Část 1
OTL logfile created on: 20.3.2016 20:44:19 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\iDragon\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17126)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,25 Gb Total Physical Memory | 0,88 Gb Available Physical Memory | 26,96% Memory free
6,50 Gb Paging File | 3,31 Gb Available in Paging File | 50,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218,87 Gb Total Space | 72,28 Gb Free Space | 33,02% Space Free | Partition Type: NTFS
Drive D: | 12,05 Gb Total Space | 8,96 Gb Free Space | 74,34% Space Free | Partition Type: NTFS
Drive E: | 1,96 Gb Total Space | 1,75 Gb Free Space | 89,41% Space Free | Partition Type: NTFS
Drive F: | 323,91 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive L: | 4,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: IDRAGON-PC | User Name: iDragon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016.03.20 20:42:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\iDragon\Downloads\OTL.exe
PRC - [2016.02.16 19:39:50 | 025,122,080 | ---- | M] (Dropbox, Inc.) -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2015.11.09 12:51:54 | 000,923,184 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2014.03.15 01:50:42 | 000,859,976 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014.02.10 14:08:54 | 000,009,216 | ---- | M] (Ellora Assets Corp.) -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
PRC - [2012.11.23 09:04:26 | 006,787,072 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtWLan.exe
PRC - [2012.05.10 09:38:06 | 000,036,864 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe
========== Modules (No Company Name) ==========
MOD - [2016.02.16 19:39:34 | 000,024,904 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
MOD - [2016.02.16 19:39:34 | 000,021,840 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
MOD - [2016.02.16 19:39:32 | 000,021,832 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
MOD - [2016.02.16 19:39:32 | 000,020,800 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_cffi_python_x66cf7a7cx17a72769.pyd
MOD - [2016.02.16 19:39:30 | 000,023,376 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
MOD - [2016.02.16 19:39:30 | 000,022,352 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
MOD - [2016.02.16 19:39:28 | 000,021,824 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd
MOD - [2016.02.16 19:39:28 | 000,020,800 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd
MOD - [2016.02.16 19:39:28 | 000,019,776 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd
MOD - [2016.02.16 19:39:26 | 000,020,800 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd
MOD - [2016.02.16 19:39:24 | 000,381,752 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
MOD - [2016.02.16 19:39:24 | 000,019,760 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
MOD - [2016.02.16 19:39:18 | 003,928,880 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
MOD - [2016.02.16 19:39:18 | 000,223,544 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
MOD - [2016.02.16 19:39:16 | 000,158,008 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
MOD - [2016.02.16 19:39:16 | 000,132,912 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
MOD - [2016.02.16 19:39:14 | 000,546,096 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
MOD - [2016.02.16 19:39:14 | 000,357,680 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
MOD - [2016.02.16 19:39:14 | 000,042,808 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
MOD - [2016.02.16 19:39:12 | 000,531,248 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
MOD - [2016.02.16 19:39:12 | 000,207,672 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
MOD - [2016.02.16 19:39:10 | 001,971,504 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
MOD - [2016.02.16 19:39:10 | 001,826,096 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
MOD - [2016.02.16 19:39:08 | 000,052,024 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
MOD - [2016.02.16 19:39:06 | 000,038,696 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\fastpath.pyd
MOD - [2016.02.16 19:39:06 | 000,024,392 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
MOD - [2016.02.16 19:39:04 | 000,084,792 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.dll
MOD - [2016.02.16 19:39:02 | 000,026,456 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
MOD - [2016.02.16 19:38:52 | 000,020,808 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
MOD - [2016.02.16 19:38:50 | 001,682,760 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
MOD - [2016.02.16 19:38:50 | 000,020,816 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
MOD - [2016.02.16 19:38:48 | 000,117,056 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd
MOD - [2016.02.16 19:38:48 | 000,020,280 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
MOD - [2016.01.12 19:52:06 | 000,697,304 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
MOD - [2016.01.12 19:49:22 | 001,631,184 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\libGLESv2.dll
MOD - [2016.01.12 19:49:12 | 000,017,864 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\libEGL.dll
MOD - [2016.01.12 19:47:34 | 000,036,296 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\librsync.dll
MOD - [2016.01.12 19:47:08 | 000,350,152 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\winxpgui.pyd
MOD - [2016.01.12 19:47:04 | 000,114,640 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32security.pyd
MOD - [2016.01.12 19:47:04 | 000,048,592 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32service.pyd
MOD - [2016.01.12 19:47:04 | 000,028,616 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32ts.pyd
MOD - [2016.01.12 19:47:02 | 000,043,472 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32process.pyd
MOD - [2016.01.12 19:47:02 | 000,030,160 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32pipe.pyd
MOD - [2016.01.12 19:47:02 | 000,024,016 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32profile.pyd
MOD - [2016.01.12 19:46:50 | 000,175,560 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32gui.pyd
MOD - [2016.01.12 19:46:46 | 000,124,880 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32file.pyd
MOD - [2016.01.12 19:46:40 | 000,057,808 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
MOD - [2016.01.12 19:46:40 | 000,024,528 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32event.pyd
MOD - [2016.01.12 19:46:38 | 000,105,928 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32api.pyd
MOD - [2016.01.12 19:46:38 | 000,024,016 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
MOD - [2016.01.12 19:46:38 | 000,020,936 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\mmapfile.pyd
MOD - [2016.01.12 19:45:54 | 000,112,592 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
MOD - [2016.01.12 19:45:50 | 000,083,912 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\sip.pyd
MOD - [2016.01.12 19:45:42 | 000,240,584 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\jpegtran.pyd
MOD - [2016.01.12 19:45:36 | 000,019,408 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\faulthandler.pyd
MOD - [2016.01.12 19:44:48 | 000,134,608 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_elementtree.pyd
MOD - [2016.01.12 19:44:48 | 000,034,768 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
MOD - [2016.01.12 19:44:46 | 000,093,640 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\_ctypes.pyd
MOD - [2016.01.12 19:44:44 | 000,692,688 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\unicodedata.pyd
MOD - [2016.01.12 19:44:42 | 000,018,376 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\select.pyd
MOD - [2016.01.12 19:44:40 | 000,134,088 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\pyexpat.pyd
MOD - [2016.01.12 19:44:34 | 000,116,688 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\pywintypes27.dll
MOD - [2016.01.12 19:44:30 | 000,392,144 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\pythoncom27.dll
MOD - [2014.03.15 01:50:40 | 000,394,568 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppgooglenaclpluginchrome.dll
MOD - [2014.03.15 01:50:38 | 004,061,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
MOD - [2014.03.15 01:50:35 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
MOD - [2014.03.15 01:50:34 | 000,100,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
MOD - [2014.03.15 01:50:32 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
MOD - [2014.03.15 01:50:30 | 000,051,016 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
========== Services (SafeList) ==========
SRV:
64bit: - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.11.149\McCHSvc.exe -- (McComponentHostService)
SRV:
64bit: - [2015.04.30 01:53:40 | 000,366,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:
64bit: - [2015.04.30 01:53:40 | 000,023,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:
64bit: - [2014.05.30 10:21:05 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:
64bit: - [2010.02.11 06:29:30 | 000,952,320 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\Windows\SysNative\Ati2evxx.exe -- (Ati External Event Utility)
SRV:
64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:
64bit: - [2000.08.04 18:02:38 | 000,514,563 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] -- C:\Windows\SysNative\spool\drivers\W32X86\hpzstatn.exe -- (hpzstatn)
SRV - [2016.03.10 20:02:50 | 000,835,152 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016.03.10 19:27:30 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015.10.05 09:48:46 | 001,135,416 | ---- | M] (Malwarebytes) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2015.07.21 19:23:32 | 000,831,096 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe -- (BstHdUpdaterSvc)
SRV - [2015.07.09 12:14:04 | 000,327,296 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2015.06.16 21:33:34 | 000,413,304 | ---- | M] (BlueStack Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2015.06.16 21:33:14 | 000,433,784 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2014.07.14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014.07.14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014.04.11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014.03.20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014.02.10 14:08:54 | 000,009,216 | ---- | M] (Ellora Assets Corp.) [Auto | Running] -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe -- (FreemakeVideoCapture)
SRV - [2013.11.06 17:29:45 | 004,609,416 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2013.08.23 15:46:55 | 000,076,888 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.05.10 09:38:06 | 000,036,864 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe -- (Realtek11nCU)
SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2000.08.04 18:02:38 | 000,514,563 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] -- C:\Windows\system32\spool\drivers\w32x86\hpzstatn.exe -- (hpzstatn)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2015.10.05 09:50:18 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:
64bit: - [2015.10.05 09:50:06 | 000,025,816 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:
64bit: - [2015.06.17 16:04:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2015.03.04 19:34:52 | 000,124,568 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:
64bit: - [2015.01.12 18:18:27 | 000,086,352 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\wolfk64.sys -- (wolfkr)
DRV:
64bit: - [2013.07.25 16:53:46 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:
64bit: - [2013.06.15 14:44:29 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012.02.10 09:36:44 | 000,986,728 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtwlanu.sys -- (RTL8192cu)
DRV:
64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011.02.11 22:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:
64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010.11.20 12:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:
64bit: - [2010.02.11 08:42:54 | 005,352,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2009.11.18 16:47:46 | 000,446,976 | ---- | M] (NETGEAR Inc. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wg111v3.sys -- (RTL8187B)
DRV:
64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.07.14 01:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:
64bit: - [2009.07.14 01:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:
64bit: - [2009.06.10 21:35:03 | 000,192,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\eFE5b32e.sys -- (E100B)
DRV:
64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009.04.22 12:46:06 | 003,552,384 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\snp2uvc.sys -- (SNP2UVC)
DRV:
64bit: - [2009.02.08 21:43:10 | 000,111,104 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hxctlflt.sys -- (hxctlflt)
DRV:
64bit: - [2007.04.23 12:15:48 | 000,031,016 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RtlProt.sys -- (RtlProt)
DRV - [2015.06.16 21:33:26 | 000,145,528 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=MSSE
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:
64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE:
64bit: - HKLM\..\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=MSSE
IE - HKLM\..\SearchScopes,DefaultScope = {BB82DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKLM\..\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKLM\..\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.google.com
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=MSSE
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..\SearchScopes,DefaultScope = {BB82DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IESR02
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.66.2: C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2: C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\torrents-time.com/TTPlugin: C:\Program Files (x86)\TorrentsTime Media Player\bin\npTTPlugin.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
fmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
fmdownloader@gmail.com\ [2014.02.16 16:09:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
ytfmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
ytfmdownloader@gmail.com\ [2014.02.16 16:09:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2015.04.17 17:09:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\iDragon\AppData\Roaming\Mozilla\Extensions
[2013.08.12 18:15:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\iDragon\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2016.02.02 20:16:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\iDragon\AppData\Roaming\Mozilla\Firefox\Profiles\sr3qfy7e.Deadhead\extensions
[2013.06.30 09:44:04 | 000,239,491 | ---- | M] () (No name found) -- C:\Users\iDragon\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
trtv3@trtv.com.xpi
[2015.11.04 13:13:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2016.01.08 11:40:12 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.1_0\
CHR - Extension: No name found = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.2_0\
CHR - Extension: No name found = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.2_1\
CHR - Extension: Freemake Video Downloader = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Freemake Video Downloader = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: Bookmark Manager = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Bookmark Manager = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo\4_0\
CHR - Extension: No name found = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\opjonmehjfmkejjifhhknofdnacklmjk\2_0\
CHR - Extension: MADAFAKA RICH BITCH = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: MADAFAKA RICH BITCH = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: MADAFAKA RICH BITCH = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\
CHR - Extension: MADAFAKA RICH BITCH = C:\Users\iDragon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8_0\
O1 HOSTS File: ([2015.07.28 15:15:16 | 000,001,479 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: @127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 adobe.activate.com 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1
www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91 127.0.0.1 hl2rcv.adobe.com
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll (Oracle Corporation)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000..\Run: [Dropbox Update] C:\Users\iDragon\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
O4 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000..\Run: [RocketDock] "C:\Program Files (x86)\Mountain Lion Skin Pack\RocketDock\RocketDock.exe" File not found
O4 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\iDragon\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk = File not found
O4 - Startup: C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\We Came As Romans - To Move On Is To Grow.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LocalAccountTokenFilterPolicy = 1
O9:
64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-1994060219-865576385-1721678995-1000\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F121D1A-EC52-433B-9103-08A54BFEED0F}: DhcpNameServer = 199.203.131.151
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{536D4476-ADC7-40E1-BF2A-7DE5D2232940}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B67F1705-D394-4F02-9529-BBB4A3D48A2B}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2015.09.25 16:42:51 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.06.13 05:16:21 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.06.18 11:24:20 | 000,000,045 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{3ee0ff09-d02b-11e2-8e39-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{3ee0ff09-d02b-11e2-8e39-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe -- [2012.11.08 06:46:44 | 000,716,800 | R--- | M] (ASUSTeK COMPUTER INC.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2016.03.20 19:46:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro
[2016.03.20 19:46:10 | 000,000,000 | ---D | C] -- C:\rsit
[2016.03.20 19:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2016.03.20 19:45:48 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2016.03.19 13:12:16 | 000,000,000 | ---D | C] -- C:\090d974ced83a7cdc896
[2016.03.08 22:11:14 | 000,000,000 | ---D | C] -- C:\84190c7b62706aa7c318510897
[2016.03.03 11:29:53 | 000,000,000 | ---D | C] -- C:\EFSTMPWP
[2016.02.29 16:54:07 | 000,000,000 | ---D | C] -- C:\Users\iDragon\Documents\Rainmeter
[2016.02.29 16:54:07 | 000,000,000 | ---D | C] -- C:\Users\iDragon\AppData\Roaming\Rainmeter
[2016.02.29 16:42:15 | 000,000,000 | ---D | C] -- C:\Program Files\Rainmeter
[2016.02.27 18:51:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2016.02.27 18:51:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2016.02.27 18:49:39 | 000,000,000 | ---D | C] -- C:\Users\iDragon\AppData\Roaming\Mine_imator
[2016.02.22 13:38:59 | 000,000,000 | ---D | C] -- C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013.01.19 08:44:40 | 002,174,976 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Program Files (x86)\Common Files\atimpenc.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2016.03.20 20:47:38 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2016.03.20 20:26:19 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000UA.job
[2016.03.20 20:23:05 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016.03.20 19:46:05 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016.03.20 19:40:45 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016.03.20 19:40:44 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016.03.20 19:27:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016.03.20 19:27:30 | 2616,053,760 | -HS- | M] () -- C:\hiberfil.sys
[2016.03.19 22:26:01 | 000,000,874 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000Core.job
[2016.03.16 16:30:46 | 000,001,966 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2016.03.16 16:30:46 | 000,001,132 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RocketDock.lnk
[2016.03.16 16:30:18 | 000,002,725 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2016.03.16 16:30:18 | 000,002,155 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\We Came As Romans - To Move On Is To Grow.lnk
[2016.03.16 16:30:18 | 000,002,080 | ---- | M] () -- C:\Users\Public\Desktop\SDFormatter.lnk
[2016.03.16 16:30:18 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2016.03.16 16:30:18 | 000,001,801 | ---- | M] () -- C:\Users\Public\Desktop\Start BlueStacks.lnk
[2016.03.16 16:30:18 | 000,001,774 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
[2016.03.16 16:30:18 | 000,001,618 | ---- | M] () -- C:\Users\Public\Desktop\Terraria.lnk
[2016.03.16 16:30:18 | 000,001,143 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2016.03.16 16:30:17 | 000,002,093 | ---- | M] () -- C:\Users\Public\Desktop\ASUS USB-N13 WLAN Control Center.lnk
[2016.03.16 16:30:17 | 000,001,944 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2016.03.16 16:30:17 | 000,001,747 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2016.03.16 16:30:17 | 000,001,562 | ---- | M] () -- C:\Users\Public\Desktop\Free YouTube to iPhone Converter.lnk
[2016.03.16 16:30:17 | 000,001,326 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Downloader.lnk
[2016.03.16 16:30:17 | 000,001,314 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2016.03.16 16:30:17 | 000,001,235 | ---- | M] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
[2016.03.16 16:30:17 | 000,001,141 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2016.03.16 16:30:17 | 000,001,096 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016.03.16 16:30:17 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\Dragon Saga.lnk
[2016.03.16 16:30:17 | 000,000,902 | ---- | M] () -- C:\Users\Public\Desktop\Mine-imator.lnk
[2016.03.16 16:29:01 | 000,000,359 | ---- | M] () -- C:\Users\iDragon\Desktop\Počítač.lnk
[2016.03.16 15:54:09 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016.03.10 19:27:18 | 000,797,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2016.03.10 19:27:17 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2016.03.10 19:25:35 | 011,035,328 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2016.03.07 19:38:56 | 000,668,882 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2016.03.07 19:38:56 | 000,654,270 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2016.03.07 19:38:56 | 000,141,542 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2016.03.07 19:38:56 | 000,122,142 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2016.03.07 19:38:55 | 001,584,626 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2016.03.20 20:47:38 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2016.03.20 19:46:05 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016.02.29 16:42:21 | 000,001,774 | ---- | C] () -- C:\Users\iDragon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
[2016.02.29 16:42:21 | 000,001,738 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainmeter.lnk
[2016.02.27 18:51:06 | 000,002,725 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2016.02.01 17:46:12 | 000,007,605 | ---- | C] () -- C:\Users\iDragon\AppData\Local\Resmon.ResmonCfg
[2015.10.04 12:11:52 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2015.05.25 14:18:17 | 000,000,000 | ---- | C] () -- C:\Users\iDragon\AppData\Local\Temp.dat
[2015.05.19 21:07:32 | 000,000,024 | ---- | C] () -- C:\Users\iDragon\AppData\Roaming\appdataFr25.bin
[2015.04.30 21:50:07 | 000,000,158 | ---- | C] () -- C:\Program Files (x86)\prefs.js
[2015.04.07 18:52:28 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2015.03.21 11:29:14 | 000,000,020 | ---- | C] () -- C:\Users\iDragon\AppData\Roaming\appdataFr3.bin
[2014.11.17 14:56:22 | 000,000,004 | ---- | C] () -- C:\Users\iDragon\AppData\Roaming\appdataFr2.bin
[2014.06.16 16:31:49 | 000,000,203 | ---- | C] () -- C:\Windows\hpfsched.ini
[2014.02.01 15:15:43 | 000,000,270 | RHS- | C] () -- C:\ProgramData\ntuser.pol
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.03.25 03:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.03.25 03:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2015.11.23 12:27:20 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\.minecraft
[2013.06.15 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DAEMON Tools Lite
[2013.06.28 17:17:39 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DragonicaECB
[2016.03.20 19:30:17 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Dropbox
[2015.08.23 12:26:44 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DVDVideoSoft
[2013.06.29 21:42:02 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Image-Line
[2013.06.29 21:34:27 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\ImTOO
[2015.10.13 15:21:40 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\java
[2016.02.27 19:19:34 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Mine_imator
[2015.04.08 16:15:18 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\MMFApplications
[2016.02.29 16:54:08 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Rainmeter
[2013.06.15 16:08:53 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Seznam.cz
[2015.11.02 18:06:55 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\skyz
[2013.06.15 16:13:36 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\SongManager
[2013.08.18 10:43:45 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2015.04.14 19:10:54 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\ThinkSky
[2016.03.17 20:45:00 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\uTorrent
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,594 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2015.05.15 12:49:16 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2015.06.21 12:15:01 | 000,000,874 | ---- | C] () -- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000Core.job
[2015.06.21 12:15:02 | 000,000,926 | ---- | C] () -- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000UA.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2015.04.11 05:31:36 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=43DCEC23557C32F7702C8D5BC729738F -- C:\Windows\SoftwareDistribution\Download\297f31dca24f19f19a16aefa9c58cd10\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7601.23033_none_2df8898bfd178df8\services.exe
[2015.04.13 04:28:33 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=71C85477DF9347FE8E7BC55768473FCA -- C:\Windows\SoftwareDistribution\Download\297f31dca24f19f19a16aefa9c58cd10\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7601.18829_none_2d7fe646e3ec3705\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2015.10.05 09:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
< MD5 for: TCPIP.SYS >
[2014.04.05 03:47:20 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=04ADD18EE5CC9FBEDAEC1DD1CD0CB45E -- C:\Windows\SysNative\drivers\tcpip.sys
[2014.04.05 03:47:20 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=04ADD18EE5CC9FBEDAEC1DD1CD0CB45E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18438_none_113260637d1284ef\tcpip.sys
[2012.10.03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2013.05.08 07:14:42 | 001,900,392 | ---- | M] (Microsoft Corporation) MD5=3E94650745D4DAB67E161F5F32CEA597 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_11d29984961f0be0\tcpip.sys
[2013.09.08 03:30:37 | 001,903,552 | ---- | M] (Microsoft Corporation) MD5=40AF23633D197905F03AB5628C558C51 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_1118bb977d265d27\tcpip.sys
[2014.04.05 03:37:43 | 001,897,408 | ---- | M] (Microsoft Corporation) MD5=4F80944B03112F486212DC20BE166079 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22648_none_11b12f2896383dd1\tcpip.sys
[2010.11.20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2013.01.04 06:41:01 | 001,893,224 | ---- | M] (Microsoft Corporation) MD5=5CFB7AB8F9524D1A1E14369DE63B83CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.17206_none_0f6a6af57fd59de6\tcpip.sys
[2013.01.03 06:57:12 | 001,876,824 | ---- | M] (Microsoft Corporation) MD5=692969AB90BDA19F56E27BF89A9260E2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21415_none_0fe8397098fc3d71\tcpip.sys
[2013.09.07 03:27:48 | 001,896,896 | ---- | M] (Microsoft Corporation) MD5=75F9106B74585D38C8FF6BB5CAD262D7 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_11ad2a34963bde27\tcpip.sys
[2010.04.09 12:06:28 | 001,898,376 | ---- | M] (Microsoft Corporation) MD5=7FC877A25796D8ADF539E64703FCA7E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16569_none_0f2ca8c580036f65\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2013.05.08 07:39:01 | 001,910,632 | ---- | M] (Microsoft Corporation) MD5=9849EA3843A2ADBDD1497E97A85D8CAE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_11278ac57d1aa96b\tcpip.sys
[2010.04.09 08:56:29 | 001,892,232 | ---- | M] (Microsoft Corporation) MD5=A9C0F786AC1F736891D05CE0A1D29DEB -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20687_none_0f9ea52499331463\tcpip.sys
[2013.07.06 06:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
[2013.01.03 07:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
[2013.01.04 06:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
[2012.10.03 18:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2013.07.06 07:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
[2013.11.26 12:34:34 | 001,897,408 | ---- | M] (Microsoft Corporation) MD5=F55B41AA6114568AC558ADBABDA85620 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22525_none_11c3cc3c962abcc3\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2014.03.04 12:08:14 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=6CE2AE073BD21C542FC2C707CAE944CC -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce748d1d04acf24f\winlogon.exe
[2014.03.04 10:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\SysNative\winlogon.exe
[2014.03.04 10:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8bf35eb848572\winlogon.exe
[2014.07.17 03:07:24 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=8CEBD9D0A0A879CDE9F36F4383B7CAEA -- C:\Windows\SoftwareDistribution\Download\81b80f6a81d826a058dde28ed40719e5\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_cdc47ed1ebad0e4e\winlogon.exe
[2014.07.16 04:23:23 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=98AA0BFEE089C7E5DADB94190D93456C -- C:\Windows\SoftwareDistribution\Download\81b80f6a81d826a058dde28ed40719e5\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_ce434d9704d2c730\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[2015.10.05 09:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[10 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[16 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[15 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\9b69d8c85dfecd630e28e7ddf9205c1f\*.tmp files -> C:\Windows\SoftwareDistribution\Download\9b69d8c85dfecd630e28e7ddf9205c1f\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\bf037778e12792d2bed8e1b555adc1cd\*.tmp files -> C:\Windows\SoftwareDistribution\Download\bf037778e12792d2bed8e1b555adc1cd\*.tmp -> ]
[41 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2015.11.23 12:27:20 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\.minecraft
[2015.10.06 18:35:54 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Adobe
[2013.08.18 10:43:46 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Adobe Mini Bridge CS5.1
[2015.09.25 10:52:26 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Apple Computer
[2014.04.06 17:38:52 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\ATI
[2013.06.15 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DAEMON Tools Lite
[2013.06.28 17:17:39 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DragonicaECB
[2016.03.20 19:30:17 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Dropbox
[2015.08.23 12:26:44 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\DVDVideoSoft
[2013.06.08 12:16:51 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Identities
[2013.06.29 21:42:02 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Image-Line
[2013.06.29 21:34:27 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\ImTOO
[2015.10.13 15:21:40 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\java
[2013.06.15 15:55:12 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Macromedia
[2013.06.23 13:07:28 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Media Center Programs
[2015.05.15 22:05:35 | 000,000,000 | --SD | M] -- C:\Users\iDragon\AppData\Roaming\Microsoft
[2016.02.27 19:19:34 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Mine_imator
[2015.04.08 16:15:18 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\MMFApplications
[2015.04.17 17:09:27 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Mozilla
[2016.02.29 16:54:08 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Rainmeter
[2013.06.15 16:08:53 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Seznam.cz
[2016.02.27 20:24:16 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Skype
[2015.11.02 18:06:55 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\skyz
[2013.06.15 16:13:36 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\SongManager
[2013.08.18 10:43:45 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2015.10.13 15:20:00 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\Sun
[2015.04.14 19:10:54 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\ThinkSky
[2016.03.17 20:45:00 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\uTorrent
[2013.06.15 14:20:55 | 000,000,000 | ---D | M] -- C:\Users\iDragon\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2016.02.16 19:39:50 | 025,122,080 | ---- | M] (Dropbox, Inc.) -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2016.02.16 19:40:02 | 000,173,032 | ---- | M] (Dropbox, Inc.) -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2016.01.12 19:50:22 | 000,018,392 | ---- | M] () -- C:\Users\iDragon\AppData\Roaming\Dropbox\bin\QtWebEngineProcess.exe
[2015.05.12 20:06:16 | 000,045,056 | R--- | M] (InstallShield Software Corp.) -- C:\Users\iDragon\AppData\Roaming\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
[2014.04.06 17:33:28 | 000,010,134 | R--- | M] () -- C:\Users\iDragon\AppData\Roaming\Microsoft\Installer\{9DBCF44B-77AC-81D8-0F8E-1E60D6330AC2}\ARPPRODUCTICON.exe
[2016.02.29 16:54:07 | 000,004,608 | -H-- | M] () -- C:\Users\iDragon\AppData\Roaming\Rainmeter\Rainmeter.exe
[2013.06.06 23:25:00 | 000,884,568 | ---- | M] (BitTorrent Inc.) -- C:\Users\iDragon\AppData\Roaming\uTorrent\utorrent.exe
[2013.06.06 23:25:00 | 000,884,568 | ---- | M] (BitTorrent Inc.) -- C:\Users\iDragon\AppData\Roaming\uTorrent\updates\3.3.1_29782.exe
[2013.06.13 18:34:48 | 000,884,056 | ---- | M] (BitTorrent Inc.) -- C:\Users\iDragon\AppData\Roaming\uTorrent\updates\3.3.1_29801.exe
[2013.07.16 18:15:22 | 000,884,056 | ---- | M] (BitTorrent Inc.) -- C:\Users\iDragon\AppData\Roaming\uTorrent\updates\3.3.1_29812.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2016.03.20 21:23:48 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2016.03.19 22:26:01 | 000,000,874 | ---- | M] () -- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000Core.job
[2016.03.20 21:26:10 | 000,000,926 | ---- | M] () -- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1994060219-865576385-1721678995-1000UA.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Steam" = "C:\Program Files (x86)\Steam\steam.exe" -silent -- [2016.03.10 20:02:50 | 003,074,128 | ---- | M] (Valve Corporation)
"RocketDock" = "C:\Program Files (x86)\Mountain Lion Skin Pack\RocketDock\RocketDock.exe"
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2013.03.14 09:23:30 | 003,672,640 | ---- | M] (Disc Soft Ltd)
"Dropbox Update" = "C:\Users\iDragon\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c -- [2015.06.21 12:14:55 | 000,134,512 | ---- | M] (Dropbox, Inc.)
"CCleaner Monitoring" = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR -- [2016.02.12 22:11:52 | 008,641,240 | ---- | M] (Piriform Ltd)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2016.01.08 11:40:05 | 000,392,136 | ---- | M] (Mozilla Corporation) MD5=1103DF442ACE5870CAFE6977EF192CA5 -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2014.06.02 05:43:13 | 000,812,248 | ---- | M] (Microsoft Corporation) MD5=60F88F6CA6303E8273AF7AAA9AAFECAC -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2014.03.15 01:50:42 | 000,859,976 | ---- | M] (Google Inc.) MD5=3A924B200D86590D2C83214CEBFA9742 -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2016.03.20 20:47:38 | 000,000,512 | ---- | M] () MD5=2BC8692F0DBC8C30F9D32F9D0FDD41EC -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2007.09.06 13:22:20 | 000,002,432 | ---- | M] () -- \Program Files (x86)\Common Files\Native Instruments\Shared Content\Sounds\Massive\Crackle Carl.ksd
[2007.09.06 13:22:20 | 000,002,061 | ---- | M] () -- \Program Files (x86)\Common Files\Native Instruments\Shared Content\Sounds\Massive\Digitoy Crackle.ksd
[2008.09.08 21:55:14 | 000,000,204 | ---- | M] () -- \Program Files (x86)\Image-Line\FL Studio 10\Plugins\Fruity\Effects\Hardcore\Presets\I cracked my Tube!.hdprg
[2010.01.15 21:56:40 | 000,000,272 | ---- | M] () -- \Program Files (x86)\Image-Line\FL Studio 10\Plugins\Fruity\Generators\Drumaxx\Drum Patches\Sound FX\Crack.dmpatch
[2010.01.15 21:56:40 | 000,000,272 | ---- | M] () -- \Program Files (x86)\Image-Line\FL Studio 10\Plugins\Fruity\Generators\DrumPad\Drum Patches\Sound FX\Crack.dmpatch
[2015.09.15 17:36:44 | 000,000,569 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\dota\scripts\vscripts\animation\particle\cracked_boulder.lua
[2015.09.15 17:36:58 | 000,001,400 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\dota_addons\holdout_example\particles\creature_splitter\earthspirit_stone_cracks.vpcf_c
[2015.12.17 14:32:37 | 000,001,741 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\dota_addons\overthrow\particles\traps\pendulum\wheel_scrape_cracks.vpcf_c
[2015.04.10 17:29:10 | 000,000,127 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff\ff_wall_cement17_cracked_blue.vmt
[2015.04.10 17:29:12 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff\ff_wall_cement17_cracked_blue.vtf
[2015.04.10 17:28:55 | 000,000,126 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff\ff_wall_cement17_cracked_red.vmt
[2015.04.10 17:29:08 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff\ff_wall_cement17_cracked_red.vtf
[2015.04.10 17:22:14 | 000,000,345 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff_impact\blend_quarkscracks.vmt
[2015.04.10 17:22:14 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff_impact\blend_quarkscracks_tooltexture.vtf
[2015.04.10 17:22:15 | 000,000,218 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff_impact\crackfloor.vmt
[2015.04.10 17:22:15 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff_impact\crackfloor.vtf
[2015.04.10 17:22:15 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\materials\ff_impact\crackfloor_normal.vtf
[2015.04.12 10:44:24 | 000,703,996 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\FortressForever\sound\Misc\lopecrackmeup.wav
[2015.04.10 17:30:47 | 000,000,574 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\hl2\materials\glass\glasswindow018a_cracked.vmt
[2015.04.10 17:30:42 | 000,022,064 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Fortress Forever\hl2\materials\glass\glasswindow018a_cracked.vtf
[2015.10.04 12:08:08 | 000,009,482 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\ui\icon\inventory\rarity\icon_crystal_cracked.png
[2015.10.04 12:08:08 | 000,011,211 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\ui\icon\inventory\weapon\bomb\firecracker.png
[2015.10.04 12:10:56 | 000,011,030 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\world\prop\castle_fire\spritewell\decal_cracks.png
[2015.10.04 12:11:06 | 000,013,768 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\world\prop\graveyard\gravestone01_crack.png
[2015.10.04 12:11:06 | 000,001,416 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\world\prop\graveyard\gravestone02_crack.png
[2015.10.04 12:11:06 | 000,002,579 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Spiral Knights\rsrc\world\prop\graveyard\gravestone03_crack.png
[2006.06.20 18:33:16 | 000,000,127 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff\ff_wall_cement17_cracked_blue.vmt
[2006.02.11 14:56:26 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff\ff_wall_cement17_cracked_blue.vtf
[2006.06.18 23:49:24 | 000,000,126 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff\ff_wall_cement17_cracked_red.vmt
[2006.02.11 14:56:26 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff\ff_wall_cement17_cracked_red.vtf
[2008.12.02 01:39:48 | 000,000,345 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff_impact\blend_quarkscracks.vmt
[2008.12.02 01:39:48 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff_impact\blend_quarkscracks_tooltexture.vtf
[2008.12.02 01:39:48 | 000,000,218 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff_impact\crackfloor.vmt
[2008.12.02 01:39:48 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff_impact\crackfloor.vtf
[2008.12.02 01:39:48 | 000,174,984 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\FortressForever\materials\ff_impact\crackfloor_normal.vtf
[2014.06.10 11:30:29 | 000,000,269 | ---- | M] () -- \ProgramData\BlueStacks\UserData\InputMapper\com.fluik.PlumberCrack.cfg
[2014.06.10 11:30:29 | 000,000,623 | ---- | M] () -- \ProgramData\BlueStacks\UserData\InputMapper\com.polarbit.crackingsands.cfg
[2014.06.10 11:30:29 | 000,000,618 | ---- | M] () -- \ProgramData\BlueStacks\UserData\InputMapper\com.polarbit.crackingsandsads.cfg
[2014.06.10 11:30:31 | 000,000,413 | ---- | M] () -- \ProgramData\BlueStacks\UserData\InputMapper\org.supergonk.safecrackerpremium.cfg
[2014.06.10 11:30:29 | 000,000,269 | ---- | M] () -- \Users\All Users\BlueStacks\UserData\InputMapper\com.fluik.PlumberCrack.cfg
[2014.06.10 11:30:29 | 000,000,623 | ---- | M] () -- \Users\All Users\BlueStacks\UserData\InputMapper\com.polarbit.crackingsands.cfg
[2014.06.10 11:30:29 | 000,000,618 | ---- | M] () -- \Users\All Users\BlueStacks\UserData\InputMapper\com.polarbit.crackingsandsads.cfg
[2014.06.10 11:30:31 | 000,000,413 | ---- | M] () -- \Users\All Users\BlueStacks\UserData\InputMapper\org.supergonk.safecrackerpremium.cfg
[2013.07.16 19:24:01 | 000,012,452 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\3D Studio Max 2011 Pre-Cracked.2011.torrent
[2013.07.14 15:44:30 | 000,018,832 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\3DS Max 2012+ CRACK BY A2Sins.torrent
[2013.07.16 19:25:04 | 000,120,991 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\AUTODESK 3D STUDIO MAX DESIGN 2010 & AUTODESK 3D STUDIO MAX+ CRACK + EXTRA Utilities.torrent
[2013.06.24 16:08:28 | 000,075,531 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\Bioshock 2[Alcohol 120][No crack].torrent
[2013.07.01 15:37:31 | 000,007,088 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\BioShock.2.PROPER.CRACK_RELOADED.rar.torrent
[2013.06.13 18:34:30 | 000,018,796 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\Fl Studio 10 + crack.1.torrent
[2013.06.13 18:34:30 | 000,018,796 | ---- | M] () -- \Users\iDragon\AppData\Roaming\uTorrent\Fl Studio 10 + crack.torrent
[2011.04.07 23:07:32 | 000,041,604 | ---- | M] () -- \Users\iDragon\Desktop\Documents\.minecraft\resources\mod\sound\crack1.wav
[2011.04.07 23:11:46 | 000,055,756 | ---- | M] () -- \Users\iDragon\Desktop\Documents\.minecraft\resources\mod\sound\cracks1.wav
[2011.04.07 23:15:22 | 000,119,476 | ---- | M] () -- \Users\iDragon\Desktop\Documents\.minecraft\resources\mod\sound\cracks3.wav
[2014.01.18 15:14:24 | 002,175,528 | ---- | M] () -- \Users\iDragon\Desktop\Documents\iTunes\Hudba\Cracks (Flux Pavilion Remix).mp3
< *keygen* /s >
< *loader* /s >
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \KMPlayer\ImLoader.dll
[2015.12.17 18:39:16 | 000,060,688 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\YSLoader.exe
[2013.08.15 12:14:34 | 000,039,992 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\DVDVideoSoft.DVSVideoDownloader.dll
[2015.06.16 01:23:40 | 003,213,328 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe
[2015.06.16 01:22:04 | 000,704,000 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.pdb
[2015.05.05 11:00:30 | 000,000,936 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.xml
[2015.04.11 15:25:14 | 000,004,856 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloaderProfile.xml
[2015.04.11 15:25:14 | 000,006,610 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloaderProfileD.xml
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\da-DK\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\de-DE\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,036,864 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\el-GR\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\es-ES\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,013,824 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\fi-FI\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\fr-FR\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\hu-HU\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\it-IT\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\ja-JP\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\nl-NL\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\pl-PL\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\pt-BR\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\pt-PT\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,036,864 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\ru-RU\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:52 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\sk-SK\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,019,968 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\sl-SI\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\sv-SE\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\tr-TR\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,032,768 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\vi-VN\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,019,968 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\zh-CN\FreeYTVDownloader.resources.dll
[2015.06.16 01:21:54 | 000,019,968 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube Download\zh-TW\FreeYTVDownloader.resources.dll
[2013.08.15 12:14:34 | 000,039,992 | ---- | M] () -- \Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\DVDVideoSoft.DVSVideoDownloader.dll
[2013.06.06 03:54:16 | 000,015,511 | ---- | M] () -- \Program Files (x86)\Freemake\Freemake Video Converter\FMCommon\FreemakeCommon\Profiles\FmDownloaderProfiles.xml
[2013.06.06 03:54:16 | 000,064,651 | ---- | M] () -- \Program Files (x86)\Freemake\Freemake Video Converter\FMCommon\FreemakeCommon\Resources\VideoDownloader.png
[2013.06.06 03:54:16 | 000,064,719 | ---- | M] () -- \Program Files (x86)\Freemake\Freemake Video Converter\FMCommon\FreemakeCommon\Resources\VideoDownloaderOn.png