:05:38 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f.manifest
[2012.10.05 19:15:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8.manifest
[2014.07.02 08:00:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c.manifest
[2014.07.14 04:06:40 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12.manifest
[2012.10.05 19:17:15 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0.manifest
[2014.07.02 08:10:04 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a.manifest
[2014.07.14 04:06:53 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061.manifest
[2009.07.14 03:57:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_dbc7f5fbdd00d40b.manifest
[2012.10.06 20:09:38 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.17136_none_dbc2dfefdd056b7e.manifest
[2012.10.06 21:00:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.21337_none_c4f52243f6ace576.manifest
[2010.11.20 05:10:46 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1.manifest
[2012.10.05 19:19:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa.manifest
[2014.07.02 07:58:58 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e.manifest
[2014.07.14 04:05:25 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754.manifest
[2012.10.05 19:22:10 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2.manifest
[2014.07.02 08:08:55 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c.manifest
[2014.07.14 04:05:41 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3.manifest
[2009.06.10 23:23:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_1c9a3ec1e01c684b\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 01:43:20 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.18523_none_1c70653de072abde\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 01:43:36 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.22733_none_05a3bea3fa19258c\System.Runtime.Serialization.Formatters.Soap.dll
[2009.07.14 17:17:20 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7600.16385_cs-cz_d5c3552dd9b47144\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.07.08 14:43:52 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7601.18523_cs-cz_d5997ba9da0ab4d7\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.06.10 23:14:06 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.16385_none_a6aa149474833896\System.Runtime.Serialization.dll
[2012.10.06 12:54:26 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.17136_none_a6a4fe887487d009\System.Runtime.Serialization.dll
[2012.10.06 12:57:06 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.21337_none_8fd740dc8e2f4a01\System.Runtime.Serialization.dll
[2010.11.05 03:52:39 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c\System.Runtime.Serialization.dll
[2012.10.05 12:53:24 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285\System.Runtime.Serialization.dll
[2014.03.09 23:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29\System.Runtime.Serialization.dll
[2014.07.11 00:24:11 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf\System.Runtime.Serialization.dll
[2012.10.06 12:57:06 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d\System.Runtime.Serialization.dll
[2014.03.17 16:38:28 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7\System.Runtime.Serialization.dll
[2014.07.08 01:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e\System.Runtime.Serialization.dll
[2009.07.14 17:17:32 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0\System.RunTime.Serialization.Resources.dll
[2009.07.14 17:17:32 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.17136_cs-cz_3450454183d3f023\System.RunTime.Serialization.Resources.dll
[2009.07.14 17:17:32 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.21337_cs-cz_1d8287959d7b6a1b\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:02:06 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1\System.RunTime.Serialization.Resources.dll
[2010.11.13 04:37:37 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48\System.RunTime.Serialization.Resources.dll
[2009.06.10 23:13:54 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.16385_none_d6ed4a2e9c2a39c9\System.Runtime.Serialization.dll
[2012.10.06 12:54:25 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.17136_none_d6e834229c2ed13c\System.Runtime.Serialization.dll
[2012.10.06 12:57:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.21337_none_c01a7676b5d64b34\System.Runtime.Serialization.dll
[2010.11.05 03:52:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f\System.Runtime.Serialization.dll
[2012.10.05 12:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8\System.Runtime.Serialization.dll
[2014.03.09 23:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c\System.Runtime.Serialization.dll
[2014.07.11 00:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12\System.Runtime.Serialization.dll
[2012.10.06 12:57:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0\System.Runtime.Serialization.dll
[2014.03.17 16:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a\System.Runtime.Serialization.dll
[2014.07.08 01:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061\System.Runtime.Serialization.dll
[2009.07.14 17:17:21 | 000,011,776 | ---- | M] () -- \Windows\winsxs\wow64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_267606ecf967dbc0\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.11.05 03:53:33 | 000,011,776 | ---- | M] () -- \Windows\winsxs\wow64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_28a71ab4f6565f5a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.11.05 03:53:33 | 000,011,776 | ---- | M] () -- \Windows\winsxs\wow64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_289b33b6f65f7b95\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.11.05 03:53:33 | 000,011,776 | ---- | M] () -- \Windows\winsxs\wow64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.22731_cs-cz_291801e80f8701c9\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.07.14 17:17:13 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed\serialui.dll.mui
[2009.07.14 03:16:13 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a\serialui.dll
[2009.07.14 17:17:32 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_5d4a68b4b3d26ecc\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:53:39 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_5f7b7c7cb0c0f266\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:53:39 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_5f6f957eb0ca0ea1\System.RunTime.Serialization.Resources.dll
[2010.11.05 03:53:39 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.22733_cs-cz_5fee6443c9efc783\System.RunTime.Serialization.Resources.dll
[2009.06.10 23:13:54 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_dbc7f5fbdd00d40b\System.Runtime.Serialization.dll
[2012.10.06 12:54:25 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.17136_none_dbc2dfefdd056b7e\System.Runtime.Serialization.dll
[2012.10.06 12:57:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.21337_none_c4f52243f6ace576\System.Runtime.Serialization.dll
[2010.11.05 03:52:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1\System.Runtime.Serialization.dll
[2012.10.05 12:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa\System.Runtime.Serialization.dll
[2014.03.09 23:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e\System.Runtime.Serialization.dll
[2014.07.11 00:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754\System.Runtime.Serialization.dll
[2012.10.06 12:57:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2\System.Runtime.Serialization.dll
[2014.03.17 16:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c\System.Runtime.Serialization.dll
[2014.07.08 01:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3\System.Runtime.Serialization.dll

< *w7lxe* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.1.7601.22943_none_1398723d3e42b6cc\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.1.7601.18738_none_131ea4ea25187c9d\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-tracedatahelper_31bf3856ad364e35_6.1.7601.23040_none_fecf2d3949aa3367\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-tracedatahelper_31bf3856ad364e35_6.1.7601.18839_none_fe598ad2307c2879\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.2.7601.22562_cs-cz_ec638d1840c0276e\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.2.7601.18361_cs-cz_ebd8ee1d27a37126\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.1.7601.22787_cs-cz_24242539a2007f30\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.1.7601.18581_cs-cz_239484cc88e84a35\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.22793_none_ebc6c37166fbce3b\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.22562_none_ebe62f1f66e466c3\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.18585_none_eb49f5404dd44807\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.18361_none_eb5b90244dc7b07b\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_23a6c740c824be85\tsgqec.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_23a6c740c824be85\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_23a6c740c824be85\aaclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_231726d3af0c898a\tsgqec.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_231726d3af0c898a\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_231726d3af0c898a\aaclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_cd128487ae7b1595\rtscom.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_cd128487ae7b1595\journal.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_cd128487ae7b1595\InkObj.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_cd128487ae7b1595\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_cd128487ae7b1595\InkDiv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_cc98e0f89550a54b\rtscom.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_cc98e0f89550a54b\journal.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_cc98e0f89550a54b\InkObj.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_cc98e0f89550a54b\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_cc98e0f89550a54b\InkDiv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..cesclient.resources_31bf3856ad364e35_7.1.7601.22787_cs-cz_250028df89a089d9\mstsc.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-t..cesclient.resources_31bf3856ad364e35_7.1.7601.18581_cs-cz_24708872708854de\mstsc.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\xmllite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wrpint.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wmiutils.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wmicmiplugin.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wdscore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wcp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wbemprox.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wbemcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\wbemcomn.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\SvcIni.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\smipi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\smiengine.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\repdrvfs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\poqexec.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\PkgMgr.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\OEMHelpIns.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\mspatcha.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\msdelta.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\mofinstall.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\mofd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\locdrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\helpcins.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\fastprox.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\esscli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\drvstore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\DrUpdate.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\dpx.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\CntrtextInstaller.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\cmiv2.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\cmitrust.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\cmiadapter.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\CbsMsg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\CbsCore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\apss.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\apircl.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_0b32a93025b365c1\apds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-sechost_31bf3856ad364e35_6.1.7601.23040_none_8a2f39b444722263\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-sechost_31bf3856ad364e35_6.1.7601.18839_none_89b9974d2b441775\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23040_none_c6248e46190bf075\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23040_none_c6248e46190bf075\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23017_none_c64c001018ed4e03\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23017_none_c64c001018ed4e03\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23002_none_c651ce8a18e9b35f\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23002_none_c651ce8a18e9b35f\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18839_none_c5aeebdeffdde587\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18839_none_c5aeebdeffdde587\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18812_none_c5bd89b0ffd3fc44\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18812_none_c5bd89b0ffd3fc44\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18798_none_c56d0a27000f76af\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18798_none_c56d0a27000f76af\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-s..-jscript9.resources_31bf3856ad364e35_11.2.9600.17801_en-us_67c7065fd4e2d7c1\jscript9.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_638fd7a7765109fc\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_638fd7a7765109fc\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_638fd7a7765109fc\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_638fd7a7765109fc\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_638fd7a7765109fc\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_631a35405d22ff0e\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_631a35405d22ff0e\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_631a35405d22ff0e\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_631a35405d22ff0e\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_631a35405d22ff0e\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23040_none_6e9cbe772b9efe0c\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23040_none_6e9cbe772b9efe0c\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23002_none_6ec9febb2b7cc0f6\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23002_none_6ec9febb2b7cc0f6\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18839_none_6e271c101270f31e\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18839_none_6e271c101270f31e\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18798_none_6de53a5812a28446\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18798_none_6de53a5812a28446\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23040_none_604ab2686917fa47\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23017_none_6072243268f957d5\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23002_none_6077f2ac68f5bd31\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18839_none_5fd510014fe9ef59\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18812_none_5fe3add34fe00616\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18798_none_5f932e49501b8081\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_c9aed724efe96060\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_c9aed724efe96060\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_c9aed724efe96060\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_c9aed724efe96060\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_c9d648eeefcabdee\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_c9d648eeefcabdee\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_c9d648eeefcabdee\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_c9d648eeefcabdee\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_c9dc1768efc7234a\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_c9dc1768efc7234a\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_c9dc1768efc7234a\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_c9dc1768efc7234a\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_c93934bdd6bb5572\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_c93934bdd6bb5572\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_c93934bdd6bb5572\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_c93934bdd6bb5572\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_c947d28fd6b16c2f\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_c947d28fd6b16c2f\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_c947d28fd6b16c2f\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_c947d28fd6b16c2f\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_c8f75305d6ece69a\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_c8f75305d6ece69a\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_c8f75305d6ece69a\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_c8f75305d6ece69a\adtschema.dll:$CmdTcID

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#8 Příspěvek od Lefiks »

@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_191bb56dea5df613\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_191bb56dea5df613\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_191bb56dea5df613\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_191bb56dea5df613\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_19432737ea3f53a1\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_19432737ea3f53a1\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_19432737ea3f53a1\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_19432737ea3f53a1\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_1948f5b1ea3bb8fd\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_1948f5b1ea3bb8fd\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_1948f5b1ea3bb8fd\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_1948f5b1ea3bb8fd\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_18a61306d12feb25\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_18a61306d12feb25\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_18a61306d12feb25\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_18a61306d12feb25\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_18b4b0d8d12601e2\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_18b4b0d8d12601e2\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_18b4b0d8d12601e2\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_18b4b0d8d12601e2\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_1864314ed1617c4d\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_1864314ed1617c4d\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_1864314ed1617c4d\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_1864314ed1617c4d\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-vgx_31bf3856ad364e35_11.2.9600.17801_none_7342ea0f458d3ec8\VGX.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_11.2.9600.17801_none_cdaf82fde9567789\sqmapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_11.2.9600.17801_none_cdaf82fde9567789\iertutil.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-ratings_31bf3856ad364e35_11.2.9600.17801_none_4d9e16f8b98d820d\msrating.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-networkinspection_31bf3856ad364e35_11.2.9600.17801_none_fb08630db0d2e8f3\networkinspection.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-mshtmldac_31bf3856ad364e35_11.2.9600.17801_none_5e497b4053f013ae\MshtmlDac.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-jsprofilerui_31bf3856ad364e35_11.2.9600.17801_none_790ad24c2b053ed3\jsprofilerui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_11.2.9600.17801_none_6ea7b1c2ee74a4c7\ieinstal.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_11.2.9600.17801_none_cd990899f70b4a19\IEShims.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_11.2.9600.17801_none_163abd03a762e3ab\ieproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-ielowutil_31bf3856ad364e35_11.2.9600.17801_none_8c81e4cace0d0171\ielowutil.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ieframe.resources_31bf3856ad364e35_11.2.9600.17801_en-us_15d220d52a809e2e\ieui.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ieframe.resources_31bf3856ad364e35_11.2.9600.17801_en-us_15d220d52a809e2e\ieframe.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-f12tools_31bf3856ad364e35_11.2.9600.17801_none_0f4c176cedf33e7b\F12Tools.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-f12tools.resources_31bf3856ad364e35_11.2.9600.17801_en-us_30b4bed011c36062\F12Tools.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-f12diagnosticstap_31bf3856ad364e35_11.2.9600.17801_none_38354546d4368ec1\DiagnosticsTap.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_11.2.9600.17801_none_c1b0e5749ca8a56d\iedvtool.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_11.2.9600.17801_none_819deefbc890d37f\ieapfltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_11.2.9600.17801_none_fa5c451db44f79f3\iedkcs32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..trolpanel.resources_31bf3856ad364e35_11.2.9600.17801_en-us_a8967dfc44fe6a54\inetcpl.cpl.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17801_none_87f4cc21fea5592c\wininet.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17801_none_87f4cc21fea5592c\jsproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..rityzones.resources_31bf3856ad364e35_11.2.9600.17801_en-us_f48e8a443e4baf90\urlmon.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..riptcollectionagent_31bf3856ad364e35_11.2.9600.17801_none_3bd320b1f59cb267\JavaScriptCollectionAgent.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..rendering.resources_31bf3856ad364e35_11.2.9600.17801_en-us_92f4442b603f6d3b\mshtml.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..osticstap.resources_31bf3856ad364e35_11.2.9600.17801_en-us_110612fc41a473a8\DiagnosticsTap.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_11.2.9600.17801_none_15457eb4aeaad7bd\inetcpl.cpl:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_11.2.9600.17801_none_3aeef080339c3299\urlmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-directwrite_31bf3856ad364e35_7.1.7601.23038_none_c68d1a7a01c252ee\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-directwrite_31bf3856ad364e35_7.1.7601.18834_none_c5ffa464e8a81a86\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-directwrite_31bf3856ad364e35_6.1.7601.23038_none_d51c9e3476dbaa1f\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-directwrite_31bf3856ad364e35_6.1.7601.18834_none_d48f281f5dc171b7\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23040_none_d9ea1252b42373ca\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23017_none_da11841cb404d158\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23002_none_da175296b40136b4\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.18833_none_d96e6e2f9afad0d2\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_23d5686530564879\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_23fcda2f3037a607\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_2402a8a930340b63\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.18833_cs-cz_2359c442172da581\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.1.7601.23040_none_e5b4ae80fdfda454\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.1.7601.18839_none_e53f0c19e4cf9966\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_d79f89ae41567edd\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_d729e747282873ef\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.1.7601.22981_none_0e677e5669e4f94f\AcSpecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.1.7601.18777_none_0deeb14d50b9d877\AcSpecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.1.7601.22981_none_0e667e0c69e5dff8\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.1.7601.18777_none_0dedb10350babf20\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23038_none_5c058d9ba00f5e20\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18834_none_72d38c5186679d48\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.7601.23038_none_6cb41eb707098479\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.7601.18834_none_83821d6ced61c3a1\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.23011_none_2b19399a457dfe3d\comctl32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18807_none_41e554362bd82458\comctl32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_d1056ab63b89509e\acwow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_d132aafa3b671388\acwow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_d08fc84f225b45b0\acwow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_d04de697228cd6d8\acwow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_7.1.7601.22787_none_a80852ef10524b37\mstsc.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_7.1.7601.18581_none_a778b281f73a163c\mstsc.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23040_none_afbf729417791cfe\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23002_none_afecb2d81756dfe8\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18839_none_af49d02cfe4b1210\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18798_none_af07ee74fe7ca338\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23040_none_151a4aa97d6bbe8f\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23002_none_15478aed7d498179\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18839_none_14a4a842643db3a1\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18798_none_1462c68a646f44c9\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23045_none_8afaef2cb9787449\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23040_none_8af5edbab97cf596\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23002_none_8b232dfeb95ab880\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18843_none_8a6f79aba05c6e8f\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18839_none_8a804b53a04eeaa8\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18798_none_8a3e699ba0807bd0\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23040_none_e5928f7fc6c4e1ed\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23017_none_e5ba0149c6a63f7b\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23002_none_e5bfcfc3c6a2a4d7\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18839_none_e51ced18ad96d6ff\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18812_none_e52b8aeaad8cedbc\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18798_none_e4db0b60adc86827\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23040_none_4fb67fd81507aecd\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23017_none_4fddf1a214e90c5b\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23002_none_4fe3c01c14e571b7\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18839_none_4f40dd70fbd9a3df\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18812_none_4f4f7b42fbcfba9c\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18798_none_4efefbb8fc0b3507\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23040_none_a3acedc3e0ef329e\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23017_none_a3d45f8de0d0902c\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23002_none_a3da2e07e0ccf588\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18839_none_a3374b5cc7c127b0\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18812_none_a345e92ec7b73e6d\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18798_none_a2f569a4c7f2b8d8\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-scripting-vbscript_31bf3856ad364e35_11.2.9600.17801_none_34d921c977777dc0\vbscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-scripting-jscript9_31bf3856ad364e35_11.2.9600.17801_none_30a8ab2a0741f12d\jscript9diag.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-scripting-jscript9_31bf3856ad364e35_11.2.9600.17801_none_30a8ab2a0741f12d\jscript9.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-scripting-jscript_31bf3856ad364e35_11.2.9600.17801_none_6f5f071140b4d184\jscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.23040_none_c1b680ee6067caeb\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.23002_none_c1e3c13260458dd5\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.18839_none_c140de874739bffd\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.18798_none_c0fefccf476b5125\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_0f2a2d6ec105570b\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_0f2a2d6ec105570b\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_0f519f38c0e6b499\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_0f519f38c0e6b499\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0f576db2c0e319f5\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0f576db2c0e319f5\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_0eb48b07a7d74c1d\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_0eb48b07a7d74c1d\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_0ec328d9a7cd62da\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_0ec328d9a7cd62da\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_0e72a94fa808dd45\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_0e72a94fa808dd45\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.23040_none_8fe21b0018ce2f6f\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.23002_none_900f5b4418abf259\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.18839_none_8f6c7898ffa02481\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.18798_none_8f2a96e0ffd1b5a9\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.23040_none_fc9d87edba85a783\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.23002_none_fccac831ba636a6d\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18839_none_fc27e586a1579c95\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18798_none_fbe603cea1892dbd\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-setup-support_31bf3856ad364e35_11.2.9600.17801_none_b24fd39ea809c3e5\iesetup.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-setup-support_31bf3856ad364e35_11.2.9600.17801_none_b24fd39ea809c3e5\iernonce.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17801_none_1be11e83638efb40\ieUnatt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-ieetwcollector_31bf3856ad364e35_11.2.9600.17801_none_af95b5524c57424f\ieetwproxystub.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrenderingmedia_31bf3856ad364e35_11.2.9600.17801_none_aaffc9a0a2dc80df\mshtmlmedia.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17801_none_ffc231166bb9f593\mshtml.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlediting_31bf3856ad364e35_11.2.9600.17801_none_34a807e18cf53f6b\mshtmled.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ieframe_31bf3856ad364e35_11.2.9600.17801_none_51218b19f7af83c0\ieui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ieframe_31bf3856ad364e35_11.2.9600.17801_none_51218b19f7af83c0\ieframe.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_11.2.9600.17801_none_4c65a8c68406df15\msfeeds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_11.2.9600.17801_none_84456d89cb348cde\dxtrans.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_11.2.9600.17801_none_84456d89cb348cde\dxtmsft.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17801_none_85357ad3f756424b\iexplore.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_c02bb2f816616adb\appidapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_c058f33c163f2dc5\appidapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7601.22981_none_74d7c34e56a5e07b\AcRes.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7601.18777_none_745ef6453d7abfa3\AcRes.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3dc68ee2b1134b71\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3dc68ee2b1134b71\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3dc68ee2b1134b71\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_3d4dc1d997e82a99\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_3d4dc1d997e82a99\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_3d4dc1d997e82a99\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_wpdmtp.inf_31bf3856ad364e35_6.1.7601.22943_none_7e2866b9b68712de\WpdMtpDr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_wpdmtp.inf_31bf3856ad364e35_6.1.7601.18738_none_7dae99669d5cd8af\WpdMtpDr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.1.7601.22943_none_6fb70dc0f6a02802\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wpd-shellextension_31bf3856ad364e35_6.1.7601.18738_none_6f3d406ddd75edd3\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_c6b0c06407288ea3\wow64win.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_c6b0c06407288ea3\wow64cpu.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_c6b0c06407288ea3\wow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23040_none_c6b0c06407288ea3\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_c6de00a80706518d\wow64win.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_c6de00a80706518d\wow64cpu.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_c6de00a80706518d\wow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.23002_none_c6de00a80706518d\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_c63b1dfcedfa83b5\wow64win.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_c63b1dfcedfa83b5\wow64cpu.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_c63b1dfcedfa83b5\wow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18839_none_c63b1dfcedfa83b5\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_c5f93c44ee2c14dd\wow64win.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_c5f93c44ee2c14dd\wow64cpu.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_c5f93c44ee2c14dd\wow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.1.7601.18798_none_c5f93c44ee2c14dd\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.23040_none_15098efccc2e9285\winsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.23002_none_1536cf40cc0c556f\winsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.18839_none_1493ec95b3008797\winsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.18798_none_14520addb33218bf\winsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.23038_none_17914450ca50d561\win32k.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.18834_none_1703ce3bb1369cf9\win32k.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de82236c5fac8\UtcResources.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de82236c5fac8\diagtrack.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845bb1d97efda\UtcResources.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845bb1d97efda\diagtrack.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tracedatahelper_31bf3856ad364e35_6.1.7601.23040_none_5aedc8bd0207a49d\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tracedatahelper_31bf3856ad364e35_6.1.7601.18839_none_5a782655e8d999af\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\NBMapTIP.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\NBDoc.DLL:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\MSPVWCTL.DLL:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\Journal.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\JNTFiltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.23020_none_76522083d4615add\InkSeg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\NBMapTIP.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\NBDoc.DLL:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\MSPVWCTL.DLL:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\Journal.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\JNTFiltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-tabletpc-journal_31bf3856ad364e35_6.1.7601.18815_none_75d87cf4bb36ea93\InkSeg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.2.7601.22562_cs-cz_4882289bf91d98a4\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.2.7601.18361_cs-cz_47f789a0e000e25c\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.1.7601.22787_cs-cz_8042c0bd5a5df066\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_7.1.7601.18581_cs-cz_7fb320504145bb6b\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.22793_none_47e55ef51f593f71\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.22562_none_4804caa31f41d7f9\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.18585_none_476890c40631b93d\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.2.7601.18361_none_477a2ba8062521b1\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_7fc562c480822fbb\tsgqec.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_7fc562c480822fbb\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.22787_none_7fc562c480822fbb\aaclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_7f35c2576769fac0\tsgqec.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_7f35c2576769fac0\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_7.1.7601.18581_none_7f35c2576769fac0\aaclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_2931200b66d886cb\rtscom.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_2931200b66d886cb\journal.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_2931200b66d886cb\InkObj.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_2931200b66d886cb\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.23020_none_2931200b66d886cb\InkDiv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_28b77c7c4dae1681\rtscom.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_28b77c7c4dae1681\journal.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_28b77c7c4dae1681\InkObj.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_28b77c7c4dae1681\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.18815_none_28b77c7c4dae1681\InkDiv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.23020_none_ac38d243ae6df39e\jnwppr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.23020_none_ac38d243ae6df39e\jnwmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.23020_none_ac38d243ae6df39e\jnwdui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.23020_none_ac38d243ae6df39e\JNWDRV.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.18815_none_abbf2eb495438354\jnwppr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.18815_none_abbf2eb495438354\jnwmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.18815_none_abbf2eb495438354\jnwdui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..ournalnotewriterqfe_31bf3856ad364e35_6.1.7601.18815_none_abbf2eb495438354\JNWDRV.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_7.1.7601.22787_none_9db3a89cdbf1893c\mstsc.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_7.1.7601.18581_none_9d24082fc2d95441\mstsc.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.23020_none_a105879c7ccea224\PDIALOG.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.23020_none_a105879c7ccea224\jnwppr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.23020_none_a105879c7ccea224\jnwmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.23020_none_a105879c7ccea224\jnwdui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.23020_none_a105879c7ccea224\JNWDRV.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.18815_none_a08be40d63a431da\PDIALOG.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.18815_none_a08be40d63a431da\jnwppr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.18815_none_a08be40d63a431da\jnwmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.18815_none_a08be40d63a431da\jnwdui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..c-journalnotewriter_31bf3856ad364e35_6.1.7601.18815_none_a08be40d63a431da\JNWDRV.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..cesclient.resources_31bf3856ad364e35_7.1.7601.22787_cs-cz_811ec46341fdfb0f\mstsc.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..cesclient.resources_31bf3856ad364e35_7.1.7601.18581_cs-cz_808f23f628e5c614\mstsc.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..alservices-webproxy_31bf3856ad364e35_7.2.7601.22907_none_49d45651b1b3ecd8\TSWbPrxy.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-t..alservices-webproxy_31bf3856ad364e35_7.2.7601.18699_none_48eb670298dd80e7\TSWbPrxy.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23040_none_a56ac841e3185b03\srcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23040_none_a56ac841e3185b03\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23040_none_a56ac841e3185b03\rstrui.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23002_none_a5980885e2f61ded\srcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23002_none_a5980885e2f61ded\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.23002_none_a5980885e2f61ded\rstrui.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18839_none_a4f525dac9ea5015\srcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18839_none_a4f525dac9ea5015\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18839_none_a4f525dac9ea5015\rstrui.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18798_none_a4b34422ca1be13d\srcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18798_none_a4b34422ca1be13d\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.18798_none_a4b34422ca1be13d\rstrui.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23040_none_0ac5a057490afc94\smss.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23040_none_0ac5a057490afc94\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23002_none_0af2e09b48e8bf7e\smss.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.23002_none_0af2e09b48e8bf7e\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18839_none_0a4ffdf02fdcf1a6\smss.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18839_none_0a4ffdf02fdcf1a6\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18798_none_0a0e1c38300e82ce\smss.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18798_none_0a0e1c38300e82ce\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\xmllite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wrpint.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wmiutils.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wmicmiplugin.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wdscore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wcp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wbemprox.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wbemcore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\wbemcomn.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\SvcIni.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\smipi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\smiengine.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\repdrvfs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\poqexec.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\PkgMgr.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\OEMHelpIns.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\mspatcha.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\msdelta.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\mofinstall.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\mofd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\locdrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\helpcins.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\fastprox.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\esscli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\drvstore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\DrUpdate.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\dpx.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\CntrtextInstaller.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\cmiv2.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\cmitrust.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\cmiadapter.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\CbsMsg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\CbsCore.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\apss.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\apircl.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.18766_none_675144b3de10d6f7\apds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-sechost_31bf3856ad364e35_6.1.7601.23040_none_e64dd537fccf9399\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-sechost_31bf3856ad364e35_6.1.7601.18839_none_e5d832d0e3a188ab\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23045_none_80a644da8517b24e\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23040_none_80a14368851c339b\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.23002_none_80ce83ac84f9f685\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18843_none_801acf596bfbac94\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18839_none_802ba1016bee28ad\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-schannel_31bf3856ad364e35_6.1.7601.18798_none_7fe9bf496c1fb9d5\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23040_none_db3de52d92641ff2\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23017_none_db6556f792457d80\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.23002_none_db6b25719241e2dc\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18839_none_dac842c679361504\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18812_none_dad6e098792c2bc1\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7601.18798_none_da86610e7967a62c\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23040_none_4561d585e0a6ecd2\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23017_none_4589474fe0884a60\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.23002_none_458f15c9e084afbc\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18839_none_44ec331ec778e1e4\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18812_none_44fad0f0c76ef8a1\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-kerberos_31bf3856ad364e35_6.1.7601.18798_none_44aa5166c7aa730c\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23040_none_99584371ac8e70a3\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23017_none_997fb53bac6fce31\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.23002_none_998583b5ac6c338d\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18839_none_98e2a10a936065b5\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18812_none_98f13edc93567c72\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-digest_31bf3856ad364e35_6.1.7601.18798_none_98a0bf529391f6dd\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23040_none_224329c9d16961ab\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23040_none_224329c9d16961ab\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23017_none_226a9b93d14abf39\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23017_none_226a9b93d14abf39\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23002_none_22706a0dd1472495\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.23002_none_22706a0dd1472495\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18839_none_21cd8762b83b56bd\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18839_none_21cd8762b83b56bd\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18812_none_21dc2534b8316d7a\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18812_none_21dc2534b8316d7a\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18798_none_218ba5aab86ce7e5\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-credssp_31bf3856ad364e35_6.1.7601.18798_none_218ba5aab86ce7e5\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-scripting-vbscript_31bf3856ad364e35_11.2.9600.17801_none_2a8477774316bbc5\vbscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-scripting-jscript9_31bf3856ad364e35_11.2.9600.17801_none_265400d7d2e12f32\jscript9diag.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-scripting-jscript9_31bf3856ad364e35_11.2.9600.17801_none_265400d7d2e12f32\jscript9.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-scripting-jscript_31bf3856ad364e35_11.2.9600.17801_none_650a5cbf0c540f89\jscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7601.18829_none_2d7fe646e3ec3705\services.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-s..-jscript9.resources_31bf3856ad364e35_11.2.9600.17801_en-us_c3e5a1e38d4048f7\jscript9.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-s..-downlevel.binaries_31bf3856ad364e35_6.3.9600.17801_none_5fbe1728ff338aca\MsSpellCheckingFacility.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22947_none_7f90c927c288b059\rdpudd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22947_none_7f90c927c288b059\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22947_none_7f90c927c288b059\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22787_none_7f6585abc2a925cf\rdpudd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22787_none_7f6585abc2a925cf\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22787_none_7f6585abc2a925cf\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22678_none_7f7153fbc2a0260e\rdpudd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22678_none_7f7153fbc2a0260e\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.22678_none_7f7153fbc2a0260e\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18740_none_7f002870a9716207\rdpudd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18740_none_7f002870a9716207\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18740_none_7f002870a9716207\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18581_none_7ed5e53ea990f0d4\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18581_none_7ed5e53ea990f0d4\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18465_none_7eef8458a97d2127\RdpGroupPolicyExtension.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-r..s-regkeys-component_31bf3856ad364e35_7.1.7601.18465_none_7eef8458a97d2127\rdpcorets.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_bfae732b2eae7b32\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_bfae732b2eae7b32\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_bfae732b2eae7b32\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_bfae732b2eae7b32\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.23040_none_bfae732b2eae7b32\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_bf38d0c415807044\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_bf38d0c415807044\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_bf38d0c415807044\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_bf38d0c415807044\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-p..ncetoolscommandline_31bf3856ad364e35_6.1.7601.18839_none_bf38d0c415807044\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23040_none_cabb59fae3fc6f42\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.23002_none_cae89a3ee3da322c\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18839_none_ca45b793cace6454\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.18798_none_ca03d5dbcafff57c\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.23040_none_b761d69c2c0708f0\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.23002_none_b78f16e02be4cbda\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.18839_none_b6ec343512d8fe02\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ntdll_31bf3856ad364e35_6.1.7601.18798_none_b6aa527d130a8f2a\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23040_none_bc694dec21756b7d\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23017_none_bc90bfb62156c90b\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.23002_none_bc968e3021532e67\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18839_none_bbf3ab850847608f\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18812_none_bc024957083d774c\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.1.7601.18798_none_bbb1c9cd0878f1b7\ncrypt.dll:$CmdTcID

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#9 Příspěvek od Lefiks »

@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_25cd72a8a846d196\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_25cd72a8a846d196\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_25cd72a8a846d196\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23040_none_25cd72a8a846d196\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_25f4e472a8282f24\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_25f4e472a8282f24\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_25f4e472a8282f24\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23017_none_25f4e472a8282f24\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_25fab2eca8249480\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_25fab2eca8249480\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_25fab2eca8249480\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.23002_none_25fab2eca8249480\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_2557d0418f18c6a8\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_2557d0418f18c6a8\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_2557d0418f18c6a8\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18839_none_2557d0418f18c6a8\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_25666e138f0edd65\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_25666e138f0edd65\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_25666e138f0edd65\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18812_none_25666e138f0edd65\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_2515ee898f4a57d0\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_2515ee898f4a57d0\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_2515ee898f4a57d0\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7601.18798_none_2515ee898f4a57d0\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_753a50f1a2bb6749\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_753a50f1a2bb6749\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_753a50f1a2bb6749\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_753a50f1a2bb6749\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_7561c2bba29cc4d7\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_7561c2bba29cc4d7\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_7561c2bba29cc4d7\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_7561c2bba29cc4d7\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_75679135a2992a33\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_75679135a2992a33\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_75679135a2992a33\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_75679135a2992a33\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_74c4ae8a898d5c5b\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_74c4ae8a898d5c5b\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_74c4ae8a898d5c5b\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_74c4ae8a898d5c5b\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_74d34c5c89837318\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_74d34c5c89837318\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_74d34c5c89837318\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_74d34c5c89837318\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_7482ccd289beed83\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_7482ccd289beed83\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_7482ccd289beed83\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_7482ccd289beed83\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23040_none_04d5831c8ca49510\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23017_none_04fcf4e68c85f29e\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.23002_none_0502c3608c8257fa\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18839_none_045fe0b573768a22\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18812_none_046e7e87736ca0df\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\sspisrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\lsass.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\lsasrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\ksecpkg.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18798_none_041dfefd73a81b4a\ksecdd.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_a1dc814fdf7a57a3\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_a203f319df5bb531\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_a209c193df581a8d\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_a166dee8c64c4cb5\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.18812_cs-cz_a1757cbac6426372\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.18798_cs-cz_a124fd30c67ddddd\lsasrv.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.23040_none_858d70ade46d6d74\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.23002_none_85bab0f1e44b305e\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.18839_none_8517ce46cb3f6286\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernelbase_31bf3856ad364e35_6.1.7601.18798_none_84d5ec8ecb70f3ae\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.23040_none_f248dd9b8624e588\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.23002_none_f2761ddf8602a872\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18839_none_f1d33b346cf6da9a\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18798_none_f191597c6d286bc2\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-vgx_31bf3856ad364e35_11.2.9600.17801_none_cf618592fdeaaffe\VGX.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-timeline_is_31bf3856ad364e35_11.2.9600.17801_none_5c007931debcc4c7\Timeline_is.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-timeline_31bf3856ad364e35_11.2.9600.17801_none_2efa6d737f059b4c\Timeline.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-setup-support_31bf3856ad364e35_11.2.9600.17801_none_a7fb294c73a901ea\iesetup.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-setup-support_31bf3856ad364e35_11.2.9600.17801_none_a7fb294c73a901ea\iernonce.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-setup-support_31bf3856ad364e35_11.2.9600.17801_none_a7fb294c73a901ea\ie4uinit.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_11.2.9600.17801_none_29ce1e81a1b3e8bf\sqmapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_11.2.9600.17801_none_29ce1e81a1b3e8bf\iertutil.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ratings_31bf3856ad364e35_11.2.9600.17801_none_a9bcb27c71eaf343\msrating.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-networkinspection_31bf3856ad364e35_11.2.9600.17801_none_5726fe9169305a29\networkinspection.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-mshtmldac_31bf3856ad364e35_11.2.9600.17801_none_ba6816c40c4d84e4\MshtmlDac.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-memoryanalyzer_31bf3856ad364e35_11.2.9600.17801_none_a5218c4a08c12f8a\MemoryAnalyzer.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-jsprofilerui_31bf3856ad364e35_11.2.9600.17801_none_d5296dcfe362b009\jsprofilerui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17801_none_118c74312f2e3945\ieUnatt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ieinstal_31bf3856ad364e35_11.2.9600.17801_none_cac64d46a6d215fd\ieinstal.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ieshims_31bf3856ad364e35_11.2.9600.17801_none_29b7a41daf68bb4f\IEShims.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ieproxy_31bf3856ad364e35_11.2.9600.17801_none_725958875fc054e1\ieproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ielowutil_31bf3856ad364e35_11.2.9600.17801_none_e8a0804e866a72a7\ielowutil.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ieetwcollector_31bf3856ad364e35_11.2.9600.17801_none_a5410b0017f68054\ieetwproxystub.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ieetwcollector_31bf3856ad364e35_11.2.9600.17801_none_a5410b0017f68054\ieetwcollectorres.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-ieetwcollector_31bf3856ad364e35_11.2.9600.17801_none_a5410b0017f68054\ieetwcollector.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrenderingmedia_31bf3856ad364e35_11.2.9600.17801_none_a0ab1f4e6e7bbee4\mshtmlmedia.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17801_none_f56d86c437593398\mshtml.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlediting_31bf3856ad364e35_11.2.9600.17801_none_2a535d8f58947d70\mshtmled.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ieframe_31bf3856ad364e35_11.2.9600.17801_none_46cce0c7c34ec1c5\ieui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ieframe_31bf3856ad364e35_11.2.9600.17801_none_46cce0c7c34ec1c5\ieframe.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ieframe.resources_31bf3856ad364e35_11.2.9600.17801_en-us_71f0bc58e2de0f64\ieui.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ieframe.resources_31bf3856ad364e35_11.2.9600.17801_en-us_71f0bc58e2de0f64\ieframe.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_11.2.9600.17801_none_4210fe744fa61d1a\msfeeds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12tools_31bf3856ad364e35_11.2.9600.17801_none_6b6ab2f0a650afb1\F12Tools.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12tools.resources_31bf3856ad364e35_11.2.9600.17801_en-us_8cd35a53ca20d198\F12Tools.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12resources_31bf3856ad364e35_11.2.9600.17801_none_6495e0412266ca2d\F12Resources.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12diagnosticstap_31bf3856ad364e35_11.2.9600.17801_none_9453e0ca8c93fff7\DiagnosticsTap.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12_31bf3856ad364e35_11.2.9600.17801_none_cfdeaf66fd92968e\F12.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-f12.resources_31bf3856ad364e35_11.2.9600.17801_en-us_526d8a5f6ebe76c1\F12.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_11.2.9600.17801_none_79f0c33796d3cae3\dxtrans.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_11.2.9600.17801_none_79f0c33796d3cae3\dxtmsft.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-diagnosticshubis_31bf3856ad364e35_11.2.9600.17801_none_f2198467d673c88c\DiagnosticsHub_is.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-devtools_31bf3856ad364e35_11.2.9600.17801_none_1dcf80f8550616a3\iedvtool.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-datawarehouse_31bf3856ad364e35_11.2.9600.17801_none_28d8ab10159b3c7c\DiagnosticsHub.DataWarehouse.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_11.2.9600.17801_none_ddbc8a7f80ee44b5\ieapfltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_11.2.9600.17801_none_567ae0a16caceb29\iedkcs32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..trolpanel.resources_31bf3856ad364e35_11.2.9600.17801_en-us_04b5197ffd5bdb8a\inetcpl.cpl.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17801_none_e41367a5b702ca62\wininet.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17801_none_e41367a5b702ca62\jsproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..rityzones.resources_31bf3856ad364e35_11.2.9600.17801_en-us_50ad25c7f6a920c6\urlmon.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..riptedsandboxplugin_31bf3856ad364e35_11.2.9600.17801_none_3e0651d1808d3ef3\DiagnosticsHub.ScriptedSandboxPlugin.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..riptcollectionagent_31bf3856ad364e35_11.2.9600.17801_none_97f1bc35adfa239d\JavaScriptCollectionAgent.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..resources.resources_31bf3856ad364e35_11.2.9600.17801_en-us_1d97a48d2cc89eee\F12Resources.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..rendering.resources_31bf3856ad364e35_11.2.9600.17801_en-us_ef12dfaf189cde71\mshtml.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..osticstap.resources_31bf3856ad364e35_11.2.9600.17801_en-us_6d24ae7ffa01e4de\DiagnosticsTap.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_11.2.9600.17801_none_71641a38670848f3\inetcpl.cpl:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17801_none_7ae0d081c2f58050\iexplore.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_11.2.9600.17801_none_970d8c03ebf9a3cf\urlmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_7.1.7601.23038_none_54b85527cbffe98c\FntCache.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_7.1.7601.18834_none_542adf12b2e5b124\FntCache.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_6.1.7601.23038_none_6347d8e2411940bd\FntCache.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite-fontcache_31bf3856ad364e35_6.1.7601.18834_none_62ba62cd27ff0855\FntCache.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite_31bf3856ad364e35_7.1.7601.23038_none_22abb5fdba1fc424\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite_31bf3856ad364e35_7.1.7601.18834_none_221e3fe8a1058bbc\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite_31bf3856ad364e35_6.1.7601.23038_none_313b39b82f391b55\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-directwrite_31bf3856ad364e35_6.1.7601.18834_none_30adc3a3161ee2ed\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.23040_none_28122f5fd536fea3\csrsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.23002_none_283f6fa3d514c18d\csrsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.18839_none_279c8cf8bc08f3b5\csrsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.18798_none_275aab40bc3a84dd\csrsrv.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-consolehost_31bf3856ad364e35_6.1.7601.23040_none_d2e6bfab31f3228d\conhost.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-consolehost_31bf3856ad364e35_6.1.7601.23002_none_d313ffef31d0e577\conhost.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-consolehost_31bf3856ad364e35_6.1.7601.18839_none_d2711d4418c5179f\conhost.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-consolehost_31bf3856ad364e35_6.1.7601.18798_none_d22f3b8c18f6a8c7\conhost.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-cmitrustinfoinstallers_1122334455667788_6.1.7601.22972_none_f071a959e6f72266\cmitrust.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-cmitrustinfoinstallers_1122334455667788_6.1.7601.18766_none_eff6dbbccdcdcee0\cmitrust.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23040_none_3608add66c80e500\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23017_none_36301fa06c62428e\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.23002_none_3635ee1a6c5ea7ea\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.1.7601.18833_none_358d09b353584208\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_7ff403e8e8b3b9af\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23017_cs-cz_801b75b2e895173d\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_8021442ce8917c99\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..ityclient.resources_31bf3856ad364e35_6.1.7601.18833_cs-cz_7f785fc5cf8b16b7\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..integrity.resources_31bf3856ad364e35_6.1.7601.23040_en-us_57bf78fb7d33e387\ci.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-c..integrity.resources_31bf3856ad364e35_6.1.7601.23002_en-us_57ecb93f7d11a671\ci.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_b9b1b28c9c803d22\winresume.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_b9b1b28c9c803d22\winresume.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_b9b1b28c9c803d22\winload.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_b9b1b28c9c803d22\winload.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23002_none_b9def2d09c5e000c\winresume.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23002_none_b9def2d09c5e000c\winresume.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23002_none_b9def2d09c5e000c\winload.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23002_none_b9def2d09c5e000c\winload.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_37b1a5b279084ad2\winresume.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_37b1a5b279084ad2\winresume.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_37b1a5b279084ad2\winload.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_37b1a5b279084ad2\winload.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_37dee5f678e60dbc\winresume.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_37dee5f678e60dbc\winresume.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_37dee5f678e60dbc\winload.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..t-windows.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_37dee5f678e60dbc\winload.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_91cd67042ce2d6ef\winresume.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_91cd67042ce2d6ef\winresume.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_91cd67042ce2d6ef\winload.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_91cd67042ce2d6ef\winload.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_91faa7482cc099d9\winresume.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_91faa7482cc099d9\winresume.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_91faa7482cc099d9\winload.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23002_cs-cz_91faa7482cc099d9\winload.efi.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23040_none_c7c38f84bca3faf3\winresume.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23040_none_c7c38f84bca3faf3\winresume.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23040_none_c7c38f84bca3faf3\winload.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23040_none_c7c38f84bca3faf3\winload.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23040_none_c7c38f84bca3faf3\setbcdlocale.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23002_none_c7f0cfc8bc81bddd\winresume.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23002_none_c7f0cfc8bc81bddd\winresume.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23002_none_c7f0cfc8bc81bddd\winload.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23002_none_c7f0cfc8bc81bddd\winload.efi:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.23002_none_c7f0cfc8bc81bddd\setbcdlocale.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_b5d708a5e200a8e0\appidsvc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_b5d708a5e200a8e0\appidpolicyconverter.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_b5d708a5e200a8e0\appidcertstorecheck.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_b5d708a5e200a8e0\appidapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23040_none_b5d708a5e200a8e0\appid.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_b60448e9e1de6bca\appidsvc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_b60448e9e1de6bca\appidpolicyconverter.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_b60448e9e1de6bca\appidcertstorecheck.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_b60448e9e1de6bca\appidapi.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23002_none_b60448e9e1de6bca\appid.sys:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-advapi32_31bf3856ad364e35_6.1.7601.23040_none_41d34a04b65b158a\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-advapi32_31bf3856ad364e35_6.1.7601.18839_none_415da79d9d2d0a9c\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.1.7601.23040_cs-cz_33be2531f9b3f013\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.1.7601.18839_cs-cz_334882cae085e525\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.1.7601.22981_none_6a8619da22426a85\acspecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c4_31bf3856ad364e35_6.1.7601.18777_none_6a0d4cd1091749ad\acspecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.1.7601.22981_none_6a8519902243512e\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.1.7601.18777_none_6a0c4c8709183056\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3371e4907cb28976\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3371e4907cb28976\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3371e4907cb28976\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.22981_none_3371e4907cb28976\aelupsvc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_32f917876387689e\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_32f917876387689e\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_32f917876387689e\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.18777_none_32f917876387689e\aelupsvc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23038_none_145856c48b93351a\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18834_none_2b26557a71eb7442\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.7601.23038_none_2506e7dff28d5b73\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.7601.18834_none_3bd4e695d8e59a9b\GdiPlus.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.23011_none_e36c02c33101d537\comctl32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18807_none_fa381d5f175bfb52\comctl32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\Temp\InstHelper.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\Temp\avast_ash\Mozilla Firefox\updater.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\Temp\avast_ash\Mozilla Firefox\update.xml:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\Temp\0EA003A0-E0B5-427C-BF36-73C7BC887743\DismHost.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\wininet.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\vbscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\urlmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\tspkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\poqexec.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\msrating.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mshtmlmedia.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mshtmled.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\MshtmlDac.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mshtml.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\msfeeds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_169_Plugin.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\jsproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\jscript9diag.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\jscript9.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\jscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\JavaScriptCollectionAgent.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\inetcpl.cpl:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieUnatt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\iesetup.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\iertutil.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\iernonce.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieframe.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieetwproxystub.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\iedkcs32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieapfltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\FlashPlayerApp.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\urlmon.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\mshtml.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\jscript9.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\ieui.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\en-US\ieframe.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\dxtrans.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\dxtmsft.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWOW64\cs-CZ\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\wpdshext.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\wow32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\wininet.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\wdigest.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\vbscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\user.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\urlmon.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\typeperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\TSpkg.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\tracerpt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\tdh.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\sspicli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\srclient.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\schannel.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\shimeng.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\setup16.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\sechost.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\secur32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\sdbinst.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\relog.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\poqexec.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ntvdm64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ntoskrnl.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ntkrnlpa.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ntdll.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ncrypt.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\msv1_0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\mstscax.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\msrating.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\msobjs.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\mshtmlmedia.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\mshtmled.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\MshtmlDac.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\mshtml.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\msfeeds.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\msaudite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_169_Plugin.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\logman.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\KernelBase.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\kernel32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\kerberos.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\jsproxy.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\jscript9diag.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\jscript9.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\jscript.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\JavaScriptCollectionAgent.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\instnm.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\InkEd.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\inetcpl.cpl:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ieUnatt.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ieui.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\iesetup.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\iertutil.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\iernonce.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ieframe.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ieetwproxystub.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\iedkcs32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\ieapfltr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\FlashPlayerApp.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\urlmon.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\mshtml.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\jscript9.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\inetcpl.cpl.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\ieui.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\en-US\ieframe.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\dxtrans.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\dxtmsft.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\DWrite.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\DriverStore\FileRepository\wpdmtp.inf_amd64_neutral_9bb06c3cf57e5001\WpdMtpDr.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\diskperf.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\mstscax.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\msobjs.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\msaudite.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\certcli.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\auditpol.exe.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\advapi32.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\cs-CZ\adtschema.dll.mui:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\credssp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\certcli.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\auditpol.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\apphelp.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\apisetschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\advapi32.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\adtschema.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\avastSS.scr:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\AppPatch64\acspecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\AppPatch64\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\acwow64.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\AcSpecfc.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\AcRes.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Windows\AppPatch\AcGenral.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Users\Petr\Desktop\raidcall_v7.3.6.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Users\Petr\Desktop\OTL.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Users\Petr\Desktop\eset_nod32_antivirus_live_installer_.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Users\Petr\Desktop\avast_free_antivirus_setup_online.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> C:\Program Files\AVAST Software\Avast\AvastUI.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_0d1e4cccf34bdee0\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_0d4b8d10f329a1ca\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_0ca8aa65da1dd3f2\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_0c66c8adda4f651a\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23040_none_693ce850aba95016\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23002_none_696a2894ab871300\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18839_none_68c745e9927b4528\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18798_none_6885643192acd650\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJR5FYJZ\loader[1].js:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVPNGRMQ\loader.min[1].js:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LV22DN8M\preloaderMusic[1].js:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja\2.2.0.18_0\js\scriptLoader.js:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Users\Petr\AppData\Local\Comodo\Chromodo\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja\2.2.0.18_0\js\configLoader.js:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Program Files\AVAST Software\Avast\ng\aswSfLoader.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Program Files\AVAST Software\Avast\aswWrcIELoader64.exe:$CmdTcID
@Alternate Data Stream - 64 bytes -> \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe:$CmdTcID
@Alternate Data Stream - 40 bytes -> C:\ProgramData\MTA San Andreas All:NT
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\raidcall_v7.3.6.exe:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\OTL.exe:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\Manian - Welcome to the Club(Official Video).mp3:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\eset_nod32_antivirus_live_installer_.exe:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\Different Heaven & EH!DE - My Heart.mp3:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Petr\Desktop\avast_free_antivirus_setup_online.exe:$CmdZnID
@Alternate Data Stream - 21 bytes -> \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\wws_crashreport_uploader.exe:crc
@Alternate Data Stream - 21 bytes -> \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\LaunchPad.libs\wws_crashreport_uploader.exe:crc
@Alternate Data Stream - 21 bytes -> \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\APEX_Loader_x86.dll:crc
@Alternate Data Stream - 21 bytes -> \Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\APEX_Loader_x64.dll:crc
@Alternate Data Stream - 160 bytes -> C:\ProgramData\MTA San Andreas All:NT2

< End of report >

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#10 Příspěvek od Lefiks »

OTL Extras logfile created on: 17.5.2015 12:47:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Petr\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17801)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

7,96 Gb Total Physical Memory | 4,97 Gb Available Physical Memory | 62,45% Memory free
15,92 Gb Paging File | 12,31 Gb Available in Paging File | 77,31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 732,42 Gb Total Space | 58,19 Gb Free Space | 7,94% Space Free | Partition Type: NTFS
Drive D: | 1130,50 Gb Total Space | 1116,09 Gb Free Space | 98,73% Space Free | Partition Type: NTFS

Computer Name: PETR-PC | User Name: Petr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2840795496-512860511-4266877744-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{99ABB425-DF5D-4B87-A897-296241CEEFA5}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{047E66E4-6B51-41E7-AFAB-631C8604F827}" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"{4A7A71CE-816F-47EB-B030-DDCC8C6A2CAC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{4D2C93D3-6441-4D8D-BDFF-4AA8FFF85C28}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragons&titans\dnt.exe |
"{5BF0F859-8136-4788-8D10-2B761978644B}" = protocol=6 | dir=in | app=c:\users\petr\appdata\local\hola\firefox\app\hola_plugin.exe |
"{5EF9FFFF-CEAD-4924-BE3A-96782BBD9041}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\toribash\toribash.exe |
"{77F16814-ECD3-4EA8-8ABA-C14B1E90BB9C}" = protocol=17 | dir=in | app=c:\users\petr\appdata\roaming\utorrent\utorrent.exe |
"{8E10BE67-8960-4B4B-8A21-B26C37915446}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\toribash\toribash.exe |
"{922D9584-76FA-44F8-939B-A31C37E9141F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tera\tera-launcher.exe |
"{AEDECC09-CEB1-4355-88A4-5650FB88BE01}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AF153FA8-516E-45D2-A2BF-E0674617E5D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragons&titans\dnt.exe |
"{B274C106-8F1A-47B1-B857-66184EACEE1C}" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"{C1D354E2-A265-4AD7-9753-667E01287600}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C73C1F7E-B839-4635-9B86-B7767A0260A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\robocraft\robocraft.exe |
"{C76546CA-5424-4B1F-BD78-692985992C2E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\robocraft\robocraft.exe |
"{CC028D72-ECA9-4BCB-888C-9D0FF7A4BE4D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E55702DE-D690-4EB4-8225-944DF3C0C727}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tera\tera-launcher.exe |
"{E5E2D141-4986-484B-9844-921B5038188E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{F31818B3-22FC-45C1-AFD3-626926BCF018}" = protocol=6 | dir=in | app=c:\users\petr\appdata\roaming\utorrent\utorrent.exe |
"{FC956791-18E3-4721-BAC7-C0E45B84FB7A}" = protocol=17 | dir=in | app=c:\users\petr\appdata\local\hola\firefox\app\hola_plugin.exe |
"TCP Query User{057F9864-816D-4281-B770-B79B4B87AF82}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{3A2EE778-F687-4759-8AC8-B70C9D515DCC}C:\users\petr\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\petr\appdata\local\akamai\netsession_win.exe |
"TCP Query User{744A11E3-D747-409B-B710-551F01A31CB2}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"UDP Query User{93E46590-7C8D-4229-A391-0AAD794F5516}C:\users\petr\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\petr\appdata\local\akamai\netsession_win.exe |
"UDP Query User{AC52E066-10FE-4481-AB66-D29893ECB072}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"UDP Query User{C77A4909-365D-4928-BD98-E5DB9C0144F7}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{14297226-E0A0-3781-8911-E9D529552663}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}" = AMD Steady Video Plug-In
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5941D535-34BF-BB6E-E52B-F464E4E955FF}" = AMD Media Foundation Decoders
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64353004-AB3A-434D-8B97-85FFC6AE841A}" = GeekBuddy
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{73830292-868E-4C82-9AF5-CCFE2047B6A3}" = COMODO Firewall
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C3E2581-B212-D5C6-35A1-DD5A9C3DA29B}" = AMD Accelerated Video Transcoding
"{90140000-0015-0405-1000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-1000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-1000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-1000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-1000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0405-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Czech) 2010
"{90140000-0044-0405-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AF88A32E-BC54-2AA3-2FC8-D63D86DF4A7A}" = AMD Catalyst Install Manager
"{CF2A565B-1504-BD48-51B5-1D88C621D8C6}" = ccc-utility64
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{D6885DDE-4632-4640-A3BB-13C9F02CE81C}" = ESET NOD32 Antivirus
"{E6277150-51D1-1D9F-1B9F-2D28985BE167}" = AMD Fuel
"{E74DBCA2-F0BC-929D-0504-87E97079EB4A}" = AMD Drag and Drop Transcoding
"CCleaner" = CCleaner
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Totalcmd64" = Total Commander 64-bit (Remove or Repair)
"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10
"WinRAR archiver" = WinRAR 5.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01BD4FC9-2F86-4706-A62E-774BB7E9D308}" = AVG PC TuneUp 2014
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08A25478-C5DD-4EA7-B168-3D687CA987FF}" = The Sims™ 3 Изысканная спальня Каталог
"{117B6BF6-82C3-420C-B284-9247C8568E53}" = The Sims™ 3 Отдых на природе Каталог
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6
"{17630FD1-B14A-4CA5-A627-B6B5F7DD41CF}" = 3TB+Unlock B12.1102.1
"{183F67DB-676D-9629-BB8D-5D91CFC5880C}" = CCC Help Chinese Traditional
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A21C23B-1049-036F-538C-40827D35D35B}" = CCC Help Czech
"{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}" = The Sims™ 3 Diesel Каталог
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}" = PDF Settings CC
"{1FD9F07F-7BBF-4C91-B3F0-A23714A3A913}_is1" = RaceRoom Racing Experience Launcher
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{21EF236B-A428-0641-0A9A-6A9A74BA1996}" = CCC Help Finnish
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 7.4
"{26A24AE4-039D-4CA4-87B4-2F83218040F0}" = Java 8 Update 40
"{28D1723C-31C4-4A83-9799-DFFB3739026D}" = Warface Launcher (Beta)
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}" = Adobe Photoshop CC
"{2E7170BC-A6CB-3C69-A940-A07834EAE1E8}" = CCC Help Italian
"{317243C1-6580-4F43-AED7-37D4438C3DD5}" = Adobe After Effects CC
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3450767E-DD72-E31C-CCA5-8F45FF5FCE08}" = AMD VISION Engine Control Center
"{3A027737-A119-FABD-4C43-8385D57FC450}" = Catalyst Control Center Localization All
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3BBFD444-5FAB-49F6-98B1-A1954E831399}" = The Sims™ 3 Шоу-бизнес
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}" = Smite
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7
"{3D9C083F-F0B4-4C43-8C4A-9D5711A64B9C}" = 4S4Vendeta
"{3DE92282-CB49-434F-81BF-94E5B380E889}" = The Sims™ 3 Времена года
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B12.1025.1
"{45017FF9-8ABB-DFDE-6BFD-43C8D89277F4}" = CCC Help Norwegian
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 В сумерках
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B13.0125.1
"{45BB2BC0-6CD3-457D-A70B-B1E4AF929189}_is1" = S.T.A.L.K.E.R. - Call of Pripyat verze 1.602
"{45E7C481-3EF4-4FCB-AF0B-19F70D618F0C}" = Worms 4 Mayhem
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{494642A2-96C3-FBF9-A43D-41D78A82AE15}" = CCC Help Hungarian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FD6306A-E967-F286-DBA1-2A3C26833A2C}" = CCC Help French
"{505FF1AC-E7F5-4462-BBA7-08900E7E9EEF}" = Adobe Premiere Pro CC
"{52C32940-C538-40CF-8DE9-B91090F49938}" = Infovox Desktop 2.2
"{534A7A1A-7102-4AF6-23EA-7CD279C7B625}_is1" = Adobe Update Management Tool
"{59E04C6D-9EE0-4F70-9358-62108888C719}" = 2010 DR PEPPER EA GAMES EVERY BOTTLE/CUP WINS PROMOTION
"{5BA86B8D-D29E-071C-5D7B-E579A54698AD}" = CCC Help Spanish
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63CEA2E4-4FE7-4F2C-B388-C1313D24157C}" = SPORE™ Galaktická dobrodružství
"{6B84E528-9705-4D36-9C97-97B8E23DAB75}" = League of Legends
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{6E6F22D7-8AD6-4A87-9A47-733E6E996F50}" = Dead Space
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 Современная роскошь Каталог
"{71A79918-3497-16D0-3497-E3356F5EE5FB}" = CCC Help Chinese Standard
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{76D0F60C-D265-CFA4-2E06-41E434F9EB41}" = CCC Help Thai
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78FD6E08-6996-7EBF-E3F8-905836E7C220}" = CCC Help Dutch
"{79A3E8B6-37C0-5F75-7E7D-F4D6FB512329}" = CCC Help Japanese
"{7A8B5F7D-6736-4DC4-A7A5-223BE131EB34}" = AVG PC TuneUp 2014 (cs-CZ)
"{7B11296A-F894-449C-8DF6-6AAAA7D4D118}" = The Sims™ 3 Городская жизнь Каталог
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX
"{80EE9168-BB59-4F87-BF1A-57C137EAF714}" = LogMeIn Hamachi
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8B526040-C3BE-5E3F-E6C1-C01BD32BA2C6}" = CCC Help Greek
"{9068D15E-25B4-EC21-9BC4-8DBD52722F8E}" = CCC Help Russian
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Карьера
"{962E05CF-3394-496D-0091-850CF1762F6B}" = The Battle for Middle-earth (tm)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AC111C4-AC8B-4CB1-A8DE-FDA68200685C}_is1" = Sun Age
"{9B2506E3-9A3F-45B5-96BF-509CAD584650}" = The Sims™ 3 Katy Perry Сладкие радости
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA46B5F5-6E96-A623-5AB4-93BE56BEBB28}" = CCC Help Danish
"{AC4BBB17-A837-3B36-83D8-7DFC90505F95}" = CCC Help Portuguese
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}" = The Sims™ 3 Сверхъестественное
"{B3CDED64-7DC2-429D-A325-BBC3CF793AA6}" = Gaming Keyboard Driver
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 Мир приключений
"{BC8CEB2B-647B-BBF1-3923-6250AFA64081}" = CCC Help Polish
"{BD8B4CA0-CBB8-42BA-A530-149059738C4A}_is1" = Freedom Force vs the 3rd Reich
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Balíček strašidelných a roztomilých doplňků
"{C12631C6-804D-4B32-B0DD-8A496462F106}" = The Sims™ 3 Питомцы
"{C3592426-531E-4110-911D-BFECE2CE284B}" = puush
"{C3E176C6-FF76-4734-929D-8E5FB9CC2E05}_is1" = STALKER - Shadow of Chernobyl verze 1.0006
"{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}" = Nokia Connectivity Cable Driver
"{C6B0FBD0-067F-5ED3-B4C1-BC61284A1079}" = Catalyst Control Center InstallProxy
"{C75FAD21-EC08-42F3-92D6-C9C0AB355345}" = AutoGreen B12.1220.1
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{CED8E25B-122A-4E80-B612-7F99B93284B3}" = Arc
"{D73E5C3C-6975-6957-3799-AB306D8189B0}" = CCC Help Korean
"{DB21639E-FE55-432C-BCA2-0C5249E3F79E}" = The Sims™ 3 Райские острова
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E05B61A8-A743-57ED-C0BA-6332CC6452FF}" = CCC Help German
"{E1868CAE-E3B9-4099-8C18-AA8944D336FD}" = The Sims™ 3 Стильные 70-е, 80-е, 90-е Каталог
"{E22F5B3F-6D82-7354-F199-0EFFDCC4DD33}" = CCC Help Swedish
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5EB7710-29E1-47E3-9636-0E8CA5B0D3CA}_is1" = Warcraft III verze 1.22
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = The Sims™ 3 Все возрасты
"{EAA01BA0-6991-4296-A404-4FFF2DAC2225}" = ParaWorld
"{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}" = The Sims™ 3 Скоростной режим Каталог
"{F0319215-C109-C2C9-ECBC-3F08C50E59B3}" = CCC Help Turkish
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}" = The Sims™ 3 Студенческая жизнь
"{F8A47958-47CC-4B57-AE7D-7DDC0A86BEF5}" = XSplit Broadcaster
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}" = Wing Commander III
"{FBE18FE1-05A4-C5AD-571A-74BC335FDDC6}" = CCC Help English
"{FE2D627E-D7E0-46EA-93A6-8583420285FA}" = Aeria Ignite
"«The Sims 3 Deluxe Edition»_is1" = «The Sims 3 Deluxe Edition» (build 9.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 17 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 17 NPAPI
"Aeria Ignite" = Aeria Ignite
"Aeria Ignite 1.13.3296" = Aeria Ignite
"AirRivals_is1" = AirRivals
"Audacity_is1" = Audacity 2.0.5
"Avast" = Avast Free Antivirus
"Battle.net" = Battle.net
"Battlelog Web Plugins" = Battlelog Web Plugins
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Dračí oko" = Dračí oko
"Fraps" = Fraps (remove only)
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"Heroes of the Storm" = Heroes of the Storm
"Cheat Engine 6.4_is1" = Cheat Engine 6.4
"Chromodo" = Chromodo
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platforma Ovladače zařízení
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B13.0125.1
"InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}" = AutoGreen B12.1220.1
"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"League of Legends 3.0.1" = League of Legends
"LogMeIn Hamachi" = LogMeIn Hamachi
"Minecraft1.7.2" = Minecraft1.7.2
"Mount&Blade With Fire and Sword" = Mount&Blade With Fire and Sword
"Mozilla Firefox 29.0.1 (x86 cs)" = Mozilla Firefox 29.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"RaidCall" = RaidCall
"RPGVXAce_RTP_is1" = RPG MAKER VX Ace RTP
"Saints Row The Third_is1" = Saints Row The Third
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 208090" = Loadout
"Steam App 222900" = Dead Island: Epidemic
"Steam App 223530" = Left 4 Dead 2 Beta
"Steam App 234710" = Poker Night 2
"Steam App 242720" = GunZ 2: The Second Duel
"Steam App 248570" = Toribash
"Steam App 263500" = Dragons and Titans
"Steam App 301520" = Robocraft
"Steam App 304930" = Unturned
"Steam App 323370" = TERA
"Steam App 33910" = Arma 2
"Steam App 4000" = Garry's Mod
"Steam App 440" = Team Fortress 2
"Steam App 550" = Left 4 Dead 2
"Steam App 563" = Left 4 Dead 2 Authoring Tools
"Steam App 570" = Dota 2
"Steam App 70000" = Dino D-Day
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 730" = Counter-Strike: Global Offensive
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TeamViewer 9" = TeamViewer 9
"TextAloud3_is1" = TextAloud 3.0
"The Forest_is1" = The Forest version 0.05
"Tunngle_is1" = Tunngle
"VLC media player" = VLC media player
"Wolfteam" = Wolfteam
"WolfTeam International_is1" = WolfTeam International
"World of Warcraft" = World of Warcraft

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2840795496-512860511-4266877744-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes (Petr)
"Akamai" = Akamai NetSession Interface
"d8f4b4d52e33052f" = Skype Voice Changer
"Dropbox" = Dropbox
"MK LOL" = MK LOL
"MKLOL" = MKLOL
"SeznamInstall" = Seznam Software
"SOE-PlanetSide 2" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 19.10.2014 3:35:35 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5b8 Čas spuštění chybující aplikace: 0x01cfea9b10956e0a Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 82c86a3d-5762-11e4-891c-94de8075019c

Error - 19.10.2014 6:45:00 | Computer Name = Petr-PC | Source = Application Hang | ID = 1002
Description = Program TheForest.exe verze 4.5.1.22013 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
d10 Čas spuštění: 01cfeb898c6ac0b6 Čas ukončení: 46 Cesta k aplikaci: C:\Program Files
(x86)\GMT-MAX.ORG\The Forest\TheForest.exe ID hlášení:

Error - 19.10.2014 16:32:45 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x580 Čas spuštění chybující aplikace: 0x01cfeb88ec1a9dc7 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 14badf45-57cf-11e4-82f3-94de8075019c

Error - 20.10.2014 16:59:52 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5b0 Čas spuštění chybující aplikace: 0x01cfec61a2beb8b6 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 08cb7f99-589c-11e4-88d5-94de8075019c

Error - 21.10.2014 15:28:21 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5b0 Čas spuštění chybující aplikace: 0x01cfed4a5dcc06b7 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 6ab19027-5958-11e4-b35b-94de8075019c

Error - 22.10.2014 4:12:23 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5ac Čas spuštění chybující aplikace: 0x01cfedc5d3003764 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 26871978-59c3-11e4-be52-94de8075019c

Error - 22.10.2014 10:37:13 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x578 Čas spuštění chybující aplikace: 0x01cfee03c37eca0f Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: e912204a-59f8-11e4-8aca-94de8075019c

Error - 22.10.2014 15:32:16 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5b4 Čas spuštění chybující aplikace: 0x01cfee114dd71119 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 20f30c46-5a22-11e4-9d10-94de8075019c

Error - 22.10.2014 16:23:17 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5ac Čas spuštění chybující aplikace: 0x01cfee320c0189f5 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: 4162d71c-5a29-11e4-ad33-94de8075019c

Error - 23.10.2014 10:35:33 | Computer Name = Petr-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Fuel.Service.exe, verze: 1.0.0.0, časové
razítko: 0x501fefb5 Název chybujícího modulu: Device.dll, verze: 4.1.0.0, časové
razítko: 0x4f55e10b Kód výjimky: 0xc0000005 Posun chyby: 0x00000000000033c1 ID chybujícího
procesu: 0x5bc Čas spuštění chybující aplikace: 0x01cfee899f0bf285 Cesta k chybující
aplikaci: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe Cesta
k chybujícímu modulu: C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll ID
zprávy: d7e26a0f-5ac1-11e4-983c-94de8075019c

[ System Events ]
Error - 17.5.2015 5:36:46 | Computer Name = Petr-PC | Source = Application Popup | ID = 875
Description = Načtení ovladače atksgt.sys je blokováno.

Error - 17.5.2015 5:36:46 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7000
Description = Služba atksgt neuspěla při spuštění v důsledku následující chyby:
%%1275

Error - 17.5.2015 5:38:11 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7009
Description = Při čekání na připojení služby LogMeIn Hamachi Tunneling Engine bylo
dosaženo časového limitu (30000 ms).

Error - 17.5.2015 5:38:11 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7000
Description = Služba LogMeIn Hamachi Tunneling Engine neuspěla při spuštění v důsledku
následující chyby: %%1053

Error - 17.5.2015 5:38:17 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: prodrv06 prohlp02 prosync1 sfhlp01

Error - 17.5.2015 5:38:22 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7034
Description = Služba Skype Click to Call PNR Service byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 17.5.2015 5:38:24 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7034
Description = Služba Skype Click to Call Updater byla neočekávaně ukončena. Tento
stav nastal již 1krát.

Error - 17.5.2015 5:40:32 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7031
Description = Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena.
Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund:
Restartovat službu.

Error - 17.5.2015 5:41:02 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7032
Description = Správce služeb se pokusil o opravnou akci (Restartovat službu) po
nečekaném ukončení služby Služba Windows Media Player Network Sharing, ale tato
akce selhala kvůli následující chybě: %%1056

Error - 17.5.2015 5:42:22 | Computer Name = Petr-PC | Source = Service Control Manager | ID = 7031
Description = Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena.
Stalo se to 2 krát. Následující opravná akce bude spuštěna za 30000 milisekund:
Restartovat službu.


< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka

#11 Příspěvek od Márty84 »

Ten system asi moc legalni nebude, ze? :(
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lefiks
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 17 kvě 2015 10:50

Re: Preventivka

#12 Příspěvek od Lefiks »

Jestli je legální nevím ale jak jsem to koupil tak to mám a se systémem jsem nic nedělal :(

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka

#13 Příspěvek od Márty84 »

K aktivaci byl pouzity nelegalni aktivator. A cpat ho do legalniho systemu asi nikdo nebude :boxed:


A bohuzel pravidla fora hovori jasne http://forum.viry.cz/viewtopic.php?f=12&t=115512
Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.
:42:



21.6. :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno