Re: Kontrola RSIT
Napsal: 25 črc 2015 09:06
========== Custom Scans ==========
< >
[2013.08.22 16:45:54 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
< >
< MD5 for: AGP440.SYS >
[2014.04.14 11:34:07 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\drivers\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2014.09.16 01:14:16 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys
< MD5 for: ATAPI.SYS >
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\drivers\atapi.sys
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2014.04.14 11:36:50 | 000,028,249 | ---- | M] () MD5=0CBDE27FB26761852F7B22AFB8C51ACB -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_d2b24d5495b82963\autochk.exe
[2014.02.22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014.02.22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014.02.22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\WINDOWS\SysNative\autochk.exe
[2014.02.22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2014.04.23 15:25:32 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe
< MD5 for: CDROM.SYS >
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\drivers\cdrom.sys
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_42e9c29f0affc440\cdrom.sys
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_5067bbed77be70be\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2015.03.09 16:44:30 | 000,018,016 | ---- | M] () MD5=14E1348B6D5DD39C23C2F8FE569B52E0 -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.16384_none_66bdf96f6ec6545d\cryptsvc.dll
[2014.10.29 03:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\WINDOWS\SysNative\cryptsvc.dll
[2014.10.29 03:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.17415_none_670a944b6e8cc0e5\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2011.05.10 17:28:52 | 000,006,952 | ---- | M] () MD5=B5DE6298D2295BA453677B21D24F1F12 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
< MD5 for: EXPLORER.EXE >
[2015.03.17 18:53:54 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2014.09.16 03:31:54 | 000,270,774 | ---- | M] () MD5=2195687491E604BA42961470EDA7660E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_42acff334d876b54\explorer.exe
[2014.09.16 04:02:20 | 000,220,250 | ---- | M] () MD5=286928E00AD34E9F88EB5BFA52660A70 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_4d01a98581e82d4f\explorer.exe
[2014.04.23 15:15:06 | 000,015,546 | ---- | M] () MD5=347EFF7EC89C3EB4F72F2408E1C4E16D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2015.03.09 16:50:17 | 000,395,976 | ---- | M] () MD5=45DD8FAA7B53ABD29BCB9BACABFFC818 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2014.04.23 15:15:03 | 000,238,918 | ---- | M] () MD5=5177BB4FECDDB9CDBCF10EF65916968D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2015.03.20 09:03:43 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2014.09.16 03:31:16 | 000,271,249 | ---- | M] () MD5=667BC926C7CB889BF276A5FEA316CAEE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2014.04.14 11:41:50 | 000,169,957 | ---- | M] () MD5=6D919C26DCB567396CD2E119B8E4310E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2015.01.28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015.01.28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2015.03.09 17:25:07 | 000,338,811 | ---- | M] () MD5=9E110FC1BA4AB7CB5F2F9D27DB534223 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe
[2015.01.28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015.01.28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe
[2014.09.16 04:02:16 | 000,208,662 | ---- | M] () MD5=C131BC6F12417306A9C8469CA49110B1 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2014.04.14 11:41:47 | 000,283,735 | ---- | M] () MD5=FA98C5D746E7C9E0912E88AC44FF9926 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe
< MD5 for: HAL.DLL >
[2014.06.02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\WINDOWS\SysNative\hal.dll
[2014.06.02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17196_none_9bde68c32da7abbb\hal.dll
[2014.09.04 19:26:03 | 000,024,467 | ---- | M] () MD5=2635F50EAF3E1B4A8D32B21E1203E130 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17031_none_9c1a44f32d7b883b\hal.dll
[2014.03.16 23:49:32 | 000,014,096 | ---- | M] () MD5=64D2873F32BB723BFFF3F8895032AA35 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16408_none_9c41d51d2d5cc0c4\hal.dll
[2014.04.14 11:42:32 | 000,066,843 | ---- | M] () MD5=D714202F057A317C8E31776EBEA0AEA2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16500_none_9c39d4b32d63f333\hal.dll
< MD5 for: IASTORV.SYS >
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\drivers\iaStorV.sys
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2014.04.14 11:34:08 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\drivers\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\isapnp.sys
[2014.09.16 01:14:20 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\isapnp.sys
< MD5 for: LSASS.EXE >
[2014.10.29 05:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\WINDOWS\SysNative\lsass.exe
[2014.10.29 05:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.17415_none_2e769c84660bda1b\lsass.exe
[2015.03.09 16:54:33 | 000,008,089 | ---- | M] () MD5=3FFB8CD649DEDA6497FD97550BE82357 -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.16408_none_2e8484166600f08e\lsass.exe
< MD5 for: NDIS.SYS >
[2014.02.16 17:43:00 | 000,046,734 | ---- | M] () MD5=68A9BA38BB275850F91165D1C1FCA8DA -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16408_none_4a6e60adfbbe952c\ndis.sys
[2015.02.05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\WINDOWS\SysNative\drivers\ndis.sys
[2015.02.05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17673_none_4a1d9ccbfbfbedff\ndis.sys
[2014.04.14 11:49:30 | 000,140,607 | ---- | M] () MD5=7B886741BDAE33AC4F116DF991D1E3CB -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16475_none_4a1fb05bfbfa0cbe\ndis.sys
[2015.03.20 09:00:18 | 000,080,695 | ---- | M] () MD5=9C48968B0344AD63559D0D080DA66103 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys
[2015.03.09 17:01:42 | 000,162,319 | ---- | M] () MD5=A627B5D38300791075615FF3C8BB3991 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys
[2014.09.16 03:48:45 | 000,025,682 | ---- | M] () MD5=D2D6A481A75207BF24E9D48C61B7F012 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys
< MD5 for: NETLOGON.DLL >
[2014.10.29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\WINDOWS\SysNative\netlogon.dll
[2014.10.29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2014.04.23 15:21:32 | 000,058,552 | ---- | M] () MD5=35048C9600694C3BF01D644D1AAE62BE -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2015.03.09 17:07:58 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015.03.09 17:30:34 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014.10.29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014.10.29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll
[2014.04.14 11:53:00 | 000,108,975 | ---- | M] () MD5=D817ED82C2A0E1CED9B396826F52F7CB -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll
< MD5 for: NVRAID.SYS >
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\drivers\nvraid.sys
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvraid.sys
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\drivers\nvstor.sys
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys
< MD5 for: SCECLI.DLL >
[2015.03.09 17:30:22 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015.03.09 17:07:31 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014.10.29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\WINDOWS\SysNative\scecli.dll
[2014.10.29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014.10.29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014.10.29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll
< MD5 for: SMSS.EXE >
[2014.04.14 11:54:29 | 000,019,120 | ---- | M] () MD5=5FBA1F5F9AA1E09595F015118AE83A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.16384_none_6f1f364dbcc273d3\smss.exe
[2014.02.22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\WINDOWS\SysNative\smss.exe
[2014.02.22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.17031_none_6f522891bc9cbe45\smss.exe
< MD5 for: SVCHOST.EXE >
[2015.03.09 17:52:42 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2015.03.09 17:08:11 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014.10.29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014.10.29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014.10.29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\WINDOWS\SysNative\svchost.exe
[2014.10.29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe
< MD5 for: TCPIP.SYS >
[2014.02.16 19:42:18 | 000,210,441 | ---- | M] () MD5=01941724D120729E2B680B22F05D4123 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16423_none_a41c53813a2d8394\tcpip.sys
[2014.03.16 23:53:58 | 000,271,861 | ---- | M] () MD5=2102610D6FD1D928A3D7155077A78B82 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16456_none_a3fee49b3a43236c\tcpip.sys
[2014.04.14 11:56:13 | 000,481,295 | ---- | M] () MD5=2F83A7537A9B8CF98E6B4710A3E3D381 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16521_none_a41a54d33a2f4e0d\tcpip.sys
[2014.10.29 05:52:15 | 002,485,056 | ---- | M] (Microsoft Corporation) MD5=468273F7089A3A33D149955F0F203FA4 -- C:\WINDOWS\SysNative\drivers\tcpip.sys
[2014.10.29 05:52:15 | 002,485,056 | ---- | M] (Microsoft Corporation) MD5=468273F7089A3A33D149955F0F203FA4 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17415_none_a4290d393a23b3f2\tcpip.sys
[2014.10.25 19:35:56 | 000,445,111 | ---- | M] () MD5=5F46548648648BE21060C8DED2B56238 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17238_none_a4166a733a313d8b\tcpip.sys
[2014.09.04 19:33:13 | 000,223,198 | ---- | M] () MD5=889B53B7C56665B0277CC00EF4051DE4 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17085_none_a3dd562d3a5c82ed\tcpip.sys
[2014.10.25 19:35:53 | 000,446,400 | ---- | M] () MD5=96F67EB5FD0CF6809C15A9530C68A8B7 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17136_none_a41467f93a330db6\tcpip.sys
[2014.10.25 19:35:49 | 000,447,007 | ---- | M] () MD5=CBBC133323549D9091F012AE8B8A3BBA -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17039_none_a41766f13a305c94\tcpip.sys
[2015.03.09 17:13:10 | 000,409,864 | ---- | M] () MD5=D0C41590A1BCB4C0BD592D8AB976FE2F -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17336_none_a4146bc53a330804\tcpip.sys
[2014.11.16 11:19:37 | 000,241,540 | ---- | M] () MD5=E7D9CAEE2A6C4007CB85632A13D4EEF3 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17278_none_a3eb2ac33a51ad4f\tcpip.sys
< MD5 for: USERINIT.EXE >
[2015.03.09 17:14:41 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015.03.09 17:55:53 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014.10.29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\WINDOWS\SysNative\userinit.exe
[2014.10.29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014.10.29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014.10.29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe
< MD5 for: WINLOGON.EXE >
[2015.03.09 17:16:47 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2014.04.14 11:58:32 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014.10.29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014.10.29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
< MD5 for: WS2_32.DLL >
[2014.10.29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014.10.29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014.10.29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\WINDOWS\SysNative\ws2_32.dll
[2014.10.29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015.03.09 17:56:30 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015.03.09 17:15:41 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[2 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2015.07.24 17:24:18 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Adobe
[2013.06.19 23:21:51 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\App Launcher Gadget
[2013.11.08 10:54:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Apple Computer
[2014.02.10 22:00:13 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ArcSoft
[2013.04.17 18:36:37 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ASUS
[2013.04.16 17:19:11 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ASUS WebStorage
[2015.03.24 16:41:07 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Autodesk
[2014.01.12 21:19:17 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Blender Foundation
[2013.04.22 08:00:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Canon
[2013.12.19 10:18:34 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2015.07.25 01:05:23 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ClassicShell
[2013.04.20 22:34:20 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.04.16 23:19:56 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\CyberLink
[2015.03.25 22:28:25 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\DAEMON Tools Lite
[2015.03.07 18:38:15 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\DisneyInteractiveStudios
[2014.08.16 19:09:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Dropbox
[2013.04.17 22:17:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ESET
[2014.03.11 19:32:50 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Hamachi
[2013.10.27 23:08:59 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\HDRsoft
[2013.04.16 17:15:10 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Intel
[2013.04.16 17:16:35 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Macromedia
[2015.04.09 18:38:12 | 000,000,000 | --SD | M] -- C:\Users\Tomáš\AppData\Roaming\Microsoft
[2014.10.25 23:55:18 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Might and Delight
[2013.10.13 11:48:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\MonoDevelop-Unity-2.8
[2013.10.03 23:35:53 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Nero
[2013.04.17 16:34:14 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\NVIDIA
[2014.10.09 17:44:07 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Origin
[2013.08.15 15:11:20 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive
[2014.01.08 22:51:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Rainmeter
[2015.07.25 08:40:58 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Skype
[2014.05.07 23:51:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Sports Interactive
[2013.04.20 23:17:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014.11.10 13:10:59 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Steam
[2014.08.27 19:02:56 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Tropico 5
[2014.03.02 01:10:00 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Tunngle
[2013.11.08 11:06:47 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Unity
[2015.07.20 21:08:47 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\uTorrent
[2013.04.17 15:13:58 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Wacom
[2013.04.17 15:15:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2015.01.24 13:01:14 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Warner Bros. Interactive Entertainment
[2014.12.10 18:11:40 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\WB Games
[2013.04.17 15:07:16 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\WTablet
< %APPDATA%\*.exe /s >
[2013.04.18 16:36:47 | 000,054,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Tomáš\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2013.08.15 15:11:20 | 000,065,024 | ---- | M] () -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive\devupgrade.exe
[2013.08.15 15:11:20 | 000,344,576 | ---- | M] () -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive\Paradox Interactive.exe
[2014.01.08 22:51:09 | 000,004,608 | -H-- | M] () -- C:\Users\Tomáš\AppData\Roaming\Rainmeter\Rainmeter.exe
[2015.02.21 00:53:04 | 001,453,392 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
[2014.05.18 19:18:10 | 001,272,400 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31139.exe
[2014.05.26 19:11:27 | 001,267,024 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31415.exe
[2014.05.27 15:26:53 | 001,267,024 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31417.exe
[2014.06.09 19:13:50 | 001,287,504 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_31619.exe
[2014.07.02 11:59:00 | 001,342,288 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32081.exe
[2014.07.07 20:23:34 | 001,468,240 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32247.exe
[2014.07.10 13:34:42 | 001,468,752 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32326.exe
[2014.07.18 18:59:04 | 001,346,384 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32380.exe
[2014.07.28 11:22:42 | 001,563,472 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32574.exe
[2014.08.02 13:52:28 | 001,431,376 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32754.exe
[2014.08.22 09:45:52 | 001,429,328 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33057.exe
[2014.08.29 09:53:52 | 001,428,816 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33320.exe
[2014.09.07 13:05:02 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33627.exe
[2014.09.12 18:05:42 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33854.exe
[2014.09.13 12:27:23 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33923.exe
[2014.09.25 17:31:13 | 001,434,448 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_34174.exe
[2014.10.30 21:22:18 | 001,403,216 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_35021.exe
[2014.12.24 16:11:58 | 001,397,584 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_37318.exe
[2015.01.24 11:25:31 | 001,391,440 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_38332.exe
[2015.02.21 00:53:04 | 001,453,392 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_38709.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2015.05.07 18:53:12 | 019,734,960 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2015.05.07 18:53:12 | 019,734,960 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2015.07.22 17:05:19 | 000,000,018 | ---- | M] () -- C:\WINDOWS\system32\log.txt
[2015.07.24 17:12:54 | 000,008,192 | ---- | M] () -- C:\WINDOWS\system32\WDPABKP.dat
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"RESTART_STICKY_NOTES" = C:\Windows\System32\StikyNot.exe
"CCleaner Monitoring" = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR -- [2014.11.21 20:41:50 | 007,063,832 | ---- | M] (Piriform Ltd)
"AdobeBridge" =
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
No captured output from command...
< >
< type c:\boot.ini >> test.txt /c >
No captured output from command...
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2015.07.25 08:46:33 | 000,000,512 | ---- | M] () MD5=47BF65858C84D5BC0C5DCA807ABFD641 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2015.07.13 22:55:42 | 000,031,291 | ---- | M] () -- \GOG Games\Terraria\Content\Images\TileCracks.xnb
[2014.06.24 23:24:18 | 000,000,036 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\SKIDROWCRACK.COM.txt
[2014.01.04 16:36:00 | 000,000,113 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\WWW.SKIDROWCRACK.COM.url
[2015.04.08 20:58:30 | 000,000,036 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\update\x64\SKIDROWCRACK.COM.txt
[2015.04.08 20:58:30 | 000,000,113 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\update\x64\WWW.SKIDROWCRACK.COM.url
[2001.08.14 19:31:08 | 000,030,054 | ---- | M] () -- \Program Files\Autodesk\3ds Max 2014\Inventor Server\Textures\surfaces\Cracks.bmp
[2011.09.15 05:27:36 | 000,008,428 | ---- | M] () -- \Program Files\Autodesk\3ds Max 2014\maps\Substance\textures\Cracked_Plaster.sbsar
[2011.09.28 04:36:26 | 002,267,256 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\rgb_crackedFun1.tif
[2011.09.28 04:36:27 | 001,539,420 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\rgb_mudCracks.tif
[2011.09.28 04:36:28 | 000,023,048 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\thumbnails\rgb_crackedFun1.tif
[2011.09.28 04:36:28 | 000,031,528 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\thumbnails\rgb_mudCracks.tif
[2014.03.25 21:43:24 | 000,118,272 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.71\python\lib\site-packages\numpy\f2py\crackfortran.py
[2014.10.26 16:36:14 | 000,119,354 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.73\python\lib\site-packages\numpy\f2py\crackfortran.py
[2014.10.26 16:36:14 | 000,119,354 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.74\python\lib\site-packages\numpy\f2py\crackfortran.py
[2001.08.14 19:31:08 | 000,030,054 | ---- | M] () -- \Program Files\Common Files\Autodesk Shared\DirectConnect2014 (64-bit)\bin\Aruba\Inventor Server\Textures\surfaces\Cracks.bmp
[2012.08.02 12:47:48 | 000,145,606 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomCrowbarUse.wav
[2012.08.02 12:47:48 | 000,016,246 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomFlashlightUse.wav
[2012.08.02 12:47:48 | 000,076,306 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomGloveUse.wav
[2012.08.02 12:47:48 | 000,069,586 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomHookUse.wav
[2012.08.02 12:47:48 | 000,032,346 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScorpianShow.wav
[2012.08.02 12:47:48 | 000,134,406 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScorpionStrike.wav
[2012.08.02 12:47:48 | 000,171,086 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScrewdriverUse.wav
[2012.08.02 12:47:48 | 000,085,406 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\HelicopterCrash\WindshieldCrack.wav
[2012.08.02 12:47:08 | 000,026,700 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Data\Scenes\Canyon\WallCrackZoom.xml
[2012.08.02 12:47:18 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\CrackLit.dds
[2012.08.02 12:47:18 | 000,093,248 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\CrackOpen.dds
[2012.08.02 12:47:20 | 000,150,608 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackOpen.dds
[2012.08.02 12:47:22 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\CrackLit.dds
[2012.08.02 12:47:22 | 000,383,744 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\CrackOpen.dds
[2012.08.02 12:47:22 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\WallCrackZoom_Background.dds
[2012.08.02 12:47:22 | 001,299,712 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\Animations\WallCrack_Sandpuff.dds
[2012.08.02 12:47:22 | 000,005,379 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\Animations\WallCrack_Sandpuff_data.xml
[2015.02.21 14:47:25 | 000,026,942 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-Kerbal.Space.Program.v0.25.0.642.Cracked-3DM.torrent
[2014.10.17 23:33:06 | 000,011,619 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Sims.4.Update.1.Incl.Crack.v4.rar.torrent
[2014.10.12 01:56:12 | 000,018,099 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Sims.4.Update.2.and.Crack.v6.rar.torrent
[2014.03.20 10:03:41 | 000,159,739 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Stanley.Parable.Cracked-3DM.7z.torrent
[2015.03.21 01:22:42 | 000,076,961 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Adobe InDesign CC 2014 Multilanguage (64 bit-crack) [ChingLiu].torrent
[2015.03.21 01:22:11 | 000,014,693 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Adobe Photoshop CS6 v6.0.335.0 [ITA] + Crack.torrent
[2014.02.21 02:56:03 | 000,013,154 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Banished_2014_eng_32bit_64bit_cracked.7z.torrent
[2014.02.17 21:09:35 | 000,000,313 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Crazybump Crack.torrent
[2013.04.27 11:14:17 | 000,009,959 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dead.Island.Crack.Only-RELOADED.1.torrent
[2013.04.26 23:58:26 | 000,009,959 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dead.Island.Crack.Only-RELOADED.torrent
[2015.02.21 01:16:56 | 000,000,542 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dying.Light.Crackfix-RELOADED.torrent
[2013.05.14 11:40:38 | 000,020,265 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By G-ADLVR_R7.rar.torrent
[2014.10.30 21:51:07 | 000,000,180 | ---- | M] () -- \Users\Tomáš\Desktop\Adobe Photoshop CS6\Readme (Installation Instructions of crack).txt
[2014.01.30 19:31:54 | 000,166,159 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_base.zip
[2014.01.30 19:33:08 | 000,015,024 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_ruins.zip
[2014.01.30 19:31:56 | 000,033,633 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_ruins_fx.zip
[2014.01.30 19:41:24 | 000,015,152 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_upper.zip
[2014.01.30 19:33:10 | 000,033,514 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_upper_fx.zip
[2014.03.07 18:28:50 | 000,174,884 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\DLC0001\levels\textures\noise_cracked.tex
[2014.05.01 00:24:58 | 000,005,677 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\DLC0001\scripts\components\wisecracker.lua
[2014.01.30 19:34:46 | 000,174,884 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\levels\textures\noise_cracked.tex
[2014.01.30 19:34:04 | 000,004,615 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\scripts\components\wisecracker.lua
[2013.10.23 08:24:04 | 001,398,246 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\mods\screecher\levels\textures\noise_cracked.tex
< *keygen* /s >
[2015.04.07 17:48:25 | 000,022,310 | ---- | M] () -- \Windows\Prefetch\KEYGEN-WIN.EXE-533E2C5D.pf
< *AntiWPA* /s >
< >
[2013.08.22 16:45:54 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
< >
< MD5 for: AGP440.SYS >
[2014.04.14 11:34:07 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\drivers\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013.08.22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2014.09.16 01:14:16 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys
< MD5 for: ATAPI.SYS >
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\drivers\atapi.sys
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013.08.22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2014.04.14 11:36:50 | 000,028,249 | ---- | M] () MD5=0CBDE27FB26761852F7B22AFB8C51ACB -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_d2b24d5495b82963\autochk.exe
[2014.02.22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014.02.22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014.02.22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\WINDOWS\SysNative\autochk.exe
[2014.02.22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2014.04.23 15:25:32 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe
< MD5 for: CDROM.SYS >
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\drivers\cdrom.sys
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_42e9c29f0affc440\cdrom.sys
[2013.08.22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_5067bbed77be70be\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2015.03.09 16:44:30 | 000,018,016 | ---- | M] () MD5=14E1348B6D5DD39C23C2F8FE569B52E0 -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.16384_none_66bdf96f6ec6545d\cryptsvc.dll
[2014.10.29 03:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\WINDOWS\SysNative\cryptsvc.dll
[2014.10.29 03:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.17415_none_670a944b6e8cc0e5\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2011.05.10 17:28:52 | 000,006,952 | ---- | M] () MD5=B5DE6298D2295BA453677B21D24F1F12 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
< MD5 for: EXPLORER.EXE >
[2015.03.17 18:53:54 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2014.09.16 03:31:54 | 000,270,774 | ---- | M] () MD5=2195687491E604BA42961470EDA7660E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_42acff334d876b54\explorer.exe
[2014.09.16 04:02:20 | 000,220,250 | ---- | M] () MD5=286928E00AD34E9F88EB5BFA52660A70 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_4d01a98581e82d4f\explorer.exe
[2014.04.23 15:15:06 | 000,015,546 | ---- | M] () MD5=347EFF7EC89C3EB4F72F2408E1C4E16D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2015.03.09 16:50:17 | 000,395,976 | ---- | M] () MD5=45DD8FAA7B53ABD29BCB9BACABFFC818 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2014.04.23 15:15:03 | 000,238,918 | ---- | M] () MD5=5177BB4FECDDB9CDBCF10EF65916968D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2015.03.20 09:03:43 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2014.09.16 03:31:16 | 000,271,249 | ---- | M] () MD5=667BC926C7CB889BF276A5FEA316CAEE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2014.04.14 11:41:50 | 000,169,957 | ---- | M] () MD5=6D919C26DCB567396CD2E119B8E4310E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2015.01.28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015.01.28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2015.03.09 17:25:07 | 000,338,811 | ---- | M] () MD5=9E110FC1BA4AB7CB5F2F9D27DB534223 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe
[2015.01.28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015.01.28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe
[2014.09.16 04:02:16 | 000,208,662 | ---- | M] () MD5=C131BC6F12417306A9C8469CA49110B1 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2014.04.14 11:41:47 | 000,283,735 | ---- | M] () MD5=FA98C5D746E7C9E0912E88AC44FF9926 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe
< MD5 for: HAL.DLL >
[2014.06.02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\WINDOWS\SysNative\hal.dll
[2014.06.02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17196_none_9bde68c32da7abbb\hal.dll
[2014.09.04 19:26:03 | 000,024,467 | ---- | M] () MD5=2635F50EAF3E1B4A8D32B21E1203E130 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17031_none_9c1a44f32d7b883b\hal.dll
[2014.03.16 23:49:32 | 000,014,096 | ---- | M] () MD5=64D2873F32BB723BFFF3F8895032AA35 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16408_none_9c41d51d2d5cc0c4\hal.dll
[2014.04.14 11:42:32 | 000,066,843 | ---- | M] () MD5=D714202F057A317C8E31776EBEA0AEA2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16500_none_9c39d4b32d63f333\hal.dll
< MD5 for: IASTORV.SYS >
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\drivers\iaStorV.sys
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013.08.22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2014.04.14 11:34:08 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\drivers\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\isapnp.sys
[2013.08.22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\isapnp.sys
[2014.09.16 01:14:20 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\isapnp.sys
< MD5 for: LSASS.EXE >
[2014.10.29 05:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\WINDOWS\SysNative\lsass.exe
[2014.10.29 05:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.17415_none_2e769c84660bda1b\lsass.exe
[2015.03.09 16:54:33 | 000,008,089 | ---- | M] () MD5=3FFB8CD649DEDA6497FD97550BE82357 -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.16408_none_2e8484166600f08e\lsass.exe
< MD5 for: NDIS.SYS >
[2014.02.16 17:43:00 | 000,046,734 | ---- | M] () MD5=68A9BA38BB275850F91165D1C1FCA8DA -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16408_none_4a6e60adfbbe952c\ndis.sys
[2015.02.05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\WINDOWS\SysNative\drivers\ndis.sys
[2015.02.05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17673_none_4a1d9ccbfbfbedff\ndis.sys
[2014.04.14 11:49:30 | 000,140,607 | ---- | M] () MD5=7B886741BDAE33AC4F116DF991D1E3CB -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16475_none_4a1fb05bfbfa0cbe\ndis.sys
[2015.03.20 09:00:18 | 000,080,695 | ---- | M] () MD5=9C48968B0344AD63559D0D080DA66103 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys
[2015.03.09 17:01:42 | 000,162,319 | ---- | M] () MD5=A627B5D38300791075615FF3C8BB3991 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys
[2014.09.16 03:48:45 | 000,025,682 | ---- | M] () MD5=D2D6A481A75207BF24E9D48C61B7F012 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys
< MD5 for: NETLOGON.DLL >
[2014.10.29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\WINDOWS\SysNative\netlogon.dll
[2014.10.29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2014.04.23 15:21:32 | 000,058,552 | ---- | M] () MD5=35048C9600694C3BF01D644D1AAE62BE -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2015.03.09 17:07:58 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015.03.09 17:30:34 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014.10.29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014.10.29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll
[2014.04.14 11:53:00 | 000,108,975 | ---- | M] () MD5=D817ED82C2A0E1CED9B396826F52F7CB -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll
< MD5 for: NVRAID.SYS >
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\drivers\nvraid.sys
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvraid.sys
[2013.08.22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\drivers\nvstor.sys
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013.08.22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys
< MD5 for: SCECLI.DLL >
[2015.03.09 17:30:22 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015.03.09 17:07:31 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014.10.29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\WINDOWS\SysNative\scecli.dll
[2014.10.29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014.10.29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014.10.29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll
< MD5 for: SMSS.EXE >
[2014.04.14 11:54:29 | 000,019,120 | ---- | M] () MD5=5FBA1F5F9AA1E09595F015118AE83A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.16384_none_6f1f364dbcc273d3\smss.exe
[2014.02.22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\WINDOWS\SysNative\smss.exe
[2014.02.22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.17031_none_6f522891bc9cbe45\smss.exe
< MD5 for: SVCHOST.EXE >
[2015.03.09 17:52:42 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2015.03.09 17:08:11 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014.10.29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014.10.29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014.10.29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\WINDOWS\SysNative\svchost.exe
[2014.10.29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe
< MD5 for: TCPIP.SYS >
[2014.02.16 19:42:18 | 000,210,441 | ---- | M] () MD5=01941724D120729E2B680B22F05D4123 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16423_none_a41c53813a2d8394\tcpip.sys
[2014.03.16 23:53:58 | 000,271,861 | ---- | M] () MD5=2102610D6FD1D928A3D7155077A78B82 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16456_none_a3fee49b3a43236c\tcpip.sys
[2014.04.14 11:56:13 | 000,481,295 | ---- | M] () MD5=2F83A7537A9B8CF98E6B4710A3E3D381 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16521_none_a41a54d33a2f4e0d\tcpip.sys
[2014.10.29 05:52:15 | 002,485,056 | ---- | M] (Microsoft Corporation) MD5=468273F7089A3A33D149955F0F203FA4 -- C:\WINDOWS\SysNative\drivers\tcpip.sys
[2014.10.29 05:52:15 | 002,485,056 | ---- | M] (Microsoft Corporation) MD5=468273F7089A3A33D149955F0F203FA4 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17415_none_a4290d393a23b3f2\tcpip.sys
[2014.10.25 19:35:56 | 000,445,111 | ---- | M] () MD5=5F46548648648BE21060C8DED2B56238 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17238_none_a4166a733a313d8b\tcpip.sys
[2014.09.04 19:33:13 | 000,223,198 | ---- | M] () MD5=889B53B7C56665B0277CC00EF4051DE4 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17085_none_a3dd562d3a5c82ed\tcpip.sys
[2014.10.25 19:35:53 | 000,446,400 | ---- | M] () MD5=96F67EB5FD0CF6809C15A9530C68A8B7 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17136_none_a41467f93a330db6\tcpip.sys
[2014.10.25 19:35:49 | 000,447,007 | ---- | M] () MD5=CBBC133323549D9091F012AE8B8A3BBA -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17039_none_a41766f13a305c94\tcpip.sys
[2015.03.09 17:13:10 | 000,409,864 | ---- | M] () MD5=D0C41590A1BCB4C0BD592D8AB976FE2F -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17336_none_a4146bc53a330804\tcpip.sys
[2014.11.16 11:19:37 | 000,241,540 | ---- | M] () MD5=E7D9CAEE2A6C4007CB85632A13D4EEF3 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17278_none_a3eb2ac33a51ad4f\tcpip.sys
< MD5 for: USERINIT.EXE >
[2015.03.09 17:14:41 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015.03.09 17:55:53 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014.10.29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\WINDOWS\SysNative\userinit.exe
[2014.10.29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014.10.29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014.10.29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe
< MD5 for: WINLOGON.EXE >
[2015.03.09 17:16:47 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2014.04.14 11:58:32 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014.10.29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014.10.29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
< MD5 for: WS2_32.DLL >
[2014.10.29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014.10.29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014.10.29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\WINDOWS\SysNative\ws2_32.dll
[2014.10.29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015.03.09 17:56:30 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015.03.09 17:15:41 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[2 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2015.07.24 17:24:18 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Adobe
[2013.06.19 23:21:51 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\App Launcher Gadget
[2013.11.08 10:54:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Apple Computer
[2014.02.10 22:00:13 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ArcSoft
[2013.04.17 18:36:37 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ASUS
[2013.04.16 17:19:11 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ASUS WebStorage
[2015.03.24 16:41:07 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Autodesk
[2014.01.12 21:19:17 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Blender Foundation
[2013.04.22 08:00:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Canon
[2013.12.19 10:18:34 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2015.07.25 01:05:23 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ClassicShell
[2013.04.20 22:34:20 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.04.16 23:19:56 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\CyberLink
[2015.03.25 22:28:25 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\DAEMON Tools Lite
[2015.03.07 18:38:15 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\DisneyInteractiveStudios
[2014.08.16 19:09:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Dropbox
[2013.04.17 22:17:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\ESET
[2014.03.11 19:32:50 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Hamachi
[2013.10.27 23:08:59 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\HDRsoft
[2013.04.16 17:15:10 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Intel
[2013.04.16 17:16:35 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Macromedia
[2015.04.09 18:38:12 | 000,000,000 | --SD | M] -- C:\Users\Tomáš\AppData\Roaming\Microsoft
[2014.10.25 23:55:18 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Might and Delight
[2013.10.13 11:48:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\MonoDevelop-Unity-2.8
[2013.10.03 23:35:53 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Nero
[2013.04.17 16:34:14 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\NVIDIA
[2014.10.09 17:44:07 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Origin
[2013.08.15 15:11:20 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive
[2014.01.08 22:51:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Rainmeter
[2015.07.25 08:40:58 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Skype
[2014.05.07 23:51:21 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Sports Interactive
[2013.04.20 23:17:09 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014.11.10 13:10:59 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Steam
[2014.08.27 19:02:56 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Tropico 5
[2014.03.02 01:10:00 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Tunngle
[2013.11.08 11:06:47 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Unity
[2015.07.20 21:08:47 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\uTorrent
[2013.04.17 15:13:58 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Wacom
[2013.04.17 15:15:30 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2015.01.24 13:01:14 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\Warner Bros. Interactive Entertainment
[2014.12.10 18:11:40 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\WB Games
[2013.04.17 15:07:16 | 000,000,000 | ---D | M] -- C:\Users\Tomáš\AppData\Roaming\WTablet
< %APPDATA%\*.exe /s >
[2013.04.18 16:36:47 | 000,054,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Tomáš\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2013.08.15 15:11:20 | 000,065,024 | ---- | M] () -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive\devupgrade.exe
[2013.08.15 15:11:20 | 000,344,576 | ---- | M] () -- C:\Users\Tomáš\AppData\Roaming\Paradox Interactive\Paradox Interactive.exe
[2014.01.08 22:51:09 | 000,004,608 | -H-- | M] () -- C:\Users\Tomáš\AppData\Roaming\Rainmeter\Rainmeter.exe
[2015.02.21 00:53:04 | 001,453,392 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
[2014.05.18 19:18:10 | 001,272,400 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31139.exe
[2014.05.26 19:11:27 | 001,267,024 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31415.exe
[2014.05.27 15:26:53 | 001,267,024 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.1_31417.exe
[2014.06.09 19:13:50 | 001,287,504 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_31619.exe
[2014.07.02 11:59:00 | 001,342,288 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32081.exe
[2014.07.07 20:23:34 | 001,468,240 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32247.exe
[2014.07.10 13:34:42 | 001,468,752 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32326.exe
[2014.07.18 18:59:04 | 001,346,384 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32380.exe
[2014.07.28 11:22:42 | 001,563,472 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32574.exe
[2014.08.02 13:52:28 | 001,431,376 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_32754.exe
[2014.08.22 09:45:52 | 001,429,328 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33057.exe
[2014.08.29 09:53:52 | 001,428,816 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33320.exe
[2014.09.07 13:05:02 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33627.exe
[2014.09.12 18:05:42 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33854.exe
[2014.09.13 12:27:23 | 001,433,936 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_33923.exe
[2014.09.25 17:31:13 | 001,434,448 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_34174.exe
[2014.10.30 21:22:18 | 001,403,216 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_35021.exe
[2014.12.24 16:11:58 | 001,397,584 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_37318.exe
[2015.01.24 11:25:31 | 001,391,440 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_38332.exe
[2015.02.21 00:53:04 | 001,453,392 | ---- | M] (BitTorrent Inc.) -- C:\Users\Tomáš\AppData\Roaming\uTorrent\updates\3.4.2_38709.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2015.05.07 18:53:12 | 019,734,960 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2015.05.07 18:53:12 | 019,734,960 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2015.07.22 17:05:19 | 000,000,018 | ---- | M] () -- C:\WINDOWS\system32\log.txt
[2015.07.24 17:12:54 | 000,008,192 | ---- | M] () -- C:\WINDOWS\system32\WDPABKP.dat
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"RESTART_STICKY_NOTES" = C:\Windows\System32\StikyNot.exe
"CCleaner Monitoring" = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR -- [2014.11.21 20:41:50 | 007,063,832 | ---- | M] (Piriform Ltd)
"AdobeBridge" =
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
No captured output from command...
< >
< type c:\boot.ini >> test.txt /c >
No captured output from command...
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2015.07.25 08:46:33 | 000,000,512 | ---- | M] () MD5=47BF65858C84D5BC0C5DCA807ABFD641 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2015.07.13 22:55:42 | 000,031,291 | ---- | M] () -- \GOG Games\Terraria\Content\Images\TileCracks.xnb
[2014.06.24 23:24:18 | 000,000,036 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\SKIDROWCRACK.COM.txt
[2014.01.04 16:36:00 | 000,000,113 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\WWW.SKIDROWCRACK.COM.url
[2015.04.08 20:58:30 | 000,000,036 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\update\x64\SKIDROWCRACK.COM.txt
[2015.04.08 20:58:30 | 000,000,113 | ---- | M] () -- \Program Files (x86)\Rockstar games\GTA V\update\x64\WWW.SKIDROWCRACK.COM.url
[2001.08.14 19:31:08 | 000,030,054 | ---- | M] () -- \Program Files\Autodesk\3ds Max 2014\Inventor Server\Textures\surfaces\Cracks.bmp
[2011.09.15 05:27:36 | 000,008,428 | ---- | M] () -- \Program Files\Autodesk\3ds Max 2014\maps\Substance\textures\Cracked_Plaster.sbsar
[2011.09.28 04:36:26 | 002,267,256 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\rgb_crackedFun1.tif
[2011.09.28 04:36:27 | 001,539,420 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\rgb_mudCracks.tif
[2011.09.28 04:36:28 | 000,023,048 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\thumbnails\rgb_crackedFun1.tif
[2011.09.28 04:36:28 | 000,031,528 | ---- | M] () -- \Program Files\Autodesk\Mudbox 2015\Stamps\thumbnails\rgb_mudCracks.tif
[2014.03.25 21:43:24 | 000,118,272 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.71\python\lib\site-packages\numpy\f2py\crackfortran.py
[2014.10.26 16:36:14 | 000,119,354 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.73\python\lib\site-packages\numpy\f2py\crackfortran.py
[2014.10.26 16:36:14 | 000,119,354 | ---- | M] () -- \Program Files\Blender Foundation\Blender\2.74\python\lib\site-packages\numpy\f2py\crackfortran.py
[2001.08.14 19:31:08 | 000,030,054 | ---- | M] () -- \Program Files\Common Files\Autodesk Shared\DirectConnect2014 (64-bit)\bin\Aruba\Inventor Server\Textures\surfaces\Cracks.bmp
[2012.08.02 12:47:48 | 000,145,606 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomCrowbarUse.wav
[2012.08.02 12:47:48 | 000,016,246 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomFlashlightUse.wav
[2012.08.02 12:47:48 | 000,076,306 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomGloveUse.wav
[2012.08.02 12:47:48 | 000,069,586 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomHookUse.wav
[2012.08.02 12:47:48 | 000,032,346 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScorpianShow.wav
[2012.08.02 12:47:48 | 000,134,406 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScorpionStrike.wav
[2012.08.02 12:47:48 | 000,171,086 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\Canyon\CrackZoomScrewdriverUse.wav
[2012.08.02 12:47:48 | 000,085,406 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Audio\Sfx\Scenes\HelicopterCrash\WindshieldCrack.wav
[2012.08.02 12:47:08 | 000,026,700 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Data\Scenes\Canyon\WallCrackZoom.xml
[2012.08.02 12:47:18 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\CrackLit.dds
[2012.08.02 12:47:18 | 000,093,248 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\CrackOpen.dds
[2012.08.02 12:47:20 | 000,150,608 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackOpen.dds
[2012.08.02 12:47:22 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\CrackLit.dds
[2012.08.02 12:47:22 | 000,383,744 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\CrackOpen.dds
[2012.08.02 12:47:22 | 001,008,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\WallCrackZoom_Background.dds
[2012.08.02 12:47:22 | 001,299,712 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\Animations\WallCrack_Sandpuff.dds
[2012.08.02 12:47:22 | 000,005,379 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Adera_1.0.0.4957_x86__8wekyb3d8bbwe\Episodes\Episode1\Graphics\Scenes\Canyon\WallCrackZoom\Animations\WallCrack_Sandpuff_data.xml
[2015.02.21 14:47:25 | 000,026,942 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-Kerbal.Space.Program.v0.25.0.642.Cracked-3DM.torrent
[2014.10.17 23:33:06 | 000,011,619 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Sims.4.Update.1.Incl.Crack.v4.rar.torrent
[2014.10.12 01:56:12 | 000,018,099 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Sims.4.Update.2.and.Crack.v6.rar.torrent
[2014.03.20 10:03:41 | 000,159,739 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\3DMGAME-The.Stanley.Parable.Cracked-3DM.7z.torrent
[2015.03.21 01:22:42 | 000,076,961 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Adobe InDesign CC 2014 Multilanguage (64 bit-crack) [ChingLiu].torrent
[2015.03.21 01:22:11 | 000,014,693 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Adobe Photoshop CS6 v6.0.335.0 [ITA] + Crack.torrent
[2014.02.21 02:56:03 | 000,013,154 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Banished_2014_eng_32bit_64bit_cracked.7z.torrent
[2014.02.17 21:09:35 | 000,000,313 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Crazybump Crack.torrent
[2013.04.27 11:14:17 | 000,009,959 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dead.Island.Crack.Only-RELOADED.1.torrent
[2013.04.26 23:58:26 | 000,009,959 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dead.Island.Crack.Only-RELOADED.torrent
[2015.02.21 01:16:56 | 000,000,542 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\Dying.Light.Crackfix-RELOADED.torrent
[2013.05.14 11:40:38 | 000,020,265 | ---- | M] () -- \Users\Tomáš\AppData\Roaming\uTorrent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By G-ADLVR_R7.rar.torrent
[2014.10.30 21:51:07 | 000,000,180 | ---- | M] () -- \Users\Tomáš\Desktop\Adobe Photoshop CS6\Readme (Installation Instructions of crack).txt
[2014.01.30 19:31:54 | 000,166,159 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_base.zip
[2014.01.30 19:33:08 | 000,015,024 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_ruins.zip
[2014.01.30 19:31:56 | 000,033,633 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_ruins_fx.zip
[2014.01.30 19:41:24 | 000,015,152 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_upper.zip
[2014.01.30 19:33:10 | 000,033,514 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\anim\nightmare_crack_upper_fx.zip
[2014.03.07 18:28:50 | 000,174,884 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\DLC0001\levels\textures\noise_cracked.tex
[2014.05.01 00:24:58 | 000,005,677 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\DLC0001\scripts\components\wisecracker.lua
[2014.01.30 19:34:46 | 000,174,884 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\levels\textures\noise_cracked.tex
[2014.01.30 19:34:04 | 000,004,615 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\data\scripts\components\wisecracker.lua
[2013.10.23 08:24:04 | 001,398,246 | ---- | M] () -- \Users\Tomáš\Documents\My Games\Do not Starve\Don't Starve and DLC Reign of Giants\mods\screecher\levels\textures\noise_cracked.tex
< *keygen* /s >
[2015.04.07 17:48:25 | 000,022,310 | ---- | M] () -- \Windows\Prefetch\KEYGEN-WIN.EXE-533E2C5D.pf
< *AntiWPA* /s >