Re: Prosím o kontrolu logu
Napsal: 11 lis 2012 23:47
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.08.15 19:57:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\8floor
[2012.01.11 16:06:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Adobe
[2009.12.27 13:32:49 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Ahead
[2012.03.08 17:51:01 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Alawar
[2011.11.26 17:08:53 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\AlawarSouthpoint
[2011.07.01 18:54:45 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\AlderGames
[2011.03.25 20:10:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\aliasworlds
[2011.07.05 13:15:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Anarchy
[2010.12.14 09:18:15 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Awem
[2011.03.04 13:54:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BeachPartyCraze
[2010.11.13 18:43:02 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BlackBean
[2012.02.24 16:01:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BlamGames
[2011.06.01 08:08:17 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Boolat Games
[2011.08.20 13:33:03 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Camel101
[2011.05.09 07:51:44 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\CasualForge
[2010.02.01 21:54:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DAEMON Tools Lite
[2011.10.30 17:30:37 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Divo Games
[2010.07.07 08:48:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DivX
[2012.02.22 19:39:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DreamDale
[2012.02.21 22:16:08 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\EleFun Games
[2011.01.06 19:20:13 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\FairyNook
[2011.03.22 10:06:51 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Farm Mania 2.1
[2012.05.06 09:33:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\FreezeTag
[2012.03.19 17:13:54 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Friday's games
[2012.01.18 12:44:08 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Gamelab
[2010.01.28 16:13:16 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Google
[2012.04.03 20:15:24 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\HdO Adventure
[2012.07.06 17:23:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Home Sweet Home Christmas
[2012.10.29 14:21:21 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ICQ
[2010.12.22 14:08:05 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ICQ Toolbar
[2009.12.01 17:19:19 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Identities
[2012.02.16 14:44:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\iMaxGen
[2012.03.30 10:19:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\InImages
[2009.12.01 18:29:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\InstallShield
[2011.12.10 20:54:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\iWinG
[2011.09.19 15:27:32 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Land Of Runes
[2009.12.02 17:33:48 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Leadertech
[2012.05.17 10:15:47 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Lonely Troops
[2010.01.02 17:31:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Macromedia
[2011.02.14 16:42:16 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\MAI
[2012.02.22 19:28:36 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\MB3
[2006.11.02 13:35:50 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Media Center Programs
[2011.03.15 22:14:17 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Media Get LLC
[2012.02.23 21:22:20 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Meridian93
[2012.02.23 17:04:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Merscom
[2012.09.03 20:34:51 | 000,000,000 | --SD | M] -- C:\Users\Fanda\AppData\Roaming\Microsoft
[2012.01.25 14:45:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Mount&Blade
[2010.02.02 19:06:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Mozilla
[2011.03.22 18:59:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\NevoSoft Games
[2010.01.05 22:08:28 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Nokia
[2012.09.29 12:12:45 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Origin
[2010.01.05 21:57:36 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PC Suite
[2012.04.27 22:23:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PeerNetworking
[2012.02.21 20:38:46 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PetShowCraze
[2011.01.05 17:18:32 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PlayFirst
[2012.04.10 20:37:11 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PoBros
[2012.08.23 08:22:20 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Registry Mechanic
[2010.01.30 15:50:47 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Sahmon Games
[2010.10.26 17:16:15 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Samsung
[2012.04.04 20:34:21 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ScreenSeven
[2011.12.13 16:17:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Settlement. Colossus
[2010.10.21 16:44:19 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Silver Style Entertainment
[2012.11.10 22:55:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Skype
[2012.07.07 07:50:41 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\skypePM
[2011.07.05 09:15:04 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Smarty Uninstaller
[2012.02.22 19:20:52 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SmashFrenzy3
[2012.01.14 18:09:11 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SpinTop
[2012.08.26 13:18:34 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SprillRichiEng
[2011.05.12 19:13:24 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Thinstall
[2012.11.03 08:41:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\TuneUp Software
[2010.01.14 21:08:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\TwoWorldsCP
[2010.12.23 18:13:51 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\UClick
[2012.07.08 14:55:41 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Unity
[2011.02.09 12:45:29 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\URSE Games
[2012.03.06 12:58:54 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\V-Games
[2010.02.24 21:10:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\VitySoft
[2010.08.02 20:30:30 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\vlc
[2012.03.14 09:04:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\wargaming.net
[2010.06.02 20:54:22 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\WinRAR
[2012.02.21 16:38:39 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\World-Loom
[2011.02.25 16:22:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\YoudaGames
< %APPDATA%\*.exe /s >
[2008.06.12 11:09:06 | 000,033,088 | ---- | M] () -- C:\Users\Fanda\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.02.10 12:08:57 | 001,956,072 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Fanda\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2010.01.14 21:08:35 | 000,165,888 | R--- | M] () -- C:\Users\Fanda\AppData\Roaming\Microsoft\Installer\{6EEEF30E-0AD2-4AD9-B854-22F1488637C7}\IconC202CEA6.exe
[2009.12.09 15:54:18 | 000,010,134 | R--- | M] () -- C:\Users\Fanda\AppData\Roaming\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
[2011.06.28 06:32:22 | 081,122,288 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\Fanda\AppData\Roaming\Microsoft\Windows\Templates\SamsungKiesSetup.exe
[2011.01.27 14:43:34 | 000,266,552 | ---- | M] (ml) -- C:\Users\Fanda\AppData\Roaming\Samsung\Kies\UpdateTemp\MCS.Thunder.Update.exe
[2011.05.12 19:13:33 | 000,007,168 | ---- | M] () -- C:\Users\Fanda\AppData\Roaming\Thinstall\ATV Mudracer\1000000800002i\svchost.exe
< %systemroot%\*. /mp /s >
ft Cor< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2012.11.11 22:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.11.11 03:05:04 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.11.11 23:06:01 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.11.10 21:09:34 | 000,000,434 | ---- | M] () -- C:\Windows\Tasks\RegPowerClean.job
[2012.11.10 21:06:06 | 000,000,420 | ---- | M] () -- C:\Windows\Tasks\RPCReminder.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009.04.11 15:14:01 | 025,030,656 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2009.04.11 15:13:38 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2009.04.11 15:14:01 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.11.11 22:58:27 | 000,003,888 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.11 22:58:27 | 000,003,888 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.09 20:40:07 | 000,002,577 | ---- | M] () -- C:\Windows\system32\config.nt
[2012.11.10 21:12:30 | 000,116,036 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2012.11.10 21:12:30 | 000,102,126 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2012.11.10 21:12:30 | 000,603,524 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2012.11.10 21:12:30 | 000,591,854 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2012.11.10 21:12:30 | 001,405,522 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009.04.11 14:19:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [2007.06.27 19:03:40 | 000,152,872 | ---- | M] (Nero AG)
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008.01.21 03:23:22 | 000,125,952 | ---- | M] (Microsoporation)
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008.01.21 03:23:48 | 000,202,240 | ---- | M] (Microsoft Corporation)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.08.24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2012.10.31 23:15:08 | 001,242,136 | ---- | M] (Google Inc.) MD5=D8510C2D48496B6C336E816FD67AA0F7 -- C:\Program Files\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.11.11 23:03:38 | 000,000,512 | ---- | M] () MD5=93896BD09457283BFCDF58EF51EC84BF -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2010.01.04 15:11:21 | 000,021,316 | ---- | M] () -- \Users\Fanda\Music\telefon\ZVUKY na mobil\MP3 Zvonění\Fireworks - Cracker - [MaxT.dk].mp3
< *keygen* /s >
< *loader* /s >
[2012.06.13 07:04:09 | 001,581,712 | ---- | M] () -- \Casino\William Hill CASINO CLUB\data\loader.dll
[2012.06.13 07:04:05 | 000,007,003 | ---- | M] () -- \Casino\William Hill CASINO CLUB\data\loader.gam
[2012.03.09 17:02:06 | 000,071,208 | ---- | M] () -- \Games\World_of_Tanks\PhysXLoader.dll
[2012.06.15 10:10:23 | 000,005,679 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\tutorial\TutorialLoader.pyc
[2007.06.27 19:03:00 | 000,177,448 | ---- | M] () -- \Program Files\Common Files\Ahead\Lib\NeGuideStoreLoader.dll
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2003.04.11 14:45:42 | 000,348,160 | ---- | M] () -- \Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
[2012.03.16 07:51:36 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2012.03.16 07:51:38 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2012.03.16 07:51:36 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\MUICoreLib\xtraLoader.swf
[2012.04.23 19:34:31 | 000,002,886 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\babylon_feed\preloader01_b.swf
[2012.03.16 07:52:16 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\profile_lightboxs\preloader.html
[2012.04.23 19:59:08 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\rps\preloader02.swf
[2012.04.23 19:26:19 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\slide-a-lama\preloader02.swf
[2012.04.23 19:16:08 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\zoopaloola\preloader02.swf
[2005.09.19 10:30:30 | 000,001,825 | R--- | M] () -- \Program Files\Microsoft Games\Age of Empires III\AI\aiLoaderInactive.xs
[2005.09.19 10:30:30 | 000,001,575 | R--- | M] () -- \Program Files\Microsoft Games\Age of Empires III\AI\aiLoaderStandard.xs
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\fasttabs.loader.gif
[19 \Program Files\MyPlayCity Toolbar\*.tmp files -> \Program Files\MyPlayCity Toolbar\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsk4140.tmp\fasttabs.loader.gif
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunswA65E.tmp\fasttabs.loader.gif
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\*.tmp -> ]
[2011.11.28 06:16:14 | 001,763,968 | ---- | M] () -- \Program Files\MyPlayCity.com\Farm Frenzy 2\PreLoader.exe
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \Program Files\The KMPlayer\ImLoader.dll
[2010.02.10 17:10:14 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.02.23 21:01:06 | 000,000,060 | ---- | M] () -- \Users\Fanda\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LFGFNBGJ\miniclip.com\games\masters-of-wrestling\en\master_of_wrestling.dcr\MiniclipLoaderAd.sol
[2011.09.08 05:36:40 | 000,002,608 | ---- | M] () -- \Users\Fanda\AppData\Roaming\Mozilla\Firefox\Profiles\kb7nk5ms.default\extensions\{A9897564-CA29-4CAE-8A26-453035570837}\chrome\content\id_toolbar\fasttabs.loader.gif
[2012.07.20 18:11:49 | 002,330,728 | ---- | M] () -- \Users\Fanda\Downloads\ArmyRage_downloader.exe
[2012.05.11 11:49:27 | 002,286,152 | ---- | M] () -- \Users\Fanda\Downloads\STOnline_US_20120502downloader.exe
[2 \Users\Fanda\Downloads\*.tmp files -> \Users\Fanda\Downloads\*.tmp -> ]
[2011.09.12 12:59:25 | 000,446,464 | ---- | M] () -- \Windows\NEXON_EU_DownloaderUpdater.exe
[1 \Windows\*.tmp files -> \Windows\*.tmp -> ]
[2009.12.01 19:17:19 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2010.11.13 18:40:25 | 000,000,000 | ---- | M] () -- \Windows\assembly\NativeImages1_v2.0.50727\GameSpy.Downloader\1.0.3764.32208__9a2037864b640668_28aa6efe\GameSpy.Downloader.exe_
[2008.01.21 03:21:45 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2006.09.06 05:42:06 | 000,053,248 | ---- | M] () -- \Windows\System32\PhysXLoader.dll
[2012.02.02 14:15:04 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2012.02.02 14:31:52 | 000,009,622 | ---- | M] () -- \Windows\System32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
[2009.05.08 18:17:00 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2009.05.08 18:17:00 | 000,027,648 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winload.exe.mui_3bc5b827
[2009.05.08 18:17:00 | 000,019,968 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winresume.exe.mui_ff8b5358
[2008.01.21 03:25:08 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673.manifest
[2008.01.21 03:25:08 | 000,026,112 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673_winload.exe.mui_3bc5b827
[2008.01.21 03:25:08 | 000,019,456 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673_winresume.exe.mui_ff8b5358
[2009.04.11 14:20:55 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2009.04.11 14:20:55 | 000,986,600 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winload.exe_75835076
[2009.04.11 14:20:55 | 000,926,184 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winresume.exe_85cd1215
[2008.01.21 03:25:02 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2008.01.21 03:25:02 | 000,021,048 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2_spldr.sys_98bd87a0
[2008.01.21 03:07:05 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_de-de_cbcaa800f7f71dcc.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_en-us_74bb7df9e6d52991.manifest
[2008.01.21 03:07:07 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_es-es_7486dadde6fc1b36.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_fr-fr_173e50dcd9ce3198.manifest
[2008.01.21 03:07:11 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_it-it_01664723b1001716.manifest
[2008.01.21 03:07:13 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_ja-jp_a38bc630a41b28f1.manifest
[2008.01.21 03:07:16 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_nl-nl_2dc76f586fdd2598.manifest
[2008.01.21 03:07:05 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_de-de_cc2ed396113192b6.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_en-us_751fa98f000f9e7b.manifest
[2008.01.21 03:07:07 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_es-es_74eb067300369020.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_fr-fr_17a27c71f308a682.manifest
[2008.01.21 03:07:11 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_it-it_01ca72b8ca3a8c00.manifest
[2008.01.21 03:07:13 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_ja-jp_a3eff1c5bd559ddb.manifest
[2008.01.21 03:07:16 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_nl-nl_2e2b9aed89179a82.manifest
[2009.05.08 18:03:51 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2008.01.21 03:19:47 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673.manifest
[2008.01.21 03:06:59 | 000,005,227 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.16609_none_59497e266f783366.manifest
[2008.01.21 03:06:59 | 000,005,227 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.20734_none_59ada9bb88b2a850.manifest
[2008.01.21 03:18:47 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18000_none_5b26ba326ca6e048.manifest
[2009.04.11 14:17:46 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2006.11.02 11:13:06 | 000,003,970 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6000.16386_none_68fc663d5430d3de.manifest
[2008.01.21 03:17:09 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2008.01.21 03:21:45 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6002.18005_none_47df94fd8cc49aa6\dmloader.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:DF462FF6
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.08.15 19:57:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\8floor
[2012.01.11 16:06:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Adobe
[2009.12.27 13:32:49 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Ahead
[2012.03.08 17:51:01 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Alawar
[2011.11.26 17:08:53 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\AlawarSouthpoint
[2011.07.01 18:54:45 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\AlderGames
[2011.03.25 20:10:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\aliasworlds
[2011.07.05 13:15:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Anarchy
[2010.12.14 09:18:15 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Awem
[2011.03.04 13:54:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BeachPartyCraze
[2010.11.13 18:43:02 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BlackBean
[2012.02.24 16:01:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\BlamGames
[2011.06.01 08:08:17 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Boolat Games
[2011.08.20 13:33:03 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Camel101
[2011.05.09 07:51:44 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\CasualForge
[2010.02.01 21:54:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DAEMON Tools Lite
[2011.10.30 17:30:37 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Divo Games
[2010.07.07 08:48:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DivX
[2012.02.22 19:39:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\DreamDale
[2012.02.21 22:16:08 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\EleFun Games
[2011.01.06 19:20:13 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\FairyNook
[2011.03.22 10:06:51 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Farm Mania 2.1
[2012.05.06 09:33:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\FreezeTag
[2012.03.19 17:13:54 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Friday's games
[2012.01.18 12:44:08 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Gamelab
[2010.01.28 16:13:16 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Google
[2012.04.03 20:15:24 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\HdO Adventure
[2012.07.06 17:23:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Home Sweet Home Christmas
[2012.10.29 14:21:21 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ICQ
[2010.12.22 14:08:05 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ICQ Toolbar
[2009.12.01 17:19:19 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Identities
[2012.02.16 14:44:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\iMaxGen
[2012.03.30 10:19:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\InImages
[2009.12.01 18:29:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\InstallShield
[2011.12.10 20:54:59 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\iWinG
[2011.09.19 15:27:32 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Land Of Runes
[2009.12.02 17:33:48 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Leadertech
[2012.05.17 10:15:47 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Lonely Troops
[2010.01.02 17:31:07 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Macromedia
[2011.02.14 16:42:16 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\MAI
[2012.02.22 19:28:36 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\MB3
[2006.11.02 13:35:50 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Media Center Programs
[2011.03.15 22:14:17 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Media Get LLC
[2012.02.23 21:22:20 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Meridian93
[2012.02.23 17:04:58 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Merscom
[2012.09.03 20:34:51 | 000,000,000 | --SD | M] -- C:\Users\Fanda\AppData\Roaming\Microsoft
[2012.01.25 14:45:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Mount&Blade
[2010.02.02 19:06:26 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Mozilla
[2011.03.22 18:59:35 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\NevoSoft Games
[2010.01.05 22:08:28 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Nokia
[2012.09.29 12:12:45 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Origin
[2010.01.05 21:57:36 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PC Suite
[2012.04.27 22:23:40 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PeerNetworking
[2012.02.21 20:38:46 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PetShowCraze
[2011.01.05 17:18:32 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PlayFirst
[2012.04.10 20:37:11 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\PoBros
[2012.08.23 08:22:20 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Registry Mechanic
[2010.01.30 15:50:47 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Sahmon Games
[2010.10.26 17:16:15 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Samsung
[2012.04.04 20:34:21 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\ScreenSeven
[2011.12.13 16:17:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Settlement. Colossus
[2010.10.21 16:44:19 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Silver Style Entertainment
[2012.11.10 22:55:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Skype
[2012.07.07 07:50:41 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\skypePM
[2011.07.05 09:15:04 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Smarty Uninstaller
[2012.02.22 19:20:52 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SmashFrenzy3
[2012.01.14 18:09:11 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SpinTop
[2012.08.26 13:18:34 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\SprillRichiEng
[2011.05.12 19:13:24 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Thinstall
[2012.11.03 08:41:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\TuneUp Software
[2010.01.14 21:08:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\TwoWorldsCP
[2010.12.23 18:13:51 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\UClick
[2012.07.08 14:55:41 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\Unity
[2011.02.09 12:45:29 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\URSE Games
[2012.03.06 12:58:54 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\V-Games
[2010.02.24 21:10:42 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\VitySoft
[2010.08.02 20:30:30 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\vlc
[2012.03.14 09:04:33 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\wargaming.net
[2010.06.02 20:54:22 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\WinRAR
[2012.02.21 16:38:39 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\World-Loom
[2011.02.25 16:22:31 | 000,000,000 | ---D | M] -- C:\Users\Fanda\AppData\Roaming\YoudaGames
< %APPDATA%\*.exe /s >
[2008.06.12 11:09:06 | 000,033,088 | ---- | M] () -- C:\Users\Fanda\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.02.10 12:08:57 | 001,956,072 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Fanda\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2010.01.14 21:08:35 | 000,165,888 | R--- | M] () -- C:\Users\Fanda\AppData\Roaming\Microsoft\Installer\{6EEEF30E-0AD2-4AD9-B854-22F1488637C7}\IconC202CEA6.exe
[2009.12.09 15:54:18 | 000,010,134 | R--- | M] () -- C:\Users\Fanda\AppData\Roaming\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
[2011.06.28 06:32:22 | 081,122,288 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\Fanda\AppData\Roaming\Microsoft\Windows\Templates\SamsungKiesSetup.exe
[2011.01.27 14:43:34 | 000,266,552 | ---- | M] (ml) -- C:\Users\Fanda\AppData\Roaming\Samsung\Kies\UpdateTemp\MCS.Thunder.Update.exe
[2011.05.12 19:13:33 | 000,007,168 | ---- | M] () -- C:\Users\Fanda\AppData\Roaming\Thinstall\ATV Mudracer\1000000800002i\svchost.exe
< %systemroot%\*. /mp /s >
ft Cor< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2012.11.11 22:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.11.11 03:05:04 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.11.11 23:06:01 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.11.10 21:09:34 | 000,000,434 | ---- | M] () -- C:\Windows\Tasks\RegPowerClean.job
[2012.11.10 21:06:06 | 000,000,420 | ---- | M] () -- C:\Windows\Tasks\RPCReminder.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009.04.11 15:14:01 | 025,030,656 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2009.04.11 15:13:38 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2009.04.11 15:14:01 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.11.11 22:58:27 | 000,003,888 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.11 22:58:27 | 000,003,888 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.09 20:40:07 | 000,002,577 | ---- | M] () -- C:\Windows\system32\config.nt
[2012.11.10 21:12:30 | 000,116,036 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2012.11.10 21:12:30 | 000,102,126 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2012.11.10 21:12:30 | 000,603,524 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2012.11.10 21:12:30 | 000,591,854 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2012.11.10 21:12:30 | 001,405,522 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009.04.11 14:19:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [2007.06.27 19:03:40 | 000,152,872 | ---- | M] (Nero AG)
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008.01.21 03:23:22 | 000,125,952 | ---- | M] (Microsoporation)
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008.01.21 03:23:48 | 000,202,240 | ---- | M] (Microsoft Corporation)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.08.24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2012.10.31 23:15:08 | 001,242,136 | ---- | M] (Google Inc.) MD5=D8510C2D48496B6C336E816FD67AA0F7 -- C:\Program Files\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.11.11 23:03:38 | 000,000,512 | ---- | M] () MD5=93896BD09457283BFCDF58EF51EC84BF -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2010.01.04 15:11:21 | 000,021,316 | ---- | M] () -- \Users\Fanda\Music\telefon\ZVUKY na mobil\MP3 Zvonění\Fireworks - Cracker - [MaxT.dk].mp3
< *keygen* /s >
< *loader* /s >
[2012.06.13 07:04:09 | 001,581,712 | ---- | M] () -- \Casino\William Hill CASINO CLUB\data\loader.dll
[2012.06.13 07:04:05 | 000,007,003 | ---- | M] () -- \Casino\William Hill CASINO CLUB\data\loader.gam
[2012.03.09 17:02:06 | 000,071,208 | ---- | M] () -- \Games\World_of_Tanks\PhysXLoader.dll
[2012.06.15 10:10:23 | 000,005,679 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\tutorial\TutorialLoader.pyc
[2007.06.27 19:03:00 | 000,177,448 | ---- | M] () -- \Program Files\Common Files\Ahead\Lib\NeGuideStoreLoader.dll
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2003.04.11 14:45:42 | 000,348,160 | ---- | M] () -- \Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
[2012.03.16 07:51:36 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2012.03.16 07:51:38 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2012.03.16 07:51:36 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\MUICoreLib\xtraLoader.swf
[2012.04.23 19:34:31 | 000,002,886 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\babylon_feed\preloader01_b.swf
[2012.03.16 07:52:16 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\profile_lightboxs\preloader.html
[2012.04.23 19:59:08 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\rps\preloader02.swf
[2012.04.23 19:26:19 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\slide-a-lama\preloader02.swf
[2012.04.23 19:16:08 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\zoopaloola\preloader02.swf
[2005.09.19 10:30:30 | 000,001,825 | R--- | M] () -- \Program Files\Microsoft Games\Age of Empires III\AI\aiLoaderInactive.xs
[2005.09.19 10:30:30 | 000,001,575 | R--- | M] () -- \Program Files\Microsoft Games\Age of Empires III\AI\aiLoaderStandard.xs
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\fasttabs.loader.gif
[19 \Program Files\MyPlayCity Toolbar\*.tmp files -> \Program Files\MyPlayCity Toolbar\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsa6E8A.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsc7410.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsdE595.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunseAE9A.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunseB824.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunshE407.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsi9B6C.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsj993.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsk4140.tmp\fasttabs.loader.gif
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsm2F6C.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsm9E.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsmCC76.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsq928.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunst9A93.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsw4888.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunswA65E.tmp\fasttabs.loader.gif
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsxD793.tmp\*.tmp -> ]
[2011.09.08 15:36:40 | 000,002,608 | ---- | M] () -- \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\fasttabs.loader.gif
[1 \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\*.tmp files -> \Program Files\MyPlayCity Toolbar\tbunsy5AF6.tmp\*.tmp -> ]
[2011.11.28 06:16:14 | 001,763,968 | ---- | M] () -- \Program Files\MyPlayCity.com\Farm Frenzy 2\PreLoader.exe
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \Program Files\The KMPlayer\ImLoader.dll
[2010.02.10 17:10:14 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.02.23 21:01:06 | 000,000,060 | ---- | M] () -- \Users\Fanda\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LFGFNBGJ\miniclip.com\games\masters-of-wrestling\en\master_of_wrestling.dcr\MiniclipLoaderAd.sol
[2011.09.08 05:36:40 | 000,002,608 | ---- | M] () -- \Users\Fanda\AppData\Roaming\Mozilla\Firefox\Profiles\kb7nk5ms.default\extensions\{A9897564-CA29-4CAE-8A26-453035570837}\chrome\content\id_toolbar\fasttabs.loader.gif
[2012.07.20 18:11:49 | 002,330,728 | ---- | M] () -- \Users\Fanda\Downloads\ArmyRage_downloader.exe
[2012.05.11 11:49:27 | 002,286,152 | ---- | M] () -- \Users\Fanda\Downloads\STOnline_US_20120502downloader.exe
[2 \Users\Fanda\Downloads\*.tmp files -> \Users\Fanda\Downloads\*.tmp -> ]
[2011.09.12 12:59:25 | 000,446,464 | ---- | M] () -- \Windows\NEXON_EU_DownloaderUpdater.exe
[1 \Windows\*.tmp files -> \Windows\*.tmp -> ]
[2009.12.01 19:17:19 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2010.11.13 18:40:25 | 000,000,000 | ---- | M] () -- \Windows\assembly\NativeImages1_v2.0.50727\GameSpy.Downloader\1.0.3764.32208__9a2037864b640668_28aa6efe\GameSpy.Downloader.exe_
[2008.01.21 03:21:45 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2006.09.06 05:42:06 | 000,053,248 | ---- | M] () -- \Windows\System32\PhysXLoader.dll
[2012.02.02 14:15:04 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2012.02.02 14:31:52 | 000,009,622 | ---- | M] () -- \Windows\System32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
[2009.05.08 18:17:00 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2009.05.08 18:17:00 | 000,027,648 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winload.exe.mui_3bc5b827
[2009.05.08 18:17:00 | 000,019,968 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winresume.exe.mui_ff8b5358
[2008.01.21 03:25:08 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673.manifest
[2008.01.21 03:25:08 | 000,026,112 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673_winload.exe.mui_3bc5b827
[2008.01.21 03:25:08 | 000,019,456 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673_winresume.exe.mui_ff8b5358
[2009.04.11 14:20:55 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2009.04.11 14:20:55 | 000,986,600 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winload.exe_75835076
[2009.04.11 14:20:55 | 000,926,184 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winresume.exe_85cd1215
[2008.01.21 03:25:02 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2008.01.21 03:25:02 | 000,021,048 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2_spldr.sys_98bd87a0
[2008.01.21 03:07:05 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_de-de_cbcaa800f7f71dcc.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_en-us_74bb7df9e6d52991.manifest
[2008.01.21 03:07:07 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_es-es_7486dadde6fc1b36.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_fr-fr_173e50dcd9ce3198.manifest
[2008.01.21 03:07:11 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_it-it_01664723b1001716.manifest
[2008.01.21 03:07:13 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_ja-jp_a38bc630a41b28f1.manifest
[2008.01.21 03:07:16 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16609_nl-nl_2dc76f586fdd2598.manifest
[2008.01.21 03:07:05 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_de-de_cc2ed396113192b6.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_en-us_751fa98f000f9e7b.manifest
[2008.01.21 03:07:07 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_es-es_74eb067300369020.manifest
[2008.01.21 03:07:01 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_fr-fr_17a27c71f308a682.manifest
[2008.01.21 03:07:11 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_it-it_01ca72b8ca3a8c00.manifest
[2008.01.21 03:07:13 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_ja-jp_a3eff1c5bd559ddb.manifest
[2008.01.21 03:07:16 | 000,003,726 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20734_nl-nl_2e2b9aed89179a82.manifest
[2009.05.08 18:03:51 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2008.01.21 03:19:47 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_7698ba05e403d673.manifest
[2008.01.21 03:06:59 | 000,005,227 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.16609_none_59497e266f783366.manifest
[2008.01.21 03:06:59 | 000,005,227 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.20734_none_59ada9bb88b2a850.manifest
[2008.01.21 03:18:47 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18000_none_5b26ba326ca6e048.manifest
[2009.04.11 14:17:46 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2006.11.02 11:13:06 | 000,003,970 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6000.16386_none_68fc663d5430d3de.manifest
[2008.01.21 03:17:09 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2008.01.21 03:21:45 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6002.18005_none_47df94fd8cc49aa6\dmloader.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:DF462FF6
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >