Re: Prosím o kontrolu logu :)
Napsal: 23 úno 2014 15:41
< MD5 for: WDF01000.SYS >
[2009.07.14 02:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) MD5=441BD2D7B4F98134C3A4F9FA570FD250 -- C:\Windows\SysNative\drivers\Wdf01000.sys
[2009.07.14 02:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) MD5=441BD2D7B4F98134C3A4F9FA570FD250 -- C:\Windows\winsxs\amd64_microsoft-windows-wdf-kernellibrary_31bf3856ad364e35_6.1.7600.16385_none_d24809e1379d1f91\Wdf01000.sys
< MD5 for: WIN32K.SYS >
[2012.01.14 05:00:52 | 003,148,288 | ---- | M] (Microsoft Corporation) MD5=0777AD78CEF3B17D12C3A1988282952B -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21898_none_1750a188ca8132fd\win32k.sys
[2012.01.14 05:06:27 | 003,145,728 | ---- | M] (Microsoft Corporation) MD5=275D3946B0EC22BA13FE299E97ABF606 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17762_none_16e172c5b150a756\win32k.sys
[2012.01.14 05:05:42 | 003,148,288 | ---- | M] (Microsoft Corporation) MD5=2A6231EDD1728E97E5C73A4C995331EF -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21127_none_15b4cbcecd231d65\win32k.sys
[2011.11.24 05:45:10 | 003,146,752 | ---- | M] (Microsoft Corporation) MD5=338E48AB7810E1B223DFECD82C44F5A3 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21866_none_176f10b8ca6aac7c\win32k.sys
[2012.10.18 19:25:58 | 003,149,824 | ---- | M] (Microsoft Corporation) MD5=34B419EDEAC6F12B34908DE3758F98C9 -- C:\Windows\SysNative\win32k.sys
[2012.10.18 19:25:58 | 003,149,824 | ---- | M] (Microsoft Corporation) MD5=34B419EDEAC6F12B34908DE3758F98C9 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17977_none_16dba817b1543c48\win32k.sys
[2012.01.14 05:02:25 | 003,143,168 | ---- | M] (Microsoft Corporation) MD5=39FF1BFDC0D5868E8D032EA349D30F51 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16948_none_1516b753b4149b92\win32k.sys
[2011.11.24 05:52:41 | 003,146,240 | ---- | M] (Microsoft Corporation) MD5=3AD5AEA8772DBEB548D0863714D7959D -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21097_none_15691a74cd5be3d5\win32k.sys
[2012.04.02 04:01:19 | 003,143,680 | ---- | M] (Microsoft Corporation) MD5=44DC57624E27B6EF3EA24F4892CB2620 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16988_none_14eb77a3b4350b56\win32k.sys
[2012.06.12 04:08:36 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=511166D3F5D7EBA36DE48C4F5E195886 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17860_none_16df7417b15271cf\win32k.sys
[2011.11.24 06:00:47 | 003,141,632 | ---- | M] (Microsoft Corporation) MD5=55CF26CF771B086A393750BD494FD6FC -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16920_none_152454dbb40b98f8\win32k.sys
[2012.10.18 19:35:40 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=5C874B021D964326A38765955E108E7F -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21347_none_159f2fc2cd334f95\win32k.sys
[2011.11.24 05:52:09 | 003,145,216 | ---- | M] (Microsoft Corporation) MD5=6E810D7C1E3881289733924CE9763B92 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17730_none_16ffe1f5b13a20d5\win32k.sys
[2012.06.12 04:02:52 | 003,147,264 | ---- | M] (Microsoft Corporation) MD5=7FF70301AB5176FC3B72BD6C9B8BF888 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.17039_none_15225fabb40bcc3a\win32k.sys
[2012.03.31 03:56:14 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=88592AB8F8AE4F7264A936AEE682BBE5 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21955_none_1778e240ca63745b\win32k.sys
[2012.10.18 19:18:22 | 003,147,264 | ---- | M] (Microsoft Corporation) MD5=8ABB4C73841402A9D30A4CC0B880FCE1 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.17147_none_15159111b415b2a4\win32k.sys
[2012.10.18 19:14:46 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=9FE34DE5E7E97DA1AB228F71687BDB88 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.22137_none_17905cb4ca519f90\win32k.sys
[2012.06.12 04:04:59 | 003,151,360 | ---- | M] (Microsoft Corporation) MD5=A8191824CC60305DD2313D7A74F95EDD -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21231_none_15a3fc0ccd309e73\win32k.sys
[2010.11.20 10:53:33 | 003,126,272 | ---- | M] (Microsoft Corporation) MD5=A89392A32BA98468710FD7E38318934B -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17514_none_17197f29b1265401\win32k.sys
[2012.03.31 04:05:06 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=B132D7E1E53C5835B13E5F23394C3202 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21179_none_1580bcc6cd49dbc8\win32k.sys
[2012.06.12 03:58:04 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=BC91C50C20709D85A2137E689DC3ED19 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.22016_none_17a4fa5cca425130\win32k.sys
[2009.07.14 00:40:40 | 003,122,176 | ---- | M] (Microsoft Corporation) MD5=CBEF2EB83438ED9FC39411CC8378B0E7 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16385_none_14e86b61b437d067\win32k.sys
[2012.03.31 04:10:03 | 003,146,240 | ---- | M] (Microsoft Corporation) MD5=F4C456F9235ED440B81107E951555411 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17803_none_1723547db11f162e\win32k.sys
< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINSRV.DLL >
[2011.07.16 06:26:18 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=0CB6EBF4B461A6043353C570BD72A1E1 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.16850_none_128f0019b5f25b8f\winsrv.dll
[2012.08.20 20:06:40 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=0E83424D4CEC0665A3A916AD6B261E53 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.21306_none_13548c10cee23265\winsrv.dll
[2012.08.20 19:27:20 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=111AFE35DD2D423EE8E176CA7B2BBDC7 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.22091_none_14d49672cc561df0\winsrv.dll
[2009.07.14 02:41:56 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=457B44AB6D502E55F64A867D4F35C76C -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.16385_none_12738849b6063c52\winsrv.dll
[2011.06.24 06:26:55 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=6D408ABD60A995A2DAB4BAAE38BCA04F -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.20995_none_12f25ea6cf2be9d0\winsrv.dll
[2012.08.18 16:42:31 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=79CDA06F75AD5373DD447F57575C4400 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.17107_none_12cbeda9b5c3aecb\winsrv.dll
[2011.06.24 06:27:05 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=C13D05A015346DED3D722BE285814495 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.21756_none_1504fba6cc30ff4f\winsrv.dll
[2010.11.20 14:27:28 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=E0406AEF04B088D1C49FC78D0546F689 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17514_none_14a49c11b2f4bfec\winsrv.dll
[2011.06.24 06:34:53 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=EB6A48CC998E1090E44E8E7F1009A640 -- C:\Windows\SysNative\winsrv.dll
[2011.06.24 06:34:53 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=EB6A48CC998E1090E44E8E7F1009A640 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17641_none_14812d55b30fc4e1\winsrv.dll
[2012.08.20 19:48:43 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=F46BBAAC1C4980F4D0DD463F190A42D3 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17932_none_148d033db306b9bc\winsrv.dll
< MD5 for: WS2_32.DLL >
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< MD5 for: WSCRIPT.EXE >
[2009.07.14 02:39:57 | 000,168,960 | ---- | M] (Microsoft Corporation) MD5=8886E0697B0A93C521F99099EF643450 -- C:\Windows\SysNative\wscript.exe
[2009.07.14 02:39:57 | 000,168,960 | ---- | M] (Microsoft Corporation) MD5=8886E0697B0A93C521F99099EF643450 -- C:\Windows\winsxs\amd64_microsoft-windows-scripting_31bf3856ad364e35_6.1.7600.16385_none_a45d44bd1a0af822\wscript.exe
[2009.07.14 02:14:49 | 000,141,824 | ---- | M] (Microsoft Corporation) MD5=D1AB72DB2BEDD2F255D35DA3DA0D4B16 -- C:\Windows\SysWOW64\wscript.exe
[2009.07.14 02:14:49 | 000,141,824 | ---- | M] (Microsoft Corporation) MD5=D1AB72DB2BEDD2F255D35DA3DA0D4B16 -- C:\Windows\winsxs\wow64_microsoft-windows-scripting_31bf3856ad364e35_6.1.7600.16385_none_aeb1ef0f4e6bba1d\wscript.exe
< >
< %systemroot%\system32\logevent.dll /md5 >
< %systemroot%\system32\sceclt.dll /md5 >
< %systemroot%\system32\ntelogon.dll /md5 >
< %systemroot%\system32\consrv.dll /md5 >
< >
< %systemroot%\system32\logevent.dll /md5 /64 >
< %systemroot%\system32\sceclt.dll /md5 /64 >
< %systemroot%\system32\ntelogon.dll /md5 /64 >
< %systemroot%\system32\consrv.dll /md5 /64 >
< >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.10.08 09:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2014.02.20 02:03:06 | 000,859,464 | ---- | M] (Google Inc.) MD5=6E6656C6618C4B0B000267D9AF9EF743 -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %systemroot%\system32\Spool\prtprocs\*.* /s >
[2009.07.14 02:41:12 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\x64\jnwppr.dll
[2011.06.22 06:48:28 | 000,036,864 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\system32\Spool\prtprocs\x64\ssp7mpc.dll
[2010.11.20 14:27:28 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\x64\winprint.dll
[2009.07.14 16:17:26 | 000,003,584 | ---- | M] (Lexmark International Inc.) -- C:\Windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
< %systemroot%\system32\drivers\*.sys /10 >
< %systemroot%\system32\drivers\*.sys /X >
[2009.06.10 22:14:29 | 003,440,660 | ---- | M] () -- C:\Windows\system32\drivers\gm.dls
[2009.06.10 22:14:29 | 000,000,646 | ---- | M] () -- C:\Windows\system32\drivers\gmreadme.txt
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\*.* /10 >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\*.* /lockedfiles >
< %systemroot%\system32\config\*.sav >
< >
< c:\$Recycle.Bin|L,N,U,@;true;true;true /FN >
< c:\Windows\Installer|L,N,U,@;true;true;true /FN >
< >
< %systemroot%\Tasks\*.job >
[2014.02.23 14:11:32 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014.02.23 14:52:00 | 000,000,952 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< %systemroot%\*.* /U /s >
[7 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[10 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[33 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp files -> C:\Windows\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp -> ]
[3 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp -> ]
[2 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp -> ]
[3 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp -> ]
[2 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp -> ]
[1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %systemroot%\*. /rp /s >
< %ALLUSERSPROFILE%\Data Aplikací\*.* >
< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
< %ALLUSERSPROFILE%\Nabídka Start\*.lnk /x >
< %ALLUSERSPROFILE%\Data Aplikácií\*.* >
< %ALLUSERSPROFILE%\Data Aplikácií\*.exe /s >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %APPDATA%\*. >
[2012.12.01 19:03:28 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\.gephi
[2012.12.02 09:31:04 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Adobe
[2012.09.13 20:53:43 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Ahead
[2013.07.23 18:52:41 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Ancestry
[2012.12.04 18:18:56 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Autodesk
[2013.07.21 21:22:46 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\avidemux
[2013.07.26 14:51:29 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Bitmeter2
[2014.02.01 12:14:51 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\BitSpirit
[2013.06.09 05:45:27 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Blender Foundation
[2013.08.09 09:24:00 | 000,000,000 | R--D | M] -- C:\Users\caesar\AppData\Roaming\Brother
[2013.01.20 15:53:57 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\BSplayer PRO
[2012.09.13 20:10:14 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Canneverbe Limited
[2013.06.10 09:06:47 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.12.01 22:11:16 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.12.18 18:50:42 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Corel
[2012.02.27 19:05:50 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools
[2014.02.18 21:53:55 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools Lite
[2014.02.18 21:53:55 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools Pro
[2012.06.26 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DassaultSystemes
[2014.02.23 14:15:01 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Dropbox
[2012.08.16 08:12:36 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\dvdcss
[2013.04.15 16:55:38 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DVDVideoSoft
[2012.12.27 18:29:28 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Edraw Max
[2012.12.01 10:12:24 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\GetRightToGo
[2013.02.23 16:37:37 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\GHISLER
[2012.07.13 09:16:18 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\gtk-2.0
[2012.02.13 18:51:00 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Identities
[2014.02.18 21:53:54 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\inkscape
[2012.02.13 23:15:05 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\InstallShield
[2012.06.27 07:55:06 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\KeePass
[2012.02.14 14:57:34 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Macromedia
[2012.10.01 14:31:56 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mathsoft
[2012.03.20 19:48:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\MathWorks
[2009.07.14 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Media Center Programs
[2013.07.03 15:12:57 | 000,000,000 | --SD | M] -- C:\Users\caesar\AppData\Roaming\Microsoft
[2012.02.14 14:00:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Miranda
[2012.07.17 10:16:44 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mobile Atlas Creator
[2012.07.07 13:21:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mozilla
[2012.08.07 20:44:03 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Nokia
[2013.02.23 15:33:20 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Notepad++
[2012.08.07 20:36:52 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\PC Suite
[2012.12.02 09:31:19 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.08.06 15:30:50 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\STV Software
[2012.07.18 15:09:57 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\TeamViewer
[2012.07.07 13:21:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Thunderbird
[2014.02.19 17:34:52 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\vlc
[2012.07.07 13:00:13 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Windows Live Writer
[2012.02.14 09:15:04 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\WinRAR
[2013.12.07 20:52:36 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\XnView
< %APPDATA%\*.* >
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] (xRgizs9q02T) -- C:\Users\caesar\AppData\Roaming\Windows.exe
< %APPDATA%\*.exe /s >
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] (xRgizs9q02T) -- C:\Users\caesar\AppData\Roaming\Windows.exe
[2014.01.03 01:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2014.01.03 01:47:26 | 000,229,288 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2012.12.04 00:43:48 | 000,880,672 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2013.06.10 09:07:16 | 000,055,424 | ---- | M] (Adobe Systems Inc.) -- C:\Users\caesar\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] () -- C:\Users\caesar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\52ae9a9b35c8ca9d61a092e4ad35cca9.exe
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32|bak;true;false;false /fp >
< %PROGRAMFILES%|bak;true;false;false /fp >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.20 14:25:17 | 001,475,584 | ---- | M] (Microsoft Corporation)
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.02.13 09:06:56 | 003,481,408 | ---- | M] (DT Soft Ltd)
"OscarX7Mouse5Mode" = "C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe" Minimum -- [2012.03.20 16:52:10 | 003,521,024 | ---- | M] ()
"AdobeBridge" =
< End of report >
[2009.07.14 02:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) MD5=441BD2D7B4F98134C3A4F9FA570FD250 -- C:\Windows\SysNative\drivers\Wdf01000.sys
[2009.07.14 02:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) MD5=441BD2D7B4F98134C3A4F9FA570FD250 -- C:\Windows\winsxs\amd64_microsoft-windows-wdf-kernellibrary_31bf3856ad364e35_6.1.7600.16385_none_d24809e1379d1f91\Wdf01000.sys
< MD5 for: WIN32K.SYS >
[2012.01.14 05:00:52 | 003,148,288 | ---- | M] (Microsoft Corporation) MD5=0777AD78CEF3B17D12C3A1988282952B -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21898_none_1750a188ca8132fd\win32k.sys
[2012.01.14 05:06:27 | 003,145,728 | ---- | M] (Microsoft Corporation) MD5=275D3946B0EC22BA13FE299E97ABF606 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17762_none_16e172c5b150a756\win32k.sys
[2012.01.14 05:05:42 | 003,148,288 | ---- | M] (Microsoft Corporation) MD5=2A6231EDD1728E97E5C73A4C995331EF -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21127_none_15b4cbcecd231d65\win32k.sys
[2011.11.24 05:45:10 | 003,146,752 | ---- | M] (Microsoft Corporation) MD5=338E48AB7810E1B223DFECD82C44F5A3 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21866_none_176f10b8ca6aac7c\win32k.sys
[2012.10.18 19:25:58 | 003,149,824 | ---- | M] (Microsoft Corporation) MD5=34B419EDEAC6F12B34908DE3758F98C9 -- C:\Windows\SysNative\win32k.sys
[2012.10.18 19:25:58 | 003,149,824 | ---- | M] (Microsoft Corporation) MD5=34B419EDEAC6F12B34908DE3758F98C9 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17977_none_16dba817b1543c48\win32k.sys
[2012.01.14 05:02:25 | 003,143,168 | ---- | M] (Microsoft Corporation) MD5=39FF1BFDC0D5868E8D032EA349D30F51 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16948_none_1516b753b4149b92\win32k.sys
[2011.11.24 05:52:41 | 003,146,240 | ---- | M] (Microsoft Corporation) MD5=3AD5AEA8772DBEB548D0863714D7959D -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21097_none_15691a74cd5be3d5\win32k.sys
[2012.04.02 04:01:19 | 003,143,680 | ---- | M] (Microsoft Corporation) MD5=44DC57624E27B6EF3EA24F4892CB2620 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16988_none_14eb77a3b4350b56\win32k.sys
[2012.06.12 04:08:36 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=511166D3F5D7EBA36DE48C4F5E195886 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17860_none_16df7417b15271cf\win32k.sys
[2011.11.24 06:00:47 | 003,141,632 | ---- | M] (Microsoft Corporation) MD5=55CF26CF771B086A393750BD494FD6FC -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16920_none_152454dbb40b98f8\win32k.sys
[2012.10.18 19:35:40 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=5C874B021D964326A38765955E108E7F -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21347_none_159f2fc2cd334f95\win32k.sys
[2011.11.24 05:52:09 | 003,145,216 | ---- | M] (Microsoft Corporation) MD5=6E810D7C1E3881289733924CE9763B92 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17730_none_16ffe1f5b13a20d5\win32k.sys
[2012.06.12 04:02:52 | 003,147,264 | ---- | M] (Microsoft Corporation) MD5=7FF70301AB5176FC3B72BD6C9B8BF888 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.17039_none_15225fabb40bcc3a\win32k.sys
[2012.03.31 03:56:14 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=88592AB8F8AE4F7264A936AEE682BBE5 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.21955_none_1778e240ca63745b\win32k.sys
[2012.10.18 19:18:22 | 003,147,264 | ---- | M] (Microsoft Corporation) MD5=8ABB4C73841402A9D30A4CC0B880FCE1 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.17147_none_15159111b415b2a4\win32k.sys
[2012.10.18 19:14:46 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=9FE34DE5E7E97DA1AB228F71687BDB88 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.22137_none_17905cb4ca519f90\win32k.sys
[2012.06.12 04:04:59 | 003,151,360 | ---- | M] (Microsoft Corporation) MD5=A8191824CC60305DD2313D7A74F95EDD -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21231_none_15a3fc0ccd309e73\win32k.sys
[2010.11.20 10:53:33 | 003,126,272 | ---- | M] (Microsoft Corporation) MD5=A89392A32BA98468710FD7E38318934B -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17514_none_17197f29b1265401\win32k.sys
[2012.03.31 04:05:06 | 003,148,800 | ---- | M] (Microsoft Corporation) MD5=B132D7E1E53C5835B13E5F23394C3202 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.21179_none_1580bcc6cd49dbc8\win32k.sys
[2012.06.12 03:58:04 | 003,151,872 | ---- | M] (Microsoft Corporation) MD5=BC91C50C20709D85A2137E689DC3ED19 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.22016_none_17a4fa5cca425130\win32k.sys
[2009.07.14 00:40:40 | 003,122,176 | ---- | M] (Microsoft Corporation) MD5=CBEF2EB83438ED9FC39411CC8378B0E7 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7600.16385_none_14e86b61b437d067\win32k.sys
[2012.03.31 04:10:03 | 003,146,240 | ---- | M] (Microsoft Corporation) MD5=F4C456F9235ED440B81107E951555411 -- C:\Windows\winsxs\amd64_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17803_none_1723547db11f162e\win32k.sys
< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINSRV.DLL >
[2011.07.16 06:26:18 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=0CB6EBF4B461A6043353C570BD72A1E1 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.16850_none_128f0019b5f25b8f\winsrv.dll
[2012.08.20 20:06:40 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=0E83424D4CEC0665A3A916AD6B261E53 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.21306_none_13548c10cee23265\winsrv.dll
[2012.08.20 19:27:20 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=111AFE35DD2D423EE8E176CA7B2BBDC7 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.22091_none_14d49672cc561df0\winsrv.dll
[2009.07.14 02:41:56 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=457B44AB6D502E55F64A867D4F35C76C -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.16385_none_12738849b6063c52\winsrv.dll
[2011.06.24 06:26:55 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=6D408ABD60A995A2DAB4BAAE38BCA04F -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.20995_none_12f25ea6cf2be9d0\winsrv.dll
[2012.08.18 16:42:31 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=79CDA06F75AD5373DD447F57575C4400 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7600.17107_none_12cbeda9b5c3aecb\winsrv.dll
[2011.06.24 06:27:05 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=C13D05A015346DED3D722BE285814495 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.21756_none_1504fba6cc30ff4f\winsrv.dll
[2010.11.20 14:27:28 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=E0406AEF04B088D1C49FC78D0546F689 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17514_none_14a49c11b2f4bfec\winsrv.dll
[2011.06.24 06:34:53 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=EB6A48CC998E1090E44E8E7F1009A640 -- C:\Windows\SysNative\winsrv.dll
[2011.06.24 06:34:53 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=EB6A48CC998E1090E44E8E7F1009A640 -- C:\Windows\winsxs\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17641_none_14812d55b30fc4e1\winsrv.dll
[2012.08.20 19:48:43 | 000,215,040 | ---- | M] (Microsoft Corporation) MD5=F46BBAAC1C4980F4D0DD463F190A42D3 -- C:\Windows\SoftwareDistribution\Download\8bc6d879943fb1718924ceb00f627453\amd64_microsoft-windows-winsrv_31bf3856ad364e35_6.1.7601.17932_none_148d033db306b9bc\winsrv.dll
< MD5 for: WS2_32.DLL >
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.20 14:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.20 13:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< MD5 for: WSCRIPT.EXE >
[2009.07.14 02:39:57 | 000,168,960 | ---- | M] (Microsoft Corporation) MD5=8886E0697B0A93C521F99099EF643450 -- C:\Windows\SysNative\wscript.exe
[2009.07.14 02:39:57 | 000,168,960 | ---- | M] (Microsoft Corporation) MD5=8886E0697B0A93C521F99099EF643450 -- C:\Windows\winsxs\amd64_microsoft-windows-scripting_31bf3856ad364e35_6.1.7600.16385_none_a45d44bd1a0af822\wscript.exe
[2009.07.14 02:14:49 | 000,141,824 | ---- | M] (Microsoft Corporation) MD5=D1AB72DB2BEDD2F255D35DA3DA0D4B16 -- C:\Windows\SysWOW64\wscript.exe
[2009.07.14 02:14:49 | 000,141,824 | ---- | M] (Microsoft Corporation) MD5=D1AB72DB2BEDD2F255D35DA3DA0D4B16 -- C:\Windows\winsxs\wow64_microsoft-windows-scripting_31bf3856ad364e35_6.1.7600.16385_none_aeb1ef0f4e6bba1d\wscript.exe
< >
< %systemroot%\system32\logevent.dll /md5 >
< %systemroot%\system32\sceclt.dll /md5 >
< %systemroot%\system32\ntelogon.dll /md5 >
< %systemroot%\system32\consrv.dll /md5 >
< >
< %systemroot%\system32\logevent.dll /md5 /64 >
< %systemroot%\system32\sceclt.dll /md5 /64 >
< %systemroot%\system32\ntelogon.dll /md5 /64 >
< %systemroot%\system32\consrv.dll /md5 /64 >
< >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.10.08 09:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2014.02.20 02:03:06 | 000,859,464 | ---- | M] (Google Inc.) MD5=6E6656C6618C4B0B000267D9AF9EF743 -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %systemroot%\system32\Spool\prtprocs\*.* /s >
[2009.07.14 02:41:12 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\x64\jnwppr.dll
[2011.06.22 06:48:28 | 000,036,864 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\system32\Spool\prtprocs\x64\ssp7mpc.dll
[2010.11.20 14:27:28 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\x64\winprint.dll
[2009.07.14 16:17:26 | 000,003,584 | ---- | M] (Lexmark International Inc.) -- C:\Windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
< %systemroot%\system32\drivers\*.sys /10 >
< %systemroot%\system32\drivers\*.sys /X >
[2009.06.10 22:14:29 | 003,440,660 | ---- | M] () -- C:\Windows\system32\drivers\gm.dls
[2009.06.10 22:14:29 | 000,000,646 | ---- | M] () -- C:\Windows\system32\drivers\gmreadme.txt
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\*.* /10 >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\*.* /lockedfiles >
< %systemroot%\system32\config\*.sav >
< >
< c:\$Recycle.Bin|L,N,U,@;true;true;true /FN >
< c:\Windows\Installer|L,N,U,@;true;true;true /FN >
< >
< %systemroot%\Tasks\*.job >
[2014.02.23 14:11:32 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014.02.23 14:52:00 | 000,000,952 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< %systemroot%\*.* /U /s >
[7 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[10 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[33 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp files -> C:\Windows\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp -> ]
[3 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp -> ]
[2 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp -> ]
[3 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\*.tmp -> ]
[2 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\*.tmp -> ]
[1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %systemroot%\*. /rp /s >
< %ALLUSERSPROFILE%\Data Aplikací\*.* >
< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
< %ALLUSERSPROFILE%\Nabídka Start\*.lnk /x >
< %ALLUSERSPROFILE%\Data Aplikácií\*.* >
< %ALLUSERSPROFILE%\Data Aplikácií\*.exe /s >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %APPDATA%\*. >
[2012.12.01 19:03:28 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\.gephi
[2012.12.02 09:31:04 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Adobe
[2012.09.13 20:53:43 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Ahead
[2013.07.23 18:52:41 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Ancestry
[2012.12.04 18:18:56 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Autodesk
[2013.07.21 21:22:46 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\avidemux
[2013.07.26 14:51:29 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Bitmeter2
[2014.02.01 12:14:51 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\BitSpirit
[2013.06.09 05:45:27 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Blender Foundation
[2013.08.09 09:24:00 | 000,000,000 | R--D | M] -- C:\Users\caesar\AppData\Roaming\Brother
[2013.01.20 15:53:57 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\BSplayer PRO
[2012.09.13 20:10:14 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Canneverbe Limited
[2013.06.10 09:06:47 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.12.01 22:11:16 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.12.18 18:50:42 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Corel
[2012.02.27 19:05:50 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools
[2014.02.18 21:53:55 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools Lite
[2014.02.18 21:53:55 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DAEMON Tools Pro
[2012.06.26 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DassaultSystemes
[2014.02.23 14:15:01 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Dropbox
[2012.08.16 08:12:36 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\dvdcss
[2013.04.15 16:55:38 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\DVDVideoSoft
[2012.12.27 18:29:28 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Edraw Max
[2012.12.01 10:12:24 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\GetRightToGo
[2013.02.23 16:37:37 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\GHISLER
[2012.07.13 09:16:18 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\gtk-2.0
[2012.02.13 18:51:00 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Identities
[2014.02.18 21:53:54 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\inkscape
[2012.02.13 23:15:05 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\InstallShield
[2012.06.27 07:55:06 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\KeePass
[2012.02.14 14:57:34 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Macromedia
[2012.10.01 14:31:56 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mathsoft
[2012.03.20 19:48:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\MathWorks
[2009.07.14 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Media Center Programs
[2013.07.03 15:12:57 | 000,000,000 | --SD | M] -- C:\Users\caesar\AppData\Roaming\Microsoft
[2012.02.14 14:00:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Miranda
[2012.07.17 10:16:44 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mobile Atlas Creator
[2012.07.07 13:21:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Mozilla
[2012.08.07 20:44:03 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Nokia
[2013.02.23 15:33:20 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Notepad++
[2012.08.07 20:36:52 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\PC Suite
[2012.12.02 09:31:19 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.08.06 15:30:50 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\STV Software
[2012.07.18 15:09:57 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\TeamViewer
[2012.07.07 13:21:32 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Thunderbird
[2014.02.19 17:34:52 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\vlc
[2012.07.07 13:00:13 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\Windows Live Writer
[2012.02.14 09:15:04 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\WinRAR
[2013.12.07 20:52:36 | 000,000,000 | ---D | M] -- C:\Users\caesar\AppData\Roaming\XnView
< %APPDATA%\*.* >
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] (xRgizs9q02T) -- C:\Users\caesar\AppData\Roaming\Windows.exe
< %APPDATA%\*.exe /s >
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] (xRgizs9q02T) -- C:\Users\caesar\AppData\Roaming\Windows.exe
[2014.01.03 01:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2014.01.03 01:47:26 | 000,229,288 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2012.12.04 00:43:48 | 000,880,672 | ---- | M] (Dropbox, Inc.) -- C:\Users\caesar\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2013.06.10 09:07:16 | 000,055,424 | ---- | M] (Adobe Systems Inc.) -- C:\Users\caesar\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2014.02.23 14:13:47 | 001,569,280 | ---- | M] () -- C:\Users\caesar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\52ae9a9b35c8ca9d61a092e4ad35cca9.exe
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32|bak;true;false;false /fp >
< %PROGRAMFILES%|bak;true;false;false /fp >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.20 14:25:17 | 001,475,584 | ---- | M] (Microsoft Corporation)
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.02.13 09:06:56 | 003,481,408 | ---- | M] (DT Soft Ltd)
"OscarX7Mouse5Mode" = "C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe" Minimum -- [2012.03.20 16:52:10 | 003,521,024 | ---- | M] ()
"AdobeBridge" =
< End of report >