Stránka 3 z 6

Re: Virus - trojský kůň

Napsal: 13 lis 2015 11:58
od Márty84
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Virus - trojský kůň

Napsal: 13 lis 2015 14:18
od P-e-tula
OTL logfile created on: 13.11.2015 12:40:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18098)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,89 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 34,73% Memory free
6,26 Gb Paging File | 3,13 Gb Available in Paging File | 50,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 423,30 Gb Total Space | 301,55 Gb Free Space | 71,24% Space Free | Partition Type: NTFS
Drive D: | 25,00 Gb Total Space | 22,60 Gb Free Space | 90,39% Space Free | Partition Type: NTFS

Computer Name: LENOVO-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2015.11.13 12:39:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
PRC - [2015.11.07 05:36:36 | 000,811,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015.10.21 11:36:16 | 000,349,968 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
PRC - [2015.10.21 11:36:06 | 000,060,688 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2015.10.21 11:35:30 | 000,103,696 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
PRC - [2015.10.13 04:46:06 | 000,060,688 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2015.10.01 21:23:07 | 000,270,848 | ---- | M] (www.logos.cz) -- C:\Program Files (x86)\eLiska4\eLiska.exe
PRC - [2015.10.01 14:54:18 | 000,245,576 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
PRC - [2015.06.26 04:24:08 | 000,851,752 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
PRC - [2014.10.29 02:05:25 | 000,315,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2014.08.12 07:07:57 | 000,154,896 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
PRC - [2014.08.12 07:07:57 | 000,153,872 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
PRC - [2014.08.12 06:59:32 | 000,294,672 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
PRC - [2014.08.12 06:59:32 | 000,109,328 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
PRC - [2014.05.22 02:29:04 | 000,584,960 | ---- | M] (LENOVO INCORPORATED.) -- C:\Program Files\Lenovo\iMController\SystemAgentService.exe
PRC - [2014.03.06 19:40:28 | 001,150,024 | ---- | M] (Lenovo(beijing) Limited) -- C:\Program Files (x86)\Lenovo\Lenovo Updates\LU.exe
PRC - [2014.02.26 05:50:24 | 000,323,584 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2014.02.26 04:13:00 | 000,053,248 | ---- | M] () -- C:\Windows\SysWOW64\UMonit64.exe
PRC - [2014.02.18 05:47:34 | 000,038,896 | ---- | M] (Lenovo(beijing) Limited) -- C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
PRC - [2013.10.10 00:08:04 | 000,381,440 | -H-- | M] () -- C:\Model\cmssservice\cmssservice.exe
PRC - [2013.08.27 06:50:36 | 000,175,016 | -H-- | M] (Oracle Corporation) -- C:\Model\java\bin\java.exe


========== Modules (No Company Name) ==========

MOD - [2015.11.07 05:36:33 | 001,532,744 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
MOD - [2015.11.07 05:36:32 | 000,081,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll
MOD - [2015.10.13 04:46:12 | 001,040,144 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2015.10.13 04:45:48 | 000,237,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
MOD - [2015.05.15 15:27:10 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014.08.12 07:07:57 | 000,101,648 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
MOD - [2014.08.12 06:59:32 | 000,294,672 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
MOD - [2014.08.12 06:59:32 | 000,109,328 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
MOD - [2014.08.12 06:59:32 | 000,105,744 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
MOD - [2014.08.12 06:59:32 | 000,102,160 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
MOD - [2014.02.26 04:13:00 | 000,053,248 | ---- | M] () -- C:\Windows\SysWOW64\UMonit64.exe
MOD - [2013.10.10 00:08:04 | 000,381,440 | -H-- | M] () -- C:\Model\cmssservice\cmssservice.exe
MOD - [2013.09.04 23:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF


========== Services (SafeList) ==========

SRV:64bit: - [2015.07.22 14:52:08 | 001,633,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2015.07.16 19:58:34 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2015.07.07 10:39:32 | 000,366,552 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2015.07.07 10:39:32 | 000,023,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2015.05.30 20:36:24 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2015.05.12 14:19:37 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2015.05.07 16:21:51 | 000,522,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2015.02.21 00:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014.10.31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014.10.29 04:59:51 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014.10.29 03:42:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2014.10.29 03:42:03 | 000,041,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2014.10.29 03:34:51 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2014.10.29 03:33:55 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2014.10.29 03:29:22 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2014.10.29 02:57:05 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:64bit: - [2014.10.29 02:48:20 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2014.10.29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2014.10.29 02:27:21 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2014.10.29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014.10.29 02:24:37 | 000,131,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2014.10.29 02:22:40 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2014.10.29 02:20:03 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2014.10.29 02:19:20 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2014.10.29 02:16:17 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2014.10.29 02:13:24 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014.10.29 02:13:02 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2014.10.29 02:12:36 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014.10.29 02:12:22 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014.10.29 02:11:10 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014.10.29 02:05:09 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2014.10.29 01:48:52 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2014.10.29 01:46:48 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014.10.29 01:35:51 | 001,668,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2014.08.12 07:15:40 | 000,198,192 | ---- | M] (Lenovo(beijing) Limited) [Auto | Running] -- C:\Windows\SysNative\LenovoWiFiHotspotSvr.exe -- (LenovoWiFiHotspotSvr)
SRV:64bit: - [2014.08.12 07:13:15 | 000,104,696 | ---- | M] (Lenovo) [On_Demand | Stopped] -- c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe -- (TESHelper)
SRV:64bit: - [2014.08.12 07:08:32 | 000,308,720 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe -- (PhoneCompanionVap)
SRV:64bit: - [2014.08.12 07:08:32 | 000,288,240 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe -- (PhoneCompanionPusher)
SRV:64bit: - [2014.05.22 02:29:04 | 000,584,960 | ---- | M] (LENOVO INCORPORATED.) [Auto | Running] -- C:\Program Files\Lenovo\iMController\SystemAgentService.exe -- (Lenovo System Agent Service)
SRV:64bit: - [2014.03.12 02:16:02 | 000,282,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
SRV:64bit: - [2013.08.22 13:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2013.07.02 04:08:48 | 000,822,232 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe -- (Intel(R)
SRV:64bit: - [2013.07.02 04:08:32 | 000,733,696 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2012.04.24 11:43:50 | 000,390,632 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV - [2015.10.05 09:48:46 | 001,135,416 | ---- | M] (Malwarebytes) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2015.05.07 16:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2015.03.29 23:54:24 | 062,382,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\sqlservr.exe -- (MSSQL$ELISKA4CLIENT)
SRV - [2015.03.29 23:53:36 | 000,442,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\SQLAGENT.EXE -- (SQLAgent$ELISKA4CLIENT)
SRV - [2014.10.29 02:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2014.10.29 02:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2014.08.12 07:07:57 | 000,070,416 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe -- (LsvUIService)
SRV - [2014.08.12 06:59:32 | 000,033,040 | ---- | M] (Lenovo) [Auto | Running] -- C:\ProgramData\LenovoTransition\Server\x64\ymc.exe -- (ymc)
SRV - [2014.03.12 02:16:06 | 000,279,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2014.02.26 06:17:38 | 000,319,104 | ---- | M] (Windows (R) Win 7 DDK provider) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2014.02.26 05:50:24 | 000,323,584 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt and Wlan Coex Agent)
SRV - [2014.02.18 05:47:34 | 000,038,896 | ---- | M] (Lenovo(beijing) Limited) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe -- (LUService)
SRV - [2014.01.10 02:27:52 | 000,019,440 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe -- (LenovoRecommends.AppService)
SRV - [2013.08.22 13:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.04.24 22:37:56 | 000,169,752 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2015.10.05 09:50:22 | 000,064,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2015.10.05 09:50:06 | 000,025,816 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2015.09.29 13:24:42 | 000,155,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2015.07.07 10:40:12 | 000,044,560 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2015.07.07 10:40:05 | 000,270,168 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2015.07.07 10:40:05 | 000,114,520 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2015.06.10 22:08:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2015.04.16 07:17:07 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2015.03.29 23:53:16 | 000,322,736 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0153.sys -- (RsFx0153)
DRV:64bit: - [2015.03.20 02:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2015.03.17 18:26:06 | 000,467,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2015.03.13 05:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2015.03.09 03:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2015.03.04 11:25:11 | 000,377,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014.11.10 19:06:59 | 000,136,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014.10.29 04:59:47 | 000,415,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014.10.29 04:57:42 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014.10.29 04:56:04 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014.10.29 03:46:43 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2014.10.29 03:46:09 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2014.10.29 03:45:54 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2014.10.29 03:45:39 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2014.10.29 03:45:16 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2014.10.15 09:32:36 | 000,921,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014.10.13 03:43:17 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2014.10.13 03:43:17 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2014.10.07 07:54:45 | 000,189,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014.10.07 07:44:39 | 000,069,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2014.08.15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014.08.12 07:16:41 | 000,035,576 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2014.04.17 09:38:36 | 000,111,336 | ---- | M] (GenesysLogic) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GeneStor.sys -- (GeneStor)
DRV:64bit: - [2014.03.18 10:54:54 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2014.03.18 10:54:43 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2014.03.18 10:54:42 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:64bit: - [2014.03.18 10:54:42 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014.03.18 10:54:42 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2014.03.18 10:54:42 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014.03.18 10:38:02 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014.03.13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\windows\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014.03.07 17:26:44 | 000,450,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2014.03.07 17:18:24 | 003,729,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2014.03.07 06:53:16 | 003,892,224 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athwbx.sys -- (athr)
DRV:64bit: - [2014.03.01 21:32:31 | 000,038,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2014.03.01 21:32:31 | 000,027,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2014.02.26 05:53:02 | 000,598,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2014.02.26 05:53:02 | 000,355,528 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2014.02.26 05:53:02 | 000,179,432 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2014.02.26 05:53:02 | 000,137,928 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2014.02.26 05:53:02 | 000,118,984 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2014.02.26 05:53:02 | 000,089,800 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2014.02.26 05:53:02 | 000,077,464 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2014.02.26 05:53:02 | 000,035,016 | ---- | M] (Qualcomm Atheros) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2014.02.25 08:55:48 | 000,532,720 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2014.02.25 08:55:46 | 000,034,544 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:64bit: - [2014.01.21 12:10:06 | 009,105,624 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvc.sys -- (rtsuvc)
DRV:64bit: - [2014.01.15 22:21:46 | 000,088,592 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TXEIx64.sys -- (TXEIx64)
DRV:64bit: - [2013.12.18 04:35:22 | 000,839,896 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2013.08.22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013.08.22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013.08.22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013.08.22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013.08.22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013.08.22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013.08.22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013.08.22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013.08.22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013.08.22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013.08.22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013.08.22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013.08.22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013.08.22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013.08.22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013.08.22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013.08.22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013.08.22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013.08.22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013.08.22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013.08.22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013.08.22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013.08.22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013.08.22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013.08.22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013.08.22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013.08.22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013.08.22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013.08.22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013.08.22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013.08.22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013.08.22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013.08.22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013.08.22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013.08.22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013.08.22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013.08.22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013.08.22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013.08.22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013.08.22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013.08.22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013.08.22 12:36:31 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BTHPRINT.SYS -- (BTHprint)
DRV:64bit: - [2013.08.22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013.08.22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013.08.13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013.08.10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013.07.30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013.07.25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013.06.18 15:45:43 | 004,649,440 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NETwew02.sys -- (NETwNe64)
DRV:64bit: - [2013.06.18 15:45:26 | 000,460,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\e1i63x64.sys -- (e1iexpress)
DRV:64bit: - [2013.04.10 21:19:19 | 000,251,128 | ---- | M] (Pismo Technic Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pfmfs_853.sys -- (pfmfs_853)
DRV:64bit: - [2012.06.14 01:10:32 | 000,102,376 | ---- | M] ("CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {1A699E11-5CDA-4037-861D-7A23910CAF09}
IE:64bit: - HKLM\..\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}: "URL" = http://www.bing.com/search?q={searchTer ... TR&pc=LCJB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {1A699E11-5CDA-4037-861D-7A23910CAF09}
IE - HKLM\..\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}: "URL" = http://www.bing.com/search?q={searchTer ... TR&pc=LCJB


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-789525210-3307182626-2393355962-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-789525210-3307182626-2393355962-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)



========== Chrome ==========

CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah\1.4.20_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_1\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

O1 HOSTS File: ([2015.11.12 17:57:58 | 000,000,035 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O2:64bit: - BHO: (ClassicIEBHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O2 - BHO: (ClassicIEBHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AutoStartTransition] C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe ()
O4:64bit: - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
O4:64bit: - HKLM..\Run: [Energy Manager] C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [Lenovo Utility] C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [PhoneCompanion] C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe (Lenovo)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVBg_LENOVO_MICPKEY] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtsFT] C:\windows\RTFTrack.exe (Realtek semiconductor)
O4 - HKLM..\Run: [Lenovo Recommends] C:\Program Files (x86)\Lenovo\Lenovo Recommends\Lenovo Recommends.exe (Lenovo)
O4 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple Inc.)
O4 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe (Apple Inc.)
O4 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" (Qualcomm®Atheros®)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O9:64bit: - Extra 'Tools' menuitem : Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe (IvoSoft)
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe (IvoSoft)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001\..Trusted Domains: csobpoj.cz ([app2] https in Trusted sites)
O15 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001\..Trusted Domains: http://127.0.0.1 ([]* in Trusted sites)
O15 - HKU\S-1-5-21-789525210-3307182626-2393355962-1001\..Trusted Domains: http://localhost ([]* in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9CE42EDD-626A-4BE9-B5A7-038A7B2EA4E1}: DhcpNameServer = 172.168.130.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C29E1424-C679-425D-844F-C8D9D838B717}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\windows\SysWow64\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\windows\SysWow64\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lame - C:\windows\SysWow64\lame.ax ()
Drivers32: msacm.scg726 - C:\windows\SysWow64\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\windows\SysWow64\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\windows\SysWow64\mcdvd_32.dll (MainConcept)
Drivers32: vidc.LAGS - C:\windows\SysWow64\Lagarith.dll ( )
Drivers32: vidc.mp42 - C:\windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mp43 - C:\windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mpg4 - C:\windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.VP60 - C:\windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP62 - C:\windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\windows\SysWow64\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2015.11.13 12:39:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2015.11.13 08:52:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CMSSModel
[2015.11.13 08:52:43 | 000,000,000 | -H-D | C] -- C:\Model
[2015.11.12 19:25:00 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2015.11.12 19:19:30 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015.11.12 19:14:32 | 004,532,776 | ---- | C] (Piriform Ltd) -- C:\Users\User\Desktop\dfsetup219.exe
[2015.11.12 19:14:12 | 006,762,072 | ---- | C] (Piriform Ltd) -- C:\Users\User\Desktop\ccsetup511.exe
[2015.11.11 15:53:56 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Viry
[2015.11.11 05:41:46 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\lsasrv.dll
[2015.11.11 05:41:45 | 000,397,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\bcryptprimitives.dll
[2015.11.11 05:41:45 | 000,137,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncrypt.dll
[2015.11.11 05:41:45 | 000,106,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncryptsslp.dll
[2015.11.11 05:41:45 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ncryptsslp.dll
[2015.11.11 05:41:44 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\certcli.dll
[2015.11.11 05:41:44 | 000,340,872 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\bcryptprimitives.dll
[2015.11.11 05:41:43 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\certcli.dll
[2015.11.11 05:41:26 | 000,183,368 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\AuthHost.exe
[2015.11.11 05:41:25 | 007,455,064 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe
[2015.11.11 05:41:25 | 001,659,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winload.efi
[2015.11.11 05:41:25 | 001,519,592 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winload.exe
[2015.11.11 05:41:25 | 001,487,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winresume.efi
[2015.11.11 05:41:25 | 001,355,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winresume.exe
[2015.11.11 05:41:22 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe
[2015.11.11 05:41:21 | 002,243,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll
[2015.11.11 05:41:21 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapi.dll
[2015.11.11 05:41:21 | 000,721,920 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wuapi.dll
[2015.11.11 05:41:21 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WUSettingsProvider.dll
[2015.11.11 05:41:21 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll
[2015.11.11 05:41:21 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wuwebv.dll
[2015.11.11 05:41:21 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wudriver.dll
[2015.11.11 05:41:21 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wudriver.dll
[2015.11.11 05:41:21 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe
[2015.11.11 05:41:21 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wuapp.exe
[2015.11.11 05:41:17 | 000,558,080 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\untfs.dll
[2015.11.11 05:41:17 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\untfs.dll
[2015.11.11 05:41:16 | 001,091,584 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\localspl.dll
[2015.11.11 05:41:15 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\puiobj.dll
[2015.11.11 05:41:15 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\puiobj.dll
[2015.11.11 05:41:15 | 000,155,480 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\tpm.sys
[2015.11.11 05:41:14 | 001,380,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\gdi32.dll
[2015.11.11 05:41:03 | 005,990,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2015.11.11 05:41:02 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2015.11.11 05:41:02 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2015.11.11 05:41:01 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2015.11.11 05:41:01 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2015.11.11 05:41:01 | 000,585,728 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll
[2015.11.11 05:41:00 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dll
[2015.11.11 05:41:00 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dll
[2015.11.11 05:40:52 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\nshwfp.dll
[2015.11.11 05:40:52 | 000,561,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\nshwfp.dll
[2015.11.11 05:40:52 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\FWPUCLNT.DLL
[2015.11.11 05:40:52 | 000,272,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\FWPUCLNT.DLL
[2015.11.11 05:40:52 | 000,136,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\wfplwfs.sys
[2015.11.10 21:09:06 | 000,192,216 | ---- | C] (Malwarebytes) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.11.10 21:08:38 | 000,109,272 | ---- | C] (Malwarebytes) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2015.11.10 21:08:38 | 000,064,216 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mwac.sys
[2015.11.10 21:08:38 | 000,025,816 | ---- | C] (Malwarebytes) -- C:\windows\SysNative\drivers\mbam.sys
[2015.11.10 21:08:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2015.11.10 21:08:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015.11.10 19:56:28 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2015.11.10 13:07:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2015.11.10 13:07:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2015.11.10 13:07:19 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2015.11.10 11:06:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2015.11.09 21:53:18 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\AVG
[2015.11.09 21:51:38 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2015.11.09 21:51:14 | 000,000,000 | -H-D | C] -- C:\$AVG
[2015.11.09 21:49:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\MFAData
[2015.11.09 21:49:19 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2015.11.09 21:48:07 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2015.11.09 21:48:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg
[2015.11.09 21:46:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\AvgSetupLog
[2015.11.09 21:46:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Avg
[2015.11.09 21:31:27 | 000,000,000 | ---D | C] -- C:\ProgramData\STOPzilla!
[2015.11.09 21:31:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iS3
[2015.11.06 19:13:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\IsolatedStorage
[2015.11.06 18:35:08 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\ČSOB_Pojišťovna,_a.s
[2015.10.30 10:41:58 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iCloud
[2015.10.30 10:41:46 | 000,000,000 | R--D | C] -- C:\Users\User\iCloudDrive
[2015.10.30 10:41:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Apple Inc
[2015.10.30 10:41:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\5D1F9447-A25A-434E-B17E-7C045F50AEB7.aplzod
[2015.10.30 10:32:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2015.10.27 12:06:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Unity
[2015.10.24 10:35:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2015.10.24 10:34:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2015.10.24 10:34:10 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2015.10.24 10:34:07 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2015.10.22 16:08:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2015.10.22 14:36:10 | 000,000,000 | R--D | C] -- C:\Users\User\AppData\Roaming\Brother
[2015.10.16 14:20:56 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Renča
[2015.10.15 14:57:21 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\appraiser.dll
[2015.10.15 14:57:21 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\devinv.dll
[2015.10.15 14:57:20 | 000,699,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\invagent.dll
[2015.10.15 14:57:19 | 001,163,776 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\aeinv.dll
[2015.10.15 14:57:19 | 000,766,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\generaltel.dll
[2015.10.15 14:57:18 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\acmigration.dll
[2015.10.15 14:57:18 | 000,035,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\CompatTelRunner.exe
[2015.10.15 12:54:43 | 001,354,240 | ---- | C] (CANON INC.) -- C:\windows\SysNative\CNC495C.dll
[2015.10.15 12:54:43 | 000,348,672 | ---- | C] (CANON INC.) -- C:\windows\SysNative\CNC495L.dll
[2015.10.15 12:54:43 | 000,307,200 | ---- | C] (CANON INC.) -- C:\windows\SysWow64\CNC495L.dll
[2015.10.15 12:54:43 | 000,112,128 | ---- | C] (CANON INC.) -- C:\windows\SysNative\CNC495I.dll
[2015.10.15 12:54:43 | 000,106,496 | ---- | C] (CANON INC.) -- C:\windows\SysWow64\CNC495U.dll
[2015.10.15 12:54:43 | 000,017,920 | ---- | C] (CANON INC.) -- C:\windows\SysNative\CNHMCA6.dll
[2015.10.15 12:54:43 | 000,015,872 | ---- | C] (CANON INC.) -- C:\windows\SysWow64\CNHMCA.dll
[2015.10.15 12:54:36 | 000,361,472 | ---- | C] (CANON INC.) -- C:\windows\SysNative\CNMLMA9.DLL
[2015.10.14 13:44:30 | 004,710,400 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d2d1.dll
[2015.10.14 13:42:51 | 001,134,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\KernelBase.dll
[2015.10.14 13:42:21 | 000,686,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\advapi32.dll
[2015.10.14 13:40:57 | 000,669,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\hhctrl.ocx
[2015.10.14 13:40:54 | 000,536,576 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\hhctrl.ocx
[2015.10.14 13:39:58 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\NcdAutoSetup.dll
[2015.10.14 13:39:58 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2015.10.14 13:39:58 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2015.10.14 13:39:58 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2015.10.14 13:39:57 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2015.10.14 13:39:57 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2015.10.14 13:39:57 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2015.10.14 13:39:57 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2015.10.14 13:39:57 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2015.10.14 13:39:57 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2015.10.14 13:39:57 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2015.10.14 13:39:57 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2015.10.14 13:39:57 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2015.10.14 13:39:56 | 000,066,400 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2015.10.14 13:39:56 | 000,063,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2015.10.14 13:39:56 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2015.10.14 13:39:56 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2015.10.14 13:39:56 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2015.10.14 13:39:56 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2015.10.14 13:39:54 | 000,901,264 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ucrtbase.dll
[2015.10.14 13:39:50 | 000,984,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ucrtbase.dll
[2015.10.14 13:39:50 | 000,022,368 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2015.10.14 13:39:50 | 000,020,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2015.10.14 13:39:50 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2015.10.14 13:39:50 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2015.10.14 13:39:50 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2015.10.14 13:39:50 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2015.10.14 13:39:50 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2015.10.14 13:39:50 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2015.10.14 13:39:50 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2015.10.14 13:39:50 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2015.10.14 13:39:49 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2015.10.14 13:39:44 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2015.11.13 12:46:40 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015.11.13 12:39:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2015.11.13 11:23:01 | 000,004,489 | ---- | M] () -- C:\Users\User\Desktop\Bez názvu.png
[2015.11.13 11:18:35 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2015.11.13 11:14:19 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015.11.13 11:14:18 | 3338,219,520 | -HS- | M] () -- C:\hiberfil.sys
[2015.11.13 09:38:20 | 000,120,981 | ---- | M] () -- C:\Users\User\Desktop\Bez názvrewu.png
[2015.11.13 08:52:58 | 000,000,791 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\cmssservice.lnk
[2015.11.13 08:52:58 | 000,000,166 | ---- | M] () -- C:\Users\Public\Desktop\ČMSSModel.url
[2015.11.12 19:23:52 | 000,208,780 | ---- | M] () -- C:\Users\User\Documents\cc_20151112_192311.reg
[2015.11.12 19:15:59 | 004,532,776 | ---- | M] (Piriform Ltd) -- C:\Users\User\Desktop\dfsetup219.exe
[2015.11.12 19:15:18 | 006,762,072 | ---- | M] (Piriform Ltd) -- C:\Users\User\Desktop\ccsetup511.exe
[2015.11.12 17:57:58 | 000,000,035 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2015.11.12 16:07:32 | 000,805,266 | ---- | M] () -- C:\windows\SysNative\perfh005.dat
[2015.11.12 16:07:32 | 000,787,818 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2015.11.12 16:07:32 | 000,160,264 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2015.11.12 16:07:31 | 001,929,746 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2015.11.12 16:07:31 | 000,176,282 | ---- | M] () -- C:\windows\SysNative\perfc005.dat
[2015.11.11 21:13:23 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.11.11 21:08:07 | 000,491,704 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2015.11.03 01:23:06 | 000,810,488 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe
[2015.11.03 01:23:06 | 000,176,632 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2015.10.31 00:24:50 | 000,585,728 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll
[2015.10.31 00:11:51 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2015.10.31 00:11:46 | 005,990,912 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2015.10.30 23:36:24 | 000,663,552 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2015.10.30 23:32:13 | 000,720,896 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2015.10.30 23:31:26 | 000,801,280 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2015.10.30 22:53:01 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ieapfltr.dll
[2015.10.30 22:46:02 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dll
[2015.10.22 14:59:58 | 000,000,423 | ---- | M] () -- C:\windows\BRWMARK.INI
[2015.10.20 22:54:41 | 000,136,904 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe
[2015.10.20 15:36:47 | 002,243,072 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll
[2015.10.20 15:35:00 | 000,891,904 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuapi.dll
[2015.10.20 15:34:36 | 000,409,088 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\WUSettingsProvider.dll
[2015.10.20 15:34:00 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll
[2015.10.20 15:34:00 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe
[2015.10.20 15:33:59 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\wudriver.dll
[2015.10.20 15:14:07 | 000,721,920 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\wuapi.dll
[2015.10.20 15:13:13 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\wuwebv.dll
[2015.10.20 15:13:13 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\wudriver.dll
[2015.10.20 15:13:13 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\wuapp.exe
[2015.10.15 00:02:56 | 001,659,560 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\winload.efi
[2015.10.15 00:02:56 | 001,519,592 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\winload.exe
[2015.10.15 00:02:56 | 001,487,008 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\winresume.efi
[2015.10.15 00:02:56 | 001,355,848 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\winresume.exe
[2015.10.15 00:02:40 | 007,455,064 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2015.11.13 12:46:40 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015.11.13 11:23:01 | 000,004,489 | ---- | C] () -- C:\Users\User\Desktop\Bez názvu.png
[2015.11.13 09:37:11 | 000,120,981 | ---- | C] () -- C:\Users\User\Desktop\Bez názvrewu.png
[2015.11.13 08:52:58 | 000,000,791 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\cmssservice.lnk
[2015.11.13 08:52:58 | 000,000,166 | ---- | C] () -- C:\Users\Public\Desktop\ČMSSModel.url
[2015.11.12 19:23:30 | 000,208,780 | ---- | C] () -- C:\Users\User\Documents\cc_20151112_192311.reg
[2015.11.11 05:41:47 | 000,414,559 | ---- | C] () -- C:\windows\SysNative\ApnDatabase.xml
[2015.11.10 10:46:50 | 000,000,283 | ---- | C] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
[2015.10.15 12:54:43 | 000,012,800 | ---- | C] () -- C:\windows\SysWow64\CNC1747D.TBL
[2015.10.11 11:01:40 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\Lagarith.dll
[2015.10.11 11:01:38 | 000,524,288 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2015.10.11 11:01:38 | 000,139,264 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2015.10.02 08:11:13 | 000,000,423 | ---- | C] () -- C:\windows\BRWMARK.INI
[2015.10.02 08:11:13 | 000,000,034 | ---- | C] () -- C:\windows\SysWow64\BD2030.DAT
[2015.10.01 20:20:21 | 000,107,008 | ---- | C] () -- C:\windows\SysWow64\OEMLicense.dll
[2015.10.01 20:16:15 | 000,046,080 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2015.10.01 15:03:32 | 000,000,161 | ---- | C] () -- C:\windows\AutoKMS.ini
[2014.08.12 06:56:49 | 000,001,137 | ---- | C] () -- C:\windows\PEIS_PreloadData.ini
[2014.08.12 06:14:43 | 000,172,097 | ---- | C] () -- C:\windows\SysWow64\NoMSGuninstall.exe
[2014.08.12 06:14:43 | 000,053,248 | ---- | C] () -- C:\windows\SysWow64\UMonit64.exe
[2014.08.12 06:14:43 | 000,001,519 | ---- | C] () -- C:\windows\SysWow64\_IconCfg0.ini
[2014.08.12 06:14:43 | 000,000,973 | ---- | C] () -- C:\windows\SysWow64\ProductName.ini
[2014.08.12 06:14:43 | 000,000,184 | ---- | C] () -- C:\windows\SysWow64\IconCfg0.ini
[2014.08.12 06:14:32 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014.08.11 13:44:49 | 000,068,608 | ---- | C] () -- C:\windows\SysWow64\igfxexps32.dll
[2014.08.11 13:44:43 | 000,342,944 | ---- | C] () -- C:\windows\SysWow64\igdmd32.dll
[2014.08.11 13:44:37 | 000,183,296 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2014.08.11 13:44:37 | 000,142,848 | ---- | C] () -- C:\windows\SysWow64\igdail32.dll
[2014.03.18 10:55:08 | 000,002,255 | ---- | C] () -- C:\windows\SysWow64\WimBootCompress.ini

========== ZeroAccess Check ==========

[2015.10.01 15:38:15 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.08.27 03:43:09 | 022,372,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.08.27 03:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014.10.29 02:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014.10.29 01:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014.10.29 02:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2015.10.02 10:33:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\(C0-1A-DA-42-40-91)
[2015.11.09 21:53:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG
[2015.10.01 15:24:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ClassicShell
[2015.10.11 10:18:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoft
[2015.10.11 11:02:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FlashIntegro
[2015.09.21 10:46:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Hightail for Lenovo
[2015.10.01 15:29:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Praguesoft s.r.o
[2015.10.02 08:19:57 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TeamViewer
[2015.11.09 21:51:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2015.10.02 14:22:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Wargaming.net

========== Purity Check ==========



========== Custom Scans ==========

< >
[2013.08.22 15:45:54 | 000,000,006 | -H-- | C] () -- C:\windows\Tasks\SA.DAT

< >

< MD5 for: AGP440.SYS >
[2013.08.22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\windows\SysNative\drivers\AGP440.sys
[2013.08.22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013.08.22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2015.10.06 08:39:36 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys

< MD5 for: ATAPI.SYS >
[2013.08.22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\windows\SysNative\drivers\atapi.sys
[2013.08.22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013.08.22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2014.03.18 10:55:08 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014.03.18 10:55:08 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014.03.18 10:54:53 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\windows\SysNative\autochk.exe
[2014.03.18 10:54:53 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe

< MD5 for: CDROM.SYS >
[2013.08.22 09:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\windows\SysNative\drivers\cdrom.sys
[2013.08.22 09:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_42e9c29f0affc440\cdrom.sys
[2013.08.22 09:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_5067bbed77be70be\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2015.10.06 08:52:52 | 000,018,016 | ---- | M] () MD5=14E1348B6D5DD39C23C2F8FE569B52E0 -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.16384_none_66bdf96f6ec6545d\cryptsvc.dll
[2014.10.29 02:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\windows\SysNative\cryptsvc.dll
[2014.10.29 02:27:24 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=6324F0D18FB52833BA64BC828E29054C -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.17415_none_670a944b6e8cc0e5\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2010.03.13 07:47:22 | 000,006,440 | ---- | M] () MD5=ACD301711FC165ED77A8D364D407BAF9 -- C:\Program Files\CyberLink\PowerDirector10\EventLog.dll

< MD5 for: EXPLORER.EXE >
[2015.10.06 09:13:11 | 000,406,329 | ---- | M] () MD5=025BA45EB718AE0DE32895BE9F020387 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2015.10.06 12:50:12 | 000,346,045 | ---- | M] () MD5=04070828E1AE13385991A06123A9F287 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2015.10.06 09:13:17 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2015.10.06 09:13:04 | 000,406,497 | ---- | M] () MD5=1F499FDDEBB43C93D9C844D81ACC755C -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2015.10.06 12:50:23 | 000,345,923 | ---- | M] () MD5=2C862CE86A0FA1E02E1518B5E20FC35E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2015.10.06 12:50:33 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2015.01.28 00:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015.01.28 00:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2015.01.28 00:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015.01.28 00:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe

< MD5 for: HAL.DLL >
[2014.06.02 03:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\windows\SysNative\hal.dll
[2014.06.02 03:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17196_none_9bde68c32da7abbb\hal.dll
[2015.10.06 09:17:43 | 000,024,467 | ---- | M] () MD5=2635F50EAF3E1B4A8D32B21E1203E130 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17031_none_9c1a44f32d7b883b\hal.dll

< MD5 for: IASTORV.SYS >
[2013.08.22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\windows\SysNative\drivers\iaStorV.sys
[2013.08.22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013.08.22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2013.08.22 13:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\windows\SysNative\drivers\isapnp.sys
[2013.08.22 13:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\isapnp.sys
[2013.08.22 13:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\isapnp.sys
[2015.10.06 08:39:37 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\isapnp.sys

< MD5 for: LSASS.EXE >
[2014.10.29 04:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\windows\SysNative\lsass.exe
[2014.10.29 04:51:48 | 000,047,024 | ---- | M] (Microsoft Corporation) MD5=382100E75B6F4668AEAEF228C6CEFFAD -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.17415_none_2e769c84660bda1b\lsass.exe
[2015.10.06 09:46:14 | 000,008,089 | ---- | M] () MD5=3FFB8CD649DEDA6497FD97550BE82357 -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.16408_none_2e8484166600f08e\lsass.exe

< MD5 for: NDIS.SYS >
[2015.10.06 10:03:50 | 000,165,519 | ---- | M] () MD5=07CE116810C119B65E9DEFA34E50C00D -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys
[2015.07.14 22:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\windows\SysNative\drivers\ndis.sys
[2015.07.14 22:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17933_none_4a48e22dfbdb75b0\ndis.sys
[2015.10.06 10:03:53 | 000,083,281 | ---- | M] () MD5=E47216FC1C4FCA5C1A9E3BBB79EA37FD -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys

< MD5 for: NETLOGON.DLL >
[2014.10.29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\windows\SysNative\netlogon.dll
[2014.10.29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2015.10.06 10:20:26 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015.10.06 13:17:40 | 000,104,557 | ---- | M] () MD5=8203890854F74B5ACB9E8920EE24C826 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2015.10.06 13:17:43 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2015.10.06 10:20:24 | 000,123,829 | ---- | M] () MD5=C5EFDD0CD180E1CEB92294BF4B7F07A1 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll
[2014.10.29 02:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014.10.29 02:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll

< MD5 for: NVRAID.SYS >
[2013.08.22 13:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\windows\SysNative\drivers\nvraid.sys
[2013.08.22 13:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvraid.sys
[2013.08.22 13:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2013.08.22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\windows\SysNative\drivers\nvstor.sys
[2013.08.22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013.08.22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys

< MD5 for: SCECLI.DLL >
[2015.10.06 13:15:55 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015.10.06 10:18:39 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014.10.29 02:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\windows\SysNative\scecli.dll
[2014.10.29 02:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014.10.29 02:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014.10.29 02:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll

< MD5 for: SMSS.EXE >
[2014.03.18 10:54:43 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\windows\SysNative\smss.exe
[2014.03.18 10:54:43 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.17031_none_6f522891bc9cbe45\smss.exe

< MD5 for: SVCHOST.EXE >
[2015.10.06 14:30:58 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2015.10.06 10:20:44 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014.10.29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014.10.29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014.10.29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\windows\SysNative\svchost.exe
[2014.10.29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe
[2015.10.05 09:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe

< MD5 for: TCPIP.SYS >
[2014.04.03 08:59:18 | 002,518,872 | ---- | M] (Microsoft Corporation) MD5=4B666AE119D2ADBAC816BEA7DB4D6881 -- C:\Windows\SoftwareDistribution\Download\200d6be154b0c1b51536b68996f23a43\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17088_none_a3e0570b3a59cef2\tcpip.sys
[2015.10.06 10:47:36 | 000,288,350 | ---- | M] () MD5=5942F26DD54126E0D5D65D5EB834CC0B -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17415_none_a4290d393a23b3f2\tcpip.sys
[2015.10.06 10:47:15 | 000,483,332 | ---- | M] () MD5=59C36E883892CDA122493F39725AD498 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17085_none_a3dd562d3a5c82ed\tcpip.sys
[2015.10.06 10:46:50 | 000,526,770 | ---- | M] () MD5=61C0AF328195C83F6927193C91D8619B -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16521_none_a41a54d33a2f4e0d\tcpip.sys
[2015.06.11 21:12:57 | 002,476,376 | ---- | M] (Microsoft Corporation) MD5=746DDF7D59AB8D721C88D48434597E8D -- C:\windows\SysNative\drivers\tcpip.sys
[2015.06.11 21:12:57 | 002,476,376 | ---- | M] (Microsoft Corporation) MD5=746DDF7D59AB8D721C88D48434597E8D -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17903_none_a431e60f3a1d5716\tcpip.sys
[2015.10.06 10:47:05 | 000,483,044 | ---- | M] () MD5=9DA504195BE369DC6EA78F636FA30667 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17039_none_a41766f13a305c94\tcpip.sys
[2015.10.06 10:47:26 | 000,481,946 | ---- | M] () MD5=EA334A4CD901A652B2A6F5FA401103B3 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17136_none_a41467f93a330db6\tcpip.sys

< MD5 for: USERINIT.EXE >
[2015.10.06 10:56:08 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015.10.06 14:39:42 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014.10.29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\windows\SysNative\userinit.exe
[2014.10.29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014.10.29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014.10.29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe

< MD5 for: WINLOGON.EXE >
[2015.10.06 11:04:08 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2015.10.05 09:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2014.10.29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\windows\SysNative\winlogon.exe
[2014.10.29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe

Re: Virus - trojský kůň

Napsal: 13 lis 2015 14:18
od P-e-tula
< MD5 for: WS2_32.DLL >
[2014.10.29 04:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014.10.29 04:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014.10.29 04:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\windows\SysNative\ws2_32.dll
[2014.10.29 04:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015.10.06 15:45:10 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015.10.06 10:58:11 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\windows\Panther\*.tmp files -> C:\windows\Panther\*.tmp -> ]
[1 C:\windows\Temp\*.tmp files -> C:\windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2015.10.02 10:33:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\(C0-1A-DA-42-40-91)
[2015.10.01 16:58:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Adobe
[2015.10.30 10:42:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Apple Computer
[2015.09.21 19:03:57 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Atheros
[2015.11.09 21:53:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG
[2015.10.22 14:36:10 | 000,000,000 | R--D | M] -- C:\Users\User\AppData\Roaming\Brother
[2015.10.01 15:24:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ClassicShell
[2015.10.11 10:18:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoft
[2015.10.11 11:02:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FlashIntegro
[2015.09.21 10:46:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Hightail for Lenovo
[2015.10.01 15:05:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Identities
[2015.10.04 16:59:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Macromedia
[2015.11.12 19:22:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Media Player Classic
[2015.11.10 15:13:22 | 000,000,000 | --SD | M] -- C:\Users\User\AppData\Roaming\Microsoft
[2015.10.01 15:29:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Praguesoft s.r.o
[2015.11.13 13:33:01 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Skype
[2015.10.02 08:19:57 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TeamViewer
[2015.11.09 21:51:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2015.11.11 15:51:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\vlc
[2015.10.02 14:22:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Wargaming.net
[2015.10.02 08:45:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Winamp
[2015.10.09 10:37:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2015.10.30 23:09:39 | 012,854,272 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\ieframe.dll
[2014.10.29 01:58:05 | 000,306,688 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\oleacc.dll
[2015.08.27 03:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\shell32.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >
[2015.10.30 23:09:39 | 012,854,272 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\ieframe.dll
[2014.10.29 01:58:05 | 000,306,688 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\oleacc.dll
[2015.08.27 03:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\windows\system32\shell32.dll

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"iCloudServices" = C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe -- [2015.10.21 11:36:06 | 000,060,688 | ---- | M] (Apple Inc.)
"iCloudDrive" = C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe -- [2015.10.21 11:35:30 | 000,103,696 | ---- | M] (Apple Inc.)
"iCloudPhotos" = C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe -- [2015.10.21 11:36:16 | 000,349,968 | ---- | M] (Apple Inc.)
"RESTART_STICKY_NOTES" = C:\Windows\System32\StikyNot.exe
"CCleaner Monitoring" = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR -- [2015.10.19 21:58:42 | 008,551,848 | ---- | M] (Piriform Ltd)

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2015.11.13 12:46:40 | 000,000,512 | ---- | M] () MD5=74523BDBF890553669A3AB7E179A04EB -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2015.08.26 14:25:57 | 000,213,184 | ---- | M] () -- \Games\World_of_Tanks\res\audio\objects_ice_crack.fsb
[2015.10.09 10:35:05 | 000,001,442 | ---- | M] () -- \Users\User\Documents\WinRAR 3.93 pln verze CZ x86 a x64 + CRACK.lnk

< *keygen* /s >

< *AntiWPA* /s >

< *loader* /s >
[2015.08.26 14:25:57 | 000,071,208 | ---- | M] () -- \Games\World_of_Tanks\PhysXLoader.dll
[2015.08.26 14:25:57 | 000,009,971 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\app_loader\loader.pyc
[2015.08.26 14:25:57 | 000,001,512 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\eulaversionloader.pyc
[2015.08.26 14:25:57 | 000,002,209 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\graphicspresetsloader.pyc
[2015.08.26 14:25:57 | 000,007,130 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\guicolorsloader.pyc
[2015.11.02 16:34:21 | 000,003,955 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\guisoundsloader.pyc
[2015.08.26 14:25:57 | 000,006,314 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\logindataloader.pyc
[2015.08.26 14:25:57 | 000,002,753 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\doc_loaders\windowsstoreddataloader.pyc
[2015.08.26 14:25:57 | 000,001,519 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\scaleform\framework\entities\abstract\loadermanagermeta.pyc
[2015.08.26 14:25:57 | 000,006,157 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\scaleform\framework\managers\loaders.pyc
[2015.08.26 14:25:57 | 000,011,861 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\shared\remotedatadownloader.pyc
[2015.08.26 14:25:57 | 000,003,419 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\helpers\rssdownloader.pyc
[2015.08.26 14:25:57 | 000,010,919 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\tutorial\loader.pyc
[2015.08.26 14:25:57 | 000,011,336 | ---- | M] () -- \Games\World_of_Tanks\res_bw\scripts\common\lib\unittest\loader.pyc
[2015.08.26 14:25:57 | 000,049,402 | ---- | M] () -- \Games\World_of_Tanks\res_bw\scripts\common\lib\unittest\test\test_loader.pyc
[2013.02.12 22:45:38 | 000,020,625 | -H-- | M] () -- \Model\apache_tomcat\webapps\docs\class-loader-howto.html
[2013.02.12 22:45:38 | 000,016,659 | -H-- | M] () -- \Model\apache_tomcat\webapps\docs\config\loader.html
[2015.10.13 04:46:20 | 000,060,688 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\YSLoader.exe
[2015.10.21 11:35:48 | 000,060,688 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
[2015.10.21 11:35:48 | 001,514,256 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader_main.dll
[2014.09.02 23:27:24 | 000,268,432 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2014.09.02 23:27:24 | 000,019,096 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2010.04.03 18:57:02 | 000,024,416 | ---- | M] () -- \Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\SqlResourceLoader.dll
[2015.07.11 02:48:08 | 000,001,003 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_about.fen
[2015.07.11 02:48:08 | 000,000,686 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_advoptions.fen
[2015.07.11 02:48:08 | 000,001,044 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_confirm.fen
[2015.07.11 02:48:08 | 000,000,765 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_debug.fen
[2015.07.11 02:48:08 | 000,001,330 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_download.fen
[2015.07.11 02:48:08 | 000,003,021 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_filestatus.fen
[2015.07.11 02:48:08 | 000,000,677 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_file_errors.fen
[2015.07.11 02:48:08 | 000,000,943 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_instructions.fen
[2015.07.11 02:48:08 | 000,002,522 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_manage_devices.fen
[2015.07.11 02:48:08 | 000,002,182 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_onboard.fen
[2015.07.11 02:48:08 | 000,002,682 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_pinwheel_72.png
[2015.07.11 02:48:08 | 000,004,464 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_pinwheel_72x2.png
[2015.07.11 02:48:08 | 000,003,010 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_prefs.fen
[2015.07.11 02:48:08 | 000,001,095 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_quota_error1.fen
[2015.07.11 02:48:08 | 000,001,089 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_quota_error2.fen
[2015.07.11 02:48:08 | 000,002,119 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_storage_notify.fen
[2015.07.11 02:48:08 | 000,001,970 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_welcome.fen
[2010.04.03 19:47:24 | 000,016,736 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2015.10.13 04:45:46 | 000,077,072 | ---- | M] () -- \Program Files\Common Files\Apple\Apple Application Support\YSLoader.exe
[2014.09.02 23:27:24 | 000,364,176 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2014.09.02 23:27:24 | 000,019,096 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2012.04.09 03:20:36 | 003,324,200 | ---- | M] () -- \Program Files\CyberLink\Shared files\Plugin\8.0\CES_3DLoaderFBX.dll
[2015.10.01 18:44:32 | 000,000,105 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Setup Bootstrap\Log\20151001_193305\Datastore\_Extension_Agent_SqlResourceLoaderPath.xml
[2015.10.03 10:07:48 | 000,000,105 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Setup Bootstrap\Log\20151003_110139\ELISKA4CLIENT\Datastore\_Extension_Agent_SqlResourceLoaderPath.xml
[2010.04.03 18:57:02 | 000,024,416 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2013.10.23 18:47:16 | 000,020,192 | ---- | M] () -- \Program Files\WindowsApps\CyberLinkCorp.id.PhotoTouch_1.0.2204.0_x64__hgg5mn3xps74a\js\fileWorker\cacheLoader.js
[2013.01.29 22:26:52 | 000,001,080 | ---- | M] () -- \Program Files\WindowsApps\FilmOnLiveTVFree.FilmOnLiveTVFree_1.3.6.87_x64__zx03kxexxb716\js\preloader.js
[2014.08.12 06:39:40 | 000,000,856 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe\js\HtmlFileLoader.js
[2014.03.18 10:40:18 | 000,001,160 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\modernpeople\appframe\backgroundloader.js
[2014.03.18 10:40:18 | 000,004,996 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\modernshareanything\sharedataloader.js
[2014.03.18 10:40:18 | 000,002,125 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\modernsharetarget\sharemaildataloader.js
[2014.08.12 06:48:45 | 000,001,160 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\modernpeople\appframe\backgroundloader.js
[2014.08.12 06:48:55 | 000,004,996 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\modernshareanything\sharedataloader.js
[2014.08.12 06:48:56 | 000,002,125 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\modernsharetarget\sharemaildataloader.js
[2014.03.18 10:42:32 | 000,043,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2010.03.15 10:27:20 | 000,054,784 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2014.01.17 17:07:06 | 000,004,613 | ---- | M] () -- \Users\Default\AppData\Local\Pokki\Engine\frames\frame\loader.gif
[2014.01.17 17:07:06 | 000,006,888 | ---- | M] () -- \Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\images\loader-2x.gif
[2014.01.17 17:07:06 | 000,004,613 | ---- | M] () -- \Users\Default\AppData\Local\Pokki\Pokkies\f22abfeae27a67446927d078890381efc546d3e1\images\loader.gif
[2015.11.13 11:22:07 | 000,019,121 | ---- | M] () -- \Users\User\AppData\Local\Microsoft\Windows\INetCache\IE\24HA0H0T\AdLoader-288a31a04e1398b1a794975bf93ce9a4.min[1].js
[2015.11.13 11:22:07 | 000,001,980 | ---- | M] () -- \Users\User\AppData\Local\Microsoft\Windows\INetCache\IE\KOBWU48W\AdLoader[1].htm
[2015.11.13 11:21:40 | 000,021,956 | ---- | M] () -- \Users\User\AppData\Local\Microsoft\Windows\INetCache\IE\OJ62NQ2P\loader_30fps[1].gif
[2015.10.06 20:43:56 | 000,072,638 | ---- | M] () -- \Users\User\AppData\Local\Skype\Apps\login\images\loader.gif
[2015.10.06 20:43:56 | 000,003,032 | ---- | M] () -- \Users\User\AppData\Local\Skype\Apps\login\images\loader.png
[2015.10.06 20:43:56 | 000,006,012 | ---- | M] () -- \Users\User\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2015.10.06 20:43:56 | 000,021,956 | ---- | M] () -- \Users\User\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2015.10.06 20:43:56 | 000,009,772 | ---- | M] () -- \Users\User\AppData\Local\Skype\Apps\login\images\retina\loader@2x.png
[2015.11.09 21:28:06 | 002,042,328 | ---- | M] () -- \Users\User\Downloads\STOPzillaPRO_Downloader.exe
[2010.03.24 19:35:48 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.03.24 19:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.03.24 19:35:48 | 000,370,512 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.03.24 19:12:34 | 000,249,680 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.03.24 19:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2015.11.09 21:28:20 | 000,056,640 | ---- | M] () -- \Windows\Prefetch\STOPZILLAPRO_DOWNLOADER.EXE-D78A78AB.pf
[2013.08.22 05:17:27 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 05:17:25 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 05:17:24 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-2-0.dll
[2013.08.22 05:17:20 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013.08.22 05:17:34 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-stringloader-l1-1-0.dll
[2013.08.22 05:17:33 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-stringloader-l1-1-1.dll
[2014.10.29 02:51:40 | 000,041,472 | ---- | M] () -- \Windows\System32\dmloader.dll
[2013.08.22 14:25:39 | 000,003,584 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 14:25:39 | 000,003,072 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 14:25:38 | 000,002,560 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-stringloader-l1-1-1.dll
[2013.08.22 05:17:27 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 05:17:25 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 05:17:24 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-2-0.dll
[2013.08.22 05:17:20 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013.08.22 05:17:34 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-stringloader-l1-1-0.dll
[2013.08.22 05:17:33 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-stringloader-l1-1-1.dll
[2014.10.29 02:51:40 | 000,041,472 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2013.08.22 14:25:39 | 000,003,584 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 14:25:39 | 000,003,072 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 14:25:38 | 000,002,560 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-stringloader-l1-1-1.dll
[2015.10.06 08:39:56 | 000,592,677 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.16384_none_210fb36c397c4e2b\hvloader.efi
[2015.10.06 08:39:54 | 000,536,051 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.16384_none_210fb36c397c4e2b\hvloader.exe
[2014.03.18 11:16:56 | 000,598,463 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17031_none_2142a5b03956989d\hvloader.efi
[2014.03.18 11:16:55 | 000,542,292 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17031_none_2142a5b03956989d\hvloader.exe
[2015.10.06 08:40:07 | 000,598,454 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17039_none_214aa800394f6355\hvloader.efi
[2015.10.06 08:40:05 | 000,542,288 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17039_none_214aa800394f6355\hvloader.exe
[2015.10.06 08:47:11 | 000,010,089 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.16384_none_36b27bfc6399d5ce\dmloader.dll
[2014.10.29 03:34:00 | 000,050,688 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.17415_none_36ff16d863604256\dmloader.dll
[2013.08.22 14:25:37 | 000,003,584 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 14:25:37 | 000,003,072 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 14:25:36 | 000,002,560 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-stringloader-l1-1-1.dll
[2013.08.22 12:45:31 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 12:45:33 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 12:45:35 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-2-0.dll
[2013.08.22 12:45:30 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013.08.22 12:45:40 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-stringloader-l1-1-0.dll
[2013.08.22 12:45:44 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-stringloader-l1-1-1.dll
[2014.08.12 06:14:26 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb.manifest
[2015.10.06 16:14:49 | 000,009,588 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winload.efi.mui_35ee487d
[2015.10.06 16:14:49 | 000,009,604 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winload.exe.mui_3bc5b827
[2015.10.06 16:14:49 | 000,007,885 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winresume.efi.mui_f412814e
[2015.10.06 16:14:49 | 000,007,900 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winresume.exe.mui_ff8b5358
[2014.03.18 10:56:19 | 000,000,462 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759.manifest
[2014.03.18 11:19:15 | 000,009,321 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759_winload.efi.mui_35ee487d
[2014.03.18 11:19:15 | 000,009,332 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759_winload.exe.mui_3bc5b827
[2014.03.18 11:19:15 | 000,007,774 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759_winresume.efi.mui_f412814e
[2014.03.18 11:19:15 | 000,007,774 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759_winresume.exe.mui_ff8b5358
[2015.11.11 09:19:44 | 000,000,584 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e.manifest
[2015.11.11 09:19:44 | 001,659,560 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e_winload.efi_75834aa0
[2015.11.11 09:19:44 | 001,519,592 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e_winload.exe_75835076
[2015.11.11 09:19:44 | 001,487,008 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e_winresume.efi_85cd069f
[2015.11.11 09:19:44 | 001,355,848 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e_winresume.exe_85cd1215
[2015.10.01 23:15:33 | 000,000,616 | ---- | M] () -- \Windows\WinSxS\FileMaps\programdata_microsoft_diagnosis_asimovuploader_0413bca0c3dfdda4.cdf-ms
[2013.08.22 16:34:52 | 000,000,596 | ---- | M] () -- \Windows\WinSxS\FileMaps\programdata_microsoft_network_downloader_7fafaef6d33e4371.cdf-ms
[2014.08.12 06:09:54 | 000,000,463 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_2400ceb4d1008089.manifest
[2014.03.18 10:24:50 | 000,000,459 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.16384_en-us_67571a10b7fadce7.manifest
[2014.08.12 06:14:04 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb.manifest
[2014.03.18 10:53:21 | 000,000,462 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_en-us_678a0c54b7d52759.manifest
[2013.08.22 16:22:38 | 000,000,542 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.16384_none_4be51a3d409de6bc.manifest
[2014.03.18 10:53:22 | 000,000,545 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17031_none_4c180c814078312e.manifest
[2015.10.01 15:38:55 | 000,000,547 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd.manifest
[2015.10.14 10:50:11 | 000,000,583 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18066_none_4bfc8767408c1d55.manifest
[2015.11.11 05:39:22 | 000,000,584 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18090_none_4bd615e740a9d91e.manifest
[2015.10.06 13:54:16 | 000,008,359 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.16384_none_da93e078ab3c6498\dmloader.dll
[2014.10.29 02:51:40 | 000,041,472 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.17415_none_dae07b54ab02d120\dmloader.dll
[2013.08.22 14:25:39 | 000,003,584 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 14:25:39 | 000,003,072 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 14:25:38 | 000,002,560 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-stringloader-l1-1-1.dll
[2013.08.22 05:17:27 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.08.22 05:17:25 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-1-1.dll
[2013.08.22 05:17:24 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-2-0.dll
[2013.08.22 05:17:20 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013.08.22 05:17:34 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-stringloader-l1-1-0.dll
[2013.08.22 05:17:33 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-stringloader-l1-1-1.dll

< *minodlogin* /s >

< *tnod* /s >
[2015.05.15 15:27:06 | 000,001,655 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\WebInspectorUI\Images\DOMTextNode.svg
[2015.05.15 15:26:44 | 000,001,655 | ---- | M] () -- \Program Files\Common Files\Apple\Apple Application Support\WebKit.resources\WebInspectorUI\Images\DOMTextNode.svg

< *AutoKMS* /s >
[2015.10.01 15:03:32 | 000,000,161 | ---- | M] () -- \Windows\AutoKMS.ini
[2 \Windows\*.tmp files -> \Windows\*.tmp -> ]

< *activator* /s >

< *serial* /s >
[2015.08.26 14:25:57 | 000,005,999 | ---- | M] () -- \Games\World_of_Tanks\res\scripts\client\gui\shared\gui_items\serializers.pyc
[2015.04.16 14:12:58 | 000,188,993 | ---- | M] () -- \Model\apache_tomcat\webapps\CMSSModel\WEB-INF\lib\serializer-2.7.0.jar
[2015.10.01 18:46:57 | 000,016,384 | ---- | M] () -- \Program Files (x86)\eLiska4\Logos.Runtime.Serialization.dll
[2015.10.01 18:46:57 | 000,016,384 | ---- | M] () -- \Program Files (x86)\eLiska4\Logos.Runtime.Serialization.SoapSerializator.dll
[2015.10.01 18:46:53 | 000,028,672 | ---- | M] () -- \Program Files (x86)\eLiska4\Logos.Xml.Serialization.dll
[2 \Program Files (x86)\eLiska4\*.tmp files -> \Program Files (x86)\eLiska4\*.tmp -> ]
[2014.07.09 02:45:06 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2013.05.22 04:02:56 | 000,125,816 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize.dll
[2013.05.22 04:03:38 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_cs.dll
[2013.05.22 04:03:40 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_da.dll
[2013.05.22 04:03:04 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_de.dll
[2013.05.22 04:03:00 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_en.dll
[2013.05.22 04:03:10 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_es.dll
[2013.05.22 04:03:34 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_fi.dll
[2013.05.22 04:03:02 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_fr.dll
[2013.05.22 04:03:44 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_hu.dll
[2013.05.22 04:03:14 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_it.dll
[2013.05.22 04:03:08 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_ja.dll
[2013.05.22 04:03:20 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_ko.dll
[2013.05.22 04:03:32 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_nb.dll
[2013.05.22 04:03:16 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_nl.dll
[2013.05.22 04:03:30 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_pl.dll
[2013.05.22 04:03:28 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_pt.dll
[2013.05.22 04:03:18 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_ru.dll
[2013.05.22 04:03:46 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_sk.dll
[2013.05.22 04:03:26 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_sv.dll
[2013.05.22 04:03:36 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_th.dll
[2013.05.22 04:03:48 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_tr.dll
[2013.05.22 04:03:12 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_zh_CN.dll
[2013.05.22 04:03:24 | 000,038,264 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxmlserialize_res_zh_TW.dll
[2013.05.22 04:02:56 | 000,372,600 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize.dll
[2013.05.22 04:03:38 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_cs.dll
[2013.05.22 04:03:42 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_da.dll
[2013.05.22 04:03:04 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_de.dll
[2013.05.22 04:03:00 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_en.dll
[2013.05.22 04:03:10 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_es.dll
[2013.05.22 04:03:34 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_fi.dll
[2013.05.22 04:03:02 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_fr.dll
[2013.05.22 04:03:44 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_hu.dll
[2013.05.22 04:03:14 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_it.dll
[2013.05.22 04:03:08 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_ja.dll
[2013.05.22 04:03:20 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_ko.dll
[2013.05.22 04:03:32 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_nb.dll
[2013.05.22 04:03:16 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_nl.dll
[2013.05.22 04:03:30 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_pl.dll
[2013.05.22 04:03:28 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_pt.dll
[2013.05.22 04:03:18 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_ru.dll
[2013.05.22 04:03:46 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_sk.dll
[2013.05.22 04:03:26 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_sv.dll
[2013.05.22 04:03:36 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_th.dll
[2013.05.22 04:03:48 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_tr.dll
[2013.05.22 04:03:12 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_zh_CN.dll
[2013.05.22 04:03:24 | 000,023,416 | ---- | M] () -- \Program Files (x86)\SAP BusinessObjects\Crystal Reports for .NET Framework 4.0\Common\SAP BusinessObjects Enterprise XI 4.0\win64_x64\saxserialize_res_zh_TW.dll
[2014.07.09 02:45:33 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2014.08.12 06:11:39 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2015.11.12 14:19:12 | 000,020,444 | ---- | M] () -- \Program Files\WindowsApps\AD2F1837.HPPrinterControl_55.1.43.0_x86__v10z8vjag6ke6\HP.Framework.Extensions.PrinterSettings\FaxSetupWizard\Views\SerialTypePhoneSystemPage.xbf
[2013.11.11 04:31:14 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2013.11.11 04:31:14 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2013.11.11 04:31:14 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2013.11.11 04:31:14 | 000,039,047 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2013.11.11 04:31:14 | 000,009,132 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Views\Pages\FindSerialNumberPage.xbf
[2013.11.11 04:31:14 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2013.11.11 04:31:14 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2013.11.11 04:31:14 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2013.11.11 04:31:14 | 000,027,531 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2013.11.11 04:31:14 | 000,012,181 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Views\Pages\SerialNumberCheck.xbf
[2014.06.10 06:37:54 | 000,003,470 | ---- | M] () -- \Program Files\WindowsApps\YouSendIt.HighTailForLenovo_1.3.0.1278_neutral__069rkrpjefrbc\YouSendIt.Support.WinRT\SerializationConfig.xml
[2015.05.21 08:12:23 | 183,568,384 | ---- | M] () -- \Users\User\Videos\Přátelé CZ\S09\Pratele.09x20.Serialovy.vecirek.avi
[2015.10.01 18:28:48 | 000,015,872 | ---- | M] () -- \Windows\assembly\GAC_64\CrystalDecisions.ReportAppServer.XmlSerialize\13.0.2000.0__692fbea5521e1304\CrystalDecisions.ReportAppServer.XmlSerialize.dll
[2015.10.03 10:06:36 | 000,073,384 | ---- | M] () -- \Windows\assembly\GAC_MSIL\Microsoft.SqlServer.Management.DacSerialization\10.0.0.0__89845dcd8080cc91\Microsoft.SqlServer.Management.DacSerialization.dll
[2014.08.12 06:11:39 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.23 23:12:42 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2014.08.12 06:11:39 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2014.07.09 02:45:06 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2015.10.03 10:08:14 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\5d1fbce671d894ebd0aec32f1d9c2072\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2015.10.03 10:11:31 | 000,396,288 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\6a2440fc7faa6508b9e9a7b0c5c93926\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2015.11.11 13:55:41 | 002,803,200 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll
[2015.11.11 13:55:41 | 000,000,980 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll.aux
[2015.11.11 13:22:14 | 003,529,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\769339283c5376245c011d81ce725abd\System.Runtime.Serialization.ni.dll
[2015.11.11 13:22:14 | 000,000,980 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\769339283c5376245c011d81ce725abd\System.Runtime.Serialization.ni.dll.aux
[2013.08.22 16:32:39 | 000,001,032 | ---- | M] () -- \Windows\Inf\c_multiportserial.inf
[2015.10.01 18:39:21 | 000,072,648 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\EED07F63FBE17074FA2A0E53EEEAAB1A\10.52.4000\MPU_Microsoft_SqlServer_Management_DacSerialization_dll_32
[2015.10.01 18:39:21 | 000,072,648 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\EED07F63FBE17074FA2A0E53EEEAAB1A\10.52.4000\MPU_Microsoft_SqlServer_Management_DacSerialization_dll_64
[2014.08.12 06:11:44 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.08.10 01:55:16 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.10 01:55:16 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Json\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Json.dll
[2013.08.10 01:55:16 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Primitives\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Primitives.dll
[2014.06.05 04:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2013.08.10 01:55:16 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Xml\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Xml.dll
[2014.07.24 04:20:32 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2013.08.10 01:55:49 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2013.08.10 01:55:49 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.XmlSerializer\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Xml.XmlSerializer.dll
[2014.06.23 23:12:42 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2014.08.12 06:11:39 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.07.09 02:45:07 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.24 04:20:32 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2013.08.10 01:55:16 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.10 01:55:16 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Json.dll
[2013.08.10 01:55:16 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2013.08.10 01:55:16 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2013.08.10 01:55:49 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2013.08.10 01:55:49 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.XmlSerializer.dll
[2014.08.12 06:11:44 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.05 04:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2014.06.23 23:12:50 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2014.08.12 06:11:37 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014.07.09 02:45:34 | 000,847,872 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014.07.24 04:20:21 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2013.08.10 01:41:27 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.10 01:41:27 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Json.dll
[2013.08.10 01:41:28 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2013.08.10 01:41:28 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2013.08.10 01:42:08 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
[2013.08.10 01:42:08 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.XmlSerializer.dll
[2014.08.12 06:11:41 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.06.05 04:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2013.08.22 22:12:22 | 000,008,827 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.cat
[2013.08.22 21:40:12 | 000,000,781 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.mum
[2013.08.22 14:08:06 | 000,008,830 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~en-US~6.3.9600.16384.cat
[2013.08.22 13:36:48 | 000,000,781 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~en-US~6.3.9600.16384.mum
[2013.08.22 13:55:01 | 000,008,827 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat
[2013.08.22 07:47:48 | 000,000,511 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.mum
[2014.10.29 02:46:05 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2013.08.22 22:12:22 | 000,008,827 | ---- | M] () -- \Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.cat
[2013.08.22 14:08:06 | 000,008,830 | ---- | M] () -- \Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~en-US~6.3.9600.16384.cat
[2013.08.22 13:55:01 | 000,008,827 | ---- | M] () -- \Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat
[2014.08.12 06:11:20 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2014.03.18 10:25:15 | 000,000,232 | ---- | M] () -- \Windows\System32\DriverStore\en-US\c_multiportserial.inf_loc
[2013.08.22 07:57:38 | 000,001,032 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\c_multiportserial.inf_amd64_7875073d426d59a6\c_multiportserial.inf
[2013.08.22 12:40:08 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_amd64_1be60ad3a61e5531\serial.sys
[2014.03.18 10:25:21 | 000,005,120 | ---- | M] () -- \Windows\System32\en-US\serialui.dll.mui
[2014.10.29 02:46:05 | 000,015,360 | ---- | M] () -- \Windows\SysWOW64\serialui.dll
[2014.08.12 06:11:20 | 000,005,120 | ---- | M] () -- \Windows\SysWOW64\cs-CZ\serialui.dll.mui
[2014.03.18 10:25:21 | 000,005,120 | ---- | M] () -- \Windows\SysWOW64\en-US\serialui.dll.mui
[2014.03.18 10:25:15 | 000,000,232 | ---- | M] () -- \Windows\WinSxS\amd64_c_multiportserial.inf.resources_31bf3856ad364e35_6.3.9600.16384_en-us_35eaebe6834354eb\c_multiportserial.inf_loc
[2013.08.22 07:57:38 | 000,001,032 | ---- | M] () -- \Windows\WinSxS\amd64_c_multiportserial.inf_31bf3856ad364e35_6.3.9600.16384_none_91b10a007e43beff\c_multiportserial.inf
[2015.10.06 10:00:38 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_b0eacafe7f4d1992\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014.08.12 06:11:37 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_b12d926c7f1ac114\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2015.10.06 10:00:41 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_b1ceee03982636a5\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014.08.12 06:11:20 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_3f29419cb7a1caf0\serialui.dll.mui
[2014.03.18 10:25:21 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_en-us_827f8cf89e9c274e\serialui.dll.mui
[2015.10.06 10:55:48 | 000,001,685 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.16384_none_e5c00198f2a1c32d\serialui.dll
[2014.10.29 03:27:06 | 000,017,920 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.17415_none_e60c9c74f2682fb5\serialui.dll
[2015.10.06 11:00:24 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_4e32729c2675dfcf\System.RunTime.Serialization.Resources.dll
[2014.08.12 06:11:39 | 000,090,112 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_4e753a0a26438751\System.RunTime.Serialization.Resources.dll
[2015.10.06 11:00:25 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_4f1695a13f4efce2\System.RunTime.Serialization.Resources.dll
[2014.08.12 06:11:11 | 000,009,728 | ---- | M] () -- \Windows\WinSxS\amd64_msports.inf.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_b574829120336a99\serial.sys.mui
[2014.03.18 10:25:15 | 000,010,240 | ---- | M] () -- \Windows\WinSxS\amd64_msports.inf.resources_31bf3856ad364e35_6.3.9600.16384_en-us_f8cacded072dc6f7\serial.sys.mui
[2013.08.22 12:40:08 | 000,083,456 | ---- | M] () -- \Windows\WinSxS\amd64_msports.inf_31bf3856ad364e35_6.3.9600.16384_none_e95610bc8c554aa7\serial.sys
[2015.10.06 11:22:59 | 000,003,691 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_1da5c476c59b0e5b\System.RunTime.Serialization.resources.dll
[2014.06.05 04:33:14 | 000,113,952 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.17238_cs-cz_1da069eec59ff302\System.RunTime.Serialization.resources.dll
[2015.10.06 11:22:59 | 000,003,304 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.20720_cs-cz_06d276aedf4770c6\System.RunTime.Serialization.resources.dll
[2013.08.10 01:41:27 | 000,142,104 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..ion.formatters.soap_b03f5f7f11d50a3a_4.0.9600.16384_none_f73c7de0bb1de286\System.Runtime.Serialization.Formatters.Soap.dll
[2013.08.10 01:41:28 | 000,029,432 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..lization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_64635c6af076b012\System.Runtime.Serialization.Primitives.dll
[2014.08.12 06:11:41 | 000,027,920 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..ters.soap.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_65f374ee29342685\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.08.10 01:41:27 | 000,029,392 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_031841e9b021a288\System.Runtime.Serialization.Json.dll
[2013.08.10 01:41:28 | 000,029,896 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_ea3019bcd508d7f5\System.Runtime.Serialization.Xml.dll
[2015.10.06 11:23:06 | 000,018,929 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_afcfdcce0af8e4ba\System.Runtime.Serialization.dll
[2014.07.24 04:20:21 | 001,059,536 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.17238_none_afca82460afdc961\System.Runtime.Serialization.dll
[2015.10.06 11:23:09 | 000,004,122 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.20720_none_98fc8f0624a54725\System.Runtime.Serialization.dll
[2013.08.10 01:42:08 | 000,045,720 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.xml.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_1f92ce7ac9b9f399\System.Xml.Serialization.dll
[2013.08.10 01:42:08 | 000,029,848 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_0b1c65bd7b1ef04c\System.Xml.XmlSerializer.dll
[2015.10.06 11:16:17 | 000,000,531 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.16384_none_f057a9271ce694b1\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.23 23:12:50 | 000,131,072 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.17226_none_f0517be51cec2cbf\System.Runtime.Serialization.Formatters.Soap.dll
[2015.10.06 11:16:18 | 000,000,491 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.20708_none_d981a48b36959176\System.Runtime.Serialization.Formatters.Soap.dll
[2015.10.06 11:32:53 | 000,000,643 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.16384_none_9fc99c9c7c4c05c7\System.Runtime.Serialization.dll
[2015.10.06 11:32:56 | 000,000,425 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17226_none_9fc36f5a7c519dd5\System.Runtime.Serialization.dll
[2014.07.09 02:45:34 | 000,847,872 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17231_none_9fc4e18c7c503707\System.Runtime.Serialization.dll
[2015.10.06 11:32:59 | 000,000,440 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20708_none_88f3980095fb028c\System.Runtime.Serialization.dll
[2015.10.06 11:33:01 | 000,000,619 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20717_none_88f4af1295fa0242\System.Runtime.Serialization.dll
[2015.10.06 11:33:04 | 000,000,643 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_daa0a966d0440060\System.Runtime.Serialization.dll
[2015.10.06 11:33:07 | 000,000,425 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_da9a7c24d049986e\System.Runtime.Serialization.dll
[2014.07.09 02:45:33 | 000,847,872 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_da9bee56d04831a0\System.Runtime.Serialization.dll
[2015.10.06 11:33:09 | 000,000,440 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_c3caa4cae9f2fd25\System.Runtime.Serialization.dll
[2015.10.06 11:33:12 | 000,000,619 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_c3cbbbdce9f1fcdb\System.Runtime.Serialization.dll
[2014.08.12 06:08:56 | 000,000,276 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf-languagepack_31bf3856ad364e35_6.3.9600.16384_cs-cz_c3036df581d2c4e4.manifest
[2014.03.18 10:24:18 | 000,000,281 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf-languagepack_31bf3856ad364e35_6.3.9600.16384_en-us_0659b95168cd2142.manifest
[2014.03.18 10:24:30 | 000,000,249 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf.resources_31bf3856ad364e35_6.3.9600.16384_en-us_35eaebe6834354eb.manifest
[2013.08.22 16:20:14 | 000,000,210 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf_31bf3856ad364e35_6.3.9600.16384_none_91b10a007e43beff.manifest
[2013.08.22 14:25:34 | 000,000,297 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.3.9600.16384_none_0273ed2980a1f589.manifest
[2013.08.22 16:22:11 | 000,001,512 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-serial-classextension_31bf3856ad364e35_6.3.9600.16384_none_26d3123b2d2a9360.manifest
[2013.08.22 16:22:07 | 000,000,110 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.3.9600.16384_none_1d7b32f2da6cfe0c.manifest
[2013.08.22 16:24:27 | 000,000,402 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_031841e9b021a288.manifest
[2013.08.22 16:24:29 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_ea3019bcd508d7f5.manifest
[2013.08.22 16:24:24 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_afcfdcce0af8e4ba.manifest
[2015.10.01 15:13:21 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.17238_none_afca82460afdc961.manifest
[2015.10.01 15:13:21 | 000,000,413 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.20720_none_98fc8f0624a54725.manifest
[2013.08.22 16:24:28 | 000,000,397 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.xml.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_1f92ce7ac9b9f399.manifest
[2013.08.22 16:24:27 | 000,000,403 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_0b1c65bd7b1ef04c.manifest
[2013.08.22 16:24:13 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.16384_none_9fc99c9c7c4c05c7.manifest
[2015.10.01 15:24:18 | 000,000,404 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17226_none_9fc36f5a7c519dd5.manifest
[2015.10.01 15:23:11 | 000,000,404 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17231_none_9fc4e18c7c503707.manifest
[2015.10.01 15:24:18 | 000,000,407 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20708_none_88f3980095fb028c.manifest
[2015.10.01 15:23:11 | 000,000,406 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20717_none_88f4af1295fa0242.manifest
[2013.08.22 16:24:13 | 000,000,416 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_daa0a966d0440060.manifest
[2015.10.01 15:24:18 | 000,000,413 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_da9a7c24d049986e.manifest
[2015.10.01 15:23:11 | 000,000,412 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_da9bee56d04831a0.manifest
[2015.10.01 15:24:18 | 000,000,415 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_c3caa4cae9f2fd25.manifest
[2015.10.01 15:23:11 | 000,000,414 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_c3cbbbdce9f1fcdb.manifest
[2013.08.22 16:24:29 | 000,000,418 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_61eedd30ec040245.manifest
[2013.08.22 16:24:24 | 000,000,430 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_dde82ee214ba2d3d.manifest
[2013.08.22 16:24:13 | 000,000,400 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.16384_none_ed2ffed67c428df1.manifest
[2015.10.01 15:24:18 | 000,000,399 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17226_none_ed29d1947c4825ff.manifest
[2015.10.01 15:23:11 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17231_none_ed2b43c67c46bf31.manifest
[2015.10.01 15:24:18 | 000,000,399 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20708_none_d659fa3a95f18ab6.manifest
[2015.10.01 15:23:11 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20717_none_d65b114c95f08a6c.manifest
[2014.08.12 06:10:23 | 000,000,448 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.16384_cs-cz_25789e4d6d93f144.manifest
[2014.03.18 10:24:58 | 000,000,149 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.16384_en-us_80951863a93f3c56.manifest
[2015.10.01 15:13:19 | 000,000,449 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.17238_cs-cz_257343c56d98d5eb.manifest
[2015.10.01 15:13:19 | 000,000,149 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.17238_en-us_808fbddba94420fd.manifest
[2015.10.01 15:13:19 | 000,000,445 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.20720_cs-cz_0ea55085874053af.manifest
[2015.10.01 15:13:19 | 000,000,148 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.20720_en-us_69c1ca9bc2eb9ec1.manifest
[2014.08.12 06:10:16 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.16384_cs-cz_7adb458f8b8eae0b.manifest
[2014.03.18 10:24:56 | 000,000,152 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.16384_en-us_d5f7bfa5c739f91d.manifest
[2015.10.01 15:24:17 | 000,000,406 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17226_cs-cz_7ad5184d8b944619.manifest
[2015.10.01 15:24:17 | 000,000,151 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17226_en-us_d5f19263c73f912b.manifest
[2015.10.01 15:23:10 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17231_cs-cz_7ad68a7f8b92df4b.manifest
[2015.10.01 15:23:10 | 000,000,152 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17231_en-us_d5f30495c73e2a5d.manifest
[2015.10.01 15:24:17 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20708_cs-cz_640540f3a53daad0.manifest
[2015.10.01 15:24:17 | 000,000,151 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20708_en-us_bf21bb09e0e8f5e2.manifest
[2015.10.01 15:23:10 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20717_cs-cz_64065805a53caa86.manifest
[2015.10.01 15:23:10 | 000,000,152 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20717_en-us_bf22d21be0e7f598.manifest
[2013.08.22 16:24:24 | 000,000,419 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_0d0d9cf22bac10f4.manifest
[2013.08.22 16:24:27 | 000,000,471 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.16384_none_c8108d2e85eed25d.manifest
[2015.10.01 15:13:20 | 000,000,471 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.17238_none_c80b32a685f3b704.manifest
[2015.10.01 15:13:20 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.20720_none_b13d3f669f9b34c8.manifest
[2013.08.22 16:24:13 | 000,000,422 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.16384_none_1d733470a3e98f24.manifest
[2015.10.01 15:24:18 | 000,000,421 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17226_none_1d6d072ea3ef2732.manifest
[2015.10.01 15:23:11 | 000,000,422 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17231_none_1d6e7960a3edc064.manifest
[2015.10.01 15:24:18 | 000,000,421 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20708_none_069d2fd4bd988be9.manifest
[2015.10.01 15:23:11 | 000,000,423 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20717_none_069e46e6bd978b9f.manifest
[2013.08.22 16:24:28 | 000,000,447 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.xml.serialization_b77a5c561934e089_4.0.9600.16384_none_5aaf0d34c0033202.manifest
[2013.08.22 16:24:24 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_3cc4c9f9340d8755.manifest
[2013.08.22 16:24:56 | 000,000,411 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_224de03de4c02966.manifest
[2015.10.01 15:24:18 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_2247b2fbe4c5c174.manifest
[2015.10.01 15:23:11 | 000,000,412 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_2249252de4c45aa6.manifest
[2015.10.01 15:24:18 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_0b77dba1fe6f262b.manifest
[2015.10.01 15:23:11 | 000,000,411 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_0b78f2b3fe6e25e1.manifest
[2013.08.10 01:55:16 | 000,142,104 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_4.0.9600.16384_none_0dbd81c1c9e100df\System.Runtime.Serialization.Formatters.Soap.dll
[2015.10.06 12:20:03 | 000,000,531 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.16384_none_63202903e7dbbda6\System.Runtime.Serialization.Formatters.Soap.dll
[2014.06.23 23:12:42 | 000,131,072 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.17226_none_6319fbc1e7e155b4\System.Runtime.Serialization.Formatters.Soap.dll
[2015.10.06 12:20:03 | 000,000,491 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.20708_none_4c4a2468018aba6b\System.Runtime.Serialization.Formatters.Soap.dll
[2014.08.12 06:11:44 | 000,027,920 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_c6e6982dc37909d8\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2015.10.06 12:20:04 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.16384_cs-cz_1c493f6fe173c69f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.08.12 06:11:39 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.17226_cs-cz_1c43122de1795ead\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2015.10.06 12:20:04 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.20708_cs-cz_05733ad3fb22c364\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.08.10 01:55:16 | 000,029,392 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_61eedd30ec040245\System.Runtime.Serialization.Json.dll
[2013.08.10 01:55:16 | 000,029,432 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_dde82ee214ba2d3d\System.Runtime.Serialization.Primitives.dll
[2015.10.06 12:20:07 | 000,000,663 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.16384_none_ed2ffed67c428df1\System.Runtime.Serialization.dll
[2015.10.06 12:20:11 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17226_none_ed29d1947c4825ff\System.Runtime.Serialization.dll
[2014.07.09 02:45:07 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17231_none_ed2b43c67c46bf31\System.Runtime.Serialization.dll
[2015.10.06 12:20:14 | 000,000,452 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20708_none_d659fa3a95f18ab6\System.Runtime.Serialization.dll
[2015.10.06 12:20:17 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20717_none_d65b114c95f08a6c\System.Runtime.Serialization.dll
[2015.10.06 12:20:17 | 000,003,691 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.16384_cs-cz_25789e4d6d93f144\System.RunTime.Serialization.resources.dll
[2014.06.05 04:33:14 | 000,113,952 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.17238_cs-cz_257343c56d98d5eb\System.RunTime.Serialization.resources.dll
[2015.10.06 12:20:18 | 000,003,304 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.20720_cs-cz_0ea55085874053af\System.RunTime.Serialization.resources.dll
[2015.10.06 12:20:18 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.16384_cs-cz_7adb458f8b8eae0b\System.RunTime.Serialization.Resources.dll
[2015.10.06 12:20:18 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17226_cs-cz_7ad5184d8b944619\System.RunTime.Serialization.Resources.dll
[2014.08.12 06:11:39 | 000,090,112 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17231_cs-cz_7ad68a7f8b92df4b\System.RunTime.Serialization.Resources.dll
[2015.10.06 12:20:19 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20708_cs-cz_640540f3a53daad0\System.RunTime.Serialization.Resources.dll
[2015.10.06 12:20:19 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20717_cs-cz_64065805a53caa86\System.RunTime.Serialization.Resources.dll
[2013.08.10 01:55:16 | 000,029,896 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_0d0d9cf22bac10f4\System.Runtime.Serialization.Xml.dll
[2015.10.06 12:20:23 | 000,018,929 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.16384_none_c8108d2e85eed25d\System.Runtime.Serialization.dll
[2014.07.24 04:20:32 | 001,059,536 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.17238_none_c80b32a685f3b704\System.Runtime.Serialization.dll
[2015.10.06 12:20:28 | 000,004,122 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.20720_none_b13d3f669f9b34c8\System.Runtime.Serialization.dll
[2015.10.06 12:20:33 | 000,000,663 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.16384_none_1d733470a3e98f24\System.Runtime.Serialization.dll
[2015.10.06 12:20:38 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17226_none_1d6d072ea3ef2732\System.Runtime.Serialization.dll
[2014.07.09 02:45:06 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17231_none_1d6e7960a3edc064\System.Runtime.Serialization.dll
[2015.10.06 12:20:42 | 000,000,452 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20708_none_069d2fd4bd988be9\System.Runtime.Serialization.dll
[2015.10.06 12:20:46 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20717_none_069e46e6bd978b9f\System.Runtime.Serialization.dll
[2013.08.10 01:55:49 | 000,045,720 | ---- | M] () -- \Windows\WinSxS\msil_system.xml.serialization_b77a5c561934e089_4.0.9600.16384_none_5aaf0d34c0033202\System.Xml.Serialization.dll
[2013.08.10 01:55:49 | 000,029,848 | ---- | M] () -- \Windows\WinSxS\msil_system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_3cc4c9f9340d8755\System.Xml.XmlSerializer.dll
[2015.10.06 14:20:48 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_54cc2f7ac6efa85c\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.08.12 06:11:39 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_550ef6e8c6bd4fde\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2015.10.06 14:20:54 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_55b0527fdfc8c56f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.08.12 06:11:20 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_e30aa618ff4459ba\serialui.dll.mui
[2014.03.18 10:25:21 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_en-us_2660f174e63eb618\serialui.dll.mui
[2015.10.06 14:39:25 | 000,001,912 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.16384_none_89a166153a4451f7\serialui.dll
[2014.10.29 02:46:05 | 000,015,360 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.17415_none_89ee00f13a0abe7f\serialui.dll
[2015.10.06 16:07:21 | 000,000,663 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_224de03de4c02966\System.Runtime.Serialization.dll
[2015.10.06 16:07:24 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_2247b2fbe4c5c174\System.Runtime.Serialization.dll
[2014.07.09 02:45:06 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_2249252de4c45aa6\System.Runtime.Serialization.dll
[2015.10.06 16:07:27 | 000,000,452 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_0b77dba1fe6f262b\System.Runtime.Serialization.dll
[2015.10.06 16:07:30 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_0b78f2b3fe6e25e1\System.Runtime.Serialization.dll

< *w7lxe* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 220 bytes -> C:\Users\User\OneDrive:ms-properties

< End of report >

Re: Virus - trojský kůň

Napsal: 13 lis 2015 14:19
od P-e-tula
OTL Extras logfile created on: 13.11.2015 12:40:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18098)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,89 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 34,73% Memory free
6,26 Gb Paging File | 3,13 Gb Available in Paging File | 50,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 423,30 Gb Total Space | 301,55 Gb Free Space | 71,24% Space Free | Partition Type: NTFS
Drive D: | 25,00 Gb Total Space | 22,60 Gb Free Space | 90,39% Space Free | Partition Type: NTFS

Computer Name: LENOVO-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-789525210-3307182626-2393355962-1001\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0507FC7B-16B0-44BD-A232-58E743892401}" = rport=445 | protocol=6 | dir=out | app=system |
"{15CA4BC2-2A6E-4D7B-86B3-8C32C2744833}" = lport=139 | protocol=6 | dir=in | app=system |
"{3B26D8DA-2B7F-4A89-ABF9-B32B313533F1}" = lport=10243 | protocol=6 | dir=in | app=system |
"{3FFAC808-BA7D-4318-A27C-59B00BCF50C0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{479781AA-949F-4295-B10C-FAB37A031774}" = lport=138 | protocol=17 | dir=in | app=system |
"{509A0778-93D3-45CF-A8A5-1654BEF833D4}" = lport=137 | protocol=17 | dir=in | app=system |
"{5FDF20D6-D79F-4899-87B9-02E87878C5AE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{627AADCE-AD0F-4A17-879F-9E1BB096B3C9}" = rport=137 | protocol=17 | dir=out | app=system |
"{70E5718C-120E-420D-98D8-9C0FA83BB562}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8176F929-804D-4E8E-BCC2-F9172070ED02}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8712D3FB-8F62-4762-AA79-8F71E5DDE741}" = rport=139 | protocol=6 | dir=out | app=system |
"{90D7C546-6714-4A5B-8F01-A0CBDD3E1E72}" = rport=138 | protocol=17 | dir=out | app=system |
"{922578A1-3763-4F03-866E-A469E5C3ECD4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{998F14EB-3F78-4A32-A638-37E746296E13}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A2AB89AB-5F91-4006-A854-98FB583EDFDC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B7FA1903-1FD5-458A-9B8A-93B6CF372CEA}" = lport=445 | protocol=6 | dir=in | app=system |
"{C6211542-B673-4973-9E8D-70243363AA32}" = lport=55100 | protocol=6 | dir=in | name=lenovo mobile phone wireless import |
"{C993794D-E76B-41CF-B7CD-15DF28581CC8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D95926D4-3128-4B05-9F9D-240D9D3A367B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D9718DEB-3832-4AAB-A3DA-F4560F27DC45}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{E1F721F8-A7C8-4B92-8D0E-568AA7F52AC4}" = rport=10243 | protocol=6 | dir=out | app=system |
"{E32028B0-FF39-4D3A-BF7B-655F6E38F238}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FE7DEBB0-D59C-4B81-8747-179D688F7E49}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FEC510BA-4153-4D7A-937D-825E144CDC6B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0200E469-0C5A-4C86-9927-C5062DF9DE6A}" = dir=out | name=canon inkjet print utility |
"{0733FFA1-8136-41AC-9E99-31269C356EFA}" = dir=in | name=skype |
"{0745BFB7-807D-4C2E-9B87-202454896A71}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0D3E63B4-B22C-49F1-AA21-42680B41BB1F}" = dir=out | name=windows_ie_ac_001 |
"{0F102704-1DB9-4910-8E85-DC3BD441ABAF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1010E77D-A29D-40C7-87E6-29A30D1D4ED0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1182D9FA-3D9C-4C5B-B64B-8827CD6CBBAB}" = dir=out | name=photo touch |
"{14E8033B-A8A9-4794-9200-64F0A9228405}" = protocol=6 | dir=out | app=c:\program files\lenovo photomasterimport\photomasterimport.exe |
"{26BE4A4B-1ECE-4CE8-8659-AB186C3E0F4A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{315D2A80-347F-464F-B504-6DBE2F7B7A42}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{3618956C-1AEF-49AF-9DB4-4678E460B95D}" = dir=out | name=hp all-in-one printer remote |
"{382AAC7D-B683-4E8F-8415-47FA995CCCC0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{3A50802C-E149-4098-B2D0-793ABEF75A45}" = dir=in | app=c:\program files\cyberlink\powerdirector10\pdr10.exe |
"{3AEDABE5-8ED7-4599-A163-6E479EB1F69B}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{3F4F3E4E-27A8-4FDA-9316-E0BEBE26A95E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3F5B68D9-874C-4C18-98C1-75F81F6294AB}" = dir=out | name=skype |
"{4174DF47-BD52-498F-A375-5FBAF5EBC314}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4259F6B0-E748-4038-BCDA-EEEB0B2F274A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{4367719E-4651-4BE0-A0E1-C23E64B8D096}" = dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{45AD25AC-8B42-460B-8BA9-D35CE1ED2DE8}" = dir=out | name=@{microsoft.zunemusic_2.6.672.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{462B9F1C-D353-4C28-B807-3C4FE081460E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{46524F74-9B7C-4CC9-9AD3-8F3F8771750D}" = protocol=6 | dir=out | app=system |
"{46DA0D1F-066C-4B90-8BAB-A0F307E2915F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{471CF6C8-AAFC-4D07-BE4D-0652B875B7BF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{577A8A50-B9F3-4970-8DA0-6D3AE1EC4548}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{71DA30D1-7227-4E4C-A090-C10F375C6213}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{753C72B9-F3DB-42AB-A54B-C02348C4054B}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{92A30D22-F23D-4FFC-96EE-3A015BA52B74}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9F303CF0-BA32-4712-8E40-DBFC569F861B}" = dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{AC3D0034-F1D7-4CEE-BA02-BE21040EC5A1}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AE97527B-35F8-4F56-9959-7E48C303FF51}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B0E7AD17-7186-4980-84BC-7BA0C2F6F4BE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B22284D0-5B6C-452B-9316-7C3B66187582}" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{B4F1E280-484C-40EC-A410-3B323907FA5F}" = dir=out | name=@{microsoft.zunevideo_2.6.446.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{B5BFFDB6-A202-4C2E-884D-C76A013CEC52}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{B7063B64-DB12-4E11-9946-49E343CE8361}" = dir=in | name=canon inkjet print utility |
"{B8FB5EAF-8C6F-4649-B7FE-F66E26B41D8B}" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{BF5ACC8C-5898-47F4-8E16-EFF4F9323ACB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C1A1A42B-09BB-4FAD-B20A-3F01367A309F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C9EB5718-7027-4953-A44A-88B622E35FD9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D01BD51D-066B-4562-B220-64BF06E40FA9}" = dir=out | name=lenovo recommends |
"{D5DF3ED4-3701-4E12-99A4-421E8A1D9757}" = dir=in | name=hp all-in-one printer remote |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D746C8A9-F59C-405E-AA6C-857CA73D48B9}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DD9169DE-DC61-41A6-8CDE-BB189DB83DF5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{FD5B18F9-E5C8-4E87-AA48-5EA41866627F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"TCP Query User{06D0933C-98F1-40E8-B079-240B9E7D7E36}C:\model\java\bin\java.exe" = protocol=6 | dir=in | app=c:\model\java\bin\java.exe |
"TCP Query User{3D43E6A3-007B-4C5A-AB33-B007B7F02ABD}C:\model\java\bin\java.exe" = protocol=6 | dir=in | app=c:\model\java\bin\java.exe |
"TCP Query User{85F167F3-468B-4EB7-836F-18E7152AF3F8}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{F8D13DFB-4E6A-4AB6-BAEA-9A67EC8CDE0A}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{38EC4164-0EB6-452B-BDA5-B5C624691167}C:\model\java\bin\java.exe" = protocol=17 | dir=in | app=c:\model\java\bin\java.exe |
"UDP Query User{66AB58BE-2D7D-45E7-A98A-AFA53BBF6B30}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{B72AD591-AF56-4929-814F-110291AC273A}C:\model\java\bin\java.exe" = protocol=17 | dir=in | app=c:\model\java\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0788641D-D31A-478D-BB34-C41564AE9F93}" = Dependency Package Update
"{0DE0A178-AC7B-4650-806C-CF226DE03766}" = Podpora aplikací Apple (64bitová)
"{176E2755-0A17-42C6-88E2-192AB2131278}" = Intel(R) Trusted Execution Engine
"{1BA457D4-90F2-4D83-9543-9715849023C8}" = Microsoft SQL Server 2008 R2 RsFx Driver
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}" = SQL Server 2008 R2 SP2 Common Files
"{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}" = Microsoft SQL Server VSS Writer
"{2D6248C0-4693-4CAB-9922-F05E4015F62A}" = Intel(R) Trusted Execution Engine
"{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}" = Hightail for Lenovo
"{3540181E-340A-4E7A-B409-31663472B2F7}" = Apple Mobile Device Support
"{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}" = SQL Server 2008 R2 SP2 Common Files
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{49860BCD-24D6-44C1-922E-AC12FE32234E}" = Microsoft SQL Server 2008 R2 Native Client
"{5252431C-288E-409D-ADCF-24407E0E6F70}" = Dependency Package Update
"{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}" = Bonjour
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6307E820-0317-4DCE-AAE0-7B6CAD867055}" = Intel(R) Trusted Execution Engine Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2010
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A2122A9C-A699-4365-ADF8-68FEAC125D61}" = SQL Server 2008 R2 SP2 Database Engine Shared
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}" = Magic Transfer
"{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}" = Dolby Digital Plus Advanced Audio
"{B2213E4E-F502-4D36-BE95-9293C866EF3F}" = Microsoft SQL Server 2008 R2 Setup (English)
"{B33C558F-772F-4308-A059-390FBF9BAAAE}" = iCloud
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{C942A025-A840-4BF2-8987-849C0DD44574}" = SQL Server 2008 R2 SP2 Database Engine Shared
"{E289B7DD-6732-4333-A47A-75A145D23EE3}" = Classic Shell
"{E690A491-702F-4DEC-9977-C015D1DBB57C}" = iTunes
"{E7B88AD2-ABEA-4B6A-B60A-3890D1B56B90}" = SAP Crystal Reports runtime engine for .NET Framework (64-bit)
"{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}" = Sql Server Customer Experience Improvement Program
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = SQL Server 2008 R2 SP2 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = SQL Server 2008 R2 SP2 Database Engine Services
"{FFED38DF-94DC-4FF9-96C1-A6990EDA6B03}" = Dependency Package Update
"6BCA401E9CBEED970D75F55FA5320F60D11984E9" = Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288)
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"EE9B1F2037C580F36D92FA431CC02BFF04C31F15" = Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34)
"Lenovo Dependency Package_is1" = Lenovo Dependency Package
"Lenovo SmartVoice" = Lenovo Smart Voice
"Lenovo Transition" = Lenovo Transition
"LenovoExperienceImprovement" = Lenovo Experience Improvement
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2 (64-bit)
"Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2 (64-bit)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PismoFileMountAuditPackage" = Pismo File Mount Audit Package
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}" = Lenovo PhoneCompanion
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}" = Lenovo Recommends
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{47C99E8D-30B8-44D4-A373-7AC310F39C43}" = CMSS Model
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}" = Podpora aplikací Apple (32bitová)
"{6A0549A9-1B96-498C-ACBC-3943001FEB19}" = Skype™ 7.13
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{756DF96D-E40E-4B52-A53D-036E3D6AAB44}_is1" = Free AVI to MP4 Converter 1.0
"{8300CA15-AD32-4C12-A6D4-121DEBCA11CC}" = Lenovo Flex 2 Demo
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{90140000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{959B7F35-2819-40C5-A0CD-3C53B5FCC935}" = Genesys USB Mass Storage Device
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}" = Lenovo Updates
"{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager
"{AC76BA86-0804-1033-1959-001824161310}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1029-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Czech
"{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}" = Magic Transfer
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser
"{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196}" = Metric Collection SDK 35
"{d5af4942-2597-453e-afb3-da5ee6fba6c6}" = eLiška4
"{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}" = Lenovo Mobile Phone Wireless Import
"{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}" = Lenovo EasyCamera
"{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = User Manuals
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}" = Apple Software Update
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}" = Lenovo PhoneCompanion
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}" = Lenovo Updates
"InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager
"InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}" = Magic Transfer
"InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}" = Lenovo Mobile Phone Wireless Import
"InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = User Manuals
"Lenovo FusionEngine" = Lenovo FusionEngine
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware verze 2.2.0.1024
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"VLC media player" = VLC media player
"Winamp" = Winamp

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-789525210-3307182626-2393355962-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1" = World of Tanks
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10.11.2015 13:26:26 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = AppendDNSNameString: Illegal empty label in name "."

Error - 10.11.2015 13:26:27 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = AppendDNSNameString: Illegal empty label in name "."

Error - 10.11.2015 13:26:30 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = AppendDNSNameString: Illegal empty label in name "."

Error - 10.11.2015 13:56:31 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = AppendDNSNameString: Illegal empty label in name "."

Error - 10.11.2015 13:56:31 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = AppendDNSNameString: Illegal empty label in name "."

Error - 10.11.2015 14:30:35 | Computer Name = Lenovo-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: rundll32.exe_winethc.dll, verze: 6.3.9600.17415,
časové razítko: 0x54504eb8 Název chybujícího modulu: USER32.dll, verze: 6.3.9600.18007,
časové razítko: 0x55c4c16b Kód výjimky: 0xc0000142 Posun chyby: 0x00000000000ec4e0
ID
chybujícího procesu: 0x198 Čas spuštění chybující aplikace: 0x01d11be5e34a810c Cesta
k chybující aplikaci: C:\windows\System32\rundll32.exe Cesta k chybujícímu modulu:
USER32.dll ID zprávy: 21788bcd-87d9-11e5-8276-3010b315dc22 Úplný název chybujícího
balíčku: ID aplikace související s chybujícím balíčkem:

Error - 10.11.2015 14:34:35 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10.11.2015 14:34:35 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 40438

Error - 10.11.2015 14:34:35 | Computer Name = Lenovo-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 40438

Error - 12.11.2015 12:57:31 | Computer Name = Lenovo-PC | Source = VSS | ID = 8194
Description =

[ System Events ]
Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba Lenovo PhoneCompanionPusher Service byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba Cyberlink RichVideo64 Service(CRVS) byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba SQL Server (ELISKA4CLIENT) byla neočekávaně ukončena. Tento
stav nastal již 1krát.

Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba SQL Server VSS Writer byla neočekávaně ukončena. Tento stav
nastal již 1krát.

Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba ymc byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error - 10.11.2015 16:02:09 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7031
Description = Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla nečekaně
ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund:
Restartovat službu.

Error - 10.11.2015 16:02:11 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7031
Description = Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát.
Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error - 10.11.2015 16:02:11 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7031
Description = Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena.
Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund:
Restartovat službu.

Error - 10.11.2015 16:02:11 | Computer Name = Lenovo-PC | Source = Service Control Manager | ID = 7034
Description = Služba Office Software Protection Platform byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 11.11.2015 16:04:45 | Computer Name = Lenovo-PC | Source = DCOM | ID = 10010
Description =


< End of report >

Re: Virus - trojský kůň

Napsal: 13 lis 2015 15:27
od Márty84
:!: Vypnete antivir, at nebrani programu v praci.
:arrow: Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]
[CreateRestorePoint]

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:otl
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {1A699E11-5CDA-4037-861D-7A23910CAF09}
IE:64bit: - HKLM\..\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {1A699E11-5CDA-4037-861D-7A23910CAF09}
IE - HKLM\..\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[2 C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\windows\Panther\*.tmp files -> C:\windows\Panther\*.tmp -> ]
[1 C:\windows\Temp\*.tmp files -> C:\windows\Temp\*.tmp -> ]
[2 \Program Files (x86)\eLiska4\*.tmp files -> \Program Files (x86)\eLiska4\*.tmp -> ]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.




:arrow: Stahnete SystemLook http://jpshortstuff.247fixes.com/SystemLook_x64.exe a ulozte ho na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Do okna zkopirujte tento skript

Kód: Vybrat vše

:filefind
*PetraRolincová*

:regfind
PetraRolincová

:folderfind
*PetraRolincová*
kliknete na Look a chvili pockejte
Mel by na vas vyskocit log s nazvem Systemlook
Ten mi sem zkopirujte

Re: Virus - trojský kůň

Napsal: 13 lis 2015 15:44
od P-e-tula
První log po restartu:

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: User
->Temp folder emptied: 2477989 bytes
->Temporary Internet Files folder emptied: 8245221 bytes
->Google Chrome cache emptied: 142249786 bytes
->Flash cache emptied: 610 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 64000 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12415826 bytes
RecycleBin emptied: 647407 bytes

Total Files Cleaned = 158,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: User
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point
========== FILES ==========
File/Folder C:\windows\system32\*.tmp.dll not found.
File/Folder C:\windows\system32\SET*.tmp not found.
File/Folder C:\windows\*.tmp not found.
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A699E11-5CDA-4037-861D-7A23910CAF09}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A699E11-5CDA-4037-861D-7A23910CAF09}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A699E11-5CDA-4037-861D-7A23910CAF09}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
File/Folder C:\windows\*.tmp not found.
C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP801C.tmp folder deleted successfully.
C:\windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPA688.tmp folder deleted successfully.
C:\windows\Panther\_s_5EF9.tmp deleted successfully.
C:\windows\Panther\_s_6600.tmp deleted successfully.
\Program Files (x86)\eLiska4\SecurityCheck.tmp deleted successfully.
File delete failed. \Program Files (x86)\eLiska4\SecurityCheckPreload.tmp scheduled to be deleted on reboot.

OTL by OldTimer - Version 3.2.69.0 log created on 11132015_153942

Files\Folders moved on Reboot...
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{2C841D94-DD74-4DB4-B5CE-00AA3B678802}.tmp not found!
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{713B2195-26C2-4FD6-ABC8-34FEE64E73DA}.tmp not found!
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{8059D74C-81E7-44EF-AF70-FA5985139707}.tmp not found!
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{A05DAF89-C7C1-4094-BFB8-72984AA14ABB}.tmp not found!
C:\Users\User\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. \Program Files (x86)\eLiska4\SecurityCheckPreload.tmp scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Virus - trojský kůň

Napsal: 13 lis 2015 15:47
od P-e-tula
Systemlook:

SystemLook 30.07.11 by jpshortstuff
Log created at 15:45 on 13/11/2015 by User
Administrator - Elevation successful

========== filefind ==========

Searching for "*PetraRolincová*"
No files found.

========== regfind ==========

Searching for "PetraRolincová"
No data found.

========== folderfind ==========

Searching for "*PetraRolincová*"

Re: Virus - trojský kůň

Napsal: 13 lis 2015 17:27
od Márty84
Ta hlaska asi stale vyskakuje, ze?

Restartujte pocitac. Az se hlaska objevi, spustte spravce uloh a podivejte se na aplikace a procesy, pripadne si je vyfotte. Pak tu hlasku zavrete a podivejte se, ktera aplikace/proces zmizela. Potrebujem zjistit, cemu to vlastne patri, protoze v lozich se to neukazuje :?:

Re: Virus - trojský kůň

Napsal: 13 lis 2015 18:07
od P-e-tula
Ano. Hláška se stále objevuje. Ráda bych poslala, co po mě chcete, ale je absolutně nemožný zjistit, který proces nebo služba se vypne nebo zapne. Po zapnutí PC mi totiž naskočí asi 100 různých procesů a služeb, které se neustále promíchávají a mění místa a pořadí :x

Re: Virus - trojský kůň

Napsal: 13 lis 2015 18:12
od Márty84
Spustte znovu SystemLook, ale s timto vyhledavacim skriptem...

Kód: Vybrat vše

:filefind
*Rolincová*

:regfind
Rolincová

:folderfind
*Rolincová*

Re: Virus - trojský kůň

Napsal: 13 lis 2015 18:30
od P-e-tula
SystemLook 30.07.11 by jpshortstuff
Log created at 18:27 on 13/11/2015 by User
Administrator - Elevation successful

========== filefind ==========

Searching for "*Rolincová*"
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\Rolincová TZ 39.xls --a---- 546304 bytes [15:22 01/10/2015] [09:44 29/09/2013] 93D093E2DA4021D5534E9C22D981C5D6
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\Rolincová TZ 8.xls --a---- 542208 bytes [15:22 01/10/2015] [18:46 23/02/2014] DB3A736BA0301A5935EB39DE89378128
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 12.xls --a---- 543232 bytes [15:22 01/10/2015] [13:46 21/03/2014] BE5970AA5652537D0C56D4A52C0314B2
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 14.xls --a---- 542208 bytes [15:22 01/10/2015] [19:21 04/04/2014] A0F86EDE37CED9C79C5B866F9359BF34
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 2.xlsx --a---- 371421 bytes [15:22 01/10/2015] [18:51 12/01/2014] 337951973D24D4C7827CC929CD910F92
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 35.xlsx --a---- 369139 bytes [15:22 01/10/2015] [18:57 01/09/2013] 98280E5A47B6D815B69B9FDCDA062694
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 36.xlsx --a---- 369099 bytes [15:22 01/10/2015] [17:15 08/09/2013] C05324EA935A073B95BC75552C6B59B1
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 38, 2014.xlsx --a---- 372159 bytes [15:22 01/10/2015] [18:02 21/09/2014] 637CD0A8B77924096F5C9D6DBFB62C2D
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 42. 2014.xlsx --a---- 371909 bytes [15:22 01/10/2015] [17:56 19/10/2014] 79051573ABB8AF20227E9CD106C2DF7F
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\tz Rolincová 43.xlsx --a---- 371852 bytes [15:22 01/10/2015] [17:23 26/10/2014] 3DD661EBB6DE64BEFA1D5C1D11657F04
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 44, 2014.xlsx --a---- 374004 bytes [15:22 01/10/2015] [19:56 02/11/2014] 04DBF61543D53AB407DCFEA0D8F85232
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 45, 2014.xlsx --a---- 374053 bytes [15:22 01/10/2015] [15:37 09/11/2014] 0E9B404507F75CEA9E15FB0A364C1F8E
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 45.xls --a---- 547328 bytes [15:22 01/10/2015] [15:28 10/11/2013] CF2051575BE1DA79E9BD162940E9C610
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 47.xlsx --a---- 369077 bytes [15:22 01/10/2015] [17:57 24/11/2013] 04B6EC673FEAE13BB960DC8D7B1472AF
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová 6.xls --a---- 542208 bytes [15:22 01/10/2015] [17:18 02/02/2014] FE7A69C4FA706A404A4C0C2D8FC3CC35
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová P. 30.xlsx --a---- 371788 bytes [15:22 01/10/2015] [06:17 28/07/2014] 9ED502A6FCBDA38F8A89E309342452A2
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová P. 34.xlsx --a---- 372063 bytes [15:22 01/10/2015] [15:56 24/08/2014] EC4D4E96FA2B5B76B54DD47FA70EDC10
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová P. 37.xlsx --a---- 369096 bytes [15:22 01/10/2015] [20:49 15/09/2013] 96701CA5CAEC476E48C032019E22FA57
C:\Users\User\Desktop\LIŠKA\Týdenní zpráva\TZ Rolincová P..xls --a---- 545792 bytes [15:22 01/10/2015] [08:57 06/08/2014] 748E94E515535D6D2EAAC0AEDF621AC8
C:\Users\User\Desktop\LIŠKA\úvěry-složky\Rolincová Petra úvěr\Kupní sml Rolincová.doc --a---- 1693184 bytes [15:24 01/10/2015] [18:33 24/06/2014] 5884089C17DC7BC4592CCE35E7967BDD
C:\Users\User\Desktop\LIŠKA\úvěry-složky\Rolincová Petra úvěr\Rolincová Petra pojistky k Mú\Rizikové životní pojištění - Rolincová, DiS. Petra.pdf --a---- 5375661 bytes [15:24 01/10/2015] [09:28 19/05/2014] A106F63BBE50EA243A3C64CD9D2206F3
C:\Users\User\Desktop\LIŠKA\úvěry-složky\Rolincová Petra úvěr\Rolincová Petra pojistky k Mú\ČSOB Pojišťovna - Předsmluvní dokument - Petra Rolincová.pdf --a---- 694139 bytes [15:24 01/10/2015] [13:20 19/05/2014] 6706513CAE21CEC786D30091AEA1DEEF
C:\Users\User\Documents\Rolincová Hana životopis.pdf --a---- 125468 bytes [15:21 01/10/2015] [19:36 08/03/2013] C27BB2E194D590FC46D2F4FDD16AD05E
C:\Users\User\Documents\Rolincová Petra životopis.pdf --a---- 130962 bytes [15:21 01/10/2015] [15:36 12/03/2012] C3B01260DA3A24C44B37EF2E5EF77291
C:\Users\User\Documents\škola\Rolincová Petra životopis.docx --a---- 17208 bytes [15:50 01/10/2015] [19:35 08/03/2013] 293EA9B98918687CEBD183A1DB24CFB0
C:\Users\User\Documents\škola\1.ročník\KOR\Petra Rolincová.doc --a---- 26112 bytes [15:50 01/10/2015] [11:25 10/09/2010] 1105EEB4200723A1C99DBC33F203E813
C:\Users\User\Documents\škola\1.ročník\KOR\KOR letní semestr\Rolincová Petra.docx --a---- 17210 bytes [15:50 01/10/2015] [20:09 28/02/2011] 816A9B1FFA0E38613737FE99FC1AAC3E
C:\Users\User\Documents\škola\2.ročník\Letní semestr\PSY\Rolincová Petra.docx --a---- 16321 bytes [15:50 01/10/2015] [18:03 10/05/2012] C32FCD990DCFB28753689E8D922B8457
C:\Users\User\Documents\škola\3.ročník\SUPERVIZE 3.AV, Rolincová, pozorovatel.docx --a---- 13158 bytes [15:51 01/10/2015] [09:01 29/04/2013] 3E459B3DA41026FEBA498A18C05117F4
C:\Users\User\Documents\škola\3.ročník\SUPERVIZE 3.AV, Rolincová.docx --a---- 13158 bytes [15:51 01/10/2015] [09:01 29/04/2013] 3E459B3DA41026FEBA498A18C05117F4
C:\Users\User\Documents\škola\3.ročník\ABSOLUTORIA\Absolventka\AP - Rolincová, Současná situace v systému péče o ohrožené děti.doc --a---- 714240 bytes [15:51 01/10/2015] [18:11 17/04/2013] 9AB56B50A1B1F2519397045D4681E60B
C:\Users\User\Documents\škola\3.ročník\ABSOLUTORIA\Absolventka\jednotlivé části\1. Kapitola - Systém náhradní rodinné péče, Rolincová, 3.AV.docx --a---- 48053 bytes [15:51 01/10/2015] [10:54 20/11/2012] 63787F5625EF1D8AD0D4234C5D83036C
C:\Users\User\Documents\škola\3.ročník\ABSOLUTORIA\Absolventka\jednotlivé části\OSNOVA - Rolincová, 3.AV.docx --a---- 14093 bytes [15:51 01/10/2015] [10:14 06/02/2013] 46731A3EBE31310CC236C31723BA7771
C:\Users\User\Documents\škola\3.ročník\ABSOLUTORIA\Absolventka\jednotlivé části\seznam literatury - Rolincová, 3.AV.docx --a---- 18713 bytes [15:51 01/10/2015] [15:44 08/11/2012] 62438568A6822FFE79B78C8D11590801
C:\Users\User\Documents\škola\3.ročník\ABSOLUTORIA\Absolventka\jednotlivé části\úvod - Rolincová, 3.AV.docx --a---- 16016 bytes [15:51 01/10/2015] [07:12 20/03/2013] A447ECF98295BA2A6AA0208A1B70F96B
C:\Users\User\Documents\škola\3.ročník\I.semestr\Seminář k AP\Oponentský posudek - Rolincová, 3.AV.doc --a---- 36864 bytes [15:51 01/10/2015] [14:31 28/11/2012] ECA4C4625E0823024687D21982C794DE
C:\Users\User\Documents\škola\3.ročník\I.semestr\Supervize\SUPERVIZE – Rolincová 3.AV.docx --a---- 13181 bytes [15:51 01/10/2015] [16:34 08/11/2012] B07270B47248B0994D04304CE254E21E
C:\Users\User\Documents\škola\3.ročník\I.semestr\TRH\TRH - Rolincová, Smíšková, 3.AV.docx --a---- 12520 bytes [15:51 01/10/2015] [08:09 04/12/2012] ABBB5E6F5EC5E1BDCC60D3EB7FCA4B50

========== regfind ==========

Searching for "Rolincová"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AccountPicture]
"LastName"="Rolincová"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DFP\Environment]
"rolincová"="?lastname?"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI]
"LastLoggedOnDisplayName"="Petra Rolincová"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData\1]
"LoggedOnDisplayName"="Petra Rolincová"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData\2]
"LoggedOnDisplayName"="Petra Rolincová"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CMSS INVOZ\cust]
"JmenoPrijmeni"="Petra Rolincová"
[HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\Petra.rolincova@cmss-oz.cz\S-1-5-21-789525210-3307182626-2393355962-1001]
"DisplayName"="Petra Rolincová"
[HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\Petra.rolincova@cmss-oz.cz\S-1-5-21-789525210-3307182626-2393355962-1001]
"LastName"="Rolincová"
[HKEY_USERS\S-1-5-21-789525210-3307182626-2393355962-1001\Software\Microsoft\Windows\CurrentVersion\AccountPicture]
"LastName"="Rolincová"
[HKEY_USERS\S-1-5-18\Software\Microsoft\IdentityCRL\StoredIdentities\Petra.rolincova@cmss-oz.cz\S-1-5-21-789525210-3307182626-2393355962-1001]
"DisplayName"="Petra Rolincová"
[HKEY_USERS\S-1-5-18\Software\Microsoft\IdentityCRL\StoredIdentities\Petra.rolincova@cmss-oz.cz\S-1-5-21-789525210-3307182626-2393355962-1001]
"LastName"="Rolincová"

========== folderfind ==========

Searching for "*Rolincová*"
C:\Users\User\Desktop\LIŠKA\úvěry-složky\Rolincová Petra úvěr d------ [15:24 01/10/2015]
C:\Users\User\Desktop\LIŠKA\úvěry-složky\Rolincová Petra úvěr\Rolincová Petra pojistky k Mú d------ [15:24 01/10/2015]

-= EOF =-

Re: Virus - trojský kůň

Napsal: 13 lis 2015 18:42
od Márty84
Tohle mi moc nepomohlo, nejake registry tam jsou, ale nevim, cemu ta hlaska patri, takze nevim, co vypnout. Kdyz smaznu vsechno, muze neco prestat fungovat.


Vyzkousejte, jestli se ta hlaska objevi i v nouzovem rezimu.


Pokud ano, zkuste spravce uloh spustit tam, bude tam toho min. Hlavne ty aplikace a procesy. Kdyz se tam neobjevi, zkuste znovu ten normalni rezim. Kdyztak par minut pockejte, az pocitac poradne nabehne. Melo by se to ustalit a nebude to tak preskakovat. Pripadne to nechte seradit treba podle abecedy...

Re: Virus - trojský kůň

Napsal: 13 lis 2015 19:12
od P-e-tula
Moc mě to mrzí, ale vyskytl se další problém. Při spuštění v nouzovém režimu mi nefunguje mé přihlašovací heslo do účtu. Nouzový režim tedy nejsem schopná spustit. :(

Re: Virus - trojský kůň

Napsal: 13 lis 2015 19:16
od cernohous13
Zdravím,

než se Márty vrátí a bude pokračovat můžeš zkusit v SystemLooku tento script?
:regfind
*.vbs

Re: Virus - trojský kůň

Napsal: 13 lis 2015 19:20
od P-e-tula
SystemLook 30.07.11 by jpshortstuff
Log created at 19:19 on 13/11/2015 by User
Administrator - Elevation successful

========== regfind ==========

Searching for "*.vbs"
No data found.

-= EOF =-