Slow download speed, some sites are very slow

Hello, I am facing a problem with downloading and some sites. Tried to run MBAM but can't download updates, so I can't run scan. AVG has not found anything.

Downloading is very slow and some sites take about 5 minutes to load. I noticed these problems maybe a week ago, but thought it is some problem on my internet provider's side.

There are logs from FRST and RSIT.



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2019 

Ran by SWAN (administrator) on PC (MSI MS-7721) (31-03-2020 13:39:49)

Running from C:\Users\SWAN\Desktop

Loaded Profiles: SWAN (Available Profiles: SWAN)

Platform: Windows 10 Pro Version 1809 17763.1098 (X64) Language: Čeština (Česko)

Default browser: Chrome

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool:


==================== Processes (Whitelisted) =================


(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)


() [File not signed] C:\Program Files (x86)\MSI\ControlCenter\Sleep\MSISleepService.exe

(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe

(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe

(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe

(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(AVG Netherlands B.V. -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\\AVGBrowserCrashHandler.exe

(AVG Netherlands B.V. -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\\AVGBrowserCrashHandler64.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe

(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe

(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe

(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe

(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe

(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe

(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe

(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe

(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe

(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe

(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe

(MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe

(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe


==================== Registry (Whitelisted) ===================


(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)


HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270560 2019-05-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)

HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [325704 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)

HKLM-x32\...\Run: [ControlCenterCount] => C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.) [File not signed]

HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1028280 2017-11-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [Gaijin.Net Agent] => C:\Users\SWAN\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2125384 2018-09-25] (Gaijin Network LTD -> Gaijin Entertainment)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILQE.EXE [297024 2013-01-24] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILQE.EXE [297024 2013-01-24] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [Spotify] => C:\Users\SWAN\AppData\Roaming\Spotify\Spotify.exe [22825376 2020-03-15] (Spotify AB -> Spotify Ltd)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3365840 2020-02-11] (Valve -> Valve Corporation)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [Reference 4 Systemwide] => C:\Program Files\Sonarworks\Reference 4\Systemwide\Reference 4 Systemwide.exe [14890480 2019-06-07] (Sonarworks, SIA -> Sonarworks) [File not signed]

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation -> AppEx Networks Corporation)

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Policies\Explorer: [NoResolveSearch] 1

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\...\Policies\Explorer: [NoInternetOpenWith] 1

HKU\S-1-5-21-2071813083-1845976314-806757171-1000\Sortware\Policies\...\system: [disablecmd] 0

HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-19] (Google LLC -> Google LLC)

HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\80.0.3623.134\Installer\chrmstp.exe [2020-03-19] (AVG Technologies USA, LLC -> AVG Technologies)

HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> 

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2019-04-15] () [File not signed]

FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

CHR HKU\.DEFAULT\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

CHR HKU\S-1-5-21-2071813083-1845976314-806757171-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION


==================== Scheduled Tasks (Whitelisted) ============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


Task: {00DC2D35-E5CC-46BE-BCCE-3D5FF6D6DD4C} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe

Task: {01235679-AA05-40EE-BDAA-0CE062C3DE01} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [3942704 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

Task: {03DF4745-4E63-4BCE-BE64-313E94274BB4} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {03E427EE-F537-49B6-95BA-AE27E74A057C} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}

Task: {06E0408D-865F-4968-931B-994B8A870FD5} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {0C85FD5E-8479-4CE1-9918-A658746D084D} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {274E6A60-04E7-45F1-9AF5-8720A3227BE2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-05] (Piriform Software Ltd -> Piriform Software Ltd)

Task: {3610F1EF-E32C-483F-85CA-1D27648C002F} - System32\Tasks\{996C2E56-CF8D-42B1-8BB4-5B25693FCF2F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\unIosales\3xzfRV2iP452n4.exe" -c /s /n /i:"ExecuteCommands;UninstallCommands" ""

Task: {36663483-C447-491B-AAB5-9CDD36E148E9} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [1871496 2020-03-09] (AVG Technologies USA, LLC -> AVG Technologies)

Task: {38A7E5EB-5BDB-44A5-A0CB-8611C403C98B} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}

Task: {455FAF33-2070-4804-969D-5174EB082EAD} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB}

Task: {4FB12AAE-257E-4B64-8BA6-8AA0222CDF81} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}

Task: {528933E0-C10D-4157-8589-EE21C8C994A9} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}

Task: {5504F1AB-5B21-4F39-938A-784E9A93FB81} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {578A7634-3F17-4AFA-B002-953AC917BA64} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [1871496 2020-03-09] (AVG Technologies USA, LLC -> AVG Technologies)

Task: {589DAEB1-19D3-4B07-A658-460B9CFF60D7} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}

Task: {61E8D464-6C98-4658-B87B-448552DE725E} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1692296 2020-02-27] (AVG Technologies USA, LLC -> AVG Technologies)

Task: {64F0B012-C0A9-4289-BDE1-FC6FB75EC1BB} - System32\Tasks\{466120E4-8C8C-4E51-8B69-F46BFC8B4EEF} => C:\Windows\system32\pcalua.exe -a E:\Autorun.exe -d E:\

Task: {6959ABD3-1070-4FD9-8744-3DF8A135BFD0} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {69A88827-1A8C-4D96-A3C2-793E4AC49E3C} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_270_pepper.exe [1453112 2019-10-09] (Adobe Inc. -> Adobe)

Task: {6B46E3AA-A48A-4458-AC9D-6B57044B8A63} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)

Task: {7082DA51-DA86-4FD1-A98B-07CA0B6DE8CD} - System32\Tasks\Safer-Networking\Spybot Anti-Beacon\Refresh Anti-Beacon immunization => C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\Spybot3AntiBeacon.exe [8969432 2019-08-29] (Safer-Networking Ltd. -> )

Task: {71C551CB-1657-4835-A13C-87E4D16F0EA9} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {76EF653B-6228-4BB0-AA24-D6509BEE3D4D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-10-09] (Adobe Inc. -> Adobe)

Task: {7782C681-6BDF-43A8-B682-EBD5E7870393} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

Task: {89336325-52D8-40E6-901A-5DDE8395BC42} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe

Task: {8AD212BB-6785-46E3-A683-8C6DA2D9E641} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {8C5E4BFF-60F7-452D-8991-04DAF349CB0A} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {8CAC1675-DDDF-49A2-A52F-FEF4B92CDC33} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [165520 2018-11-02] (AVG Netherlands B.V. -> AVG Technologies)

Task: {8D4736F8-A8B2-431D-8009-AFAFB642F929} - System32\Tasks\EPSON XP-610 Series Update {F046D536-3200-4F23-BAD7-73FA9472B4DD} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

Task: {8EA7FB19-561A-43A7-AD47-8CFDA5D00CEF} - System32\Tasks\{C3E3F5FC-6C4D-4BEB-AFB6-6E0AF263B50A} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\HD-V1.9\Uninstall.exe" -c /fcp=1

Task: {8F71AC29-E88F-403F-9659-0A8B5ABF81A4} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe

Task: {95606B13-9A48-4726-B5ED-AE5A404C402D} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK

Task: {975CA11C-29B2-479B-8CCA-10CBACDCE9BD} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

Task: {9FCB9B0A-1605-4542-AB35-1D9C8074E1F6} - System32\Tasks\EPSON XP-610 Series Invitation {F046D536-3200-4F23-BAD7-73FA9472B4DD} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

Task: {A288DD09-6487-43C8-BB4D-12C0F2584A73} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe

Task: {A2FE3E52-3986-48F0-9AE0-EA2AA5A1CF14} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}

Task: {A6132231-63DC-4B7E-989A-7F5FFDDB3AE4} - System32\Tasks\{1CA0FA9F-C6F9-42E3-8D18-DFCEB9BCE8C7} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Torntv V9.0\Uninstall.exe" -c /fromcontrolpanel=1

Task: {A6858A86-6B1F-4564-94E7-7B28F377E4B0} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {ACBD6E4C-ECC0-4FEE-BED4-9EE0E46E287F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-09] (Google Inc -> Google Inc.)

Task: {AFCFAD6C-C942-4724-8EEE-A8638EA78C1F} - System32\Tasks\EPSON XP-610 Series Invitation {2CEC53D3-1048-4830-A3EB-6CDB033BFCB0} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

Task: {B07CDC2B-CD1A-46E7-98A7-96D8AC0D5469} - System32\Tasks\{B99D28A7-9F65-43D0-9F08-97012174B353} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\We Love Deals\We Love Deals.exe" -c /s /n /i:"ExecuteCommands;UninstallCommands" ""

Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}

Task: {BA9D6900-DDC0-47F4-BA43-57CB108A29A9} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {C7F296B9-254A-471B-B3E2-5CE93FF9A754} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)

Task: {CBA8CAC1-7E10-4759-A25D-7CF5A389610C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {D1C2F64E-B395-42D3-B663-34C629E83752} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-09] (Google Inc -> Google Inc.)

Task: {DC98F61B-53A1-4E32-B562-0C6A91966862} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [165520 2018-11-02] (AVG Netherlands B.V. -> AVG Technologies)

Task: {E2DA047C-5A60-42E2-A778-8BFDC85C77DA} - System32\Tasks\EPSON XP-610 Series Update {2CEC53D3-1048-4830-A3EB-6CDB033BFCB0} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

Task: {E829E330-F4B6-43DF-A74E-467D35E90B5C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-05] (Piriform Software Ltd -> Piriform Software Ltd)

Task: {ECC8BAA6-5412-488B-8FCD-61FCCCD18D5F} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe

Task: {FD96C816-E8A7-47C4-B713-1621870F44DB} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {2CEC53D3-1048-4830-A3EB-6CDB033BFCB0}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE

Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {F046D536-3200-4F23-BAD7-73FA9472B4DD}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE

Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Update {2CEC53D3-1048-4830-A3EB-6CDB033BFCB0}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE:/EXE:{2CEC53D3-1048-4830-A3EB-6CDB033BFCB0} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi

Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Update {F046D536-3200-4F23-BAD7-73FA9472B4DD}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE:/EXE:{F046D536-3200-4F23-BAD7-73FA9472B4DD} /F:UpdateWORKGROUP\SWAN-PC$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi


==================== Internet (Whitelisted) ====================


(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)


Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

Tcpip\..\Interfaces\{0DA8CC2C-FE9D-44AE-B37E-E6316F216CD9}: [DhcpNameServer]

Tcpip\..\Interfaces\{212ccb34-bd9a-47e4-8b8c-d9b116be0a04}: [DhcpNameServer]

Tcpip\..\Interfaces\{4BDB8EF9-88CC-4624-83B4-ED7CB716502E}: [DhcpNameServer]

Tcpip\..\Interfaces\{62e421a9-fed2-4db4-b2ff-18aedefafa90}: [DhcpNameServer]


Internet Explorer:


HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

SearchScopes: HKU\S-1-5-21-2071813083-1845976314-806757171-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://{searchTerms}

BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-06-15] (Microsoft Corporation -> Microsoft Corporation)

BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-06-14] (Microsoft Corporation -> Microsoft Corporation)

Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-06-14] (Microsoft Corporation -> Microsoft Corporation)

Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-06-14] (Microsoft Corporation -> Microsoft Corporation)

Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-06-14] (Microsoft Corporation -> Microsoft Corporation)

Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)




FF ProfilePath: C:\Users\SWAN\AppData\Roaming\Nvu\Profiles\pefchsj5.default [2018-06-28]

FF Homepage: Nvu\Profiles\pefchsj5.default -> about:home

FF NewTab: Nvu\Profiles\pefchsj5.default -> about:newtab

FF Plugin:,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

FF Plugin:,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

FF Plugin:,version=14.0 -> C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)

FF Plugin-x32: Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)

FF Plugin-x32: Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)

FF Plugin-x32: Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)

FF Plugin-x32: Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)

FF Plugin-x32:,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

FF Plugin-x32:,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle America, Inc. -> Oracle Corporation)

FF Plugin-x32:,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)




CHR StartupUrls: Default -> "hxxps://"

CHR Profile: C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default [2020-03-31]

CHR Extension: (Prezentace) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-06-28]

CHR Extension: (Dokumenty) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-06-28]

CHR Extension: (Disk Google) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-06-28]

CHR Extension: (YouTube) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-06-28]

CHR Extension: (Tabulky) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-06-28]

CHR Extension: (Dokumenty Google offline) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-11]

CHR Extension: (AdBlock — best ad blocker) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-03-17]

CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]

CHR Extension: (Gmail) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-29]

CHR Extension: (Chrome Media Router) - C:\Users\SWAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-20]

CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]


==================== Services (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [255512 2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> AMD)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [85304 2018-10-16] (Apple Inc. -> Apple Inc.)

S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [165520 2018-11-02] (AVG Netherlands B.V. -> AVG Technologies)

R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [413544 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [6094272 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [165520 2018-11-02] (AVG Netherlands B.V. -> AVG Technologies)

S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\80.0.3623.134\elevation_service.exe [973792 2020-03-09] (AVG Technologies USA, LLC -> AVG Technologies)

R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [110608 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8402648 2019-11-30] (BattlEye Innovations e.K. -> )

S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)

S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [777856 2019-11-30] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)

S4 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)

S4 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2014-08-31] (Macrovision Europe Ltd.) [File not signed]

S4 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2016-11-15] (Foxit Software Incorporated -> Foxit Software Inc.)

R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)

S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]

R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)

R4 MBAMInstallerService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe [6009264 2020-03-31] (Malwarebytes Inc -> Malwarebytes)

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6960640 2020-02-18] (Malwarebytes Inc -> Malwarebytes)

S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2206304 2017-01-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4172896 2017-02-24] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2102880 2017-02-15] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2330296 2017-09-07] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 MSISleep; C:\Program Files (x86)\MSI\ControlCenter\Sleep\MSISleepService.exe [282624 2013-04-29] () [File not signed]

S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-12-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [611936 2017-02-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [183480 2019-02-14] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

S3 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-03-19] (Even Balance, Inc. -> )

S3 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2014-03-19] (Even Balance, Inc. -> )

S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5897968 2020-03-17] (Microsoft Windows Publisher -> Microsoft Corporation)

S3 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2019-11-30] ( Co., Ltd. -> Co., Ltd.)

S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3831576 2019-06-13] (Microsoft Corporation -> Microsoft Corporation)

S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)


===================== Drivers (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [31992 2015-06-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)

R3 amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [21631512 2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)

R3 amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [673816 2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)

R0 amd_sata; C:\WINDOWS\System32\drivers\amd_sata.sys [85704 2017-01-29] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

R0 amd_xata; C:\WINDOWS\System32\drivers\amd_xata.sys [43720 2017-01-29] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

R2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation -> AppEx Networks Corporation)

R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-22] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)

R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [37928 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [206160 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [271704 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [207192 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [64344 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [16520 2020-02-25] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)

R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [43560 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [175472 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [111144 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [84096 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [849256 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [459192 2020-03-11] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [235280 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [316840 2020-02-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)

R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30352 2015-04-03] (Disc Soft Ltd -> Disc Soft Ltd)

R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-02-11] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)

R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-05] (Martin Malik - REALiX -> REALiX™)

S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Windows ® Win 7 DDK provider)

S3 ipadtst2; C:\Program Files (x86)\MSI\Super Charger\ipadtst2_64.sys [16336 2016-07-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-03-31] (Malwarebytes Inc -> Malwarebytes)

S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-02-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)

R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-03-31] (Malwarebytes Inc -> Malwarebytes)

S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2016-12-21] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)

S3 NTIOLib_1_0_2; C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys [13328 2012-02-14] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)

R2 RAMDriv; C:\WINDOWS\system32\DRIVERS\ramdriv.sys [86936 2016-03-10] (Christiaan GHIJSELINCK -> Micro-Star Int'l Co., Ltd.)

R2 RAMDriv; C:\Windows\SysWOW64\DRIVERS\ramdriv.sys [86936 2016-03-10] (Christiaan GHIJSELINCK -> Micro-Star Int'l Co., Ltd.)

R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1138136 2019-02-20] (Realtek Semiconductor Corp. -> Realtek )

R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8206848 2018-09-15] (Microsoft Windows -> Realtek Semiconductor Corporation )

R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129856 2014-04-25] (Razer Inc. -> Razer, Inc.)

R3 sonarworks_VirtualDevice; C:\WINDOWS\system32\DRIVERS\sonarworks.sys [444200 2019-10-25] (SIA Sonarworks -> Sonarworks)

R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)

S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-12-21] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)

R3 usbfilter; C:\WINDOWS\System32\DRIVERS\usbfilter.sys [58536 2012-08-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46584 2018-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)

S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [340008 2018-09-15] (Microsoft Windows -> Microsoft Corporation)

S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [61992 2018-09-15] (Microsoft Windows -> Microsoft Corporation)

S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2020-02-12] ( Co., Ltd. -> Co., Ltd.)

S3 cpuz136; \??\C:\WINDOWS\TEMP\cpuz136\cpuz136_x64.sys [X]


U3 idsvc; no ImagePath

S3 VGAOCTool; \??\C:\Users\SWAN\AppData\Local\Temp\VGAOCTool.sys [X] <==== ATTENTION


==================== NetSvcs (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== One month (created) ===================


(If an entry is included in the fixlist, the file/folder will be moved.)


2020-03-31 13:12 - 2020-03-31 13:12 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys

2020-03-31 13:12 - 2020-03-31 13:12 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys

2020-03-31 11:51 - 2020-03-31 11:54 - 002096052 _____ C:\Users\SWAN\Documents\fadfaf.mp4

2020-03-31 11:39 - 2020-03-31 11:40 - 047864903 _____ C:\Users\SWAN\Downloads\ssk.mp4.sfvp0

2020-03-31 11:39 - 2020-03-31 11:39 - 000024872 _____ C:\Users\SWAN\Downloads\ssk.mp4.sfk

2020-03-31 11:21 - 2020-03-31 11:24 - 054418205 _____ C:\Users\SWAN\Downloads\ssk.mp4

2020-03-31 11:21 - 2020-03-31 11:24 - 004761674 _____ C:\Users\SWAN\Downloads\ssk.wav

2020-03-31 11:14 - 2020-03-31 11:16 - 060716543 _____ C:\Users\SWAN\Downloads\ssw.mp4

2020-03-31 11:14 - 2020-03-31 11:16 - 004761674 _____ C:\Users\SWAN\Downloads\ssw.wav

2020-03-31 10:28 - 2020-03-31 10:28 - 004385554 _____ C:\Users\SWAN\Downloads\Story Odevzdání.rar

2020-03-30 22:39 - 2020-03-30 22:39 - 008661980 _____ C:\Users\SWAN\Desktop\30.3 garage.wav

2020-03-30 14:36 - 2020-03-30 14:36 - 000000000 ____D C:\Users\SWAN\Documents\Custom Office Templates

2020-03-29 18:09 - 2020-03-29 18:09 - 039365282 _____ C:\Users\SWAN\Downloads\Million Stylez - Miss Fatty.wav

2020-03-27 23:04 - 2019-01-28 22:28 - 000000927 _____ C:\Users\SWAN\Desktop\TeamSpeak 3 Client.lnk

2020-03-27 12:00 - 2020-03-27 12:02 - 000083859 _____ C:\Users\SWAN\Desktop\Addition.txt

2020-03-27 11:58 - 2020-03-31 13:41 - 000041781 _____ C:\Users\SWAN\Desktop\FRST.txt

2020-03-26 22:00 - 2020-03-26 22:00 - 000000000 ____D C:\Users\SWAN\Downloads\Xfer_LFOTool_1_6_9_2 [WIN,OSX]

2020-03-22 17:20 - 2020-03-22 17:20 - 039709582 _____ C:\Users\SWAN\Downloads\LANDR-master2-Medium-Balanced.Wav

2020-03-22 15:06 - 2020-03-22 15:08 - 000000000 ____D C:\Users\SWAN\Documents\Mount&Blade Warband

2020-03-22 15:06 - 2020-03-22 15:06 - 000001815 _____ C:\Users\Public\Desktop\Mount&Blade Warband.lnk

2020-03-22 15:05 - 2020-03-22 15:05 - 000000000 ____D C:\Users\SWAN\Documents\Mount&Blade Warband Savegames

2020-03-22 15:04 - 2020-03-22 15:04 - 000000000 ____D C:\Users\SWAN\AppData\Roaming\Paradox Interactive

2020-03-22 15:01 - 2020-03-22 15:03 - 575889150 _____ C:\Users\SWAN\Downloads\Mount and Blade Warband 1.126 + Čeština.rar

2020-03-22 14:59 - 2020-03-22 14:59 - 000125275 _____ C:\Users\SWAN\Downloads\Mount-and-Blade-Warband-Napoleonic-Wars-MULTIPLAYER-Crack-All-Versions.rar.torrent

2020-03-22 14:57 - 2020-03-22 15:01 - 615036714 _____ C:\Users\SWAN\Downloads\mount-blade-warband_1.153.exe

2020-03-22 13:39 - 2020-03-22 13:40 - 001872698 _____ C:\Users\SWAN\Desktop\24.10.wav

2020-03-19 16:43 - 2020-03-19 16:43 - 000654446 _____ C:\Users\SWAN\Downloads\37001837945.pdf

2020-03-19 16:43 - 2020-03-19 16:43 - 000273175 _____ C:\Users\SWAN\Downloads\3700183794.pdf

2020-03-19 16:30 - 2020-03-19 16:31 - 002289956 _____ C:\Users\SWAN\Desktop\3- ss 2.wav

2020-03-18 20:52 - 2020-03-31 10:49 - 058130905 _____ C:\Users\SWAN\Downloads\jan mrdka první.mp4

2020-03-18 20:52 - 2020-03-31 10:49 - 004567040 _____ C:\Users\SWAN\Downloads\jan mrdka prvn�.wav

2020-03-18 13:59 - 2020-02-03 23:41 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

2020-03-18 13:59 - 2020-02-03 23:41 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

2020-03-17 23:46 - 2020-03-17 23:46 - 000000000 ____D C:\ProgramData\ssh

2020-03-17 18:24 - 2020-03-17 18:24 - 002169104 _____ C:\Users\SWAN\Desktop\3 - ss.wav

2020-03-17 18:23 - 2020-03-17 18:23 - 002162744 _____ C:\Users\SWAN\Desktop\2 - ss.wav

2020-03-17 18:22 - 2020-03-17 18:22 - 002174192 _____ C:\Users\SWAN\Desktop\1-ss.wav

2020-03-17 18:21 - 2020-03-17 18:21 - 002203448 _____ C:\Users\SWAN\Desktop\3.wav

2020-03-17 18:20 - 2020-03-17 18:20 - 002202176 _____ C:\Users\SWAN\Desktop\2.wav

2020-03-17 18:19 - 2020-03-17 18:20 - 002203448 _____ C:\Users\SWAN\Desktop\1..wav

2020-03-17 13:53 - 2020-02-01 08:36 - 000801080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 024617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 012306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 011723776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 005436904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 004488192 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe

2020-03-17 13:41 - 2020-03-17 13:41 - 004066816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 003629568 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 003550624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 003442176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe

2020-03-17 13:41 - 2020-03-17 13:41 - 002986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002751336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002469432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002429768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL

2020-03-17 13:41 - 2020-03-17 13:41 - 002393600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002323688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002273296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002182456 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 002160160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL

2020-03-17 13:41 - 2020-03-17 13:41 - 002100056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001876960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001707208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001605000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001430880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001296360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001288648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001267216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi

2020-03-17 13:41 - 2020-03-17 13:41 - 001229824 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001201128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl

2020-03-17 13:41 - 2020-03-17 13:41 - 001076040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001024712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\assignedaccessmanagersvc.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000763032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessManager.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys

2020-03-17 13:41 - 2020-03-17 13:41 - 000486400 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys

2020-03-17 13:41 - 2020-03-17 13:41 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe

2020-03-17 13:41 - 2020-03-17 13:41 - 000350416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000263576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000254264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys

2020-03-17 13:41 - 2020-03-17 13:41 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000249856 _____ (Gracenote, Inc.) C:\WINDOWS\SysWOW64\gnsdk_fp.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSHExtensions.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddpchunk.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000161280 ____R (Microsoft Corporation) C:\WINDOWS\system32\SecureAssessmentHandlers.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssecuser.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll

2020-03-17 13:41 - 2020-03-17 13:41 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll

2020-03-17 13:40 - 2020-03-17 13:41 - 019020288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 013013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 008907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 007870976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 006545096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 006445056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\

2020-03-17 13:40 - 2020-03-17 13:40 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 005210896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 004664320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 004344832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003952760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003909632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003656792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003656704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003496448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AI.MachineLearning.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003429888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 003096064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002942976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002349056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002279296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002150912 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001759232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001750528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001693696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001647104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmsipc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001606144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001590072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001573480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001538560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001495480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001465264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001427592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001294336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001292800 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001278808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001223168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001222456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001219584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl

2020-03-17 13:40 - 2020-03-17 13:40 - 001122304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 001062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000946688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000926056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl

2020-03-17 13:40 - 2020-03-17 13:40 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000876032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000866304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000828728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000821760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000805504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000801280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000796160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000791864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000774968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000718944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000651264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000648392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfrgui.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000574864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000572416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000560640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dfrgui.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000555440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000548864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000541472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000522104 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.PredictionUnit.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000473832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provsvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000461488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIso.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UiaManager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000453208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl

2020-03-17 13:40 - 2020-03-17 13:40 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000410616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000408528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000373560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000370176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000312632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFIPP.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000279416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000277840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000267264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockScreenData.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationManager.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\srrstr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000243216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchangeHost.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000239664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Cortana.Persona.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl

2020-03-17 13:40 - 2020-03-17 13:40 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE

2020-03-17 13:40 - 2020-03-17 13:40 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactHarvesterDS.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000212480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000205312 _____ C:\WINDOWS\SysWOW64\HeatCore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\feclient.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\recdisc.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti_ci.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000186880 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE

2020-03-17 13:40 - 2020-03-17 13:40 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000176112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000175928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpcsp.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe

2020-03-17 13:40 - 2020-03-17 13:40 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.OneCore.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll

2020-03-17 13:40 - 2020-03-17 13:40 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll

Table of Contents:

combined cuts 1.jpg

Ben Deri (on the left) and Nadeem Nawara


As with any incident between Israel and Palestine, the case in-front of us cannot be judged detached from the historical context that created it and the political predispositions that interpret it. And yet, some truths do not derive from the pages of history and seem to self proclaim their independence from any specific time or context. One such moral truth, is the rejection of the act of murder, in any form it may appear.

This text is an investigation into the killing of Nadeem Nawara, and the trial of the soldier who shot him, Ben Deri. It is designed to walk you through all the evidence of the case, so you can derive your own conclusions (though i certainly share my own):

Is Deri a clumsy hero who made a technical ammunition mistake – as his defense and Israel would have you believe –  or a serial killer of Palestinians, who carefully planned to conceal live fire as non-lethal rubber coated bullets,  motivated by nationalism and racism towards Palestinians and Arabs?

As the incident before us was widely covered throughout the world and gave rise to many conspiracy theories that attacked every detail and piece of evidence, this text is quite lengthy, as it in turn tackles back each of these theories. From objective non-Israeli eyes, this might seem ridiculous or insane, but in Israel (and pro-Israel spheres) the objective eyes are considered naive if not antisemitic. For many if not most Jewish-Israelis, all Palestinians killed by Jews were terrorists and all the Jews who killed them are heroes, until proven otherwise beyond unreasonable doubt.

I realize that many find the forensic and legal investigation of a criminal case to be boring, but i believe that the more you go down the rabbit hole and the twists and turns of this trial, the more you’ll find it captivating. In many ways, it will also give you a picture of the Israeli-Palestinian conflict as a whole, and the current Israeli beliefs and rationalizations, with regards to killing of Arabs by the armed forces.


Ben Deri bored during the trial, next to his girlfriend and Tzion Amir, his lawyer.

In any case, laziness does not exonerate us: the accused, and he alone, enjoys the presumption of innocence. All that his and Israel’s uninformed supporters and defenders could prove, is innocence due to ignorance. And from the rag of ignorance, one cannot wring innocence – even with a strong hand and an outstretched arm.

On the other hand, the purpose of this article is not to generalize: A criminal amongst us (Israelis) is not proof of the criminals that are us. But those who knowingly acquit the guilty, are equally guilty of the crime.

It is common belief in Israel, that the Israeli army is the world’s most moral army, while simultaneously believing that it is immoral to judge soldiers in that army, for any crime they might commit against Palestinians. But infallibility is fallibility at its prime, and morality unquestioned, is without question immoral.

The following is the English translation of the original Hebrew investigation, which can be found here. Please excuse any grammar mistakes or just general linguistic awkwardness, as this isn’t my native tongue (but do leave a comment and I’ll fix the issue mentioned).

Eishton is an Israeli anonymous investigative blog, which relies solely on donations from its readers. The following post is the result of roughly 350 hours of research, writing and editing + 80 hours for the English translation. If you found the content worthy, please donate by clicking here.

The table of contents is for technical purposes only, so don’t waste your time reading through it. Clicking on the subjects will take you to that specific location and then you can copy that link from the browser, if you want to share directly to a certain sub-section.

Thursday, may 15th 2014, 13:45pm – During a Nakba Day stone throwing demonstration in Beitunia, Palestine, Ben Deri, a border police officer (which in Israel is basically another part of the army), was caught on tape shooting Nadeem Nawara, as he was walking unarmed:

Roughly an hour later and almost in the same location, Mohammad Abu Daher was shot in the back, as he was walking away from Deri and his force:

Two more Palestinians were injured by live fire during the protest (in the chest and arm) but Nawara and Abu Daher did not survive.

The security cameras footage was watched the world over, and right from the start Israel and Pro-Israel crowds (mostly in the US) claimed that the video is fake or as they call it, “pallywood”, meaning Palestinian-Hollywood: directed and scripted movies, designed to frame Israeli soldiers of unjustly attacking\killing Palestinians.

Israel’s politicians, army and media, either gave rise to these theories or backed them up. Deri and his force claimed to have only shot rubber coated bullets that day. In Israel, the whole incident became a joke which supposedly exposes the patheticness of the Palestinian Pallywood and those gullible bleeding heart lefties, who buy in to it. This view is most clearly demonstrated in a series of YouTube clips which started appearing in the days following the incident, such as the following clip, which according to its cynical creators “was recorded by a reliable Betzelem (Israeli human rights organization)  volunteer and is corroborated by an eye witness testimony from Stevie Wander”:

But a month later all those voices vanished discretely as the autopsy of Nawara’s body, conducted in-front of Israeli, American and Norwegian pathologists, concluded Nawara was shot by a live bullet. The fragments found in his body matched the bullet found in his backpack (after it traveled through his body), and the bullet in turn, matched Deri’s rifle.

Abu Daher’s family decided not to exhume his body. Generally speaking, Israel doesn’t actively and seriously tries to investigate suspected killings\attacks of Palestinians, if not forced to do so by evidence handed over  by the Palestinians themselves (or some human rights organization). As such, Deri wasn’t charged with the killing of Daher or the attempted killings of the two injured. Nadeem’s father, Siam, on the other hand, backed Israel to a corner as he went on CNN and said he demands an autopsy in front of international representatives.

But despite all the evidence you just read about (and much more to come), which sound like an open and shut case, a few weeks ago the prosecution offered Deri a plea deal, convicting him only with criminally negligent homicide. On Jan 29 2017, Deri accepted the deal.

So how did we go from a fake Pallywood incident, to multiple murders, to a single manslaughter charge, and finally a technical mishap? Is Israel truly conducting a just trial or just seeks the appearance of one? Is this a serial killer or a brave warrior tormented by lawyers & lefties, whom aspire to “tie the hands of the soldiers”, as the Facebook protest surrounding the case claims?

ידיים באזיקון.jpg

As we’ve seen, prior to the trial all sorts of conspiracy theories arose, clearing Deri of blame and placing it on Palestinian Pallywood. On any other trial, these insanely complex theories would have been dismissed as preposterous. But our Israeli judges and the Judges that we become as Israelis when exposed to such incidents, are all a product of our informal education, which guides us towards a predisposition to favor the Jewish soldier over the Palestinian stone thrower, without it requiring a single racist thought.

For the past 2 decades, Israelis have been told – perhaps indoctrinated – that there exists a vast cinematic industry in Palestine, called “Pallywood”, which produces frame-up movies of Israeli soldiers killing Palestinians (Note: we aren’t talking about lies, incitements or edited content, but actual video productions with scripts, directors and actors). Thus, for Israelis, the denial of documented wrong-doing doesn’t require active racism. An elaborate scheme fitting of a “mission Impossible” movie, becomes not only a plausible explanation, but rather the obvious one, which isn’t a burden on the accused soldier to prove, but a requirement from the dead Palestinian to disprove.

It is in that state of mind, that Israel’s minister of defense (at the time), went on national TV, prior to even seeing the footage, and explained: “I’ve seen many such edited movies and i know this tactic”. But in reality, he hasn’t. Non of us have. We just feel like we have.

I’m not going to get into this subject in length, but suffice to say that in the 50 years of Israeli occupation beyond the 1967 border, and more than a 100 years of conflict, there are only 2 incidents that the Palestinians are even suspected (by Israelis) of directing a fake live event: The death of Muhammad Al-Durrah and “the fake funeral“.

The funeral doesn’t involve any Israelis at all. So contrary to common belief and whats echoed in the media, there is only one instance were Palestinians are suspected of Pallywood incorporating Israeli forces (which obviously makes it very hard to do, as they are not “in on it”) – and even that instance, has never been proven as Pallywood (Because Al-Durrah’s body wasn’t exhumed and because the army, claiming operational necessity, bulldozed the wall behind Al-Durrah, before anyone could test the bullets inside it).

Part of the negligence by the prosecution in Deri’s case, is not the result of not doing their regular job, but rather that it didn’t or chose not to understand, that its normal standard would be insufficient for this case. If a single case of Pallywood, which hasn’t even been proven, was sufficient for most Israeli to believe that Pallywood is not only real but common enough to justify an acquittal, than the prosecution should have prepared the case for that standard (as unfair or constitutionally unjust as that is).

On top of that, the Palestinians are represented by lawyers of varied capabilities and experience, appointed by the state, while the soldier is free to choose his own lawyer. Usually it’s just the “normal” case of the rich-over-poor advantage, that we all know exists in the criminal system. But this becomes significant because even poor soldiers, such as Deri, are crowdfunded by thousands of Israelis and far-right organizations, who back up any Jew in Israel accused of killing or attacking Palestinians (Same people who backed Deri also backed the settlers who fire bombed the Dawabsha family or the settlers who kidnapped Mohammed Abu Khdeir, beat him, forced petrol down his throat, and burnt him to death, from the inside out).

Though i don’t claim to have any evidence of an attempt to self-fail by the prosecution and the state, we do know that virtually no evidence or witnesses were added, above the ones who came forward on their own (mostly through Nawara’s family). Critical tests failed to produce results (such as DNA identification of the body) and the prosecution chose not to repeat those tests. The two prosecutors chosen for the case, are not well known or very experienced with murder trials. The judge presiding the case, Daniel Taperberg, was previously a family court judge, and this is his first criminal case. Now add all that to the initial and routine conflict of interest, that an Israeli court is deciding weather the Israeli army has committed a crime against people who are considered an enemy of Israel, and you can see how the deck was stacked against the Nawara family.

So, in this uneven light, let us mention the obvious:
An instant or two from the past, where the crime at trial was faked or an accused was framed, is not a reason for acquittal. There’s literally no crime in the criminal law books that looking back 50 years, you wont be able to find cases that turned out to be false accusations, frame-ups, forged evidence, etc (with no Palestinian involved). And we don’t set people free because of these rare exceptions.

Just to clarify the point, we have dozens of Israeli soldiers who were convicted in Israeli courts of killing\attacking Palestinians for no reason. Yet we don’t accept a generalization based on these incidents, claiming that the Israeli army as a whole, is immoral. But then, if dozens of incidents don’t justify a generalization, than surely just one or two in fifty years, do not. Or if we flip it:
If one (unproven) case of Pallywood is sufficient evidence by your standard, for dismissing all Palestinian footage of Israeli crimes as fake, then by that same standard, dozens of (proven) cases of soldiers attacking Palestinians, require that even without footage, we shall accept such claims as true.

Obviously i don’t agree with either. All i ask, is that you remain objective.

So while the state chose two non-exceptional prosecutors for the case, Deri’s crowdfunding raised hundreds of thousands of dollars, allowing him to afford one of the best criminal lawyers in Israel: Tzion Amir.

Amir has represented politicians, celebrities, heads of crime-families, and in our field, many killers of Arabs (including the two mentioned above: the Dawabsha’s fire-bombing and Abu Khdeir torching) and of left-wingers (including a co-conspirator to the murder of prime-minister Yitzhak Rabin).

Amir is most definitely a trial lawyer, aware of the false belief that trials are an objective process, of mathematically valuing evidence. He pushes the judge’s “Jew-button” as much as he can, even though the victim never hurt a Jew and Deri isn’t claiming self-defense. He systematically interrupts the prosecutors with disrespect bordering cursing, while calling them “girls” (the prosecutors are two women) and successfully manipulates the trial to his advantage. He walks into and widens all the gaps left in the investigation, by the negligent prosecution. All the while, he is well aware of the prosecution’s limited time and resources, and so he delays and prolongs, dragging the trial for as long as possible (50 court-dates were canceled thus far. almost of all of them at the request of the defense), all for the purpose of strong-arming the prosecution into a lenient plea-deal – not by the merits of the evidence, but by the short-coming of the process and system themselves. This strategy, as can be deduced from the negligence plea-deal signed  with the prosecution, has worked.

Contrary to their representation on TV, real criminal trials aren’t a battle between two clear narratives. While the prosecution explained what it believes happened, the defense only casts doubt on that explanation, while raising many theories and exonerating possibilities (many of whom contradict amongst themselves. A tactic known in courts as “Argument in the alternative“):

Nobody fired, if someone fired Deri wasn’t the shooter, if he was it wasn’t live fire, if it was no one was hurt, if someone was hurt it wasn’t the person seen falling down, if it was than that person wasn’t Nawara.


Ben Deri

On top of all of these, the defense also claims a parallel theory:

Deri did shoot live fire that did kill Nawara, but he thought he was shooting rubber coated bullets.

As a good attorney ought to do, Amir points the flashlight to wherever doubt is found (and even where it isn’t), to the point where you lose sight of the big picture and all you see is uncertainty.

Since the defense doesn’t provide a single definitive version of what Deri claims happened that day, i will now deal with all the options they raised – from the reasonable ones to the conspirative and irriational.

before we start, a quick word from judge Alfred Denning, on the burden of proof and what is required in order to find a man guilty of a crime:

“It need not reach certainty, but it must carry a high degree of probability. Proof beyond reasonable doubt does not mean proof beyond a shadow of a doubt. The law would fail to protect the community if it permitted fanciful possibilities to deflect the course of justice. If the evidence is so strong against a man as to leave only a remote possibility in his favour which can be dismissed with the sentence “Of course it is possible but not in the least probable”, the case is proved beyond reasonable doubt; nothing short will suffice.”

As we’ve seen, the case sparked many claims of Pallywood, based on what is seen in the footage from the incident. We shall now run quickly through these claims, and dismiss them.

Ironically, all these theories of directed and staged death scenes, that come up every time footage of Palestinians getting shot by Israelis emerges, is mostly based on the fact that we are used to seeing people getting shot on movies that really are fake – AKA Hollywood. In other words, we are blaming Palestinians for faking death scenes, because their death scenes don’t look fake.

Why does Nawara break his fall with his hands?

As Nawara crashes to the ground, he extends his hands to break his fall. But if the shot killed him, how can that be? why doesn’t he fall like in the movies and instead protects himself in such a phony way?!

nawara extended arms.jpg

Roughly at the age of 6 months, as we start to crawl and approach walking, all babies develop a defensive reflex called the parachute reflex:

רפלקס הצנחן.jpg

Unless the bullet went through the brain or severed the spine, most falls will be accompanied by the parachute reflex. Nawara (and all the others shot that day), were not hit in these locations. Since they didn’t die immediately, they also chose to role and not remain face flat on the floor (as anyone would).

If Nawara was shot in the chest, why isn’t he blown backwards?

Another TV myth… this one i need not explain for TV giveth and TV taketh away. “The Mythbusters” dedicated a whole episode to trying to move a body with a bullet. Watch if you wish, as they move from guns, to rifles and almost cannons, and still fail to get any movement resembling the “Blown away” effect you see in the movies (Animal lovers warning: they test with a pig’s body):

Can you shoot live rounds through the rubber bullets launcher extension?


A Rubber bullets launcher extension

A few days after the incident, Israel pretty much proved that the Palestinians were lying:

the extension seen on Deri’s gun is meant for rubber bullets only, and a live round could not have been fired through it.

This claim was not advertised by random internet trolls. This came directly from the IDF’s spokesperson, then repeated by Israeli politicians on CNN. The greatest effect (for Israelis) came from the prime time testimony of Yosef Yekutiel, who is an Israeli weapons expert who works with the IDF and the police, who almost laughed at the Palestinian accusation:

If this claim was true, it means the Palestinians were lying and the whole thing was Pallywood. And so i did the naive thing and went searching for the extension’s manual in the Israeli manufacturer’s website, and it turns out the weapons expert and the army itself were wrong:


3rd from the top: “Immediate 5.56-mm lethal firing capability without removing adapter”

You can shoot live bullets through the extension. It is specifically designed so that a soldier won’t have to unscrew the extension while someone is running at him with a knife.

The myth of the squirting blood also derives from the movies. Unless we’re looking at a head-shot or a severed artery close to the surface of the skin (like in the neck), a regular bullet wound will not produce squirts of blood or intense and immediate external bleeding. The security cams are not high definition, but you can see in this photo of the second victim that day, Abu Daher, that there was blood:

thar bleeding.png

M16 bullets create small entry and exit wounds, and most of the damage is internal (as was found in autopsy in this case). Like a leaking pipe inside a wall, it takes time for a significant amount of blood to leak out of the wounds.

Another myth is that there should be blood on Nawara’s entry wound, on his chest. M16 bullets are so fast, that as they move through the body they create sub-pressure behind them, and suck organs and liquids after them. That’s why, contrary to Hollywood, you are more likely to see blood from an exit wound than an entry wound. Nawara’s exit wound was covered by his backpack (which we will get into later), and so you see nothing. Abu Daher was shot in the back, and that’s why we see blood on his exit wound in the chest.

As for blood stains on the floor – both victims were lifted within seconds of getting shot and carried to an ambulance. Since blood doesn’t flows out like in the movies, there wasn’t and shouldn’t have been any blood stains.

Notice how every Pallywood accusation, actually proves the opposite:

If someone was directing a fake event and doing so as it’s done in the movies, we would have seen many things that would make sense to us (Nawara would have been blown back from the bullet without breaking his fall with his hands and while squirting blood all over), but would actually indicate real “Pallywood”. They accuse them of Pallywood, because it doesn’t look like the “real deaths” of Hollywood.

The video was first collected by Palestinian intelligence. They copied the content (later gave it to an NGO which published it) and when the Hard-drives were returned to the shop’s owner, they were erased. The owner testified they do it so Israeli forces wont get the footage showing the faces of the stone throwers, and than arrest them (as they do).

At first only 2 minute segments of each victim’s footage were released. A few days later, perhaps understanding the significance of the incidents and the relative insignificance of the stone throwing around them, all 12 hours of video from each camera, were released to the media. Deri’s defense asks: maybe during this time the Palestinians edited or manipulated the videos?

The video has been checked by the IDF and Israeli police, which found no editing or manipulation. In their testimony, some of the visual experts explained that it is extremely difficult to manipulate a movie in a manner that the IDF and the police could not trace. But in this case, because we have 4 cameras that each shares parts of its field of view with another camera, it is just impossible. Someone moving can be seen from 2 or 3 angles, doing the exact same thing. On top of that, we have lots of other footage from CNN and others, which also sync-up. Here is such an example which syncs CNN, the security cams and photos by Samer Nazal (Follow the circles):

The next video syncing (and there are many more) was conducted by a UK visual forensics company, in order to determine if Deri’s shot syncs to Nawara’s fall. They used the movement of a man in white, seen in both videos, to create a sync-point. From that point, they rewind the exact same number of frames in each video, until the shooting:

To watch the unedited Security cams footage you need to contact Betzelem. For the segmentd footage (in order to upload it to YouTube) see here: Camera 1 (1, 2), Camera 2 (1, 2, 3), Camera 3 (1,2,3,4), Camera 4 (1,2,3).

We’ve now went through all the simple theories, which mostly dealt with the videos and misconceptions about what happens in them. Now we go inside the courtroom and start dealing with the more complex theories that were conjured up. For the sake of keeping the text organized, i chose not to present the proceedings as they developed in the trial, but by focusing on each subject at a time.

The Backpack That Wasn’t There

When he was shot, Nawara had his backpack on him. The bullet, which matched Deri’s rifle, was found inside that bag, after it passed through Nawara’s body. He fell bleeding on his bag. he was carried and put inside the ambulance – all of this with his bag still on him.

On May 18th, 2016, Yeal Herman from the Division of Identification and Forensic Science in the Israeli police, testified that blood was found on a book and notebook inside the bag. That blood was found to be of a male offspring of Nawara’s parents (since the DNA test for Nawara’s body didn’t work, they tested it against the DNA of his parents).


Blood on a notebook from Nawara’s Bag

Everything seemed to align with the accusations against Deri. But then Tzion Amir asks Herman about a critical problem in her tests (from the transcript of the trial):

  • Herman: i approached, looked and scanned the bag with my eyes, and couldn’t see [any blood stains].

    • Amir: what does it mean? listen, if i cut myself right now, the blood will spill on my clothes. than when you’d look, let say 5 minutes after, you would see a blood stain, right?
  • Herman: yes. A visual scan will indicate blood.
    • Amir: Good. and if i show you the same clothing 4 months later, when it was persevered in good conditions – like in our case – could you still see the blood stain?
    • Judge Tapergberg: Is the amount of time that passed meaningful to the possibility of detecting the blood?
  • Herman: No.
    • Judge Tapergberg: so if there was blood, there should be blood.
  • Herman: if optimal conditions are kept and it wasn’t, lets say washed.
    • Judge Tapergberg: IF there was a blood stain at the time of the event, you should’ve seen it when you looked at the bag?
  • Herman: could be. but it… i didn’t see any. maybe if I’d look at it today, more carefully i might…
    • Amir: go ahead, here! look at it again. scan it in front of us inside and out. look for blood where the bullet came in.
  • Herman: I can’t see any blood.
    • Judge Taperberg: Can you explain how you found blood in the notebook inside the bag, but no blood on the bag itself?
  • Herman: i can’t.

Blood on things from inside the bag, but no blood on the bag. Supposedly magic blood that jumped from Nawara’s body to Nawara’s notebook, without touching his bag? How can this be?

The vindicating tests that I’m not asking for:

Throughout the trial, dramatic testimonies and lab results that weren’t done or were screwed up, are explained in the court:
Cellphone location on Nawara’s phone, DNA identification of Nawara’s body, DNA extraction from the fragments pulled out of the body, DNA elimination-test of Nawara’s only male brother.

In all those instances, Tzion Amir yells and explains how frustrated he is of all the missing or screwed up tests, that would have exonerated Deri. If only cell-location was done, you would see Nawara wasn’t there. If only the DNA test didn’t fail, you would see the body wasn’t Nawara’s. And in our example: If only a biochemical test of the bag was requested, and not just a visual scan, you would see that there’s no blood on the bag. And if there’s no blood on the bag, but there’s blood inside it, than it must of been planted there!

There is only one thing that Amir is careful not to do, with regards to all those missing tests that would vindicate his client: Ask that they’d be done now.

The vindicating tests which can no longer be done:

The only instances that Amir does ask for tests, are when he knows they it can no longer be performed:

  • He demands the fragments and the bullet’s projectile be weighed, so we can check if they sum up to the original weight of the projectile (not a useful test since you can never be sure you found all fragments. mostly works in extremes: The combined weight is much more or less than the original projectile). But he already knows that one of the fragments was melted in order to test if it matches the bullet.
  • He demands to check the original recording of the security tapes when he already knows the original was deleted and that the copy was confirmed to be unedited or manipulated.
  • He demands to test the shirt Nawara was shot with, when he knows it was torn off him in the hospital and thrown away (and since the shot was from 80 meters, there would be no gun residue anyhow).

The Trick Turns Against his Maker:

In a criminal case, the prosecution is not allowed to continue its investigation during the trial. The defense has a right not to be surprised and to arrive at court when all the evidence and testimonies against the accused, are already known to him. The defense on the other hand, can do and ask to do, whatever it wants (within the constraints of the law of course).

And while the prosecution definitely mishandled the investigation and the lab tests, Amir is free to ask to complete or re-due those tests. Yet all he does is point to the  void, and claims its theoretical filling would have exonerated his client. This is how things end for all those tests, except in one case. In Herman’s redirect testimony, the prosecution asks a few more questions about the bloodless bag, when suddenly the Judge’s curiosity over takes him:

  • Judge Taperberg: tell me, if there was blood, how can we tell even though we can’t see it?
  • Herman: if you’d ask me today, than we have tests for hidden blood. Biochemical tests and immunological tests.
  • Judge Taperberg: I’d like it done.
  • Tzion Amir: what done?
  • Judge Taperberg: the tests on the bag. to see if there’s still blood on it.
  • Tzion Amir: your honor is saying? your honor wants?
  • Judge Taperberg: yes. DECISION: the court is instructing the lab to perform a chemical blood test.
  • Tzion Amir: your honor, if i may, your authority. Our opinion wasn’t asked in the matter, but your honor should state what authority grants him,
  • Judge Taperberg: the authority to seek the truth, which you so heatedly support.
  • Tzion Amir: no, but your honor should state in his decision from where he derives the authority to instruct such a decision [to test the bag].
  • Judge Taperberg: as requested by the defense. now, during the expert testimony, a question arose in the court and doubt, as to the inability to see blood on the bag, if as claimed, the victim was wearing the bag when he was shot. In order to discover the truth and complete the missing information, the court here by instructs to conduct the aforementioned test.

Notice Amir’s reaction, who all of the sudden is not thrilled to perform the test, which only moments ago he claimed would vindicate his client. “by what authority?” Amir asks the judge. “the authority to seek the truth, which you so heatedly support”, Judge Taperberg snipes back sarcastically, making it clear he, like you now, is aware of the distance between Amir’s verbal cries for the truth lost with the missing tests, and the way he actively pushes to suppress that truth, when retesting is available.

A month later Herman returns to court with the results: Blood. Blood on the bag, inside the bag, and all around the entry hole left by the bullet.

התיק עם הדם.jpg

Nawara’s bag before the endless delaying of the trial removed all visually traceable stains of blood

As a bullet passes through the body, it carves and cuts its way through the flesh and organs, leaving a Permanent tunnel or cavity. It also produces short term damage – tissues and organs which are blown by the shock waves (AKA Hydrostatic shock\pressure waves), but then mostly return to their original placement.


On June 16th 2016, Dr. Chen Kugel, the chief Pathologist in Israel’s national institute of forensic medicine,  testified that the permanent cavity – the “tunnel” left in the body by the bullet – is not what he’d expect to find and he cannot explain it. The media silence about the case was broken the next day, as Kugel’s testimony became this headline:


“No explanation for the direction of the bullet”: A turn in the case of the border police officer accused of killing a Palestinian.

The head of the national institute of forensic medicine testified in the trial of warrior Ben Deri, accused of killing a Palestinian boy during a disruptive protest in Beitunia. According to him, the locations of the wounds on Nadeem Nawara’s body, aren’t consistent with the location of the accused at the time he fired.

In order to understand Dr. Kugel’s testimony, i will first need to anguish you through some basic knowledge in Ballistics, internal ballistics and other terms and fields relating to the movement of a projectile through the human body.

The Problem:

At the time of the shooting, Deri is on an elevated platform, referred to as “The Balcony”, which is about 5 meters above Nawara. From Nawara’s perspective, Deri is in front and above him. So a bullet fired by Deri at Nawara, should move down between the entry wound in his chest and the exit wound in his back.

The permanent cavity left by the bullet, is indeed a downwards movement with an insignificant 3cm to the side. Only the downwards movement is significantly sharper that Deri’s angle as he was firing. Dr. Kugel would expect to see such a permanent cavity from the same general horizontal location Deri was in, but from much higher.


Aerial photo of the location showing the line of fire between Deri and the balcony (on top) and Nawara (on the bottom).

This, as the headline claimed, really is a dramatic turn: the shot couldn’t have come from Deri’s location. But whoever leaked\reported the testimony, did so only partially, and left out the cross-examination:

The prosecution asks Dr. Kugel if one’s posture would effect the cavity, and Kugel confirms. Kugel is asked if Nawara’s walk, which is a little bent over, could effect the cavity, and he confirms. Kugel is asked if the weight of the bag pulling back, when we know that we unconsciously auto-correct this by leaning forward – would that affect the canal, and he confirms. Finally, Kugel is asked weather these elements combined could create the permanent cavity he saw in the body, and he answers that it is possible.

Now some of you might think, as Amir yelled in the court, that Nawara isn’t that crouched over. He is leaning forward, but could that really explain a drop of 11cm (4.3in) in height from the entry wound to the exit wound?

The prosecution stops here. Though Kugel’s testimony now allows for Deri to be the shooter, it still deems it unlikely. This is a hard blow to the case, which we shall try to fix now.

The Natural Loss of Altitude:

First we need to calculate whats the drop in altitude we would expect from a bullet passing in the air, over roughly 25cm (an average distance between a thin-muscular man’s chest and back)?

So we know Deri is 5m elevated from Nawara and is 80m away. A simple Pythagoras calculation will tell us that the angle of the shot was 4 degrees (the rifle was slightly pointing down), as was testified by the IDF’s expert.


So how much altitude is lost at 4 degrees over 25 cm? Pythagoras will again tell us that we should expect 2cm drop, and not the 11cm that was found in the body. So we have 9 extra centimeters, which do not align with the angle between Deri and Nawara.


Black triangle: The angle between Deri & Nawara and the altitude drop Kugel expected to find. Red triangle: The angle & altitude drop found in Nawara’s body

It should be stated that the location of the wounds, is relative to the spine on the back the chest bones in the front. as they are not on the same surface, there can be a 1-2cm miscalculation. But still, as Kugel stated, 7-9cm is still a lot.

Proof by contradiction:

Will begin by assuming Dr. Kugel is right, and that the angle between the entry and exit wounds, is the angle between the shooter and Nawara (or somewhat close to it). We go back to Pythagoras and calculate that the 11cm drop, over 25cm~ distance (through the body), gives us an angle of ~24 degrees.

As found by the IDF’s expert, the structure on the right of Nawara blocked any fire coming from that direction. We know from the wounds the shooter couldn’t have been behind Nawara and to the left of Nawara its all flat (which obviously doesn’t work with an angle of 24 degrees). so the only area a sniper could have been elevated and still been able to see Nawara was the balcony Deri was on and the buildings behind it.


We know from IDF’s report on possible lines of fire, that everything to the right of the red line in the picture above, has no view of Nawara. The black circle is where Deri and his force were.

So we can see, the only other possibility for an elevated “incriminating sniper”, is the building behind Deri, in the parts left from the red line. The building behind Deri is about 10m back, which means 90m from Nawara. Back to Pythagoras: 90m at 24 degrees, means the shooter was 40m in the air.

The building behind Deri has 3 floors and another one if you include the narrow section with the red roof tiles. So 4 floors all together, making the red roof the highest location “the incriminating sniper” could have been at.

Israeli standard for floor-ceiling height is 3m but to avoid arguing about the subject, we’ll assume 4m. And so: 4 floors X 4 meters + 5m which is the height of the balcony = 21m . When according to Dr. Kugel, the sniper should have been 40m in the air – twice as high. Not just an invisible sniper, but a flying one too!

So how can all this make sense? The answer, in my opinion, is that Dr. Kugel is wrong.

Introduction to Forensic Ballistics:

When Kugel is asked if the bullets trajectory in the body could be influenced by the bullets movement in the air, he answers dismissively: “I don’t think its because the bullet made any stunts in the air”. But it did. All bullets do.

We tend to think of bullets in flight, as facing forward, with their tip\nose directly facing the target. We’ve learned from forensics shows on TV, that you can stretch lines from wounds on a body, and arrive at the exact location of the shooter. All these things, in most cases, range from exaggeration to complete nonsense.

A combination of different forces cause bullets to move in different ways:

  • They obviously travel in the direction you aimed (normal ballistic trajectory)
  • Circular Grooves in the barrel cause the bullet to spin (which keeps it balanced)
  • The friction with the air causes the bullet to be a bit “snobbish” and raise its nose a little, creating an angle of attack (the angle between the direction the bullet is moving towards and the direction his nose is facing).

In simple words, the bullet takes time to stabilize and it leaves the barrel somewhat shaky. This shaking of the bullet’s nose, which creates different angles of attack, is called “Yaw”. Generally speaking, a longer barrel produces a steadier bullet, and Deri’s gun was an M4, which is Basically a shortened M16 (meaning more “Yaw” and more shaking).

Image result for bullet yaw

I’m telling you all of this because the way and the angle a bullet hits the body, is critical to the trajectory it will take inside the body, and the permanent cavity it will leave behind. So while we think bullets hit their target like this:

shadowgraph straight.jpg

In most cases they’ll hit it like this:

shadowgraph yaw.jpg

The arrows represent the counter force acting on the bullet from the friction of the body or matter it passes through. When a bullet is perfectly aligned, then the friction forces acting on him are symmetrical, It slows down, but it does so without changing its path from the trajectory it had in the air. But when the bullet has an angle of attack, the friction acts more on one side of the bullet, than the other. this can be seen easily in wind tunnel testing of air craft wings:

wind aroud wing.jpg

Because the wing is tilted down, there’s a lot of air friction beneath it but non above it. The same thing happens to a bullet.

This is the stability graph for the bullet Deri was using – a 5.56mm M-193 FMJ:

יציבות קליע לפי טווח.png

Without going into specifics, the bullet starts with 3 degrees of Yaw and only stabilizes after 200m (The graph is for a longer barrel, so Deri’s bullet would have been even shakier). Nawara was 80m from Deri, so we  know that the bullet most likely hit him with an angle of attack ranging from 0.8 to 2 degrees, and that the Yaw forces were still active at impact (the nose was still moving around).

shadowgraph yaw.jpg

And when a bullet hits the body at an angle, the friction causes it to tilt towards that angle and the center of gravity of the bullet (marked by the red dot) “tries” to move forward. The more the bullet continues to travel in this manner and the slower it gets, so would the angle of attack increase. What starts off as just a degree or two, quickly turns to sharp angles and sometimes even spinning of the nose and tail (AKA “tumbling”). This explanation is missing from Dr. Kugel testimony: the M-193 trajectory inside the body, is rarely a continuation of its trajectory prior to entering the body.

But how dramatic this effect can be? am i not just bothering you with insignificant details?

Since the M-193 is an unstable bullet with a rear center of gravity, many times, inside the body, it will start to turn towards a complete reversal, which is known as Tumbling:

But just as many times, the bullet’s Yaw will create an angle of attack, but not one sufficient for full tumbling. In those cases, research has found that after 9-16cm of penetration, the bullet will start wandering off its flight trajectory (your welcome to read these 2 pages , but feel free to skip):

So roughly 10-15cm in to the body, a “cone of possibilities” opens, for possible paths the bullet might take.


But does this “wandering around” characteristic of the M-193 explains the 7-9cm altitude drop between the entry and exit wounds in Nawara’s body?

Watch this testing of an M-193 fired into ballistic gel (a gel with the same average density as human tissue and organs). The block of gel is about 28cm long, which is about the same as a thin-muscular male’s chest. Watch where the bullet hits, how straight its trajectory is in the beginning, how it turns, and where it ends up:

A screen capture of the result :


The bullet penetrates about 8-9cm deep, maintaining its ballistic trajectory prior to hitting the gel. It then turns and takes a dive downwards (basically takes a single option out of the cone of possibilities), until it leaves the gel – roughly 10cm below the entry point!

Kugel Vs. Eishton:

So you can see that the M-193 isn’t loyal to the ballistic trajectory, and its wandering can explain 7-9cm in altitude drop in Nawara’s wounds. In his response to this investigation, Dr. Kugel explained that though he agrees with what you’ve seen thus far, the permanent cavity found in Nawara’s body, was quite straight and didn’t present a hard turn as depicted above.

I myself obviously didn’t gain access to the body or the autopsy’s photos, so i must rely on Kugel’s testimony of it (and he seems to be a very honest person). That said, i am not as certain as he is, as to the accuracy of measuring a permanent cavity which runs through multiple moving organs, in a body that was in motion when it was hit, and in a partially rotten corpse, one month after it was buried. Kugel himself, after reading this investigation, understands that there are paradoxes within his conclusions:

if the bullet tunnel in the body is completely straight, it means the friction on the bullet was symmetrical and only acted on the bullet’s nose. Which means there shouldn’t have been any fragments (M193 bullets do not break or get squashed without hitting bone, if they don’t tumble or turn). As such, we began – Kugel and I – searching in forensic ballistics’ experimentation and research, to find a possible explanation.

At first, i was able to find the following test of an M-193 fired into a ballistic gel, which still shows a 10cm altitude drop, but without the sharp turn (just a gentle arc, which is so gentle as to be confused in a partially rotten body with a straight line):

Though this (and many other recordings of the same phenomena) got us passed the “sharp turn” issue,  Kugel replied that the permanent cavity in Nawara’s body didn’t show the severe damage and tearing, that is caused by the shock waves and expansion you see in the video (the growing “bubble” inside the gel, known as Hydrostatic pressure waves).

So i kept on reading, until i came across a study conducted in Iraq in 2010, which examined the bodies of 30 people killed by high velocity bullets (such as the M-193). That study sent me to another book in the field, which explains that the hydrostatic pressure waves which should have created the damage around the permanent cavity in Nawara’s body, mostly occur when the bullets move through the body at speeds greater than 2500fps.

There is some debate regarding the hydrostatic threshold. It changes with different guns, bullets, angles and conditions. But generally speaking, most estimates place it around this number, for the combination of Deri’s rifle and bullet (M4 firing an M193). For our purpose, suffice to say that if the bullet hit Nawara at a velocity lower than 2500fps,  than it’s likely that no hydrostatic shock occurred and therefore, Dr. Kugel wouldn’t find the injuries associated with it.

As mentioned, Deri was using an M4 rifle, which has a muzzle velocity – the speed at which the bullet exits the rifle – of ~2900fps. Again, every change in the gun, humidity, elevation, and quality and maker of the bullet, will give you different results. But at 80m – the distance between Nawara and Deri – the spectrum is from 2200 to 2700fps (from worst to optimal conditions).

So we can clearly see that Nawara was very likely to have been hit under 2500fps, and thus it’s very likely he didn’t suffer any hydrostatic shock damage. On top of that, further reading taught me that most bodily tissue and organs, are too elastic to be damaged by the hydrostatic shock. The brain, enclosed in the skull, blows up like a tiny bomb set off in a closed bottle of water. The liver has enough plasticity, so that the stretching shreds it beyond repair. But other organs, though they might suffer from the shock, don’t tear and leave evidence of it. So even if there was some shock at entrance, it is possible that by the time the bullet reached Nawara’s liver, it had slowed below 2500fps, and thus, left no significant damage for Kugel to find.


Kugel Response:

Presented with these findings, Dr Kugel accepted them as a possible explanation for the wounds found in Nawara, though still defending his testimony in court, that it’s unlikely. This change though, happened a day after the plea deal was signed.

I asked Kugel weather he changes unlikely options, when he’s made aware of the incident’s circumstances. For example, he sees a wound which 95% of the time, would indicate it was caused by a serrated knife. But this time he has video of the attack, and the knife retrieved from the body – which had a smooth blade. Surely he wouldn’t testify in such a case, that the weapon found is very unlikely to be origin of the wound. Kugel agreed that the correct testimony in such an incident, would be to indicate that if the evidence regarding what happened outside the body is confirmed, than a 5% reason, becomes a 100% fitting explanation.

Kugel still maintained his testimony wasn’t that important and wasn’t the main cause for the deal signing, rationalizing that the deal confirms Deri as the shooter even though his testimony concluded this is very unlikely. But i believe Kugel’s testimony put pressure on the already willing to settle prosecution. An alibi testimony saying an accused wasn’t in the crime scene, could create sufficient pressure or excuse to sign a deal which states he was. Deals are signed because of evidence, but not necessarily with accordance to them.

Once the deal was signed, confirming Deri as the shooter, i asked Kugel how he reasons this with his contradicting testimony. he replied:

“Deri probably shot the bullet which killed Nawara. How this happened? I’m not sure. But i live with many things which i cannot explain, and I’m aware that i can’t explain everything and not everything is known to us”.

I asked did he not think that this should have been mentioned to the judge (for whom this is his first criminal case) and the prosecutors? Isn’t it important to know that the understanding of pathology is not yet perfect (like most forensic fields)? That an unexplained cavity doesn’t actually mean an impossible one and that it’s happened to him before that he couldn’t explain a wound, though he knew from other facts exactly how it was made? Doesn’t he find the difference from this explanation (which we discussed in our emails), to the one he gave in court (“I can’t explain this angle in the body”) to be important? Not only for this case, but for the judge’s next cases, in which he might rule based on “a fact” which isn’t one at all?

In conclusion:

Here the correspondence ended (I’ll update if Kugel replies). In conclusion we can summarize that the bullet cavity found in Nawara’s body could have derived from Deri’s location (according to science), is a less likely possibility for a shot from Deri’s location (according to Kugel), and is definitely the cavity created from the shot Deri made from his location (according to all the other evidence, the video and Deri’s own confession in the plea deal).

A second problem Kugel described in his testimony, was that he couldn’t explain the shape of the bullet found in Nawara’s bag. The bullet remained rather intact, with some unsymmetrical squashing in its tale.

This slideshow requires JavaScript.

Deri’s Lawyer asks Dr. Kugel about the condition of the bullet, with regards to the fact that it didn’t hit any bones in its path. Kugel replies:

“We don’t see a reason for the bullet’s squashed condition. From its path in the body i can’t explain its condition”

In Reality:

Here Dr. Kugel steps outside is realm of expertise. Bullets routinely break and are squashed without hitting bones, just  from the forces acting on them. Here’s a picture of the famous fragmentation tests, conducted by Martin Fackler, on the M193 bullet, in Various striking velocities:


Displaying image.png

As you can see, there’s a whole spectrum of possibilities for end condition of the bullet. Our bullet is bent\squashed in its tale, but not broken. This correlates with the result on the left of the 2nd row from the bottom. As you can see by the striking velocity – 2395fps – this not only fits with the condition of the bullet found, but also the velocity expected at 80m distance (which we covered in the previous section). This in turn, also matches the science in the field which says hydrostatic-shock damage is likely not appear in this velocity (and it hasn’t). So you can see how the evidence don’t contradict, as Kugel testified, but actually  complement each other. Here are some more M193 bullets, shot in to ballistic gel, which ended up intact and only squashed non-symmetrically in their rear:


And here again is the bullet found in Nawara’s bag (you can clearly see this result isn’t “unexplainable”, but standard at the right velocity and recurring):


Non-Jacketed Fragments:

Another support for the fact that the condition of the bullet found matches the trajectory in Nawara’s body, is the content of the fragments retrieved from the body. Those were tested to check if their composition is the same as the bullet found in Nawara’s bag (and it was).

Image result for bullet jacket

M193 sliced to reveal copper jacket and lead interior

As a side note, the lab report also found that the fragments contained lead and small amounts of other impurities, but no Copper or Zinc from the bullet’s jacket (see image to the right). The head of the forensics lab in the Israeli police, testified that “the bullet was a little squashed in the back, and the lead inside it was squeezed out, like squeezing the toothpaste out of the tube”.

When an M193 bullet tumbles inside the body, it tears apart to fragments – both the Jacket and the Lead interior. But when the velocity and angle are below the fragmentation threshold, which is about 2500fps for the M193, the bullet can still bend and get squashed, but the forces are insufficient for complete tearing of the bullet (proving again that their shouldn’t have been any hydrostatic shock, since the speed needed for the shock, is roughly the same as needed for the fragmentation – and neither occurred).


The reason the M193’s lead core can get squeezed out like toothpaste, is because of the bottom of its jacket, or rather the lack thereof:

M193 imi bottom.png

As the friction in the body acts on one side of the bullet (because of its angle), the Jacket is bent, but remains intact. The lead inside is compressed and squashed out of the M193’s open bottom.

M193 bootm to angle to curve to squeezed lead.jpg


So the non-Jacketed fragments found in Nawara’s body, match the bullet found in Nawara’s bag: not only in the composition of the lead, but also in the fact that the fragments were only from the lead interior, and the bullet found still had a complete jacket. This again shows the condition of the bullet isn’t unexplainable, as Dr. Kugel testified, but rather in complete alignment with the other facts of the case and the research in the field. Contrary to his testimony, bullets do bend and get squashed (leaving lead fragments behind them), without hitting bones. And now, after the deal, we can also add that Deri confessed to making that shot (though supposedly without knowledge of it being a live round), which again means that not only the facts contradict Kugel, but also the accused himself.

Kugel’s response:

“With regards to the bullet’s condition, I’m now not as firm on my stance as i was [prior to reading this article]”. I believe that you might be right, but i want to check the photographs in the case file before deciding”.

Kugel hasn’t returned to me on this subject after looking at the photos (though i believe it’s just from forgetfulness and not avoidance). But his answer, the evidence and the plea deal, speak for themselves.

So we’ve now finished going through most of the basic evidence and correcting Dr. Kugel critical testimony, which basically cleared Deri of the blame, by claiming his position didn’t match the bullet trajectory in the body, and that the condition of the bullet found in Nawara’s bag, can’t be explained from the path it took through his body.

In this section we will be going over the conspiracy theories raised by the defense, which claim Deri was framed by the Palestinians or his friends in the army. As crazy as some of them might seem to you, i assure that they don’t seem that way to most Israelis and they are explained in court, with a serious and straight face.

M16 Vs. AK-47

Deri’s lawyer finds many insignificant correlations and connections, which could imply the existence of a conspiracy. But really, non of them make sense or have real substance in them – none but one: The postmortem medical report for Nawara, notes that his wounds were caused by an M16 rifle, and not an Ak-47.

Only this diagnosis is impossible. The two rifles are too similar in the wounds they inflict, to decide which of them was the weapon used. This Pseudo-medicine conclusion, was written in order to point the finger at Israeli forces (which use M4 and M16) and not the Palestinian police (which use AK-47). Lets admit the obvious: this really doesn’t look good.

But the report wasn’t actually written by the Palestinian doctors. They were asked to write it by the Palestinian authorities. If you’d ask me, this is nothing more than a stupid propaganda attempt. They wanted to run out to the press with “evidence” of Israel’s blame. This all happened prior to the collection of the footage from the incident and even the knowledge of its existence. And when you think about it, lets say we accept it’s proof of a framing conspiracy, then why would you write a fake medical report  to prove the identity of the killer, when you already know you have the killer on tape?

But you may certainly interpret this differently (as the defense does). All i ask, as i asked before, is that you keep thinking: “Assuming this is true, does it align with the rest of the objective facts of the case? And if it is true, why did the defense settle for negligent homicide, which means Deri did kill Nawara (only by accident), and all these conspiracy theories are false?

A fake report – to the detriment of its own makers?!

In the same reports, that the defense claims are fake, there are pro-Israel mistakes, which the defense uses as an advantage: In the first report, Nawara is said to be suffering from two entry wounds – as if he was shot in the back and in the chest. Only Dr. Kugel explains in his testimony, that this is a common mistake in a preliminary visual scan (prior to surgery), and that he too sometimes confuses exit wounds as entry wounds at such early stages.

But if the event and reports are fake and meant to frame Deri, than why would it have a mistake deflecting blame from Israel and punching holes in Deri’s guilt? Why would a “cooked report” be undercooked?

These mistakes, which benefit a different side every time, point more to a general lack of professionalism in the Palestinian hospitals, rather than a complex and well-thought of conspiracy.

The flipped view:

Let us for a second, look at this incident from a Palestinian prospective. Lets assume  you’re a Palestinian watching the news, and you see the IDF spokesperson saying that a live bullet can’t be fired through the rubber bullet’s extension. After that, a whole bunch of Israeli politicians, media people and journalists, all say the same thing: A live bullet couldn’t have been fired through the extension. All the while, living for decades under the army’s occupation, you know this to be false.

Now, do we derive from all these experts, politicians and the army itself, stating a false claim which points the blame at the Palestinians, that there must be a conspiracy between these parties? Do we conclude from this single lie, that the IDF spokesperson, Yekutiel the weapon expert and Ben Deri, had all colluded to murder Nawara?

Of course not. This is insane. And that’s why, for the same reason, i think one should always have faith in the stupidity of unrightfully confident people, whose blind patriotism leads them to make false claims, which they think will serve their side. The Israelis who claimed Nawara couldn’t have been shot by the M16\M4 are the same as the Palestinians who claimed he couldn’t have been shot by the AK-47: They are patriotic idiots, unaccompanied or guided by a large conspiracy, who in the end and contrary to their objective, only hurt their nation’s credibility.

But aside from this explanation, we shall now go through all the conspiracy theories raised by the defense. If I’ll prove them false or below a reasonable doubt (as i believe i do), than a line in a medical report has no meaning, since the conspiracy interpreted from it, cannot be.

One of the defense’s claims, is that Deri only fired rubber bullets that day. Do we have evidence to the contrary?

Hearing Testimonies:

Under the occupation, the Palestinians have been hearing live and rubber bullets for decades. With time, like the soldiers who fire them, they learn to distinguish between the sound the two make. All the Palestinian witnesses from that day, claimed they heard 3-4 live shots (and the rest were rubber coated bullets).

Matching the bullet:

The bullet found in Nawara’s bag, was a match to Deri’s rifle barrel. This test isn’t 100% accurate and shouldn’t be thought of as a deterministic result to the level of DNA testing, but rather a positive reinforcement. That said, the likelihood of someone being at the right time and in the right place, having a gun barrel similar enough to confuse the lab, is very low. Not only is it unlikely, it also cannot be by design: No 3rd party could have known the interior of Deri’s rifle barrel, and then find or make a similar one. They would have to rely on a lot of luck.

Matching the Fragments:

The fragments of bullet found in Nawara’s body, matched the bullet found in his bag (which we already said, matched Deri’s rifle). This to isn’t a 100% accuracy test, but the likelihood that a bullet left fragments in Nawara’s body, that are compositionally similar enough to Deri’s bullet, are slim.

The bullet and fragments went through a very accurate test (Isotope analysis), to check if the metal composition in them, is the same.The lead inside the bullet, has small impurities from other metals. The test checks for the ratios between all these metals in the bullet and fragments. If the ratios are the same (as they were), it means the bullet and the fragments are indistinguishable.

A Similar Bullet:

Deri’s defense asks Nadav Levin, head of Israel’s police forensics lab, if the bullet couldn’t have derived from the same maker and the same batch of bullets? The defense basically tries to detach the bullet – which matched Deri’s rifle – from the fragments. Maybe the bullet is Deri’s, but the fragments belong to a similar bullet, fired by someone else – perhaps someone from Deri’s force. Levin is asked if maybe Deri’s friends had such similar bullets, and had he tested them, they too would match:

Levin: No, Not at all
Deri’s lawyer: Explain
Levin: Because it’s a result of the manufacturing method. The method they use is such that the projectile’s cores [the lead interior of the bullet] is mixed with batches from many different Lead sources. and so, in the same batch of ammunition, i can find large variations in composition, but within a single bullet, i expect to find the exact same composition [as found in the fragments], which is what we found here.

What Levin is explaining is that even within a series of bullets that left the factory at the same time or arrived in the same box, there is great variation in the metal composition of their lead cores. It isn’t absolute variation: he expects there to be dozens or even hundreds of internal sub-groups, which are sufficiently similar to be tested as indistinguishable from each other. But this still means that the likelihood of someone in Deri’s force having a similar bullet, is in the single digit percentage or even less.

This again, is one of those instances were Deri’s Lawyer would like you to think no further. Here… We have a chance that the bullet isn’t Deri’s. that chance might even be 5%, which is the acceptable legal standard for reasonable doubt. So should we acquit Deri?

But doubt doesn’t accumulates. We again need to ask: assuming this is true, how does it align with the rest of the facts?

If we agree that the bullet derived from Deri’s force, we also agree that Nawara was shot and killed by them. But then, we already have the footage of the shot that killed Nawara, and it syncs with Deri’s shot. What is the other option? That Nawara faked his fall and death by Deri, and then later returned and was really shot by someone else from Deri’s force, who against all odds had a bullet with the same composition as Deri’s?!? And even if that was true, than where is the footage of this second shot at Nawara?!

The Bullet’s Jacket:

As we discussed, The fragments not only matched the bullet by the lead composition, but also by the lack of Cooper and Zinc from the bullet’s Jacket. If the shot came from another shooter, even with a similar bullet,they couldn’t have known or control the result of their shot to match it with Deri’s found bullet (meaning: Jacket intact and lead squeezed out).

The Empty Case Ejection:

As I showed in my first investigation of the incident, zooming on Deri in the CNN footage, shows and ejection of the bullet’s empty case.


Right-Left: Complete bullet, empty case, Bullet’s projectile

This is critical because of the mechanism behind the automatic ejection of the empty case:

As you just saw, the force from the explosion of the gun powder in the bullet, pushes the projectile down the barrel of the gun. The same gases, are also partially channeled backwards, to push the mechanism back, and eject the empty case.

The only problem is, that this only happens because the projectile blocks the gases (it is 1mm smaller than the barrel), so that the gases are forced upwards and backwards, to release the empty case. When shooting rubber coated “bullets” (actually 3 metal cylinders covered in rubber and wrapped in nylon – Army nickname: Tampon), this doesn’t happen.

טמפון תחמיש ורומה - english.jpg

The “tampon” is inserted into the extension from the front (left side in the picture). A blank bullet, which has no projectile, is fired. The gases go up the barrel, into the extension, and propel the Tampon at the target. Since there’s no projectile to block the gases, very little of them go up and backwards (because physics dictates they shall always aspire to continue in the same direction, unless forced otherwise), And the empty case isn’t released automatically.

Enlarge the video if you need, but you can see the empty case ejected after the shot – which doesn’t happen when firing rubber coated bullets.

זום על התרמיל

Sonography of the shot:

In my first investigation i also explained that you could test the audio from the recordings of the shots, to see if they are live rounds or rubber bullets. This was possible, because we knew that the second shooter, who fired seconds after Deri, did fire a rubber bullet. Since the same camera captured both of them from the same location, firing the same gun with the same rubber bullet extension, than the sound of the two can be compared to see if they are the same.

Unfortunately this was beyond my modest means. But later Nawara’s family with the help of a human rights group (DCI) asked a UK forensics company to do just that. Here are the results (Full textual explanation can be found here):

In Conclusion:

  • All the witnesses claim they heard live fire
  • The projectile found matches Deri’s rifle
  • The fragments found match the bullet. Chances of matching a random bullet: slim to none. Chances of matching with someone from Deri’s force: single digit at best. But if the shot came from Deri’s force, than we have that shot on tape, and the shooter which syncs to that shot, is Deri.
  • The video shows an empty case automatically ejecting, which only happens with live fire
  • The Sonography of the shots shows Deri’s shot was live fire
  • As such, the only possible and reasonable conclusion, is that the bullet Deri fired at Nawara, was a live bullet.

The defense also claimed that Deri can’t be the shooter, since he couldn’t see Nawara. Maybe he fired a live round and maybe he didn’t – but the round didn’t hit Nawara, as Deri couldn’t see him.

Proof by contradiction:

If there’s no line of fire, than what the hell is he shooting at? Even Deri claims he was shooting at Nawara (though alleging it was only rubber), so how can he claim to have shot at him, while at the same time claiming he couldn’t have shot at him? And if there’s no line of fire, why is Deri and all the soldiers with him, are shooting from that location throughout that day?

Re-positioning by the Palestinians:

The Palestinians themselves took pictures from Deri’s position, looking at Nawara’s position, substituting Nawara and the other victims with stand-ins. Deri’s location (top picture) is next to the tree with the red flowers (you can see that in the CNN footage), and his view is seen in the red square (and enlarged in the bottom picture).


Lieutenant colonel Naftaly’s report:

lieutenant colonel Guy Naftaly, a visual analysis expert in the IDF for the past 25 years, was asked to check possible lines of fire towards Nawara’s location when he fell (seen on the security cameras). He concludes the obvious: there was a line of fire between Deri and Nawara:


Aerial photo of the area, showing the line of fire from Deri to Nawara (From Col. Naftaly’s report)

3D reconstruction:

The UK forensics company also tested lines of fire, by reconstructing the whole area in a 3d model:

In Conclusion:

  • If there wasn’t a line of fire, Deri and the rest of the soldiers were just shooting the whole day at thin air, with great aiming and concentration.
  • Palestinian reconstruction shows there was a line of fire
  • Col. Naftaly concluded there was a line of fire
  • 3D reconstruction concluded there was a line of fire
  • Put together, there is no other option but to conclude Deri did have a line of fire at Nawara

Another angle tested by the defense, claims that maybe Deri had a line of fire in principal, but at the time Nawara was shot, it was blocked by the parking tractor or some passing truck?

By contradiction:

Again… if the line of fire was blocked, why are they shooting? Just sniping at a parked tractor for fun?!

Camera 8:

The carpentry business to the right of Nawara, had 8 security cameras. Since nothing interesting is shown on the other 6, no one cared to look at them. But camera 8 is just on the corner of the building, facing the balcony that Deri and his friends were stationed on (Meaning it’s almost identical to the line of fire and to the view Nawara had of Deri).

According to the time-code on cameras 1 and 2 (which captured Nawara’s fall), he was shot at 13:45:10. Here is a screen shot of the exact same moment on Cam8:


I marked Deri’s location with the red circle, and you can clearly see there’s no truck passing and the tractor tall enough to obstruct Deri’s view, is at least 5m to the right of the line of fire.

Though the time-code between the cameras has been proven to be in sync, those of you who are worried it isn’t can read the following syncing explanation (the rest can skip past the next video):
On Cam8, you can see a soldier moving from the right of the balcony to the left (towards Deri), and you can see the same soldier in the CNN footage (only from their angle he’s coming from behind Deri). Also, at 13:45:30 (20 seconds after the shot), you can see a gas grenade fired from the balcony. Looking through the low quality Cam2 at the same time, you can see that Nawara is being placed inside the ambulance. At that same moment, a 3rd camera man was taping the ambulance from the other side of the street, and you can see the gas grenade hit the road:

Reverse Angle:

This is a photo of the reverse angle (from above and to the left of Deri’s point of view) taken a few hours after the incident (Deri’s actual position is further to the right of the soldiers you see on the balcony):

מעל המרפסת 2 עם סימונים.jpg

Again, you can see the tractor (marked with a red arrow), is far to the left of the line of fire between Deri and Nawara, which fell a few meters to the left of the jeep in the red circle.

From Nawara’s perspective:

The next photo was capture just a second after Nawara fell. In the background you can clearly see that the only thing between Deri and Nawara, is the white van, which is to short to block the view. The tractors cannot be seen, because they are outside the line of fire.

רצפה פנים גלויות 4.jpg

In Conclusion:

  • If the line of fire was blocked by the tractor, Deri and the rest of the soldiers were just shooting the whole day, with great aiming and concentration, at a parking tractor.
  • Cam8, which syncs with all the other cameras, show no obstruction in Deri’s line of fire, and so does the reverse photo from behind Deri’s location
  • The photo of Nawara on the ground, also shows no obstruction between Deri and Nawara
  • Conclusion: There was a line of fire between Deri and Nawara – throughout the day and also specifically at 13:45:10.

Another of the defense conspiracy theories, is that the person seen falling in the video, isn’t Nawara. This claim is based on the fact that at the time he was shot, Nawara’s face was covered. A second fact supporting this claim, is that Nawara was left handed, and the person claimed to be Nawara, is seen at one of the times he is throwing stones, throwing a stone with his right hand.

I haven’t seen the footage myself (just read of it in the trial’s protocols), but if it’s one time out of all the rest, than this doesn’t have much meaning. Perhaps he just did it once. Perhaps his left arm was hurting from previous throws. I can’t say. In the footage I’ve seen, he is throwing with his left hand. Anyway, we’ll deal with the identification problem, in better and more reliable ways.


Nawara in the protest that day, holding a stone with his left hand

The identification oversight:

Another example of negligence by the prosecution, can be found in their failure to properly identify Nawara in the footage. They did have Nawara’s father, Siam, identify his son, but only in the security footage. The defense, in its cross examination, got Siam to admit the obvious: He identified his son in the security camera footage, only by the way he walks and the clothes he’s wearing. Not a facial identification (which cannot be done with that footage).

Identification by clothing:

You can See Nawara’s clothing from that day, in the picture above (and more further down). I’ll show you one photo from his past, showing him with the same Keffiyeh and bag, but there’s endless video and footage of him from the months prior, Wearing the same clothes:


Facial Identification:

Aside from the security cameras, we have other photos from the event, which clearly show Nawara’s face (and they all sync with the security cameras):

This slideshow requires JavaScript.

And here’s a video zooming to make it clearer:

The prosecution did introduce the footage I’ve shown you into evidence, but there’s a legal distinction between “here are photos showing Nawara” and “Sir, do you recognize your son in this photo?”. Its technical, but necessary. So let us, again, mention the obvious: Siam and the rest of Nadeem’s family, identify him in the footage from that day.

In Conclusion:

  • all the witnesses who knew Nawara, testify he was there and he is the person collapsing in the footage
  • The clothing match
  • The still photos clearly show his face and his family and friends identify him in those photos
  • Conclusion: Nawara is the character in the security camera’s footage

This one is simple by now, because as we’ve already seen and proven Nawara was alive  during the protest, as documented by video and photos, and testified by the people there who knew him.

In another of the prosecution’s failures, the samples taken from Nawara’s body failed to produce DNA, and the prosecution didn’t ask to retake samples in order to validate the identity of the body (which was already partially decomposed). Even if the prosecution didn’t want to put the family through a second grave opening, it could have at least tested Nawara’s little brother, in order to eliminate him as the source of the DNA found on the bloody bag (which the test found originated from a male offspring of Nawara’s parents). The prosecution could have also asked to test a hair brush of Nawara’s or something he left that might have his DNA on it.

None of this was done (the family wasn’t even aware that the identification failed until i told them). I’m not saying the prosecution tried to fail, but it sure succeeded in doing so. As a result, the defense claimed that the body from the autopsy isn’t Nawara’s at all. So Lets prove Nawara did die.


  • We have photos and movies of the bodies, but it’s up to you if you want to check them or just believe me (be aware the images are graphic). Nawara’s body can easily be identified as you can see his face and also the scar on his chin (i added a picture from his past for comparison):
  • Videos from the funeral: 1,2,3,4,5,6,7
  • For photos after the bodies were cleaned and dressed, click here.

So we’ve got plenty of documentation of the bodies. But, obviously, the defense claims those might be fake (though if it is, it is beyond Hollywood level). But we also have hundreds and even thousands of people who saw and even touched the bodies. But here again, we return to Israel’s belief in a vast national-effort Pallywood, not only made up of the hundreds involved in the “fake shooting”, but thousands more in the “fake funeral”.

The “Legitimate” Witnesses:

Since Israelis don’t believe Palestinians and since the prosecution didn’t care to do it, i went and looked for Israeli-Jews who saw the bodies. Finally i came across two photo journalists who were in the morgue with Nawara’s body:

This slideshow requires JavaScript.

First, before we start another conspiracy theory going: no… the dead don’t always close their eyes, and when they don’t it’s very hard to force it (37% remain with eyes open).

Aside from their photos (above) I also asked to interview them as eyewitnesses to Nawara’s lifeless corpse:

  • Yotam Ronen is an independent photographer who publishes with Walla! and Activestills. Mentioning the obvious: He is an Israeli Jew. Yotam arrived at the morgue the day after the shootings. He testifies  that as a photographer in Palestine and Israel he’s seen dozens of bodies, and while he isn’t a doctor, Nawara and Abu Daher were lifeless and didn’t move or breathe. Yotam was with the bodies in the small morgue for 4 minutes and in the funeral for 30.
  • The second photographer is a ‘Getty images’ worker, who preferred to remain anonymous. He too is an Israeli Jew, who spent 5-10 minutes with the bodies in morgue, and he too testifies they were dead.

In Conclusion:

  • We have the Palestinian’s death certificates
  • We have many videos and photos of the bodies
  • We have thousands of Palestinian witnesses
  • And for those who don’t believe Palestinians, we have two Jewish witnesses
  • As such, Nawara’s death is proven, by any sane standard


We have one Palestinian witness (the owner of the carpentry factory), who says the shot that killed Nawara, came from IDF soldiers, who were stationed that day on what is known as “The surface”. Could this be true?


Position and distances between Deri, the surface & Nawara

It’s almost impossible to locate the source of a shot based on sound. You might be able to say it came from the left or right, back or front, but actually differentiating between two close locations, is virtually impossible to do without the help of computers and microphones.

The factory owner was sitting on the balcony of his home, from which he couldn’t see Deri or his force. Blind to them, it’s likely that he naturally connected the sound with the visual information available to him, which was only the soldiers on the surface.

He also testified he thought Deri’s force and the protesters couldn’t even see each other. Since we know this to be wrong, it just further exemplifies how his field of view formed his erroneous conclusions. But Lets go beyond disproving his testimony and proving the shot didn’t come from the surface.

CNN’s Cameraman:

The Cameramen and photographers that day, located themselves outside of the crossfire of the stones and bullets. Below you can see CNN’s location and how close they were to the line of fire between the surface and Nawara. They stood there facing the balcony, because it was facing the action, while still being safe.


This is how CNN’s cameraman responded to the defense’s claim that the shots came from the surface:

 “I’ll tell you one thing, if that soldier was shooting at my direction i would have screamed at him, that’s what i would have done. I would have screamed “are you crazy? to shoot at us?”. I would have noticed if someone was shooting from there [the surface]. it’s flat”.

The stone throwers reaction:

Throughout that day, the stone thrower snever hide from the surface – only from the balcony. You can see it in all the footage: a shot is fired, they run to the wall of the carpentry factory (see picture below), which hides them from the balcony, but not the surface.


Top: White arrow marks Deri’s location and the red frame his view of the dead and injured that day. Bottom: The same view enlarged. Left of them is the carpentry factory.

The Open-Fire instructions:

The soldiers on the surface were not given clearance to shoot at any time that day – live rounds or rubber. There is no testimony or evidence, in the IDF, the police or by the defense, that claims that any one approved fire or shot without approval.

Deri’s force on the other hand, were given instructions to use non-lethal fire (rubber coated cylinders, gas grenades and the sorts). Within an area of permitted fire, you might be able to conceal unpermitted fire  (for example: Deri’s force allowed an IDF photographer to snipe rubber coated cylinders at Palestinians for fun). But the soldiers on the surface, didn’t fire at all. If one of them had taken a shot, it would’ve been unconcealable. In order to conceal it after the fact, they would all have to back the shooter up, in an IDF conspiracy to to frame Deri (a fellow soldier) and help the Palestinians (which is obviously absurd).

Difficulty of the shot:

IDF’s expert testified that a shot from the surface would have been tricky: 250m (compared to Deri’s 80m), on the same level (compared to Deri’s 5m elevation), with obstacles in the middle (Utility poles obstructing the view). Not impossible, but difficult. Here’s a zooming from Nawara’s point of view, to the surface:

Syncing to Deri:

We have the CNN video, which shows Deri’s shot synced to Nawara’s fall. If a soldier from the surface took a shot at the same time, he’d have to somehow sync it to Deri as he pulled the trigger – something which cannot be done. Even if it happened by accident, The distance between Deri and the surface, and them being on different sides of the CNN camera, would have resulted with the sound of two different shots.

The Bullet:

If another soldier killed Nawara, then why does the bullet match Deri’s rifle? Though it’s a possibility that a similar enough rifle was used, but it cannot be planned in advance and must be based on luck alone. Who would take such a gamble?

The bullet’s cavity canal:

If the shot was made from the surface, than why does the cavity canal in Nawara’s body fit a shot from Deri’s location? Nawara was shot on the right side of his chest (i censored the open wound and stitches from the surgery, but you can see the entry point of the bullet):


Now look where Nawara is facing when he was shot:


A shot from the surface will arrive roughly from the direction of the red arrow, while Nawara is facing Deri (the black arrow).

Even if the supposed surface sniper made the shot, the angle would be sharp: the bullet would hit Nawara not perpendicularly (like from Deri’s location), but more in the area of 45 degrees, pointing at Nawara’s right shoulder.

3man english.jpg

Nawara’s bullet cavity canal, describes a shot from the front. We did learn that this bullet isn’t loyal to its ballistic trajectory, but it’s still loyal to the general direction of the momentum from that trajectory. You can think about it like a first time ice skater who’s pushed forward. He’ll make awkward motions that would move him a bit here and there, but still in the general direction in which he was pushed at (with the direction of the vector). The bullet’s bodily trajectory, will be limited to a cone of possibilities, which open from the ballistic trajectory and in its direction.


The turn that would be required from a bullet from the surface to fit the cavity is extremely unlikely. Not only is it unlikely, but the cavity shows no such turn.  Furthermore, the cavity indicates the shot came from above Nawara, and the surface has no elevation over Nawara’s location.

In Conclusion:

  • A shot from the surface is difficult to make, with 250m to Nawara and obstacles in its path.
  • except for one witness who couldn’t see Deri, every one else testifies all shots that day came from the balcony (Including the army and the police).
  • Concealing the shot from the surface would require syncing with Deri’s trigger pull, which is impossible.
  • If it was synced by luck, then because no other shots were made from the surface that day, the other soldiers on the surface would be aware of it. And so, it would require a conspiracy of soldiers against soldiers, for the benefit of their enemy.
  • The bullet found matched Deri’s rifle and is unlikely to match one of the other soldier’s rifles.
  • Deri’s shot syncs to Nawara’s fall.
  • The bullet’s permanent cavity fits a shot from Deri’s location and doesn’t fit a shot from the surface.
  • Put together, the likelihood of the shot originating from the surface is infinitesimal and doesn’t reach or even come close to reasonable doubt.

From previous sections, we already know that Deri fired a live round. We also know that the shot syncs with Nawara’s fall and that the cavity fits a shot from Deri’s general location. The fragments matched the bullet which matched Deri’s rifle.

Even if such an invisible-Palestinian-James-Bond-sniper existed, and even if by chance Deri missed his shot and the unknown sniper’s shot was silenced, we still couldn’t explain the matching of the fragments and bullet to Deri’s rifle.

Again, since the fragments & bullet match Deri’s rifle, it would require a Palestinian  “mission impossible” team, which collects bullets and bodies from Israeli shootings. Then a body swap is required and it has to be a shot Deri made in the recent past (otherwise the body would rot or show signs of preservation). Yet we know of no such shot made by Deri. The two shots Deri makes – the theoretical legal shot from Deri’s recent past and the rubber shot at Nawara – would have to be from roughly the same location in order for the wounds to match. The DNA testing needs to be sabotaged in some way (since the body doesn’t belong to the killed “actor”).

Since there’s no previous shot by Deri for a “body swap” or a “fragments implantation surgery”, and since even if there was it would be way beyond CIA or Mossad’s capabilities (let alone the barley functioning Palestinian authority), this obviously is impossible.

The Body in the autopsy wasn’t Nawara’s

Since the DNA testing of the body failed and the prosecution didn’t ask for a second test, the defense claims maybe the body isn’t Nawara’s at all and then all the evidence derived from it – mainly the bullet fragments – are irrelevant. What Identifies the body from the autopsy as Nawara?

The body and Nawara:

  • The wounds are in the same locations as Nawara’s wounds
  • The body is of a young male, with short dark hair, 169cm in height and weighed 50kg – all fits Nawara
  • The body had a surgical incision which was crudely stitched – 12cm horizontally and then 28cm vertically – all identical to Nawara’s body in the morgue:961085_10152354916571391_1265068530_n
  • Another incision on the right side of the body (not seen in the image above), which is done for inflating the lung, also match Nawara’s operation before he died
  • The shoes generally match (a timberland style brown boot).

The autopsy details were taken from the reports which, if you don’t believe me, you can read here (otherwise skip ahead):


Why would they swap the bodies? We’ve established the person collapsing in the video is Nawara and that he definitely died. If it was “Pallywood” and he wasn’t really hit or was hit by a rubber bullet only, then the Palestinians killed him after the event and before the hospital. But why? He is the person they claimed that died, so why use another body? Now we return to the fragments problem (if Nawara wasn’t shot by a live round from Deri, the fragments would be missing or a mismatch for Deri’s bullet). But as we discussed before, this would require the “mission impossible” team finding another body from Deri’s near-past; a body which doesn’t exist.

The other option, contrary to all these insanely complex conspiracies, is that the person seen in the video shooting the person that is seen falling, shot him.

Surely Occam’s razor would slit these theories at their illogical throats, versus the simplicity of accepting the what is seen is what happened. But this isn’t only a case of choosing the simpler possibility, but rather the only one that is actually plausible.

As you’ve seen, the conspiracy theories acquitting Deri are so improbable, that even his supporters probably won’t buy in to them. Deri’s lawyer, Tzion Amir, is to smart not be aware of this. He raises these theories as a hail Mary and perhaps to squeeze a better deal (which he has), but you don’t rely on them actually being accepted by the court.

This is how we reached the plea deal that was signed a few days ago, convicting Deri only of negligent homicide and aggravated assault. The deal is based on a theory in which the live bullet fired by Deri, got there without his knowledge or intent. He should have checked his magazine, but he didn’t (hence the negligent) and accidentally killed Nawara, when all he wanted was to shot a rubber bullet.

We shall now test the feasibility of this the bullet mix-up theory. Note that according to this theory, all previous conspiracies are false and no doubt that you might found there, is valid here. In the mix-up theory, both sides agree that Deri did fire a live bullet, which did kill Nawara, as seen on the footage. The only thing in debate here, is Deri’s knowledge of the live bullet’s existence and the probability of such an occurrence.

Outside Deri’s mind:

Since we can’t access Deri’s thoughts and know his intent, we seemingly must arrive at a reasonable doubt, and only convict him in negligence, as the prosecution did in the plea deal. So how will i go inside Deri’s mind and prove murder or homicide? in two ways:

  • Proof by contradiction –
    Proving the mix-up is impossible or improbable beyond a reasonable doubt. If I’ll prove that, the only remaining option will be murder.
  • Proof of intent –
    circumstantial evidence which show malice and partial confessions (by accident and by advertising his pride in the killings)

Lets begin.

The sterile war room

The loading of the blank magazines used for launching the rubber coated cylinders, is done in the war room of the base, where no live ammunition is allowed (Live magazines are loaded in a completely different location). The Sergeant from Deri’s company in charge of loading the magazines, explained the process in his testimony:

  • Closed boxes arrive with the blank bullets to the war room and are store in a back room, which holds all the non-lethal weapons.
  • The sergeant currently in shift will take a box of blanks from the back room to his table in the war room, and load them into regular empty magazines which have been painted red to mark they’re for blank use only.
  • At the end of each magazine the sergeant looks inside it to see there’s no bullet tip (the projectile which the blanks don’t have).
  • When a fire-team or a squad needs equipment, the squad’s commander goes to the war room and signs off on what he needs. He is then suppose the inspect the magazines again, to see no live bullet somehow got inside one of them.

In theory and by the rules, the war room is supposed to be sterile of any live ammunition. But Deri’s lawyer quickly proves with photos from inside the war room, that this isn’t the case. Soldiers are seen entering the war room with their personal guns, and the magazines attached to them (loaded with live bullets). So does this mean that a bullet mix-up is possible?

The chain of  mix-ups

The Israeli press explained the plea deal to the public, as if one mistake is all that was required for the tragic unintended result. But is this true? What is the chain of mishaps required for the end result of this case? The war room isn’t sterile as it should be, but bullets don’t just fall out of magazines:

  • lets assume that one bullet did fall out or a soldier was playing with a live round in his hand, and it fell in the war room.
    • But the blanks are in back room.
  • So lets assume that the accidental fall of the bullet, happened during the loading of blanks into magazines.
    • But they’re still inside a box on the table.
  • So lets assume it fell from a magazine or a hand, directly into the box.
    • But then the sergeant would pick it up and notice it’s a live round.
  • So he missed it. It’s dull work, and he wasn’t paying attention.
    • But when he finishes loading the magazine, he looks inside to see if there a live bullet.
  • So he didn’t look or missed that too.
    • But the sergeant testified this never happens. Deri’s lawyer tries to lead him: “were all human. maybe the lighting was bad. maybe just once”. The sergeant answers decisively – no. It never happens.
  • But lets assume that it did.
    • Than the Squad’s commander should have seen the bullet when he checked.
  • So maybe he too didn’t look or missed it.

So as you see, a single mistake isn’t sufficient for the end result of killing Nawara with a live bullet. A whole chain of random mistakes has to occur. Each mistake is unlikely by itself, but as a combination which also requires a specific order and synchronization, it’s unheard of. The sergeant, who is a friend of Deri, testified there has never been such an incident. Trying to crack his confidence he was asked again, maybe it happened somewhere else or in the past. “No!”, he replied. Unheard of.

I can add that after a lot of research, i have found no previous example of such a chain of mistakes in the IDF or the Israeli police. If it happened, it wasn’t in the last 30 years or so (prior to digital documentation). And 30 years ago (even 20 years ago), the whole separation between live rounds and blanks didn’t exist. In fact, the whole extension for firing rubber coated cylinders was only developed in Israel in 1989, which means if a case cannot be found up until then (which it cannot), then there is no such previous case.

