========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 04 BC 7D 60 F2 A2 D2 01 [binary data]
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IESR02
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-116116240-444440880-2871013289-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "CZ"
FF - prefs.js..browser.search.region: "CZ"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:53.0.2
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\winki\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\winki\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 53.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 53.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2017.04.07 11:43:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Extensions
[2017.05.09 12:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\browser-extension-data
[2017.05.09 12:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\browser-extension-data\
sp@avast.com
[2017.05.09 12:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\browser-extension-data\
wrc@avast.com
[2017.05.08 04:30:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\extensions
[2017.05.08 04:30:36 | 000,352,829 | ---- | M] () (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\extensions\
sp@avast.com.xpi
[2017.05.08 04:30:36 | 000,692,271 | ---- | M] () (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\extensions\
wrc@avast.com.xpi
[2017.05.10 12:33:27 | 000,044,954 | ---- | M] () (No name found) -- C:\Users\winki\AppData\Roaming\Mozilla\Firefox\Profiles\8k8cupjw.default\features\{2542ac87-aeb2-4634-ada1-ec71991b2ba0}\
shield-recipe-client@mozilla.org.xpi
[2017.05.10 11:23:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.6_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj\15.1.0.6_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil\1.97.54_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl\2.2_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpniocchabmgenibceglhnfeimmdhdfm\2.12.9_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp\57.0.2987.84_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi\1.5.0.20_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak\6.91_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi\3.1_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.4.1_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\9.3_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.12_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\winki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\
O1 HOSTS File: ([2017.04.18 12:54:10 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvLaunch.exe (AVAST Software)
O4:
64bit: - HKLM..\Run: [LogiOptions] C:\Program Files\Logitech\LogiOptions\LogiOptions.exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Logitech Download Assistant] C:\WINDOWS\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [SecurityHealth] C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [ShadowPlay] C:\WINDOWS\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [5KPlayer.exe] C:\Program Files (x86)\DearMob\5KPlayer\5KPlayer.exe ()
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies Ltd.)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-116116240-444440880-2871013289-1001..\Run: [Google Update] C:\Users\winki\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe (Google Inc.)
O4 - HKU\S-1-5-21-116116240-444440880-2871013289-1001..\Run: [OneDrive] C:\Users\winki\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-116116240-444440880-2871013289-1001..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
O4 - HKU\S-1-5-21-116116240-444440880-2871013289-1001..\Run: [Spotify Web Helper] C:\Users\winki\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.5.1 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{f6f79c62-3dd4-4c57-afbc-ad196e28e681}: DhcpNameServer = 192.168.5.1 8.8.8.8
O18:
64bit: - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:
64bit: dosvc - C:\Windows\SysNative\dosvc.dll (Microsoft Corporation)
NetSvcs:
64bit: shpamsvc - C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll (Microsoft Corporation)
NetSvcs:
64bit: XblGameSave - C:\Windows\SysNative\XblGameSave.dll (Microsoft Corporation)
NetSvcs:
64bit: NaturalAuthentication - C:\Windows\SysNative\NaturalAuth.dll (Microsoft Corporation)
NetSvcs:
64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: UserManager - C:\Windows\SysNative\usermgr.dll (Microsoft Corporation)
NetSvcs:
64bit: XblAuthManager - C:\Windows\SysNative\XblAuthManager.dll (Microsoft Corporation)
NetSvcs:
64bit: DmEnrollmentSvc - C:\Windows\SysNative\Windows.Internal.Management.dll (Microsoft Corporation)
NetSvcs:
64bit: xbgm - C:\Windows\SysNative\xbgmsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: TokenBroker - C:\Windows\SysNative\TokenBroker.dll (Microsoft Corporation)
NetSvcs:
64bit: lfsvc - C:\Windows\SysNative\lfsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: dmwappushservice - C:\Windows\SysNative\dmwappushsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: wisvc - C:\Windows\SysNative\FlightSettings.dll (Microsoft Corporation)
NetSvcs:
64bit: WpnService - C:\Windows\SysNative\wpnservice.dll (Microsoft Corporation)
NetSvcs:
64bit: XboxNetApiSvc - C:\Windows\SysNative\XboxNetApiSvc.dll (Microsoft Corporation)
NetSvcs:
64bit: UsoSvc - C:\Windows\SysNative\usocore.dll (Microsoft Corporation)
NetSvcs:
64bit: NetSetupSvc - C:\Windows\SysNative\NetSetupSvc.dll (Microsoft Corporation)
NetSvcs:
64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:
64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:
64bit: XboxGipSvc - C:\Windows\SysNative\xboxgipsvc.dll (Microsoft Corporation)
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs: TokenBroker - C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2017.05.14 03:49:53 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\AdobeGC
[2017.05.13 18:41:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf5c22d6750ddac1d
[2017.05.13 18:40:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignae896445d7bac9eb
[2017.05.13 18:40:50 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne40b791031c4cce9
[2017.05.13 18:40:50 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign379f5a0cb355b263
[2017.05.13 18:16:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd4ff1751dec261aa
[2017.05.13 18:16:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncf4249153baa79b7
[2017.05.13 18:16:32 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignae8ff2788a5f26c7
[2017.05.13 18:16:32 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign581b9270483465b3
[2017.05.13 18:16:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigna967a282f0538743
[2017.05.13 18:16:16 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne7dc96d72c39c073
[2017.05.13 18:16:14 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncad9523386f18c8c
[2017.05.13 18:16:14 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign704bc2e21f21aff6
[2017.05.13 14:38:25 | 000,000,000 | ---D | C] -- C:\ProgramData\SWCUTemp
[2017.05.12 23:28:18 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\speech
[2017.05.12 16:37:22 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\Google
[2017.05.12 16:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\VideoCopilot
[2017.05.11 20:17:46 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncf6c3b7bd363e978
[2017.05.11 20:17:46 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0431e8aed84beeeb
[2017.05.11 20:17:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf793f0a9ab9a9890
[2017.05.11 20:17:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc0d1baa1b0324e1a
[2017.05.11 12:19:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2017.05.11 12:12:31 | 020,505,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2017.05.11 12:12:31 | 006,759,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2017.05.11 12:12:31 | 006,728,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2017.05.11 12:12:31 | 006,292,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2017.05.11 12:12:31 | 004,559,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbgeng.dll
[2017.05.11 12:12:31 | 004,469,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2017.05.11 12:12:31 | 003,667,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_47.dll
[2017.05.11 12:12:31 | 002,957,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2017.05.11 12:12:31 | 002,330,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2017.05.11 12:12:31 | 002,298,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2017.05.11 12:12:31 | 002,259,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2017.05.11 12:12:31 | 002,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2017.05.11 12:12:31 | 001,463,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2017.05.11 12:12:31 | 001,411,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2017.05.11 12:12:31 | 001,291,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVPXENC.dll
[2017.05.11 12:12:31 | 001,285,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbghelp.dll
[2017.05.11 12:12:31 | 001,248,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AzureSettingSyncProvider.dll
[2017.05.11 12:12:31 | 001,019,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aadtb.dll
[2017.05.11 12:12:31 | 000,987,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wpnapps.dll
[2017.05.11 12:12:31 | 000,909,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2017.05.11 12:12:31 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autochk.exe
[2017.05.11 12:12:31 | 000,806,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\StoreAgent.dll
[2017.05.11 12:12:31 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBroker.dll
[2017.05.11 12:12:31 | 000,790,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.dll
[2017.05.11 12:12:31 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mmgaserver.exe
[2017.05.11 12:12:31 | 000,636,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WpcWebFilter.dll
[2017.05.11 12:12:31 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbonRes.dll
[2017.05.11 12:12:31 | 000,583,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreMessaging.dll
[2017.05.11 12:12:31 | 000,559,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2017.05.11 12:12:31 | 000,523,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppResolver.dll
[2017.05.11 12:12:31 | 000,476,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OneDriveSettingSyncProvider.dll
[2017.05.11 12:12:31 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2017.05.11 12:12:31 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InstallAgentUserBroker.exe
[2017.05.11 12:12:31 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2017.05.11 12:12:31 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieproxy.dll
[2017.05.11 12:12:31 | 000,354,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2017.05.11 12:12:31 | 000,329,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webplatstorageserver.dll
[2017.05.11 12:12:31 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InstallAgent.exe
[2017.05.11 12:12:31 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VEEventDispatcher.dll
[2017.05.11 12:12:31 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WiFiDisplay.dll
[2017.05.11 12:12:31 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CloudBackupSettings.dll
[2017.05.11 12:12:31 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
[2017.05.11 12:12:31 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2017.05.11 12:12:31 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2017.05.11 12:12:31 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2017.05.11 12:12:31 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2017.05.11 12:12:31 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cldapi.dll
[2017.05.11 12:12:31 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\odbcconf.dll
[2017.05.11 12:12:25 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Gaming.Preview.dll
[2017.05.11 12:12:25 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2017.05.11 12:12:20 | 007,904,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2017.05.11 12:12:20 | 001,260,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GamePanel.exe
[2017.05.11 12:12:20 | 001,051,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.dll
[2017.05.11 12:12:20 | 000,707,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2017.05.11 12:12:20 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsrv.dll
[2017.05.11 12:12:19 | 005,557,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbgeng.dll
[2017.05.11 12:12:19 | 003,672,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2017.05.11 12:12:19 | 002,056,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2017.05.11 12:12:19 | 001,075,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StoreAgent.dll
[2017.05.11 12:12:19 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usocore.dll
[2017.05.11 12:12:19 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbonRes.dll
[2017.05.11 12:12:19 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2017.05.11 12:12:19 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgentUserBroker.exe
[2017.05.11 12:12:19 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\updatehandlers.dll
[2017.05.11 12:12:19 | 000,373,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgent.exe
[2017.05.11 12:12:19 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationObjFactory.dll
[2017.05.11 12:12:19 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2017.05.11 12:12:19 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2017.05.11 12:12:19 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEStoreEventHandlers.dll
[2017.05.11 12:12:19 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\musdialoghandlers.dll
[2017.05.11 12:12:18 | 007,931,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2017.05.11 12:12:18 | 004,175,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StartTileData.dll
[2017.05.11 12:12:18 | 002,499,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.pcshell.dll
[2017.05.11 12:12:18 | 002,435,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ResetEngine.dll
[2017.05.11 12:12:18 | 001,878,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AzureSettingSyncProvider.dll
[2017.05.11 12:12:18 | 001,611,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SpeechPal.dll
[2017.05.11 12:12:18 | 001,293,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aadtb.dll
[2017.05.11 12:12:18 | 001,242,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedStartModel.dll
[2017.05.11 12:12:18 | 001,103,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2017.05.11 12:12:18 | 001,087,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2017.05.11 12:12:18 | 001,054,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBroker.dll
[2017.05.11 12:12:18 | 000,985,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TSWorkspace.dll
[2017.05.11 12:12:18 | 000,840,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2017.05.11 12:12:18 | 000,651,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2017.05.11 12:12:18 | 000,585,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneDriveSettingSyncProvider.dll
[2017.05.11 12:12:17 | 008,244,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2017.05.11 12:12:17 | 004,730,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2017.05.11 12:12:17 | 004,446,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2017.05.11 12:12:17 | 001,433,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettings.Handlers.dll
[2017.05.11 12:12:17 | 000,590,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2017.05.11 12:12:17 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aadcloudap.dll
[2017.05.11 12:12:16 | 008,320,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2017.05.11 12:12:16 | 005,477,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneCoreUAPCommonProxyStub.dll
[2017.05.11 12:12:16 | 002,765,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
[2017.05.11 12:12:16 | 001,320,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2017.05.11 12:12:16 | 001,302,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVPXENC.dll
[2017.05.11 12:12:16 | 001,257,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnapps.dll
[2017.05.11 12:12:16 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\modernexecserver.dll
[2017.05.11 12:12:16 | 000,925,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcWebFilter.dll
[2017.05.11 12:12:16 | 000,775,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2017.05.11 12:12:16 | 000,716,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2017.05.11 12:12:16 | 000,647,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RDXService.dll
[2017.05.11 12:12:16 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll
[2017.05.11 12:12:16 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2017.05.11 12:12:15 | 002,399,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2017.05.11 12:12:15 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mmgaserver.exe
[2017.05.11 12:12:15 | 000,741,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2017.05.11 12:12:15 | 000,712,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms2.sys
[2017.05.11 12:12:15 | 000,708,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kernel32.dll
[2017.05.11 12:12:15 | 000,687,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LogonController.dll
[2017.05.11 12:12:15 | 000,673,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppBroker.dll
[2017.05.11 12:12:15 | 000,646,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockHostingFramework.dll
[2017.05.11 12:12:15 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2017.05.11 12:12:15 | 000,387,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpps.dll
[2017.05.11 12:12:15 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.ps.dll
[2017.05.11 12:12:15 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\odbcconf.dll
[2017.05.11 12:12:14 | 023,677,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2017.05.11 12:12:14 | 001,583,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2017.05.11 12:12:14 | 000,805,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieproxy.dll
[2017.05.11 12:12:14 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2017.05.11 12:12:14 | 000,457,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webplatstorageserver.dll
[2017.05.11 12:12:14 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2017.05.11 12:12:14 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2017.05.11 12:12:14 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2017.05.11 12:12:14 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2017.05.11 12:12:14 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2017.05.11 12:12:14 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2017.05.11 12:12:12 | 004,848,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2017.05.11 12:12:12 | 004,396,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_47.dll
[2017.05.11 12:12:12 | 002,969,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreUIComponents.dll
[2017.05.11 12:12:12 | 002,651,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2017.05.11 12:12:12 | 002,077,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2017.05.11 12:12:12 | 001,852,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\crypt32.dll
[2017.05.11 12:12:12 | 001,604,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2017.05.11 12:12:12 | 001,600,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbghelp.dll
[2017.05.11 12:12:12 | 001,295,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dosvc.dll
[2017.05.11 12:12:12 | 001,269,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2017.05.11 12:12:12 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpAXHolder.dll
[2017.05.11 12:12:12 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsEnvironment.Desktop.dll
[2017.05.11 12:12:12 | 000,301,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseAppMgmtSvc.dll
[2017.05.11 12:12:12 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\domgmt.dll
[2017.05.11 12:12:12 | 000,105,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imagehlp.dll
[2017.05.11 12:12:11 | 003,116,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2017.05.11 12:12:11 | 001,325,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2017.05.11 12:12:11 | 000,667,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2017.05.11 12:12:11 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cldapi.dll
[2017.05.11 12:12:11 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\catsrvps.dll
[2017.05.11 12:12:10 | 001,628,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comsvcs.dll
[2017.05.11 12:12:10 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2017.05.11 12:12:10 | 000,142,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wcifs.sys
[2017.05.11 12:12:08 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CloudBackupSettings.dll
[2017.05.11 12:12:08 | 000,207,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\browserbroker.dll
[2017.05.11 12:12:08 | 000,027,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\browser_broker.exe
[2017.05.11 12:12:07 | 002,800,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2017.05.11 12:12:07 | 001,886,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2017.05.11 12:12:07 | 001,854,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppVEntVirtualization.dll
[2017.05.11 12:12:07 | 001,468,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2017.05.11 12:12:07 | 001,452,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppVEntSubsystemController.dll
[2017.05.11 12:12:07 | 000,970,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autochk.exe
[2017.05.11 12:12:07 | 000,673,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppResolver.dll
[2017.05.11 12:12:07 | 000,624,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2017.05.11 12:12:07 | 000,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2017.05.11 12:12:07 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.AppDefaults.dll
[2017.05.11 12:12:07 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseModernAppMgmtCSP.dll
[2017.05.11 12:12:06 | 002,085,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpdateAgent.dll
[2017.05.11 12:12:06 | 000,923,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreMessaging.dll
[2017.05.11 12:12:06 | 000,872,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2017.05.11 12:12:06 | 000,864,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2017.05.11 12:12:06 | 000,543,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2017.05.11 12:12:06 | 000,524,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TileDataRepository.dll
[2017.05.11 12:12:06 | 000,517,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2017.05.11 12:12:04 | 000,388,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2017.05.11 12:12:04 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netvsc.sys
[2017.05.11 12:12:04 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BasicRender.sys
[2017.05.08 22:31:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne26c1ac22bd462de
[2017.05.08 21:58:44 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9e7938b39d386aab
[2017.05.08 21:58:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc39221c5bce56df7
[2017.05.08 21:58:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9dfd3197a7b8900f
[2017.05.08 21:58:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign8f1b12b8e395c2bb
[2017.05.08 04:30:42 | 000,400,456 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2017.05.05 00:23:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Factorio
[2017.05.05 00:22:45 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\Factorio
[2017.05.04 20:50:28 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Red Giant
[2017.05.04 20:50:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\LooksBuilder
[2017.05.04 16:57:19 | 000,134,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2017.05.04 16:57:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2017.05.04 16:55:23 | 035,388,864 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2017.05.04 16:55:23 | 011,056,456 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvptxJitCompiler.dll
[2017.05.04 16:55:23 | 010,547,440 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2017.05.04 16:55:23 | 009,014,792 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvptxJitCompiler.dll
[2017.05.04 16:55:23 | 008,805,232 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2017.05.04 16:55:22 | 040,201,848 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcompiler.dll
[2017.05.04 16:55:22 | 035,281,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2017.05.04 16:55:22 | 011,024,384 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2017.05.04 16:55:22 | 009,245,744 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2017.05.04 16:55:22 | 003,792,320 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2017.05.04 16:55:22 | 003,247,736 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2017.05.04 16:55:22 | 001,988,032 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6438205.dll
[2017.05.04 16:55:22 | 001,589,696 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6438205.dll
[2017.05.04 16:55:22 | 001,278,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncMFTH264.dll
[2017.05.04 16:55:22 | 001,276,128 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncMFThevc.dll
[2017.05.04 16:55:22 | 001,054,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2017.05.04 16:55:22 | 000,995,736 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncMFTH264.dll
[2017.05.04 16:55:22 | 000,993,872 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncMFThevc.dll
[2017.05.04 16:55:22 | 000,991,168 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2017.05.04 16:55:22 | 000,960,960 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2017.05.04 16:55:22 | 000,911,992 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2017.05.04 16:55:22 | 000,821,184 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvDecMFTMjpeg.dll
[2017.05.04 16:55:22 | 000,776,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2017.05.04 16:55:22 | 000,688,968 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvfatbinaryLoader.dll
[2017.05.04 16:55:22 | 000,651,200 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvDecMFTMjpeg.dll
[2017.05.04 16:55:22 | 000,618,744 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmcumd.dll
[2017.05.04 16:55:22 | 000,612,088 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2017.05.04 16:55:22 | 000,609,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2017.05.04 16:55:22 | 000,577,728 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll
[2017.05.04 16:55:22 | 000,499,320 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2017.05.03 15:58:44 | 000,513,144 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2017.05.03 15:57:29 | 001,988,216 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6438189.dll
[2017.05.03 15:57:29 | 001,589,880 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6438189.dll
[2017.05.03 15:44:27 | 000,153,536 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvaudcap64v.dll
[2017.05.03 15:44:27 | 000,127,424 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvaudcap32v.dll
[2017.05.01 23:58:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\VS Revo Group
[2017.05.01 23:58:12 | 000,040,240 | ---- | C] (VS Revo Group) -- C:\WINDOWS\SysNative\drivers\revoflt.sys
[2017.05.01 23:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2017.05.01 23:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2017.05.01 23:58:11 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2017.04.28 17:23:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign13981d18137ad82a
[2017.04.28 16:48:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignbdd2a2d86ef77dc1
[2017.04.28 16:48:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign930ee542570c4560
[2017.04.27 22:40:50 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb477b0518b676774
[2017.04.27 22:40:50 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign629bea0186baaed8
[2017.04.27 22:40:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf7aae8e80bdac187
[2017.04.27 22:40:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne328759f20e9e618
[2017.04.27 22:36:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb4d8d7dfb50fead1
[2017.04.27 22:36:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign2470776e10a697bd
[2017.04.27 22:36:10 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign640f53b6124855d8
[2017.04.27 22:36:10 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign137e2625931c94b4
[2017.04.27 22:36:00 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigneea7c8172ba8c408
[2017.04.27 22:36:00 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignda27637ba242b7e7
[2017.04.27 22:35:39 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigna0b2640d105c1997
[2017.04.27 22:35:39 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign04d866d89c22db72
[2017.04.27 16:59:40 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign00f83501a9ebf265
[2017.04.27 16:59:02 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign3746836e43f90599
[2017.04.27 16:58:42 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne9f5ade61b66f630
[2017.04.27 16:58:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncfd0645bed94c498
[2017.04.27 16:58:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigna2bf50ef94e72e7a
[2017.04.26 03:08:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2017.04.25 14:10:17 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\dvdcss
[2017.04.25 14:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2017.04.25 14:09:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2017.04.25 14:09:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2017.04.25 14:09:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\5kplayer
[2017.04.25 14:09:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DearMob
[2017.04.25 14:09:47 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\5kplayer
[2017.04.25 14:01:33 | 000,000,000 | ---D | C] -- C:\Users\winki\Documents\Aviosoft
[2017.04.24 23:54:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignfee4c261cdd90e2e
[2017.04.24 23:54:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign891c6abbabb52a27
[2017.04.24 23:54:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0d01e7714212ed5c
[2017.04.24 21:39:13 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2017.04.24 18:57:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigndec9157c8ddb3c70
[2017.04.24 18:57:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign448df59b5f76dffa
[2017.04.24 11:41:05 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign5e1d5d87412024d4
[2017.04.24 11:40:57 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd986c4682bcf93c8
[2017.04.24 11:40:57 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign66d86ea17898ae97
[2017.04.24 11:22:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign5bccc938cf585fe4
[2017.04.24 11:22:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign08ab7d9c25864558
[2017.04.24 10:56:54 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncceb35b134d8de5e
[2017.04.24 10:56:54 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign6a3dc533d0e3c0ff
[2017.04.24 05:18:35 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc496fc0564cab0a8
[2017.04.24 05:18:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignac0ea24355f7192b
[2017.04.24 05:18:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign5d06880071bd8ad6
[2017.04.24 05:00:03 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignda266668d7b8db79
[2017.04.24 04:59:38 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4ce5d0075f3766c6
[2017.04.24 04:59:19 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignad948fdaf72bf569
[2017.04.24 04:59:19 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign333541d2930c31cb
[2017.04.24 04:19:02 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne64e082df04d9341
[2017.04.24 04:19:02 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd801b3974ef1cb4b
[2017.04.24 04:19:02 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign7475f65b71538a7a
[2017.04.24 04:15:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb57228b8f3004e4e
[2017.04.24 04:15:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign311e91a97408ee74
[2017.04.24 04:07:55 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign64aa6402f28e6e8d
[2017.04.24 04:07:55 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign498add4d41bcda50
[2017.04.24 04:07:33 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign38b4bd3b46b5d81f
[2017.04.24 04:07:33 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign275877caef5e8766
[2017.04.24 03:50:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign1dda067de6628e85
[2017.04.24 03:30:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncdadaec9e7f51e3b
[2017.04.24 03:06:44 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignfaeaaf948012a30e
[2017.04.24 03:04:02 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign333c7fa001bac9d5
[2017.04.24 02:23:57 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign82dd7206540bfd3c
[2017.04.23 23:54:32 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign46eceefee4470e67
[2017.04.23 23:54:31 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9942de3af9eb2130
[2017.04.23 23:45:45 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign6d101089f4cc8b94
[2017.04.23 23:45:01 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign52e2f2d40e4c0908
[2017.04.23 23:45:01 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4b90c8cdb952de3d
[2017.04.23 20:01:54 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z
[2017.04.23 20:01:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GPU-Z
[2017.04.23 15:22:01 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncf56e2eee65cb2c9
[2017.04.23 15:22:01 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignbad00783bea2dde5
[2017.04.23 15:22:01 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign16cbbd27226fe929
[2017.04.23 02:37:22 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0ab62dd1e375a428
[2017.04.23 02:37:19 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne3b2119bcff5c433
[2017.04.23 02:37:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne62fbaf5a5f40115
[2017.04.23 02:37:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigna246eaa2058bf1e1
[2017.04.23 02:36:52 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf3a532af00cb3956
[2017.04.23 02:36:46 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne5cbcbc3e1bb543d
[2017.04.23 02:36:43 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc9005e14120a9f0c
[2017.04.23 02:36:43 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign12d1c5d8fa10327a
[2017.04.23 02:35:52 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd3dff5d72ef39bbc
[2017.04.23 02:35:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9291e4f86535c88c
[2017.04.23 02:35:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignbc41ad696c26644f
[2017.04.23 02:35:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign44dd9d6d197ba8ff
[2017.04.22 22:57:42 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd48750f8e8549bfe
[2017.04.22 22:57:42 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign89f83eaa392c0995
[2017.04.22 22:57:41 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign7a7c209d2207d618
[2017.04.22 22:57:17 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9d45355b486acd78
[2017.04.22 22:57:17 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign824904fd146d31a9
[2017.04.22 22:57:17 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign591ed7bb8db19d33
[2017.04.22 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf90a3280a254b021
[2017.04.22 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd353e40b6cbdbce1
[2017.04.22 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign8255e721b8e77cdf
[2017.04.22 21:41:45 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignaf718082d82d8a9f
[2017.04.22 21:41:45 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign8458e4b819312128
[2017.04.22 21:41:45 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign23a11b0ba32b1939
[2017.04.22 21:41:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf2e1d2320fd8f556
[2017.04.22 21:41:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc5c8cd0e33744dd3
[2017.04.22 21:30:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AdobeInstalledCodecs
[2017.04.22 21:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2017.04.21 22:44:38 | 000,000,000 | ---D | C] -- C:\MoTemp
[2017.04.21 22:44:38 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Imagineer Systems Ltd
[2017.04.21 20:28:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc5be1eead629af95
[2017.04.21 20:28:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignbba20e9b82512859
[2017.04.21 20:28:23 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign49c80d80bafd90d6
[2017.04.21 15:25:22 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb12a8c45ef3f4b01
[2017.04.21 15:25:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign2d975f9cf007b893
[2017.04.21 15:25:09 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign522270e676141beb
[2017.04.21 15:25:09 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4c52d376daed448e
[2017.04.21 15:24:28 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign6812311677203235
[2017.04.21 15:24:28 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign5805bba2237c74e9
[2017.04.21 15:24:28 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign29d404fdaf31a2a0
[2017.04.21 14:51:08 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign208f876a10d07a1d
[2017.04.21 14:49:12 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign629403745e711471
[2017.04.21 14:49:10 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign8b348f91448a41d4
[2017.04.21 14:49:09 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb1656f7ad9f612f7
[2017.04.21 13:48:58 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb97d4194a3ed4c3c
[2017.04.21 13:48:58 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign468dca8834f72326
[2017.04.21 13:47:55 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigna2d9937729a5a39c
[2017.04.21 13:47:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9047687bf044ce0e
[2017.04.21 13:47:48 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign25f9600bf808083c
[2017.04.21 12:41:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd807bd61a50c28df
[2017.04.21 12:41:50 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb3f12187ce23f6f8
[2017.04.20 22:04:25 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9de081fc80c494ae
[2017.04.20 22:03:22 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4e9fa8c89d7f86c1
[2017.04.20 22:03:20 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4c12072d772b4621
[2017.04.20 22:03:20 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign02e44ccec66e3d19
[2017.04.20 21:55:37 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncbc428d28be02e87
[2017.04.20 21:55:35 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4314bda28723a783
[2017.04.20 21:55:33 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne6b4f9619889007e
[2017.04.20 21:55:33 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignadaa36fb6f8d6dc6
[2017.04.20 18:43:12 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign2e5f6f6123f590d4
[2017.04.20 18:43:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignce25c2fd5c80f19c
[2017.04.20 18:43:08 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb128eea8632100a7
[2017.04.20 18:43:08 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9d317ee1ee6c9cd8
[2017.04.20 18:41:38 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne64b443c38284b1a
[2017.04.20 18:41:38 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigndefc08432c2e71fe
[2017.04.20 18:41:38 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9db4187beddac3f1
[2017.04.20 18:40:49 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignfe0ee341a910adfd
[2017.04.20 18:40:49 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign65a30d191a42e1a6
[2017.04.20 18:40:49 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0c816b4efca6a6cf
[2017.04.20 18:40:29 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigned8abf1ae9542c61
[2017.04.20 18:40:29 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign9c017fc6c452aab2
[2017.04.20 18:40:29 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0c0eb275b67e7acd
[2017.04.20 18:39:52 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd962f4e55c2db9e5
[2017.04.20 18:39:52 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignaeda5862e1dc322d
[2017.04.20 18:39:52 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign3ef31e5d87d1f4d3
[2017.04.20 11:28:57 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\DBG
[2017.04.19 13:01:53 | 000,000,000 | ---D | C] -- C:\Windows.old
[2017.04.19 13:01:45 | 001,506,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\quartz.dll
[2017.04.19 13:01:45 | 001,060,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsPrint.dll
[2017.04.19 13:01:45 | 000,364,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msIso.dll
[2017.04.19 13:01:45 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsDocumentTargetPrint.dll
[2017.04.19 13:01:45 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserDataTimeUtil.dll
[2017.04.19 13:01:43 | 001,760,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsCodecs.dll
[2017.04.19 13:01:43 | 001,657,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2017.04.19 13:01:43 | 001,605,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\quartz.dll
[2017.04.19 13:01:43 | 001,147,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2017.04.19 13:01:43 | 001,024,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2017.04.19 13:01:43 | 000,750,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2017.04.19 13:01:43 | 000,626,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2017.04.19 13:01:43 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2017.04.19 13:01:43 | 000,433,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msIso.dll
[2017.04.19 13:01:43 | 000,409,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2017.04.19 13:01:43 | 000,382,368 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2017.04.19 13:01:43 | 000,354,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2017.04.19 13:01:43 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsDocumentTargetPrint.dll
[2017.04.19 13:01:43 | 000,311,192 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2017.04.19 13:01:43 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserDataTimeUtil.dll
[2017.04.19 13:01:43 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmjpegdec.dll
[2017.04.19 13:01:43 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmjpegdec.dll
[2017.04.19 13:01:43 | 000,047,104 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2017.04.19 13:01:43 | 000,038,912 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2017.04.19 13:01:13 | 006,348,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NlsData0009.dll
[2017.04.19 13:01:13 | 005,739,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\prm0009.dll
[2017.04.19 13:01:13 | 002,629,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NlsLexicons0009.dll
[2017.04.19 13:00:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceProfiles
[2017.04.19 13:00:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Microsoft
[2017.04.19 12:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2017.04.19 12:30:56 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2017.04.19 12:11:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2017.04.19 12:10:20 | 000,000,000 | ---D | C] -- C:\ProgramData\USOShared
[2017.04.19 12:05:39 | 002,233,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2017.04.19 12:04:11 | 000,000,000 | --SD | C] -- C:\Users\winki\AppData\Roaming\Microsoft
[2017.04.19 12:04:11 | 000,000,000 | R--D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2017.04.19 12:04:11 | 000,000,000 | R--D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2017.04.19 12:04:11 | 000,000,000 | R--D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2017.04.19 12:04:11 | 000,000,000 | R--D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\AppData\Local\Temporary Internet Files
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Šablony
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Soubory cookie
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\SendTo
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Poslední
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Okolní tiskárny
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Okolní síť
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Documents\Obrázky
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Nabídka Start
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Local Settings
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Documents\Hudba
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\AppData\Local\History
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Documents\Filmy
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Dokumenty
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\Data aplikací
[2017.04.19 12:04:11 | 000,000,000 | -HSD | C] -- C:\Users\winki\AppData\Local\Data aplikací
[2017.04.19 12:04:11 | 000,000,000 | -H-D | C] -- C:\Users\winki\AppData
[2017.04.19 12:04:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Temp
[2017.04.19 12:04:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Microsoft
[2017.04.19 12:04:11 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2017.04.19 12:04:01 | 006,437,312 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcpl.dll
[2017.04.19 12:04:01 | 002,479,552 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvc64.dll
[2017.04.19 12:04:01 | 001,762,752 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvcr.dll
[2017.04.19 12:04:01 | 000,548,800 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshext.dll
[2017.04.19 12:04:01 | 000,392,312 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmctray.dll
[2017.04.19 12:04:01 | 000,081,856 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshextr.dll
[2017.04.19 12:04:01 | 000,069,752 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvshext.dll
[2017.04.19 12:03:58 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2017.04.19 12:03:57 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Uninstall Information
[2017.04.19 12:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2017.04.19 12:03:53 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2017.04.19 12:03:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2017.04.19 12:03:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2017.04.19 12:03:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2017.04.18 20:23:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc2d169af56cbf558
[2017.04.18 20:23:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign6ab506a96f84c28e
[2017.04.18 20:23:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign4816c8bf468a7909
[2017.04.18 20:18:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign6ec04166cdd5e691
[2017.04.18 20:18:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign259bf4cb1dd3fdd9
[2017.04.18 20:18:15 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign0c90ede3db4b4084
[2017.04.18 20:09:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignc9c80737b4f9d051
[2017.04.18 20:09:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign63f5cf114822e2f4
[2017.04.18 20:09:07 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign1f9f5565fd0529b5
[2017.04.18 20:06:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignf1d33b5aca431f07
[2017.04.18 20:06:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigncadf06b14089cd35
[2017.04.18 20:06:27 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign7c31f272761f197f
[2017.04.18 20:01:43 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignfe596db5ac613b43
[2017.04.18 20:01:43 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignd4d987a035dfb32d
[2017.04.18 20:01:43 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignb31188562d8bf4b3
[2017.04.18 19:50:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigne1470ea06c35c143
[2017.04.18 19:50:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsignbbbe53647dc84f07
[2017.04.18 19:50:26 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign3be68492feccd027
[2017.04.18 19:49:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsigndddd5eee344b2a9e
[2017.04.18 19:49:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign828904dd41f72875
[2017.04.18 19:49:51 | 000,000,000 | ---D | C] -- C:\Users\winki\AppData\Local\Tempzxpsign282f30c4ecab02aa
[2017.04.17 15:18:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2017.04.15 12:34:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2017.04.15 12:34:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes