musel sem to rozdelit
========== Files/Folders - Created Within 30 Days ==========
[2012.03.03 17:02:15 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.03.03 15:54:10 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxthon
[2012.03.03 15:54:09 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Maxthon3
[2012.03.03 15:54:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Maxthon3
[2012.03.03 15:48:49 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.03.03 13:37:40 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\Nová složka (2)
[2012.03.03 13:31:09 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\Boot
[2012.03.03 11:37:53 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\Nová složka
[2012.03.03 08:57:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dead Disc Doctor
[2012.03.03 08:17:55 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\Fotecky!
[2012.03.03 07:56:01 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\wwwwwwwwwww
[2012.03.03 07:01:56 | 000,585,216 | ---- | C] (OldTimer Tools) -- C:\Users\CART\Desktop\OTL.exe
[2012.03.03 03:22:20 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\XnView
[2012.03.03 03:22:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
[2012.03.03 03:22:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XnView
[2012.03.03 02:20:26 | 000,000,000 | ---D | C] -- C:\Users\CART\Documents\ZPS14
[2012.03.03 02:20:24 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Zoner
[2012.03.03 02:20:24 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Local\Zoner
[2012.03.03 02:20:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Zoner
[2012.03.03 02:20:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoner Photo Studio 14
[2012.03.03 02:19:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zoner
[2012.02.28 20:36:44 | 010,731,611 | ---- | C] (XeroBank) -- C:\Users\CART\Desktop\XeroBank_Installer_3.9.10.24.EXE
[2012.02.27 23:35:56 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.02.27 23:35:54 | 000,000,000 | ---D | C] -- C:\rsit
[2012.02.26 21:48:08 | 000,352,784 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\5555295.sys
[2012.02.26 21:48:08 | 000,157,712 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\55552951.sys
[2012.02.26 21:48:08 | 000,040,464 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\55552952.sys
[2012.02.26 21:48:07 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\Virus Removal Tool
[2012.02.26 17:42:49 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\Foto Mobilek
[2012.02.26 15:14:03 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.02.26 08:27:13 | 000,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTTextToAudio2.dll
[2012.02.26 08:27:13 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mp3 Audio Editor
[2012.02.26 08:12:55 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Mp3 Audio Editor
[2012.02.26 07:09:20 | 003,628,016 | ---- | C] (Piriform Ltd) -- C:\Users\CART\Desktop\ccsetup316.exe
[2012.02.26 07:04:38 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\systweak
[2012.02.26 06:57:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MuseTips
[2012.02.26 06:57:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MuseTips
[2012.02.26 06:52:36 | 000,000,000 | ---D | C] -- C:\Users\CART\Documents\Native Instruments
[2012.02.26 06:52:07 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Native Instruments
[2012.02.26 06:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
[2012.02.26 06:52:00 | 000,000,000 | ---D | C] -- C:\Users\CART\Documents\Traktor3
[2012.02.26 06:31:04 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\KOTATKO SD
[2012.02.26 06:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Power Mp3 Editor 2004
[2012.02.26 06:11:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Power Mp3 Editor 2004
[2012.02.26 06:00:51 | 000,000,000 | ---D | C] -- C:\Users\CART\Desktop\VVVVVV
[2012.02.26 01:51:59 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2012.02.26 01:47:08 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\010101010101010101010101010101010100
[2012.02.26 00:42:47 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\OBRAZKY
[2012.02.26 00:36:04 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\NEW FOTO ATD
[2012.02.26 00:34:20 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\NEW MP3
[2012.02.18 05:19:02 | 000,000,000 | ---D | C] -- C:\Users\CART\AppData\Roaming\Audacity
[2012.02.18 05:17:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
[2012.02.15 15:20:01 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2012.02.15 15:19:55 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl
[2012.02.15 15:19:54 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl
[2012.02.15 15:19:45 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll
[2012.02.15 15:19:18 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012.02.15 15:19:18 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.02.15 15:19:17 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.02.15 15:19:16 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.02.15 15:19:16 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.02.15 15:19:15 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.02.15 15:19:15 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.02.12 04:58:23 | 000,000,000 | ---D | C] -- C:\Casino
[2012.02.12 03:02:19 | 000,000,000 | R--D | C] -- C:\Users\CART\Desktop\hhhhhh
[2012.02.10 03:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012.02.10 03:20:58 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[1 C:\Users\CART\*.tmp files -> C:\Users\CART\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.03.03 17:16:16 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.03.03 17:14:13 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.03 17:14:13 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.03 17:06:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.03 17:06:51 | 3167,346,688 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.03 17:02:31 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012.03.03 17:01:28 | 000,585,216 | ---- | M] (OldTimer Tools) -- C:\Users\CART\Desktop\OTL.exe
[2012.03.03 15:54:10 | 000,001,094 | ---- | M] () -- C:\Users\CART\Desktop\Maxthon 3.lnk
[2012.03.03 15:48:50 | 000,002,313 | ---- | M] () -- C:\Users\CART\Desktop\Google Chrome.lnk
[2012.03.03 14:43:40 | 000,002,544 | ---- | M] () -- C:\Windows\diagwrn.xml
[2012.03.03 14:43:40 | 000,001,890 | ---- | M] () -- C:\Windows\diagerr.xml
[2012.03.03 13:41:13 | 001,656,524 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.03 13:41:13 | 000,700,022 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012.03.03 13:41:13 | 000,669,682 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.03 13:41:13 | 000,153,592 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012.03.03 13:41:13 | 000,133,384 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.03 08:57:35 | 000,000,773 | ---- | M] () -- C:\Users\Public\Desktop\DeadDiscDoctor.exe.lnk
[2012.03.03 03:22:31 | 000,000,923 | ---- | M] () -- C:\Users\CART\Desktop\XnView.lnk
[2012.03.03 02:20:09 | 000,002,077 | ---- | M] () -- C:\Users\Public\Desktop\Zoner Photo Studio 14 FREE.lnk
[2012.03.01 20:59:05 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.03.01 19:42:19 | 115,802,720 | ---- | M] () -- C:\Users\CART\Desktop\Fimfárum.rar
[2012.03.01 05:28:49 | 000,000,648 | ---- | M] () -- C:\Users\CART\Desktop\xB Browser.lnk
[2012.02.28 20:38:00 | 010,731,611 | ---- | M] (XeroBank) -- C:\Users\CART\Desktop\XeroBank_Installer_3.9.10.24.EXE
[2012.02.28 19:15:36 | 000,935,175 | ---- | M] () -- C:\Users\CART\Desktop\RSITx64.exe
[2012.02.28 18:59:17 | 000,075,839 | ---- | M] () -- C:\Users\CART\Desktop\oooooooooooooooooooooooooooooooooooo.jpg
[2012.02.28 18:57:31 | 000,075,839 | ---- | M] () -- C:\Users\CART\Desktop\418089_358570510841007_100000641842673_1128105_128257947_n.jpg
[2012.02.27 02:16:19 | 000,007,061 | ---- | M] () -- C:\Users\CART\Desktop\FDV413413_RS4120039_medium.jpg
[2012.02.26 21:22:34 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.26 19:27:59 | 120,786,136 | ---- | M] () -- C:\Users\CART\Documents\Super Mario pack PC.zip
[2012.02.26 19:19:02 | 000,018,984 | ---- | M] () -- C:\Users\CART\Documents\Super Mario pack PC.zip.torrent
[2012.02.26 18:40:57 | 034,963,428 | ---- | M] () -- C:\Users\CART\Desktop\youtube.com.Anonymní zpráva vládcům světa. #GlobalREvolution 2012 [CZ SUB] - YouTube_6.flv
[2012.02.26 18:34:48 | 000,067,186 | ---- | M] () -- C:\Users\CART\Desktop\dddddd.jpg
[2012.02.26 18:02:09 | 007,739,592 | ---- | M] () -- C:\Users\CART\Desktop\Modified-Motion---1Up.mp3
[2012.02.26 16:36:15 | 000,088,667 | ---- | M] () -- C:\Users\CART\Desktop\430970_2257758222812_1814086776_1343916_2025360729_n.jpg
[2012.02.26 08:27:14 | 000,000,770 | ---- | M] () -- C:\Users\CART\Desktop\Mp3 Audio Editor.lnk
[2012.02.26 07:10:33 | 000,001,021 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.02.26 07:09:47 | 003,628,016 | ---- | M] (Piriform Ltd) -- C:\Users\CART\Desktop\ccsetup316.exe
[2012.02.26 06:57:43 | 000,001,273 | ---- | M] () -- C:\Users\Public\Desktop\Free MP3 Cutter and Editor.lnk
[2012.02.26 06:52:49 | 000,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn
[2012.02.26 06:52:49 | 000,001,409 | ---- | M] () -- C:\Windows\QTFont.for
[2012.02.26 06:52:32 | 000,001,205 | ---- | M] () -- C:\Users\CART\Desktop\Traktor DJ Studio 3.lnk
[2012.02.26 06:48:28 | 000,025,734 | ---- | M] () -- C:\BarStyle.dat
[2012.02.26 06:12:54 | 000,000,013 | ---- | M] () -- C:\Windows\SysWow64\WINSPOOL.CRC
[2012.02.26 06:11:11 | 000,001,042 | ---- | M] () -- C:\Users\CART\Desktop\Power Mp3 Editor 2004.lnk
[2012.02.26 01:53:08 | 000,000,639 | ---- | M] () -- C:\Users\CART\Desktop\KMPlayer.lnk
[2012.02.26 01:23:30 | 000,000,517 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012.02.18 05:17:54 | 000,001,148 | ---- | M] () -- C:\Users\CART\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2012.02.18 05:10:00 | 000,889,298 | ---- | M] () -- C:\00.bmp
[2012.02.16 03:26:12 | 000,278,736 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.02.12 04:58:26 | 000,000,767 | ---- | M] () -- C:\Users\Public\Desktop\EuroGrand Casino.lnk
[1 C:\Users\CART\*.tmp files -> C:\Users\CART\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.03.03 17:16:16 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.03.03 17:06:51 | 3167,346,688 | -HS- | C] () -- C:\hiberfil.sys
[2012.03.03 15:54:10 | 000,001,094 | ---- | C] () -- C:\Users\CART\Desktop\Maxthon 3.lnk
[2012.03.03 15:48:50 | 000,002,313 | ---- | C] () -- C:\Users\CART\Desktop\Google Chrome.lnk
[2012.03.03 08:57:35 | 000,000,773 | ---- | C] () -- C:\Users\Public\Desktop\DeadDiscDoctor.exe.lnk
[2012.03.03 08:03:12 | 000,002,544 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012.03.03 08:03:12 | 000,001,890 | ---- | C] () -- C:\Windows\diagerr.xml
[2012.03.03 03:22:09 | 000,000,923 | ---- | C] () -- C:\Users\CART\Desktop\XnView.lnk
[2012.03.03 02:20:09 | 000,002,077 | ---- | C] () -- C:\Users\Public\Desktop\Zoner Photo Studio 14 FREE.lnk
[2012.03.01 19:42:15 | 115,802,720 | ---- | C] () -- C:\Users\CART\Desktop\Fimfárum.rar
[2012.02.28 18:59:16 | 000,075,839 | ---- | C] () -- C:\Users\CART\Desktop\oooooooooooooooooooooooooooooooooooo.jpg
[2012.02.28 18:57:27 | 000,075,839 | ---- | C] () -- C:\Users\CART\Desktop\418089_358570510841007_100000641842673_1128105_128257947_n.jpg
[2012.02.27 23:35:06 | 000,935,175 | ---- | C] () -- C:\Users\CART\Desktop\RSITx64.exe
[2012.02.27 02:16:19 | 000,007,061 | ---- | C] () -- C:\Users\CART\Desktop\FDV413413_RS4120039_medium.jpg
[2012.02.26 21:22:34 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.26 19:19:02 | 120,786,136 | ---- | C] () -- C:\Users\CART\Documents\Super Mario pack PC.zip
[2012.02.26 19:19:02 | 000,018,984 | ---- | C] () -- C:\Users\CART\Documents\Super Mario pack PC.zip.torrent
[2012.02.26 18:38:26 | 034,963,428 | ---- | C] () -- C:\Users\CART\Desktop\youtube.com.Anonymní zpráva vládcům světa. #GlobalREvolution 2012 [CZ SUB] - YouTube_6.flv
[2012.02.26 18:22:12 | 000,067,186 | ---- | C] () -- C:\Users\CART\Desktop\dddddd.jpg
[2012.02.26 18:01:59 | 007,739,592 | ---- | C] () -- C:\Users\CART\Desktop\Modified-Motion---1Up.mp3
[2012.02.26 16:36:14 | 000,088,667 | ---- | C] () -- C:\Users\CART\Desktop\430970_2257758222812_1814086776_1343916_2025360729_n.jpg
[2012.02.26 09:17:51 | 000,000,044 | ---- | C] () -- C:\Users\CART\Desktop\Track01.cda
[2012.02.26 08:27:14 | 000,000,770 | ---- | C] () -- C:\Users\CART\Desktop\Mp3 Audio Editor.lnk
[2012.02.26 08:27:13 | 000,113,486 | ---- | C] () -- C:\Windows\SysWow64\NCTWMAProfiles.prx
[2012.02.26 06:57:43 | 000,001,273 | ---- | C] () -- C:\Users\Public\Desktop\Free MP3 Cutter and Editor.lnk
[2012.02.26 06:52:49 | 000,054,156 | -H-- | C] () -- C:\Windows\QTFont.qfn
[2012.02.26 06:52:49 | 000,001,409 | ---- | C] () -- C:\Windows\QTFont.for
[2012.02.26 06:52:32 | 000,001,205 | ---- | C] () -- C:\Users\CART\Desktop\Traktor DJ Studio 3.lnk
[2012.02.26 06:09:38 | 000,025,734 | ---- | C] () -- C:\BarStyle.dat
[2012.02.26 06:08:44 | 000,000,013 | ---- | C] () -- C:\Windows\SysWow64\WINSPOOL.CRC
[2012.02.26 06:07:52 | 000,001,042 | ---- | C] () -- C:\Users\CART\Desktop\Power Mp3 Editor 2004.lnk
[2012.02.26 01:51:59 | 000,000,639 | ---- | C] () -- C:\Users\CART\Desktop\KMPlayer.lnk
[2012.02.26 01:23:30 | 000,000,517 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012.02.18 05:17:54 | 000,001,160 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity 1.3 Beta (Unicode).lnk
[2012.02.18 05:17:54 | 000,001,148 | ---- | C] () -- C:\Users\CART\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2012.02.12 04:58:26 | 000,000,779 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EuroGrand Casino.lnk
[2012.02.12 04:58:26 | 000,000,767 | ---- | C] () -- C:\Users\Public\Desktop\EuroGrand Casino.lnk
[2011.12.17 21:45:40 | 000,007,597 | ---- | C] () -- C:\Users\CART\AppData\Local\Resmon.ResmonCfg
[2011.12.09 01:30:47 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2011.10.26 20:20:00 | 000,000,348 | ---- | C] () -- C:\Windows\level.ini
[2011.10.26 20:20:00 | 000,000,075 | ---- | C] () -- C:\Windows\tmp2Level.ini
[2011.10.07 04:32:07 | 000,000,048 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.09.24 00:42:14 | 000,011,098 | ---- | C] () -- C:\Users\CART\AppData\Roaming\TheHunterSettings_live.bin
[2011.06.01 13:38:14 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini
[2011.05.08 15:15:23 | 000,003,584 | ---- | C] () -- C:\Users\CART\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.06 11:01:28 | 000,000,092 | ---- | C] () -- C:\Users\CART\AppData\Local\fusioncache.dat
[2011.03.05 23:31:23 | 000,669,184 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011.01.30 23:28:15 | 000,050,624 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011.01.05 16:59:16 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.01.05 16:59:13 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.01.04 19:06:01 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2010.12.30 22:41:02 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010.12.30 22:41:02 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2010.12.30 22:41:02 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2010.10.28 22:24:50 | 000,000,761 | ---- | C] () -- C:\Windows\m3jp2k.ini
[2010.10.28 22:24:50 | 000,000,714 | ---- | C] () -- C:\Windows\m3jpeg.ini
[2010.10.28 22:24:50 | 000,000,702 | ---- | C] () -- C:\Windows\mmtvmj.ini
[2010.10.28 22:24:48 | 000,019,968 | ---- | C] () -- C:\Windows\SysWow64\cpuinf32.dll
[2010.10.28 22:24:47 | 000,152,064 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2010.10.28 22:24:46 | 000,761,856 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010.10.28 21:52:46 | 000,000,055 | ---- | C] () -- C:\Windows\videotoaudio.ini
[2010.10.28 21:39:50 | 000,000,005 | ---- | C] () -- C:\Windows\SysWow64\SySatm.dat
[2010.10.21 00:40:26 | 001,634,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.12 19:09:54 | 000,000,025 | ---- | C] () -- C:\Windows\cdplayer.ini
[2010.10.12 12:43:48 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2010.10.02 17:42:31 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.06.25 18:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2010.06.15 23:28:54 | 000,002,857 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010.04.10 12:42:34 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\msrtcao-d.dll
========== LOP Check ==========
[2012.01.18 21:08:50 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\.minecraft
[2012.02.18 05:28:27 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Audacity
[2011.10.06 22:47:21 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\AVG
[2010.12.03 00:44:44 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Bioshock
[2011.06.25 18:56:20 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Bioshock2
[2010.10.15 19:20:42 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\bizarre creations
[2010.10.15 22:07:32 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\BlackBean
[2011.06.04 21:48:01 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2011.06.02 12:34:04 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Command and Conquer 4
[2012.02.26 21:11:22 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\DAEMON Tools Lite
[2011.05.05 17:40:55 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Digiarty
[2010.10.02 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\ESET
[2011.10.14 01:33:05 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Genie-Soft
[2011.11.24 12:26:07 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\GetRightToGo
[2011.03.12 15:50:08 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\GHISLER
[2011.07.18 22:06:29 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\gnupg
[2010.10.14 09:21:15 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\KWorld Multimedia
[2010.11.12 12:53:40 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Leawo
[2012.03.03 15:54:33 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Maxthon3
[2011.06.20 00:34:08 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Mirillis
[2012.02.26 08:23:07 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Moyea
[2012.02.26 15:14:06 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Mp3 Audio Editor
[2010.11.28 23:49:26 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Opera
[2011.06.25 15:13:27 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\ProtectDISC
[2011.05.28 22:00:54 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Red Alert 3
[2011.03.12 16:17:12 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Sierra Entertainment
[2011.06.07 22:32:51 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Simnet
[2011.10.05 01:20:25 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Sondle Soft
[2012.02.26 07:04:38 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\systweak
[2011.03.26 09:32:03 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\The Creative Assembly
[2010.10.27 22:01:39 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Thunderbird
[2010.10.20 00:44:38 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\URSoft
[2012.03.03 16:31:22 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\uTorrent
[2012.01.15 20:54:39 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\wargaming.net
[2012.03.03 04:32:56 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\XnView
[2012.03.03 02:20:24 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Zoner
[2011.10.18 21:19:20 | 000,032,524 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
< MD5 for: AGP440.SYS >
[2009.07.14 03:38:05 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\$WINDOWS.~BT\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:38:05 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:38:05 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\$WINDOWS.~BT\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2009.07.14 03:38:05 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\$WINDOWS.~BT\Windows\System32\drivers\atapi.sys
[2009.07.14 03:38:05 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:38:05 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\$WINDOWS.~BT\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\$WINDOWS.~BT\Windows\System32\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2009.07.14 03:38:05 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\$WINDOWS.~BT\Windows\System32\drivers\cdrom.sys
[2009.07.14 03:38:05 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_db87d184bc84f910\cdrom.sys
[2009.07.14 03:38:05 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_5f7fb206051affbb\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\$WINDOWS.~BT\Windows\System32\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2010.11.20 14:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\SysNative\cryptsvc.dll
[2010.11.20 14:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2009.07.14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_d1f48b0bb4805490\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\$WINDOWS.~BT\Windows\System32\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
[2010.11.20 13:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\SysWOW64\cryptsvc.dll
[2010.11.20 13:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\$WINDOWS.~BT\Windows\System32\hal.dll
[2009.07.14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_aaff48c7bafdccc6\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: IASTORV.SYS >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2009.07.14 03:38:05 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\$WINDOWS.~BT\Windows\System32\drivers\iaStorV.sys
[2009.07.14 03:38:05 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:38:05 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2009.07.14 03:38:05 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\$WINDOWS.~BT\Windows\System32\drivers\isapnp.sys
[2009.07.14 03:38:05 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\isapnp.sys
[2009.07.14 03:38:05 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys
< MD5 for: LSASS.EXE >
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_023e7e05767d22ad\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_02bd4ae48fa2de68\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
[2011.11.17 07:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
[2011.11.17 08:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=156F6159457D0AA7E59B62681B56EB90 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16915_none_028b374176436a30\lsass.exe
[2011.11.17 07:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
[2011.11.17 07:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
[2011.11.17 07:42:52 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=D21BD47E528CD62E79311FB5DF0150E6 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21092_none_02bb2a0a8fa4d398\lsass.exe
[2009.07.14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\$WINDOWS.~BT\Windows\System32\lsass.exe
[2009.07.14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_a620e0e5be1ecda7\lsass.exe
< MD5 for: NDIS.SYS >
[2009.07.14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\$WINDOWS.~BT\Windows\System32\drivers\ndis.sys
[2009.07.14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_a79d81ea7d62a289\ndis.sys
[2010.11.20 14:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\SysNative\drivers\ndis.sys
[2010.11.20 14:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
[2009.07.14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\$WINDOWS.~BT\Windows\System32\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVRAID.SYS >
[2011.03.11 07:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011.03.11 07:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011.03.11 07:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
[2009.07.14 03:38:05 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\$WINDOWS.~BT\Windows\System32\drivers\nvraid.sys
[2009.07.14 03:38:05 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvraid.sys
[2009.07.14 03:38:05 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\$WINDOWS.~BT\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvraid.sys
[2010.11.20 14:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.20 14:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011.03.11 07:19:21 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
[2011.03.11 07:23:06 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvraid.sys
[2011.03.11 07:25:53 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A5C82EB2F72AA004887F90B84A771F73 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2009.07.14 03:38:05 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\$WINDOWS.~BT\Windows\System32\drivers\nvstor.sys
[2009.07.14 03:38:05 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\$WINDOWS.~BT\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:38:05 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\$WINDOWS.~BT\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\$WINDOWS.~BT\Windows\System32\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\$WINDOWS.~BT\Windows\System32\smss.exe
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\$WINDOWS.~BT\Windows\System32\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2011.04.25 06:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
[2009.07.14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\$WINDOWS.~BT\Windows\System32\drivers\tcpip.sys
[2009.07.14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_b2f46875c7b9d667\tcpip.sys
[2011.09.29 18:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011.06.21 07:16:55 | 001,888,128 | ---- | M] (Microsoft Corporation) MD5=5279D4DD69C7C71524B8E7A5746D15CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_0f8ed978993fa916\tcpip.sys
[2010.06.14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2011.04.25 06:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2011.04.25 06:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2011.06.21 07:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
[2011.09.29 17:17:51 | 001,886,064 | ---- | M] (Microsoft Corporation) MD5=AC3E29880DB5659532A1AA3439304A43 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_0fad20ca992955d7\tcpip.sys
[2011.04.25 07:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.06.21 07:27:14 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=B9D87C7707F058AC652A398CD28DE14B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_0f4d1e3b7feb1307\tcpip.sys
[2011.06.21 07:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
[2011.09.29 17:24:44 | 001,897,328 | ---- | M] (Microsoft Corporation) MD5=F18F56EFC0BFB9C87BA01C37B27F4DA5 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_0f170e9f80139ebc\tcpip.sys
[2011.09.29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\SysNative\drivers\tcpip.sys
[2011.09.29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\$WINDOWS.~BT\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\$WINDOWS.~BT\Windows\System32\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WS2_32.DLL >
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\$WINDOWS.~BT\Windows\System32\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\$WINDOWS.~BT\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[9 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.01.18 21:08:50 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\.minecraft
[2010.12.25 12:17:40 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Adobe
[2010.10.03 18:00:06 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\ATI
[2012.02.18 05:28:27 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Audacity
[2011.10.06 22:47:21 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\AVG
[2011.02.20 15:57:40 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\AVS4YOU
[2010.12.03 00:44:44 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Bioshock
[2011.06.25 18:56:20 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Bioshock2
[2010.10.15 19:20:42 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\bizarre creations
[2010.10.15 22:07:32 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\BlackBean
[2011.06.04 21:48:01 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2011.06.02 12:34:04 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Command and Conquer 4
[2010.10.14 09:27:48 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\CyberLink
[2012.02.26 21:11:22 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\DAEMON Tools Lite
[2011.05.05 17:40:55 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Digiarty
[2011.03.14 07:20:22 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\dvdcss
[2010.10.02 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\ESET
[2011.10.14 01:33:05 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Genie-Soft
[2011.11.24 12:26:07 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\GetRightToGo
[2011.03.12 15:50:08 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\GHISLER
[2011.07.18 22:06:29 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\gnupg
[2010.10.06 19:44:48 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Hamachi
[2010.10.02 17:56:53 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Identities
[2011.11.17 23:24:38 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\InstallShield
[2010.10.14 09:21:15 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\KWorld Multimedia
[2010.11.12 12:53:40 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Leawo
[2010.10.02 18:44:45 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Macromedia
[2010.10.27 21:47:03 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Malwarebytes
[2012.03.03 15:54:33 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Maxthon3
[2009.07.14 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Media Center Programs
[2011.10.14 01:20:06 | 000,000,000 | --SD | M] -- C:\Users\CART\AppData\Roaming\Microsoft
[2011.06.20 00:34:08 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Mirillis
[2012.02.26 08:23:07 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Moyea
[2012.02.12 05:19:52 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Mozilla
[2012.02.26 15:14:06 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Mp3 Audio Editor
[2011.01.30 21:14:02 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\NCH Software
[2010.10.17 00:12:54 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Nero
[2010.11.28 23:49:26 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Opera
[2011.06.25 15:13:27 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\ProtectDISC
[2011.05.13 18:49:35 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Real
[2011.05.28 22:00:54 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Red Alert 3
[2011.01.20 23:17:47 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\SecuROM
[2011.03.12 16:17:12 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Sierra Entertainment
[2011.06.07 22:32:51 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Simnet
[2012.02.26 07:13:28 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Skype
[2011.12.23 19:05:13 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\skypePM
[2011.10.05 01:20:25 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Sondle Soft
[2012.02.26 07:04:38 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\systweak
[2011.03.26 09:32:03 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\The Creative Assembly
[2010.10.27 22:01:39 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Thunderbird
[2010.10.20 00:44:38 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\URSoft
[2012.03.03 16:31:22 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\uTorrent
[2011.10.29 18:58:27 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\vlc
[2012.01.15 20:54:39 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\wargaming.net
[2010.10.02 23:09:49 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\WinRAR
[2012.03.03 04:32:56 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\XnView
[2012.03.03 02:20:24 | 000,000,000 | ---D | M] -- C:\Users\CART\AppData\Roaming\Zoner
< %APPDATA%\*.exe /s >
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_1E02B3D8732010A792DC8B.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_21F3885A18D238E15AAE81.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_415493353D745EEA216D94.exe
[2011.06.20 00:33:38 | 000,009,662 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_57171CA7761BF4A88F7E34.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_6FEFF9B68218417F98F549.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_806048DC66200FE6D24FF3.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_85972F4A73DF7EADFBAFC2.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_934312A2105DE40686D86A.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_A5279446A5A2E345996804.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_A753214149FB4F8721C1CB.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_A7A1F24988209FFD6FF84A.exe
[2011.06.20 00:33:39 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_BD3CC5E8F02CE8257CF964.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_C7D4D81C64CE2B2A005D42.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_C7EFEC170C2E3BE8B9D183.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_CF15DB293FB3ABD44856FB.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_D707CE1C009F1381803C2C.exe
[2011.06.20 00:33:38 | 000,287,934 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3BED8560-ED90-40AD-8023-60B92B98AE29}\_FD8B6BA922FF5C34868F02.exe
[2011.01.30 20:42:01 | 000,069,944 | R--- | M] (Macrovision Corporation) -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{3D587291-A4D7-4D0B-AB47-F322D24402D8}\New_Shortcut_S1418_E404E3F7ABAD4D71949F30D2A9D5566C.exe
[2011.01.01 02:04:28 | 000,010,134 | R--- | M] () -- C:\Users\CART\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2007.08.29 15:36:00 | 000,110,592 | ---- | M] () -- C:\Users\CART\AppData\Roaming\NCH Software\Components\mp3el\mp3enc.exe
[2007.11.27 08:41:32 | 000,405,504 | ---- | M] () -- C:\Users\CART\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.03.01 20:59:05 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\FlashPlayerCPLApp.cpl
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.20 14:25:17 | 001,475,584 | ---- | M] (Microsoft Corporation)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.03.03 17:16:16 | 000,000,512 | ---- | M] () MD5=AF21D813AD2D7DA624AF7548D9E46A0B -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2006.04.24 09:22:14 | 006,638,616 | R--- | M] () -- \hry files\Euro\Radio\Radio Bot\Fix the Cracks - Humanzi.mp3
[2012.02.26 19:29:24 | 000,001,406 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.crackfound.com%2Ffavicon.ico
[2012.02.26 19:30:06 | 000,001,150 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.crackserialcodes.com%2Ffavicon.ico
[2012.02.26 19:28:41 | 000,001,150 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.crackserialkeygen.com%2Ffavicon.ico
[2012.02.26 19:29:24 | 000,000,113 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\
www.crackfound.com.idx
[2012.02.26 19:30:06 | 000,000,148 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\
www.crackserialcodes.com.idx
[2012.02.26 19:28:41 | 000,000,102 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\
www.crackserialkeygen.com.idx
[2012.02.26 08:24:59 | 000,000,802 | ---- | M] () -- \Users\CART\AppData\Roaming\Microsoft\Windows\Recent\Mp3.Audio.Editor.v7.3.1+%2B+Crack.lnk
[2011.10.05 02:23:00 | 000,000,354 | ---- | M] () -- \Users\CART\AppData\Roaming\uTorrent\E-mail Password Cracker 2010 V1.0.rar.torrent
[2011.09.20 16:43:09 | 000,041,743 | ---- | M] () -- \Users\CART\AppData\Roaming\uTorrent\Red Orchestra 2 Heroes Of Stalingrad STEAM CRACKED-3DM.torrent
[2010.10.21 00:54:28 | 005,209,629 | ---- | M] () -- \Users\CART\Desktop\B.A.T.D\Nová složka (2)\Crack GTA IV Razor 1911.rar
[2010.10.21 00:57:46 | 037,751,764 | ---- | M] () -- \Users\CART\Desktop\B.A.T.D\Nová složka (2)\GTA IV patch 1.0.2.0 + NO - CD Crack (Razor 1911).zip
[2010.01.24 07:45:48 | 000,000,706 | ---- | M] () -- \Users\CART\Desktop\COH\company iof heroes\Company of Heroes\Eastern_Front\Data\sound\weapons\ppsh41\ppsh41_whipcrack.bsc
[2010.01.24 07:45:48 | 000,000,706 | ---- | M] () -- \Users\CART\Desktop\COH\company iof heroes\Eastern_Front\Data\sound\weapons\ppsh41\ppsh41_whipcrack.bsc
[2011.06.25 15:13:00 | 000,881,609 | ---- | M] () -- \Users\CART\Desktop\cracks\air crack.7z
[2010.10.31 16:41:13 | 008,472,483 | ---- | M] () -- \Users\CART\Desktop\MP3 SLOZKY VSE\TOP DNB\Brookes Brothers Crackdown (Shock One Remix).mp3
[2012.02.26 08:24:59 | 014,320,851 | ---- | M] () -- \Users\CART\Desktop\UMB.REW\Mp3.Audio.Editor.v7.3.1+%2B+Crack.rar
[2012.02.26 04:58:05 | 006,416,228 | ---- | M] () -- \Users\CART\Desktop\UMB.REW\Power-Mp3-Editor-Deluxe-Pro-2004---digital-audio-editor+CRACK.zip
[2004.05.06 18:46:36 | 000,001,002 | ---- | M] () -- \Users\CART\Desktop\UMB.REW\Power-Mp3-Editor-Deluxe-Pro-2004---digital-audio-editor+CRACK\Power Mp3 Editor Deluxe Pro 2004 CRACK.rar
[2012.03.01 21:09:30 | 000,315,178 | ---- | M] () -- \Users\CART\Downloads\Adobe Photoshop CS5 CZ\Crack\ADBE_CRACK - 32bit.rar
[2012.03.01 21:09:15 | 000,377,747 | ---- | M] () -- \Users\CART\Downloads\Adobe Photoshop CS5 CZ\Crack\ADBE_CRACK - 64bit.rar
[2011.09.20 17:37:14 | 000,002,799 | ---- | M] () -- \Users\CART\Downloads\Red Orchestra 2 Heroes Of Stalingrad STEAM CRACKED-3DM\Red Orchestra 2 Heroes Of Stalingrad STEAM CRACKED-3DM.txt
[2011.09.14 05:32:25 | 005,021,038 | ---- | M] () -- \Users\CART\Downloads\Red Orchestra 2 Heroes Of Stalingrad STEAM CRACKED-3DM\red\Red Orchestra 2 Heroes Of Stalingrad STEAM CRACKED-3DM\Crack.rar
< *keygen* /s >
[2012.02.26 19:26:07 | 000,000,318 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fkeygens.nl%2Ffavicon.ico
[2012.02.26 19:28:41 | 000,001,150 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.crackserialkeygen.com%2Ffavicon.ico
[2012.02.26 19:26:07 | 000,000,070 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\keygens.nl.idx
[2012.02.26 19:28:41 | 000,000,102 | ---- | M] () -- \Users\CART\AppData\Local\Opera\Opera\icons\
www.crackserialkeygen.com.idx
[2000.10.30 08:32:48 | 000,025,088 | ---- | M] () -- \Users\CART\Desktop\hry\red-alert2-portable-jonathan-pack\redalert2_portable\redalert2_portable\redalert2_portable\Keygen.exe
[2000.11.01 02:13:38 | 000,002,293 | ---- | M] () -- \Users\CART\Desktop\hry\red-alert2-portable-jonathan-pack\redalert2_portable\redalert2_portable\redalert2_portable\keygen.nfo
[2012.03.01 21:09:31 | 000,063,365 | ---- | M] () -- \Users\CART\Downloads\Adobe Photoshop CS5 CZ\Crack\adobe_PS_CS5_keygen.exe
[2012.03.01 21:09:31 | 000,003,121 | ---- | M] () -- \Users\CART\Downloads\Adobe Photoshop CS5 CZ\Crack\KeyGen-Readme.txt