OTL.txt
--------
OTL logfile created on: 26.8.2015 12:06:44 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kopac\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 0,88 Gb Available Physical Memory | 43,85% Memory free
4,24 Gb Paging File | 2,43 Gb Available in Paging File | 57,42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225,07 Gb Total Space | 43,37 Gb Free Space | 19,27% Space Free | Partition Type: NTFS
Computer Name: KOPAC-PC | User Name: Kopac | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015.08.26 11:59:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kopac\Desktop\OTL.exe
PRC - [2015.08.13 04:58:03 | 000,377,000 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2015.07.17 20:33:20 | 006,453,528 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2015.04.20 01:59:56 | 001,765,856 | ---- | M] (Last.fm) -- C:\Program Files\Winamp\Last.fm\Last.fm Scrobbler.exe
PRC - [2015.03.28 12:58:42 | 000,089,840 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
PRC - [2014.12.16 14:07:19 | 001,005,352 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
PRC - [2013.10.20 08:04:24 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
PRC - [2013.04.30 05:53:00 | 000,453,632 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2013.04.30 05:52:26 | 000,217,088 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011.10.10 14:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2015.07.17 19:34:42 | 000,047,104 | ---- | M] () -- C:\Program Files\CCleaner\Lang\lang-1029.dll
MOD - [2015.05.13 22:08:20 | 000,250,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\69e762017ca0da2b45d9ed147e4865e3\WindowsFormsIntegration.ni.dll
MOD - [2015.05.13 22:07:15 | 019,547,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a78078ff6ff0c28ef3bf65bd84e193f0\System.ServiceModel.ni.dll
MOD - [2015.05.13 22:00:24 | 018,753,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\dba6e73775e7b823a02925f063bd2983\PresentationFramework.ni.dll
MOD - [2015.05.13 22:00:07 | 011,014,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\f6fee9c78602505e874ec0807e3b1a51\PresentationCore.ni.dll
MOD - [2015.05.13 21:59:57 | 003,904,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\efd34838fa44da246b78328f4432eac7\WindowsBase.ni.dll
MOD - [2015.05.13 21:59:52 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\908075c4922acdf834c67ac802814c9d\System.Configuration.ni.dll
MOD - [2015.05.13 21:59:48 | 006,982,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\c61bafa9d029e3f2bf83bd5af3f1f5ac\System.Core.ni.dll
MOD - [2015.04.20 02:00:38 | 000,184,800 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\plugins\phonon_backend\phonon_vlc.dll
MOD - [2015.04.20 02:00:38 | 000,051,680 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\plugins\audio_output\libaout_directx_plugin.dll
MOD - [2015.04.20 02:00:04 | 000,353,248 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\lastfm.dll
MOD - [2015.04.20 02:00:04 | 000,034,784 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\logger.dll
MOD - [2015.04.20 02:00:00 | 000,738,784 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\unicorn.dll
MOD - [2015.04.20 02:00:00 | 000,128,992 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\listener.dll
MOD - [2015.04.20 01:59:56 | 000,304,608 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\phonon.dll
MOD - [2015.04.20 01:59:56 | 000,113,120 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\libvlc.dll
MOD - [2015.04.20 01:59:54 | 002,288,608 | ---- | M] () -- C:\Program Files\Winamp\Last.fm\libvlccore.dll
MOD - [2015.02.08 23:22:51 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d18e2115a3270f89663fce831547f534\System.ni.dll
MOD - [2015.02.08 23:22:36 | 000,188,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\232495ea0368dada2d208c51f0e5349c\UIAutomationTypes.ni.dll
MOD - [2015.02.08 23:15:34 | 000,286,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatiod51afaa5#\4edaa939589829c3b21a1295310bf2d1\PresentationFramework.classic.ni.dll
MOD - [2015.02.08 23:15:32 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\9e42fe7c83345249b5dde1693d1bf8b5\PresentationFramework-SystemXml.ni.dll
MOD - [2015.02.08 20:29:01 | 007,793,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\3d6ee4ffbd9a86ac1e7b01800b6fe9c7\System.Xml.ni.dll
MOD - [2015.02.08 20:27:15 | 001,873,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\1196cc375887ce75f134047505fe19bf\System.Xaml.ni.dll
MOD - [2015.02.08 20:26:11 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll
MOD - [2013.09.05 01:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2013.06.17 13:35:10 | 000,478,400 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
MOD - [2013.04.30 04:46:36 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012.03.07 02:37:08 | 000,020,288 | ---- | M] () -- C:\Program Files\CCleaner\branding.dll
========== Services (SafeList) ==========
SRV - [2015.08.13 04:58:15 | 000,149,160 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015.03.28 12:58:42 | 000,089,840 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2013.12.19 01:41:02 | 030,814,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2013.10.20 08:04:24 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe -- (AVP)
SRV - [2013.04.30 05:52:26 | 000,217,088 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013.02.04 18:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2011.10.10 14:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) [Auto | Running] -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2008.01.19 00:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2014.03.20 13:07:23 | 000,576,608 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2014.02.17 11:32:32 | 000,025,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klkbdflt.sys -- (klkbdflt)
DRV - [2014.02.07 14:07:00 | 000,243,128 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2014.02.07 13:18:00 | 000,144,992 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kneps.sys -- (kneps)
DRV - [2014.02.07 13:17:59 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (kl1)
DRV - [2013.10.20 08:04:20 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2013.10.20 08:04:20 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2013.05.14 18:34:44 | 000,045,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kltdi.sys -- (kltdi)
DRV - [2013.04.30 06:14:44 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2013.04.30 04:47:52 | 000,290,304 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2013.04.12 16:34:48 | 000,014,432 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klpd.sys -- (klpd)
DRV - [2012.10.26 17:32:26 | 000,136,192 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qcusbnet.sys -- (qcusbnet)
DRV - [2012.10.26 17:31:56 | 000,110,080 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qcusbser.sys -- (qcusbser)
DRV - [2012.02.23 14:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2011.02.11 12:22:50 | 000,025,728 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\androidusb.sys -- (androidusb)
DRV - [2010.03.04 14:50:14 | 000,261,152 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2005.05.08 13:30:56 | 000,070,233 | ---- | M] (Y0YS Software) [File_System | Boot | Running] -- C:\Windows\System32\secdir.sys -- (secdir)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3771582624-879338843-1209121951-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3771582624-879338843-1209121951-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3771582624-879338843-1209121951-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-3771582624-879338843-1209121951-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "CZ"
FF - prefs.js..browser.search.hiddenOneOffs: "Seznam,Heuréka,Mapy.cz,Slunečnice"
FF - prefs.js..browser.search.region: "CZ"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:40.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
url_advisor@kaspersky.com [2014.12.16 14:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
virtual_keyboard@kaspersky.com [2014.12.16 14:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
content_blocker@kaspersky.com [2014.12.16 14:09:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
anti_banner@kaspersky.com [2014.12.16 14:09:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\
online_banking@kaspersky.com [2014.12.16 14:09:02 | 000,000,000 | ---D | M]
[2014.02.06 13:02:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kopac\AppData\Roaming\Mozilla\Extensions
[2015.08.20 00:32:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kopac\AppData\Roaming\Mozilla\Firefox\Profiles\58vzoub2.default-1439983395755\extension-data
[2015.08.20 13:41:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kopac\AppData\Roaming\Mozilla\Firefox\Profiles\58vzoub2.default-1439983395755\extensions
[2015.08.19 13:25:52 | 003,627,011 | ---- | M] () (No name found) -- C:\Users\Kopac\AppData\Roaming\Mozilla\Firefox\Profiles\58vzoub2.default-1439983395755\extensions\
uBlock0@raymondhill.net.xpi
[2015.08.19 23:45:57 | 000,963,213 | ---- | M] () (No name found) -- C:\Users\Kopac\AppData\Roaming\Mozilla\Firefox\Profiles\58vzoub2.default-1439983395755\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015.08.16 02:36:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2015.08.16 02:36:13 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2015.08.20 11:56:59 | 000,000,057 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 license.piriform.com
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\AMD\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3771582624-879338843-1209121951-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Přidat do součásti Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm ()
O9 - Extra Button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62190150-41CE-4D59-AFD3-1CDAFFB9A237}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Kopac\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kopac\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{055a57b2-9ec4-11e3-a1c7-00a0c6000016}\Shell - "" = AutoRun
O33 - MountPoints2\{055a57b2-9ec4-11e3-a1c7-00a0c6000016}\Shell\AutoRun\command - "" = J:\setup.exe
O33 - MountPoints2\{245bae5b-9c66-11e3-95ab-00a0c6000015}\Shell - "" = AutoRun
O33 - MountPoints2\{245bae5b-9c66-11e3-95ab-00a0c6000015}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{a9726611-958e-11e3-b35a-001f81000250}\Shell - "" = AutoRun
O33 - MountPoints2\{a9726611-958e-11e3-b35a-001f81000250}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{a9726622-958e-11e3-b35a-001f81000250}\Shell - "" = AutoRun
O33 - MountPoints2\{a9726622-958e-11e3-b35a-001f81000250}\Shell\AutoRun\command - "" = J:\setup.exe
O33 - MountPoints2\{d4d31824-0310-11e5-a151-00a0c6000019}\Shell - "" = AutoRun
O33 - MountPoints2\{d4d31824-0310-11e5-a151-00a0c6000019}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{df20c158-8fe6-11e3-898a-001d7d432424}\Shell - "" = AutoRun
O33 - MountPoints2\{df20c158-8fe6-11e3-898a-001d7d432424}\Shell\AutoRun\command - "" = I:\Setup.exe
O33 - MountPoints2\{fd4e185a-d45c-11e3-8590-00a0c6000018}\Shell - "" = AutoRun
O33 - MountPoints2\{fd4e185a-d45c-11e3-8590-00a0c6000018}\Shell\AutoRun\command - "" = K:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2015.08.26 11:59:12 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Kopac\Desktop\OTL.exe
[2015.08.20 12:57:16 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Local\Eraser 6
[2015.08.20 12:54:47 | 000,000,000 | ---D | C] -- C:\Program Files\Eraser
[2015.08.20 12:04:54 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2015.08.20 11:54:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015.08.19 20:15:35 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2015.08.19 14:14:28 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015.08.19 14:12:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2015.08.19 14:12:58 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2015.08.19 13:47:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DO
[2015.08.17 22:38:58 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2015.08.17 22:38:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015.08.17 13:41:47 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2015.08.14 14:58:55 | 000,000,000 | ---D | C] -- C:\Users\Kopac\Documents\NFS Most Wanted
[2015.08.14 12:23:32 | 000,000,000 | ---D | C] -- C:\Users\Kopac\Documents\Criterion Games
[2015.08.13 18:12:00 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Local\CrashRpt
[2015.08.13 00:24:49 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2015.08.13 00:24:49 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmmsp.dll
[2015.08.13 00:24:48 | 003,605,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2015.08.13 00:24:46 | 003,553,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2015.08.13 00:20:46 | 000,103,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2015.08.12 21:36:13 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basesrv.dll
[2015.08.12 21:24:27 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2015.08.12 21:24:27 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2015.08.12 21:24:27 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2015.08.12 21:24:27 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2015.08.12 21:24:26 | 002,066,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2015.08.12 21:24:26 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2015.08.12 21:24:26 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2015.08.12 21:24:26 | 000,682,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2015.08.12 21:24:26 | 000,297,472 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2015.08.12 21:24:26 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2015.08.12 21:24:25 | 001,072,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2015.08.12 10:09:12 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2015.08.12 10:09:11 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2015.08.12 10:09:11 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2015.08.12 10:09:11 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2015.08.12 10:09:11 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2015.08.12 10:09:10 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2015.08.12 10:09:10 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2015.08.12 10:09:09 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2015.08.12 10:09:07 | 001,810,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2015.08.12 10:09:07 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2015.08.12 10:09:07 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2015.08.12 10:09:05 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2015.08.09 16:29:53 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Roaming\dvdcss
[2015.08.05 00:03:08 | 000,877,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr120_clr0400.dll
[2015.08.05 00:03:08 | 000,538,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp120_clr0400.dll
[2015.08.04 14:48:18 | 000,000,000 | ---D | C] -- C:\Users\Kopac\Documents\Bigasoft Total Video Converter
[2015.08.04 14:46:23 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Roaming\Bigasoft Total Video Converter 5
[2015.08.04 14:46:05 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bigasoft
[2015.08.04 14:46:01 | 000,000,000 | ---D | C] -- C:\Program Files\Bigasoft
[2015.08.04 14:24:15 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Roaming\avidemux
[2015.08.04 14:17:30 | 000,000,000 | ---D | C] -- C:\Users\Kopac\AppData\Roaming\Nico Mak Computing
[2015.08.03 16:37:37 | 000,000,000 | ---D | C] -- C:\Users\Kopac\Documents\GTA San Andreas User Files
[2015.08.03 15:37:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2015.08.03 15:35:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015.08.26 12:16:11 | 000,063,488 | ---- | M] () -- C:\Users\Kopac\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2015.08.26 12:12:23 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015.08.26 11:59:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kopac\Desktop\OTL.exe
[2015.08.26 10:48:58 | 000,004,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2015.08.26 10:48:58 | 000,004,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2015.08.26 10:48:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.08.26 10:48:50 | 2147,016,704 | -HS- | M] () -- C:\hiberfil.sys
[2015.08.26 00:02:44 | 000,001,076 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2015.08.25 22:27:26 | 000,390,336 | ---- | M] () -- C:\Users\Kopac\Documents\all.m3u
[2015.08.23 11:24:28 | 000,000,918 | ---- | M] () -- C:\Users\Kopac\Documents\cc_20150823_112423.reg
[2015.08.20 11:56:59 | 000,000,057 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2015.08.19 13:09:47 | 000,029,696 | ---- | M] () -- C:\Users\Kopac\AppData\Local\MSGBOX.EXE
[2015.08.15 00:55:37 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2015.08.12 22:18:39 | 000,377,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2015.08.12 12:05:35 | 000,778,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015.08.12 12:05:35 | 000,142,536 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015.08.09 09:53:51 | 000,024,206 | ---- | M] () -- C:\Users\Kopac\AppData\Roaming\UserTile.png
[2015.08.06 10:47:04 | 000,658,970 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2015.08.06 10:47:04 | 000,648,752 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015.08.06 10:47:04 | 000,144,862 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2015.08.06 10:47:04 | 000,125,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015.08.05 00:03:08 | 000,877,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr120_clr0400.dll
[2015.08.05 00:03:08 | 000,538,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcp120_clr0400.dll
[2015.08.01 00:08:07 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2015.07.31 23:46:51 | 001,029,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2015.07.31 23:46:51 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2015.07.31 23:46:51 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2015.07.31 23:46:51 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2015.07.31 22:41:22 | 001,172,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2015.07.31 22:40:42 | 000,486,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2015.07.31 22:35:10 | 000,682,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2015.07.31 22:33:57 | 001,072,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2015.07.31 22:33:43 | 002,066,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2015.07.31 22:33:04 | 000,297,472 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2015.07.31 21:27:52 | 000,103,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015.08.26 12:12:23 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015.08.23 11:24:26 | 000,000,918 | ---- | C] () -- C:\Users\Kopac\Documents\cc_20150823_112423.reg
[2015.08.20 12:54:48 | 000,001,670 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eraser.lnk
[2015.08.19 11:33:50 | 000,029,696 | ---- | C] () -- C:\Users\Kopac\AppData\Local\MSGBOX.EXE
[2015.08.16 02:36:19 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015.08.12 22:13:04 | 2147,016,704 | -HS- | C] () -- C:\hiberfil.sys
[2015.08.09 09:53:51 | 000,024,206 | ---- | C] () -- C:\Users\Kopac\AppData\Roaming\UserTile.png
[2015.05.24 18:17:46 | 000,162,689 | ---- | C] () -- C:\Windows\hpoins19.dat
[2015.05.24 18:14:25 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2014.07.12 10:08:39 | 000,000,161 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2014.02.11 13:31:55 | 000,028,456 | ---- | C] () -- C:\Windows\System32\solidlocalmon.dll
[2014.02.11 13:31:55 | 000,019,752 | ---- | C] () -- C:\Windows\System32\solidlocalui.dll
[2014.02.11 12:21:08 | 000,000,200 | ---- | C] () -- C:\Windows\pdf2word.INI
[2014.02.08 21:10:27 | 000,000,298 | ---- | C] () -- C:\Windows\game.ini
[2014.02.07 14:10:47 | 000,000,543 | ---- | C] () -- C:\Windows\wininit.ini
[2014.02.06 18:59:23 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2014.02.06 18:58:04 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2014.02.06 18:58:04 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2014.02.06 15:49:51 | 000,063,488 | ---- | C] () -- C:\Users\Kopac\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.02.06 15:08:03 | 000,433,664 | ---- | C] () -- C:\Users\Kopac\AppData\Roaming\setup.msi
[2014.02.06 13:14:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014.02.06 12:56:54 | 000,001,356 | ---- | C] () -- C:\Users\Kopac\AppData\Local\d3d9caps.dat
[2014.02.06 12:48:27 | 000,001,076 | ---- | C] () -- C:\Windows\bthservsdp.dat
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.07.11 17:56:09 | 011,587,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 00:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014.02.20 12:28:45 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\602Installer
[2014.02.20 12:32:35 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\602XML
[2014.11.07 14:47:50 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\AnvSoft
[2014.11.06 12:30:23 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\anyburn
[2014.11.06 10:31:21 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Ashampoo
[2015.03.04 16:47:52 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\AVG
[2015.08.10 15:53:42 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\avidemux
[2015.08.04 14:46:23 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Bigasoft Total Video Converter 5
[2015.01.28 11:58:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\calibre
[2015.03.16 14:56:25 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Canneverbe Limited
[2015.08.19 14:19:01 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\DAEMON Tools Lite
[2014.07.19 20:32:17 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\fofix
[2014.11.05 17:26:51 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Free Burning Studio
[2014.07.19 19:16:03 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\fretsonfire
[2014.06.26 12:57:39 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\ICQ-Profile
[2014.02.13 16:59:00 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\ICQM
[2015.07.09 19:55:09 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Image Zone Express
[2015.03.08 12:40:16 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Maxthon3
[2015.08.26 11:00:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\MiniLyrics
[2015.04.07 16:42:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Miranda
[2014.11.05 17:26:54 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\New Version Available
[2015.08.04 22:17:13 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Nico Mak Computing
[2015.08.17 11:04:13 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Opera Software
[2014.08.26 10:15:20 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Printer Info Cache
[2015.04.06 07:30:37 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\QIP
[2014.02.08 00:31:30 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Seznam.cz
[2014.02.20 12:32:42 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Software602
[2014.02.11 14:54:27 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\SolidDocuments
[2014.02.11 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\SomePDF
[2014.02.07 13:31:08 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Thunderbird
[2014.02.06 15:10:56 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\TuneUp Software
[2014.02.11 12:43:20 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Wondershare
[2015.03.09 16:27:12 | 000,000,000 | ---D | M] -- C:\Users\Ostatní\AppData\Roaming\AVG
[2014.07.26 20:54:51 | 000,000,000 | ---D | M] -- C:\Users\Ostatní\AppData\Roaming\MiniLyrics
[2015.04.02 16:46:29 | 000,000,000 | ---D | M] -- C:\Users\Ostatní\AppData\Roaming\Opera Software
[2014.02.06 17:39:48 | 000,000,000 | ---D | M] -- C:\Users\Ostatní\AppData\Roaming\TuneUp Software
[2015.01.16 18:23:07 | 000,000,000 | ---D | M] -- C:\Users\Ostatní\AppData\Roaming\XRay Engine
========== Purity Check ==========
========== Custom Scans ==========
< >
[2006.11.02 15:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 15:01:49 | 000,032,604 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2015.05.26 18:59:14 | 000,000,292 | ---- | C] () -- C:\Windows\Tasks\WebReg psc 1400 series.job
< >
< MD5 for: AGP440.SYS >
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2014.02.06 17:11:24 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2014.02.06 17:11:24 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2014.02.06 17:11:24 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009.04.11 00:27:22 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\System32\autochk.exe
[2009.04.11 00:27:22 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2008.01.19 00:33:02 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2006.11.02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe
< MD5 for: CDROM.SYS >
[2008.01.18 22:49:52 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_a29e71c6\cdrom.sys
[2008.01.18 22:49:52 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6001.18000_none_5fa95be2a3c76a4a\cdrom.sys
[2009.04.10 22:39:18 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\drivers\cdrom.sys
[2009.04.10 22:39:18 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_c949a5b6\cdrom.sys
[2009.04.10 22:39:18 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys
[2006.11.02 10:51:44 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=8D1866E61AF096AE8B582454F5E4D303 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_e487f727\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2013.10.03 15:16:48 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=165E9D93A84A7F55EBEEB1B554110680 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23235_none_78542a95b127239a\cryptsvc.dll
[2006.11.02 11:46:03 | 000,123,392 | ---- | M] (Microsoft Corporation) MD5=1C26FB097170A2A91066D1E3A24366E3 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\cryptsvc.dll
[2013.04.24 06:00:30 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=3EDE4C1F9672C972479201544969ADCB -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18831_none_77c6b0b4980cf0e4\cryptsvc.dll
[2013.04.17 14:30:06 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=58CEF2D243575512657452B9E89A2E1F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18827_none_77d7825c97ff6cfd\cryptsvc.dll
[2013.07.08 06:16:55 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=684C130BBC6DB681BAD4920A4C944AA5 -- C:\Windows\System32\cryptsvc.dll
[2013.07.08 06:16:55 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=684C130BBC6DB681BAD4920A4C944AA5 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18881_none_7790a11898357c99\cryptsvc.dll
[2008.01.19 00:34:02 | 000,128,000 | ---- | M] (Microsoft Corporation) MD5=6DE363F9F99334514C46AEC02D3E3678 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\cryptsvc.dll
[2013.07.08 04:50:53 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=828805E2E7F529B24849AD52740288DA -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23154_none_783d888db13844fe\cryptsvc.dll
[2013.04.17 13:28:51 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=CC8E2C87016A07892B5448D764BF8A30 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23097_none_781547d5b15603a0\cryptsvc.dll
[2009.04.11 00:28:20 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=FB27772BEAF8E1D28CCD825C09DA939B -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_77eb127097f11935\cryptsvc.dll
[2013.04.24 05:46:45 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=FBE051C07C3D2B9011ECB1C7A73120C1 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23101_none_7870974bb1126d44\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2014.02.06 17:10:35 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2014.02.06 17:10:34 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2014.02.06 17:10:34 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2014.02.06 15:28:08 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2014.02.06 15:28:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2014.02.06 17:10:34 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008.01.19 00:33:12 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: HAL.DLL >
[2009.04.11 00:32:48 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Windows\System32\hal.dll
< MD5 for: IASTORV.SYS >
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2006.11.02 11:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\Windows\System32\drivers\isapnp.sys
[2006.11.02 11:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\isapnp.sys
[2008.01.19 00:42:16 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\isapnp.sys
[2008.01.19 00:42:16 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\isapnp.sys
[2008.01.19 00:42:16 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\isapnp.sys
[2008.01.19 00:42:16 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\isapnp.sys
< MD5 for: LSASS.EXE >
[2014.02.06 17:09:10 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=203D86EBD6D8E4C8501B222421E81506 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_a886901f7335e2fc\lsass.exe
[2014.02.06 15:24:46 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2D3AC5E7AC01E905F3ABD2D745FE3A9B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
[2015.06.27 16:20:12 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2DCDD1B84875C0D5404173EC3B00E454 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23737_none_a8a1260573213258\lsass.exe
[2014.02.06 15:24:47 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_a7fbf30a5a1929db\lsass.exe
[2015.04.30 16:19:51 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=474FDD99DB6012E21405AAEE8DA61546 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23683_none_a867135b734d5b8a\lsass.exe
[2014.02.06 17:00:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=59DE082968FDD257FFF0D209B9A5B460 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[2012.06.02 00:37:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=613DEB66A91820F0A41915B40BB8833F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22869_none_a882cf8373379c5f\lsass.exe
[2006.11.02 11:45:21 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=6A0E382E74280E4CC0DF17FE2661D003 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16386_none_a413c8c65fe02762\lsass.exe
[2014.02.06 17:09:09 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=6F1F23D3599EAE17734451936B7F17C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_a69e1da376115b2a\lsass.exe
[2014.10.11 01:21:41 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=86C519D59C70327434641E862A70B52B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23521_none_a8a5f069731e840f\lsass.exe
[2015.01.15 07:17:50 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A28A5386D01A5C6B085838624955EF3C -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23594_none_a85d41d3735493ab\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\System32\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18541_none_a806cc745a10ffad\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18643_none_a808ceee5a0f2f82\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.19214_none_a82a209c59f61a0b\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.19284_none_a7de71285a2edda2\lsass.exe
[2011.11.16 16:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.19431_none_a81183b25a090036\lsass.exe
[2014.02.06 15:24:46 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A911ECAC81F94ADEAFBE8E3F7873EDB0 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_a600dfae5d0228c9\lsass.exe
[2015.03.06 04:16:32 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=ACAC4085ECDA9A35ED621936D67DB9D4 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23640_none_a88f522d732f9fc1\lsass.exe
[2014.02.06 17:00:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=AFF8A58280863629CA4FFA9E0B259F1E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[2014.02.06 17:09:10 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=BA9A67672E025078C77967731BCFC560 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_a4b3e75378eccda6\lsass.exe
[2014.12.03 02:23:58 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=C4AA089041242987308AE2A7B30E910A -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23555_none_a88981cd73333d3e\lsass.exe
[2014.02.06 15:24:48 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=C731B1FE449D4E9CEA358C9D55B69BE9 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_a418a0745fdd652a\lsass.exe
[2014.02.06 15:24:46 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=CB7E838C140B4087B2DA323F2D4523C5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
[2014.02.06 15:24:47 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=D09A5DA84B7C9CA9B02EBCD7FAE41C8D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
[2014.02.06 17:00:01 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[2014.02.06 17:00:01 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[2014.02.06 17:00:01 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\lsass.exe
[2011.11.16 15:57:04 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=EBFAEB786C46B407930811F94F08877D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22742_none_a8916b6f732db5f5\lsass.exe
[2014.02.06 17:00:01 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=F4C62B07E5BF96F1FDCA9DB393ECED22 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe
< MD5 for: NDIS.SYS >
[2009.04.11 00:32:50 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009.04.11 00:32:50 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2006.11.02 11:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys
[2008.01.19 00:43:32 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
< MD5 for: NETLOGON.DLL >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVRAID.SYS >
[2008.01.19 00:43:02 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvraid.sys
[2008.01.19 00:43:02 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvraid.sys
[2006.11.02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\drivers\nvraid.sys
[2006.11.02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< MD5 for: SMSS.EXE >
[2013.07.08 03:18:50 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=18CE0D0DCB7AF0D3E67ECF12BDE1382D -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23154_none_ae7897262f9a96cf\smss.exe
[2015.03.13 02:10:36 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=363FBAC6FECBD86D1795EE69B342DA30 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23654_none_ae78a0a42f9a8892\smss.exe
[2008.01.19 00:33:32 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=6701DDAF68BEDE6BBEEA9D514D73A35B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
[2015.07.21 16:15:47 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=97BDD5240706720FA47B7F8F904EE87E -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23762_none_ae6bd20a2fa46efc\smss.exe
[2009.04.11 00:28:06 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_ae26210916536b06\smss.exe
[2015.01.09 02:18:11 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=B5C66E0B251D954D6CED30E4FDB07792 -- C:\Windows\System32\smss.exe
[2015.01.09 02:18:11 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=B5C66E0B251D954D6CED30E4FDB07792 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.19279_none_adde5fc11688a7e8\smss.exe
[2013.03.09 03:28:08 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=BE7480C91E89EB82FC080F772C220AE4 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18805_none_ae2630391653543e\smss.exe
[2006.11.02 11:45:45 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=CAA75757BB3695478C23CB0624342A61 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6000.16386_none_aa03e6011c468ee6\smss.exe
[2015.07.18 16:16:27 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=E999B040E681E143171F3F8925899934 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23761_none_ae6ad1c02fa555a5\smss.exe
[2015.02.26 02:16:47 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=EF4707EB97B522B1FBC447654DC4F1F2 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23636_none_ae9041102f88835e\smss.exe
< MD5 for: SVCHOST.EXE >
[2006.11.02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008.01.19 00:33:34 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008.01.19 00:33:34 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: TCPIP.SYS >
[2009.04.11 00:33:04 | 000,897,000 | ---- | M] (Microsoft Corporation) MD5=0E6B0885C3D5E4643ED2D043DE3433D8 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_b5098b5e63880c42\tcpip.sys
[2014.02.06 15:29:24 | 000,816,640 | ---- | M] (Microsoft Corporation) MD5=2512B4D1353370D6688B1AF1F5AFA1CF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\tcpip.sys
[2014.02.06 15:29:19 | 000,900,168 | ---- | M] (Microsoft Corporation) MD5=2608E71AAD54564647D4BB984E1925AA -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys
[2014.02.06 17:02:23 | 000,818,688 | ---- | M] (Microsoft Corporation) MD5=2C1F7005AA3B62721BFDB307BD5F5010 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_6019359fab5bb15b\tcpip.sys
[2014.02.06 17:02:22 | 000,898,952 | ---- | M] (Microsoft Corporation) MD5=2EAE4500984C2F8DACFB977060300A15 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys
[2014.02.06 15:29:24 | 000,813,568 | ---- | M] (Microsoft Corporation) MD5=300208927321066EA53761FDC98747C6 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\tcpip.sys
[2014.02.06 17:02:23 | 000,904,576 | ---- | M] (Microsoft Corporation) MD5=48CBE6D53632D0067C2D6B20F90D84CA -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_b50d905263846bec\tcpip.sys
[2014.02.06 17:02:24 | 000,815,104 | ---- | M] (Microsoft Corporation) MD5=4A82FA8F0DF67AA354580C3FAAF8BDE3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_5f8a957c924295b7\tcpip.sys
[2014.02.06 17:08:39 | 000,806,400 | ---- | M] (Microsoft Corporation) MD5=52A8BD6294F7D1443C6184C67AE13AF4 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys
[2014.02.06 17:08:40 | 000,803,328 | ---- | M] (Microsoft Corporation) MD5=5DF77458AA92FDB36FCE79C60F74AB5D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
[2014.02.06 15:29:22 | 000,904,776 | ---- | M] (Microsoft Corporation) MD5=65877AA1B6A7CB797488E831698973E9 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_b4a43aea63d4a25f\tcpip.sys
[2013.07.05 05:20:37 | 000,914,880 | ---- | M] (Microsoft Corporation) MD5=6D0D344F643E28B31262AC2682109A3C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.23152_none_b55a00e77cd1055d\tcpip.sys
[2014.02.06 15:29:19 | 000,897,608 | ---- | M] (Microsoft Corporation) MD5=8A7AD2A214233F684242F289ED83EBC3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys
[2014.02.06 17:02:22 | 000,902,024 | ---- | M] (Microsoft Corporation) MD5=93A5655CD9CD2F080EF1CB71A3666215 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys
[2014.04.05 05:23:10 | 000,915,392 | ---- | M] (Microsoft Corporation) MD5=A4196D394207369E1431E8681B373312 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.23370_none_b54264477ce304df\tcpip.sys
[2014.04.05 04:42:27 | 000,905,664 | ---- | M] (Microsoft Corporation) MD5=C7B0746FCD576D7EEBA6A2530B0B2966 -- C:\Windows\System32\drivers\tcpip.sys
[2014.04.05 04:42:27 | 000,905,664 | ---- | M] (Microsoft Corporation) MD5=C7B0746FCD576D7EEBA6A2530B0B2966 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.19080_none_b4adf3c463cd86b8\tcpip.sys
[2013.07.05 06:53:33 | 000,905,664 | ---- | M] (Microsoft Corporation) MD5=D18D53974FD715D50FC76F9FFE1C830D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18880_none_b4ae19bc63cd564f\tcpip.sys
[2006.11.02 10:58:38 | 000,802,816 | ---- | M] (Microsoft Corporation) MD5=D944522B048A5FEB7700B5170D3D9423 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
[2014.02.06 17:02:23 | 000,910,216 | ---- | M] (Microsoft Corporation) MD5=D9F5DD5BBC8348E8F8220CCBF14C022E -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_b563eb1d7cc9b0c2\tcpip.sys
[2008.01.19 00:43:40 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=FC6E2835D667774D409C7C7021EAF9C4 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys
[2014.02.06 15:29:22 | 000,905,784 | ---- | M] (Microsoft Corporation) MD5=FF71856BD4CD6D4367F9FD84BE79A874 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_b58e289d7caa2a80\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.01.19 00:37:10 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\System32\ws2_32.dll
[2008.01.19 00:37:10 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll
[2006.11.02 11:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6000.16386_none_f080eec6d16af4f0\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[6 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[189 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\twain_32\*.tmp files -> C:\Windows\twain_32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2014.02.20 12:28:45 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\602Installer
[2014.02.20 12:32:35 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\602XML
[2014.02.09 01:22:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Adobe
[2014.11.07 14:47:50 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\AnvSoft
[2014.11.06 12:30:23 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\anyburn
[2014.11.06 10:31:21 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Ashampoo
[2014.02.06 17:26:48 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\ATI
[2015.03.04 16:47:52 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\AVG
[2015.08.10 15:53:42 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\avidemux
[2015.08.04 14:46:23 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Bigasoft Total Video Converter 5
[2015.01.28 11:58:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\calibre
[2015.03.16 14:56:25 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Canneverbe Limited
[2015.08.19 14:19:01 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\DAEMON Tools Lite
[2015.08.09 16:32:48 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\dvdcss
[2014.07.19 20:32:17 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\fofix
[2014.11.05 17:26:51 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Free Burning Studio
[2014.07.19 19:16:03 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\fretsonfire
[2015.05.24 18:37:56 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\HP
[2015.05.30 16:02:10 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\HpUpdate
[2014.06.26 12:57:39 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\ICQ-Profile
[2014.02.13 16:59:00 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\ICQM
[2014.02.06 12:56:59 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Identities
[2015.07.09 19:55:09 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Image Zone Express
[2014.02.06 13:19:27 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Macromedia
[2015.03.08 12:40:16 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Maxthon3
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Media Center Programs
[2015.06.12 18:03:58 | 000,000,000 | --SD | M] -- C:\Users\Kopac\AppData\Roaming\Microsoft
[2015.08.26 11:00:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\MiniLyrics
[2015.04.07 16:42:06 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Miranda
[2014.02.06 13:02:41 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Mozilla
[2015.03.17 12:38:54 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Nero
[2014.11.05 17:26:54 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\New Version Available
[2015.08.04 22:17:13 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Nico Mak Computing
[2015.08.17 11:04:13 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Opera Software
[2014.08.26 10:15:20 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Printer Info Cache
[2015.04.06 07:30:37 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\QIP
[2014.02.08 00:31:30 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Seznam.cz
[2014.02.20 12:32:42 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Software602
[2014.02.11 14:54:27 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\SolidDocuments
[2014.02.11 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\SomePDF
[2014.02.07 13:31:08 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Thunderbird
[2014.02.06 15:10:56 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\TuneUp Software
[2015.08.26 00:01:58 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\vlc
[2014.10.01 19:59:08 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Winamp
[2014.02.06 14:05:27 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\WinRAR
[2014.02.11 12:43:20 | 000,000,000 | ---D | M] -- C:\Users\Kopac\AppData\Roaming\Wondershare
< %APPDATA%\*.exe /s >
[2015.02.25 16:50:57 | 001,071,160 | ---- | M] (Power Software Ltd) -- C:\Users\Kopac\AppData\Roaming\anyburn\Upgrade\anyburn_setup.exe
[2014.02.13 16:59:00 | 033,664,344 | ---- | M] (ICQ) -- C:\Users\Kopac\AppData\Roaming\ICQM\icq.exe
[2014.02.13 16:59:04 | 039,431,496 | ---- | M] (ICQ) -- C:\Users\Kopac\AppData\Roaming\ICQM\icqsetup.exe
[2014.02.13 16:59:00 | 004,739,616 | ---- | M] () -- C:\Users\Kopac\AppData\Roaming\ICQM\ICQ\dll\mailrusputnik.exe
[2015.05.08 14:50:52 | 001,799,448 | ---- | M] (Maxthon International ltd.) -- C:\Users\Kopac\AppData\Roaming\Maxthon3\Public\MxUp\MxUp.exe
[2013.08.21 17:20:08 | 000,253,440 | ---- | M] (Microsoft) -- C:\Users\Kopac\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\StartUp Manager\Disabled objects\Adsystem.exe
[2014.01.04 13:31:42 | 002,083,568 | ---- | M] (Wondershare ) -- C:\Users\Kopac\AppData\Roaming\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2015.08.26 12:49:04 | 000,004,896 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2015.08.26 12:49:04 | 000,004,896 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CCleaner Monitoring" = "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR -- [2015.07.17 20:33:20 | 006,453,528 | ---- | M] (Piriform Ltd)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2015.08.26 12:12:23 | 000,000,512 | ---- | M] () MD5=8F239AE2F71121409D1FC39CF1EF66DD -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2015.08.26 12:08:19 | 275,597,778 | ---- | M] () -- \Filmy\Seriály\South Park\15. série\05.-SPORTOVNÍ-ASOCIACE-PRO-DĚTI-ZÁVISLÉ-NA-CRACKU.avi
[2003.12.05 14:52:40 | 000,000,796 | ---- | M] () -- \Hry\Rockstar Games\GTA San Andreas\data\Decision\Craig\crack1.ped
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2011.04.15 17:29:28 | 000,000,118 | ---- | M] () -- \Hry\DiRT 3\audio\audio_loader.xml
[2014.09.03 01:27:24 | 000,268,432 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2014.09.03 01:27:24 | 000,019,096 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2014.12.16 14:07:11 | 001,451,816 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kasperskylab.kis.ui.loader.dll
[2013.05.14 11:59:38 | 000,221,376 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kas_loader.dll
[2014.02.17 11:31:36 | 000,340,672 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\prloader.dll
[2014.02.17 11:31:38 | 000,203,456 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\remote_eka_prague_loader.dll
[1 \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\*.tmp files -> \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\*.tmp -> ]
[2013.06.17 12:55:30 | 000,001,557 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_16.gif
[2013.06.17 12:55:30 | 000,000,419 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_16.png
[2013.06.17 12:55:30 | 000,006,377 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_32.gif
[2013.06.17 12:55:30 | 000,001,276 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_32.png
[2013.06.17 12:55:30 | 000,009,568 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_48.gif
[2013.06.17 12:55:30 | 000,001,805 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_48.png
[2013.06.17 12:55:30 | 000,020,462 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_96.gif
[2013.06.17 12:55:30 | 000,004,009 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\common\loader_96.png
[2013.06.17 12:55:30 | 000,002,793 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\btn_loader.png
[2013.06.17 12:55:30 | 000,001,459 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0001.png
[2013.06.17 12:55:30 | 000,001,423 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00010.png
[2013.06.17 12:55:30 | 000,001,453 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00011.png
[2013.06.17 12:55:30 | 000,001,464 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00012.png
[2013.06.17 12:55:30 | 000,001,487 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00013.png
[2013.06.17 12:55:30 | 000,001,480 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00014.png
[2013.06.17 12:55:30 | 000,001,455 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00015.png
[2013.06.17 12:55:30 | 000,001,408 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_00016.png
[2013.06.17 12:55:30 | 000,001,472 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0002.png
[2013.06.17 12:55:30 | 000,001,480 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0003.png
[2013.06.17 12:55:30 | 000,001,471 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0004.png
[2013.06.17 12:55:30 | 000,001,439 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0005.png
[2013.06.17 12:55:30 | 000,001,413 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0006.png
[2013.06.17 12:55:30 | 000,001,367 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0007.png
[2013.06.17 12:55:30 | 000,001,274 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0008.png
[2013.06.17 12:55:30 | 000,001,390 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\images\scale-100\scan\loader\loader_0009.png
[2013.06.17 12:55:32 | 000,006,957 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\skin\resources\neutral\templates\images\safe_banking\preloader.gif
[2015.02.09 11:56:20 | 000,076,088 | ---- | M] () -- \Program Files\Maxthon\Bin\MxAppLoader.exe
[2015.02.09 11:56:20 | 000,668,440 | ---- | M] () -- \Program Files\Maxthon\Bin\MxDownloader.dll
[2015.02.09 11:56:24 | 000,086,768 | ---- | M] () -- \Program Files\Maxthon\Core\Webkit\Npplugins\gameloader.exe
[2015.06.08 20:01:18 | 000,002,381 | ---- | M] () -- \Program Files\Mozilla Thunderbird\distribution\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calBackendLoader.js
[2013.03.05 08:29:10 | 000,001,706 | ---- | M] () -- \Program Files\Winamp\MiniLyrics\Skins\Metal\iPodLyricsDownloader.java
[2013.04.29 15:19:12 | 000,007,217 | ---- | M] () -- \Program Files\Winamp\MiniLyrics\Skins\Metal\iPodLyricsDownloader.xml
[2013.03.05 08:29:10 | 000,000,462 | ---- | M] () -- \Program Files\Winamp\MiniLyrics\Skins\Metal\iPodLyricsDownloader_theme.xml
[2013.04.29 15:19:12 | 000,004,840 | ---- | M] () -- \Program Files\Winamp\MiniLyrics\Skins\MiniLyrics\iPodLyricsDownloader.xml
[2013.03.05 08:29:10 | 000,000,462 | ---- | M] () -- \Program Files\Winamp\MiniLyrics\Skins\MiniLyrics\iPodLyricsDownloader_theme.xml
[2014.02.06 14:04:01 | 000,001,033 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\MiniLyrics\iPod Lyrics Downloader.lnk
[2014.02.06 14:04:01 | 000,001,033 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\MiniLyrics\iPod Lyrics Downloader.lnk
[2015.07.11 17:48:17 | 000,002,381 | ---- | M] () -- \Users\Kopac\AppData\Roaming\Thunderbird\Profiles\2iaz538s.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calBackendLoader.js
[2015.07.11 17:48:17 | 000,000,249 | ---- | M] () -- \Users\Kopac\AppData\Roaming\Thunderbird\Profiles\2iaz538s.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calBackendLoader.manifest
[2013.03.09 09:17:04 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2013.03.09 09:17:04 | 000,268,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:12:34 | 000,249,680 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2008.01.19 00:34:06 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.07.20 09:34:54 | 000,070,936 | ---- | M] () -- \Windows\System32\PhysXLoader.dll
[2 \Windows\System32\*.tmp files -> \Windows\System32\*.tmp -> ]
[2014.02.06 18:22:04 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2014.02.06 18:22:04 | 000,027,648 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winload.exe.mui_3bc5b827
[2014.02.06 18:22:04 | 000,019,968 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winresume.exe.mui_ff8b5358
[2014.02.06 19:12:11 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2014.02.06 19:12:11 | 000,986,600 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winload.exe_75835076
[2014.02.06 19:12:11 | 000,926,184 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winresume.exe_85cd1215
[2014.02.06 18:20:58 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2014.02.06 18:20:58 | 000,021,048 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2_spldr.sys_98bd87a0
[2014.02.06 13:52:47 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_de-de_cb9c6772f81a418b.manifest
[2014.02.06 13:52:31 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_en-us_748d3d6be6f84d50.manifest
[2014.02.06 13:52:57 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_es-es_74589a4fe71f3ef5.manifest
[2014.02.06 13:52:32 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_fr-fr_1710104ed9f15557.manifest
[2014.02.06 13:53:19 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_it-it_01380695b1233ad5.manifest
[2014.02.06 13:53:23 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_ja-jp_a35d85a2a43e4cb0.manifest
[2014.02.06 13:53:40 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_nl-nl_2d992eca70004957.manifest
[2014.02.06 13:52:47 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_de-de_cbf6c366115bebbd.manifest
[2014.02.06 13:52:31 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_en-us_74e7995f0039f782.manifest
[2014.02.06 13:52:57 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_es-es_74b2f6430060e927.manifest
[2014.02.06 13:52:31 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_fr-fr_176a6c41f332ff89.manifest
[2014.02.06 13:53:19 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_it-it_01926288ca64e507.manifest
[2014.02.06 13:53:23 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_ja-jp_a3b7e195bd7ff6e2.manifest
[2014.02.06 13:53:39 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_nl-nl_2df38abd8941f389.manifest
[2008.01.19 05:14:52 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2014.02.06 13:52:24 | 000,004,858 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.16646_none_591b3d986f9b5725.manifest
[2014.02.06 13:52:23 | 000,004,858 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.20782_none_5975998b88dd0157.manifest
[2008.01.19 01:00:00 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18000_none_5b26ba326ca6e048.manifest
[2014.02.06 13:52:10 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18027_none_5b181c606cb0c98b.manifest
[2014.02.06 13:52:09 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.22125_none_5b9fb89785d036a7.manifest
[2009.04.11 01:12:44 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2006.11.02 12:13:06 | 000,003,970 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6000.16386_none_68fc663d5430d3de.manifest
[2008.01.19 01:05:22 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2006.11.02 14:34:33 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6000.16386_none_43bd59f592b7be86\dmloader.dll
[2008.01.19 00:34:06 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6001.18000_none_45f41bf18fa2cf5a\dmloader.dll
[2008.01.19 00:34:06 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6002.18005_none_47df94fd8cc49aa6\dmloader.dll