========== Purity Check ==========
========== Custom Scans ==========
< >
[2012.03.28 12:34:52 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2012.03.28 12:39:33 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.09.09 13:27:46 | 000,000,830 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.09.16 00:51:17 | 000,000,278 | ---- | C] () -- C:\WINDOWS\Tasks\SoundTapReminder.job
[2012.09.16 00:51:17 | 000,000,278 | ---- | C] () -- C:\WINDOWS\Tasks\SoundTapSevenDays.job
[2012.10.25 20:21:40 | 000,000,274 | ---- | C] () -- C:\WINDOWS\Tasks\WavePadDowngrade.job
[2013.10.15 14:59:36 | 000,000,916 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2013.10.15 14:59:36 | 000,000,920 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2014.03.23 01:09:25 | 000,000,276 | ---- | C] () -- C:\WINDOWS\Tasks\WavePadReminder.job
[2014.03.28 20:34:26 | 000,000,216 | ---- | C] () -- C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014.03.28 20:34:26 | 000,000,222 | ---- | C] () -- C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014.04.25 22:46:00 | 000,000,964 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1006Core.job
[2014.04.25 22:46:01 | 000,001,016 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1078145449-839522115-1006UA.job
< >
< MD5 for: AGP440.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\erdnt\cache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2006.02.28 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe
[2008.04.14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2006.02.28 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.02.28 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2006.02.28 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\erdnt\cache\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\erdnt\cache\eventlog.dll
[2008.04.14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2006.02.28 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
[2006.02.28 14:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.02.28 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.04.14 00:06:42 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 00:06:42 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2006.02.28 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=E504F706CCB699C2596E9A3DA1596E87 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
< MD5 for: LSASS.EXE >
[2006.02.28 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\erdnt\cache\lsass.exe
[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\erdnt\cache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2006.02.28 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\erdnt\cache\netlogon.dll
[2008.04.14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2006.02.28 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVGTS.SYS >
[2010.04.09 02:30:10 | 000,168,040 | ---- | M] (NVIDIA Corporation) MD5=52DCE3B30C9D61C8E20FE3C6DA4BDFB7 -- C:\Documents and Settings\Mato\Desktop\Plocha\ovladace\Chipset_V1556_XP32bit\Chipset_V15.56_XP32bit\IDE\WinXP\sata_ide\nvgts.sys
[2010.04.09 02:30:10 | 000,168,040 | ---- | M] (NVIDIA Corporation) MD5=52DCE3B30C9D61C8E20FE3C6DA4BDFB7 -- C:\WINDOWS\system32\drivers\nvgts.sys
[2010.04.09 02:30:10 | 000,168,040 | ---- | M] (NVIDIA Corporation) MD5=52DCE3B30C9D61C8E20FE3C6DA4BDFB7 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\nvgts.sys
[2010.04.09 02:30:28 | 000,168,040 | ---- | M] (NVIDIA Corporation) MD5=87096913DFB9129144E1038AADFF17EE -- C:\Documents and Settings\Mato\Desktop\Plocha\ovladace\Chipset_V1556_XP32bit\Chipset_V15.56_XP32bit\IDE\WinXP\sataraid\nvgts.sys
< MD5 for: NVRD32.SYS >
[2010.04.09 02:30:28 | 000,139,368 | ---- | M] (NVIDIA Corporation) MD5=587E8634A13B682FA39E0DA48CA88ED5 -- C:\Documents and Settings\Mato\Desktop\Plocha\ovladace\Chipset_V1556_XP32bit\Chipset_V15.56_XP32bit\IDE\WinXP\sataraid\nvrd32.sys
< MD5 for: SCECLI.DLL >
[2006.02.28 14:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe
[2006.02.28 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.04 00:56:58 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=DA5CF1C368B33D75602FD6B3A7F5E0C6 -- C:\cmdcons\SYSTEM32\SMSS.EXE
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2006.02.28 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\erdnt\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.02.28 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2006.02.28 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.02.28 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\erdnt\cache\ws2_32.dll
[2008.04.14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
[2006.02.28 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[24 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[6 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2012.10.22 20:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2014.04.13 17:10:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\792004a728ea8548
[2012.09.09 13:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012.04.20 23:42:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2012.10.22 20:16:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2012.03.28 13:35:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2014.04.29 20:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Assistant
[2013.05.13 13:17:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2012.03.31 13:46:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2014.04.01 19:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJ
[2014.05.14 10:58:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2012.03.31 13:57:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2012.03.31 13:52:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2014.05.14 10:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2012.10.08 11:57:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2012.03.31 13:52:19 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2012.07.24 14:39:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2013.09.11 18:02:07 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\DSS
[2013.09.17 16:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2014.04.29 20:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ExstrauSSavings
[2012.04.20 14:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2013.10.12 22:31:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\id Software
[2014.03.25 22:33:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2012.08.19 11:41:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JAGUAR
[2013.10.03 15:21:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2014.04.28 19:08:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012.03.29 21:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2014.01.15 12:07:38 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2014.05.15 10:25:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012.05.04 15:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012.07.26 19:31:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MySQL
[2012.11.03 13:27:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Software
[2012.10.25 20:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2013.09.17 16:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin
[2014.04.13 08:33:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Package Cache
[2014.03.25 22:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Puresafe
[2012.08.24 13:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Remedy
[2014.03.25 22:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\safeweB
[2013.10.13 19:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2014.03.05 17:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2013.06.28 15:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2013.04.20 19:51:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Steam
[2012.04.06 00:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012.08.11 18:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2012.03.28 13:25:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2013.12.27 00:13:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012.04.20 23:43:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2012.08.21 13:01:28 | 001,977,816 | ---- | M] (GEAR Software, Inc.) -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1\GEARDIFx.exe
[2012.08.21 13:01:22 | 000,115,672 | ---- | M] (GEAR Software, Inc.) -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\DifXInst32.exe
[2012.01.03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.0\3540\AcrobatUpdater.exe
[2012.01.03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.0\3540\AdobeARM.exe
[2012.01.03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.0\3540\AdobeARMHelper.exe
[2012.01.03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.0\3540\ReaderUpdater.exe
[2012.12.03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.4\30793\AcrobatUpdater.exe
[2012.12.03 09:35:28 | 000,946,352 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.4\30793\AdobeARM.exe
[2012.12.03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.4\30793\AdobeARMHelper.exe
[2012.12.03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.4\30793\ReaderUpdater.exe
[2013.04.04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.6\9666\AcrobatUpdater.exe
[2013.04.04 23:06:36 | 000,958,576 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.6\9666\AdobeARM.exe
[2013.04.04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.6\9666\AdobeARMHelper.exe
[2013.04.04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.6\9666\ReaderUpdater.exe
[2013.11.21 18:57:26 | 000,342,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.8\26928\AcrobatUpdater.exe
[2013.11.21 18:57:26 | 000,959,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.8\26928\AdobeARM.exe
[2013.11.21 18:57:26 | 000,342,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.8\26928\AdobeARMHelper.exe
[2013.11.21 18:57:26 | 000,342,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.8\26928\ReaderUpdater.exe
[2011.06.06 22:45:23 | 001,560,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1029-7B44-AA1000000001}\setup.exe
[2012.10.22 20:11:14 | 000,073,624 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.7.0.21\SetupAdmin.exe
[2014.03.23 00:42:27 | 011,455,808 | ---- | M] (Electronic Arts) -- C:\Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe
[2012.04.20 14:45:53 | 001,053,198 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger\update\12069\GarenaMessenger.exe
[2012.04.20 14:45:54 | 000,102,036 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger\update\12069\PluginAdminExec.exe
[2012.04.20 14:46:08 | 000,100,676 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger\update\12069\UpdateEx.exe
[2012.11.30 03:09:14 | 000,015,528 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Application Data\InstallMate\{307AE154-8BDE-4A70-A89B-C3FCEB99C3A2}\Setup.exe
[2013.03.12 10:59:14 | 000,015,968 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Application Data\InstallMate\{530B5127-30B6-41B4-A35F-789488E873D1}\Setup.exe
[2013.03.12 10:59:14 | 000,015,968 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Application Data\InstallMate\{62A144B0-3DA5-4875-AA9E-7587B9426646}\Setup.exe
[2012.04.23 03:14:15 | 000,015,496 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Application Data\InstallMate\{C1E28B35-42CA-43F0-8B8B-85F6E7255916}\Setup.exe
[2012.11.30 03:09:14 | 000,015,528 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\Documents and Settings\All Users\Application Data\InstallMate\{DF431D30-7AC8-4947-ABAC-32EA04A03FC6}\Setup.exe
[2014.04.12 14:11:18 | 000,457,880 | ---- | M] (Корпорация Майкрософт) -- C:\Documents and Settings\All Users\Application Data\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
[2014.03.25 22:31:38 | 000,424,448 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\safeweB\4iT.exe
[2013.10.09 10:58:16 | 003,275,136 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
< %APPDATA%\*. >
[2013.03.19 20:31:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\.minecraft
[2012.12.09 12:48:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\.minecraftsl
[2013.04.07 16:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\.Torrent Stream
[2012.08.11 14:31:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Adobe
[2013.06.29 15:06:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Apple Computer
[2012.12.23 20:05:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Ashampoo
[2014.01.19 13:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\BANDISOFT
[2012.10.08 11:57:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Canon
[2012.07.24 14:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\DAEMON Tools Lite
[2012.04.06 14:48:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\DonationCoder
[2012.08.22 16:02:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Dropbox
[2014.01.23 00:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\dvdcss
[2013.07.10 11:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\DVDVideoSoft
[2012.07.25 21:23:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\GameRanger
[2012.04.20 13:23:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Garena
[2012.04.20 14:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\GarenaPlus
[2012.08.10 00:15:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\GHISLER
[2012.03.28 19:47:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Identities
[2012.04.01 21:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Leadertech
[2012.03.28 19:50:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Macromedia
[2014.04.28 19:08:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Malwarebytes
[2012.07.13 22:10:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\MAXON
[2013.10.17 19:41:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Mato\Application Data\Microsoft
[2012.08.12 12:10:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Mozilla
[2012.07.26 19:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\MySQL
[2012.11.03 13:27:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\NCH Software
[2012.10.25 20:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\NCH Swift Sound
[2012.07.17 22:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Need for Speed World
[2012.08.04 23:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\NVIDIA
[2012.03.28 20:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\OpenOffice.org
[2013.03.02 13:01:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Opera
[2013.09.11 16:52:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Origin
[2012.07.26 23:53:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\PSpad
[2013.06.29 12:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Publish Providers
[2012.08.02 10:32:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\PunkBuster
[2012.10.22 20:04:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\redsn0w
[2012.11.25 15:07:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Rovio
[2012.06.16 12:52:51 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Mato\Application Data\SecuROM
[2014.01.25 20:05:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Skype
[2013.06.29 12:58:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Sony
[2012.06.02 13:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Sports Interactive
[2013.03.02 17:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\StreamTorrent
[2012.04.06 00:44:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Sun
[2013.04.16 19:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\TeamViewer
[2013.03.02 17:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\TorrentStream
[2013.02.13 19:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\TS3Client
[2012.07.10 16:00:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\TuneUpMedia
[2012.08.02 10:41:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Ubisoft
[2014.01.16 23:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Unity
[2014.05.01 09:10:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\uTorrent
[2012.07.21 00:27:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\VDownloader
[2014.02.26 16:05:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\vlc
[2013.01.02 14:03:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\Wargaming.net
[2012.03.29 18:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mato\Application Data\WinRAR
< %APPDATA%\*.exe /s >
[2012.10.27 16:29:45 | 001,486,560 | ---- | M] (GameRanger Technologies) -- C:\Documents and Settings\Mato\Application Data\GameRanger\GameRanger\GameRanger.exe
[2012.03.29 14:07:04 | 000,015,872 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C9.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_094D2999E03AF067E6C5DD.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_1324D739AAFBC438F5DF5F.exe
[2012.08.16 01:09:40 | 000,005,430 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_1AB13FACDDE6955FB8A230.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_424C98A5BFF6DCA1DAE5AA.exe
[2012.08.16 01:09:40 | 000,013,262 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_468CFA8A7E114B58D146CF.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_48052E75363D0C07BD1414.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_498497E0B3A19E434C34D4.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_4E163F42BA37980EA26431.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_5136A5F2DDCC0D3A910F9D.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_67C82776DA9B2BD2EB5CB6.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_6FEFF9B68218417F98F549.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_7572D79E3B577574CBB073.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_77654C49366B8066FC67A3.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_7E89081F3BF7470C4D96D2.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_8B7EEDD38F13EE503C777F.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_8FB306F005534A5F8F402B.exe
[2012.08.16 01:09:40 | 000,013,262 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_980D59E01FA54B6F16CD02.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_993F095DA040DDF2E96980.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_A3706132CB87E4F6FEBBC8.exe
[2012.08.16 01:09:40 | 000,009,662 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_CBE8F7724EE29FD3761298.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_CD14D44FFAEB27F11907E1.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_CE3B7AE2615BF6D60CFA40.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_D8815CCC03F12BBA2E8FF2.exe
[2012.08.16 01:09:40 | 000,005,430 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_DE23B4B754846A2F62380B.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_E3A6692DA78EA6348F46BB.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_F4CF425756336027E951C6.exe
[2012.08.16 01:09:40 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\Microsoft\Installer\{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}\_FBB40E0B40EF52A434900A.exe
[2011.02.24 17:07:45 | 000,835,440 | R--- | M] () -- C:\Documents and Settings\Mato\Application Data\PunkBuster\pbsetup\pbsvc.exe
[2013.03.02 17:11:29 | 000,150,214 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\Uninstall.exe
[2013.02.27 22:12:20 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\backup\last\tsengine.exe
[2013.02.27 22:12:22 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\backup\last\tsengine_stream.exe
[2013.02.27 22:12:20 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\download\2.0.8.5\tsengine.exe
[2013.02.27 22:12:22 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\download\2.0.8.5\tsengine_stream.exe
[2013.03.06 13:10:44 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\download\2.0.8.6\tsengine.exe
[2013.03.06 13:10:44 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\.data\engine2\download\2.0.8.6\tsengine_stream.exe
[2013.03.06 13:10:44 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\engine\tsengine.exe
[2013.03.06 13:10:44 | 000,026,744 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\engine\tsengine_stream.exe
[2011.06.12 15:05:52 | 000,049,664 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\engine\w9xpopen.exe
[2012.11.29 15:56:24 | 000,098,936 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\player\tsplayer.exe
[2012.11.29 15:56:24 | 000,039,544 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\player\vlc-cache-gen.exe
[2012.10.26 15:43:52 | 000,026,232 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\updater\tsupdate.exe
[2011.06.12 15:05:52 | 000,049,664 | ---- | M] () -- C:\Documents and Settings\Mato\Application Data\TorrentStream\updater\w9xpopen.exe
[2013.02.02 20:01:54 | 001,075,024 | ---- | M] (BitTorrent Inc.) -- C:\Documents and Settings\Mato\Application Data\uTorrent\uTorrent.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2012.03.28 14:26:40 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2012.03.28 14:26:40 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2012.03.28 14:26:40 | 000,888,832 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:42:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.05.22 22:44:23 | 000,000,512 | ---- | M] () MD5=63035BC7840E52C5956ECE7C3472373A -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2014.03.26 11:04:44 | 002,063,765 | R--- | M] () -- \Castlevania.Lord.of.Shadow.2-WOLVERDONFILMES.COM\rld-cvanialos2\CLoS Crack FLT.7z
[2013.09.30 16:31:07 | 234,356,440 | ---- | M] () -- \Documents and Settings\Mato\Desktop\FL-Studio-10.0.9c-Producer-Edition-+-crack-a-český-návod-na-instalaci........HANZY.zip
[2012.02.26 11:12:08 | 009,872,653 | ---- | M] () -- \Documents and Settings\Mato\Desktop\PhotoShopCS4\Textures\crackedtextures.rar
[2012.10.10 15:45:03 | 016,707,995 | ---- | M] () -- \Documents and Settings\Mato\Desktop\Plocha\Crack.rar
[1 \Documents and Settings\Mato\Desktop\Plocha\*.tmp files -> \Documents and Settings\Mato\Desktop\Plocha\*.tmp -> ]
[2012.02.26 11:12:08 | 009,872,653 | ---- | M] () -- \Documents and Settings\Mato\Desktop\Plocha\PhotoShopCS4\Textures\crackedtextures.rar
[2013.12.30 00:28:01 | 000,001,062 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\ftblauncher\ModPacks\MindCrack\logo_minecrack.png
[2013.12.30 00:28:01 | 000,008,681 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\ftblauncher\ModPacks\MindCrack\mindcrack_splash.png
[2014.03.26 11:04:35 | 000,002,608 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\uTorrent\CLoS Crack FLT.7z.torrent
[2012.11.18 10:51:02 | 000,020,518 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\uTorrent\GTA SAN ANDREAS + CRACK + SA-MP.1.torrent
[2012.11.18 10:45:18 | 000,020,518 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\uTorrent\GTA SAN ANDREAS + CRACK + SA-MP.torrent
[2013.01.23 14:50:47 | 000,695,296 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Preberanie\Minecraft-AnjoCaido-(cracked).exe
[2012.07.24 21:59:09 | 172,331,269 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Stažené soubory\Assassins-Creed-Revelations---CRACK.rar
[2012.10.19 08:56:10 | 009,962,246 | ---- | M] () -- \Program Files\Image-Line\FL Studio 10\Fl Studio 10 Crack.....HANZY.exe
[2008.09.08 22:55:14 | 000,000,204 | ---- | M] () -- \Program Files\Image-Line\FL Studio 10\Plugins\Fruity\Effects\Hardcore\Presets\I cracked my Tube!.hdprg
[2010.01.15 22:56:40 | 000,000,272 | ---- | M] () -- \Program Files\Image-Line\FL Studio 10\Plugins\Fruity\Generators\Drumaxx\Drum Patches\Sound FX\Crack.dmpatch
[2010.01.15 22:56:40 | 000,000,272 | ---- | M] () -- \Program Files\Image-Line\FL Studio 10\Plugins\Fruity\Generators\DrumPad\Drum Patches\Sound FX\Crack.dmpatch
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2014.01.16 13:19:45 | 000,004,361 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\js\chromeBackstageLoader.js.vir
[2014.01.16 13:19:46 | 000,003,100 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\js\pluginLoader.js.vir
[2014.01.16 13:19:32 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.01.16 13:19:32 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\tb\al\ac\img\loader-icon.png.vir
[2014.01.16 13:19:29 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\tb\al\ui\gf\img\loader.gif.vir
[2014.01.16 13:19:26 | 000,001,849 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.15.0.62_0\tb\al\wa\TWITTER\resources\ajax-loader.gif.vir
[2014.01.16 13:22:37 | 000,048,624 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.0.540_0\js\chromeBackstageLoader.js.vir
[2014.01.16 13:22:34 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.0.540_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.01.16 13:22:35 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.0.540_0\tb\al\ac\img\loader-icon.png.vir
[2014.01.16 13:22:33 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.0.540_0\tb\al\ui\gf\img\loader.gif.vir
[2014.01.16 13:22:21 | 000,004,069 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.20.101.5_0\js\chromeBackstageLoader.js.vir
[2014.01.16 13:22:21 | 000,003,100 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.20.101.5_0\js\pluginLoader.js.vir
[2014.01.16 13:22:20 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.20.101.5_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.01.16 13:22:20 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.20.101.5_0\tb\al\ac\img\loader-icon.png.vir
[2014.01.16 13:22:17 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.20.101.5_0\tb\al\ui\gf\img\loader.gif.vir
[2014.03.16 17:25:13 | 000,048,683 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\js\chromeBackstageLoader.js.vir
[2014.03.16 17:25:13 | 000,003,100 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\js\pluginLoader.js.vir
[2014.03.16 17:25:10 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.03.16 17:25:10 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\tb\al\ac\img\loader-icon.png.vir
[2014.03.16 17:25:09 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\tb\al\ui\gf\img\loader.gif.vir
[2014.01.16 13:19:52 | 000,002,082 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.13.20.29_0\js\pluginLoader.js.vir
[2014.01.16 13:19:50 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.13.20.29_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.01.16 13:19:50 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.13.20.29_0\tb\al\ac\img\loader-icon.png.vir
[2014.01.16 13:19:48 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.13.20.29_0\tb\al\ui\gf\img\loader.gif.vir
[2014.01.16 13:19:37 | 000,001,849 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.13.20.29_0\tb\al\wa\TWITTER\resources\ajax-loader.gif.vir
[2014.01.16 13:22:52 | 000,048,624 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.0.540_0\js\chromeBackstageLoader.js.vir
[2014.01.16 13:22:49 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.0.540_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.01.16 13:22:49 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.0.540_0\tb\al\ac\img\loader-icon.png.vir
[2014.01.16 13:22:49 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mamina\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.0.540_0\tb\al\ui\gf\img\loader.gif.vir
[2012.07.05 12:54:37 | 000,000,264 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mato\Application Data\dvdvideosoftiehelpers\freeytvdownloader.htm.vir
[2014.02.12 11:14:49 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\Extensions\{124d001a-bdcb-472f-aa59-bbe7e4bc3204}\Chrome\CT2481032\content\tb\al\ac\img\ajax-loader.gif.vir
[2014.02.12 11:14:50 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\Extensions\{124d001a-bdcb-472f-aa59-bbe7e4bc3204}\Chrome\CT2481032\content\tb\al\ac\img\loader-icon.png.vir
[2014.02.12 11:14:51 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Mato\Application Data\Mozilla\Firefox\Profiles\q2j5jg21.default\Extensions\{124d001a-bdcb-472f-aa59-bbe7e4bc3204}\Chrome\CT2481032\content\tb\al\ui\gf\img\loader.gif.vir
[2012.07.23 08:11:21 | 000,216,359 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\autth4pj.default\Extensions\
OneClickDownloader@OneClickDownloader.com.xpi.vir
[2014.02.07 21:54:20 | 000,048,624 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.4.512_1\js\chromeBackstageLoader.js.vir
[2014.02.07 21:54:16 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.4.512_1\tb\al\ac\img\ajax-loader.gif.vir
[2014.02.07 21:54:16 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.4.512_1\tb\al\ac\img\loader-icon.png.vir
[2014.02.07 21:54:15 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp\10.26.4.512_1\tb\al\ui\gf\img\loader.gif.vir
[2014.02.08 09:29:11 | 000,048,624 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.4.512_0\js\chromeBackstageLoader.js.vir
[2014.02.08 09:29:09 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.4.512_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.02.08 09:29:09 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.4.512_0\tb\al\ac\img\loader-icon.png.vir
[2014.02.08 09:29:08 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.4.512_0\tb\al\ui\gf\img\loader.gif.vir
[2014.02.08 09:28:58 | 000,048,624 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.4.512_0\js\chromeBackstageLoader.js.vir
[2014.02.08 09:28:55 | 000,000,847 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.4.512_0\tb\al\ac\img\ajax-loader.gif.vir
[2014.02.08 09:28:55 | 000,001,135 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.4.512_0\tb\al\ac\img\loader-icon.png.vir
[2014.02.08 09:28:53 | 000,003,208 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ggagiiobgjmfpdadhecbofeoelcpidec\10.26.4.512_0\tb\al\ui\gf\img\loader.gif.vir
[2013.09.11 03:15:30 | 000,006,820 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\SafetyNut\SRTOOL~1\IE\chrome\skin\lib\panels\images\ajax-loader.gif.vir
[2012.06.02 08:58:54 | 000,004,068 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\GFX\_RadialFlareLoader_Double.gfx
[2012.04.20 14:45:48 | 000,014,515 | ---- | M] () -- \Documents and Settings\All Users\Application Data\GarenaMessenger\update\12069\FileLoader.dll
[2012.07.05 12:54:25 | 000,001,168 | ---- | M] () -- \Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft\Programs\Free Uploader for Facebook.lnk
[2012.07.05 12:54:25 | 000,001,113 | ---- | M] () -- \Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube Uploader.lnk
[2014.05.16 18:34:56 | 000,004,006 | ---- | M] () -- \Documents and Settings\Mamina\Local Settings\Temporary Internet Files\Content.IE5\BD5KNUBH\uploaderapi2[2].swf
[2012.07.17 14:18:28 | 000,009,051 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.07.17 14:18:28 | 000,016,119 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.07.17 14:18:28 | 000,018,434 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.07.17 14:18:28 | 000,009,283 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.07.17 14:18:28 | 000,001,898 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\NewsLoader.js
[2012.05.30 16:21:28 | 000,008,378 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DVDVideoSoft\backup\FreeYTVDownloader\FreeYTVDownloaderProfile.xml
[2012.05.30 16:21:28 | 000,008,378 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DVDVideoSoft\FreeYTVDownloader\FreeYTVDownloaderProfile.xml
[2012.10.24 21:01:21 | 000,177,718 | ---- | M] () -- \Documents and Settings\Mato\Application Data\DVDVideoSoft\logs\FreeYTVDownloader_v1.log
[2012.04.18 00:39:24 | 000,010,145 | ---- | M] () -- \Documents and Settings\Mato\Application Data\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\modules\ExternalLibraryLoader.jsm
[2012.02.07 18:37:14 | 000,008,192 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\engine\lib\_win32sysloader.pyd
[2012.09.13 14:09:56 | 000,000,553 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\fs\default\1024\loader.png
[2012.09.13 14:09:56 | 000,000,686 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\fs\default\1280\loader.png
[2012.09.13 14:09:56 | 000,000,686 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\fs\default\1600\loader.png
[2012.09.13 14:09:56 | 000,001,239 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\fs\default\1920\loader.png
[2012.09.13 14:09:56 | 000,000,453 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\fs\default\800\loader.png
[2012.09.13 14:09:56 | 000,000,477 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\player\skins\nofs\default\playlist\loader.png
[2012.02.07 18:37:14 | 000,008,192 | ---- | M] () -- \Documents and Settings\Mato\Application Data\TorrentStream\updater\lib\_win32sysloader.pyd
[2012.02.13 14:23:18 | 002,760,702 | ---- | M] () -- \Documents and Settings\Mato\Desktop\PhotoShopCS4\MojeVýtvory\uploader_des+.psd
[2012.02.13 14:23:18 | 002,760,702 | ---- | M] () -- \Documents and Settings\Mato\Desktop\Plocha\PhotoShopCS4\MojeVýtvory\uploader_des+.psd
[2014.05.05 16:08:46 | 001,103,814 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\attack-of-the-bteam\ForgeModLoader-client-0.log
[2014.05.05 16:06:16 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\attack-of-the-bteam\ForgeModLoader-client-0.log.lck
[2014.03.09 17:56:07 | 001,263,930 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\attack-of-the-bteam\ForgeModLoader-client-1.log
[2014.03.09 17:40:37 | 000,000,068 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\attack-of-the-bteam\config\TConPreloader.cfg
[2014.03.09 17:55:56 | 000,000,004 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\attack-of-the-bteam\saves\New World\galacticraft\chunkloaders.dat
[2014.05.05 16:42:02 | 000,298,093 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\carovny-minecraft-verze-41\ForgeModLoader-client-0.log
[2014.05.05 16:32:34 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\carovny-minecraft-verze-41\ForgeModLoader-client-0.log.lck
[2014.01.11 11:43:42 | 000,864,579 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\hexxit\ForgeModLoader-client-0.log
[2014.01.11 11:34:11 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\hexxit\ForgeModLoader-client-0.log.lck
[2014.01.11 11:33:44 | 000,844,960 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\hexxit\ForgeModLoader-client-1.log
[2013.12.28 18:46:03 | 000,646,473 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\hexxit\ForgeModLoader-client-2.log
[2014.05.05 16:17:16 | 000,064,138 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkit\ForgeModLoader-0.log
[2014.05.05 16:12:14 | 000,001,980 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkit\mods\ComputerCraft\org\luaj\vm2\luajc\JavaLoader.class
[2013.12.17 10:55:01 | 000,489,026 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkitlite\ForgeModLoader-client-0.log
[2013.12.17 10:28:53 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkitlite\ForgeModLoader-client-0.log.lck
[2013.12.28 18:34:53 | 000,424,429 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkitmain\ForgeModLoader-client-0.log
[2013.12.28 18:30:39 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkitmain\ForgeModLoader-client-0.log.lck
[2013.12.28 18:28:59 | 000,422,235 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\.technic\modpacks\tekkitmain\ForgeModLoader-client-1.log
[2012.07.17 14:18:28 | 000,009,051 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.07.17 14:18:28 | 000,016,119 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.07.17 14:18:28 | 000,018,434 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.07.17 14:18:28 | 000,009,283 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.07.17 14:18:28 | 000,001,898 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\NewsLoader.js
[2012.05.30 16:21:28 | 000,008,378 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\DVDVideoSoft\FreeYTVDownloader\FreeYTVDownloaderProfile.xml
[2012.10.14 08:24:06 | 000,001,765 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\MP3 Downloader.lnk
[2013.07.27 08:00:30 | 000,000,847 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\ac\img\ajax-loader.gif
[2013.07.27 08:00:30 | 000,001,135 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\ac\img\loader-icon.png
[2013.07.27 08:00:30 | 000,003,208 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\ui\gf\img\loader.gif
[2013.07.27 08:00:31 | 000,001,849 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\wa\TWITTER\resources\ajax-loader.gif
[2013.07.27 08:00:27 | 000,000,847 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\chrome\CT3289075\content\tb\al\ac\img\ajax-loader.gif
[2013.07.27 08:00:21 | 000,001,135 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\chrome\CT3289075\content\tb\al\ac\img\loader-icon.png
[2013.07.27 08:00:23 | 000,003,208 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\chrome\CT3289075\content\tb\al\ui\gf\img\loader.gif
[2013.07.27 08:00:23 | 000,001,849 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\chrome\CT3289075\content\tb\al\wa\TWITTER\resources\ajax-loader.gif
[2012.11.13 03:12:56 | 000,001,607 | ---- | M] () -- \Documents and Settings\Tomas\Desktop\iné\Staré údaje Firefoxu\extensions\
ffxtlbr@delta.com\content\loader.xul
[2012.06.27 21:56:46 | 000,002,920 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\YIV9AST8\vdownloader[1].xml
[2014.01.28 20:35:56 | 000,072,638 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Skype\Apps\login\images\loader.gif
[2014.01.28 20:35:56 | 000,003,032 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Skype\Apps\login\images\loader.png
[2014.01.28 20:35:56 | 000,006,012 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Skype\Apps\login\images\normal\loader_15fps.gif
[2014.01.28 20:35:56 | 000,021,956 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Skype\Apps\login\images\normal\loader_30fps.gif
[2014.01.28 20:35:56 | 000,009,772 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Application Data\Skype\Apps\login\images\retina\
loader@2x.png
[2014.05.22 07:47:02 | 000,001,976 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\GSW24V79\AdLoader[1].htm
[2014.05.17 19:15:39 | 000,000,353 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\TPG6X7ZC\queryLoader[1].css
[2014.05.17 19:15:44 | 000,005,505 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\TPG6X7ZC\queryLoader[1].js
[2014.05.20 19:23:23 | 000,017,912 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\AdLoader-3b8e790904fffcf74f96367cd382e261.min[1].js
[2014.05.14 16:54:03 | 000,112,122 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\AdLoader-7b473315d0084c71df83cdee72aab144.min[1].js
[2014.05.21 18:55:34 | 000,001,976 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\AdLoader[2].htm
[2014.05.20 07:41:27 | 000,001,870 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\AdLoader[3].htm
[2014.05.22 08:45:29 | 000,000,353 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\queryLoader[1].css
[2014.05.22 08:45:35 | 000,005,505 | ---- | M] () -- \Documents and Settings\Tomas\Local Settings\Temporary Internet Files\Content.IE5\XE6XBT29\queryLoader[1].js
[2012.10.03 14:48:40 | 000,096,810 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\DVDVideoSoft\FreeYTVDownloader_v1.log
[2013.12.30 01:17:07 | 000,082,472 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Preberanie\Unleashed\minecraft\ForgeModLoader-client-0.log
[2013.12.30 01:16:39 | 000,000,000 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Preberanie\Unleashed\minecraft\ForgeModLoader-client-0.log.lck
[2013.12.30 01:04:33 | 000,827,172 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Preberanie\Unleashed\minecraft\ForgeModLoader-client-1.log
[2013.12.30 00:58:23 | 000,832,277 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Preberanie\Unleashed\minecraft\ForgeModLoader-client-2.log
[2012.04.13 22:32:40 | 016,800,525 | ---- | M] () -- \Documents and Settings\Tomas\My Documents\Stažené soubory\VDownloaderSetup.exe
[2012.08.27 21:33:18 | 000,008,827 | ---- | M] () -- \Program Files\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2012.06.27 21:23:54 | 000,938,144 | ---- | M] () -- \Program Files\Common Files\DVDVideoSoft\Dll\DVSVideoDownloader.dll
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2014.03.24 21:47:38 | 000,268,440 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2014.03.24 21:47:38 | 000,019,104 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2010.01.29 06:43:52 | 000,071,008 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2003.09.26 08:15:26 | 000,169,384 | ---- | M] () -- \Program Files\Valve\cstrike\models\qloader.mdl
[2013.10.23 22:07:40 | 000,007,825 | ---- | M] () -- \Program Files\Valve\Steam\remoteui\static\libs\images\ajax-loader.gif
[2013.02.17 01:02:12 | 000,169,384 | ---- | M] () -- \Program Files\Valve\Steam\SteamApps\common\Half-Life\cstrike\models\qloader.mdl
[2013.02.17 00:59:11 | 000,352,548 | ---- | M] () -- \Program Files\Valve\Steam\SteamApps\common\Half-Life\valve\models\loader.mdl
[2013.02.17 00:59:33 | 000,012,764 | ---- | M] () -- \Program Files\Valve\Steam\SteamApps\common\Half-Life\valve\sound\ambience\loader_hydra1.wav
[2013.02.17 00:59:33 | 000,012,164 | ---- | M] () -- \Program Files\Valve\Steam\SteamApps\common\Half-Life\valve\sound\ambience\loader_step1.wav
[2003.09.26 14:19:52 | 000,352,548 | ---- | M] () -- \Program Files\Valve\valve\models\loader.mdl
[2003.09.26 14:24:16 | 000,012,764 | ---- | M] () -- \Program Files\Valve\valve\sound\ambience\loader_hydra1.wav
[2003.09.26 14:24:16 | 000,012,164 | ---- | M] () -- \Program Files\Valve\valve\sound\ambience\loader_step1.wav
[2010.03.15 11:28:24 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2013.06.06 18:50:00 | 000,499,712 | R--- | M] () -- \Program Files\WinZip\adxloader.dll
[2013.06.06 18:50:00 | 000,000,348 | ---- | M] () -- \Program Files\WinZip\adxloader.dll.manifest
[2013.06.06 18:50:00 | 000,704,000 | R--- | M] () -- \Program Files\WinZip\adxloader64.dll
[2013.12.25 20:52:54 | 000,000,404 | ---- | M] () -- \Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.90\deploy\assets\storeImages\layout\small_loader.gif
[2006.02.28 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2008.04.14 05:41:54 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.14 00:01:44 | 000,230,400 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 00:01:46 | 000,278,016 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 05:41:54 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
< *minodlogin* /s >
< *tnod* /s >
< *AutoKMS* /s >
< *activator* /s >
< *serial* /s >
[2004.08.03 23:15:54 | 000,030,067 | ---- | M] () -- \cmdcons\SERIAL.SY_
[2013.05.25 09:14:21 | 000,141,931 | ---- | M] () -- \Documents and Settings\Tomas\Application Data\TS3Client\cache\remote\img.blesk.cz\img\1\full\443358-img-simpsonovi-homer-simpson-serial-serialy-homer-crop-crop.jpg
[2003.10.09 07:11:48 | 000,000,216 | ---- | M] () -- \Program Files\Image-Line\FL Studio 10\Plugins\Fruity\Generators\Sytrus\Artwork\DelSerialCache.bmp
[2014.02.13 23:57:42 | 000,434,368 | ---- | M] () -- \Program Files\Microsoft Silverlight\5.1.30214.0\System.Runtime.Serialization.dll
[2014.03.13 15:22:54 | 001,164,288 | ---- | M] () -- \Program Files\Microsoft Silverlight\5.1.30214.0\System.Runtime.Serialization.ni.dll
[2012.09.27 01:12:26 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2014.05.13 13:31:51 | 000,000,948 | ---- | M] () -- \Qoobox\Quarantine\Registry_backups\AddRemove-18_Zinia_Serial_Driver.reg.dat
[2006.02.28 14:00:00 | 000,064,896 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys
[2014.02.13 09:32:18 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.01.10 15:33:57 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.02.13 18:23:43 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6c29ee2bedfe88dcd66993f1af135ad8\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.02.13 16:50:21 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9860da66bf0219612908e7412b0a6e2e\System.Runtime.Serialization.ni.dll
[2014.02.13 20:31:09 | 002,659,328 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\b71d4a24ecc32f0c5a110a5c7b9d755f\System.Runtime.Serialization.ni.dll
[2014.02.13 20:29:41 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\efdf6e0cd334958ba2eb6db14486b7b3\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2010.03.18 13:16:28 | 001,026,936 | R--- | M] () -- \WINDOWS\Installer\$PatchCache$\Managed\5C1093C35543A0E32A41B090A305076A\4.0.30319\System.Runtime.Serialization.dll.x86
[2014.02.13 09:38:32 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2014.02.13 09:38:29 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2012.09.27 01:12:26 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2013.09.11 16:17:16 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2003.08.01 12:54:06 | 000,005,632 | ---- | M] () -- \WINDOWS\mui\FALLBACK\041b\serialui.dll.mui
[2008.04.14 00:10:22 | 000,028,288 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys
[2008.04.14 00:45:46 | 000,064,512 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys
[2006.02.28 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2006.02.28 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2006.02.28 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2006.02.28 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 00:45:46 | 000,064,512 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
< *w7lxe* /s >
< End of report >