[2010.10.18 21:44:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\Extensions
[2012.10.25 22:45:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions
[2010.10.19 13:26:00 | 000,000,000 | ---D | M] (QipAuthorizer) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2012.08.29 10:30:43 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012.08.21 11:06:06 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.08.22 14:16:42 | 000,000,000 | ---D | M] (MyAshampoo Community Toolbar) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2012.02.24 11:05:53 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.31 18:37:38 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\
engine@conduit.com
[2012.09.17 21:40:30 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\
foxmarks@kei.com
[2010.10.18 21:48:17 | 000,000,000 | ---D | M] (Noia 2.0 eXtreme OPT) -- C:\Users\denosek\AppData\Roaming\mozilla\Firefox\Profiles\4brtbfr2.default\extensions\
noia2_option@kk.noia
[2012.01.14 17:15:44 | 000,126,555 | ---- | M] () (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\extensions\
Noia4Options@ArisT2.xpi
[2012.10.25 22:45:02 | 000,065,957 | ---- | M] () (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\extensions\
NoiaFoxoption@davidvincent.tld.xpi
[2012.05.29 09:24:19 | 000,009,880 | ---- | M] () (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\extensions\
togglepersona@davidvincent.tld.xpi
[2012.10.25 22:45:02 | 002,278,298 | ---- | M] () (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi
[2012.09.26 09:51:52 | 000,061,406 | ---- | M] () (No name found) -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2012.04.17 23:39:24 | 000,000,935 | ---- | M] () -- C:\Users\denosek\AppData\Roaming\mozilla\firefox\profiles\4brtbfr2.default\searchplugins\conduit.xml
[2012.10.29 11:24:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.10.29 11:24:58 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.04.13 20:24:08 | 000,002,046 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\firmycz.xml
[2012.09.08 22:48:19 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.09.08 22:48:19 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.10.22 00:36:19 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2010.04.13 20:24:30 | 000,002,041 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mapycz.xml
[2012.09.08 22:48:19 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.09.08 22:48:19 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.09.08 22:48:19 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2010.04.13 20:24:54 | 000,002,207 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\zbocz.xml
========== Chrome ==========
CHR - homepage:
http://search.conduit.com/?ctid=CT30722 ... hSource=48
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url =
http://search.conduit.com/Results.aspx? ... =CT3072253
CHR - default_search_provider: suggest_url =
http://search.conduit.com/
CHR - homepage:
http://search.conduit.com/?ctid=CT30722 ... hSource=48
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\denosek\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U16 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\denosek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\denosek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\denosek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\denosek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: uTorrentControl2 = C:\Users\denosek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\
CHR - Extension: Gmail = C:\Users\denosek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012.02.02 08:24:48 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found.
O3 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..\Toolbar\WebBrowser: (no name) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - No CLSID value found.
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1176429872-680437442-246994520-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\denosek\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([]https in Trusted sites)
O15 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..Trusted Domains: mojebanka.cz ([]https in Trusted sites)
O15 - HKU\S-1-5-21-1176429872-680437442-246994520-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5939B29F-0DF1-4471-B01B-77A6E23D0BD1}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B6FF19D4-6C66-4FDC-AEF4-73530C0CD80E}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.10.29 18:23:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\denosek\Desktop\OTL.exe
[2012.10.29 11:24:18 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.10.29 11:05:03 | 000,687,724 | R--- | C] (Swearware) -- C:\Users\denosek\Desktop\dds.exe
[2012.10.29 09:51:36 | 000,000,000 | R--D | C] -- C:\Users\denosek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9
========== Files - Modified Within 7 Days ==========
[2012.10.29 19:17:15 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.10.29 18:54:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.29 18:45:01 | 000,000,970 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000UA.job
[2012.10.29 18:34:01 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.29 18:23:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\denosek\Desktop\OTL.exe
[2012.10.29 11:05:14 | 000,687,724 | R--- | M] (Swearware) -- C:\Users\denosek\Desktop\dds.exe
[2012.10.29 09:58:26 | 000,010,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 09:58:26 | 000,010,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 09:55:28 | 000,687,030 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.10.29 09:55:28 | 000,667,896 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.10.29 09:55:28 | 000,652,638 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.10.29 09:55:28 | 000,148,158 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.10.29 09:55:28 | 000,140,632 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.10.29 09:55:28 | 000,021,218 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.10.29 09:51:21 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.29 09:51:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.29 09:51:07 | 2616,643,584 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.24 05:45:00 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000Core.job
========== Files Created - No Company Name ==========
[2012.05.31 18:55:30 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.12.04 17:10:39 | 000,038,433 | ---- | C] () -- C:\Users\denosek\AppData\Roaming\Hodnoty oddělené čárkami (Windows).ADR
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.11 13:06:51 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2011.01.11 22:10:28 | 000,014,336 | ---- | C] () -- C:\Users\denosek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.12.31 13:40:23 | 000,071,096 | ---- | C] () -- C:\Windows\System32\NMSAccessU.exe
[2010.12.31 13:40:23 | 000,017,408 | ---- | C] () -- C:\Windows\System32\SyncBackPro.dll
[2010.11.24 20:49:10 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.11.20 14:16:39 | 000,000,840 | ---- | C] () -- C:\Users\denosek\AppData\Local\SRDownloader.nast
[2010.11.20 14:16:10 | 000,000,046 | ---- | C] () -- C:\Users\denosek\AppData\Local\SRDownloader.err
[2010.10.28 14:28:29 | 000,000,024 | ---- | C] () -- C:\Users\denosek\AppData\Roaming\AVSDVDPlayer.m3u
[2010.10.19 10:41:17 | 000,000,088 | RHS- | C] () -- C:\ProgramData\8E6BEC914D.sys
[2010.10.19 10:41:16 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2010.11.07 00:13:55 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\.Torrent Swapper
[2011.12.26 02:06:54 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Ashampoo
[2011.05.17 19:35:39 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Audacity
[2012.04.12 16:17:55 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Broad Intelligence
[2010.11.11 08:49:54 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\BullGuard
[2012.07.29 12:28:51 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DAEMON Tools Lite
[2012.02.24 11:08:11 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DVDVideoSoft
[2012.02.24 11:05:53 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.10.19 10:06:27 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\GHISLER
[2012.02.01 16:09:59 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\go
[2010.10.19 13:40:00 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\ICQ
[2012.06.06 20:16:36 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\ImgBurn
[2010.10.19 13:54:36 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\InterVideo
[2012.05.11 09:27:04 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Jpeg Resampler
[2010.12.28 18:39:52 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\kikin
[2010.12.31 15:20:16 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Passware
[2010.10.26 21:10:46 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\PowerCinema
[2010.10.19 13:26:08 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\QIP
[2011.05.01 20:34:47 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.10.29 08:49:31 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\uTorrent
[2010.10.18 22:09:42 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\VitySoft
[2012.02.01 08:27:26 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Yandex
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 05:53:46 | 000,032,608 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 05:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.06.12 10:01:42 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.09.11 22:29:30 | 000,000,936 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.09.11 22:29:31 | 000,000,940 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.09.20 05:40:19 | 000,000,918 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000Core.job
[2012.09.20 05:40:20 | 000,000,970 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000UA.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\System32\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\drivers\cdrom.sys
[2009.07.14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_db87d184bc84f910\cdrom.sys
[2009.07.14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_5f7fb206051affbb\cdrom.sys
[2010.11.20 09:38:10 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys
[2010.11.20 09:38:10 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\ERDNT\cache\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.20 13:29:53 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_ad305c8fb7ec5060\hal.dll
[2010.11.20 13:29:53 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_ad305c8fb7ec5060\hal.dll
[2009.07.14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\System32\hal.dll
[2009.07.14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_aaff48c7bafdccc6\hal.dll
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\ERDNT\cache\services.exe
[2009.07.14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009.07.14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
< MD5 for: TCPIP.SYS >
[2011.04.25 05:56:06 | 001,286,016 | ---- | M] (Microsoft Corporation) MD5=0158D5E9982E9D6A90DFC802F618E130 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_b347f075c77b9c9d\tcpip.sys
[2011.06.21 06:34:23 | 001,290,624 | ---- | M] (Microsoft Corporation) MD5=04E4A7D53A7ACE02E8C55B17A498F631 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_b513df73c4b4f466\tcpip.sys
[2011.09.29 17:02:44 | 001,301,872 | ---- | M] (Microsoft Corporation) MD5=22F7E7CBCA308DEE3428B097D4F8A61C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_b38e8546e0cbe4a1\tcpip.sys
[2011.04.25 05:31:30 | 001,290,624 | ---- | M] (Microsoft Corporation) MD5=24326784DF8F3D5F5BBB9F878CE33C14 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_b52f4dc5c4a121e0\tcpip.sys
[2009.07.14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_b2f46875c7b9d667\tcpip.sys
[2010.11.20 13:30:12 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys
[2010.11.20 13:30:12 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys
[2011.09.29 17:17:18 | 001,303,920 | ---- | M] (Microsoft Corporation) MD5=3C1C41E317710F74CEC1E7F0D5325993 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_b5a84e10ddca7566\tcpip.sys
[2012.03.30 11:29:05 | 001,287,024 | ---- | M] (Microsoft Corporation) MD5=55E9965552741F3850CB22CBBA9671ED -- C:\Windows\System32\drivers\tcpip.sys
[2012.03.30 11:29:05 | 001,287,024 | ---- | M] (Microsoft Corporation) MD5=55E9965552741F3850CB22CBBA9671ED -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_b2f57423c7b8dea8\tcpip.sys
[2011.09.29 16:43:37 | 001,285,488 | ---- | M] (Microsoft Corporation) MD5=56C198AC82EFA622DD93E9E43575F79C -- C:\Windows\ERDNT\cache\tcpip.sys
[2011.09.29 16:43:37 | 001,285,488 | ---- | M] (Microsoft Corporation) MD5=56C198AC82EFA622DD93E9E43575F79C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_b2f8731bc7b62d86\tcpip.sys
[2010.04.09 08:16:33 | 001,289,096 | ---- | M] (Microsoft Corporation) MD5=5D6A83E928F22AF5AC9868B162FFAD0D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20687_none_b38009a0e0d5a32d\tcpip.sys
[2010.04.09 08:24:54 | 001,285,000 | ---- | M] (Microsoft Corporation) MD5=63170B9EE1D0EF0032F0408605671D1A -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16569_none_b30e0d41c7a5fe2f\tcpip.sys
[2011.09.29 17:03:04 | 001,290,608 | ---- | M] (Microsoft Corporation) MD5=65D10B191C59C5501A1263FC33F6894B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_b4d1ffa1c4e682b5\tcpip.sys
[2011.04.25 07:31:09 | 001,301,376 | ---- | M] (Microsoft Corporation) MD5=6D4728CFF2724FF3A4654971D61D0F1C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_b5ad1a5addc7c444\tcpip.sys
[2012.03.30 11:23:11 | 001,291,632 | ---- | M] (Microsoft Corporation) MD5=7FA2E0F8B072BD04B77B421480B6CC22 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_b52e5147c4a202d7\tcpip.sys
[2011.04.25 05:44:18 | 001,298,816 | ---- | M] (Microsoft Corporation) MD5=8861B9A06BA99C6E1D62D0C86DFAB86C -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_b39a7d5ae0c2aec5\tcpip.sys
[2012.03.30 10:04:23 | 001,306,480 | ---- | M] (Microsoft Corporation) MD5=88FCDB9923EFECA207B3CEBD24407126 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_b583df0adde66104\tcpip.sys
[2011.06.21 06:30:45 | 001,301,376 | ---- | M] (Microsoft Corporation) MD5=93C444D118B184452132357C322124CD -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_b3703df4e0e237e0\tcpip.sys
[2010.06.14 07:06:58 | 001,288,576 | ---- | M] (Microsoft Corporation) MD5=A39EA325C081AD27461F630C8E3E56E0 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_b3b219fae0b0af43\tcpip.sys
[2010.06.14 07:12:30 | 001,286,016 | ---- | M] (Microsoft Corporation) MD5=BB7F39C31C4A4417FD318E7CD184E225 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_b33b1c29c7858b92\tcpip.sys
[2011.06.21 06:39:53 | 001,286,016 | ---- | M] (Microsoft Corporation) MD5=C2DAAEB48F3A47C410B041A0D2382EE1 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_b32e82b7c78da1d1\tcpip.sys
[2011.06.21 07:54:00 | 001,303,424 | ---- | M] (Microsoft Corporation) MD5=DEC4940487050AE13C60C86F40E07E75 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_b583db3edde666b6\tcpip.sys
[2012.03.30 11:08:19 | 001,303,408 | ---- | M] (Microsoft Corporation) MD5=E47C2844A1605A44178F4281E4D58B3D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_b38bb990e0ccc871\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\ERDNT\cache\winlogon.exe
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< >
< %systemroot%*.* /U /s >
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[287 C:\Windows\temp\*.tmp files -> C:\Windows\temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.11.07 00:13:55 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\.Torrent Swapper
[2011.05.04 06:35:51 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Adobe
[2011.05.01 20:34:47 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Adobe Mini Bridge CS5
[2011.12.26 02:06:54 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Ashampoo
[2011.05.17 19:35:39 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Audacity
[2012.04.12 16:17:55 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Broad Intelligence
[2010.11.11 08:49:54 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\BullGuard
[2010.10.26 21:41:26 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Corel
[2010.12.31 14:58:49 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\CyberLink
[2012.07.29 12:28:51 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DAEMON Tools Lite
[2012.01.15 23:31:02 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\dvdcss
[2012.02.24 11:08:11 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DVDVideoSoft
[2012.02.24 11:05:53 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.10.19 10:06:27 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\GHISLER
[2012.02.01 16:09:59 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\go
[2010.10.19 13:40:00 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\ICQ
[2010.10.18 21:35:15 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Identities
[2012.06.06 20:16:36 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\ImgBurn
[2010.10.19 13:54:36 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\InterVideo
[2012.05.11 09:27:04 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Jpeg Resampler
[2010.12.28 18:39:52 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\kikin
[2010.10.19 09:35:02 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Macromedia
[2009.07.14 09:56:41 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Media Center Programs
[2012.06.12 10:02:01 | 000,000,000 | --SD | M] -- C:\Users\denosek\AppData\Roaming\Microsoft
[2012.10.10 20:45:44 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Mozilla
[2012.05.31 20:02:09 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Nero
[2010.12.31 15:20:16 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Passware
[2010.10.26 21:10:46 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\PowerCinema
[2010.10.19 13:26:08 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\QIP
[2011.02.13 00:35:13 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Real
[2012.10.29 09:31:38 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Skype
[2011.11.17 18:46:11 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\skypePM
[2011.05.01 20:34:47 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.02.02 07:51:31 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\SUPERAntiSpyware.com
[2012.10.29 08:49:31 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\uTorrent
[2010.10.18 22:09:42 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\VitySoft
[2012.08.30 19:06:51 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\vlc
[2012.10.29 08:49:31 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Winamp
[2010.10.18 22:29:59 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\WinRAR
[2012.02.01 08:27:26 | 000,000,000 | ---D | M] -- C:\Users\denosek\AppData\Roaming\Yandex
< %APPDATA%\*.exe /s >
[2010.12.28 18:39:59 | 001,166,568 | ---- | M] () -- C:\Users\denosek\AppData\Roaming\kikin\kikin_updater_2.9.1.exe
[2010.12.31 14:45:27 | 000,367,686 | R--- | M] () -- C:\Users\denosek\AppData\Roaming\Microsoft\Installer\{FEBED6FC-140F-43F6-8CB5-D3C0EB0F3D66}\icon.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2012.10.29 18:54:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.10.29 09:51:21 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.10.29 19:34:07 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.10.24 05:45:00 | 000,000,918 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000Core.job
[2012.10.29 19:45:00 | 000,000,970 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1176429872-680437442-246994520-1000UA.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.10.29 09:58:26 | 000,010,096 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 09:58:26 | 000,010,096 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 09:55:28 | 000,140,632 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2012.10.29 09:55:28 | 000,148,158 | ---- | M] () -- C:\Windows\system32\perfc007.dat
[2012.10.29 09:55:28 | 000,021,218 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2012.10.29 09:55:28 | 000,667,896 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2012.10.29 09:55:28 | 000,687,030 | ---- | M] () -- C:\Windows\system32\perfh007.dat
[2012.10.29 09:55:28 | 000,652,638 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2012.10.29 09:55:28 | 002,306,364 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Google Update" = "C:\Users\denosek\AppData\Local\Google\Update\GoogleUpdate.exe" /c -- [2011.10.16 20:00:20 | 000,136,176 | ---- | M] (Google Inc.)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2011.11.10 10:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.10.29 11:24:57 | 000,917,984 | ---- | M] (Mozilla Corporation) MD5=E60E9D5F229CB8DA347D48ADD6E8DC47 -- C:\Program Files\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.08.24 18:15:32 | 000,672,872 | ---- | M] (Microsoft Corporation) MD5=4ADB84297505A1627DEEA18529BF4B16 -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2012.10.10 11:06:17 | 001,239,064 | ---- | M] (Google Inc.) MD5=848D034D067BE2FF5CD3D779BECBDA00 -- C:\Program Files\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.10.29 19:17:15 | 000,000,512 | ---- | M] () MD5=21FBD41E635222B83511AEEBA3A813F6 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2011.08.28 21:02:26 | 008,495,245 | ---- | M] () -- \Install\auto\Disco hity\Amnezia Super Hits 62\Cd 1\13. Dj Neo ft. Martina Balogova - Just Another Crack (Radio Edit).mp3
[2012.10.29 18:03:37 | 000,004,412 | ---- | M] () -- \Program Files\JDownloader\jd\plugins\hoster\CrackedCom.class
[2000.08.08 22:06:26 | 000,002,238 | ---- | M] () -- \Program Files\MAMEi\icons\cracksht.ico
[2012.08.05 23:25:45 | 000,791,428 | ---- | M] () -- \Users\denosek\AppData\LocalLow\MyAshampoo\Rss\http___crackle_com_rss_media_sxsw_featured_rss.xml
[2012.07.23 21:51:34 | 000,005,828 | ---- | M] () -- \Users\denosek\AppData\LocalLow\MyAshampoo\Rss\http___crackle_com_rss_media_sxsw_featured_rss_history.xml
[2012.08.05 23:25:45 | 000,010,122 | ---- | M] () -- \Users\denosek\AppData\LocalLow\MyAshampoo\Rss\http___crackle_com_rss_media_sxsw_featured_rss_structured.xml
[2010.10.19 10:51:48 | 000,000,000 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\CT2475029\feed\http___crackle_com_rss_media_sxsw_featured_rss_history.xml
[2010.10.19 10:51:48 | 000,000,000 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\CT2475029\feed\http___crackle_com_rss_media_sxsw_featured_rss_structured.xml
[2004.02.19 06:29:44 | 000,010,420 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_arab_dance.mid
[2004.02.19 06:29:44 | 000,006,682 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_chinese_dance.mid
[2004.02.19 06:29:44 | 000,008,066 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_dance_of_the_sugar.mid
[2004.02.19 06:29:44 | 000,013,452 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_march.mid
[2004.02.19 06:29:46 | 000,011,123 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_reed_flutes.mid
[2004.02.19 06:29:46 | 000,007,861 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\n\nutcracker_suite_-_russian_dance.mid
[2004.02.21 11:29:34 | 000,003,066 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\M_Tjaikovski-Nut_Cracker.mid
[2004.02.21 11:29:34 | 000,008,718 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\RingTones\Arabian Dance Nutcracker Suite (Tchaicovsky).mid
[2004.02.21 11:29:36 | 000,014,902 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\RingTones\Overture Nutcracker Suite (Tchaicovsky).mid
[2004.02.21 11:29:38 | 000,029,237 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\RingTones\Waltz of the Flowers from the Nutcracker Suite.mid
[2004.02.21 11:29:44 | 000,014,902 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\Tones\Overture Nutcracker Suite (Tchaicovsky).mid
[2004.02.21 11:29:50 | 000,003,066 | ---- | M] () -- \Users\denosek\Documents\Veru\Ostatní\disk\melodie\polyphone_midi_ringtones\Very nice polytones\M_Tjaikovski-Nut_Cracker.mid
[2011.08.28 20:02:24 | 008,495,245 | ---- | M] () -- \Users\denosek\Music\Disco\Amnezia Super Hits 62\Cd 1\13. Dj Neo ft. Martina Balogova - Just Another Crack (Radio Edit).mp3
< *keygen* /s >
< *loader* /s >
[2009.11.03 21:48:00 | 000,001,115 | ---- | M] () -- \Install\karta diamond2\NAVIGON\NavLoader.cfg
[2009.08.06 01:38:38 | 000,001,111 | ---- | M] () -- \Install\Navigon\MN7.4.3Build793-PDAv20\NAVIGON\NavLoader.cfg
[2010.11.09 23:29:54 | 005,297,608 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\Photodownloader.exe
[2010.03.09 01:38:58 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2010.03.09 01:38:58 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\de_de\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\en_us\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\es_es\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\it_it\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\no_no\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,308 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2011.07.22 15:12:04 | 002,795,648 | ---- | M] () -- \Program Files\Common Files\DVDVideoSoft\Dll\DVSVideoDownloader.dll
[2006.10.26 12:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 12:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2010.03.18 23:21:56 | 000,063,312 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader80.dll
[2010.03.18 00:17:14 | 000,004,096 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader80.tlb
[2009.07.27 14:49:10 | 000,056,416 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\Koan\pyloader.dll
[2009.07.27 14:49:18 | 002,184,488 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\subsys\CES\CES_3DLoaderFBX.dll
[2009.07.27 14:49:20 | 000,020,284 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\subsys\DataCenter\ImageLoader.kc
[2009.07.13 20:55:20 | 000,010,788 | ---- | M] () -- \Program Files\CyberLink\PowerCinema Movie\mm\MediaCtrl\ImageLoader.kc
[2009.07.13 20:55:22 | 000,003,499 | ---- | M] () -- \Program Files\CyberLink\PowerCinema Movie\Widget\langloader.kc
[2009.07.13 20:55:22 | 000,012,802 | ---- | M] () -- \Program Files\CyberLink\PowerCinema Movie\Widget\layoutloader.kc
[2009.08.11 18:41:32 | 000,058,664 | ---- | M] () -- \Program Files\CyberLink\PowerCinema\Koan\pyloader.dll
[2009.08.11 18:41:46 | 000,011,734 | ---- | M] () -- \Program Files\CyberLink\PowerCinema\System\KernelCtrl\ImageLoader.kc
[2009.08.11 18:41:46 | 000,017,513 | ---- | M] () -- \Program Files\CyberLink\PowerCinema\System\KernelCtrl\ImageLoader2.kc
[2009.08.11 18:41:46 | 000,003,955 | ---- | M] () -- \Program Files\CyberLink\PowerCinema\Widget\langloader.kc
[2009.08.11 18:41:46 | 000,013,982 | ---- | M] () -- \Program Files\CyberLink\PowerCinema\Widget\layoutloader.kc
[2010.11.25 01:16:16 | 000,058,664 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PK\Koan\pyloader.dll
[2010.11.25 01:16:16 | 000,027,657 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PK\subsys\PyImpLoader\PyImpLoader.kc
[2010.11.25 01:16:16 | 000,120,104 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PK\subsys\PyImpLoader\_PyImpLoader.pyd
[2010.11.10 15:03:30 | 000,010,781 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cinema\mm\MediaCtrl\ImageLoader.kc
[2010.11.10 15:03:38 | 000,003,492 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cinema\widget\langloader.kc
[2010.11.10 15:03:38 | 000,013,453 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cinema\widget\layoutloader.kc
[2010.07.15 10:12:06 | 000,010,775 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cox\mm\MediaCtrl\ImageLoader.kc
[2010.07.15 10:12:08 | 000,003,567 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cox\widget\langloader.kc
[2010.07.15 10:12:08 | 000,013,369 | ---- | M] () -- \Program Files\CyberLink\PowerDVD10\PowerDVD Cox\widget\layoutloader.kc
[2009.02.28 22:12:40 | 000,010,789 | ---- | M] () -- \Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\mm\MediaCtrl\ImageLoader.kc
[2009.02.28 22:12:44 | 000,003,500 | ---- | M] () -- \Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\widget\langloader.kc
[2009.02.28 22:12:44 | 000,012,803 | ---- | M] () -- \Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\widget\layoutloader.kc
[2009.02.25 08:13:46 | 002,184,488 | ---- | M] () -- \Program Files\CyberLink\Shared files\Plugin\5.0\CES_3DLoaderFBX.dll
[2009.07.23 20:24:20 | 000,056,416 | ---- | M] () -- \Program Files\CyberLink\YouCam\Koan\pyloader.dll
[2009.07.23 20:22:40 | 000,012,794 | ---- | M] () -- \Program Files\CyberLink\YouCam\subsys\Uploader\PyUploader.kc
[2009.07.23 20:22:40 | 000,162,912 | ---- | M] () -- \Program Files\CyberLink\YouCam\subsys\Uploader\_PyUploader.pyd
[2009.07.23 20:22:40 | 002,475,304 | ---- | M] () -- \Program Files\CyberLink\YouCam\subsys\YouCam\CES_3DLoaderFBX.dll
[2011.07.22 15:28:10 | 000,042,144 | ---- | M] () -- \Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\DVDVideoSoft.DVSVideoDownloader.dll
[2010.10.19 13:40:30 | 000,005,795 | ---- | M] () -- \Program Files\ICQ6.5\Packages\centrum_cz\Skins\centrumSkin\images\XtraPreloader\loader.jpg
[2010.10.19 13:40:30 | 000,004,089 | ---- | M] () -- \Program Files\ICQ6.5\Packages\centrum_cz\Skins\centrumSkin\images\XtraPreloader\loader.swf
[2009.03.01 11:31:26 | 000,005,795 | ---- | M] () -- \Program Files\ICQ6.5\services\icqApp\ver1\theme\IMAGES\XtraPreloader\loader.jpg
[2009.03.01 11:31:26 | 000,004,089 | ---- | M] () -- \Program Files\ICQ6.5\services\icqApp\ver1\theme\IMAGES\XtraPreloader\loader.swf
[2010.10.19 13:40:39 | 000,003,479 | ---- | M] () -- \Program Files\ICQ6.5\services\icqXtraz\ver1\content\contact_list\preloader04.swf
[2010.10.19 13:40:43 | 000,552,798 | ---- | M] () -- \Program Files\ICQ6.5\services\icqXtraz\ver1\theme\game_center\loaderBkg.png
[2010.09.23 13:40:22 | 000,214,528 | ---- | M] () -- \Program Files\JDownloader\JDownloader.exe
[2011.02.27 23:36:49 | 000,593,293 | ---- | M] () -- \Program Files\JDownloader\JDownloader.jar
[2010.11.25 16:43:07 | 000,000,105 | ---- | M] () -- \Program Files\JDownloader\jd\img\hosterlogos\uploader.pl.png
[2012.10.29 17:58:51 | 000,011,071 | ---- | M] () -- \Program Files\JDownloader\jd\plugins\hoster\MyDownloaderNet.class
[2012.10.29 17:57:07 | 000,007,073 | ---- | M] () -- \Program Files\JDownloader\jd\plugins\hoster\UploaderPl.class
[2010.09.23 13:43:06 | 000,032,222 | ---- | M] () -- \Program Files\JDownloader\licenses\jdownloader.license
[2008.12.06 17:13:52 | 000,001,070 | ---- | M] () -- \Program Files\MediaCoder\extensions\_include\loader.html
[2010.09.01 02:36:32 | 000,023,040 | ---- | M] () -- \Program Files\Microsoft Expression\Blend 4\Microsoft.VisualStudio.AssetSystem.Loader.dll
[2010.03.15 11:28:24 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2010.11.25 16:41:48 | 000,000,362 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader Support.lnk
[2010.11.25 16:41:48 | 000,001,097 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader.lnk
[2010.11.25 16:41:55 | 000,001,087 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader\Uninstall JDownloader.lnk
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.06.03 21:48:35 | 049,817,600 | ---- | M] () -- \Stahovani\The.Cold.Light.of.Day.2012.CAM.XviD-M2D.by.Colly.of.PowerUploaders.avi.part
[2010.11.24 15:49:10 | 000,019,456 | ---- | M] () -- \Symbols\api-ms-win-core-libraryloader-l1-1-0.pdb\1B6430CDAA0F4F9595D61A14DAC4BA7E1\api-ms-win-core-libraryloader-l1-1-0.pdb
[2010.11.24 16:33:16 | 000,019,456 | ---- | M] () -- \Symbols\api-ms-win-core-libraryloader-l1-1-0.pdb\2300785E90B14164A36E5313768857AC1\api-ms-win-core-libraryloader-l1-1-0.pdb
[2010.11.24 16:34:10 | 000,068,608 | ---- | M] () -- \Symbols\dmloader.pdb\379A946DCA164B9590851C83ECD5F32E1\dmloader.pdb
[2010.11.24 15:47:06 | 000,084,992 | ---- | M] () -- \Symbols\dmloader.pdb\D89614FF5A014881A633E4C36475583E1\dmloader.pdb
[2010.11.24 16:18:22 | 000,338,944 | ---- | M] () -- \Symbols\upgloader.pdb\0FDFD25BCFF049B8B318AC857832AFB21\upgloader.pdb
[2010.11.24 15:32:18 | 000,363,520 | ---- | M] () -- \Symbols\upgloader.pdb\FEECA36D9E05491CAA7622D4DB53B05D1\upgloader.pdb
[2010.11.25 16:41:48 | 000,000,362 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader Support.lnk
[2010.11.25 16:41:48 | 000,001,097 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader.lnk
[2010.11.25 16:41:55 | 000,001,087 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\JDownloader\Uninstall JDownloader.lnk
[2012.06.18 11:39:40 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.06.18 11:39:40 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2010.11.20 14:16:10 | 000,000,046 | ---- | M] () -- \Users\denosek\AppData\Local\SRDownloader.err
[2010.11.20 14:22:41 | 000,000,840 | ---- | M] () -- \Users\denosek\AppData\Local\SRDownloader.nast
[2012.07.04 06:51:35 | 000,000,673 | ---- | M] () -- \Users\denosek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\ajax-loader.gif
[2011.12.24 23:34:09 | 000,057,728 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png
[2011.12.24 23:34:11 | 000,057,728 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png
[2011.12.24 23:34:12 | 000,057,728 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png
[2011.12.24 23:34:14 | 000,057,728 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin3\dt_dadget_loader.png
[2011.12.24 23:34:15 | 000,057,728 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin4\dt_dadget_loader.png
[2011.12.24 23:34:16 | 000,061,770 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin5\dt_dadget_loader.png
[2011.12.24 23:34:17 | 000,061,770 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin6\dt_dadget_loader.png
[2012.10.29 09:26:53 | 000,000,753 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9QFN0F41\AdLoader[1].htm
[2012.10.29 09:26:53 | 000,105,903 | ---- | M] () -- \Users\denosek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZKWE4NEK\AdLoader-427d9fd2a91e2f2c023aefe9f69a01d0.min[1].js
[2010.11.25 17:04:22 | 000,000,997 | ---- | M] () -- \Users\denosek\AppData\Roaming\Microsoft\Internet Explorer\JDownloader.lnk
[2012.04.17 23:39:24 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\conduitCommon\modules\3.12.0.8\ExternalLibraryLoader.jsm
[2012.05.03 18:54:14 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\conduitCommon\modules\3.12.2.3\ExternalLibraryLoader.jsm
[2012.05.30 07:43:28 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\conduitCommon\modules\3.13.0.6\ExternalLibraryLoader.jsm
[2012.07.16 22:09:06 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\conduitCommon\modules\3.14.1.0\ExternalLibraryLoader.jsm
[2012.08.27 16:56:10 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\conduitCommon\modules\3.15.1.0\ExternalLibraryLoader.jsm
[2012.08.27 16:56:10 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\modules\ExternalLibraryLoader.jsm
[2012.08.21 09:55:30 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\modules\ExternalLibraryLoader.jsm
[2012.08.21 17:00:04 | 000,010,145 | ---- | M] () -- \Users\denosek\AppData\Roaming\Mozilla\Firefox\Profiles\4brtbfr2.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\modules\ExternalLibraryLoader.jsm
[2010.11.15 02:06:58 | 006,162,055 | ---- | M] () -- \Users\denosek\Downloads\Freerapid-Downloader_0.83u1.zip
[2010.11.25 16:40:48 | 029,100,879 | ---- | M] () -- \Users\denosek\Downloads\JDownloader_WIN_Setup.zip
[2009.08.13 16:17:57 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2012.05.13 21:11:40 | 000,083,456 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\9cbddfcee12d09b6101cab70831c391d\Microsoft.VisualStudio.AssetSystem.Loader.ni.dll
[2012.10.29 18:03:53 | 000,013,208 | ---- | M] () -- \Windows\Prefetch\JDOWNLOADER.EXE-630521E0.pf
[2010.11.20 07:28:20 | 000,002,838 | ---- | M] () -- \Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.17514_fi-fi_178685823786d34d.manifest
[2010.11.20 07:38:52 | 000,002,838 | ---- | M] () -- \Windows\SoftwareDistribution\Download\033b0c7c2634a2c344c62aab1ebcd6ad\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.17514_zh-cn_d8268e5f2967c990.manifest
[2010.11.20 06:28:20 | 000,002,838 | ---- | M] () -- \Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.17514_fi-fi_178685823786d34d.manifest
[2010.11.20 06:38:52 | 000,002,838 | ---- | M] () -- \Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.17514_zh-cn_d8268e5f2967c990.manifest
[2010.11.20 04:02:40 | 000,004,225 | ---- | M] () -- \Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2012.08.18 12:09:17 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.07.14 05:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2010.10.18 21:58:58 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2010.10.18 21:58:58 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winload.exe.mui_3bc5b827
[2010.10.18 21:58:58 | 000,030,272 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winresume.exe.mui_ff8b5358
[2009.07.14 09:47:30 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_de-de_cd7e3a305679601f.manifest
[2009.07.14 09:47:30 | 000,035,920 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_de-de_cd7e3a305679601f_winload.exe.mui_3bc5b827
[2009.07.14 09:47:30 | 000,030,800 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_de-de_cd7e3a305679601f_winresume.exe.mui_ff8b5358
[2010.10.19 09:29:52 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16411_none_5b44c087cdc549ed.manifest
[2010.10.19 09:29:53 | 000,507,568 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16411_none_5b44c087cdc549ed_winload.exe_75835076
[2010.10.19 09:29:53 | 000,442,920 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16411_none_5b44c087cdc549ed_winresume.exe_85cd1215
[2009.07.14 03:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 03:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2010.10.18 21:55:56 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2009.07.14 09:46:47 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_de-de_cd7e3a305679601f.manifest
[2009.07.14 02:47:46 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_5afd1055cdfa75b9.manifest
[2009.08.19 08:38:48 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16411_none_5b44c087cdc549ed.manifest
[2009.08.19 08:21:21 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20509_none_5be12f8ee6d3987e.manifest
[2010.11.20 05:02:40 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2009.07.14 02:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.05.14 07:22:35 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16816_none_0ad4ff55dce9d030\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.02 06:45:50 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16823_none_0ac72e8bdcf4a01c\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:19:58 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_0aa3bde9dd0fa7ea\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.18 12:09:17 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17107_none_0ae0ab79dce0fb26\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 06:50:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.20978_none_0b1fbd2cf6364a4e\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:12:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_0b587286f60d0b32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.20 18:42:56 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21306_none_0b6949e0f5ff7ec0\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.05.14 07:13:36 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17617_none_0cbc5ca5da0f5573\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 06:47:28 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_0caf8c25da193eb6\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:15:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.20 18:32:13 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17932_none_0ca1c10dda240617\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.05.14 08:15:40 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21728_none_0d3c29cef3342a85\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 07:56:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_0d3159e2f33c4676\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.20 18:23:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22091_none_0ce95442f3736a4b\api-ms-win-core-libraryloader-l1-1-0.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\Windows:975DF3EB93190650
< End of report >