Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Opakující se zobrazování ruských stránek

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#16 Příspěvek od Márty84 »

:arrow: Vypnete trvale Windows Defender.



:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

File::
c:\windows\inf\mncjmqx.vbe
c:\windows\inf\msmjpo.vbe

Folder::
c:\programdata\Malwarebytes

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"=-
"MMServerListAutoUpdaterTSS"=-
"DAEMON Tools Lite"=-
"uTorrent"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"GarminExpressTrayApp"=-

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Driver::
MBAMSwissArmy

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#17 Příspěvek od Kanarek »

ComboFix 14-10-29.01 - Beny 31.10.2014 20:11:41.2.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.606 [GMT 1:00]
Spuštěný z: c:\users\Beny\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Beny\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\inf\mncjmqx.vbe"
"c:\windows\inf\msmjpo.vbe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Malwarebytes
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\gatekeeper.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\license.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\notifications.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\settings.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\scheduler.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Configuration\statistics.conf
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\exclusions.dat
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2014-10-30 (10-42-35).xml
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2014-10-30 (18-50-49).xml
c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\Logs\protection-log-2014-10-30.xml
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MBAMSWISSARMY
-------\Service_MBAMSwissArmy
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-09-28 do 2014-10-31 )))))))))))))))))))))))))))))))
.
.
2014-10-31 19:21 . 2014-10-31 19:21 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-10-31 19:21 . 2014-10-31 19:21 -------- d-----w- c:\users\HomeGroupUser$\AppData\Local\temp
2014-10-31 19:21 . 2014-10-31 19:21 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-10-31 19:21 . 2014-10-31 19:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-31 19:21 . 2014-10-31 19:21 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-10-31 16:45 . 2014-10-31 16:15 24064 ----a-w- c:\windows\zoek-delete.exe
2014-10-31 16:45 . 2014-10-31 19:25 -------- d-----w- c:\users\Beny\AppData\Local\Temp
2014-10-31 16:15 . 2014-10-31 16:43 -------- d-----w- C:\zoek_backup
2014-10-31 15:46 . 2014-10-31 15:46 -------- d-----w- c:\windows\ERUNT
2014-10-31 08:59 . 2014-10-14 20:13 8901368 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0909F359-ABFF-4C95-B5DB-24796EC330B6}\mpengine.dll
2014-10-30 00:23 . 2014-10-30 00:25 -------- d-----w- c:\users\Beny\AppData\Roaming\Dropbox
2014-10-30 00:09 . 2010-08-30 07:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-10-30 00:08 . 2014-10-30 00:09 -------- d-----w- c:\windows\system32\vbox
2014-10-30 00:07 . 2014-10-30 00:09 -------- d-----w- C:\AdwCleaner
2014-10-29 23:59 . 2014-10-29 23:59 -------- d-----w- c:\users\Beny\AppData\Roaming\AVAST Software
2014-10-29 23:57 . 2014-10-29 23:57 91496 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-10-29 23:57 . 2014-10-31 19:07 70384 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
2014-10-29 23:57 . 2014-10-29 23:57 206248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-10-29 23:57 . 2014-10-29 23:57 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-10-29 23:57 . 2014-10-29 23:57 422760 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-10-29 23:57 . 2014-10-29 23:57 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-10-29 23:57 . 2014-10-29 23:57 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-10-29 23:57 . 2014-10-31 19:07 787800 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-10-29 23:57 . 2014-10-29 23:57 291352 ----a-w- c:\windows\system32\aswBoot.exe
2014-10-29 23:57 . 2014-10-29 23:57 43152 ----a-w- c:\windows\avastSS.scr
2014-10-29 23:56 . 2014-10-29 23:56 -------- d-----w- c:\program files\AVAST Software
2014-10-29 23:56 . 2014-10-29 23:56 -------- d-----w- c:\programdata\AVAST Software
2014-10-29 18:10 . 2014-10-29 18:12 -------- d-----w- C:\FRST
2014-10-14 20:24 . 2014-09-13 01:40 67072 ----a-w- c:\windows\system32\packager.dll
2014-10-14 20:23 . 2014-08-19 01:48 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2014-10-14 20:23 . 2014-07-07 01:40 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-10-14 20:23 . 2014-08-19 02:40 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2014-10-14 20:23 . 2014-07-07 01:40 102400 ----a-w- c:\program files\Windows Media Player\wmpshare.exe
2014-10-14 20:23 . 2014-07-07 01:40 101888 ----a-w- c:\program files\Windows Media Player\wmpconfig.exe
2014-10-14 20:23 . 2014-07-07 01:40 4096 ----a-w- c:\windows\system32\dxmasf.dll
2014-10-14 20:23 . 2014-07-07 01:40 8192 ----a-w- c:\windows\system32\spwmp.dll
2014-10-14 20:23 . 2014-07-07 01:40 4096 ----a-w- c:\windows\system32\msdxm.ocx
2014-10-14 20:23 . 2014-07-07 01:39 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-10-14 20:23 . 2014-07-07 01:37 2048 ----a-w- c:\windows\system32\mferror.dll
2014-10-05 12:28 . 2014-10-05 12:28 -------- d-----w- c:\users\Beny\AppData\Local\Diagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-30 00:27 . 2012-12-02 09:55 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-10-30 00:27 . 2012-12-02 09:55 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-10-28 05:35 . 2012-11-21 19:24 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-08-23 01:46 . 2014-08-27 19:37 305152 ----a-w- c:\windows\system32\gdi32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-10-29 23:57 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-10-31 5223016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
STK03N PNP Monitor.lnk - c:\windows\STK03N\STK03NM.exe [2012-12-2 163840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Beny^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\users\Beny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-08-21 16:30 959176 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2012-11-06 10:46 3673728 ----a-w- c:\program files\Programy\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
2014-07-01 10:01 122200 ----a-w- c:\program files\Garmin\Express Tray\ExpressTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 21:17 52256 ----a-w- c:\program files\Programy\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-14 20:01 71216 ------w- c:\program files\Programy\CyberLink\PowerDVD\PDVDServ.exe
.
R3 DCamUSBSTK03N;Standard_Camera;c:\windows\system32\DRIVERS\STK03NW2.sys [2009-12-18 108544]
R3 DFX11_1;DFX Audio Enhancer 11.1;c:\windows\system32\drivers\dfx11_1.sys [2012-12-13 24424]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-09-19 108032]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-23 1343400]
R3 XFDriver;XFDrive;c:\program files\Xfire2\XFDriver.sys [2013-03-14 16648]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-10-31 787800]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-10-29 422760]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-27 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-10-29 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-10-31 70384]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-10-29 91496]
S2 Garmin Core Update Service;Garmin Core Update Service;c:\program files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2014-07-01 437080]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-10-29 218192]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-10-29 3192344]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-10-27 21:48 1089352 ----a-w- c:\program files\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-11-16 19:03]
.
2014-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-11-16 19:03]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.195.165.131 217.195.160.10
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{aece03a3-686f-4b3c-9931-9dafb71829b7} - c:\programdata\Package Cache\{aece03a3-686f-4b3c-9931-9dafb71829b7}\GarminExpressInstaller.exe
AddRemove-{ce085a78-074e-4823-8dc1-8a721b94b76d} - c:\programdata\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\msiexec.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\conhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\vssvc.exe
.
**************************************************************************
.
Celkový čas: 2014-10-31 20:29:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-10-31 19:29
ComboFix2.txt 2014-10-30 20:15
.
Před spuštěním: Volných bajtů: 87 914 119 168
Po spuštění: Volných bajtů: 87 817 383 936
.
- - End Of File - - 021CA7311360261CA7D65E78173CE6D4
A36C5E4F47E84449FF07ED3517B43A31

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#18 Příspěvek od Márty84 »

Jak to zatim vypada?

Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=130786
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#19 Příspěvek od Kanarek »

Vypadá to zatím dobře. Problém ale je, že předtím se problémy objevovaly jen někdy, tak to budu muset sledovat delší dobu. Každopádně se mi zdá, že prohlížeč a záložky, které mám stále otevřené se načtou rychleji než dříve.


Logfile of random's system information tool 1.10 (written by random/random)
Run by Beny at 2014-11-02 16:57:05
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 84 GB (27%) free of 305 GB
Total RAM: 2046 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:57:19, on 2.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Windows\STK03N\STK03NM.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera_crashreporter.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Program Files\Opera\25.0.1614.68\opera.exe
C:\Users\Beny\Downloads\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\trend micro\Beny.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - Global Startup: STK03N PNP Monitor.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 4610 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-10-30 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-10-31 5223016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\Programy\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2014-07-01 122200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\Programy\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\Programy\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~1\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Beny^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2005-03-16 113664]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
STK03N PNP Monitor.lnk - C:\Windows\STK03N\STK03NM.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XFR1"=xfcodec.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-11-02 16:57:06 ----D---- C:\Program Files\trend micro
2014-11-02 16:57:05 ----D---- C:\rsit
2014-10-31 20:29:07 ----A---- C:\ComboFix.txt
2014-10-31 20:28:41 ----SHD---- C:\$RECYCLE.BIN
2014-10-31 20:08:24 ----D---- C:\ComboFix
2014-10-31 17:45:45 ----A---- C:\Windows\zoek-delete.exe
2014-10-31 17:45:43 ----D---- C:\Windows\Temp
2014-10-31 17:15:14 ----D---- C:\zoek_backup
2014-10-31 16:46:22 ----D---- C:\Windows\ERUNT
2014-10-30 20:59:49 ----A---- C:\Windows\zip.exe
2014-10-30 20:59:49 ----A---- C:\Windows\SWSC.exe
2014-10-30 20:59:49 ----A---- C:\Windows\SWREG.exe
2014-10-30 20:59:49 ----A---- C:\Windows\sed.exe
2014-10-30 20:59:49 ----A---- C:\Windows\PEV.exe
2014-10-30 20:59:49 ----A---- C:\Windows\NIRCMD.exe
2014-10-30 20:59:49 ----A---- C:\Windows\MBR.exe
2014-10-30 20:59:49 ----A---- C:\Windows\grep.exe
2014-10-30 20:56:57 ----D---- C:\Qoobox
2014-10-30 20:56:31 ----D---- C:\Windows\erdnt
2014-10-30 01:25:28 ----D---- C:\Users\Beny\AppData\Roaming\DropboxMaster
2014-10-30 01:23:13 ----D---- C:\Users\Beny\AppData\Roaming\Dropbox
2014-10-30 01:09:09 ----A---- C:\Windows\system32\sqlite3.dll
2014-10-30 01:08:57 ----D---- C:\Windows\system32\vbox
2014-10-30 01:07:21 ----D---- C:\AdwCleaner
2014-10-30 00:59:46 ----D---- C:\Users\Beny\AppData\Roaming\AVAST Software
2014-10-30 00:57:57 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-10-30 00:57:56 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2014-10-30 00:57:56 ----A---- C:\Windows\system32\drivers\aswSP.sys
2014-10-30 00:57:56 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2014-10-30 00:57:56 ----A---- C:\Windows\system32\drivers\aswmonflt.sys
2014-10-30 00:57:55 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-10-30 00:57:55 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-10-30 00:57:54 ----A---- C:\Windows\system32\drivers\aswsnx.sys
2014-10-30 00:57:52 ----A---- C:\Windows\system32\aswBoot.exe
2014-10-30 00:57:44 ----A---- C:\Windows\avastSS.scr
2014-10-30 00:56:51 ----D---- C:\Program Files\AVAST Software
2014-10-30 00:56:09 ----D---- C:\ProgramData\AVAST Software
2014-10-29 19:10:20 ----D---- C:\FRST
2014-10-14 21:26:47 ----A---- C:\Windows\system32\win32k.sys
2014-10-14 21:26:18 ----A---- C:\Windows\system32\rastls.dll
2014-10-14 21:26:14 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 21:26:14 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-10-14 21:26:14 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-10-14 21:26:12 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 21:26:11 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-14 21:26:11 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-14 21:26:10 ----A---- C:\Windows\system32\vbscript.dll
2014-10-14 21:26:10 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 21:26:10 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-14 21:26:09 ----A---- C:\Windows\system32\wininet.dll
2014-10-14 21:26:08 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-14 21:26:07 ----A---- C:\Windows\system32\ieui.dll
2014-10-14 21:26:06 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-10-14 21:26:06 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-14 21:26:05 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-10-14 21:26:05 ----A---- C:\Windows\system32\iertutil.dll
2014-10-14 21:26:03 ----A---- C:\Windows\system32\jscript9diag.dll
2014-10-14 21:26:02 ----A---- C:\Windows\system32\jscript9.dll
2014-10-14 21:25:59 ----A---- C:\Windows\system32\mshtml.dll
2014-10-14 21:25:56 ----A---- C:\Windows\system32\urlmon.dll
2014-10-14 21:25:56 ----A---- C:\Windows\system32\iernonce.dll
2014-10-14 21:25:56 ----A---- C:\Windows\system32\ie4uinit.exe
2014-10-14 21:25:54 ----A---- C:\Windows\system32\iedkcs32.dll
2014-10-14 21:25:53 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-14 21:25:53 ----A---- C:\Windows\system32\ieapfltr.dll
2014-10-14 21:25:51 ----A---- C:\Windows\system32\msrating.dll
2014-10-14 21:25:51 ----A---- C:\Windows\system32\iesetup.dll
2014-10-14 21:25:49 ----A---- C:\Windows\system32\ieframe.dll
2014-10-14 21:25:44 ----A---- C:\Windows\system32\mscories.dll
2014-10-14 21:25:44 ----A---- C:\Windows\system32\mscorier.dll
2014-10-14 21:25:44 ----A---- C:\Windows\system32\dfshim.dll
2014-10-14 21:25:31 ----A---- C:\Windows\system32\mstscax.dll
2014-10-14 21:25:29 ----A---- C:\Windows\system32\mstsc.exe
2014-10-14 21:25:27 ----A---- C:\Windows\system32\termsrv.dll
2014-10-14 21:25:26 ----A---- C:\Windows\system32\winsta.dll
2014-10-14 21:25:26 ----A---- C:\Windows\system32\winlogon.exe
2014-10-14 21:25:26 ----A---- C:\Windows\system32\schannel.dll
2014-10-14 21:25:26 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-14 21:25:25 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-14 21:25:24 ----A---- C:\Windows\system32\wdigest.dll
2014-10-14 21:25:24 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-14 21:25:24 ----A---- C:\Windows\system32\ncrypt.dll
2014-10-14 21:25:24 ----A---- C:\Windows\system32\msv1_0.dll
2014-10-14 21:25:24 ----A---- C:\Windows\system32\aaclient.dll
2014-10-14 21:25:23 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-14 21:25:23 ----A---- C:\Windows\system32\credssp.dll
2014-10-14 21:24:46 ----A---- C:\Windows\system32\packager.dll
2014-10-14 21:24:33 ----A---- C:\Windows\system32\blackbox.dll
2014-10-14 21:24:32 ----A---- C:\Windows\system32\drmv2clt.dll
2014-10-14 21:24:31 ----A---- C:\Windows\system32\wmdrmsdk.dll
2014-10-14 21:24:26 ----A---- C:\Windows\system32\wmp.dll
2014-10-14 21:24:23 ----A---- C:\Windows\system32\mf.dll
2014-10-14 21:24:22 ----A---- C:\Windows\system32\drmmgrtn.dll
2014-10-14 21:24:22 ----A---- C:\Windows\system32\AUDIOKSE.dll
2014-10-14 21:24:21 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2014-10-14 21:24:21 ----A---- C:\Windows\system32\ci.dll
2014-10-14 21:24:20 ----A---- C:\Windows\system32\AudioSes.dll
2014-10-14 21:24:19 ----A---- C:\Windows\system32\winload.exe
2014-10-14 21:24:18 ----A---- C:\Windows\system32\winresume.exe
2014-10-14 21:24:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-10-14 21:24:17 ----A---- C:\Windows\system32\EncDump.dll
2014-10-14 21:24:16 ----A---- C:\Windows\system32\cryptsvc.dll
2014-10-14 21:24:15 ----A---- C:\Windows\system32\wintrust.dll
2014-10-14 21:24:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-10-14 21:24:13 ----A---- C:\Windows\system32\quartz.dll
2014-10-14 21:24:13 ----A---- C:\Windows\system32\evr.dll
2014-10-14 21:24:11 ----A---- C:\Windows\system32\crypt32.dll
2014-10-14 21:24:10 ----A---- C:\Windows\system32\pcasvc.dll
2014-10-14 21:24:10 ----A---- C:\Windows\system32\cryptui.dll
2014-10-14 21:24:09 ----A---- C:\Windows\system32\mfplat.dll
2014-10-14 21:24:07 ----A---- C:\Windows\system32\qdvd.dll
2014-10-14 21:24:06 ----A---- C:\Windows\system32\cryptsp.dll
2014-10-14 21:24:06 ----A---- C:\Windows\system32\AudioEng.dll
2014-10-14 21:24:04 ----A---- C:\Windows\system32\audiosrv.dll
2014-10-14 21:24:03 ----A---- C:\Windows\system32\msscp.dll
2014-10-14 21:24:02 ----A---- C:\Windows\system32\rrinstaller.exe
2014-10-14 21:24:02 ----A---- C:\Windows\system32\msnetobj.dll
2014-10-14 21:24:02 ----A---- C:\Windows\system32\audiodg.exe
2014-10-14 21:24:01 ----A---- C:\Windows\system32\mfps.dll
2014-10-14 21:24:01 ----A---- C:\Windows\system32\appidsvc.dll
2014-10-14 21:24:01 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 21:24:01 ----A---- C:\Windows\system32\appidapi.dll
2014-10-14 21:24:00 ----A---- C:\Windows\system32\setbcdlocale.dll
2014-10-14 21:24:00 ----A---- C:\Windows\system32\mfpmp.exe
2014-10-14 21:23:59 ----A---- C:\Windows\system32\drivers\appid.sys
2014-10-14 21:23:58 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 21:23:56 ----A---- C:\Windows\system32\spwmp.dll
2014-10-14 21:23:56 ----A---- C:\Windows\system32\dxmasf.dll
2014-10-14 21:23:55 ----A---- C:\Windows\system32\wmploc.DLL
2014-10-14 21:23:55 ----A---- C:\Windows\system32\mferror.dll

======List of files/folders modified in the last 1 month======

2014-11-02 16:57:06 ----RD---- C:\Program Files
2014-11-02 16:54:24 ----D---- C:\Windows\System32
2014-11-02 16:53:41 ----D---- C:\ProgramData\NVIDIA
2014-10-31 20:31:44 ----D---- C:\Windows\system32\config
2014-10-31 20:29:11 ----D---- C:\Windows\system32\drivers
2014-10-31 20:25:42 ----D---- C:\Windows
2014-10-31 20:25:42 ----A---- C:\Windows\system.ini
2014-10-31 20:25:27 ----D---- C:\Windows\system32\drivers\etc
2014-10-31 20:20:54 ----D---- C:\ProgramData
2014-10-31 20:17:25 ----D---- C:\Windows\AppPatch
2014-10-31 20:17:23 ----D---- C:\Program Files\Common Files
2014-10-31 20:05:33 ----D---- C:\Users\Beny\AppData\Roaming\uTorrent
2014-10-31 17:18:20 ----SHD---- C:\System Volume Information
2014-10-30 20:49:38 ----D---- C:\Windows\Prefetch
2014-10-30 19:07:56 ----D---- C:\Windows\system32\Tasks
2014-10-30 19:07:56 ----D---- C:\Program Files\Opera
2014-10-30 13:09:45 ----D---- C:\Windows\ServiceProfiles
2014-10-30 11:21:48 ----D---- C:\Windows\inf
2014-10-30 01:27:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-10-30 00:57:53 ----D---- C:\Windows\winsxs
2014-10-30 00:55:17 ----SHD---- C:\Windows\Installer
2014-10-30 00:54:41 ----D---- C:\Config.Msi
2014-10-30 00:54:12 ----D---- C:\Windows\system32\DriverStore
2014-10-29 20:38:56 ----D---- C:\Windows\system32\catroot
2014-10-28 19:04:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-28 06:35:00 ----N---- C:\Windows\system32\MpSigStub.exe
2014-10-24 10:30:51 ----D---- C:\Program Files\Common Files\Steam
2014-10-22 18:46:07 ----D---- C:\Users\Beny\AppData\Roaming\Canon
2014-10-21 23:36:22 ----D---- C:\Windows\Tasks
2014-10-16 11:43:30 ----D---- C:\Windows\rescache
2014-10-16 10:29:38 ----D---- C:\Windows\SoftwareDistribution
2014-10-16 10:28:10 ----D---- C:\Windows\Minidump
2014-10-16 10:28:10 ----D---- C:\Windows\debug
2014-10-15 19:54:15 ----D---- C:\Windows\Microsoft.NET
2014-10-15 19:53:43 ----RSD---- C:\Windows\assembly
2014-10-15 12:08:08 ----D---- C:\Windows\system32\catroot2
2014-10-15 12:02:28 ----D---- C:\Boot
2014-10-15 10:09:52 ----D---- C:\Windows\system32\en-US
2014-10-15 10:09:52 ----D---- C:\Program Files\Internet Explorer
2014-10-15 10:09:51 ----D---- C:\Windows\system32\cs-CZ
2014-10-15 10:09:50 ----D---- C:\Windows\system32\Dism
2014-10-15 10:09:50 ----D---- C:\Program Files\Windows Media Player
2014-10-15 10:09:48 ----D---- C:\Windows\system32\CodeIntegrity
2014-10-15 10:09:48 ----D---- C:\Windows\system32\Boot
2014-10-15 08:47:32 ----D---- C:\Windows\system32\MRT
2014-10-15 08:41:25 ----A---- C:\Windows\system32\MRT.exe
2014-10-05 15:10:20 ----D---- C:\Users\Beny\AppData\Roaming\DAEMON Tools Lite
2014-10-05 13:28:01 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-10-30 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-10-30 206248]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-10-30 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-10-31 787800]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-10-30 422760]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-27 242240]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-10-30 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-10-31 70384]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-10-30 91496]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-10-30 218192]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 DCamUSBSTK03N;Standard_Camera; C:\Windows\system32\DRIVERS\STK03NW2.sys [2009-12-18 108544]
S3 DFX11_1;DFX Audio Enhancer 11.1; C:\Windows\system32\drivers\dfx11_1.sys [2012-12-13 24424]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2012-12-13 45056]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 XFDriver;XFDriver; \??\C:\Program Files\Xfire2\XFDriver.sys [2013-03-14 16648]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-10-30 50344]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Garmin Core Update Service;Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2014-07-01 437080]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-18 639776]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-10-30 3192344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-16 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-29 1260472]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2012-12-01 72704]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-16 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 108032]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-10-21 833728]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-11-23 1343400]

-----------------EOF-----------------

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#20 Příspěvek od Kanarek »

tak vyřešeno to není. Nyní jsem klikl na odkaz na stránkách sbazar.cz a v novém okně mi vyskočilo http://start.webalta.ru.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#21 Příspěvek od Márty84 »

Dela to i v jinych prohlizecich?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#22 Příspěvek od Kanarek »

Používám jen Operu, takže nevím. Jelikož se to děje nahodile mám to otestovat tím, že nějakou dobu budu používat jiný prohlížeč nebo zkusit zběsile klikat na odkazy na nějakých prověřených stránkách (např. seznam.cz)? Případně existuje třetí možnost?

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#23 Příspěvek od Márty84 »

Jelikoz tam uz havet nevidim, bude to zalezle primo v Opere. Budete ji muset preinstalovat.

Na zkousku pak nainstalujte treba Mozillu.



:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#24 Příspěvek od Kanarek »

mám nejdříve přeinstalovat tu operu nebo provést operaci popisovanou výše?

PS: nyní jsem zkoušel otevírat stránku jakcestovat.moxo.cz (stránku sám vytvářím) v chromu a když se mi nechtěla načíst s tím, že je stránka momentálně nedostupná, klikl jsem na podrobnosti o hlášení a vyskočilo okno http://www.roulettebot-plus.com/3a9b7.l ... 4977254274 (informace, jak vydělat 600 EUR denně, takže nějaký spam).
Problém bude nejspíše i v jiných prohlížečích.
Hlášení od avastu s nějakým problémem nevyskočilo.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#25 Příspěvek od Márty84 »

Nejprve preinstalujte Operu, pak spustte OTL podle navodu.

Mozna je zavirovana ta vase stranka.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#26 Příspěvek od Kanarek »

První:

OTL logfile created on: 3.11.2014 9:52:00 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Beny\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 0,63 Gb Available Physical Memory | 31,65% Memory free
4,00 Gb Paging File | 1,94 Gb Available in Paging File | 48,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298,08 Gb Total Space | 81,51 Gb Free Space | 27,34% Space Free | Partition Type: NTFS
Drive D: | 5,60 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 931,48 Gb Total Space | 623,08 Gb Free Space | 66,89% Space Free | Partition Type: NTFS

Computer Name: BENY-PC | User Name: Beny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014.11.03 09:49:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Beny\Desktop\OTL.exe
PRC - [2014.10.31 20:07:54 | 005,223,016 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014.10.30 00:57:35 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.10.30 00:57:25 | 003,192,344 | ---- | M] (Avast Software) -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
PRC - [2014.10.29 08:59:50 | 000,500,344 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\opera_crashreporter.exe
PRC - [2014.10.29 08:59:48 | 050,073,720 | ---- | M] (Opera Software) -- C:\Program Files\Opera\25.0.1614.68_0\opera.exe
PRC - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014.07.01 11:01:36 | 000,437,080 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2013.01.18 15:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013.01.18 15:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013.01.18 07:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.11.23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.12.18 10:23:08 | 000,163,840 | ---- | M] (Syntek Ltd.) -- C:\Windows\STK03N\STK03NM.exe


========== Modules (No Company Name) ==========

MOD - [2014.10.30 01:27:31 | 016,832,176 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_15_0_0_189.dll
MOD - [2014.10.30 00:57:37 | 038,561,576 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014.10.29 08:59:59 | 009,218,680 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\pdf.dll
MOD - [2014.10.29 08:59:55 | 001,310,328 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\libGLESv2.dll
MOD - [2014.10.29 08:59:54 | 000,219,256 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\libEGL.dll
MOD - [2014.10.29 08:59:52 | 000,991,864 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\ffmpegsumo.dll
MOD - [2014.10.29 08:59:50 | 000,500,344 | ---- | M] () -- C:\Program Files\Opera\25.0.1614.68_0\opera_crashreporter.exe
MOD - [2012.02.17 20:55:36 | 000,166,912 | ---- | M] () -- C:\Program Files\Programy\WinRAR\RarExt.dll


========== Services (SafeList) ==========

SRV - [2014.10.30 00:57:35 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014.10.30 00:57:25 | 003,192,344 | ---- | M] (Avast Software) [On_Demand | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
SRV - [2014.10.21 20:22:40 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014.09.19 01:50:15 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.07.01 11:01:36 | 000,437,080 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2013.05.27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013.01.18 07:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.12.29 11:26:54 | 001,260,472 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.11.23 07:12:35 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2014.10.31 20:07:58 | 000,787,800 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsnx.sys -- (aswSnx)
DRV - [2014.10.31 20:07:58 | 000,070,384 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswmonflt.sys -- (aswMonFlt)
DRV - [2014.10.30 00:57:45 | 000,206,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014.10.30 00:57:45 | 000,091,496 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm)
DRV - [2014.10.30 00:57:44 | 000,422,760 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2014.10.30 00:57:44 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014.10.30 00:57:44 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014.10.30 00:57:44 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2014.10.30 00:57:25 | 000,218,192 | ---- | M] (Avast Software) [Kernel | Auto | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
DRV - [2013.03.14 13:36:22 | 000,016,648 | ---- | M] (XFire) [File_System | On_Demand | Stopped] -- C:\Program Files\Xfire2\XFDriver.sys -- (XFDriver)
DRV - [2013.02.25 23:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.12.13 16:41:10 | 000,024,424 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dfx11_1.sys -- (DFX11_1)
DRV - [2012.11.27 22:14:21 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010.11.20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010.11.20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 22:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010.11.20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.12.18 10:51:36 | 000,108,544 | ---- | M] (Syntek Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\STK03NW2.sys -- (DCamUSBSTK03N)
DRV - [2009.07.13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2004.08.13 09:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\..\SearchScopes,DefaultScope = {012E1000-F331-11DB-8314-0800200C9A66}
IE - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Beny\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.10.30 00:57:51 | 000,000,000 | ---D | M]

[2014.03.11 21:03:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Beny\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2204.148_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\iapdadaeaebaoigieglfababneoaifnf\4.1.0.0_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Beny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_4\

O1 HOSTS File: ([2014.10.31 20:25:27 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.195.165.131 217.195.160.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93301838-8932-4374-9AAB-D39B51219DFD}: DhcpNameServer = 217.195.165.131 217.195.160.10
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2014.01.07 21:51:53 | 000,000,000 | ---D | M] - F:\autorun -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.LAGS - C:\Windows\System32\lagarith.dll ( )
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2014.11.03 09:49:20 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Beny\Desktop\OTL.exe
[2014.11.02 16:57:06 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.11.02 16:57:05 | 000,000,000 | ---D | C] -- C:\rsit
[2014.10.31 20:28:41 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014.10.31 20:08:24 | 000,000,000 | ---D | C] -- C:\ComboFix
[2014.10.31 17:45:43 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2014.10.31 17:45:43 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Local\Temp
[2014.10.31 17:15:14 | 000,000,000 | ---D | C] -- C:\zoek_backup
[2014.10.31 16:46:22 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014.10.31 16:45:23 | 001,706,144 | ---- | C] (Thisisu) -- C:\Users\Beny\Desktop\JRT.exe
[2014.10.30 20:59:49 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014.10.30 20:59:49 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014.10.30 20:59:49 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014.10.30 20:58:09 | 005,591,672 | R--- | C] (Swearware) -- C:\Users\Beny\Desktop\ComboFix.exe
[2014.10.30 20:56:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014.10.30 20:56:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014.10.30 01:25:28 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Roaming\DropboxMaster
[2014.10.30 01:24:56 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2014.10.30 01:23:13 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Roaming\Dropbox
[2014.10.30 01:09:09 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\System32\sqlite3.dll
[2014.10.30 01:08:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\vbox
[2014.10.30 01:07:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.10.30 00:59:46 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Roaming\AVAST Software
[2014.10.30 00:59:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014.10.30 00:57:57 | 000,091,496 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys
[2014.10.30 00:57:56 | 000,422,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2014.10.30 00:57:56 | 000,070,384 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswmonflt.sys
[2014.10.30 00:57:55 | 000,081,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014.10.30 00:57:54 | 000,787,800 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014.10.30 00:57:52 | 000,291,352 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014.10.30 00:57:44 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.10.30 00:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014.10.30 00:56:09 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014.10.29 19:10:20 | 000,000,000 | ---D | C] -- C:\FRST
[2014.10.29 19:08:21 | 001,104,896 | ---- | C] (Farbar) -- C:\Users\Beny\Desktop\FRST.exe
[2014.10.14 21:26:47 | 002,379,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014.10.14 21:26:14 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2014.10.14 21:26:14 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2014.10.14 21:26:14 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2014.10.14 21:26:12 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2014.10.14 21:26:11 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014.10.14 21:26:11 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014.10.14 21:26:10 | 000,365,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014.10.14 21:26:10 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2014.10.14 21:26:08 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014.10.14 21:26:07 | 000,440,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014.10.14 21:26:06 | 001,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2014.10.14 21:26:05 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2014.10.14 21:26:03 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2014.10.14 21:26:02 | 004,201,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014.10.14 21:25:56 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014.10.14 21:25:56 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014.10.14 21:25:54 | 000,331,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2014.10.14 21:25:53 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.10.14 21:25:53 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014.10.14 21:25:53 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014.10.14 21:25:51 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014.10.14 21:25:51 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014.10.14 21:25:51 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014.10.14 21:25:44 | 000,156,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2014.10.14 21:25:44 | 000,081,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2014.10.14 21:25:26 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2014.10.14 21:25:24 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2014.10.14 21:25:24 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2014.10.14 21:24:46 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2014.10.14 21:24:33 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
[2014.10.14 21:24:32 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmv2clt.dll
[2014.10.14 21:24:31 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
[2014.10.14 21:24:23 | 003,208,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2014.10.14 21:24:22 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AUDIOKSE.dll
[2014.10.14 21:24:22 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
[2014.10.14 21:24:21 | 000,409,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ci.dll
[2014.10.14 21:24:20 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
[2014.10.14 21:24:19 | 000,521,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2014.10.14 21:24:18 | 003,970,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2014.10.14 21:24:18 | 000,455,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2014.10.14 21:24:17 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDump.dll
[2014.10.14 21:24:14 | 003,914,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2014.10.14 21:24:13 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2014.10.14 21:24:13 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
[2014.10.14 21:24:09 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2014.10.14 21:24:07 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2014.10.14 21:24:06 | 000,374,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioEng.dll
[2014.10.14 21:24:03 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
[2014.10.14 21:24:02 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
[2014.10.14 21:24:02 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
[2014.10.14 21:24:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rrinstaller.exe
[2014.10.14 21:24:01 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2014.10.14 21:24:01 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidpolicyconverter.exe
[2014.10.14 21:24:01 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidapi.dll
[2014.10.14 21:24:00 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setbcdlocale.dll
[2014.10.14 21:24:00 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfpmp.exe
[2014.10.14 21:23:58 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appidcertstorecheck.exe
[2014.10.14 21:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2014.10.14 21:23:56 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2014.10.14 21:23:55 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2014.10.14 21:23:55 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2014.10.14 21:23:55 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mferror.dll
[2014.10.05 13:28:01 | 000,000,000 | ---D | C] -- C:\Users\Beny\AppData\Local\Diagnostics
[14 C:\Users\Beny\Desktop\*.tmp files -> C:\Users\Beny\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014.11.03 09:55:14 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.03 09:49:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Beny\Desktop\OTL.exe
[2014.11.03 09:48:04 | 000,001,093 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.11.03 09:47:16 | 000,004,104 | ---- | M] () -- C:\Users\Beny\Documents\cc_20141103_094641.reg
[2014.11.03 09:41:13 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.03 09:32:56 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.11.03 09:32:55 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.03 09:24:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.11.03 09:24:49 | 1609,424,896 | -HS- | M] () -- C:\hiberfil.sys
[2014.10.31 20:25:27 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2014.10.31 20:07:58 | 000,787,800 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014.10.31 20:07:58 | 000,070,384 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswmonflt.sys
[2014.10.31 17:15:12 | 000,024,064 | ---- | M] () -- C:\Windows\zoek-delete.exe
[2014.10.31 16:58:30 | 001,292,800 | ---- | M] () -- C:\Users\Beny\Desktop\zoek.exe
[2014.10.31 16:45:43 | 001,706,144 | ---- | M] (Thisisu) -- C:\Users\Beny\Desktop\JRT.exe
[2014.10.30 20:58:42 | 005,591,672 | R--- | M] (Swearware) -- C:\Users\Beny\Desktop\ComboFix.exe
[2014.10.30 01:27:31 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014.10.30 01:27:31 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014.10.30 01:00:22 | 001,375,089 | ---- | M] () -- C:\Users\Beny\Desktop\adwcleaner_3.311.exe
[2014.10.30 00:59:13 | 000,002,117 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.10.30 00:57:45 | 000,206,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014.10.30 00:57:45 | 000,091,496 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys
[2014.10.30 00:57:44 | 000,422,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2014.10.30 00:57:44 | 000,291,352 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014.10.30 00:57:44 | 000,081,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014.10.30 00:57:44 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014.10.30 00:57:44 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.10.30 00:57:44 | 000,024,184 | ---- | M] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014.10.30 00:31:13 | 000,000,002 | ---- | M] () -- C:\Users\Beny\rgmnr
[2014.10.29 19:09:56 | 000,015,327 | ---- | M] () -- C:\Users\Beny\Desktop\LM.bat
[2014.10.29 19:08:30 | 001,104,896 | ---- | M] (Farbar) -- C:\Users\Beny\Desktop\FRST.exe
[2014.10.28 19:04:12 | 000,631,054 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2014.10.28 19:04:12 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014.10.28 19:04:12 | 000,121,708 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2014.10.28 19:04:12 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014.10.28 06:35:00 | 000,229,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2014.10.27 22:51:27 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.10.24 12:26:31 | 000,031,020 | ---- | M] () -- C:\Users\Beny\Desktop\misky01.jpg
[2014.10.21 23:36:20 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.10.15 12:01:55 | 000,282,672 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014.10.07 03:04:46 | 000,331,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[14 C:\Users\Beny\Desktop\*.tmp files -> C:\Users\Beny\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014.11.03 09:55:14 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.11.03 09:48:04 | 000,001,093 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.11.03 09:48:04 | 000,001,093 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2014.11.03 09:46:49 | 000,004,104 | ---- | C] () -- C:\Users\Beny\Documents\cc_20141103_094641.reg
[2014.10.31 17:45:45 | 000,024,064 | ---- | C] () -- C:\Windows\zoek-delete.exe
[2014.10.31 17:14:56 | 001,292,800 | ---- | C] () -- C:\Users\Beny\Desktop\zoek.exe
[2014.10.30 20:59:49 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014.10.30 20:59:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014.10.30 20:59:49 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014.10.30 20:59:49 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014.10.30 20:59:49 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014.10.30 00:59:53 | 001,375,089 | ---- | C] () -- C:\Users\Beny\Desktop\adwcleaner_3.311.exe
[2014.10.30 00:59:13 | 000,002,117 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.10.30 00:57:56 | 000,206,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014.10.30 00:57:56 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014.10.30 00:57:55 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014.10.29 19:09:56 | 000,015,327 | ---- | C] () -- C:\Users\Beny\Desktop\LM.bat
[2014.10.24 12:26:12 | 000,031,020 | ---- | C] () -- C:\Users\Beny\Desktop\misky01.jpg
[2014.07.25 09:37:03 | 000,000,003 | ---- | C] () -- C:\Users\Beny\stut
[2014.07.25 09:34:37 | 000,000,002 | ---- | C] () -- C:\Users\Beny\rgmnr
[2014.07.24 20:10:57 | 000,100,864 | --S- | C] () -- C:\Windows\System32\zlib1.dll
[2014.07.24 20:10:56 | 000,538,126 | --S- | C] () -- C:\Windows\System32\libcurl-4.dll
[2014.07.24 20:10:56 | 000,192,512 | --S- | C] () -- C:\Windows\System32\libidn-11.dll
[2014.07.24 20:10:56 | 000,133,632 | --S- | C] () -- C:\Windows\System32\librtmp.dll
[2014.07.24 18:41:40 | 000,082,072 | ---- | C] () -- C:\Windows\cadkasdeinst01e.exe
[2014.07.14 20:50:07 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2014.07.14 20:49:55 | 000,000,045 | ---- | C] () -- C:\Windows\sierra.ini
[2013.05.10 14:54:23 | 000,005,120 | ---- | C] () -- C:\Users\Beny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.12.28 22:04:22 | 000,036,352 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2012.12.10 22:59:08 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
[2012.12.10 22:59:07 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012.12.10 22:59:07 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012.12.10 22:58:57 | 000,112,640 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012.11.28 18:33:57 | 000,000,376 | ---- | C] () -- C:\Windows\mozregistry.dat
[2012.11.22 17:34:40 | 000,000,384 | ---- | C] () -- C:\Windows\ODBC.INI

========== ZeroAccess Check ==========

[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.03.25 03:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013.07.03 20:49:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\All Free iPad Video Converter
[2014.10.30 00:59:46 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\AVAST Software
[2013.11.16 12:31:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bioshock2
[2014.05.23 11:41:43 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bombermaaan
[2013.04.11 23:34:29 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer
[2012.11.22 23:00:06 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer Pro
[2014.07.24 18:41:54 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\CAD-KAS
[2014.10.22 18:46:07 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Canon
[2013.02.14 22:19:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\COWON
[2014.10.05 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DAEMON Tools Lite
[2014.10.30 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Dropbox
[2014.10.30 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DropboxMaster
[2014.07.24 20:42:32 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\everysale
[2014.06.30 15:06:36 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Garmin
[2013.10.09 20:08:02 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\GHISLER
[2012.11.21 20:21:56 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera
[2013.09.22 18:07:40 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera Software
[2014.07.29 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\PDF Architect 2
[2014.03.11 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Thunderbird
[2014.05.15 16:41:42 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Unity
[2014.10.31 20:05:33 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\uTorrent
[2014.07.24 10:06:05 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Garmin
[2014.07.24 10:06:05 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Garmin

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009.07.14 05:53:46 | 000,032,522 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 05:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2013.11.16 20:04:12 | 000,000,936 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.11.16 20:04:14 | 000,000,940 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< >

< MD5 for: AGP440.SYS >
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\erdnt\cache\AGP440.sys
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\erdnt\cache\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010.11.20 22:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\System32\autochk.exe
[2010.11.20 22:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2010.11.20 22:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\drivers\cdrom.sys
[2010.11.20 22:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys
[2010.11.20 22:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\erdnt\cache\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll

< MD5 for: CRYPTSVC.DLL >
[2012.06.02 05:52:32 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=063DD65889D21035311463337BD268E7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_788c7cc71232cc19\cryptsvc.dll
[2013.05.13 05:45:55 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=3897DFF247D9ED0006190349DE264E14 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_77d8a461f934afb8\cryptsvc.dll
[2014.07.07 02:40:07 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=623E143F2DF17C0106A9988F5D7DC878 -- C:\Windows\erdnt\cache\cryptsvc.dll
[2014.07.07 02:40:07 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=623E143F2DF17C0106A9988F5D7DC878 -- C:\Windows\System32\cryptsvc.dll
[2014.07.07 02:40:07 | 000,143,872 | ---- | M] (Microsoft Corporation) MD5=623E143F2DF17C0106A9988F5D7DC878 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18526_none_77fe1d2ff917cf34\cryptsvc.dll
[2013.07.09 14:57:37 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=6DB499DEFCC827317C5371164A7CDB27 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_7840d305126b8725\cryptsvc.dll
[2013.07.09 05:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=7CA1BECEA5DE2643ADDAD32670E7A4C9 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_7812b70bf9088686\cryptsvc.dll
[2014.07.07 02:40:42 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=90BFC30E730A6760F1FEE2A55F8AB029 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22736_none_787cebf5123d8816\cryptsvc.dll
[2012.06.02 05:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=96C0E38905CFD788313BE8E11DAE3F2F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_77ddc9e5f93000db\cryptsvc.dll
[2010.11.20 22:29:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
[2013.05.11 05:59:05 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=AC04D05309BB2C418D0D80B9FB014642 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_7883b3211239122d\cryptsvc.dll
[2013.10.05 02:52:03 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=F2D9242C3BBD1C36467FCAE1AE01733F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_784ea5b51260b460\cryptsvc.dll

< MD5 for: EXPLORER.EXE >
[2010.11.20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\erdnt\cache\explorer.exe
[2010.11.20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\explorer.exe
[2010.11.20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe

< MD5 for: HAL.DLL >
[2010.11.20 22:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\System32\hal.dll
[2010.11.20 22:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_ad305c8fb7ec5060\hal.dll

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#27 Příspěvek od Kanarek »

< MD5 for: IASTORV.SYS >
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\drivers\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\drivers\isapnp.sys
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\isapnp.sys
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\isapnp.sys

< MD5 for: LSASS.EXE >
[2013.09.25 01:54:21 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=559C7769B397F07E12725EE55337D4C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22465_none_a8a66792d452b56a\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22653_none_a8af3ab6d44c6119\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22712_none_a8d97c02d42cd525\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22736_none_a8c7dd52d4397263\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22807_none_a8e94f46d420350e\lsass.exe
[2013.09.25 01:49:20 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=803B370865D907EA21DC0C2B6A8936B5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18270_none_a80cf783bb41b5b7\lsass.exe
[2011.11.17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=81951F51E318AECC2D68559E47485CC4 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_a84828d7bb1480d7\lsass.exe
[2011.11.17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=81951F51E318AECC2D68559E47485CC4 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_a828bb43bb2beb28\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\erdnt\cache\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\System32\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18443_none_a8306bf1bb26a837\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18496_none_a7fd5d33bb4c7ff1\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18526_none_a8490e8dbb13b981\lsass.exe
[2009.07.14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_a851f4adbb0d5141\lsass.exe
[2012.06.02 05:51:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=FA7B950E4CA6AA260C4EABA19E03644D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_a8d76e24d42eb666\lsass.exe
[2011.11.17 06:24:04 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=FBCB2DFA40862DAA7B1534C9538208A5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_a8a284cad4562b09\lsass.exe

< MD5 for: NDIS.SYS >
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\erdnt\cache\ndis.sys
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\System32\drivers\ndis.sys
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_a9ce95b27a512623\ndis.sys

< MD5 for: NETLOGON.DLL >
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\erdnt\cache\netlogon.dll
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll

< MD5 for: NVRAID.SYS >
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\System32\drivers\nvraid.sys
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\drivers\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys

< MD5 for: SCECLI.DLL >
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\erdnt\cache\scecli.dll
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll

< MD5 for: SMSS.EXE >
[2013.03.19 03:43:41 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=0294CC751D7FAEB13621EEFB8A749429 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22280_none_ae7bdfb790cddbcf\smss.exe
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
[2013.07.08 04:02:28 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=634E0B45780F502304592C5615A31089 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22379_none_ae8fb42390bda114\smss.exe
[2013.11.26 20:08:17 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D2A72C71CD6C18A99E920EC5761F0C7D -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22436_none_aeb7f4db909fe272\smss.exe
[2014.04.12 03:06:24 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D8A5E3B8EB601B897AC78B060177E460 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22653_none_ae9f57f190b2c89d\smss.exe
[2014.04.12 03:06:24 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D8A5E3B8EB601B897AC78B060177E460 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22780_none_ae7be93590cdcd92\smss.exe
[2013.03.19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=DE91DCC7BC55E940979097E98F743205 -- C:\Windows\System32\smss.exe
[2013.03.19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=DE91DCC7BC55E940979097E98F743205 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18113_none_ae40f33e7774c473\smss.exe
[2013.05.06 04:02:20 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=EC745C0949B101129AB6D39CD63808A6 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22318_none_aecf9361908de017\smss.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: TCPIP.SYS >
[2012.08.22 18:05:21 | 001,306,992 | ---- | M] (Microsoft Corporation) MD5=23790A44D9A6B67F8690C34D4F516446 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_b55b785ade04500f\tcpip.sys
[2011.04.25 05:31:30 | 001,290,624 | ---- | M] (Microsoft Corporation) MD5=24326784DF8F3D5F5BBB9F878CE33C14 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_b52f4dc5c4a121e0\tcpip.sys
[2010.11.20 22:29:20 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys
[2013.01.04 05:56:23 | 001,308,504 | ---- | M] (Microsoft Corporation) MD5=4A95845C5F33A4DDEB6AEF6367FB6520 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_b5becc06ddb98192\tcpip.sys
[2013.07.06 06:05:35 | 001,293,760 | ---- | M] (Microsoft Corporation) MD5=4E8B9BE71B807B3BAEDB7F4243F85E3C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_b52f2f65c4a146e5\tcpip.sys
[2013.07.06 05:57:37 | 001,309,120 | ---- | M] (Microsoft Corporation) MD5=528F7CC60391DD0FAB0344F32F051FDF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_b5721e2eddf328f9\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\erdnt\cache\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\System32\drivers\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18438_none_b513c4dfc4b513b9\tcpip.sys
[2013.05.08 07:15:22 | 001,309,032 | ---- | M] (Microsoft Corporation) MD5=6088D01FAD49729EA0A5A3D9B9BA8B84 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_b5b3fe00ddc19aaa\tcpip.sys
[2013.11.26 20:07:52 | 001,309,120 | ---- | M] (Microsoft Corporation) MD5=6C4F3D92764FFA22D28061A4D9235446 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_b58e8eb0ddde6cf1\tcpip.sys
[2011.04.25 07:31:09 | 001,301,376 | ---- | M] (Microsoft Corporation) MD5=6D4728CFF2724FF3A4654971D61D0F1C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_b5ad1a5addc7c444\tcpip.sys
[2013.01.03 06:05:20 | 001,293,672 | ---- | M] (Microsoft Corporation) MD5=7C0507D2391AF5933600CBCED799F277 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_b502eb9fc4c2a304\tcpip.sys
[2012.03.30 11:23:11 | 001,291,632 | ---- | M] (Microsoft Corporation) MD5=7FA2E0F8B072BD04B77B421480B6CC22 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_b52e5147c4a202d7\tcpip.sys
[2012.03.30 10:04:23 | 001,306,480 | ---- | M] (Microsoft Corporation) MD5=88FCDB9923EFECA207B3CEBD24407126 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_b583df0adde66104\tcpip.sys
[2012.08.22 18:16:54 | 001,292,144 | ---- | M] (Microsoft Corporation) MD5=A5EBB8F648000E88B7D9390B514976BF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_b514e56fc4b40532\tcpip.sys
[2013.11.26 20:07:52 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=CA59F7C570AF70BC174F477CFE2D9EE3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_b4fa2013c4c8ebf1\tcpip.sys
[2013.05.08 06:38:00 | 001,293,672 | ---- | M] (Microsoft Corporation) MD5=D32FDAC73FCD76B85389C39BC1087F2A -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_b508ef41c4bd3835\tcpip.sys
[2014.04.05 03:16:21 | 001,310,144 | ---- | M] (Microsoft Corporation) MD5=EA47AB18E289333AB94397D77CA6E3A1 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22648_none_b59293a4dddacc9b\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe

< MD5 for: WINLOGON.EXE >
[2014.07.16 03:56:14 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=4F37B93C14AEE313BEC52A23AFB15C2E -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_7224b2134c7555fa\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\erdnt\cache\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\System32\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_71a5e34e334f9d18\winlogon.exe
[2010.11.20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2014.03.04 10:17:02 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=998507B046BA314CE8245364C686FA67 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_71da23b23327143c\winlogon.exe
[2014.03.04 11:39:02 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=D53972F87D850CD2EB4B29B60CAFDD77 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_7255f1994c4f8119\winlogon.exe

< MD5 for: WS2_32.DLL >
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\erdnt\cache\ws2_32.dll
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\System32\ws2_32.dll
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[10 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[14 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2013.01.01 19:38:25 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Adobe
[2013.07.03 20:49:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\All Free iPad Video Converter
[2013.07.04 17:31:52 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Apple Computer
[2012.12.09 20:10:24 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\ArcSoft
[2014.10.30 00:59:46 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\AVAST Software
[2013.11.16 12:31:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bioshock2
[2014.05.23 11:41:43 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bombermaaan
[2013.04.11 23:34:29 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer
[2012.11.22 23:00:06 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer Pro
[2014.07.24 18:41:54 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\CAD-KAS
[2014.10.22 18:46:07 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Canon
[2013.02.14 22:19:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\COWON
[2012.11.22 16:24:11 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\CyberLink
[2014.10.05 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DAEMON Tools Lite
[2014.10.30 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Dropbox
[2014.10.30 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DropboxMaster
[2014.07.24 20:42:32 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\everysale
[2014.06.30 15:06:36 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Garmin
[2013.10.09 20:08:02 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\GHISLER
[2012.11.21 20:16:47 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Identities
[2012.12.02 16:00:03 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\InstallShield
[2012.12.02 10:56:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Macromedia
[2011.04.12 02:46:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Media Center Programs
[2013.10.31 22:25:41 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Media Player Classic
[2013.11.17 20:14:10 | 000,000,000 | --SD | M] -- C:\Users\Beny\AppData\Roaming\Microsoft
[2014.03.11 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Mozilla
[2014.01.02 20:08:28 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\NVIDIA
[2012.11.21 20:21:56 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera
[2013.09.22 18:07:40 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera Software
[2014.07.29 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\PDF Architect 2
[2014.03.11 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Thunderbird
[2014.05.15 16:41:42 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Unity
[2014.10.31 20:05:33 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\uTorrent
[2012.11.27 22:20:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\WinRAR
[2013.11.20 18:14:19 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Xfire

< %APPDATA%\*.exe /s >
[2009.08.11 21:21:26 | 000,087,552 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 21:21:30 | 000,090,112 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 14:52:04 | 000,697,690 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
[2012.10.11 09:01:20 | 001,175,371 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\FFDShow\unins000.exe
[2010.08.14 10:42:54 | 000,113,152 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 10:45:10 | 000,358,400 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 10:42:06 | 000,137,728 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 15:30:22 | 000,042,305 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
[2014.03.19 13:17:02 | 032,667,896 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2014.03.19 13:18:14 | 000,244,648 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2014.03.19 13:17:06 | 000,143,616 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2014.10.30 00:30:12 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\uTorrent.exe
[2014.02.06 20:24:52 | 000,905,296 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.3.2_30488.exe
[2014.04.28 19:58:56 | 001,270,352 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_30888.exe
[2014.05.15 08:16:44 | 001,272,400 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_31139.exe
[2014.06.14 08:18:57 | 001,267,536 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_31395.exe
[2014.07.02 20:37:00 | 001,322,832 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_32126.exe
[2014.09.20 06:51:59 | 001,416,016 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34024.exe
[2014.10.08 08:21:55 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34309.exe
[2014.10.30 00:30:12 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34944.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >
[2014.10.31 20:07:58 | 000,070,384 | ---- | M] (AVAST Software) -- C:\Windows\system32\drivers\aswmonflt.sys
[2014.10.31 20:07:58 | 000,787,800 | ---- | M] (AVAST Software) -- C:\Windows\system32\drivers\aswsnx.sys

< %systemroot%\system32\*.* /3 >
[2014.10.31 15:58:00 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-14-57-51.039-AvastVBoxSVC.exe-4236.log
[2014.10.31 16:53:11 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-52-52.082-aswFe.exe-6068.log
[2014.10.31 16:54:33 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-54-14.066-aswFe.exe-1104.log
[2014.10.31 16:59:23 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-59-07.051-aswFe.exe-6032.log
[2014.10.31 17:00:05 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-59-49.010-aswFe.exe-3184.log
[2014.10.31 17:02:58 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-02-40.059-aswFe.exe-3908.log
[2014.10.31 17:15:16 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-15-14.098-AvastVBoxSVC.exe-2060.log
[2014.10.31 17:49:49 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-49-47.090-AvastVBoxSVC.exe-3260.log
[2014.10.31 20:08:21 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-19-08-21.016-AvastVBoxSVC.exe-1744.log
[2014.10.31 20:27:16 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-19-27-14.095-AvastVBoxSVC.exe-3160.log
[2014.11.02 16:54:33 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-11-02-15-54-24.037-AvastVBoxSVC.exe-3400.log
[2014.11.03 09:27:48 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-11-03-08-27-44.038-AvastVBoxSVC.exe-3608.log
[2014.11.03 09:32:55 | 000,021,904 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.03 09:32:56 | 000,021,904 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.11.03 09:55:14 | 000,000,512 | ---- | M] () MD5=C6D65CF37E024B3ED21CF4BDC5F64DAF -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2013.09.29 21:22:42 | 000,003,072 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.cracked.com_0.localstorage
[2013.09.29 21:22:42 | 000,003,608 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.cracked.com_0.localstorage-journal
[2012.11.27 18:03:04 | 000,035,529 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Call.of.Duty.Modern.Warfare.3.for.PC.with.Crack.rar.torrent
[2012.12.03 19:58:24 | 000,012,448 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - BESTFull Version With Crack!!.torrent
[2012.12.03 19:39:45 | 000,001,215 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - čeština,crack ,keygen.torrent

< *keygen* /s >
[2012.12.03 19:39:45 | 000,001,215 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - čeština,crack ,keygen.torrent
[2009.08.13 18:11:02 | 000,088,399 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen.rar
[2009.03.18 19:27:22 | 000,095,232 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen\keygen.exe
[2006.03.21 10:44:16 | 000,050,586 | ---- | M] () -- \Users\Beny\Downloads\Adobe-Acrobat-6.0-CE-Professional\Adobe Acrobat 6.0 CE Professional\Adobe_Acrobat_v6.0_Keygen.zip
[2003.06.25 01:17:16 | 000,053,434 | ---- | M] () -- \Users\Beny\Downloads\Adobe-Acrobat-6.0-CE-Professional\Adobe Acrobat 6.0 CE Professional\Adobe_Acrobat_v6.0_Keygen\acrobat 6 keygen.exe

< *AntiWPA* /s >

< *loader* /s >
[2005.03.24 13:51:08 | 000,002,090 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge\Resources\en\_media\rssloader.swf
[2014.10.30 00:57:35 | 000,072,480 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
[2005.03.16 19:16:50 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2014.07.01 11:00:40 | 000,042,496 | ---- | M] () -- \Program Files\Garmin\Core Update Service\Garmin.Cartography.MyDownloader.Core.dll
[2001.10.15 13:51:40 | 000,003,065 | ---- | M] () -- \Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\uriloader.xpt
[2013.10.23 21:07:40 | 000,007,825 | ---- | M] () -- \Program Files\Hry\Steam\remoteui\static\libs\images\ajax-loader.gif
[2012.11.21 20:44:07 | 000,051,200 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Absolution\PhysXLoader.dll
[2013.01.27 12:06:24 | 000,333,840 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.WAV
[2013.01.27 12:06:24 | 000,005,952 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.WHD
[2013.01.27 12:06:24 | 000,351,949 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.ZIP
[2013.01.27 12:06:39 | 000,313,360 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.WAV
[2013.01.27 12:06:24 | 000,005,392 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.WHD
[2013.01.27 12:06:33 | 000,570,691 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.WHD
[2013.01.27 12:06:50 | 000,711,223 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.WHD
[2013.01.27 12:08:07 | 000,634,201 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.WHD
[2013.01.27 12:08:36 | 000,707,294 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.WHD
[2013.01.27 12:07:30 | 000,531,761 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.WHD
[2013.01.27 12:08:15 | 000,591,946 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.WHD
[2013.01.27 12:10:24 | 000,617,459 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.WHD
[2013.01.27 12:08:13 | 000,440,664 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.WHD
[2013.01.27 12:08:54 | 000,550,700 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.WHD
[2013.01.27 12:10:46 | 000,650,200 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.WHD
[2013.01.27 12:10:53 | 000,596,635 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.WHD
[2013.01.27 12:10:57 | 000,668,734 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.WHD
[2013.01.27 12:09:28 | 000,632,940 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.ZIP
[2013.08.18 20:00:42 | 000,057,856 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Sniper Challenge\PhysXLoader.dll
[2013.08.03 16:23:12 | 000,329,232 | ---- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\ubiorbitapi_r2_loader.dll
[2013.08.21 04:41:00 | 000,037,376 | R--- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\uplay_r1_loader.dll
[2012.11.01 09:32:14 | 000,057,224 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2012.09.04 23:34:12 | 000,083,848 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \Program Files\Programy\The KMPlayer\ImLoader.dll
[2012.12.03 19:46:55 | 000,000,214 | ---- | M] () -- \Users\Beny\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fstep.yourfiledownloader.com%2Fstatic%2Fa%2Fimages%2Ffavicon.png
[2014.06.03 22:04:32 | 000,000,121 | ---- | M] () -- \Users\Beny\AppData\Roaming\Unity\WebPlayerPrefs\ultimate_2ddisassembly_2ecom\prefloader2_2eunity3d.upp
[2010.08.04 19:42:20 | 000,032,349 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.0.1-cs_CZ\wordpress\wp-includes\script-loader.php
[2010.08.04 19:42:22 | 000,001,893 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.0.1-cs_CZ\wordpress\wp-includes\template-loader.php
[2014.05.01 03:27:16 | 000,047,934 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\script-loader.php
[2013.10.30 13:39:10 | 000,002,747 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\template-loader.php
[2014.02.13 07:03:14 | 000,003,878 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\images\uploader-icons-2x.png
[2014.02.13 07:03:14 | 000,001,556 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\images\uploader-icons.png
[2013.11.15 03:31:10 | 000,004,281 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\customize-loader.js
[2013.11.13 20:45:12 | 000,002,539 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\customize-loader.min.js
[2013.12.28 22:53:16 | 000,002,608 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\tinymce\skins\lightgray\img\loader.gif
[2013.08.02 02:48:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.07.14 05:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2014.10.15 08:38:46 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60.manifest
[2014.10.15 08:38:46 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60_winload.exe.mui_3bc5b827
[2014.10.15 08:38:46 | 000,030,272 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60_winresume.exe.mui_ff8b5358
[2014.10.15 08:38:53 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a.manifest
[2014.10.15 08:38:53 | 000,521,384 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a_winload.exe_75835076
[2014.10.15 08:38:54 | 000,455,752 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a_winresume.exe_85cd1215
[2009.07.14 03:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 03:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2011.04.12 02:36:26 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2014.07.08 22:41:55 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60.manifest
[2014.07.08 22:42:00 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22736_cs-cz_35bfc13a7477b442.manifest
[2010.11.20 22:23:54 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2014.08.19 04:02:10 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a.manifest
[2014.08.19 04:09:35 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22780_none_5d67fb6ae4430e20.manifest
[2009.07.14 02:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 17:40:37 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 02:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 17:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 05:43:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22209_none_0d52a9aaf32333d8\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 06:53:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_0d3fdb3af3327f5f\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.03.04 11:35:49 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22616_none_0d44e078f32df860\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.04.12 03:03:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22653_none_0d169feaf3511c1f\api-ms-win-core-libraryloader-l1-1-0.dll

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >

< *activator* /s >

< *serial* /s >
[2013.08.03 16:22:08 | 000,120,336 | ---- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Launcher_SharePoint.XmlSerializers.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2013.06.09 20:10:31 | 000,000,581 | ---- | M] () -- \Users\Beny\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.serialzone.cz%2Ffavicon.png
[3 \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp files -> \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp -> ]
[2014.07.18 08:37:16 | 000,005,120 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.serialzone.cz_0.localstorage
[2014.07.18 08:37:16 | 000,003,608 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2005.12.06 21:02:38 | 000,794,268 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\Serials.exe
[2011.01.20 22:09:38 | 000,000,783 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\jquery\jquery.serialize-object.js
[2013.07.08 13:43:48 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.10.15 12:16:41 | 000,310,784 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\91eb4f41130c65ef17f0fee1d3ab48fb\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.15 19:09:09 | 002,347,008 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\b1e0939384cc320d6ac7b8921ccc2877\System.Runtime.Serialization.ni.dll
[2014.10.15 09:14:56 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8c4fe3e44341707d99100b07b6a259ef\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.09.11 23:24:01 | 002,656,768 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\974ec1c5604d87c64b2368c1a2074296\System.Runtime.Serialization.ni.dll
[2014.09.13 15:29:32 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a366e9e1ffc94991f5a6dc706abd9d59\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.15 09:14:50 | 002,656,768 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\c9614599d9cc883cb6d8682a901c6a01\System.Runtime.Serialization.ni.dll
[2014.09.13 15:32:23 | 000,009,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\1fcf609cac2b1ce3b6efaf0c822cee24\System.Xml.Serialization.ni.dll
[2010.03.18 12:16:28 | 001,026,936 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\5C1093C35543A0E32A41B090A305076A\4.0.30319\System.Runtime.Serialization.dll.x86
[2013.08.30 20:31:15 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.10.15 08:56:14 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.30 20:31:15 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2014.10.15 08:56:12 | 001,038,016 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.10.15 08:56:18 | 000,012,080 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.07.10 23:24:11 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.03 06:17:44 | 001,038,016 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 12:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2012.01.21 16:40:04 | 000,012,080 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2010.06.15 01:33:16 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.06.15 01:33:16 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2011.04.12 02:36:50 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\drivers\serial.sys
[2011.04.12 02:36:55 | 000,009,728 | ---- | M] () -- \Windows\System32\drivers\cs-CZ\serial.sys.mui
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\mdmmotsm.inf_x86_neutral_c1415d9789c54b89\smserial.sys
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_x86_neutral_63e72c669d043f14\grserial.sys
[2009.07.14 03:18:03 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 03:18:03 | 000,015,952 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486_kdcom.dll_db5e7744
[2011.04.12 02:37:09 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed_serialui.dll.mui_7d29d2a3
[2009.07.14 03:18:51 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a_serialui.dll_bea29328
[2010.11.20 22:24:56 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c.manifest
[2012.10.05 18:15:39 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285.manifest
[2014.07.02 06:57:49 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29.manifest
[2014.07.14 03:04:09 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf.manifest
[2012.10.05 18:17:50 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d.manifest
[2014.07.02 07:07:46 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7.manifest
[2014.07.14 03:04:27 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e.manifest
[2011.04.12 02:36:33 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0.manifest
[2012.10.05 20:04:43 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f.manifest
[2014.07.02 07:50:42 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43.manifest
[2014.07.14 04:14:58 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9.manifest
[2012.10.05 20:02:24 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797.manifest
[2014.07.02 21:15:55 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1.manifest
[2014.07.14 04:04:07 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48.manifest
[2010.11.20 22:24:56 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f.manifest
[2012.10.05 18:15:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8.manifest
[2014.07.02 07:00:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c.manifest
[2014.07.14 03:06:40 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12.manifest
[2012.10.05 18:17:15 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0.manifest
[2014.07.02 07:10:04 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a.manifest
[2014.07.14 03:06:53 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061.manifest
[2009.07.14 02:49:26 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 02:45:27 | 000,000,866 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.1.7600.16385_none_2c93290b67c98d09.manifest
[2010.11.20 22:24:56 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1.manifest
[2012.10.05 18:19:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa.manifest
[2014.07.02 06:58:58 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e.manifest
[2014.07.14 03:05:25 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754.manifest
[2012.10.05 18:22:10 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2.manifest
[2014.07.02 07:08:55 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c.manifest
[2014.07.14 03:05:41 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3.manifest
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_1c9a3ec1e01c684b\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.18523_none_1c70653de072abde\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 00:43:36 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.22733_none_05a3bea3fa19258c\System.Runtime.Serialization.Formatters.Soap.dll
[2011.04.12 02:36:53 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7600.16385_cs-cz_d5c3552dd9b47144\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.07.08 13:43:48 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7601.18523_cs-cz_d5997ba9da0ab4d7\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c\System.Runtime.Serialization.dll
[2012.10.05 11:53:24 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29\System.Runtime.Serialization.dll
[2014.07.10 23:24:11 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf\System.Runtime.Serialization.dll
[2012.10.05 11:56:07 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d\System.Runtime.Serialization.dll
[2014.03.17 15:38:28 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e\System.Runtime.Serialization.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0\System.RunTime.Serialization.Resources.dll
[2010.11.13 02:55:26 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48\System.RunTime.Serialization.Resources.dll
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f\System.Runtime.Serialization.dll
[2012.10.05 11:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c\System.Runtime.Serialization.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12\System.Runtime.Serialization.dll
[2012.10.05 11:56:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0\System.Runtime.Serialization.dll
[2014.03.17 15:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061\System.Runtime.Serialization.dll
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\winsxs\x86_mdmmotsm.inf_31bf3856ad364e35_6.1.7600.16385_none_7a97936f8a972896\smserial.sys
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_c233d4df09982c29\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_c227ede109a14864\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.22731_cs-cz_c2a4bc1222c8ce98\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:50 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed\serialui.dll.mui
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a\serialui.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_5f7b7c7cb0c0f266\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_5f6f957eb0ca0ea1\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.22733_cs-cz_5fee6443c9efc783\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:55 | 000,009,728 | ---- | M] () -- \Windows\winsxs\x86_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_c48c78a9ad8ff996\serial.sys.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\winsxs\x86_smartcrd.inf_31bf3856ad364e35_6.1.7600.16385_none_7280378295916274\grserial.sys
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1\System.Runtime.Serialization.dll
[2012.10.05 11:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e\System.Runtime.Serialization.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754\System.Runtime.Serialization.dll
[2012.10.05 11:56:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2\System.Runtime.Serialization.dll
[2014.03.17 15:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3\System.Runtime.Serialization.dll

< *w7lxe* /s >

< End of report >

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#28 Příspěvek od Kanarek »

< MD5 for: IASTORV.SYS >
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\drivers\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\drivers\isapnp.sys
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\isapnp.sys
[2009.07.14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\isapnp.sys

< MD5 for: LSASS.EXE >
[2013.09.25 01:54:21 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=559C7769B397F07E12725EE55337D4C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22465_none_a8a66792d452b56a\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22653_none_a8af3ab6d44c6119\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22712_none_a8d97c02d42cd525\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22736_none_a8c7dd52d4397263\lsass.exe
[2014.04.12 03:06:16 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=627B40EB2595D8FCF1960F33389EB7D3 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22807_none_a8e94f46d420350e\lsass.exe
[2013.09.25 01:49:20 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=803B370865D907EA21DC0C2B6A8936B5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18270_none_a80cf783bb41b5b7\lsass.exe
[2011.11.17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=81951F51E318AECC2D68559E47485CC4 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_a84828d7bb1480d7\lsass.exe
[2011.11.17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=81951F51E318AECC2D68559E47485CC4 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_a828bb43bb2beb28\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\erdnt\cache\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\System32\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18443_none_a8306bf1bb26a837\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18496_none_a7fd5d33bb4c7ff1\lsass.exe
[2014.04.12 03:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=DD17E1573651293D4ED31053795B3471 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18526_none_a8490e8dbb13b981\lsass.exe
[2009.07.14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_a851f4adbb0d5141\lsass.exe
[2012.06.02 05:51:22 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=FA7B950E4CA6AA260C4EABA19E03644D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_a8d76e24d42eb666\lsass.exe
[2011.11.17 06:24:04 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=FBCB2DFA40862DAA7B1534C9538208A5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_a8a284cad4562b09\lsass.exe

< MD5 for: NDIS.SYS >
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\erdnt\cache\ndis.sys
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\System32\drivers\ndis.sys
[2010.11.20 22:29:12 | 000,712,576 | ---- | M] (Microsoft Corporation) MD5=E7C54812A2AAF43316EB6930C1FFA108 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_a9ce95b27a512623\ndis.sys

< MD5 for: NETLOGON.DLL >
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\erdnt\cache\netlogon.dll
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll

< MD5 for: NVRAID.SYS >
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\System32\drivers\nvraid.sys
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.20 22:29:03 | 000,117,120 | ---- | M] (NVIDIA Corporation) MD5=AF2EEC9580C1D32FB7EAF105D9784061 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\drivers\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys

< MD5 for: SCECLI.DLL >
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\erdnt\cache\scecli.dll
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll

< MD5 for: SMSS.EXE >
[2013.03.19 03:43:41 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=0294CC751D7FAEB13621EEFB8A749429 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22280_none_ae7bdfb790cddbcf\smss.exe
[2009.07.14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
[2013.07.08 04:02:28 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=634E0B45780F502304592C5615A31089 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22379_none_ae8fb42390bda114\smss.exe
[2013.11.26 20:08:17 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D2A72C71CD6C18A99E920EC5761F0C7D -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22436_none_aeb7f4db909fe272\smss.exe
[2014.04.12 03:06:24 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D8A5E3B8EB601B897AC78B060177E460 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22653_none_ae9f57f190b2c89d\smss.exe
[2014.04.12 03:06:24 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=D8A5E3B8EB601B897AC78B060177E460 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22780_none_ae7be93590cdcd92\smss.exe
[2013.03.19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=DE91DCC7BC55E940979097E98F743205 -- C:\Windows\System32\smss.exe
[2013.03.19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=DE91DCC7BC55E940979097E98F743205 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18113_none_ae40f33e7774c473\smss.exe
[2013.05.06 04:02:20 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=EC745C0949B101129AB6D39CD63808A6 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22318_none_aecf9361908de017\smss.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: TCPIP.SYS >
[2012.08.22 18:05:21 | 001,306,992 | ---- | M] (Microsoft Corporation) MD5=23790A44D9A6B67F8690C34D4F516446 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_b55b785ade04500f\tcpip.sys
[2011.04.25 05:31:30 | 001,290,624 | ---- | M] (Microsoft Corporation) MD5=24326784DF8F3D5F5BBB9F878CE33C14 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_b52f4dc5c4a121e0\tcpip.sys
[2010.11.20 22:29:20 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys
[2013.01.04 05:56:23 | 001,308,504 | ---- | M] (Microsoft Corporation) MD5=4A95845C5F33A4DDEB6AEF6367FB6520 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_b5becc06ddb98192\tcpip.sys
[2013.07.06 06:05:35 | 001,293,760 | ---- | M] (Microsoft Corporation) MD5=4E8B9BE71B807B3BAEDB7F4243F85E3C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_b52f2f65c4a146e5\tcpip.sys
[2013.07.06 05:57:37 | 001,309,120 | ---- | M] (Microsoft Corporation) MD5=528F7CC60391DD0FAB0344F32F051FDF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_b5721e2eddf328f9\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\erdnt\cache\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\System32\drivers\tcpip.sys
[2014.04.05 03:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18438_none_b513c4dfc4b513b9\tcpip.sys
[2013.05.08 07:15:22 | 001,309,032 | ---- | M] (Microsoft Corporation) MD5=6088D01FAD49729EA0A5A3D9B9BA8B84 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_b5b3fe00ddc19aaa\tcpip.sys
[2013.11.26 20:07:52 | 001,309,120 | ---- | M] (Microsoft Corporation) MD5=6C4F3D92764FFA22D28061A4D9235446 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_b58e8eb0ddde6cf1\tcpip.sys
[2011.04.25 07:31:09 | 001,301,376 | ---- | M] (Microsoft Corporation) MD5=6D4728CFF2724FF3A4654971D61D0F1C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_b5ad1a5addc7c444\tcpip.sys
[2013.01.03 06:05:20 | 001,293,672 | ---- | M] (Microsoft Corporation) MD5=7C0507D2391AF5933600CBCED799F277 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_b502eb9fc4c2a304\tcpip.sys
[2012.03.30 11:23:11 | 001,291,632 | ---- | M] (Microsoft Corporation) MD5=7FA2E0F8B072BD04B77B421480B6CC22 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_b52e5147c4a202d7\tcpip.sys
[2012.03.30 10:04:23 | 001,306,480 | ---- | M] (Microsoft Corporation) MD5=88FCDB9923EFECA207B3CEBD24407126 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_b583df0adde66104\tcpip.sys
[2012.08.22 18:16:54 | 001,292,144 | ---- | M] (Microsoft Corporation) MD5=A5EBB8F648000E88B7D9390B514976BF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_b514e56fc4b40532\tcpip.sys
[2013.11.26 20:07:52 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=CA59F7C570AF70BC174F477CFE2D9EE3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_b4fa2013c4c8ebf1\tcpip.sys
[2013.05.08 06:38:00 | 001,293,672 | ---- | M] (Microsoft Corporation) MD5=D32FDAC73FCD76B85389C39BC1087F2A -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_b508ef41c4bd3835\tcpip.sys
[2014.04.05 03:16:21 | 001,310,144 | ---- | M] (Microsoft Corporation) MD5=EA47AB18E289333AB94397D77CA6E3A1 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22648_none_b59293a4dddacc9b\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe

< MD5 for: WINLOGON.EXE >
[2014.07.16 03:56:14 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=4F37B93C14AEE313BEC52A23AFB15C2E -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_7224b2134c7555fa\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\erdnt\cache\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\System32\winlogon.exe
[2014.07.17 02:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_71a5e34e334f9d18\winlogon.exe
[2010.11.20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2014.03.04 10:17:02 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=998507B046BA314CE8245364C686FA67 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_71da23b23327143c\winlogon.exe
[2014.03.04 11:39:02 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=D53972F87D850CD2EB4B29B60CAFDD77 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_7255f1994c4f8119\winlogon.exe

< MD5 for: WS2_32.DLL >
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\erdnt\cache\ws2_32.dll
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\System32\ws2_32.dll
[2010.11.20 22:29:06 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[10 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[14 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2013.01.01 19:38:25 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Adobe
[2013.07.03 20:49:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\All Free iPad Video Converter
[2013.07.04 17:31:52 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Apple Computer
[2012.12.09 20:10:24 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\ArcSoft
[2014.10.30 00:59:46 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\AVAST Software
[2013.11.16 12:31:00 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bioshock2
[2014.05.23 11:41:43 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Bombermaaan
[2013.04.11 23:34:29 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer
[2012.11.22 23:00:06 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\BSplayer Pro
[2014.07.24 18:41:54 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\CAD-KAS
[2014.10.22 18:46:07 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Canon
[2013.02.14 22:19:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\COWON
[2012.11.22 16:24:11 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\CyberLink
[2014.10.05 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DAEMON Tools Lite
[2014.10.30 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Dropbox
[2014.10.30 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\DropboxMaster
[2014.07.24 20:42:32 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\everysale
[2014.06.30 15:06:36 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Garmin
[2013.10.09 20:08:02 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\GHISLER
[2012.11.21 20:16:47 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Identities
[2012.12.02 16:00:03 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\InstallShield
[2012.12.02 10:56:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Macromedia
[2011.04.12 02:46:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Media Center Programs
[2013.10.31 22:25:41 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Media Player Classic
[2013.11.17 20:14:10 | 000,000,000 | --SD | M] -- C:\Users\Beny\AppData\Roaming\Microsoft
[2014.03.11 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Mozilla
[2014.01.02 20:08:28 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\NVIDIA
[2012.11.21 20:21:56 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera
[2013.09.22 18:07:40 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Opera Software
[2014.07.29 21:08:13 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\PDF Architect 2
[2014.03.11 21:03:50 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Thunderbird
[2014.05.15 16:41:42 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Unity
[2014.10.31 20:05:33 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\uTorrent
[2012.11.27 22:20:30 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\WinRAR
[2013.11.20 18:14:19 | 000,000,000 | ---D | M] -- C:\Users\Beny\AppData\Roaming\Xfire

< %APPDATA%\*.exe /s >
[2009.08.11 21:21:26 | 000,087,552 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 21:21:30 | 000,090,112 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 14:52:04 | 000,697,690 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
[2012.10.11 09:01:20 | 001,175,371 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\FFDShow\unins000.exe
[2010.08.14 10:42:54 | 000,113,152 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 10:45:10 | 000,358,400 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 10:42:06 | 000,137,728 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 15:30:22 | 000,042,305 | ---- | M] () -- C:\Users\Beny\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
[2014.03.19 13:17:02 | 032,667,896 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2014.03.19 13:18:14 | 000,244,648 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2014.03.19 13:17:06 | 000,143,616 | ---- | M] (Dropbox, Inc.) -- C:\Users\Beny\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2014.10.30 00:30:12 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\uTorrent.exe
[2014.02.06 20:24:52 | 000,905,296 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.3.2_30488.exe
[2014.04.28 19:58:56 | 001,270,352 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_30888.exe
[2014.05.15 08:16:44 | 001,272,400 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_31139.exe
[2014.06.14 08:18:57 | 001,267,536 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.1_31395.exe
[2014.07.02 20:37:00 | 001,322,832 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_32126.exe
[2014.09.20 06:51:59 | 001,416,016 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34024.exe
[2014.10.08 08:21:55 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34309.exe
[2014.10.30 00:30:12 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Beny\AppData\Roaming\uTorrent\updates\3.4.2_34944.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >
[2014.10.31 20:07:58 | 000,070,384 | ---- | M] (AVAST Software) -- C:\Windows\system32\drivers\aswmonflt.sys
[2014.10.31 20:07:58 | 000,787,800 | ---- | M] (AVAST Software) -- C:\Windows\system32\drivers\aswsnx.sys

< %systemroot%\system32\*.* /3 >
[2014.10.31 15:58:00 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-14-57-51.039-AvastVBoxSVC.exe-4236.log
[2014.10.31 16:53:11 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-52-52.082-aswFe.exe-6068.log
[2014.10.31 16:54:33 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-54-14.066-aswFe.exe-1104.log
[2014.10.31 16:59:23 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-59-07.051-aswFe.exe-6032.log
[2014.10.31 17:00:05 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-15-59-49.010-aswFe.exe-3184.log
[2014.10.31 17:02:58 | 000,000,280 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-02-40.059-aswFe.exe-3908.log
[2014.10.31 17:15:16 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-15-14.098-AvastVBoxSVC.exe-2060.log
[2014.10.31 17:49:49 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-16-49-47.090-AvastVBoxSVC.exe-3260.log
[2014.10.31 20:08:21 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-19-08-21.016-AvastVBoxSVC.exe-1744.log
[2014.10.31 20:27:16 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-10-31-19-27-14.095-AvastVBoxSVC.exe-3160.log
[2014.11.02 16:54:33 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-11-02-15-54-24.037-AvastVBoxSVC.exe-3400.log
[2014.11.03 09:27:48 | 000,000,197 | ---- | M] () -- C:\Windows\system32\2014-11-03-08-27-44.038-AvastVBoxSVC.exe-3608.log
[2014.11.03 09:32:55 | 000,021,904 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.03 09:32:56 | 000,021,904 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.11.03 09:55:14 | 000,000,512 | ---- | M] () MD5=C6D65CF37E024B3ED21CF4BDC5F64DAF -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2013.09.29 21:22:42 | 000,003,072 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.cracked.com_0.localstorage
[2013.09.29 21:22:42 | 000,003,608 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.cracked.com_0.localstorage-journal
[2012.11.27 18:03:04 | 000,035,529 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Call.of.Duty.Modern.Warfare.3.for.PC.with.Crack.rar.torrent
[2012.12.03 19:58:24 | 000,012,448 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - BESTFull Version With Crack!!.torrent
[2012.12.03 19:39:45 | 000,001,215 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - čeština,crack ,keygen.torrent

< *keygen* /s >
[2012.12.03 19:39:45 | 000,001,215 | ---- | M] () -- \Users\Beny\AppData\Roaming\uTorrent\Swat 4 - čeština,crack ,keygen.torrent
[2009.08.13 18:11:02 | 000,088,399 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen.rar
[2009.03.18 19:27:22 | 000,095,232 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen\keygen.exe
[2006.03.21 10:44:16 | 000,050,586 | ---- | M] () -- \Users\Beny\Downloads\Adobe-Acrobat-6.0-CE-Professional\Adobe Acrobat 6.0 CE Professional\Adobe_Acrobat_v6.0_Keygen.zip
[2003.06.25 01:17:16 | 000,053,434 | ---- | M] () -- \Users\Beny\Downloads\Adobe-Acrobat-6.0-CE-Professional\Adobe Acrobat 6.0 CE Professional\Adobe_Acrobat_v6.0_Keygen\acrobat 6 keygen.exe

< *AntiWPA* /s >

< *loader* /s >
[2005.03.24 13:51:08 | 000,002,090 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge\Resources\en\_media\rssloader.swf
[2014.10.30 00:57:35 | 000,072,480 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
[2005.03.16 19:16:50 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2014.07.01 11:00:40 | 000,042,496 | ---- | M] () -- \Program Files\Garmin\Core Update Service\Garmin.Cartography.MyDownloader.Core.dll
[2001.10.15 13:51:40 | 000,003,065 | ---- | M] () -- \Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\uriloader.xpt
[2013.10.23 21:07:40 | 000,007,825 | ---- | M] () -- \Program Files\Hry\Steam\remoteui\static\libs\images\ajax-loader.gif
[2012.11.21 20:44:07 | 000,051,200 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Absolution\PhysXLoader.dll
[2013.01.27 12:06:24 | 000,333,840 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.WAV
[2013.01.27 12:06:24 | 000,005,952 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.WHD
[2013.01.27 12:06:24 | 000,351,949 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\hideout\Loader_Sequence.ZIP
[2013.01.27 12:06:39 | 000,313,360 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.WAV
[2013.01.27 12:06:24 | 000,005,392 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.WHD
[2013.01.27 12:06:33 | 000,570,691 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M00\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.WHD
[2013.01.27 12:06:50 | 000,711,223 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M01\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.WHD
[2013.01.27 12:08:07 | 000,634,201 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M02\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.WHD
[2013.01.27 12:08:36 | 000,707,294 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M03\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.WHD
[2013.01.27 12:07:30 | 000,531,761 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M04\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.WHD
[2013.01.27 12:08:15 | 000,591,946 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M05\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.WHD
[2013.01.27 12:10:24 | 000,617,459 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M06\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.WHD
[2013.01.27 12:08:13 | 000,440,664 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M08\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.WHD
[2013.01.27 12:08:54 | 000,550,700 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M09\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.WHD
[2013.01.27 12:10:46 | 000,650,200 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M10\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.WHD
[2013.01.27 12:10:53 | 000,596,635 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M11\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.WHD
[2013.01.27 12:10:57 | 000,668,734 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M12\Loader_Sequence.ZIP
[2013.01.27 12:06:28 | 000,320,528 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.WAV
[2013.01.27 12:06:28 | 000,005,616 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.WHD
[2013.01.27 12:09:28 | 000,632,940 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Blood Money\Scenes\M13\Loader_Sequence.ZIP
[2013.08.18 20:00:42 | 000,057,856 | ---- | M] () -- \Program Files\Hry\Steam\SteamApps\common\Hitman Sniper Challenge\PhysXLoader.dll
[2013.08.03 16:23:12 | 000,329,232 | ---- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\ubiorbitapi_r2_loader.dll
[2013.08.21 04:41:00 | 000,037,376 | R--- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\uplay_r1_loader.dll
[2012.11.01 09:32:14 | 000,057,224 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2012.09.04 23:34:12 | 000,083,848 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2008.02.25 07:05:22 | 000,856,064 | ---- | M] () -- \Program Files\Programy\The KMPlayer\ImLoader.dll
[2012.12.03 19:46:55 | 000,000,214 | ---- | M] () -- \Users\Beny\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fstep.yourfiledownloader.com%2Fstatic%2Fa%2Fimages%2Ffavicon.png
[2014.06.03 22:04:32 | 000,000,121 | ---- | M] () -- \Users\Beny\AppData\Roaming\Unity\WebPlayerPrefs\ultimate_2ddisassembly_2ecom\prefloader2_2eunity3d.upp
[2010.08.04 19:42:20 | 000,032,349 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.0.1-cs_CZ\wordpress\wp-includes\script-loader.php
[2010.08.04 19:42:22 | 000,001,893 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.0.1-cs_CZ\wordpress\wp-includes\template-loader.php
[2014.05.01 03:27:16 | 000,047,934 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\script-loader.php
[2013.10.30 13:39:10 | 000,002,747 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\template-loader.php
[2014.02.13 07:03:14 | 000,003,878 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\images\uploader-icons-2x.png
[2014.02.13 07:03:14 | 000,001,556 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\images\uploader-icons.png
[2013.11.15 03:31:10 | 000,004,281 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\customize-loader.js
[2013.11.13 20:45:12 | 000,002,539 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\customize-loader.min.js
[2013.12.28 22:53:16 | 000,002,608 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\tinymce\skins\lightgray\img\loader.gif
[2013.08.02 02:48:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.07.14 05:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2014.10.15 08:38:46 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60.manifest
[2014.10.15 08:38:46 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60_winload.exe.mui_3bc5b827
[2014.10.15 08:38:46 | 000,030,272 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60_winresume.exe.mui_ff8b5358
[2014.10.15 08:38:53 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a.manifest
[2014.10.15 08:38:53 | 000,521,384 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a_winload.exe_75835076
[2014.10.15 08:38:54 | 000,455,752 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a_winresume.exe_85cd1215
[2009.07.14 03:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 03:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2011.04.12 02:36:26 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2014.07.08 22:41:55 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18526_cs-cz_3540f2755b51fb60.manifest
[2014.07.08 22:42:00 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22736_cs-cz_35bfc13a7477b442.manifest
[2010.11.20 22:23:54 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2014.08.19 04:02:10 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18574_none_5ced2dcdcb19ba9a.manifest
[2014.08.19 04:09:35 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22780_none_5d67fb6ae4430e20.manifest
[2009.07.14 02:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 17:40:37 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 02:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 17:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 05:43:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22209_none_0d52a9aaf32333d8\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.02 06:53:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22411_none_0d3fdb3af3327f5f\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.03.04 11:35:49 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22616_none_0d44e078f32df860\api-ms-win-core-libraryloader-l1-1-0.dll
[2014.04.12 03:03:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22653_none_0d169feaf3511c1f\api-ms-win-core-libraryloader-l1-1-0.dll

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >

< *activator* /s >

< *serial* /s >
[2013.08.03 16:22:08 | 000,120,336 | ---- | M] () -- \Program Files\Hry\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Launcher_SharePoint.XmlSerializers.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2013.06.09 20:10:31 | 000,000,581 | ---- | M] () -- \Users\Beny\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fwww.serialzone.cz%2Ffavicon.png
[3 \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp files -> \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp -> ]
[2014.07.18 08:37:16 | 000,005,120 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.serialzone.cz_0.localstorage
[2014.07.18 08:37:16 | 000,003,608 | ---- | M] () -- \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.serialzone.cz_0.localstorage-journal
[2005.12.06 21:02:38 | 000,794,268 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\Serials.exe
[2011.01.20 22:09:38 | 000,000,783 | ---- | M] () -- \Users\Beny\Downloads\wordpress-3.9.1\wordpress\wp-includes\js\jquery\jquery.serialize-object.js
[2013.07.08 13:43:48 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.10.15 12:16:41 | 000,310,784 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\91eb4f41130c65ef17f0fee1d3ab48fb\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.15 19:09:09 | 002,347,008 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\b1e0939384cc320d6ac7b8921ccc2877\System.Runtime.Serialization.ni.dll
[2014.10.15 09:14:56 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8c4fe3e44341707d99100b07b6a259ef\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.09.11 23:24:01 | 002,656,768 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\974ec1c5604d87c64b2368c1a2074296\System.Runtime.Serialization.ni.dll
[2014.09.13 15:29:32 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a366e9e1ffc94991f5a6dc706abd9d59\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.10.15 09:14:50 | 002,656,768 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\c9614599d9cc883cb6d8682a901c6a01\System.Runtime.Serialization.ni.dll
[2014.09.13 15:32:23 | 000,009,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\1fcf609cac2b1ce3b6efaf0c822cee24\System.Xml.Serialization.ni.dll
[2010.03.18 12:16:28 | 001,026,936 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\5C1093C35543A0E32A41B090A305076A\4.0.30319\System.Runtime.Serialization.dll.x86
[2013.08.30 20:31:15 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.10.15 08:56:14 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.30 20:31:15 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2014.10.15 08:56:12 | 001,038,016 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.10.15 08:56:18 | 000,012,080 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.07.10 23:24:11 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.03 06:17:44 | 001,038,016 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 12:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2012.01.21 16:40:04 | 000,012,080 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2010.06.15 01:33:16 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.06.15 01:33:16 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2011.04.12 02:36:50 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\drivers\serial.sys
[2011.04.12 02:36:55 | 000,009,728 | ---- | M] () -- \Windows\System32\drivers\cs-CZ\serial.sys.mui
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\mdmmotsm.inf_x86_neutral_c1415d9789c54b89\smserial.sys
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_x86_neutral_63e72c669d043f14\grserial.sys
[2009.07.14 03:18:03 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 03:18:03 | 000,015,952 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486_kdcom.dll_db5e7744
[2011.04.12 02:37:09 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed_serialui.dll.mui_7d29d2a3
[2009.07.14 03:18:51 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a_serialui.dll_bea29328
[2010.11.20 22:24:56 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c.manifest
[2012.10.05 18:15:39 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285.manifest
[2014.07.02 06:57:49 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29.manifest
[2014.07.14 03:04:09 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf.manifest
[2012.10.05 18:17:50 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d.manifest
[2014.07.02 07:07:46 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7.manifest
[2014.07.14 03:04:27 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e.manifest
[2011.04.12 02:36:33 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0.manifest
[2012.10.05 20:04:43 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f.manifest
[2014.07.02 07:50:42 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43.manifest
[2014.07.14 04:14:58 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9.manifest
[2012.10.05 20:02:24 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797.manifest
[2014.07.02 21:15:55 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1.manifest
[2014.07.14 04:04:07 | 000,001,626 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48.manifest
[2010.11.20 22:24:56 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f.manifest
[2012.10.05 18:15:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8.manifest
[2014.07.02 07:00:03 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c.manifest
[2014.07.14 03:06:40 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12.manifest
[2012.10.05 18:17:15 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0.manifest
[2014.07.02 07:10:04 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a.manifest
[2014.07.14 03:06:53 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061.manifest
[2009.07.14 02:49:26 | 000,002,762 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_118be3420dfe8486.manifest
[2009.07.14 02:45:27 | 000,000,866 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.1.7600.16385_none_2c93290b67c98d09.manifest
[2010.11.20 22:24:56 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1.manifest
[2012.10.05 18:19:53 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa.manifest
[2014.07.02 06:58:58 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e.manifest
[2014.07.14 03:05:25 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754.manifest
[2012.10.05 18:22:10 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2.manifest
[2014.07.02 07:08:55 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c.manifest
[2014.07.14 03:05:41 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3.manifest
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_1c9a3ec1e01c684b\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 00:43:20 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.18523_none_1c70653de072abde\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.24 00:43:36 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7601.22733_none_05a3bea3fa19258c\System.Runtime.Serialization.Formatters.Soap.dll
[2011.04.12 02:36:53 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7600.16385_cs-cz_d5c3552dd9b47144\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.07.08 13:43:48 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.1.7601.18523_cs-cz_d5997ba9da0ab4d7\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c\System.Runtime.Serialization.dll
[2012.10.05 11:53:24 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17966_none_a683f56a74d63285\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18523_none_a6803b1074d97c29\System.Runtime.Serialization.dll
[2014.07.10 23:24:11 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.18532_none_a681522274d87bdf\System.Runtime.Serialization.dll
[2012.10.05 11:56:07 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22126_none_8fb250ac8e81277d\System.Runtime.Serialization.dll
[2014.03.17 15:38:28 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22733_none_8fb394768e7ff5d7\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.22743_none_8fb494c08e7f0f2e\System.Runtime.Serialization.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_cs-cz_34555b4d83cf58b0\System.RunTime.Serialization.Resources.dll
[2010.11.13 02:55:26 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.17966_cs-cz_342f3c238422529f\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18523_cs-cz_342b81c984259c43\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.18532_cs-cz_342c98db84249bf9\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22126_cs-cz_1d5d97659dcd4797\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22733_cs-cz_1d5edb2f9dcc15f1\System.RunTime.Serialization.Resources.dll
[2010.11.13 03:37:50 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7601.22743_cs-cz_1d5fdb799dcb2f48\System.RunTime.Serialization.Resources.dll
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f\System.Runtime.Serialization.dll
[2012.10.05 11:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17966_none_d6c72b049c7d33b8\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18523_none_d6c370aa9c807d5c\System.Runtime.Serialization.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.18532_none_d6c487bc9c7f7d12\System.Runtime.Serialization.dll
[2012.10.05 11:56:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22126_none_bff58646b62828b0\System.Runtime.Serialization.dll
[2014.03.17 15:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22733_none_bff6ca10b626f70a\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.22743_none_bff7ca5ab6261061\System.Runtime.Serialization.dll
[2009.07.13 23:13:45 | 001,068,032 | ---- | M] () -- \Windows\winsxs\x86_mdmmotsm.inf_31bf3856ad364e35_6.1.7600.16385_none_7a97936f8a972896\smserial.sys
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_c233d4df09982c29\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_c227ede109a14864\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:49 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.1.7601.22731_cs-cz_c2a4bc1222c8ce98\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011.04.12 02:36:50 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_4e4137b544fe59ed\serialui.dll.mui
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a\serialui.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.17514_cs-cz_5f7b7c7cb0c0f266\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.18523_cs-cz_5f6f957eb0ca0ea1\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.1.7601.22733_cs-cz_5fee6443c9efc783\System.RunTime.Serialization.Resources.dll
[2011.04.12 02:36:55 | 000,009,728 | ---- | M] () -- \Windows\winsxs\x86_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_c48c78a9ad8ff996\serial.sys.mui
[2009.07.14 00:45:33 | 000,083,456 | ---- | M] () -- \Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\serial.sys
[2009.07.13 23:09:18 | 000,031,232 | ---- | M] () -- \Windows\winsxs\x86_smartcrd.inf_31bf3856ad364e35_6.1.7600.16385_none_7280378295916274\grserial.sys
[2010.11.20 22:29:48 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1\System.Runtime.Serialization.dll
[2012.10.05 11:53:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17966_none_dba1d6d1dd53cdfa\System.Runtime.Serialization.dll
[2014.03.09 22:47:42 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18523_none_db9e1c77dd57179e\System.Runtime.Serialization.dll
[2014.07.10 23:24:10 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.18532_none_db9f3389dd561754\System.Runtime.Serialization.dll
[2012.10.05 11:56:05 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22126_none_c4d03213f6fec2f2\System.Runtime.Serialization.dll
[2014.03.17 15:38:27 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22733_none_c4d175ddf6fd914c\System.Runtime.Serialization.dll
[2014.07.08 00:27:52 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.22743_none_c4d27627f6fcaaa3\System.Runtime.Serialization.dll

< *w7lxe* /s >

< End of report >

Kanarek
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 23 črc 2009 18:14

Re: Opakující se zobrazování ruských stránek

#29 Příspěvek od Kanarek »

Druhý:

OTL Extras logfile created on: 3.11.2014 9:52:00 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Beny\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 0,63 Gb Available Physical Memory | 31,65% Memory free
4,00 Gb Paging File | 1,94 Gb Available in Paging File | 48,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298,08 Gb Total Space | 81,51 Gb Free Space | 27,34% Space Free | Partition Type: NTFS
Drive D: | 5,60 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 931,48 Gb Total Space | 623,08 Gb Free Space | 66,89% Space Free | Partition Type: NTFS

Computer Name: BENY-PC | User Name: Beny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software)

[HKEY_USERS\S-1-5-21-1424593332-1298421875-114481279-1000\SOFTWARE\Classes\<extension>]
.html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
https [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EA2BE7A-4E77-41E7-A26E-ECB8378D78FC}" = lport=138 | protocol=17 | dir=in | app=system |
"{12AC5E45-7B51-47AC-9BAA-2443363D0103}" = lport=445 | protocol=6 | dir=in | app=system |
"{1857FEE8-1F3C-4DEC-B18E-04D94AB78CC9}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C6FD2EB-8F74-4FB8-9DFE-72E2BC23CCC8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{239A6A85-781C-4844-9653-DAE7C427D97A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{540CFBD1-C922-42CD-8F18-688100185C85}" = lport=137 | protocol=17 | dir=in | app=system |
"{6497BDD2-92EF-4265-AFFD-9FF0E827B2BD}" = rport=139 | protocol=6 | dir=out | app=system |
"{649DD172-A7D5-4B3D-85C3-9F1BFF97B087}" = rport=138 | protocol=17 | dir=out | app=system |
"{6726D2AF-829B-4C26-870F-896CE801ACA4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{719A310C-5592-43D5-8F62-6487094C3927}" = lport=2869 | protocol=6 | dir=in | app=system |
"{838D760A-7569-4161-AEF5-FA157E8EF3EE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{95DF8A8A-27E5-4098-99D3-C00A2D9750DD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9DD62DF1-883E-4219-A4E8-55DA3263489A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9EC7599D-A7C0-4355-AC45-6D5DFC0A0BF7}" = rport=137 | protocol=17 | dir=out | app=system |
"{A2DF774D-CF88-46DB-A33F-EC0F32464CDA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A3EA8636-85D4-495D-A1C9-DB17C4EBD4FA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AD128692-CBFE-4D83-8E3D-1F4400281C0C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{C1E6AAE5-B80C-46D6-A146-48782E36EBA2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C2622BBC-7414-4549-B1AC-5C3DDEDA5CEB}" = lport=139 | protocol=6 | dir=in | app=system |
"{CEE979D7-2A25-42B6-A8B8-0EF84E6BB760}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\google\chrome\application\chrome.exe |
"{D28CF11F-C529-4729-8BB2-678BC3FC163C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC1AB7D7-8045-4BCA-9119-912DFD8A3B5A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E1390FBB-0698-421D-AE1F-0886E868D3D7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E8FF30FF-7E95-47FD-AC21-FC2BAC85BB05}" = rport=10243 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00DE97AA-690D-40FF-B200-9247F4F9FDFA}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman absolution\hma.exe |
"{028C5A81-FE30-4CB3-92C0-601810C0089D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{030BBC1C-64DD-4CB7-950F-3F538E8278F7}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman 2 silent assassin\hitman2.exe |
"{033C5F44-E1C9-4FA6-8F27-4FA40FEE09A3}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman sniper challenge\hmsc.exe |
"{05E75501-D8C6-40B5-A5E3-804E19E2AAB5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{077B2A98-F35A-4CC1-8122-CC900B2237AA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0AA940AE-E05B-494B-88A1-D3C6FF76D15E}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman codename 47\hitman.exe |
"{176EB1BB-BCB0-4747-82A4-7BD8274EBFFD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{180E5ADA-5696-4810-8DCB-5D9CD53D8C32}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{1D9608DF-6E25-4E0B-A188-242F33FDA1CE}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman codename 47\setup.exe |
"{1F51B968-2D15-4093-8C95-A362296C9D7D}" = protocol=17 | dir=in | app=c:\users\beny\appdata\roaming\dropbox\bin\dropbox.exe |
"{21C56B2D-0BB3-47B8-AC29-1FFFFA63B8F1}" = protocol=17 | dir=in | app=c:\users\beny\appdata\roaming\utorrent\utorrent.exe |
"{262464CD-5B5D-4C33-B626-6F541E8866F6}" = protocol=6 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\blacklist_launcher.exe |
"{26A64091-C27A-4E5A-8938-825674B7C4A7}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman codename 47\setup.exe |
"{373F9DB9-2611-4157-997E-43E674098181}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steam.exe |
"{37F93633-2409-42BE-AE50-3BD506D62439}" = protocol=6 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe |
"{386C5AC1-D603-4979-9D9E-AAAC59D8AF78}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3C9FAFED-EA9E-4C08-B6E0-C41B5A9F8269}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{44A2BF25-56AB-433E-9FD6-DB48CD19122F}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steam.exe |
"{4647EF35-FE47-4F19-A01A-FDB80DE4F90D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{46AF5918-D704-4212-B063-FDF066B1894F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4A79C821-9479-4A24-904E-9E05A6C310BE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{504A0D39-19D9-478A-A26F-26F898F1BB79}" = protocol=6 | dir=in | app=c:\program files\hry\vugames\swat 4\contentexpansion\system\swat4xdedicatedserver.exe |
"{5DE70A37-6AD9-478D-A81A-B2162A20E722}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5FB22BAA-F601-47CF-A509-417797C26AC2}" = protocol=17 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe |
"{5FC0E476-3DC2-40D9-AB30-DCF88E476A83}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{654669C5-4716-4512-9C68-E308F2739B8C}" = protocol=17 | dir=in | app=c:\program files\hry\vugames\swat 4\contentexpansion\system\swat4xdedicatedserver.exe |
"{6560670B-0AD8-4033-A12A-F1C22BAD85D3}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman 2 silent assassin\config.exe |
"{7724BF3E-E536-430D-A56E-5CCB01025F2A}" = dir=in | app=c:\program files\programy\cyberlink\powerdvd\powerdvd.exe |
"{783D6FEB-A179-403B-9BC6-8F9AAB3D8BF6}" = protocol=6 | dir=out | app=system |
"{7C8F89FA-CBDF-4EEA-9761-DE20FDDC8E0A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7FD4F0BF-0797-49A0-80E0-CE2A7F2B99FF}" = protocol=6 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe |
"{801BA29B-D1E2-4FA2-AEA3-EE46A7B7CADC}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman blood money\configure.exe |
"{818D658F-8B1D-41D2-8326-93B62E1A2824}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman 2 silent assassin\hitman2.exe |
"{88CC14D1-977B-45C4-B8C2-C5B5312CBC87}" = protocol=17 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\gu.exe |
"{8D0566D8-40FD-4823-B58D-A0D4EE3E2A62}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman absolution\hma.exe |
"{8EFE0F14-CBE9-4CF1-A227-C9987ADCB468}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{9119C5D3-A9D3-46B3-90D2-4042FF652F6C}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman blood money\hitmanbloodmoney.exe |
"{954D8F05-D43E-4E9B-B938-5CF341D53AD2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{96BD59D1-8E19-4A03-8A48-5B9890311DA0}" = protocol=6 | dir=in | app=c:\program files\hry\steam\bin\steamwebhelper.exe |
"{96C61AA9-C66F-4AB4-AB98-017F0DF0047C}" = protocol=17 | dir=in | app=c:\program files\hry\vugames\swat 4\contentexpansion\system\swat4x.exe |
"{9B4B5A13-230D-4CC4-99D6-A2234109A09B}" = protocol=17 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_game.exe |
"{9F481ED0-2416-490E-8928-15FD92FBEEB4}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman 2 silent assassin\config.exe |
"{9FC0C94C-56C8-426B-BBA6-ADACCCFB9F74}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{B310D767-43E2-4775-A4BA-BA703A2EAA21}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steam.exe |
"{C6D6D3B0-F9EB-4773-8B21-889E3ED85FF2}" = protocol=6 | dir=in | app=c:\users\beny\appdata\roaming\utorrent\utorrent.exe |
"{C9020320-F589-4825-98CD-3D086F91CCC7}" = protocol=6 | dir=in | app=c:\users\beny\appdata\roaming\utorrent\utorrent.exe |
"{CF65BE37-DFAA-43F1-B5FF-5B4463066439}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D0D0EFD5-FCFB-44E1-B26D-583D8ED00BC5}" = protocol=58 | dir=in | app=system |
"{D41E93DC-9B28-4553-9B22-AE73648968CA}" = protocol=17 | dir=in | app=c:\program files\hry\steam\bin\steamwebhelper.exe |
"{D677A2D4-2260-4CD0-A01D-342831367512}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D730D135-E57D-4FF0-A532-00FD9261D859}" = protocol=6 | dir=in | app=c:\program files\hry\vugames\swat 4\contentexpansion\system\swat4x.exe |
"{D7A18D80-027F-4AD5-8E12-FCF4DF8C2480}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman blood money\hitmanbloodmoney.exe |
"{DC62591E-9978-41AF-AEBA-7F6C002A9591}" = protocol=6 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\src\system\gu.exe |
"{DEE43937-6A88-434D-9C61-D4C6C8390472}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman codename 47\hitman.exe |
"{E5CF482D-E66B-4EDB-8FEC-941EFAD5B937}" = protocol=17 | dir=in | app=c:\program files\hry\ubisoft\tom clancy's splinter cell® blacklist™\blacklist_launcher.exe |
"{E75148E8-8E64-483B-9A91-6F025A9BED9E}" = protocol=6 | dir=in | app=c:\users\beny\appdata\roaming\dropbox\bin\dropbox.exe |
"{EBFE360F-9D05-46D2-9783-3A829633AEB3}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman blood money\configure.exe |
"{F78C7B45-778E-4E4C-9B98-66DD72B47605}" = protocol=6 | dir=in | app=c:\program files\hry\steam\steamapps\common\hitman sniper challenge\hmsc.exe |
"{F7A29E46-B551-4511-B472-748A958FB80E}" = protocol=17 | dir=in | app=c:\program files\hry\steam\steam.exe |
"{FE2D9B24-A08A-452A-863C-38BD84486838}" = protocol=17 | dir=in | app=c:\users\beny\appdata\roaming\utorrent\utorrent.exe |
"TCP Query User{5A019AFD-9B9D-4EC7-80A7-D6825AFA6598}C:\program files\xfire2\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire2\xfire.exe |
"TCP Query User{79C64A1C-A3BA-4AB8-B6C8-53A063E662B7}C:\program files\hry\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\hry\xfire\xfire.exe |
"TCP Query User{BB3BE7ED-BDD9-4746-B82E-AEA04E34FB34}C:\totalcmd\totalcmd.exe" = protocol=6 | dir=in | app=c:\totalcmd\totalcmd.exe |
"UDP Query User{2F445193-4B2B-4AD1-A969-2C926A2E3622}C:\totalcmd\totalcmd.exe" = protocol=17 | dir=in | app=c:\totalcmd\totalcmd.exe |
"UDP Query User{6F7059B7-E8BD-4846-AE21-E7339055E84F}C:\program files\hry\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\hry\xfire\xfire.exe |
"UDP Query User{6FDE87E1-8C12-4FC6-B4C1-03A04CABCE86}C:\program files\xfire2\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire2\xfire.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1B54E2F7-0396-478A-8868-267922A98854}" = Garmin Express Tray
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{3713C93E-16C1-4311-81BC-337E9E7C9D76}_is1" = Gothic II
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1" = Xfire 2.0
"{647BB978-2876-487B-9B0E-FDB73F0EA4A2}" = Garmin Communicator Plugin
"{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}" = Microsoft Games for Windows Marketplace
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{90280405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional s aplikací FrontPage
"{97E12F84-C033-4DA2-97D2-F540C3E292EA}" = Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A6356F2F-D3E1-4D83-9AA2-72871DD0C298}" = Tom Clancy's Splinter Cell® Blacklist™
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA2A50EB-24BA-49C4-ACAA-73BFF91F9D7E}" = Elevated Installer
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.09) - Czech
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BF133B81-EEE5-4751-8F64-9BC8E42708A7}" = Garmin Express
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{D3B98B1B-A286-49A0-A1D9-E4D3B93E6670}" = ANT Drivers Installer x86
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio Basic VX
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5
"{E83CD823-C522-4B71-B10A-E1088B3BD261}" = STK03N
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Avast" = Avast Free Antivirus
"BSPlayerf" = BS.Player FREE
"CCleaner" = CCleaner
"DAEMON Tools Lite" = DAEMON Tools Lite
"F9D2A789F9CFF8CEC36B544F53877C80F1F73C46" = Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)
"Fallout New Vegas_is1" = Fallout New Vegas 1.4
"Google Chrome" = Google Chrome
"InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4
"InstallShield_{97E12F84-C033-4DA2-97D2-F540C3E292EA}" = SWAT 4 - The Stetchkov Syndicate
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 9.5.5
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Opera 25.0.1614.68" = Opera Stable 25.0.1614.68
"Steam App 203140" = Hitman: Absolution
"Steam App 205930" = Hitman: Sniper Challenge
"Steam App 6850" = Hitman 2: Silent Assassin
"Steam App 6860" = Hitman: Blood Money
"Steam App 6900" = Hitman: Codename 47
"SWAT3 Elite Edition" = SWAT3 Elite Edition
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"Uplay" = Uplay
"VobSub" = VobSub v2.23 (Remove Only)
"WinRAR archiver" = WinRAR 4.11 (32-bit)
"Xfire" = Xfire
"XfireCodec" = Xfire Codec (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1424593332-1298421875-114481279-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 31.10.2014 12:15:02 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

Error - 31.10.2014 12:47:39 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

Error - 31.10.2014 15:06:17 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

Error - 31.10.2014 15:25:11 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

Error - 2.11.2014 11:54:20 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

Error - 2.11.2014 12:32:01 | Computer Name = Beny-PC | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\totalcmd\TCUNIN64.EXE se nezdařilo.
Závislé
sestavení Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 2.11.2014 14:56:17 | Computer Name = Beny-PC | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\totalcmd\TCUNIN64.EXE se nezdařilo.
Závislé
sestavení Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 3.11.2014 4:25:38 | Computer Name = Beny-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2.11.2014 11:54:09 | Computer Name = Beny-PC | Source = Server | ID = 2505
Description = Server nemohl vytvořit vazbu na přenos \Device\NetBT_Tcpip_{93301838-8932-4374-9AAB-D39B51219DFD},
protože jiný počítač v síti má stejný název. Server nelze spustit.

Error - 2.11.2014 11:54:09 | Computer Name = Beny-PC | Source = NetBT | ID = 4321
Description = Název BENY-PC :20 nelze zaregistrovat v rozhraní s IP adresou
80.243.104.124. Počítač s IP adresou 80.243.104.90 nepovolil získání názvu tímto
počítačem.

Error - 2.11.2014 11:56:20 | Computer Name = Beny-PC | Source = Service Control Manager | ID = 7038
Description = Služba nvUpdatusService se nemohla přihlásit jako .\UpdatusUser s
aktuálně konfigurovaným heslem z důvodu následující chyby: %%1330 Chcete-li zajistit
správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management
Console (MMC).

Error - 2.11.2014 11:56:20 | Computer Name = Beny-PC | Source = Service Control Manager | ID = 7000
Description = Služba NVIDIA Update Service Daemon neuspěla při spuštění v důsledku
následující chyby: %%1069

Error - 2.11.2014 12:32:46 | Computer Name = Beny-PC | Source = Microsoft-Windows-HAL | ID = 12
Description = Firmware platformy při předchozím přechodu systémového napájení poškodil
paměť. Zkontrolujte dostupnost aktualizovaného firmwaru pro váš systém.

Error - 2.11.2014 12:40:29 | Computer Name = Beny-PC | Source = Server | ID = 2505
Description = Server nemohl vytvořit vazbu na přenos \Device\NetBT_Tcpip_{93301838-8932-4374-9AAB-D39B51219DFD},
protože jiný počítač v síti má stejný název. Server nelze spustit.

Error - 2.11.2014 12:40:29 | Computer Name = Beny-PC | Source = NetBT | ID = 4321
Description = Název BENY-PC :20 nelze zaregistrovat v rozhraní s IP adresou
80.243.104.124. Počítač s IP adresou 80.243.104.90 nepovolil získání názvu tímto
počítačem.

Error - 2.11.2014 12:41:02 | Computer Name = Beny-PC | Source = DCOM | ID = 10010
Description =

Error - 3.11.2014 4:27:43 | Computer Name = Beny-PC | Source = Service Control Manager | ID = 7038
Description = Služba nvUpdatusService se nemohla přihlásit jako .\UpdatusUser s
aktuálně konfigurovaným heslem z důvodu následující chyby: %%1330 Chcete-li zajistit
správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management
Console (MMC).

Error - 3.11.2014 4:27:43 | Computer Name = Beny-PC | Source = Service Control Manager | ID = 7000
Description = Služba NVIDIA Update Service Daemon neuspěla při spuštění v důsledku
následující chyby: %%1069


< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Opakující se zobrazování ruských stránek

#30 Příspěvek od Márty84 »

:arrow: Napiste mi velikost adresare plochy (C:\Users\Beny\Desktop)




:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]
[CreateRestorePoint]

:services
AdobeARMservice
gupdate
gupdatem

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\zoek-delete.exe
C:\zoek_backup

:otl
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1424593332-1298421875-114481279-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[14 C:\Users\Beny\Desktop\*.tmp files -> C:\Users\Beny\Desktop\*.tmp -> ]
[10 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[14 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[2009.08.13 18:11:02 | 000,088,399 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen.rar
[2009.03.18 19:27:22 | 000,095,232 | ---- | M] () -- \Users\Beny\Desktop\Veřejné složky\Jára\ZoneAlarm Pro 8.0.400.020\keygen\keygen.exe
[3 \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp files -> \Users\Beny\AppData\Roaming\Opera Software\Opera Stable\*.tmp -> ]

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Beny^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno