Re: Preventivna kontrola logu
Napsal: 25 zář 2013 19:51
========== Files - Modified Within 7 Days ==========
[2013.09.25 20:21:14 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.09.25 20:09:00 | 000,000,938 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 17:22:52 | 000,614,400 | ---- | M] () -- C:\Windows\AutoKMS.exe
[2013.09.25 17:22:52 | 000,000,204 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2013.09.25 17:22:52 | 000,000,135 | ---- | M] () -- C:\Windows\AutoKMS.ini
[2013.09.25 17:16:44 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.09.25 17:16:43 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.09.25 17:08:42 | 000,000,934 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.09.25 17:08:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.09.25 17:08:08 | 2106,478,591 | -HS- | M] () -- C:\hiberfil.sys
[2013.09.25 10:22:35 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForGrejtak.job
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.09.24 18:36:45 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.24 18:36:34 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.09.24 15:17:36 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.09.24 15:17:36 | 000,653,724 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.09.24 15:17:36 | 000,121,596 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.09.24 02:38:00 | 002,094,844 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1207020.003\Cat.DB
[2013.09.24 02:34:51 | 000,765,700 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.09.23 23:20:46 | 000,000,073 | ---- | M] () -- C:\Windows\wininit.ini
[2013.09.23 16:51:25 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.09.23 01:00:35 | 000,001,883 | ---- | M] () -- C:\Users\Grejtak\Desktop\BlueJ.lnk
[2013.09.23 00:51:07 | 000,312,744 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.09.23 00:51:07 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.09.23 00:51:07 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.09.23 00:51:07 | 000,108,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.09.23 00:51:06 | 001,095,080 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.09.23 00:51:06 | 000,973,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.09.22 20:17:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.09.21 16:45:16 | 000,000,533 | ---- | M] () -- C:\Users\Grejtak\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013.09.21 00:24:21 | 000,251,904 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll
[2013.09.20 23:44:28 | 004,444,672 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll
[2013.09.20 23:44:28 | 001,987,072 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll
[2013.09.20 23:44:28 | 001,425,408 | ---- | M] (IDT, Inc.) -- C:\Windows\sttray64.exe
[2013.09.20 23:44:28 | 000,654,336 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2013.09.20 23:44:28 | 000,535,552 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys
[2013.09.20 23:44:28 | 000,448,512 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll
[2013.09.20 23:44:27 | 006,344,704 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNGUI.exe
[2013.09.20 23:44:27 | 005,298,688 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNHP.dll
[2013.09.20 23:44:27 | 001,819,136 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl
[2013.09.20 23:44:27 | 001,085,440 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNX.dll
[2013.09.20 23:44:27 | 000,442,368 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTEC64.dll
[2013.09.20 23:44:27 | 000,249,344 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNJ.exe
[2013.09.20 23:44:27 | 000,223,744 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\HPToneCtrls64.dll
[2013.09.20 23:44:27 | 000,162,304 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAC64.dll
[2013.09.20 23:44:27 | 000,090,624 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTCo64.dll
[2013.09.20 23:44:27 | 000,068,608 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAR64.dll
[2013.09.20 23:40:47 | 009,888,360 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysWow64\RtsPStorIcon.dll
[2013.09.20 23:40:47 | 000,338,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\drivers\RtsPStor.sys
[2013.09.20 23:36:49 | 000,208,896 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\drivers\nusb3xhc.sys
[2013.09.20 23:36:49 | 000,091,648 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\drivers\nusb3hub.sys
[2013.09.20 23:36:49 | 000,081,920 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\nusb3co2.dll
[2013.09.20 23:35:52 | 001,089,238 | ---- | M] () -- C:\Windows\SysNative\oem31.inf
[2013.09.20 23:35:00 | 004,747,840 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\BCMWL664.SYS
[2013.09.20 23:35:00 | 003,952,640 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmihvsrv64.dll
[2013.09.20 23:35:00 | 003,617,792 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmihvui64.dll
[2013.09.20 23:35:00 | 000,095,544 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmwlcoi.dll
[2013.09.20 23:35:00 | 000,006,656 | ---- | M] () -- C:\Windows\SysNative\bcmwlrc.dll
[2013.09.20 23:32:50 | 001,451,056 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys
[2013.09.20 23:32:50 | 000,226,600 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPAPI.dll
[2013.09.20 23:32:50 | 000,148,264 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPCo9.dll
[2013.09.20 23:32:50 | 000,107,816 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynTPCOM.dll
[2013.09.20 23:32:50 | 000,066,856 | ---- | M] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2013.09.20 23:32:49 | 000,411,944 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCOM.dll
[2013.09.20 23:32:49 | 000,276,264 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCtrl.dll
[2013.09.20 23:32:49 | 000,222,504 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCtrl.dll
[2013.09.20 23:32:49 | 000,177,448 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCOM.dll
[2013.09.20 12:01:42 | 000,277,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.09.20 01:58:02 | 000,174,200 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013.09.20 01:58:02 | 000,007,488 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013.09.20 01:58:02 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013.09.19 22:09:13 | 000,000,056 | -H-- | M] () -- C:\Windows\SysWow64\ezsidmv.dat
[2013.09.19 22:07:33 | 000,185,998 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013.09.19 22:07:33 | 000,185,998 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013.09.19 21:57:28 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.09.19 21:57:27 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.09.19 21:57:27 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.09.19 21:57:26 | 000,868,264 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.09.19 21:57:26 | 000,790,440 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.09.19 21:57:26 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
========== Files Created - No Company Name ==========
[2013.09.25 20:21:14 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.09.25 17:22:52 | 000,614,400 | ---- | C] () -- C:\Windows\AutoKMS.exe
[2013.09.25 17:22:52 | 000,000,204 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job
[2013.09.25 17:22:52 | 000,000,135 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2013.09.24 18:36:34 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.24 18:25:05 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.09.24 18:25:05 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.09.24 18:25:03 | 002,580,552 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.09.24 01:40:26 | 003,330,608 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2013.09.24 01:40:26 | 003,296,864 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2013.09.24 01:40:26 | 000,230,452 | ---- | C] () -- C:\Windows\SysNative\ativvaxy_cik.dat
[2013.09.24 01:40:26 | 000,230,064 | ---- | C] () -- C:\Windows\SysNative\ativvaxy_cik_nd.dat
[2013.09.24 01:40:26 | 000,073,984 | ---- | C] () -- C:\Windows\SysNative\ativce02.dat
[2013.09.24 01:40:26 | 000,042,535 | ---- | C] () -- C:\Windows\atiogl.xml
[2013.09.24 01:40:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013.09.24 01:40:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat
[2013.09.24 01:40:25 | 000,665,329 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
[2013.09.24 01:40:24 | 000,340,256 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2013.09.24 01:40:24 | 000,340,256 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2013.09.23 23:32:53 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.23 23:20:46 | 000,000,073 | ---- | C] () -- C:\Windows\wininit.ini
[2013.09.23 16:51:25 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.09.23 15:37:25 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.09.23 01:00:35 | 000,001,883 | ---- | C] () -- C:\Users\Grejtak\Desktop\BlueJ.lnk
[2013.09.22 20:17:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.09.21 16:45:16 | 000,000,533 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013.09.21 15:57:31 | 000,765,700 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.09.21 15:47:53 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.09.21 15:47:53 | 000,204,952 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
[2013.09.21 15:47:53 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.09.21 15:47:53 | 000,157,144 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
[2013.09.20 23:35:59 | 001,089,238 | ---- | C] () -- C:\Windows\SysNative\oem31.inf
[2013.09.20 23:32:55 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2013.09.20 09:33:09 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.09.20 02:49:33 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.09.20 01:04:35 | 000,000,938 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.09.20 01:04:35 | 000,000,934 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.09.19 22:14:43 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForGrejtak.job
[2013.09.19 21:59:03 | 2106,478,591 | -HS- | C] () -- C:\hiberfil.sys
[2013.09.19 21:49:36 | 000,001,413 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013.09.19 21:49:32 | 000,001,447 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.09.05 09:45:42 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.09.05 09:45:42 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2012.11.27 00:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.11.25 15:27:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.11.25 15:15:10 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.11.25 15:15:10 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.11.25 15:10:22 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.09.23 15:11:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\IDT
[2013.09.21 00:00:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Origin
[2013.09.23 12:15:10 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Subversion
[2013.09.19 21:49:44 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Synaptics
[2013.09.25 16:44:51 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Tific
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,013,300 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.09.19 22:14:43 | 000,000,340 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForGrejtak.job
[2013.09.20 01:04:35 | 000,000,934 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.09.20 01:04:35 | 000,000,938 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 17:22:52 | 000,000,204 | ---- | C] () -- C:\Windows\Tasks\AutoKMS.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012.10.03 19:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011.09.07 19:32:42 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2013.07.06 07:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
[2011.09.07 19:32:42 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.11.26 01:07:49 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2012.10.03 19:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\SysNative\drivers\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
[2011.11.26 01:07:49 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< >
< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[3 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp -> ]
[5 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2013.09.21 17:19:31 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Adobe
[2013.09.23 15:46:46 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Apple Computer
[2013.09.19 21:50:46 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\ATI
[2013.09.20 22:52:08 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Hewlett-Packard
[2013.09.20 23:57:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\hpqLog
[2013.09.19 21:49:22 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Identities
[2013.09.23 15:11:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\IDT
[2013.09.19 23:01:52 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\InstallShield
[2013.09.19 21:49:48 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Intel Corporation
[2013.09.21 16:53:59 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Macromedia
[2013.09.25 13:28:16 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Malwarebytes
[2011.11.26 01:06:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Media Center Programs
[2013.09.25 17:34:21 | 000,000,000 | --SD | M] -- C:\Users\Grejtak\AppData\Roaming\Microsoft
[2013.09.21 00:00:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Origin
[2013.09.21 17:28:49 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Skype
[2013.09.25 17:24:58 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\SkypEmoticons
[2013.09.23 12:15:10 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Subversion
[2013.09.19 21:49:44 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Synaptics
[2013.09.25 16:44:51 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Tific
[2013.09.23 00:22:13 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2013.09.24 16:46:17 | 000,088,102 | R--- | M] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Installer\{63059735-CA97-FDFB-0E7A-3B8D81572EFD}\ARPPRODUCTICON.exe
[2013.09.25 16:24:10 | 005,842,336 | ---- | M] (SkypEmoticons) -- C:\Users\Grejtak\AppData\Roaming\SkypEmoticons\SE.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2013.07.31 12:05:18 | 009,738,752 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2013.08.02 03:50:41 | 001,114,112 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\kernel32.dll
[2013.08.02 03:51:23 | 001,292,192 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ntdll.dll
< %systemroot%\Tasks\*.job >
[2013.09.25 17:22:52 | 000,000,204 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2013.09.25 17:08:42 | 000,000,934 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.09.25 20:09:00 | 000,000,938 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 10:22:35 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleForGrejtak.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2013.07.31 12:05:18 | 009,738,752 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2013.08.02 03:50:41 | 001,114,112 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\kernel32.dll
[2013.08.02 03:51:23 | 001,292,192 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ntdll.dll
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2013.09.25 17:24:14 | 000,000,088 | ---- | M] () -- C:\Windows\system32\11898457325152260558.log
[2013.09.23 23:52:33 | 000,054,600 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309232352338336.log
[2013.09.24 02:15:02 | 000,055,445 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240215027736.log
[2013.09.24 02:40:18 | 000,055,445 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240240188423.log
[2013.09.24 02:48:19 | 000,055,153 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240248192339.log
[2013.09.25 17:11:24 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
[2013.09.24 02:34:51 | 000,765,700 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
[2013.09.24 18:36:45 | 000,076,888 | ---- | M] () -- C:\Windows\system32\PnkBstrA.exe
[2013.09.24 18:36:34 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.ex0
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.exe
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.xtr
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Bloody2" = "C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum -- [2013.08.30 19:45:52 | 011,895,808 | ---- | M] ()
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.21 05:24:51 | 001,475,584 | ---- | M] (Microsoft Corporation)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2013.07.31 12:39:59 | 000,757,400 | ---- | M] (Microsoft Corporation) MD5=AA9CBDCD4675A48755DDA3A73BE3E283 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2013.09.17 05:21:30 | 000,829,392 | ---- | M] (Google Inc.) MD5=E7148BB584830E51AFD414CE9AEAE74C -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.09.25 20:21:14 | 000,000,512 | ---- | M] () MD5=3E55343007E697E2FE40F631D2055282 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2013.02.16 18:27:28 | 000,000,107 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\ako cracknut.txt
[2012.04.10 09:38:38 | 000,000,117 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Deus Ex - Human Revolution (2011) - CZ\sc-dxhr-1.4.651\SKIDROW CRACK.url
[2012.10.06 16:49:07 | 006,029,312 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\nfs.mw\Crack-na-NFS-most-wanted-(alik).exe
[2013.08.01 17:28:46 | 006,710,244 | ---- | M] () -- \Users\Grejtak\Documents\Programy\nero 10\Crack-Nero-10.6.11300.exe
[2012.10.31 21:04:00 | 007,082,092 | ---- | M] () -- \Users\Grejtak\Music\part 2\15. Norman Doray ft. Andreas Moe - Cracks.mp3
< *keygen* /s >
[2004.04.13 02:24:14 | 000,091,136 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Unreal Tournament 2004\UT2004 Keygen (XP only).exe
< *loader* /s >
[2013.09.13 19:51:30 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2010.03.24 20:12:34 | 000,249,680 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2010.03.24 20:12:34 | 000,018,264 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2010.08.23 10:07:00 | 000,053,248 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\Koan\pyloader.dll
[2011.03.22 11:42:38 | 000,015,118 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\Uploader\PyUploader.kc
[2011.03.22 11:42:38 | 000,175,200 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\Uploader\_PyUploader.pyd
[2010.09.08 15:53:28 | 000,167,720 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\YouCam\CES_3DLoaderC3S.dll
[2010.09.08 15:53:28 | 002,525,480 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\YouCam\CES_3DLoaderFBX.dll
[2013.02.09 03:39:28 | 000,000,934 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_main.fen
[2011.01.31 03:11:32 | 000,053,248 | ---- | M] () -- \Program Files (x86)\Hewlett-Packard\HP Setup\ContentDownloader.exe
[2011.01.31 03:06:58 | 000,005,974 | ---- | M] () -- \Program Files (x86)\Hewlett-Packard\HP Setup\ContentDownloader.exe.config
[2010.10.15 04:58:52 | 000,001,012 | R--- | M] () -- \Program Files (x86)\HP Games\onplay\downloader_bg_400.gif
[2008.02.25 08:05:22 | 000,856,064 | ---- | M] () -- \Program Files (x86)\The KMPlayer\ImLoader.dll
[2011.02.16 22:13:02 | 000,411,888 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\WTDownloader.exe
[2010.11.03 23:17:00 | 000,002,193 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\GamePlay_Loader.html
[2011.02.16 21:02:14 | 000,009,072 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Scripts\gameplay_loader.js
[2010.11.03 23:17:00 | 000,002,355 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Skins\default\gameplay_loader.css
[2010.03.24 20:35:48 | 000,370,512 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2010.03.24 20:35:48 | 000,018,264 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2013.09.23 00:49:56 | 000,000,948 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2013.09.23 00:49:57 | 000,000,411 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2013.09.23 00:49:59 | 001,183,660 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\org-openide-loaders.jar
[2013.09.23 00:49:59 | 000,006,274 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2013.09.23 00:49:59 | 000,005,853 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2013.09.23 00:50:00 | 000,000,457 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2013.08.22 19:01:26 | 000,061,528 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2013.09.25 16:25:58 | 000,003,208 | ---- | M] () -- \Users\Grejtak\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0\skin\ajax-loader.gif
[2013.09.25 16:25:59 | 000,000,808 | ---- | M] () -- \Users\Grejtak\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg\2013.122.3.1_0\javascript\delayed-loader.js
[2012.11.14 12:41:38 | 000,234,616 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\ubiorbitapi_r2_loader.dll
[2012.11.18 23:58:16 | 000,003,584 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\uplay_r1_loader.dll
[2007.09.17 05:50:38 | 000,169,384 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\cstrike\models\qloader.mdl
[2007.10.12 13:08:58 | 000,352,548 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\models\loader.mdl
[2007.10.12 13:10:00 | 000,012,764 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\sound\ambience\loader_hydra1.wav
[2007.10.12 13:10:00 | 000,012,164 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\sound\ambience\loader_step1.wav
[2012.05.16 22:43:52 | 009,580,713 | ---- | M] () -- \Users\Grejtak\Music\Lukas_ music\Far East Movement ft. Justin Bieber - Live My Life (CDQ) (SuntUploader@www.mp3md.org).mp3
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \Windows\SysWOW64\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2009.07.14 03:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 03:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:38:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_68a2edab92971725\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:38:44 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_68d8d569926ebeb2\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 04:12:19 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_68d20a7192733a4d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:35:00 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_6957a248ab947a6d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:39:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_69239340abbb38d0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 08:20:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_695e76beab8ff095\api-ms-win-core-libraryloader-l1-1-0.dll
[2010.11.21 09:06:45 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 09:06:45 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2010.11.21 09:06:45 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2010.11.21 09:06:45 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2010.11.21 09:06:45 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2011.09.07 19:33:22 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.09.07 19:33:22 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2011.09.07 19:33:22 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2011.09.07 19:33:22 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2011.09.07 19:33:22 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009.07.14 04:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 04:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2010.11.21 09:05:43 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 05:16:35 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011.09.07 19:33:17 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.09.07 19:33:17 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 04:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:45:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_0cba39e5da114d7c\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:46:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_0d04f7bcf35dc79a\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 07:53:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_0d3fdb3af3327f5f\api-ms-win-core-libraryloader-l1-1-0.dll
< End of report >
[2013.09.25 20:21:14 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.09.25 20:09:00 | 000,000,938 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 17:22:52 | 000,614,400 | ---- | M] () -- C:\Windows\AutoKMS.exe
[2013.09.25 17:22:52 | 000,000,204 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2013.09.25 17:22:52 | 000,000,135 | ---- | M] () -- C:\Windows\AutoKMS.ini
[2013.09.25 17:16:44 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.09.25 17:16:43 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.09.25 17:08:42 | 000,000,934 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.09.25 17:08:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.09.25 17:08:08 | 2106,478,591 | -HS- | M] () -- C:\hiberfil.sys
[2013.09.25 10:22:35 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForGrejtak.job
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.09.24 18:36:45 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.24 18:36:34 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.09.24 15:17:36 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.09.24 15:17:36 | 000,653,724 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.09.24 15:17:36 | 000,121,596 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.09.24 02:38:00 | 002,094,844 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1207020.003\Cat.DB
[2013.09.24 02:34:51 | 000,765,700 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.09.23 23:20:46 | 000,000,073 | ---- | M] () -- C:\Windows\wininit.ini
[2013.09.23 16:51:25 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.09.23 01:00:35 | 000,001,883 | ---- | M] () -- C:\Users\Grejtak\Desktop\BlueJ.lnk
[2013.09.23 00:51:07 | 000,312,744 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.09.23 00:51:07 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.09.23 00:51:07 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.09.23 00:51:07 | 000,108,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.09.23 00:51:06 | 001,095,080 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.09.23 00:51:06 | 000,973,736 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.09.22 20:17:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.09.21 16:45:16 | 000,000,533 | ---- | M] () -- C:\Users\Grejtak\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013.09.21 00:24:21 | 000,251,904 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll
[2013.09.20 23:44:28 | 004,444,672 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll
[2013.09.20 23:44:28 | 001,987,072 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll
[2013.09.20 23:44:28 | 001,425,408 | ---- | M] (IDT, Inc.) -- C:\Windows\sttray64.exe
[2013.09.20 23:44:28 | 000,654,336 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2013.09.20 23:44:28 | 000,535,552 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys
[2013.09.20 23:44:28 | 000,448,512 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll
[2013.09.20 23:44:27 | 006,344,704 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNGUI.exe
[2013.09.20 23:44:27 | 005,298,688 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNHP.dll
[2013.09.20 23:44:27 | 001,819,136 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl
[2013.09.20 23:44:27 | 001,085,440 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNX.dll
[2013.09.20 23:44:27 | 000,442,368 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTEC64.dll
[2013.09.20 23:44:27 | 000,249,344 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNJ.exe
[2013.09.20 23:44:27 | 000,223,744 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\HPToneCtrls64.dll
[2013.09.20 23:44:27 | 000,162,304 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAC64.dll
[2013.09.20 23:44:27 | 000,090,624 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTCo64.dll
[2013.09.20 23:44:27 | 000,068,608 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAR64.dll
[2013.09.20 23:40:47 | 009,888,360 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysWow64\RtsPStorIcon.dll
[2013.09.20 23:40:47 | 000,338,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\drivers\RtsPStor.sys
[2013.09.20 23:36:49 | 000,208,896 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\drivers\nusb3xhc.sys
[2013.09.20 23:36:49 | 000,091,648 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\drivers\nusb3hub.sys
[2013.09.20 23:36:49 | 000,081,920 | ---- | M] (Renesas Electronics Corporation) -- C:\Windows\SysNative\nusb3co2.dll
[2013.09.20 23:35:52 | 001,089,238 | ---- | M] () -- C:\Windows\SysNative\oem31.inf
[2013.09.20 23:35:00 | 004,747,840 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\BCMWL664.SYS
[2013.09.20 23:35:00 | 003,952,640 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmihvsrv64.dll
[2013.09.20 23:35:00 | 003,617,792 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmihvui64.dll
[2013.09.20 23:35:00 | 000,095,544 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\bcmwlcoi.dll
[2013.09.20 23:35:00 | 000,006,656 | ---- | M] () -- C:\Windows\SysNative\bcmwlrc.dll
[2013.09.20 23:32:50 | 001,451,056 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys
[2013.09.20 23:32:50 | 000,226,600 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPAPI.dll
[2013.09.20 23:32:50 | 000,148,264 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPCo9.dll
[2013.09.20 23:32:50 | 000,107,816 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynTPCOM.dll
[2013.09.20 23:32:50 | 000,066,856 | ---- | M] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2013.09.20 23:32:49 | 000,411,944 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCOM.dll
[2013.09.20 23:32:49 | 000,276,264 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCtrl.dll
[2013.09.20 23:32:49 | 000,222,504 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCtrl.dll
[2013.09.20 23:32:49 | 000,177,448 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCOM.dll
[2013.09.20 12:01:42 | 000,277,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.09.20 01:58:02 | 000,174,200 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013.09.20 01:58:02 | 000,007,488 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013.09.20 01:58:02 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013.09.19 22:09:13 | 000,000,056 | -H-- | M] () -- C:\Windows\SysWow64\ezsidmv.dat
[2013.09.19 22:07:33 | 000,185,998 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013.09.19 22:07:33 | 000,185,998 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013.09.19 21:57:28 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.09.19 21:57:27 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.09.19 21:57:27 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.09.19 21:57:26 | 000,868,264 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.09.19 21:57:26 | 000,790,440 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.09.19 21:57:26 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
========== Files Created - No Company Name ==========
[2013.09.25 20:21:14 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.09.25 17:22:52 | 000,614,400 | ---- | C] () -- C:\Windows\AutoKMS.exe
[2013.09.25 17:22:52 | 000,000,204 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job
[2013.09.25 17:22:52 | 000,000,135 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2013.09.24 18:36:34 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.24 18:25:05 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.09.24 18:25:05 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.09.24 18:25:03 | 002,580,552 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.09.24 01:40:26 | 003,330,608 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2013.09.24 01:40:26 | 003,296,864 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2013.09.24 01:40:26 | 000,230,452 | ---- | C] () -- C:\Windows\SysNative\ativvaxy_cik.dat
[2013.09.24 01:40:26 | 000,230,064 | ---- | C] () -- C:\Windows\SysNative\ativvaxy_cik_nd.dat
[2013.09.24 01:40:26 | 000,073,984 | ---- | C] () -- C:\Windows\SysNative\ativce02.dat
[2013.09.24 01:40:26 | 000,042,535 | ---- | C] () -- C:\Windows\atiogl.xml
[2013.09.24 01:40:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013.09.24 01:40:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat
[2013.09.24 01:40:25 | 000,665,329 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
[2013.09.24 01:40:24 | 000,340,256 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2013.09.24 01:40:24 | 000,340,256 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2013.09.23 23:32:53 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.23 23:20:46 | 000,000,073 | ---- | C] () -- C:\Windows\wininit.ini
[2013.09.23 16:51:25 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.09.23 15:37:25 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.09.23 01:00:35 | 000,001,883 | ---- | C] () -- C:\Users\Grejtak\Desktop\BlueJ.lnk
[2013.09.22 20:17:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.09.21 16:45:16 | 000,000,533 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\All CPU MeterV3_Settings.ini
[2013.09.21 15:57:31 | 000,765,700 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.09.21 15:47:53 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.09.21 15:47:53 | 000,204,952 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
[2013.09.21 15:47:53 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.09.21 15:47:53 | 000,157,144 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
[2013.09.20 23:35:59 | 001,089,238 | ---- | C] () -- C:\Windows\SysNative\oem31.inf
[2013.09.20 23:32:55 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2013.09.20 09:33:09 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.09.20 02:49:33 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.09.20 01:04:35 | 000,000,938 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.09.20 01:04:35 | 000,000,934 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.09.19 22:14:43 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForGrejtak.job
[2013.09.19 21:59:03 | 2106,478,591 | -HS- | C] () -- C:\hiberfil.sys
[2013.09.19 21:49:36 | 000,001,413 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013.09.19 21:49:32 | 000,001,447 | ---- | C] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.09.05 09:45:42 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.09.05 09:45:42 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2012.11.27 00:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.11.25 15:27:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.11.25 15:15:10 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.11.25 15:15:10 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.11.25 15:10:22 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.09.23 15:11:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\IDT
[2013.09.21 00:00:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Origin
[2013.09.23 12:15:10 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Subversion
[2013.09.19 21:49:44 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Synaptics
[2013.09.25 16:44:51 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Tific
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,013,300 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.09.19 22:14:43 | 000,000,340 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForGrejtak.job
[2013.09.20 01:04:35 | 000,000,934 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.09.20 01:04:35 | 000,000,938 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 17:22:52 | 000,000,204 | ---- | C] () -- C:\Windows\Tasks\AutoKMS.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.09.07 19:36:59 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.09.07 19:36:59 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012.10.03 19:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011.09.07 19:32:42 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2013.07.06 07:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
[2011.09.07 19:32:42 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.11.26 01:07:49 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2012.10.03 19:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\SysNative\drivers\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
[2011.11.26 01:07:49 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< >
< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[3 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp -> ]
[5 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2013.09.21 17:19:31 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Adobe
[2013.09.23 15:46:46 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Apple Computer
[2013.09.19 21:50:46 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\ATI
[2013.09.20 22:52:08 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Hewlett-Packard
[2013.09.20 23:57:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\hpqLog
[2013.09.19 21:49:22 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Identities
[2013.09.23 15:11:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\IDT
[2013.09.19 23:01:52 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\InstallShield
[2013.09.19 21:49:48 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Intel Corporation
[2013.09.21 16:53:59 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Macromedia
[2013.09.25 13:28:16 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Malwarebytes
[2011.11.26 01:06:04 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Media Center Programs
[2013.09.25 17:34:21 | 000,000,000 | --SD | M] -- C:\Users\Grejtak\AppData\Roaming\Microsoft
[2013.09.21 00:00:07 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Origin
[2013.09.21 17:28:49 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Skype
[2013.09.25 17:24:58 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\SkypEmoticons
[2013.09.23 12:15:10 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Subversion
[2013.09.19 21:49:44 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Synaptics
[2013.09.25 16:44:51 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\Tific
[2013.09.23 00:22:13 | 000,000,000 | ---D | M] -- C:\Users\Grejtak\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2013.09.24 16:46:17 | 000,088,102 | R--- | M] () -- C:\Users\Grejtak\AppData\Roaming\Microsoft\Installer\{63059735-CA97-FDFB-0E7A-3B8D81572EFD}\ARPPRODUCTICON.exe
[2013.09.25 16:24:10 | 005,842,336 | ---- | M] (SkypEmoticons) -- C:\Users\Grejtak\AppData\Roaming\SkypEmoticons\SE.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2013.07.31 12:05:18 | 009,738,752 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2013.08.02 03:50:41 | 001,114,112 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\kernel32.dll
[2013.08.02 03:51:23 | 001,292,192 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ntdll.dll
< %systemroot%\Tasks\*.job >
[2013.09.25 17:22:52 | 000,000,204 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2013.09.25 17:08:42 | 000,000,934 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.09.25 20:09:00 | 000,000,938 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.09.25 10:22:35 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleForGrejtak.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2013.07.31 12:05:18 | 009,738,752 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2013.08.02 03:50:41 | 001,114,112 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\kernel32.dll
[2013.08.02 03:51:23 | 001,292,192 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ntdll.dll
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2013.09.25 17:24:14 | 000,000,088 | ---- | M] () -- C:\Windows\system32\11898457325152260558.log
[2013.09.23 23:52:33 | 000,054,600 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309232352338336.log
[2013.09.24 02:15:02 | 000,055,445 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240215027736.log
[2013.09.24 02:40:18 | 000,055,445 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240240188423.log
[2013.09.24 02:48:19 | 000,055,153 | ---- | M] () -- C:\Windows\system32\CCCInstall_201309240248192339.log
[2013.09.25 17:11:24 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
[2013.09.24 02:34:51 | 000,765,700 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
[2013.09.24 18:36:45 | 000,076,888 | ---- | M] () -- C:\Windows\system32\PnkBstrA.exe
[2013.09.24 18:36:34 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.ex0
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.exe
[2013.09.24 19:41:35 | 000,290,184 | ---- | M] () -- C:\Windows\system32\PnkBstrB.xtr
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Bloody2" = "C:\Program Files (x86)\Bloody4\Bloody4\Bloody4.exe" Minimum -- [2013.08.30 19:45:52 | 011,895,808 | ---- | M] ()
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.21 05:24:51 | 001,475,584 | ---- | M] (Microsoft Corporation)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2013.07.31 12:39:59 | 000,757,400 | ---- | M] (Microsoft Corporation) MD5=AA9CBDCD4675A48755DDA3A73BE3E283 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2013.09.17 05:21:30 | 000,829,392 | ---- | M] (Google Inc.) MD5=E7148BB584830E51AFD414CE9AEAE74C -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.09.25 20:21:14 | 000,000,512 | ---- | M] () MD5=3E55343007E697E2FE40F631D2055282 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2013.02.16 18:27:28 | 000,000,107 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\ako cracknut.txt
[2012.04.10 09:38:38 | 000,000,117 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Deus Ex - Human Revolution (2011) - CZ\sc-dxhr-1.4.651\SKIDROW CRACK.url
[2012.10.06 16:49:07 | 006,029,312 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\nfs.mw\Crack-na-NFS-most-wanted-(alik).exe
[2013.08.01 17:28:46 | 006,710,244 | ---- | M] () -- \Users\Grejtak\Documents\Programy\nero 10\Crack-Nero-10.6.11300.exe
[2012.10.31 21:04:00 | 007,082,092 | ---- | M] () -- \Users\Grejtak\Music\part 2\15. Norman Doray ft. Andreas Moe - Cracks.mp3
< *keygen* /s >
[2004.04.13 02:24:14 | 000,091,136 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Unreal Tournament 2004\UT2004 Keygen (XP only).exe
< *loader* /s >
[2013.09.13 19:51:30 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2010.03.24 20:12:34 | 000,249,680 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2010.03.24 20:12:34 | 000,018,264 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2010.08.23 10:07:00 | 000,053,248 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\Koan\pyloader.dll
[2011.03.22 11:42:38 | 000,015,118 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\Uploader\PyUploader.kc
[2011.03.22 11:42:38 | 000,175,200 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\Uploader\_PyUploader.pyd
[2010.09.08 15:53:28 | 000,167,720 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\YouCam\CES_3DLoaderC3S.dll
[2010.09.08 15:53:28 | 002,525,480 | ---- | M] () -- \Program Files (x86)\CyberLink\YouCam\subsys\YouCam\CES_3DLoaderFBX.dll
[2013.02.09 03:39:28 | 000,000,934 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_main.fen
[2011.01.31 03:11:32 | 000,053,248 | ---- | M] () -- \Program Files (x86)\Hewlett-Packard\HP Setup\ContentDownloader.exe
[2011.01.31 03:06:58 | 000,005,974 | ---- | M] () -- \Program Files (x86)\Hewlett-Packard\HP Setup\ContentDownloader.exe.config
[2010.10.15 04:58:52 | 000,001,012 | R--- | M] () -- \Program Files (x86)\HP Games\onplay\downloader_bg_400.gif
[2008.02.25 08:05:22 | 000,856,064 | ---- | M] () -- \Program Files (x86)\The KMPlayer\ImLoader.dll
[2011.02.16 22:13:02 | 000,411,888 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\WTDownloader.exe
[2010.11.03 23:17:00 | 000,002,193 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\GamePlay_Loader.html
[2011.02.16 21:02:14 | 000,009,072 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Scripts\gameplay_loader.js
[2010.11.03 23:17:00 | 000,002,355 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Skins\default\gameplay_loader.css
[2010.03.24 20:35:48 | 000,370,512 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2010.03.24 20:35:48 | 000,018,264 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2013.09.23 00:49:56 | 000,000,948 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2013.09.23 00:49:57 | 000,000,411 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2013.09.23 00:49:59 | 001,183,660 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\org-openide-loaders.jar
[2013.09.23 00:49:59 | 000,006,274 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2013.09.23 00:49:59 | 000,005,853 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2013.09.23 00:50:00 | 000,000,457 | ---- | M] () -- \Program Files\Java\jdk1.7.0_40\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2013.08.22 19:01:26 | 000,061,528 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2013.09.25 16:25:58 | 000,003,208 | ---- | M] () -- \Users\Grejtak\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0\skin\ajax-loader.gif
[2013.09.25 16:25:59 | 000,000,808 | ---- | M] () -- \Users\Grejtak\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg\2013.122.3.1_0\javascript\delayed-loader.js
[2012.11.14 12:41:38 | 000,234,616 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\ubiorbitapi_r2_loader.dll
[2012.11.18 23:58:16 | 000,003,584 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\BB_AC3\Assassins-Creed.3.CRACK.FIX-SKIDROW\uplay_r1_loader.dll
[2007.09.17 05:50:38 | 000,169,384 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\cstrike\models\qloader.mdl
[2007.10.12 13:08:58 | 000,352,548 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\models\loader.mdl
[2007.10.12 13:10:00 | 000,012,764 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\sound\ambience\loader_hydra1.wav
[2007.10.12 13:10:00 | 000,012,164 | ---- | M] () -- \Users\Grejtak\Documents\Games for install\Counter-Strike_Miloš\valve\sound\ambience\loader_step1.wav
[2012.05.16 22:43:52 | 009,580,713 | ---- | M] () -- \Users\Grejtak\Music\Lukas_ music\Far East Movement ft. Justin Bieber - Live My Life (CDQ) (SuntUploader@www.mp3md.org).mp3
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \Windows\SysWOW64\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2009.07.14 03:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 03:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:38:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_68a2edab92971725\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:38:44 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_68d8d569926ebeb2\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 04:12:19 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_68d20a7192733a4d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:35:00 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_6957a248ab947a6d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:39:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_69239340abbb38d0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 08:20:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_695e76beab8ff095\api-ms-win-core-libraryloader-l1-1-0.dll
[2010.11.21 09:06:45 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 09:06:45 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2010.11.21 09:06:45 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2010.11.21 09:06:45 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2010.11.21 09:06:45 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2011.09.07 19:33:22 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.09.07 19:33:22 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2011.09.07 19:33:22 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2011.09.07 19:33:22 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2011.09.07 19:33:22 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009.07.14 04:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 04:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2010.11.21 09:05:43 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 05:16:35 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011.09.07 19:33:17 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.09.07 19:33:17 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 04:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:45:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_0cba39e5da114d7c\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 03:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 06:46:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_0d04f7bcf35dc79a\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 07:53:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_0d3fdb3af3327f5f\api-ms-win-core-libraryloader-l1-1-0.dll
< End of report >