< MD5 for: NVRAID.SYS >
[2009.07.14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\System32\drivers\nvraid.sys
[2009.07.14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvraid.sys
[2009.07.14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2009.07.14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009.07.14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\System32\smss.exe
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2014.10.01 11:09:16 | 000,761,656 | ---- | M] (MalwareBytes) MD5=C0AFB3C7E6C7CA3F6E42FF242BBBCB1F -- C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
< MD5 for: TCPIP.SYS >
[2011.04.25 05:56:06 | 001,286,016 | ---- | M] (Microsoft Corporation) MD5=0158D5E9982E9D6A90DFC802F618E130 -- C:\Windows\SoftwareDistribution\Download\919003e3012e674674fc2a83c2329826\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_b347f075c77b9c9d\tcpip.sys
[2011.04.25 05:31:30 | 001,290,624 | ---- | M] (Microsoft Corporation) MD5=24326784DF8F3D5F5BBB9F878CE33C14 -- C:\Windows\SoftwareDistribution\Download\919003e3012e674674fc2a83c2329826\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_b52f4dc5c4a121e0\tcpip.sys
[2009.07.14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\System32\drivers\tcpip.sys
[2009.07.14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_b2f46875c7b9d667\tcpip.sys
[2011.04.25 07:31:09 | 001,301,376 | ---- | M] (Microsoft Corporation) MD5=6D4728CFF2724FF3A4654971D61D0F1C -- C:\Windows\SoftwareDistribution\Download\919003e3012e674674fc2a83c2329826\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_b5ad1a5addc7c444\tcpip.sys
[2011.04.25 05:44:18 | 001,298,816 | ---- | M] (Microsoft Corporation) MD5=8861B9A06BA99C6E1D62D0C86DFAB86C -- C:\Windows\SoftwareDistribution\Download\919003e3012e674674fc2a83c2329826\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_b39a7d5ae0c2aec5\tcpip.sys
< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\System32\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2014.10.01 11:09:16 | 000,761,656 | ---- | M] (MalwareBytes) MD5=C0AFB3C7E6C7CA3F6E42FF242BBBCB1F -- C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
< MD5 for: WS2_32.DLL >
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\System32\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\04edea0e898ff8f83bd8f66c447c353c\*.tmp files -> C:\Windows\SoftwareDistribution\Download\04edea0e898ff8f83bd8f66c447c353c\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\04f916c5ef03037217eb8604680bc44b\*.tmp files -> C:\Windows\SoftwareDistribution\Download\04f916c5ef03037217eb8604680bc44b\*.tmp -> ]
[36 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[1 C:\Windows\Temp\avg_a09956\ProgData\*.tmp files -> C:\Windows\Temp\avg_a09956\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a09956\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a09956\ProgFiles\AVG Secure Search\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2014.06.15 17:24:16 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Adobe
[2013.12.08 12:03:54 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Adobe Mini Bridge CS5.1
[2014.06.17 10:39:20 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\AnvSoft
[2012.09.25 07:03:24 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Ashampoo
[2013.09.10 16:26:17 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\AVG2013
[2014.03.24 18:35:47 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\BSplayer
[2012.09.28 17:01:57 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\BSplayer Pro
[2013.02.15 13:32:15 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2014.03.24 09:36:55 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\DAEMON Tools Lite
[2012.10.03 09:01:56 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\GHISLER
[2012.11.10 09:44:01 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\GO Games
[2013.09.04 16:04:16 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\HpUpdate
[2012.09.16 15:21:10 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Identities
[2013.05.02 14:25:08 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\jAlbum
[2012.09.21 08:23:50 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Macromedia
[2013.08.28 16:38:14 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Malwarebytes
[2009.07.14 08:48:45 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Media Center Programs
[2014.03.23 19:16:46 | 000,000,000 | --SD | M] -- C:\Users\anetqua\AppData\Roaming\Microsoft
[2013.04.10 11:14:11 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Mozilla
[2012.09.16 19:06:38 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Opera
[2014.07.23 15:54:55 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\SeaApple
[2014.10.29 21:00:12 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Seznam.cz
[2014.10.30 04:05:54 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Skype
[2014.07.23 15:55:34 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Software Informer
[2013.12.08 12:03:53 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.05.18 08:58:02 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\TeamViewer
[2013.08.28 10:05:27 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\TuneUp Software
[2014.06.28 19:23:03 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\WinRAR
[2014.01.08 16:46:21 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\Zoner
[2014.03.20 18:51:04 | 000,000,000 | ---D | M] -- C:\Users\anetqua\AppData\Roaming\{28a8f263-0a12-e7e9-4337-e12c28a8f263}
< %APPDATA%\*.exe /s >
[2009.08.11 20:21:26 | 000,087,552 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 20:21:30 | 000,090,112 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 13:52:04 | 000,697,690 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
[2010.02.23 16:01:52 | 001,185,871 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\FFDShow\unins000.exe
[2010.08.14 09:42:54 | 000,113,152 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 09:45:10 | 000,358,400 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 09:42:06 | 000,137,728 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 14:30:22 | 000,042,305 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
[2011.05.02 07:27:34 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\anetqua\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2014.03.23 19:16:46 | 000,010,134 | R--- | M] () -- C:\Users\anetqua\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2014.03.25 20:35:53 | 000,786,492 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
[2014.03.25 20:35:57 | 015,823,872 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
[2014.03.25 20:35:54 | 000,107,008 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
[2012.09.13 14:24:48 | 001,009,288 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\szninstall.exe
[2012.09.14 13:06:28 | 002,515,592 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\sznsetup.exe
[2013.02.13 15:16:08 | 000,942,080 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\bin\chromeUpdatePref.exe
[2013.02.04 14:53:30 | 000,055,808 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\bin\ffkill.exe
[2013.01.22 13:55:12 | 000,456,696 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
[2013.01.22 13:54:46 | 000,092,152 | ---- | M] () -- C:\Users\anetqua\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
[2014.10.30 04:05:41 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\mbamswissarmy.sys
< %systemroot%\system32\*.* /3 >
[2014.10.29 20:59:48 | 000,014,192 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.10.29 20:59:48 | 000,014,192 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.10.29 20:59:50 | 000,120,008 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2014.10.29 20:59:50 | 000,104,412 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2014.10.29 20:59:50 | 000,625,936 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2014.10.29 20:59:50 | 000,610,094 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2014.10.29 20:59:50 | 001,454,084 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"AdobeBridge" =
"cz.seznam.software.autoupdate" = "C:\Users\anetqua\AppData\Roaming\Seznam.cz\szninstall.exe" -c -- [2012.09.13 14:24:48 | 001,009,288 | ---- | M] ()
"cz.seznam.software.szndesktop" = "C:\Users\anetqua\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q -- [2013.01.22 13:54:46 | 000,092,152 | ---- | M] ()
"Rainlendar2" = C:\Program Files\Rainlendar2\Rainlendar2.exe
"Google Update" = Reg Error: Value error. -- File not found
"Skype" = "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun -- [2014.07.24 18:55:56 | 021,653,096 | R--- | M] (Skype Technologies S.A.)
"EA Core" = "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
"Zoner Photo Studio Autoupdate" = C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE -- [2013.06.07 15:51:02 | 000,774,680 | ---- | M] (ZONER software)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
< >
< type c:\boot.ini >> test.txt /c >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.10.29 21:03:30 | 000,000,512 | ---- | M] () MD5=C9202EDB26D666F995171C8576DC8F3F -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2420 \Users\anetqua\AppData\Local\Temp\*.tmp files -> \Users\anetqua\AppData\Local\Temp\*.tmp -> ]
[2014.03.22 07:54:00 | 006,586,527 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Temp1_Adobe_Illustrator_CS5.1_CRACK.zip\Adobe_Illustrator_CS5.1_CRACK.exe
[2014.05.12 09:14:38 | 006,988,025 | ---- | M] () -- \Users\anetqua\Downloads\Adobe_Illustrator_CS5.1_CRACK.zip
[2013.08.19 21:28:34 | 003,143,148 | ---- | M] () -- \Users\anetqua\Downloads\Crack-na-age-of-empires-3.rar
[2012.09.17 21:48:04 | 1262,385,962 | ---- | M] () -- \Users\anetqua\Downloads\FULL-Adobe-Photoshop-CS5-+-100%-working-crack-&-ČEŠTINA-+-návod.rar
[2014.03.24 09:09:50 | 004,944,747 | ---- | M] () -- \Users\anetqua\Downloads\Simisims3-TS3-Domácí-Mazlíčci-Crack.rar
[2012.04.12 21:32:25 | 000,315,178 | ---- | M] () -- \Users\anetqua\Downloads\FULL Adobe Photoshop CS5 + 100% working crack & ČEŠTINA + návod\Adobe Photoshop CS5.1 - CRACK - 32bit&64bit\ADBE_CRACK - 32bit.rar
[2012.04.12 21:32:24 | 000,377,747 | ---- | M] () -- \Users\anetqua\Downloads\FULL Adobe Photoshop CS5 + 100% working crack & ČEŠTINA + návod\Adobe Photoshop CS5.1 - CRACK - 32bit&64bit\ADBE_CRACK - 64bit.rar
[2014.02.22 14:16:38 | 000,395,744 | ---- | M] () -- \Users\anetqua\Pictures\2014-upravene\BILLYSHOP\grafiky\pitbul\american-flag-cracked.jpg
[2011.01.14 17:31:04 | 000,000,156 | ---- | M] () -- \Users\Public\StarStableOnline\Data\Cracked_wall.pmt
[2013.04.02 15:52:50 | 000,005,753 | ---- | M] () -- \Users\Public\StarStableOnline\Data\Cracked_wall.pte
[2011.01.14 17:31:04 | 000,000,162 | ---- | M] () -- \Users\Public\StarStableOnline\Data\Cracked_wall_2.pmt
[2013.04.02 15:52:50 | 000,005,757 | ---- | M] () -- \Users\Public\StarStableOnline\Data\Cracked_wall_2.pte
[2013.01.15 19:00:20 | 000,000,186 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackEffectTexture1.pmt
[2013.01.15 19:37:42 | 000,022,180 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackEffectTexture1.pte
[2013.01.15 18:59:18 | 000,000,168 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackTexture1.pmt
[2013.01.15 18:59:18 | 000,087,664 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackTexture1.pte
[2013.01.15 19:15:16 | 000,000,168 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackTexture2.pmt
[2013.08.22 10:44:14 | 000,087,644 | ---- | M] () -- \Users\Public\StarStableOnline\Data\CrackTexture2.pte
[2013.08.20 11:31:14 | 000,000,165 | ---- | M] () -- \Users\Public\StarStableOnline\Data\DialogIcon_PandorianCrack.pmt
[2013.08.20 11:31:14 | 000,065,797 | ---- | M] () -- \Users\Public\StarStableOnline\Data\DialogIcon_PandorianCrack.pte
[2011.12.26 18:12:42 | 000,152,882 | ---- | M] () -- \Users\Public\StarStableOnline\Data\Fireworks_Crackers.pso
[2013.07.12 13:53:42 | 000,006,303 | ---- | M] () -- \Users\Public\StarStableOnline\Data\FO_Cracks.pxo
[2013.01.15 18:59:18 | 000,054,639 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack1.pme
[2013.01.15 19:37:42 | 000,001,005 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack1_Effect.pme
[2013.01.15 19:05:58 | 000,030,143 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack1_Effect2.pme
[2013.01.15 19:37:46 | 000,002,145 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack1_Effect3.pme
[2013.08.22 10:44:14 | 000,075,055 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack2.pme
[2013.07.12 13:28:20 | 000,004,133 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack2_Lod.pme
[2013.01.15 19:23:48 | 000,004,955 | ---- | M] () -- \Users\Public\StarStableOnline\Data\MysticValleyCrack_Col.pco
< *keygen* /s >
[2014.03.25 20:35:20 | 000,001,623 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.lnk
[2014.03.25 20:35:20 | 000,001,623 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.lnk
[2014.03.25 20:32:46 | 019,189,530 | ---- | M] () -- \Users\anetqua\Downloads\Microsoft-Office-2010-Pro-Plus-x64-&-x86-Activator-and-Keygen.zip
[2014.03.25 20:33:38 | 018,806,257 | ---- | M] () -- \Users\anetqua\Downloads\office 2010 activator\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.exe
< *AntiWPA* /s >
< *loader* /s >
[2013.08.22 11:36:13 | 000,019,497 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif.vir
[2011.03.02 20:35:42 | 005,299,048 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\Photodownloader.exe
[2011.03.02 17:57:10 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2011.03.02 17:57:10 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2011.03.02 17:57:10 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\de_de\Photodownloader.ini
[2011.03.02 17:57:10 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\en_us\Photodownloader.ini
[2011.03.02 17:57:10 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\es_es\Photodownloader.ini
[2011.03.02 17:57:10 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\it_it\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\no_no\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2011.03.02 17:57:12 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2011.03.02 17:57:14 | 000,000,308 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2011.03.02 17:57:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2012.02.22 23:45:00 | 000,078,336 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012.02.22 23:45:00 | 000,155,136 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012.02.22 23:45:00 | 000,117,248 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2010.03.24 19:12:34 | 000,249,680 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2010.03.24 19:12:34 | 000,018,264 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2009.10.06 05:08:30 | 000,145,082 | ---- | M] () -- \Program Files\HP\HP Deskjet 5520 series\Bin\HelpViewer\Resources\Loader.gif
[2013.01.21 15:03:44 | 000,030,608 | ---- | M] () -- \Program Files\Seznam.cz\distribution\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \Program Files\The KMPlayer\ImLoader.dll
[2013.08.21 07:01:29 | 000,003,062 | ---- | M] () -- \Program Files\Windows Defender\cs-CZ\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\remote.loader[1].js
[2013.08.21 07:01:30 | 000,120,580 | ---- | M] () -- \Program Files\Windows Defender\cs-CZ\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\sayt_loader_libs[1].js
[2013.08.21 07:01:29 | 000,003,062 | ---- | M] () -- \Program Files\Windows Defender\en-US\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\remote.loader[1].js
[2013.08.21 07:01:30 | 000,120,580 | ---- | M] () -- \Program Files\Windows Defender\en-US\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\sayt_loader_libs[1].js
[2011.12.06 12:06:24 | 000,429,568 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Facebook\ZPSFacebookUploader.exe
[2010.04.29 13:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Facebook\ZPSPluginLoader.exe
[2011.12.06 12:06:40 | 000,444,416 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Flickr\ZPSFlickrUploader.exe
[2010.04.29 13:12:42 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Flickr\ZPSPluginLoader.exe
[2011.03.08 16:09:04 | 000,194,048 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Picasa\ZPSPicasaUploader.exe
[2010.04.29 13:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Plugins\Picasa\ZPSPluginLoader.exe
[2011.12.19 15:12:24 | 000,102,792 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Program32\8bfLoader.exe
[2011.12.19 15:12:36 | 000,016,776 | ---- | M] () -- \Program Files\Zoner\Photo Studio 14\Program32\WICLoader.exe
[2013.03.05 10:11:10 | 000,432,128 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSFacebookUploader.exe
[2010.04.29 14:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSPluginLoader.exe
[2013.02.06 16:42:00 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\en\ZPSFacebookUploader.resources.dll
[2013.03.05 13:03:44 | 000,443,904 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSFlickrUploader.exe
[2010.04.29 14:12:42 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSPluginLoader.exe
[2011.12.06 13:06:40 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\en\ZPSFlickrUploader.resources.dll
[2013.03.05 12:34:20 | 000,192,512 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPicasaUploader.exe
[2010.04.29 14:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPluginLoader.exe
[2013.02.06 16:20:12 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\en\ZPSPicasaUploader.resources.dll
[2013.06.07 15:50:44 | 000,103,960 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\8bfLoader.exe
[2013.06.07 15:50:52 | 000,017,944 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\WICLoader.exe
[2013.08.21 11:36:29 | 000,000,673 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KGGAELH9\loader.white[1].gif
[2013.08.21 10:34:51 | 000,006,494 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a01260\ProgData\AVG Secure Search\FireFoxExt\15.4.0.5\modules\skin\ajax-loader.gif
[2013.08.21 10:34:52 | 000,000,729 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a01260\ProgData\AVG Secure Search\FireFoxExt\15.4.0.5\modules\skin\loader.gif
[2013.08.21 10:34:52 | 000,019,497 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a01260\ProgFiles\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2013.08.21 10:34:28 | 000,006,494 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a02532\ProgData\AVG Secure Search\FireFoxExt\15.1.0.2\modules\skin\ajax-loader.gif
[2013.08.21 10:34:28 | 000,000,729 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a02532\ProgData\AVG Secure Search\FireFoxExt\15.1.0.2\modules\skin\loader.gif
[2013.08.21 10:34:28 | 000,019,497 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Temp\avg_a02532\ProgFiles\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2012.09.13 14:45:58 | 000,058,424 | ---- | M] () -- \Users\Anetka 1\AppData\Roaming\Seznam.cz\bin\libfoxloader.dll
[2012.08.07 13:39:12 | 000,000,165 | ---- | M] () -- \Users\Anetka 1\AppData\Roaming\Seznam.cz\conf\szndesktop.d\libfoxloader.conf
[2012.08.13 18:05:28 | 000,000,235 | ---- | M] () -- \Users\Anetka 1\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_0_0.install.bat
[2012.08.13 18:05:26 | 000,000,130 | ---- | M] () -- \Users\Anetka 1\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_0_0.uninstall.bat
[2014.04.18 20:53:14 | 000,001,870 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\09QNG1GC\AdLoader[1].htm
[2014.03.17 19:24:50 | 000,001,870 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIX9FBPX\AdLoader[1].htm
[2014.05.11 08:24:44 | 000,001,870 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P3IRHGSG\AdLoader[1].htm
[2014.07.09 18:30:05 | 000,017,912 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QC7JDJVB\AdLoader-3b8e790904fffcf74f96367cd382e261.min[1].js
[2014.10.27 18:53:37 | 000,018,715 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QC7JDJVB\AdLoader-a5fa12058ddb9a8919d6906ba95d7c57.min[1].js
[2014.08.17 08:17:44 | 000,018,544 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VK2Q9EKK\AdLoader-0ee9685baf8ff395a7119d551063e2d4.min[1].js
[2014.07.09 18:30:05 | 000,001,980 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VK2Q9EKK\AdLoader[1].htm
[2014.10.27 18:53:36 | 000,001,980 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VK2Q9EKK\AdLoader[2].htm
[2014.10.27 18:53:50 | 000,001,980 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VK2Q9EKK\AdLoader[3].htm
[2014.10.28 18:57:13 | 000,001,980 | ---- | M] () -- \Users\anetqua\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZW8ZANI0\AdLoader[1].htm
[2014.07.01 10:46:16 | 000,072,638 | ---- | M] () -- \Users\anetqua\AppData\Local\Skype\Apps\login\images\loader.gif
[2014.07.01 10:46:16 | 000,003,032 | ---- | M] () -- \Users\anetqua\AppData\Local\Skype\Apps\login\images\loader.png
[2014.07.01 10:46:16 | 000,006,012 | ---- | M] () -- \Users\anetqua\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2014.07.01 10:46:16 | 000,021,956 | ---- | M] () -- \Users\anetqua\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2014.07.01 10:46:16 | 000,009,772 | ---- | M] () -- \Users\anetqua\AppData\Local\Skype\Apps\login\images\retina\
loader@2x.png
[2013.12.07 20:17:11 | 000,002,572 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Dog-Silhouette-Vector.rar_Downloader (1)_005896.log
[2013.12.10 09:52:03 | 000,007,818 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Dog-Silhouette-Vector.rar_Downloader_000656.log
[2013.12.07 20:17:21 | 000,007,470 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Dog-Silhouette-Vector.rar_Downloader_001744.log
[2013.12.08 23:08:58 | 000,007,006 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Dog-Silhouette-Vector.rar_Downloader_005796.log
[2013.12.10 10:15:52 | 000,004,860 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\Dog-Silhouette-Vector.rar_Downloader_006012.log
[2420 \Users\anetqua\AppData\Local\Temp\*.tmp files -> \Users\anetqua\AppData\Local\Temp\*.tmp -> ]
[2013.04.15 21:31:51 | 000,008,192 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\_MEI24722\_win32sysloader.pyd
[2013.07.04 07:05:55 | 000,006,494 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a01660\ProgData\AVG SafeGuard toolbar\FireFoxExt\14.0.0.12\modules\skin\ajax-loader.gif
[2013.07.04 07:05:55 | 000,000,729 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a01660\ProgData\AVG SafeGuard toolbar\FireFoxExt\14.0.0.12\modules\skin\loader.gif
[2013.07.04 07:05:55 | 000,019,497 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a01660\ProgFiles\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2013.07.04 07:07:38 | 000,006,494 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a07480\ProgData\AVG SafeGuard toolbar\FireFoxExt\15.3.0.11\modules\skin\ajax-loader.gif
[2013.07.04 07:07:38 | 000,000,729 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a07480\ProgData\AVG SafeGuard toolbar\FireFoxExt\15.3.0.11\modules\skin\loader.gif
[2013.07.04 07:07:38 | 000,019,497 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\avg_a07480\ProgFiles\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2013.08.29 07:42:27 | 000,003,208 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\ibtmpe0c3674\config\ajax-loader.gif
[2013.08.29 07:42:27 | 000,006,820 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\ibtmpe0c3674\config\ajax-loader2.gif
[2013.07.04 07:07:38 | 000,019,497 | ---- | M] () -- \Users\anetqua\AppData\Local\Temp\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2012.09.13 14:45:58 | 000,058,424 | ---- | M] () -- \Users\anetqua\AppData\Roaming\Seznam.cz\bin\libfoxloader.dll
[2012.08.07 13:39:12 | 000,000,165 | ---- | M] () -- \Users\anetqua\AppData\Roaming\Seznam.cz\conf\szndesktop.d\libfoxloader.conf
[2013.01.21 15:03:44 | 000,030,608 | ---- | M] () -- \Users\anetqua\AppData\Roaming\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2012.08.13 18:05:28 | 000,000,235 | ---- | M] () -- \Users\anetqua\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_0_0.install.bat
[2012.08.13 18:05:26 | 000,000,130 | ---- | M] () -- \Users\anetqua\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_0_0.uninstall.bat
[2013.03.27 14:26:04 | 000,000,169 | ---- | M] () -- \Users\anetqua\Documents\aaa-e-shop\E-shop\šperky\Řetízek ZARPA_files\imagepreloader.js
[2013.08.21 07:01:29 | 000,003,062 | ---- | M] () -- \Windows\$NtUninstallKB48746$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\remote.loader[1].js
[2013.08.21 07:01:30 | 000,120,580 | ---- | M] () -- \Windows\$NtUninstallKB48746$\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\sayt_loader_libs[1].js
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2013.08.21 07:01:29 | 000,003,062 | ---- | M] () -- \Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\remote.loader[1].js
[2013.08.21 07:01:30 | 000,120,580 | ---- | M] () -- \Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\URAZWMTS\sayt_loader_libs[1].js
[2009.07.14 05:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2013.08.22 11:36:12 | 000,006,494 | ---- | M] () -- \Windows\Temp\avg_a09956\ProgData\AVG Secure Search\FireFoxExt\15.5.0.2\modules\skin\ajax-loader.gif
[2013.08.22 11:36:13 | 000,000,729 | ---- | M] () -- \Windows\Temp\avg_a09956\ProgData\AVG Secure Search\FireFoxExt\15.5.0.2\modules\skin\loader.gif
[2013.08.22 11:36:13 | 000,019,497 | ---- | M] () -- \Windows\Temp\avg_a09956\ProgFiles\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2012.09.16 15:42:16 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2012.09.16 15:42:16 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winload.exe.mui_3bc5b827
[2012.09.16 15:42:16 | 000,030,272 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winresume.exe.mui_ff8b5358
[2009.07.14 05:56:40 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_766f102945576be4.manifest
[2009.07.14 05:56:40 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_766f102945576be4_winload.exe.mui_3bc5b827
[2009.07.14 05:56:40 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_766f102945576be4_winresume.exe.mui_ff8b5358
[2009.07.14 03:17:55 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_5afd1055cdfa75b9.manifest
[2009.07.14 03:17:55 | 000,507,568 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_5afd1055cdfa75b9_winload.exe_75835076
[2009.07.14 03:17:55 | 000,442,920 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_5afd1055cdfa75b9_winresume.exe_85cd1215
[2009.07.14 03:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 03:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2009.07.13 17:54:50 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2009.07.14 03:29:12 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_766f102945576be4.manifest
[2009.07.14 02:47:46 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_5afd1055cdfa75b9.manifest
[2009.07.14 02:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
< *minodlogin* /s >
< *tnod* /s >
< *AutoKMS* /s >
[2014.03.25 20:45:37 | 000,000,161 | ---- | M] () -- \Windows\AutoKMS.ini
[1 \Windows\*.tmp files -> \Windows\*.tmp -> ]
< *activator* /s >
[2014.03.25 20:35:20 | 000,001,623 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.lnk
[2014.03.25 20:35:20 | 000,001,623 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.lnk
[2014.03.25 20:32:46 | 019,189,530 | ---- | M] () -- \Users\anetqua\Downloads\Microsoft-Office-2010-Pro-Plus-x64-&-x86-Activator-and-Keygen.zip
[2014.03.25 20:33:38 | 018,806,257 | ---- | M] () -- \Users\anetqua\Downloads\office 2010 activator\Microsoft Office 2010 Pro Plus x64 & x86 Activator and Keygen.exe
< *serial* /s >
[2013.08.19 20:17:00 | 000,015,399 | ---- | M] () -- \Program Files\BitLord\Torrents\AGE OF EMPIRES III + SERIAL.torrent
[2013.08.19 21:22:44 | 000,002,133 | ---- | M] () -- \Program Files\BitLord\Torrents\AGE OF EMPIRES III + SERIAL.xml
[2014.02.13 21:57:42 | 000,434,368 | ---- | M] () -- \Program Files\Microsoft Silverlight\5.1.30214.0\System.Runtime.Serialization.dll
[2014.04.26 20:10:19 | 001,164,288 | ---- | M] () -- \Program Files\Microsoft Silverlight\5.1.30214.0\System.Runtime.Serialization.ni.dll
[2013.04.17 18:43:42 | 000,005,687 | ---- | M] () -- \Program Files\PokerStars\gx\tokenserial.jpg
[2009.06.10 22:13:54 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2009.06.08 09:38:48 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2014.05.15 09:16:50 | 000,003,072 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_eserial.cz_0.localstorage
[2014.05.15 09:16:50 | 000,003,608 | ---- | M] () -- \Users\Anetka 1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_eserial.cz_0.localstorage-journal
[2014.01.31 20:53:41 | 000,003,072 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_serialy.befun.cz_0.localstorage
[2014.01.31 20:53:41 | 000,000,512 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_serialy.befun.cz_0.localstorage-journal
[2014.04.14 13:40:54 | 000,003,072 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage
[2014.04.14 13:40:54 | 000,003,608 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2014.10.28 12:55:50 | 002,076,672 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage
[2014.10.28 12:55:51 | 000,016,384 | ---- | M] () -- \Users\anetqua\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage-journal
[2013.01.05 13:47:46 | 000,185,386 | ---- | M] () -- \Users\anetqua\Documents\___Haf&Mnau\2013\AAAA-2013\1\18-19_serial_zdravi psu.pdf
[1 \Users\anetqua\Documents\___Haf&Mnau\2013\AAAA-2013\BREZEN\*.tmp files -> \Users\anetqua\Documents\___Haf&Mnau\2013\AAAA-2013\BREZEN\*.tmp -> ]
[2013.01.05 13:46:00 | 000,192,937 | ---- | M] () -- \Users\anetqua\Downloads\18-19_serial_zdravi psu.pdf
[2011.08.08 15:34:04 | 000,000,153 | ---- | M] () -- \Users\Public\StarStableOnline\Data\SerialNr.pmt
[2011.08.08 15:33:42 | 000,001,690 | ---- | M] () -- \Users\Public\StarStableOnline\Data\SerialNr.pte
[2011.08.08 15:33:42 | 000,001,579 | ---- | M] () -- \Users\Public\StarStableOnline\Data\SerialNRPlate.pme
[2009.06.10 13:14:16 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.08 09:38:48 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2009.06.10 22:13:54 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2009.07.14 05:43:53 | 002,347,008 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\39e53f507d9cbc5c10a2f47c4b0d09dd\System.Runtime.Serialization.ni.dll
[2009.07.14 05:43:05 | 000,310,784 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\d57d865568209a71d63739fa448ed6df\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.10 13:14:16 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.06.10 22:14:06 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2009.07.13 17:38:14 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\drivers\serial.sys
[2009.07.13 17:39:44 | 000,009,728 | ---- | M] () -- \Windows\System32\drivers\cs-CZ\serial.sys.mui
[2009.07.14 03:09:30 | 000,010,240 | ---- | M] () -- \Windows\System32\drivers\en-US\serial.sys.mui
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\mdmmotsm.inf_x86_neutral_c1415d9789c54b89\smserial.sys
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_x86_neutral_63e72c669d043f14\grserial.sys
[2009.07.14 03:10:04 | 000,005,120 | ---- | M] () -- \Windows\System32\en-US\serialui.dll.mui
[2009.07.14 03:18:03 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 03:18:03 | 000,015,952 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486_kdcom.dll_db5e7744
[2012.09.16 15:42:14 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed_serialui.dll.mui_7d29d2a3
[2009.07.14 05:56:40 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_919783112bf8b64b_serialui.dll.mui_7d29d2a3
[2009.07.14 03:18:51 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a_serialui.dll_bea29328
[2009.07.14 02:52:33 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.16385_none_a6aa149474833896.manifest
[2009.07.13 17:54:22 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0.manifest
[2009.07.14 03:28:14 | 000,000,531 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_en-us_8f71d563bf7aa3c2.manifest
[2009.07.14 02:51:52 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.16385_none_d6ed4a2e9c2a39c9.manifest
[2009.07.14 02:49:26 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 02:45:27 | 000,000,866 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.1.7600.16385_none_2c93290b67c98d09.manifest
[2009.07.14 02:57:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_dbc7f5fbdd00d40b.manifest
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_1c9a3ec1e01c684b\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.10 13:14:16 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7600.16385_cs-cz_d5c3552dd9b47144\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.06.10 22:14:06 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7600.16385_none_a6aa149474833896\System.Runtime.Serialization.dll
[2009.06.08 09:38:48 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0\System.RunTime.Serialization.Resources.dll
[2009.06.10 22:13:54 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7600.16385_none_d6ed4a2e9c2a39c9\System.Runtime.Serialization.dll
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\winsxs\x86_mdmmotsm.inf_31bf3856ad364e35_6.1.7600.16385_none_7a97936f8a972896\smserial.sys
[2009.06.10 13:14:16 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_c002c1170ca9a88f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.07.13 17:38:14 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed\serialui.dll.mui
[2009.07.14 03:10:04 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_919783112bf8b64b\serialui.dll.mui
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a\serialui.dll
[2009.06.08 09:38:48 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_5d4a68b4b3d26ecc\System.RunTime.Serialization.Resources.dll
[2009.07.13 17:39:44 | 000,009,728 | ---- | M] () -- \Windows\winsxs\x86_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_c48c78a9ad8ff996\serial.sys.mui
[2009.07.14 03:09:30 | 000,010,240 | ---- | M] () -- \Windows\winsxs\x86_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_en-us_07e2c405948a55f4\serial.sys.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\winsxs\x86_smartcrd.inf_31bf3856ad364e35_6.1.7600.16385_none_7280378295916274\grserial.sys
[2009.06.10 22:13:54 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7600.16385_none_dbc7f5fbdd00d40b\System.Runtime.Serialization.dll
< *w7lxe* /s >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB48746$] -> Error: Cannot create file handle -> Unknown point type
< End of report >