Win32/ConMiner
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Win32/ConMiner
Prosím o pomoc s virem.
vypnul antivir a při pokusech o spuštěni antiviru dochazi k restartu PC
vkládam sken
Logfile of random's system information tool 1.09 (written by random/random)
Run by vanda at 2011-08-27 15:55:10
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 270 GB (88%) free of 305 GB
Total RAM: 2047 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:55:15, on 27.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\update.tray-3-0\svchost.exe
C:\Windows\sysdriver32.exe
C:\Windows\sysdriver32_.exe
C:\Windows\systemup.exe
C:\Windows\l1rezerv.exe
C:\Windows\vsnp2uvc.exe
C:\Windows\tsnp2uvc.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Programy\Skype\Phone\Skype.exe
C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Programy\Skype\Plugin Manager\skypePM.exe
C:\Users\vanda\Desktop\RSIT.exe
C:\Program Files\trend micro\vanda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programy\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-3-0\svchost.exe
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKCU\..\Run: [Skype] "C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [InternetCalls] "C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programy\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programy\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programy\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programy\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ddservice - Unknown owner - C:\Windows\update.7.1\svchostdriver.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 9624 bytes
=========Mozilla firefox=========
ProfilePath - C:\Users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Win7codecs\rm\browser\plugins\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69]
"Description"=6.0.12.69
"Path"=C:\Program Files\Win7codecs\rm\browser\plugins\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Programy\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll [2011-04-20 2194464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-06 187672]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-02-08 8505888]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-01-12 37888]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-15 644696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"wxpdrv"=C:\Windows\services32.exe [2011-08-23 1211904]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-3-0\svchost.exe [2011-08-23 1211904]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-08-23 258048]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-08-23 258048]
"systemup"=C:\Windows\systemup.exe [2011-08-23 137728]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-08-23 232960]
"snp2uvc"=C:\Windows\vsnp2uvc.exe [2009-06-22 662016]
"tsnp2uvc"=C:\Windows\tsnp2uvc.exe [2009-06-26 241664]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2516296]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Programy\Skype\Phone\Skype.exe [2010-04-20 26192680]
"InternetCalls"=C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe [2011-08-27 13871928]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Programy\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.reg - open - "%1" %*
.scr - open - "%1" %*
======List of files/folders created in the last 1 month======
2011-08-27 15:46:57 ----D---- C:\rsit
2011-08-27 15:46:57 ----D---- C:\Program Files\trend micro
2011-08-27 15:08:21 ----D---- C:\Program Files\CCleaner
2011-08-27 14:30:12 ----D---- C:\Users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 14:29:49 ----HD---- C:\ProgramData\CanonIJEPPEX
2011-08-27 14:29:21 ----HD---- C:\ProgramData\CanonIJSolutionMenuEX
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonIJMyPrinter
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonIJEPPEX2
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonEPP
2011-08-27 14:21:19 ----D---- C:\ProgramData\CanonIJMSetup
2011-08-27 14:19:16 ----D---- C:\Program Files\Common Files\CANON
2011-08-27 14:19:07 ----D---- C:\ProgramData\CanonIJWSpt
2011-08-27 14:16:54 ----A---- C:\Windows\system32\CNMLMAF.DLL
2011-08-27 14:16:50 ----A---- C:\Windows\system32\CNMIUAF.DLL
2011-08-27 14:02:14 ----D---- C:\Program Files\Common Files\ArcSoft
2011-08-27 14:02:12 ----RA---- C:\Windows\system32\unicows.dll
2011-08-27 14:02:12 ----A---- C:\Windows\system32\drivers\afc.sys
2011-08-27 14:01:37 ----SHD---- C:\Config.Msi
2011-08-27 13:57:28 ----D---- C:\Program Files\Trust Webcam
2011-08-27 13:57:28 ----A---- C:\Windows\tsnp2uvc.exe
2011-08-27 13:57:28 ----A---- C:\Windows\amcap.exe
2011-08-27 13:57:03 ----D---- C:\Users\vanda\AppData\Roaming\InstallShield
2011-08-25 19:04:20 ----A---- C:\Windows\system32\tzres.dll
2011-08-25 18:24:43 ----HD---- C:\Windows\update.8.1
2011-08-23 12:04:54 ----D---- C:\ATI
2011-08-23 11:57:46 ----D---- C:\Windows\ufa
2011-08-23 11:57:46 ----D---- C:\Windows\rpcminer
2011-08-23 11:57:46 ----D---- C:\Windows\phoenix
2011-08-23 11:56:14 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-23 11:56:11 ----A---- C:\Windows\l1rezerv.exe
2011-08-23 11:56:07 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-23 11:55:57 ----HD---- C:\Windows\update.7.1
2011-08-23 11:55:50 ----HD---- C:\Windows\update.2
2011-08-23 11:55:24 ----HD---- C:\Windows\update.5.0
2011-08-23 11:55:08 ----A---- C:\Windows\systemup.exe
2011-08-23 11:54:43 ----A---- C:\Windows\iplist.txt
2011-08-23 11:54:38 ----A---- C:\Windows\unrar.exe
2011-08-23 11:53:39 ----A---- C:\Windows\sysdriver32_.exe
2011-08-23 11:53:25 ----A---- C:\Windows\sysdriver32.exe
2011-08-23 11:53:08 ----A---- C:\Windows\front_ip_list.txt
2011-08-23 11:53:05 ----D---- C:\Windows\av_ico
2011-08-23 11:52:05 ----HD---- C:\Windows\update.1
2011-08-23 11:52:03 ----HD---- C:\Windows\update.tray-3-0-lnk
2011-08-23 11:52:03 ----HD---- C:\Windows\update.tray-3-0
2011-08-23 08:50:52 ----A---- C:\Windows\winlog-ids.txt
2011-08-23 08:50:52 ----A---- C:\Windows\winlog-dirs.txt
2011-08-23 08:50:47 ----A---- C:\Windows\services32.exe
2011-08-14 20:37:21 ----D---- C:\Users\vanda\AppData\Roaming\vlc
2011-08-10 21:42:03 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-10 21:42:03 ----A---- C:\Windows\system32\iertutil.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jscript9.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jscript.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\ieui.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\wininet.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\urlmon.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\url.dll
2011-08-10 21:42:00 ----A---- C:\Windows\system32\ieframe.dll
2011-08-10 21:41:59 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 19:18:44 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 19:18:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 19:18:37 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-10 19:18:36 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 19:18:30 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-10 19:18:28 ----A---- C:\Windows\system32\kernel32.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\conhost.exe
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 19:18:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbcjt32.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-10 19:18:22 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-10 19:18:22 ----A---- C:\Windows\system32\odbccp32.dll
2011-07-31 20:10:13 ----D---- C:\ProgramData\tmp
2011-07-31 20:10:12 ----D---- C:\ProgramData\hps
2011-07-31 20:02:13 ----D---- C:\Program Files\dm
======List of files/folders modified in the last 1 month======
2011-08-27 15:53:27 ----D---- C:\ProgramData\Easybits GO
2011-08-27 15:53:22 ----D---- C:\Users\vanda\AppData\Roaming\Skype
2011-08-27 15:51:24 ----D---- C:\Windows\Temp
2011-08-27 15:51:24 ----D---- C:\Windows\system32\config
2011-08-27 15:46:57 ----D---- C:\Program Files
2011-08-27 15:45:19 ----D---- C:\Windows\System32
2011-08-27 15:45:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-27 15:45:18 ----D---- C:\Windows\inf
2011-08-27 15:17:52 ----D---- C:\Windows\system32\catroot2
2011-08-27 15:16:14 ----D---- C:\Windows
2011-08-27 15:12:36 ----D---- C:\Program Files\Zrychleni Pocitace
2011-08-27 15:09:20 ----D---- C:\Users\vanda\AppData\Roaming\Winamp
2011-08-27 15:09:07 ----D---- C:\Windows\debug
2011-08-27 14:59:03 ----D---- C:\Windows\Prefetch
2011-08-27 14:38:29 ----D---- C:\ProgramData\CanonIJPLM
2011-08-27 14:38:24 ----SHD---- C:\Windows\Installer
2011-08-27 14:38:24 ----HD---- C:\ProgramData
2011-08-27 14:31:59 ----SD---- C:\ProgramData\Microsoft
2011-08-27 14:19:25 ----D---- C:\Program Files\Canon
2011-08-27 14:19:16 ----D---- C:\Program Files\Common Files
2011-08-27 14:17:03 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-08-27 14:17:02 ----D---- C:\Windows\system32\catroot
2011-08-27 14:17:01 ----D---- C:\Windows\system32\DriverStore
2011-08-27 14:02:28 ----D---- C:\Users\vanda\AppData\Roaming\ArcSoft
2011-08-27 14:02:12 ----D---- C:\Windows\system32\drivers
2011-08-27 14:01:57 ----D---- C:\Program Files\ArcSoft
2011-08-27 14:01:56 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-27 13:57:21 ----SHD---- C:\System Volume Information
2011-08-27 13:53:45 ----D---- C:\Windows\twain_32
2011-08-27 08:27:16 ----D---- C:\Users\vanda\AppData\Roaming\go
2011-08-25 20:28:34 ----D---- C:\Windows\winsxs
2011-08-25 20:28:28 ----D---- C:\Windows\system32\cs-CZ
2011-08-23 13:10:26 ----D---- C:\Users\vanda\AppData\Roaming\InternetCalls
2011-08-23 13:05:52 ----SD---- C:\Users\vanda\AppData\Roaming\Microsoft
2011-08-23 12:25:13 ----D---- C:\Program Files\ATI Technologies
2011-08-23 11:56:10 ----D---- C:\Windows\system32\drivers\etc
2011-08-18 18:31:35 ----D---- C:\Users\vanda\AppData\Roaming\Canon
2011-08-12 10:17:33 ----D---- C:\Windows\Microsoft.NET
2011-08-12 10:17:31 ----RSD---- C:\Windows\assembly
2011-08-11 11:18:53 ----D---- C:\Windows\system32\migration
2011-08-11 11:18:52 ----D---- C:\Program Files\Internet Explorer
2011-08-10 21:40:53 ----A---- C:\Windows\system32\MRT.exe
2011-08-04 15:06:53 ----D---- C:\Ula
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-31 7680]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-14 4194816]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-02-08 3019232]
R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-23 3486336]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ddservice;ddservice; C:\Windows\update.7.1\svchostdriver.exe [2011-08-23 382464]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-08-23 355840]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-08-24 636416]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-08-23 258048]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-08-23 1211904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Programy\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
-----------------EOF-----------------
vypnul antivir a při pokusech o spuštěni antiviru dochazi k restartu PC
vkládam sken
Logfile of random's system information tool 1.09 (written by random/random)
Run by vanda at 2011-08-27 15:55:10
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 270 GB (88%) free of 305 GB
Total RAM: 2047 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:55:15, on 27.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\update.tray-3-0\svchost.exe
C:\Windows\sysdriver32.exe
C:\Windows\sysdriver32_.exe
C:\Windows\systemup.exe
C:\Windows\l1rezerv.exe
C:\Windows\vsnp2uvc.exe
C:\Windows\tsnp2uvc.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Programy\Skype\Phone\Skype.exe
C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Programy\Skype\Plugin Manager\skypePM.exe
C:\Users\vanda\Desktop\RSIT.exe
C:\Program Files\trend micro\vanda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programy\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-3-0\svchost.exe
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKCU\..\Run: [Skype] "C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [InternetCalls] "C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programy\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programy\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programy\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programy\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ddservice - Unknown owner - C:\Windows\update.7.1\svchostdriver.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 9624 bytes
=========Mozilla firefox=========
ProfilePath - C:\Users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Win7codecs\rm\browser\plugins\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69]
"Description"=6.0.12.69
"Path"=C:\Program Files\Win7codecs\rm\browser\plugins\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Programy\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Users\vanda\AppData\Local\Seznam.cz\listicka.dll [2011-04-20 2194464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-06 187672]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Programy\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-02-08 8505888]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-01-12 37888]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-15 644696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"wxpdrv"=C:\Windows\services32.exe [2011-08-23 1211904]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-3-0\svchost.exe [2011-08-23 1211904]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-08-23 258048]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-08-23 258048]
"systemup"=C:\Windows\systemup.exe [2011-08-23 137728]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-08-23 232960]
"snp2uvc"=C:\Windows\vsnp2uvc.exe [2009-06-22 662016]
"tsnp2uvc"=C:\Windows\tsnp2uvc.exe [2009-06-26 241664]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2516296]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Programy\Skype\Phone\Skype.exe [2010-04-20 26192680]
"InternetCalls"=C:\Programy\InternetCalls.com\InternetCalls\internetcalls.exe [2011-08-27 13871928]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Programy\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.reg - open - "%1" %*
.scr - open - "%1" %*
======List of files/folders created in the last 1 month======
2011-08-27 15:46:57 ----D---- C:\rsit
2011-08-27 15:46:57 ----D---- C:\Program Files\trend micro
2011-08-27 15:08:21 ----D---- C:\Program Files\CCleaner
2011-08-27 14:30:12 ----D---- C:\Users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 14:29:49 ----HD---- C:\ProgramData\CanonIJEPPEX
2011-08-27 14:29:21 ----HD---- C:\ProgramData\CanonIJSolutionMenuEX
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonIJMyPrinter
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonIJEPPEX2
2011-08-27 14:29:20 ----HD---- C:\ProgramData\CanonEPP
2011-08-27 14:21:19 ----D---- C:\ProgramData\CanonIJMSetup
2011-08-27 14:19:16 ----D---- C:\Program Files\Common Files\CANON
2011-08-27 14:19:07 ----D---- C:\ProgramData\CanonIJWSpt
2011-08-27 14:16:54 ----A---- C:\Windows\system32\CNMLMAF.DLL
2011-08-27 14:16:50 ----A---- C:\Windows\system32\CNMIUAF.DLL
2011-08-27 14:02:14 ----D---- C:\Program Files\Common Files\ArcSoft
2011-08-27 14:02:12 ----RA---- C:\Windows\system32\unicows.dll
2011-08-27 14:02:12 ----A---- C:\Windows\system32\drivers\afc.sys
2011-08-27 14:01:37 ----SHD---- C:\Config.Msi
2011-08-27 13:57:28 ----D---- C:\Program Files\Trust Webcam
2011-08-27 13:57:28 ----A---- C:\Windows\tsnp2uvc.exe
2011-08-27 13:57:28 ----A---- C:\Windows\amcap.exe
2011-08-27 13:57:03 ----D---- C:\Users\vanda\AppData\Roaming\InstallShield
2011-08-25 19:04:20 ----A---- C:\Windows\system32\tzres.dll
2011-08-25 18:24:43 ----HD---- C:\Windows\update.8.1
2011-08-23 12:04:54 ----D---- C:\ATI
2011-08-23 11:57:46 ----D---- C:\Windows\ufa
2011-08-23 11:57:46 ----D---- C:\Windows\rpcminer
2011-08-23 11:57:46 ----D---- C:\Windows\phoenix
2011-08-23 11:56:14 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-23 11:56:11 ----A---- C:\Windows\l1rezerv.exe
2011-08-23 11:56:07 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-23 11:55:57 ----HD---- C:\Windows\update.7.1
2011-08-23 11:55:50 ----HD---- C:\Windows\update.2
2011-08-23 11:55:24 ----HD---- C:\Windows\update.5.0
2011-08-23 11:55:08 ----A---- C:\Windows\systemup.exe
2011-08-23 11:54:43 ----A---- C:\Windows\iplist.txt
2011-08-23 11:54:38 ----A---- C:\Windows\unrar.exe
2011-08-23 11:53:39 ----A---- C:\Windows\sysdriver32_.exe
2011-08-23 11:53:25 ----A---- C:\Windows\sysdriver32.exe
2011-08-23 11:53:08 ----A---- C:\Windows\front_ip_list.txt
2011-08-23 11:53:05 ----D---- C:\Windows\av_ico
2011-08-23 11:52:05 ----HD---- C:\Windows\update.1
2011-08-23 11:52:03 ----HD---- C:\Windows\update.tray-3-0-lnk
2011-08-23 11:52:03 ----HD---- C:\Windows\update.tray-3-0
2011-08-23 08:50:52 ----A---- C:\Windows\winlog-ids.txt
2011-08-23 08:50:52 ----A---- C:\Windows\winlog-dirs.txt
2011-08-23 08:50:47 ----A---- C:\Windows\services32.exe
2011-08-14 20:37:21 ----D---- C:\Users\vanda\AppData\Roaming\vlc
2011-08-10 21:42:03 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-10 21:42:03 ----A---- C:\Windows\system32\iertutil.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jscript9.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\jscript.dll
2011-08-10 21:42:02 ----A---- C:\Windows\system32\ieui.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\wininet.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\urlmon.dll
2011-08-10 21:42:01 ----A---- C:\Windows\system32\url.dll
2011-08-10 21:42:00 ----A---- C:\Windows\system32\ieframe.dll
2011-08-10 21:41:59 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 19:18:44 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 19:18:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 19:18:37 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-10 19:18:36 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 19:18:30 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-10 19:18:28 ----A---- C:\Windows\system32\kernel32.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-10 19:18:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-10 19:18:27 ----A---- C:\Windows\system32\conhost.exe
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 19:18:26 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 19:18:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 19:18:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbcjt32.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-10 19:18:23 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-10 19:18:22 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-10 19:18:22 ----A---- C:\Windows\system32\odbccp32.dll
2011-07-31 20:10:13 ----D---- C:\ProgramData\tmp
2011-07-31 20:10:12 ----D---- C:\ProgramData\hps
2011-07-31 20:02:13 ----D---- C:\Program Files\dm
======List of files/folders modified in the last 1 month======
2011-08-27 15:53:27 ----D---- C:\ProgramData\Easybits GO
2011-08-27 15:53:22 ----D---- C:\Users\vanda\AppData\Roaming\Skype
2011-08-27 15:51:24 ----D---- C:\Windows\Temp
2011-08-27 15:51:24 ----D---- C:\Windows\system32\config
2011-08-27 15:46:57 ----D---- C:\Program Files
2011-08-27 15:45:19 ----D---- C:\Windows\System32
2011-08-27 15:45:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-27 15:45:18 ----D---- C:\Windows\inf
2011-08-27 15:17:52 ----D---- C:\Windows\system32\catroot2
2011-08-27 15:16:14 ----D---- C:\Windows
2011-08-27 15:12:36 ----D---- C:\Program Files\Zrychleni Pocitace
2011-08-27 15:09:20 ----D---- C:\Users\vanda\AppData\Roaming\Winamp
2011-08-27 15:09:07 ----D---- C:\Windows\debug
2011-08-27 14:59:03 ----D---- C:\Windows\Prefetch
2011-08-27 14:38:29 ----D---- C:\ProgramData\CanonIJPLM
2011-08-27 14:38:24 ----SHD---- C:\Windows\Installer
2011-08-27 14:38:24 ----HD---- C:\ProgramData
2011-08-27 14:31:59 ----SD---- C:\ProgramData\Microsoft
2011-08-27 14:19:25 ----D---- C:\Program Files\Canon
2011-08-27 14:19:16 ----D---- C:\Program Files\Common Files
2011-08-27 14:17:03 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-08-27 14:17:02 ----D---- C:\Windows\system32\catroot
2011-08-27 14:17:01 ----D---- C:\Windows\system32\DriverStore
2011-08-27 14:02:28 ----D---- C:\Users\vanda\AppData\Roaming\ArcSoft
2011-08-27 14:02:12 ----D---- C:\Windows\system32\drivers
2011-08-27 14:01:57 ----D---- C:\Program Files\ArcSoft
2011-08-27 14:01:56 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-27 13:57:21 ----SHD---- C:\System Volume Information
2011-08-27 13:53:45 ----D---- C:\Windows\twain_32
2011-08-27 08:27:16 ----D---- C:\Users\vanda\AppData\Roaming\go
2011-08-25 20:28:34 ----D---- C:\Windows\winsxs
2011-08-25 20:28:28 ----D---- C:\Windows\system32\cs-CZ
2011-08-23 13:10:26 ----D---- C:\Users\vanda\AppData\Roaming\InternetCalls
2011-08-23 13:05:52 ----SD---- C:\Users\vanda\AppData\Roaming\Microsoft
2011-08-23 12:25:13 ----D---- C:\Program Files\ATI Technologies
2011-08-23 11:56:10 ----D---- C:\Windows\system32\drivers\etc
2011-08-18 18:31:35 ----D---- C:\Users\vanda\AppData\Roaming\Canon
2011-08-12 10:17:33 ----D---- C:\Windows\Microsoft.NET
2011-08-12 10:17:31 ----RSD---- C:\Windows\assembly
2011-08-11 11:18:53 ----D---- C:\Windows\system32\migration
2011-08-11 11:18:52 ----D---- C:\Program Files\Internet Explorer
2011-08-10 21:40:53 ----A---- C:\Windows\system32\MRT.exe
2011-08-04 15:06:53 ----D---- C:\Ula
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-31 7680]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-14 4194816]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-02-08 3019232]
R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-23 3486336]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ddservice;ddservice; C:\Windows\update.7.1\svchostdriver.exe [2011-08-23 382464]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-08-23 355840]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-08-24 636416]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-08-23 258048]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-08-23 1211904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Programy\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
-----------------EOF-----------------
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
Zdravím, tady mu říkáme FB virus.
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Úplná kontrola -> Prohledat
po ukončení -> Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené
vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych rád viděl
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Win32/ConMiner
doufam že je to dobře.
xml version="1.0" encoding="UTF-8"?>
-<AROScanLog> <AROVersion>6.0.793.824</AROVersion> <ScanningDate>Sat. August 27, 2011. 07:34 PM</ScanningDate> <TotalRegErrorsFound>379</TotalRegErrorsFound> <TotalJunkErrorsFound>215</TotalJunkErrorsFound> <TotalSecErrorsFound>1</TotalSecErrorsFound> -<Scanning Section="File types"><Description>File types pointing to programs that are no longer on your system.</Description><ErrorsInThisSection>30 Errors</ErrorsInThisSection> -<EntryDetails><Entry>.RV file (*.rv)</Entry> <Details>The key HKEY_CLASSES_ROOT\.rv points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SHTML file (*.shtml)</Entry> <Details>The key HKEY_CLASSES_ROOT\.shtml points to the missing key HKEY_CLASSES_ROOT\shtmlfile.</Details></EntryDetails> -<EntryDetails><Entry>.SMI file (*.smi)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smi points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SMIL file (*.smil)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smil points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SMK file (*.smk)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smk points to the missing key HKEY_CLASSES_ROOT\smkfile.</Details></EntryDetails> -<EntryDetails><Entry>Acrobat Rights Management Document</Entry> <Details>The key HKEY_CLASSES_ROOT\AcroExch.RMFFile\DefaultIcon points to the missing icon C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\RMFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details></EntryDetails> -<EntryDetails><Entry>DmonObject Class</Entry> <Details>The key HKEY_CLASSES_ROOT\DMON.DmonObject.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{13B65A91-FC6A-4FD8-B042-60B788FEB89C}.</Details></EntryDetails> -<EntryDetails><Entry>DmonObject Class</Entry> <Details>The key HKEY_CLASSES_ROOT\DMON.DmonObject\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{13B65A91-FC6A-4FD8-B042-60B788FEB89C}.</Details></EntryDetails> -<EntryDetails><Entry>Formulářový dokument Adobe Acrobat</Entry> <Details>The key HKEY_CLASSES_ROOT\AcroExch.XFDFDoc\DefaultIcon points to the missing icon C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\XFDFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details></EntryDetails> -<EntryDetails><Entry>JavaPlugin.FamilyVersionSupport</Entry> <Details>The key HKEY_CLASSES_ROOT\JavaPlugin.FamilyVersionSupport\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}.</Details></EntryDetails> -<EntryDetails><Entry>Microsoft Office OneNote Protocol Handler for Windows Desktop Search</Entry> <Details>The key HKEY_CLASSES_ROOT\OneIndex\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> -<EntryDetails><Entry>PNR Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details></EntryDetails> -<EntryDetails><Entry>PNR Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details></EntryDetails> -<EntryDetails><Entry>PNRCountryList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details></EntryDetails> -<EntryDetails><Entry>PNRCountryList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details></EntryDetails> -<EntryDetails><Entry>PNRGeoZone Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details></EntryDetails> -<EntryDetails><Entry>PNRGeoZone Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details></EntryDetails> -<EntryDetails><Entry>PNRNumberList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details></EntryDetails> -<EntryDetails><Entry>PNRNumberList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserSimple Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserSimple Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserThreaded Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserThreaded Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRPrefixList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRPrefixList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRResults Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details></EntryDetails> -<EntryDetails><Entry>PNRResults Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details></EntryDetails> -<EntryDetails><Entry>Sticky Notes Protocol</Entry> <Details>The key HKEY_CLASSES_ROOT\StickyNotes\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> -<EntryDetails><Entry>Voip Client Contacts</Entry> <Details>Thy key HKEY_CLASSES_ROOT\vccfile\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details></EntryDetails> -<EntryDetails><Entry>Windows Search Service Media Center Namespace Extension Handler</Entry> <Details>The key HKEY_CLASSES_ROOT\mcstore\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> </Scanning> -<Scanning Section="History lists"><Description>Some entries in the Windows and program history lists refer to missing files and can be deleted.</Description><ErrorsInThisSection>2 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Explorer history list: unneeded entry for the file type . file (*.)</Entry> <Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. when you wanted to open a file with the extension .. As no data has been written in the key, it can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Explorer history list: unneeded entry for the file type .PS file (*.ps)</Entry> <Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps when you wanted to open a file with the extension .ps. As no data has been written in the key, it can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Shared files"><Description>References and pointers to files in use by more than one application that no longer exist.</Description><ErrorsInThisSection>3 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Missing shared file ESET Smart Security - Context Menu Shell Extension.</Entry> <Details>The registry contains a reference to the missing shared file {B089FE88-FB52-11D3-BDF1-0050DA34150D} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> -<EntryDetails><Entry>Missing shared file Haali Matroska Thumbnail Exctractor.</Entry> <Details>The registry contains a reference to the missing shared file {327669A0-59A7-4be9-B99E-1C9F3A57611A} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> -<EntryDetails><Entry>Missing shared file WebCheck.</Entry> <Details>The registry contains a reference to the missing shared file {E6FB5E20-DE35-11CF-9C87-00AA005127ED} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> </Scanning> -<Scanning Section="Software"><Description>Programs listed in the Control Panel are no longer installed, do not have uninstall programs, or have other configuration problems.</Description><ErrorsInThisSection>21 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Adobe Reader 9.4.5 - Czech</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1029-7B44-A94000000001} that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Incomplete entry Easy-LayoutPrint</Entry> <Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Easy-LayoutPrint does not contain any data needed by Windows to remove the program or component and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\2fca61e260ba7318d4a6e7563fca383e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\93BE2EC28C544D23A89955923CF8B199\SourceList\Net that points to the missing file c:\2fca61e260ba7318d4a6e7563fca383e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3eb5bf576b7a65a51133876c69c9af\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\A6A9D82760228E13F9563CAEEBCF5FE3\SourceList\Net that points to the missing file c:\3eb5bf576b7a65a51133876c69c9af\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3f2eda63cd21bc1004404f3ff691c909\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\1E4ACFA687B90463F8277AFB33442800\SourceList\Net that points to the missing file c:\3f2eda63cd21bc1004404f3ff691c909\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\4d7dfa2eae49b7b2c182947f5109\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\6E8A266FCD4F2A1409E1C8110F44DBCE\SourceList\Net that points to the missing file c:\4d7dfa2eae49b7b2c182947f5109\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\c0062945d6c13e8a9d\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\DDA39468D428E8B4DB27C8D5DC5CA217\SourceList\Net that points to the missing file c:\c0062945d6c13e8a9d\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\c711ccd5e0ca1cbd32f83119a4301470\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\5C1093C35543A0E32A41B090A305076A\SourceList\Net that points to the missing file C:\c711ccd5e0ca1cbd32f83119a4301470\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\db4fae4f47f42d2107de743e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\BD6080E35803A87348A00F3DEA63901D\SourceList\Net that points to the missing file c:\db4fae4f47f42d2107de743e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\eb552b0c095311ebba73642a\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\4F6A6307DAD5809359D67125DCF7E7A5\SourceList\Net that points to the missing file C:\eb552b0c095311ebba73642a\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009014\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\68AB67CA7DA79201B7449A0400000010\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009024\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009054\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009034\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\</Entry> <Details>The registry contains an entry for the font 2 under HKEY_CLASSES_ROOT\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\eset\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\F1FC79DED691D5041B2DBB3660EFD8C6\SourceList\Net that points to the missing file C:\Users\vanda\Desktop\eset\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File :c:\8c19c4363af0a085ca32d80350\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\38BA79E7EF1CED838B8478E7A0B48DE1\SourceList\Net that points to the missing file c:\8c19c4363af0a085ca32d80350\.</Details></EntryDetails> -<EntryDetails><Entry>Windows Media Player Firefox Plugin</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} that points to the missing file C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>{26A24AE4-039D-4CA4-87B4-2F83216020FB}</Entry> <Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216020FB} points to the incomplete command line under UninstallString and can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Startup"><Description>These are redundant links left behind by software that were earlier scheduled to run during Windows StartUp but were removed or uninstalled. These can be deleted.</Description><ErrorsInThisSection>5 Errors</ErrorsInThisSection> -<EntryDetails><Entry>tray_ico</Entry> <Details>The registry contains the startup entry tray_ico in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico1</Entry> <Details>The registry contains the startup entry tray_ico1 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico2</Entry> <Details>The registry contains the startup entry tray_ico2 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico3</Entry> <Details>The registry contains the startup entry tray_ico3 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico4</Entry> <Details>The registry contains the startup entry tray_ico4 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Deep Scan"><Description>Invalid or orphaned references and pathways to system, application, and file settings.</Description><ErrorsInThisSection>211 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\OneIndex\shell key HKEY_LOCAL_MACHINE\software\Classes\OneIndex\shell for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Package\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Package\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Package2\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Package2\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\VideoDecode key HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\VideoDecode for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows.XPSActiveDocument.1\DocObject key HKEY_LOCAL_MACHINE\software\Classes\Windows.XPSActiveDocument.1\DocObject for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\7f7b65b8-769f-4221-a079-d93a05a933df\Providers\afd4f857-2524-4a24-b5b3-c08bd96915ed key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\7f7b65b8-769f-4221-a079-d93a05a933df\Providers\afd4f857-2524-4a24-b5b3-c08bd96915ed for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\AudioDecode key HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\AudioDecode for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Clients\Media\Winamp\Capabilities\MimeAssociations key HKEY_LOCAL_MACHINE\software\Clients\Media\Winamp\Capabilities\MimeAssociations for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs key HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\StickyNotes\Shell key HKEY_LOCAL_MACHINE\software\Classes\StickyNotes\Shell for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f key HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\afd4f857-2524-4a24-b5b3-c08bd96915ed\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\afd4f857-2524-4a24-b5b3-c08bd96915ed\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocksProxy.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocksProxy.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ATI Technologies\System Wide Settings key HKEY_LOCAL_MACHINE\software\ATI Technologies\System Wide Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Windows\CurrentVersion\Explorer\Browser Helper Objects key HKEY_LOCAL_MACHINE\software\Windows\CurrentVersion\Explorer\Browser Helper Objects for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\General key HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ \Trust Webcam\5.8.53003.1 key HKEY_LOCAL_MACHINE\software\ \Trust Webcam\5.8.53003.1 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Adobe\Reader\5.0 key HKEY_LOCAL_MACHINE\software\Adobe\Reader\5.0 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ArcSoft\TrackLog key HKEY_LOCAL_MACHINE\software\ArcSoft\TrackLog for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Crypt2.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Crypt2.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatCrypt2.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatCrypt2.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatOmaDrm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatOmaDrm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocket.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocket.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Ntlm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Ntlm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.OmaDrm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.OmaDrm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Socket.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Socket.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Nullsoft\Winamp key HKEY_LOCAL_MACHINE\software\Nullsoft\Winamp for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry>
xml version="1.0" encoding="UTF-8"?>
-<AROScanLog> <AROVersion>6.0.793.824</AROVersion> <ScanningDate>Sat. August 27, 2011. 07:34 PM</ScanningDate> <TotalRegErrorsFound>379</TotalRegErrorsFound> <TotalJunkErrorsFound>215</TotalJunkErrorsFound> <TotalSecErrorsFound>1</TotalSecErrorsFound> -<Scanning Section="File types"><Description>File types pointing to programs that are no longer on your system.</Description><ErrorsInThisSection>30 Errors</ErrorsInThisSection> -<EntryDetails><Entry>.RV file (*.rv)</Entry> <Details>The key HKEY_CLASSES_ROOT\.rv points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SHTML file (*.shtml)</Entry> <Details>The key HKEY_CLASSES_ROOT\.shtml points to the missing key HKEY_CLASSES_ROOT\shtmlfile.</Details></EntryDetails> -<EntryDetails><Entry>.SMI file (*.smi)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smi points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SMIL file (*.smil)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smil points to the missing key HKEY_CLASSES_ROOT\RealMedia.</Details></EntryDetails> -<EntryDetails><Entry>.SMK file (*.smk)</Entry> <Details>The key HKEY_CLASSES_ROOT\.smk points to the missing key HKEY_CLASSES_ROOT\smkfile.</Details></EntryDetails> -<EntryDetails><Entry>Acrobat Rights Management Document</Entry> <Details>The key HKEY_CLASSES_ROOT\AcroExch.RMFFile\DefaultIcon points to the missing icon C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\RMFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details></EntryDetails> -<EntryDetails><Entry>DmonObject Class</Entry> <Details>The key HKEY_CLASSES_ROOT\DMON.DmonObject.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{13B65A91-FC6A-4FD8-B042-60B788FEB89C}.</Details></EntryDetails> -<EntryDetails><Entry>DmonObject Class</Entry> <Details>The key HKEY_CLASSES_ROOT\DMON.DmonObject\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{13B65A91-FC6A-4FD8-B042-60B788FEB89C}.</Details></EntryDetails> -<EntryDetails><Entry>Formulářový dokument Adobe Acrobat</Entry> <Details>The key HKEY_CLASSES_ROOT\AcroExch.XFDFDoc\DefaultIcon points to the missing icon C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\XFDFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details></EntryDetails> -<EntryDetails><Entry>JavaPlugin.FamilyVersionSupport</Entry> <Details>The key HKEY_CLASSES_ROOT\JavaPlugin.FamilyVersionSupport\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}.</Details></EntryDetails> -<EntryDetails><Entry>Microsoft Office OneNote Protocol Handler for Windows Desktop Search</Entry> <Details>The key HKEY_CLASSES_ROOT\OneIndex\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> -<EntryDetails><Entry>PNR Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details></EntryDetails> -<EntryDetails><Entry>PNR Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details></EntryDetails> -<EntryDetails><Entry>PNRCountryList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details></EntryDetails> -<EntryDetails><Entry>PNRCountryList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details></EntryDetails> -<EntryDetails><Entry>PNRGeoZone Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details></EntryDetails> -<EntryDetails><Entry>PNRGeoZone Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details></EntryDetails> -<EntryDetails><Entry>PNRNumberList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details></EntryDetails> -<EntryDetails><Entry>PNRNumberList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserSimple Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserSimple Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserThreaded Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRParserThreaded Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRPrefixList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRPrefixList Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details></EntryDetails> -<EntryDetails><Entry>PNRResults Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details></EntryDetails> -<EntryDetails><Entry>PNRResults Class</Entry> <Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details></EntryDetails> -<EntryDetails><Entry>Sticky Notes Protocol</Entry> <Details>The key HKEY_CLASSES_ROOT\StickyNotes\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> -<EntryDetails><Entry>Voip Client Contacts</Entry> <Details>Thy key HKEY_CLASSES_ROOT\vccfile\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details></EntryDetails> -<EntryDetails><Entry>Windows Search Service Media Center Namespace Extension Handler</Entry> <Details>The key HKEY_CLASSES_ROOT\mcstore\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details></EntryDetails> </Scanning> -<Scanning Section="History lists"><Description>Some entries in the Windows and program history lists refer to missing files and can be deleted.</Description><ErrorsInThisSection>2 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Explorer history list: unneeded entry for the file type . file (*.)</Entry> <Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. when you wanted to open a file with the extension .. As no data has been written in the key, it can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Explorer history list: unneeded entry for the file type .PS file (*.ps)</Entry> <Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps when you wanted to open a file with the extension .ps. As no data has been written in the key, it can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Shared files"><Description>References and pointers to files in use by more than one application that no longer exist.</Description><ErrorsInThisSection>3 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Missing shared file ESET Smart Security - Context Menu Shell Extension.</Entry> <Details>The registry contains a reference to the missing shared file {B089FE88-FB52-11D3-BDF1-0050DA34150D} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> -<EntryDetails><Entry>Missing shared file Haali Matroska Thumbnail Exctractor.</Entry> <Details>The registry contains a reference to the missing shared file {327669A0-59A7-4be9-B99E-1C9F3A57611A} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> -<EntryDetails><Entry>Missing shared file WebCheck.</Entry> <Details>The registry contains a reference to the missing shared file {E6FB5E20-DE35-11CF-9C87-00AA005127ED} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details></EntryDetails> </Scanning> -<Scanning Section="Software"><Description>Programs listed in the Control Panel are no longer installed, do not have uninstall programs, or have other configuration problems.</Description><ErrorsInThisSection>21 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Adobe Reader 9.4.5 - Czech</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1029-7B44-A94000000001} that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Incomplete entry Easy-LayoutPrint</Entry> <Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Easy-LayoutPrint does not contain any data needed by Windows to remove the program or component and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\2fca61e260ba7318d4a6e7563fca383e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\93BE2EC28C544D23A89955923CF8B199\SourceList\Net that points to the missing file c:\2fca61e260ba7318d4a6e7563fca383e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3eb5bf576b7a65a51133876c69c9af\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\A6A9D82760228E13F9563CAEEBCF5FE3\SourceList\Net that points to the missing file c:\3eb5bf576b7a65a51133876c69c9af\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3f2eda63cd21bc1004404f3ff691c909\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\1E4ACFA687B90463F8277AFB33442800\SourceList\Net that points to the missing file c:\3f2eda63cd21bc1004404f3ff691c909\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\4d7dfa2eae49b7b2c182947f5109\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\6E8A266FCD4F2A1409E1C8110F44DBCE\SourceList\Net that points to the missing file c:\4d7dfa2eae49b7b2c182947f5109\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\c0062945d6c13e8a9d\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\DDA39468D428E8B4DB27C8D5DC5CA217\SourceList\Net that points to the missing file c:\c0062945d6c13e8a9d\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\c711ccd5e0ca1cbd32f83119a4301470\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\5C1093C35543A0E32A41B090A305076A\SourceList\Net that points to the missing file C:\c711ccd5e0ca1cbd32f83119a4301470\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\db4fae4f47f42d2107de743e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\BD6080E35803A87348A00F3DEA63901D\SourceList\Net that points to the missing file c:\db4fae4f47f42d2107de743e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\eb552b0c095311ebba73642a\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\4F6A6307DAD5809359D67125DCF7E7A5\SourceList\Net that points to the missing file C:\eb552b0c095311ebba73642a\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009014\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\68AB67CA7DA79201B7449A0400000010\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009024\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009054\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\68AB67CA7DA700005205A7C804009034\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\</Entry> <Details>The registry contains an entry for the font 2 under HKEY_CLASSES_ROOT\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\eset\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\F1FC79DED691D5041B2DBB3660EFD8C6\SourceList\Net that points to the missing file C:\Users\vanda\Desktop\eset\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File :c:\8c19c4363af0a085ca32d80350\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Patches\38BA79E7EF1CED838B8478E7A0B48DE1\SourceList\Net that points to the missing file c:\8c19c4363af0a085ca32d80350\.</Details></EntryDetails> -<EntryDetails><Entry>Windows Media Player Firefox Plugin</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} that points to the missing file C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>{26A24AE4-039D-4CA4-87B4-2F83216020FB}</Entry> <Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216020FB} points to the incomplete command line under UninstallString and can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Startup"><Description>These are redundant links left behind by software that were earlier scheduled to run during Windows StartUp but were removed or uninstalled. These can be deleted.</Description><ErrorsInThisSection>5 Errors</ErrorsInThisSection> -<EntryDetails><Entry>tray_ico</Entry> <Details>The registry contains the startup entry tray_ico in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico1</Entry> <Details>The registry contains the startup entry tray_ico1 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico2</Entry> <Details>The registry contains the startup entry tray_ico2 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico3</Entry> <Details>The registry contains the startup entry tray_ico3 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> -<EntryDetails><Entry>tray_ico4</Entry> <Details>The registry contains the startup entry tray_ico4 in the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which points to the missing program . This invalid entry should be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Deep Scan"><Description>Invalid or orphaned references and pathways to system, application, and file settings.</Description><ErrorsInThisSection>211 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\OneIndex\shell key HKEY_LOCAL_MACHINE\software\Classes\OneIndex\shell for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Package\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Package\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Package2\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Package2\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\VideoDecode key HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\VideoDecode for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows.XPSActiveDocument.1\DocObject key HKEY_LOCAL_MACHINE\software\Classes\Windows.XPSActiveDocument.1\DocObject for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\7f7b65b8-769f-4221-a079-d93a05a933df\Providers\afd4f857-2524-4a24-b5b3-c08bd96915ed key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\7f7b65b8-769f-4221-a079-d93a05a933df\Providers\afd4f857-2524-4a24-b5b3-c08bd96915ed for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\AudioDecode key HKEY_LOCAL_MACHINE\software\Classes\Windows Media\WMSDK\AudioDecode for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Clients\Media\Winamp\Capabilities\MimeAssociations key HKEY_LOCAL_MACHINE\software\Clients\Media\Winamp\Capabilities\MimeAssociations for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs key HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\StickyNotes\Shell key HKEY_LOCAL_MACHINE\software\Classes\StickyNotes\Shell for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f key HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\5b853b2b-ae26-47d5-ae86-96fce181140f for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 key HKEY_LOCAL_MACHINE\software\Classes\SVCID.Local\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\e24c132e-d6f4-4d75-8601-7e6b34c87d23 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\deae4575-c820-423d-8413-cb45c460f193 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8955595-cd6e-4c48-a7ef-35dd189d0f90 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\afd4f857-2524-4a24-b5b3-c08bd96915ed\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\afd4f857-2524-4a24-b5b3-c08bd96915ed\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocksProxy.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocksProxy.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\5b853b2b-ae26-47d5-ae86-96fce181140f\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\c8955595-cd6e-4c48-a7ef-35dd189d0f90\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\CID.Local\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID.Local\e24c132e-d6f4-4d75-8601-7e6b34c87d23\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ATI Technologies\System Wide Settings key HKEY_LOCAL_MACHINE\software\ATI Technologies\System Wide Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Windows\CurrentVersion\Explorer\Browser Helper Objects key HKEY_LOCAL_MACHINE\software\Windows\CurrentVersion\Explorer\Browser Helper Objects for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\General key HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ \Trust Webcam\5.8.53003.1 key HKEY_LOCAL_MACHINE\software\ \Trust Webcam\5.8.53003.1 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Adobe\Reader\5.0 key HKEY_LOCAL_MACHINE\software\Adobe\Reader\5.0 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\ArcSoft\TrackLog key HKEY_LOCAL_MACHINE\software\ArcSoft\TrackLog for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Crypt2.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Crypt2.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatCrypt2.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatCrypt2.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatOmaDrm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatCrypt2.ChilkatOmaDrm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocket.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\ChilkatSocket.ChilkatSocket.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Ntlm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Ntlm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.OmaDrm.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.OmaDrm.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Socket.1\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Chilkat.Socket.1\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Nullsoft\Winamp key HKEY_LOCAL_MACHINE\software\Nullsoft\Winamp for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry>
Re: Win32/ConMiner
<Details>The HKEY_LOCAL_MACHINE\software\TrendMicro\HijackThis key HKEY_LOCAL_MACHINE\software\TrendMicro\HijackThis for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\Capture key HKEY_LOCAL_MACHINE\software\Waves Audio\MaxxAudio\Capture for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\ExcelWorksheet\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\ExcelWorksheet\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\SRS Labs\APO key HKEY_LOCAL_MACHINE\software\SRS Labs\APO for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Equations\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equations\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : %USERPROFILE%\My Documents\Visual Studio 2005</Entry> <Details>The registry contains an entry for the font UserDataFolder under HKEY_LOCAL_MACHINE\software\Microsoft\MSEnvCommunityContent\ContentTypes\VSTemplate\ContentHosts\1.0\Visual Studio Tools for Applications 2005 that points to the missing file %USERPROFILE%\My Documents\Visual Studio 2005.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : %USERPROFILE%\My Documents\Visual Studio 2005</Entry> <Details>The registry contains an entry for the font UserDataFolder under HKEY_LOCAL_MACHINE\software\Microsoft\MSEnvCommunityContent\ContentTypes\Code Snippet\ContentHosts\1.0\Visual Studio Tools for Applications 2005 that points to the missing file %USERPROFILE%\My Documents\Visual Studio 2005.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\2fca61e260ba7318d4a6e7563fca383e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\93BE2EC28C544D23A89955923CF8B199\SourceList\Net that points to the missing file c:\2fca61e260ba7318d4a6e7563fca383e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3eb5bf576b7a65a51133876c69c9af\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\A6A9D82760228E13F9563CAEEBCF5FE3\SourceList\Net that points to the missing file c:\3eb5bf576b7a65a51133876c69c9af\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3f2eda63cd21bc1004404f3ff691c909\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\1E4ACFA687B90463F8277AFB33442800\SourceList\Net that points to the missing file c:\3f2eda63cd21bc1004404f3ff691c909\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3f2eda63cd21bc1004404f3ff691c909\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1E4ACFA687B90463F8277AFB33442800\InstallProperties that points to the missing file c:\3f2eda63cd21bc1004404f3ff691c909\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\3f2eda63cd21bc1004404f3ff691c909\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{6AFCA4E1-9B78-3640-8F72-A7BF33448200} that points to the missing file c:\3f2eda63cd21bc1004404f3ff691c909\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\4d7dfa2eae49b7b2c182947f5109\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\6E8A266FCD4F2A1409E1C8110F44DBCE\SourceList\Net that points to the missing file c:\4d7dfa2eae49b7b2c182947f5109\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\4d7dfa2eae49b7b2c182947f5109\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC} that points to the missing file c:\4d7dfa2eae49b7b2c182947f5109\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\4d7dfa2eae49b7b2c182947f5109\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E8A266FCD4F2A1409E1C8110F44DBCE\InstallProperties that points to the missing file c:\4d7dfa2eae49b7b2c182947f5109\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\8c19c4363af0a085ca32d80350\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\38BA79E7EF1CED838B8478E7A0B48DE1\SourceList\Net that points to the missing file c:\8c19c4363af0a085ca32d80350\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\c0062945d6c13e8a9d\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\DDA39468D428E8B4DB27C8D5DC5CA217\SourceList\Net that points to the missing file c:\c0062945d6c13e8a9d\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\c0062945d6c13e8a9d\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} that points to the missing file c:\c0062945d6c13e8a9d\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\c0062945d6c13e8a9d\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDA39468D428E8B4DB27C8D5DC5CA217\InstallProperties that points to the missing file c:\c0062945d6c13e8a9d\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\c711ccd5e0ca1cbd32f83119a4301470\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5C1093C35543A0E32A41B090A305076A\InstallProperties that points to the missing file C:\c711ccd5e0ca1cbd32f83119a4301470\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\c711ccd5e0ca1cbd32f83119a4301470\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\5C1093C35543A0E32A41B090A305076A\SourceList\Net that points to the missing file C:\c711ccd5e0ca1cbd32f83119a4301470\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\c711ccd5e0ca1cbd32f83119a4301470\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{3C3901C5-3455-3E0A-A214-0B093A5070A6} that points to the missing file C:\c711ccd5e0ca1cbd32f83119a4301470\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\db4fae4f47f42d2107de743e\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\BD6080E35803A87348A00F3DEA63901D\SourceList\Net that points to the missing file c:\db4fae4f47f42d2107de743e\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\eb552b0c095311ebba73642a\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\4F6A6307DAD5809359D67125DCF7E7A5\SourceList\Net that points to the missing file C:\eb552b0c095311ebba73642a\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\eb552b0c095311ebba73642a\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{7036A6F4-5DAD-3908-956D-1752CD7F7E5A} that points to the missing file C:\eb552b0c095311ebba73642a\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\eb552b0c095311ebba73642a\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4F6A6307DAD5809359D67125DCF7E7A5\InstallProperties that points to the missing file C:\eb552b0c095311ebba73642a\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\\MSBuild\Microsoft.VisualStudio.OfficeTools.targets</Entry> <Details>The registry contains an entry for the font VisualStudio9 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\MSBuild\SafeImports that points to the missing file C:\Program Files\\MSBuild\Microsoft.VisualStudio.OfficeTools.targets.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\\MSBuild\Microsoft.VisualStudio.OfficeTools.targets</Entry> <Details>The registry contains an entry for the font VisualStudio9 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\MSBuild\SafeImports that points to the missing file C:\Program Files\\MSBuild\Microsoft.VisualStudio.OfficeTools.targets.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Ask.com\TaskScheduler.exe</Entry> <Details>The registry contains an entry for the font A28B4D68DEBAA244EB686953B7074FEF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED that points to the missing file C:\Program Files\Ask.com\TaskScheduler.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\ffdshow</Entry> <Details>The registry contains an entry for the font pth under HKEY_LOCAL_MACHINE\software\GNU\ffdshow that points to the missing file C:\Program Files\ffdshow.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre1.6.0_17\patchjre.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF2381206710F under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3512061A07 that points to the missing file C:\Program Files\Java\jre1.6.0_17\patchjre.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre1.6.0_17\zipper.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF2381206710F under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3312061A07 that points to the missing file C:\Program Files\Java\jre1.6.0_17\zipper.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\bin\jp2ssv_patch.dll</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120602BF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3712062B00 that points to the missing file C:\Program Files\Java\jre6\bin\jp2ssv_patch.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin_patch.dll</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120602BF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3812062B00 that points to the missing file C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin_patch.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\patchjre.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120602BF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3512062B00 that points to the missing file C:\Program Files\Java\jre6\patchjre.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\patchjre.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120691FF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3512061F09 that points to the missing file C:\Program Files\Java\jre6\patchjre.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\zipper.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120691FF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3312061F09 that points to the missing file C:\Program Files\Java\jre6\zipper.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Java\jre6\zipper.exe</Entry> <Details>The registry contains an entry for the font 4EA42A62D9304AC4784BF238120602BF under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3312062B00 that points to the missing file C:\Program Files\Java\jre6\zipper.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ImportProjects\VB</Entry> <Details>The registry contains an entry for the font ImportProjectsDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F}\ImportTemplates that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ImportProjects\VB.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ImportProjects\VB</Entry> <Details>The registry contains an entry for the font ImportProjectsDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F}\ImportTemplates that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ImportProjects\VB.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\NewScriptItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{A2FE74E1-B743-11d0-AE1A-00A0C90FFFC3}\AddItemTemplates\TemplateDirs\{F5E7E720-1401-11d1-883B-0000F87579D2}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\NewScriptItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\NewScriptItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{A2FE74E1-B743-11d0-AE1A-00A0C90FFFC3}\AddItemTemplates\TemplateDirs\{F5E7E720-1401-11d1-883B-0000F87579D2}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\NewScriptItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ProjectTemplates</Entry> <Details>The registry contains an entry for the font UserFolder under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\VSTemplate\Project that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ProjectTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ProjectTemplates</Entry> <Details>The registry contains an entry for the font UserFolder under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\VSTemplate\Project that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ProjectTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{8b223f60-81ae-4d37-9a35-2621bc61801b} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{db7e39d5-1bfc-451d-8321-f54d76bf962f} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{8b223f60-81ae-4d37-9a35-2621bc61801b} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{db7e39d5-1bfc-451d-8321-f54d76bf962f} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\ecbuild.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\jsee.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{4D4D35A3-1391-4E17-813D-54D1B846096A} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\jsee.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\jsee.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{4D4D35A3-1391-4E17-813D-54D1B846096A} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\jsee.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\metade.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{A8403605-9923-4605-BFBA-F47A4739AB43} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\metade.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\metade.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{A8403605-9923-4605-BFBA-F47A4739AB43} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\metade.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{1fbd5ec4-b8e4-4d94-9efe-7ccaf9132c98} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{37dfdbcc-40a5-4f4a-8523-123c746d38f0} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{bce36434-2c24-499e-bf49-8bd99b0eeb68} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{1fbd5ec4-b8e4-4d94-9efe-7ccaf9132c98} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{37dfdbcc-40a5-4f4a-8523-123c746d38f0} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{bce36434-2c24-499e-bf49-8bd99b0eeb68} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\msdia80.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{3B476D36-A401-11D2-AAD4-00C04F990171} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{3B476D36-A401-11D2-AAD4-00C04F990171} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{3B476D37-A401-11D2-AAD4-00C04F990171} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{3B476D37-A401-11D2-AAD4-00C04F990171} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\NatDbgDE.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{56B4E602-21A1-11D2-8FD6-00C04FA30000} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{56B4E602-21A1-11D2-8FD6-00C04FA30000} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\CLSID\{5A670B56-80E3-4A1E-A5C5-5597A943AD5D} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\CLSID\{5A670B56-80E3-4A1E-A5C5-5597A943AD5D} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\Debugger\scriptle2.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\webdirprj.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Packages\{8FF02D1A-C177-4ac8-A62F-88FC6EA65F57} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\webdirprj.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\webdirprj.dll</Entry> <Details>The registry contains an entry for the font InprocServer32 under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Packages\{8FF02D1A-C177-4ac8-A62F-88FC6EA65F57} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\Common7\Packages\webdirprj.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\ImportProjects\vcs</Entry> <Details>The registry contains an entry for the font ImportProjectsDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\ImportTemplates that points to the missing file C:\Program Files\Microsoft Visual Studio 8\ImportProjects\vcs.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\ImportProjects\vcs</Entry> <Details>The registry contains an entry for the font ImportProjectsDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\ImportTemplates that points to the missing file C:\Program Files\Microsoft Visual Studio 8\ImportProjects\vcs.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems</Entry> <Details>The registry contains an entry for the font ItemTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F}\AddItemTemplates\TemplateDirs\{164B10B9-B200-11D0-8C61-00A0C91E29D5}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems</Entry> <Details>The registry contains an entry for the font ItemTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F}\AddItemTemplates\TemplateDirs\{164B10B9-B200-11D0-8C61-00A0C91E29D5}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\NewProjectTemplates\TemplateDirs\{164B10B9-B200-11D0-8C61-00A0C91E29D5}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\NewProjectTemplates\TemplateDirs\{164B10B9-B200-11D0-8C61-00A0C91E29D5}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects</Entry> <Details>The registry contains an entry for the font ProjectTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects</Entry> <Details>The registry contains an entry for the font ProjectTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards</Entry> <Details>The registry contains an entry for the font WizardsTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards</Entry> <Details>The registry contains an entry for the font WizardsTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards\DesignerTemplates</Entry> <Details>The registry contains an entry for the font DesignerTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards\DesignerTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards\DesignerTemplates</Entry> <Details>The registry contains an entry for the font DesignerTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{F184B08F-C81C-45F6-A57F-5ABD9991F28F} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VB\.\VBWizards\DesignerTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\AddItemTemplates\TemplateDirs\{FAE04EC1-301F-11D3-BF4B-00C04F79EFBC}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\AddItemTemplates\TemplateDirs\{FAE04EC1-301F-11D3-BF4B-00C04F79EFBC}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems</Entry> <Details>The registry contains an entry for the font ItemTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems</Entry> <Details>The registry contains an entry for the font ItemTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjectItems.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects</Entry> <Details>The registry contains an entry for the font ProjectTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\NewProjectTemplates\TemplateDirs\{FAE04EC1-301F-11D3-BF4B-00C04F79EFBC}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects</Entry> <Details>The registry contains an entry for the font TemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\NewProjectTemplates\TemplateDirs\{FAE04EC1-301F-11D3-BF4B-00C04F79EFBC}\/1 that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects</Entry> <Details>The registry contains an entry for the font ProjectTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\CSharpProjects.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\DesignerTemplates</Entry> <Details>The registry contains an entry for the font DesignerTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\DesignerTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\DesignerTemplates</Entry> <Details>The registry contains an entry for the font DesignerTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\DesignerTemplates.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\VC#Wizards</Entry> <Details>The registry contains an entry for the font WizardsTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTA\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\VC#Wizards.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Microsoft Visual Studio 8\VC#\.\VC#Wizards</Entry> <Details>The registry contains an entry for the font WizardsTemplatesDir under HKEY_LOCAL_MACHINE\software\Microsoft\VSTAHost\InfoPath\8.0\Projects\{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} that points to the missing file C:\Program Files\Microsoft Visual Studio 8\VC#\.\VC#Wizards.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Mozilla Firefox\plugins</Entry> <Details>The registry contains an entry for the font Plugins under HKEY_LOCAL_MACHINE\software\Mozilla\Mozilla Firefox 5.0.1\extensions that points to the missing file C:\Program Files\Mozilla Firefox\plugins.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Win7codecs\rm\RCAPlugins\</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\SOFTWARE\RealNetworks\Gemini\0.1\Preferences\PluginFilePath that points to the missing file C:\Program Files\Win7codecs\rm\RCAPlugins\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Win7codecs\rm\RealPlayer.exe</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\SOFTWARE\RealNetworks\RealPlayer\6.0\Preferences\MainApp that points to the missing file C:\Program Files\Win7codecs\rm\RealPlayer.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1029-7B44-A94000000001} that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\68AB67CA7DA700005205A7C804009014\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA79201B7449A0400000010\InstallProperties that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.3\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA79201B7449A0400000010\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.3\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\68AB67CA7DA700005205A7C804009054\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\68AB67CA7DA700005205A7C804009024\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\Adobe\Reader\9.4\ARM\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\68AB67CA7DA700005205A7C804009034\SourceList\Net that points to the missing file C:\ProgramData\Adobe\Reader\9.4\ARM\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\OEM Links</Entry>
Re: Win32/ConMiner
<Details>The registry contains an entry for the font OEM Links under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders that points to the missing file C:\ProgramData\OEM Links.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\real</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\SOFTWARE\RealNetworks\RealMediaSDK\6.0\Preferences\CacheFilename that points to the missing file C:\ProgramData\real.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} that points to the missing file C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4262599357-941623066-141293655-1000\Products\6BBFDF96D153C8B4988D68D79C0D2A4A\InstallProperties that points to the missing file C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\pft2F2C~tmp\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} that points to the missing file C:\Users\vanda\AppData\Local\Temp\pft2F2C~tmp\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\pftBFD5~tmp\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Acrobat 5.0 that points to the missing file C:\Users\vanda\AppData\Local\Temp\pftBFD5~tmp\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp1_Advent.zip</Entry> <Details>The registry contains an entry for the font ConfigApplicationPath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{64E2D7ED-AD8B-4C1C-A4BC-E5BA3AE399CB} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp1_Advent.zip.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp1_Advent.zip\Advent.exe</Entry> <Details>The registry contains an entry for the font AppExePath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{64E2D7ED-AD8B-4C1C-A4BC-E5BA3AE399CB} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp1_Advent.zip\Advent.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp2_Advent.zip</Entry> <Details>The registry contains an entry for the font ConfigApplicationPath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{D6720681-F343-49E1-BBDC-AC31B1087A70} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp2_Advent.zip.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp2_Advent.zip\Advent.exe</Entry> <Details>The registry contains an entry for the font AppExePath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{D6720681-F343-49E1-BBDC-AC31B1087A70} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp2_Advent.zip\Advent.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp3_Advent.zip</Entry> <Details>The registry contains an entry for the font ConfigApplicationPath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{6AC5B561-1EC6-4713-A3C7-DC712BF5FCAA} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp3_Advent.zip.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\Temp3_Advent.zip\Advent.exe</Entry> <Details>The registry contains an entry for the font AppExePath under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-4262599357-941623066-141293655-1000\{6AC5B561-1EC6-4713-A3C7-DC712BF5FCAA} that points to the missing file C:\Users\vanda\AppData\Local\Temp\Temp3_Advent.zip\Advent.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{53B19A1C-3674-44A4-AA6D-6EE2EADE6194}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF\InstallProperties that points to the missing file C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\</Entry> <Details>The registry contains an entry for the font 2 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} that points to the missing file C:\Users\vanda\AppData\Local\Temp\{C97C895D-AD30-4668-8E19-35F84C55ACBF}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\eset\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\F1FC79DED691D5041B2DBB3660EFD8C6\SourceList\Net that points to the missing file C:\Users\vanda\Desktop\eset\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\eset\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F1FC79DED691D5041B2DBB3660EFD8C6\InstallProperties that points to the missing file C:\Users\vanda\Desktop\eset\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\eset\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{ED97CF1F-196D-405D-B1D2-BB6306FE8D6C} that points to the missing file C:\Users\vanda\Desktop\eset\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\RMFFile_8.ico,0</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\AcroExch.RMFFile\DefaultIcon that points to the missing file C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\RMFFile_8.ico,0.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\XFDFFile_8.ico,0</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\AcroExch.XFDFDoc\DefaultIcon that points to the missing file C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-A94000000001}\XFDFFile_8.ico,0.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : file://C:\Windows\web\iejit.htm</Entry> <Details>The registry contains an entry for the font JITSetupPage under HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup that points to the missing file file://C:\Windows\web\iejit.htm.</Details></EntryDetails> </Scanning> -<Scanning Section="Current User"><Description>Current User settings for installed programs may differ from System settings, be invalid, or orphaned.</Description><ErrorsInThisSection>107 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c4\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c5\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c3\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c15\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c2\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\DBRecoveryOptions key HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\DBRecoveryOptions for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\ActiveSkin key HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\ActiveSkin for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\TellAFriend key HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\TellAFriend for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\Acrobat.com key HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\Acrobat.com for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Winamp Toolbar\ieToolbar\settings\_ldefault_\search\customSearches key HKEY_CURRENT_USER\Software\Winamp Toolbar\ieToolbar\settings\_ldefault_\search\customSearches for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Winamp Toolbar\ieToolbar\settings\_ldefault_\search\searchTerms key HKEY_CURRENT_USER\Software\Winamp Toolbar\ieToolbar\settings\_ldefault_\search\searchTerms for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\System\CurrentControlSet\Policies key HKEY_CURRENT_USER\System\CurrentControlSet\Policies for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\Vandazmija\AutoLogon key HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\Vandazmija\AutoLogon for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\wandazmija key HKEY_CURRENT_USER\Software\InternetCalls\InternetCalls\wandazmija for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\JavaSoft\Prefs key HKEY_CURRENT_USER\Software\JavaSoft\Prefs for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c6\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c7\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c9\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c8\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\EWH\5.0\General key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\EWH\5.0\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\Weblink\5.0\General key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\Weblink\5.0\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\Weblink\5.0\OpenURL key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\Weblink\5.0\OpenURL for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Control Panel\don't load key HKEY_CURRENT_USER\Control Panel\don't load for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Network key HKEY_CURRENT_USER\Network for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\AcroHLS\5.0\General key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\AcroHLS\5.0\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cButtonsInternal key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cButtonsInternal for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\Settings key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF\cSettings key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF\cSettings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\WHA Library\5.0\General key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\WHA Library\5.0\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\WHAPI\5.0\General key HKEY_CURRENT_USER\Software\Adobe\Acrobat\5.0\WHAPI\5.0\General for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cButtonsExternal key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cButtonsExternal for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuCommand\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuCommand\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuPopup\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuPopup\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Minimize\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Minimize\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\AppGPFault\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\AppGPFault\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Maximize\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Maximize\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreUp\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreUp\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemQuestion\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemQuestion\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration key HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\PrintComplete\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\PrintComplete\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreDown\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreDown\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF\cSettings key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF\cSettings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c14\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c13\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cDockables key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cDockables for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cToolbars\cAdvCommenting key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cToolbars\cAdvCommenting for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cToolbars\cBasicCommenting key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral\cToolbars\cBasicCommenting for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cLeftView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cLeftView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c11\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews\cNoCategoryFiles\c10\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\dm.capture\</Entry> <Details>The registry contains an entry for the font WriteCaptureDir under HKEY_CURRENT_USER\Software\Microsoft\MPEG2Demultiplexer that points to the missing file c:\dm.capture\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files\Win7codecs\rm\RCAPlugins</Entry> <Details>The registry contains an entry for the font under HKEY_CURRENT_USER\Software\RealNetworks\Gemini\0.1\Preferences\PluginFilePath that points to the missing file C:\Program Files\Win7codecs\rm\RCAPlugins.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\subtitles</Entry> <Details>The registry contains an entry for the font Path1 under HKEY_CURRENT_USER\Software\Gabest\VSFilter\DefTextPathes that points to the missing file c:\subtitles.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSD.XML</Entry> <Details>The registry contains an entry for the font LocalDelta under HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace that points to the missing file C:\Users\vanda\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSD.XML.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSR.XML</Entry> <Details>The registry contains an entry for the font RemoteDelta under HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace that points to the missing file C:\Users\vanda\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSR.XML.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\6BBFDF96D153C8B4988D68D79C0D2A4A\SourceList\Net that points to the missing file C:\Users\vanda\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe</Entry> <Details>The registry contains an entry for the font under HKEY_CURRENT_USER\Software\Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\LocalServer32 that points to the missing file C:\Users\vanda\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\BSplayer\bsplayer.exe</Entry> <Details>The registry contains an entry for the font AppPath under HKEY_CURRENT_USER\Software\BST\bsplayerv1 that points to the missing file C:\Users\vanda\Desktop\BSplayer\bsplayer.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\vanda\Desktop\Hrát hry (EasyBits GO).lnk</Entry> <Details>The registry contains an entry for the font DesktopIcon under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Game Organizer that points to the missing file C:\Users\vanda\Desktop\Hrát hry (EasyBits GO).lnk.</Details></EntryDetails> </Scanning> -<Scanning Section="Recent Documents"><Description>Displays links of recently used documents on your computer that can be deleted periodically to protect your privacy and avoid misuse of your personal data.</Description><ErrorsInThisSection>21 Errors</ErrorsInThisSection> -<EntryDetails><Entry>2011-08-18Asia u babci15.7-8.8.2011.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\2011-08-18Asia u babci15.7-8.8.2011.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>desktop.ini</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\desktop.ini found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Dokumenty.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\Dokumenty.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>log.txt.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\log.txt.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Program na rozpoczęcie roku sz1.docx.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\Program na rozpoczęcie roku sz1.docx.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>rsit.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\rsit.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Systém a zabezpečení.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\Systém a zabezpečení.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Všechny položky Ovládacích panelů.lnk</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\Všechny položky Ovládacích panelů.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1b4dd67f29cb1962.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5ee0bc8bc97ff32e.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\5ee0bc8bc97ff32e.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>7d1be5b58b94b5ed.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\7d1be5b58b94b5ed.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>918e0ecb43d17e23.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\918e0ecb43d17e23.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>16ec093b8f51508f.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>28c8b86deab549a1.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5afe4de1b92fc382.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5bac51434181e1ba.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\5bac51434181e1ba.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>8e85d5b0c4b87d2a.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\8e85d5b0c4b87d2a.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>ae5cd8ebf4af1227.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\ae5cd8ebf4af1227.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>ed7a5cc3cca8d52a.customDestinations-ms</Entry> <Details>File C:\Users\vanda\appdata\roaming\microsoft\windows\recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms found in recent documents.</Details></EntryDetails> </Scanning> -<Scanning Section="Recycle Bin"><Description>Collects all the files and folders that you have deleted on your computer. These can be deleted.</Description><ErrorsInThisSection>5 Errors</ErrorsInThisSection> -<EntryDetails><Entry>$I6NU3UN.raw</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-4262599357-941623066-141293655-1000\$I6NU3UN.raw found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$INBL0DE.exe</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-4262599357-941623066-141293655-1000\$INBL0DE.exe found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R6NU3UN.raw</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-4262599357-941623066-141293655-1000\$R6NU3UN.raw found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RNBL0DE.exe</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-4262599357-941623066-141293655-1000\$RNBL0DE.exe found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R82T9ND</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-4262599357-941623066-141293655-1000\$R82T9ND found in recycle bin.</Details></EntryDetails> </Scanning> -<Scanning Section="Shortcuts"><Description>Some shortcuts on your system refer to missing targets.</Description><ErrorsInThisSection>3 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Hrát</Entry> <Details>The shortcut c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{D6720681-F343-49E1-BBDC-AC31B1087A70}\PlayTasks\0\Hrát.lnk points to the missing target c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{D6720681-F343-49E1-BBDC-AC31B1087A70}\PlayTasks\0\Hrát.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Hrát</Entry> <Details>The shortcut c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{6AC5B561-1EC6-4713-A3C7-DC712BF5FCAA}\PlayTasks\0\Hrát.lnk points to the missing target c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{6AC5B561-1EC6-4713-A3C7-DC712BF5FCAA}\PlayTasks\0\Hrát.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Hrát</Entry> <Details>The shortcut c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{64E2D7ED-AD8B-4C1C-A4BC-E5BA3AE399CB}\PlayTasks\0\Hrát.lnk points to the missing target c:\users\vanda\appdata\local\Microsoft\Windows\GameExplorer\{64E2D7ED-AD8B-4C1C-A4BC-E5BA3AE399CB}\PlayTasks\0\Hrát.lnk and can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Taskbar Jumplist"><Description>Displays links of recently used applications and documents on the task bar. These can be deleted to protect your privacy and avoid misuse of personal data.</Description><ErrorsInThisSection>13 Errors</ErrorsInThisSection> -<EntryDetails><Entry>1b4dd67f29cb1962.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5ee0bc8bc97ff32e.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5ee0bc8bc97ff32e.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>7d1be5b58b94b5ed.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7d1be5b58b94b5ed.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>918e0ecb43d17e23.automaticDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\918e0ecb43d17e23.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>16ec093b8f51508f.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>28c8b86deab549a1.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5afe4de1b92fc382.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5bac51434181e1ba.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5bac51434181e1ba.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>8e85d5b0c4b87d2a.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8e85d5b0c4b87d2a.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>ae5cd8ebf4af1227.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ae5cd8ebf4af1227.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>ed7a5cc3cca8d52a.customDestinations-ms</Entry> <Details>File C:\Users\vanda\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms found in task bar jump list</Details></EntryDetails> </Scanning> -<Scanning Section="Temporary Files"><Description>These are files created and left behind by applications and programs when they are launched. These can be deleted.</Description><ErrorsInThisSection>173 Errors</ErrorsInThisSection> -<EntryDetails><Entry>859A95E3.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\859a95e3.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>AdobeARM.log</Entry> <Details>File c:\users\vanda\appdata\local\temp\adobearm.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>AskSLib.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\askslib.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>bcdedit32.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\bcdedit32.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>e13c.rra</Entry> <Details
Re: Win32/ConMiner
>File c:\users\vanda\appdata\local\temp\e13c.rra found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>log115.txt</Entry> <Details>File c:\users\vanda\appdata\local\temp\log115.txt found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MS4F3DF.LOG</Entry> <Details>File c:\users\vanda\appdata\local\temp\ms4f3df.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MSETUP4.EXE</Entry> <Details>File c:\users\vanda\appdata\local\temp\msetup4.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>pavbase.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\pavbase.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setto.set</Entry> <Details>File c:\users\vanda\appdata\local\temp\setto.set found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TWAIN.LOG</Entry> <Details>File c:\users\vanda\appdata\local\temp\twain.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Twain001.Mtx</Entry> <Details>File c:\users\vanda\appdata\local\temp\twain001.mtx found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Twunk001.MTX</Entry> <Details>File c:\users\vanda\appdata\local\temp\twunk001.mtx found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Twunk002.MTX</Entry> <Details>File c:\users\vanda\appdata\local\temp\twunk002.mtx found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF14A7C6AF8D1291EF.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df14a7c6af8d1291ef.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF284470AD69A89253.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df284470ad69a89253.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF3F506B062794983B.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df3f506b062794983b.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF7EDEC43EFC44FFE9.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df7edec43efc44ffe9.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF8AB86A34AF338C83.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df8ab86a34af338c83.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF96FC3BB5B2788B57.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df96fc3bb5b2788b57.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DF9E0FBA3112A053D7.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~df9e0fba3112a053d7.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFB847A83FC9EF6F18.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dfb847a83fc9ef6f18.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFD2C7C340CC37033C.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dfd2c7c340cc37033c.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFD6AC7256B215FD43.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dfd6ac7256b215fd43.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFDF311EEEF8B654C8.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dfdf311eeef8b654c8.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFF2C065BC2895DE9F.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dff2c065bc2895de9f.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFF4BE8C76A2FFDBAE.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dff4be8c76a2ffdbae.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFF93FECE75A9825C4.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dff93fece75a9825c4.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>~DFFBEAFDCEEA50C180.TMP</Entry> <Details>File c:\users\vanda\appdata\local\temp\~dffbeafdceea50c180.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>soref.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\is-fj684.tmp\soref.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>is-FJ684.tmp</Entry> <Details>File c:\users\vanda\appdata\local\temp\is-fj684.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Low</Entry> <Details>File c:\users\vanda\appdata\local\temp\low found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_631B5A69-5F45-404F-AA21-9014B8EC4B0D_</Entry> <Details>File c:\users\vanda\appdata\local\temp\msdtadmin\_631b5a69-5f45-404f-aa21-9014b8ec4b0d_ found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_F2165372-A464-4773-8CD4-050924C5F4DE_</Entry> <Details>File c:\users\vanda\appdata\local\temp\msdtadmin\_f2165372-a464-4773-8cd4-050924c5f4de_ found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>msdtadmin</Entry> <Details>File c:\users\vanda\appdata\local\temp\msdtadmin found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>WPDNSE</Entry> <Details>File c:\users\vanda\appdata\local\temp\wpdnse found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>corecomp.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\corecomp.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>dotnetinstaller.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\dotnetinstaller.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>default.pal</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\default.pal found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>difxapi.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\difxapi.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DIFxData.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\difxdata.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>FontData.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\fontdata.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>isrt.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\isrt.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.inx</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\setup.inx found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>sndc_i64.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\sndc_i64.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>sndc_x64.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\sndc_x64.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>sndc_x86.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\sndc_x86.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>StringTable-0009-English.ips</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\stringtable-0009-english.ips found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_IsRes.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e}\_isres.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>{F7DCAA4A-DDE8-481E-8D44-F6CDCD48DB0E}</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341}\{f7dcaa4a-dde8-481e-8d44-f6cdcd48db0e} found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>{63B837BF-BCEA-4ECA-BA9D-D05BEB795341}</Entry> <Details>File c:\users\vanda\appdata\local\temp\{63b837bf-bcea-4eca-ba9d-d05beb795341} found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\setup.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_ispackdel.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\_ispackdel.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_Setup.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\_setup.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>data1.cab</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\data1.cab found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>data1.hdr</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\data1.hdr found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>ISSetup.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\issetup.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>layout.bin</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\layout.bin found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.exe</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\setup.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.ini</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\setup.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.inx</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\setup.inx found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>setup.iss</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\setup.iss found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>_Setup.dll</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1\_setup.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Disk1</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2}\disk1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>{6B3805D9-DAD9-4FB9-A6D3-CB031AEBA7B2}</Entry> <Details>File c:\users\vanda\appdata\local\temp\{6b3805d9-dad9-4fb9-a6d3-cb031aeba7b2} found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>1754957.exe</Entry> <Details>File c:\windows\temp\1754957.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>bcdedit32.exe</Entry> <Details>File c:\windows\temp\bcdedit32.exe found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>js_vk_0</Entry> <Details>File c:\windows\temp\js_vk_0 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>js_vk_1</Entry> <Details>File c:\windows\temp\js_vk_1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MpCmdRun.log</Entry> <Details>File c:\windows\temp\mpcmdrun.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>AudioDiagnosticSnapIn.dll</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\audiodiagnosticsnapin.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Invocation.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cl_invocation.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LoadAssembly.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cl_loadassembly.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_RegSnapin.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cl_regsnapin.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_RunDiagnosticScript.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cl_rundiagnosticscript.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Utility.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cl_utility.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.diagpkg</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\diagpackage.diagpkg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\diagpackage.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MF_AudioDiagnostic.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\mf_audiodiagnostic.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Registry log.reg</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\registry log.reg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_AudioService.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\rs_audioservice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_ChangeVolume.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\rs_changevolume.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_EnableInCPL.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\rs_enableincpl.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_NotDefault.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\rs_notdefault.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_Unmute.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\rs_unmute.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_AudioDeviceDriver.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_audiodevicedriver.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_AudioService.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_audioservice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DisabledInCPL.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_disabledincpl.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_LowVolume.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_lowvolume.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_Mute.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_mute.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_NotDefault.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_notdefault.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_UnpluggedIn.ps1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\ts_unpluggedin.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LocalizationData.psd1</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cs-cz\cl_localizationdata.psd1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll.mui</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cs-cz\diagpackage.dll.mui found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>cs-CZ</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\cs-cz found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Registry log.reg</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\result\registry log.reg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>results.xsl</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\result\results.xsl found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>result</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5\result found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>SDIAG_03b62327-3dc7-4032-acf9-bb8e5ad81ee5</Entry> <Details>File c:\windows\temp\sdiag_03b62327-3dc7-4032-acf9-bb8e5ad81ee5 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_DetectingDevice.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\cl_detectingdevice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Utility.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\cl_utility.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DB_DeviceErrorLibrary.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\db_deviceerrorlibrary.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.diagpkg</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\diagpackage.diagpkg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\diagpackage.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_CheckDevices.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_checkdevices.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_DriverNotFound.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_drivernotfound.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_EnableDevice.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_enabledevice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_RescanAllDevices.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_rescanalldevices.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_UpdateDriver.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_updatedriver.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_WindowsUpdate.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\rs_windowsupdate.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DeviceDisabled.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_devicedisabled.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DriverNeedUpdated.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_driverneedupdated.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DriverNotFound.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_drivernotfound.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_HardwareDeviceMain.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_hardwaredevicemain.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_NotWorkProperly.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_notworkproperly.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_WindowsUpdate.ps1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\ts_windowsupdate.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LocalizationData.psd1</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\cs-cz\cl_localizationdata.psd1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll.mui</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\cs-cz\diagpackage.dll.mui found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>cs-CZ</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\cs-cz found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>results.xsl</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\result\results.xsl found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>result</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17\result found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>SDIAG_2601c11c-2a10-437e-9fa6-fc974fb4fb17</Entry> <Details>File c:\windows\temp\sdiag_2601c11c-2a10-437e-9fa6-fc974fb4fb17 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>AudioDiagnosticSnapIn.dll</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\audiodiagnosticsnapin.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Invocation.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cl_invocation.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LoadAssembly.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cl_loadassembly.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_RegSnapin.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cl_regsnapin.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_RunDiagnosticScript.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cl_rundiagnosticscript.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Utility.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cl_utility.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.diagpkg</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\diagpackage.diagpkg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\diagpackage.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MF_AudioDiagnostic.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\mf_audiodiagnostic.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_AudioService.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\rs_audioservice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_ChangeVolume.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\rs_changevolume.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_EnableInCPL.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\rs_enableincpl.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_NotDefault.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\rs_notdefault.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_Unmute.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\rs_unmute.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_AudioDeviceDriver.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_audiodevicedriver.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_AudioService.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_audioservice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DisabledInCPL.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_disabledincpl.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_LowVolume.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_lowvolume.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_Mute.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_mute.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_NotDefault.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_notdefault.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_UnpluggedIn.ps1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\ts_unpluggedin.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LocalizationData.psd1</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cs-cz\cl_localizationdata.psd1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll.mui</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cs-cz\diagpackage.dll.mui found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>cs-CZ</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\cs-cz found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DebugReport.xml</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\result\debugreport.xml found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>results.xsl</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\result\results.xsl found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>result</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef\result found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>SDIAG_6ebba3d3-044d-4fdf-b833-a3c64efb1bef</Entry> <Details>File c:\windows\temp\sdiag_6ebba3d3-044d-4fdf-b833-a3c64efb1bef found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_DetectingDevice.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\cl_detectingdevice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_Utility.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\cl_utility.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DB_DeviceErrorLibrary.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\db_deviceerrorlibrary.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.diagpkg</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\diagpackage.diagpkg found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\diagpackage.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_CheckDevices.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_checkdevices.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_DriverNotFound.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_drivernotfound.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_EnableDevice.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_enabledevice.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_RescanAllDevices.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_rescanalldevices.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_UpdateDriver.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_updatedriver.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RS_WindowsUpdate.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\rs_windowsupdate.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DeviceDisabled.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_devicedisabled.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DriverNeedUpdated.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_driverneedupdated.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_DriverNotFound.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_drivernotfound.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_HardwareDeviceMain.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_hardwaredevicemain.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_NotWorkProperly.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_notworkproperly.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>TS_WindowsUpdate.ps1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\ts_windowsupdate.ps1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>CL_LocalizationData.psd1</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\cs-cz\cl_localizationdata.psd1 found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>DiagPackage.dll.mui</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\cs-cz\diagpackage.dll.mui found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>cs-CZ</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\cs-cz found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>results.xsl</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\result\results.xsl found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>result</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c\result found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>SDIAG_d3f422bf-ba1a-4045-ad7e-f311923a002c</Entry> <Details>File c:\windows\temp\sdiag_d3f422bf-ba1a-4045-ad7e-f311923a002c found in temporary files can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Antivirus"><Description>Displays the current status of installed Antivirus software to help protect your computer from the attack of various types of malware.</Description><ErrorsInThisSection>1 Error</ErrorsInThisSection> -<EntryDetails><Entry/> <Details>There is no Antivirus product installed on your system.</Details></EntryDetails> </Scanning> </AROScanLog>
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
Spusť MBAM a na páté záložce "Protokoly" najdeš textový soubor, který otevřeš a obsah mi sem zkopíruješ
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Win32/ConMiner
posílam ten výpis
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Verze databáze: 7595
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
28.8.2011 19:24:33
mbam-log-2011-08-28 (19-24-33).txt
Typ: Úplná kontrola (C:\|)
Kontrolované objekty: 243528
Uplynulý čas: 22 minut, 48 sekund
Infikované procesy v paměti: 13
Infikované moduly v paměti: 0
Infikované klíče v registru: 10
Infikované hodnoty v registru: 9
Infikované datové položky v registru: 4
Infikované složky: 1
Infikované soubory: 28
Infikované procesy v paměti:
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> 1688 -> Unloaded process successfully.
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> 528 -> Unloaded process successfully.
c:\Windows\update.tray-3-0\svchost.exe (Trojan.Dropper) -> 1984 -> Unloaded process successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> 1992 -> Unloaded process successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> 3336 -> Unloaded process successfully.
c:\Windows\sysdriver32_.exe (Trojan.Agent) -> 2000 -> Unloaded process successfully.
c:\Windows\l1rezerv.exe (Trojan.Agent) -> 2024 -> Unloaded process successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> 1192 -> Unloaded process successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> 2412 -> Unloaded process successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> 2328 -> Unloaded process successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> 2568 -> Unloaded process successfully.
c:\Windows\update.1\svchost.exe (Trojan.Dropper) -> 3696 -> Unloaded process successfully.
c:\Windows\systemup.exe (Trojan.Agent.Gen) -> 2016 -> Unloaded process successfully.
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddservice (Spyware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvbtcclient (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srviecheck (Trojan.Downloader.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpdrivers (Trojan.Dropper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tray_ico0 (Trojan.Dropper) -> Value: tray_ico0 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32.exe (Trojan.Agent) -> Value: sysdriver32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32_.exe (Trojan.Agent) -> Value: sysdriver32_.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\l1rezerv.exe (Trojan.Agent) -> Value: l1rezerv.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxpdrv (Trojan.Dropper) -> Value: wxpdrv -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\systemup (Trojan.Agent.Gen) -> Value: systemup -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddservice\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpDrivers\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("%1" %*) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> Quarantined and deleted successfully.
Infikované soubory:
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> Quarantined and deleted successfully.
c:\Windows\update.tray-3-0\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\sysdriver32_.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\l1rezerv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> Quarantined and deleted successfully.
c:\Windows\update.1\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\services32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\vanda\Music\flash-player.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\update.tray-3-0-lnk\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\systemup.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\1754957.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\4109319.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Verze databáze: 7595
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
28.8.2011 19:24:33
mbam-log-2011-08-28 (19-24-33).txt
Typ: Úplná kontrola (C:\|)
Kontrolované objekty: 243528
Uplynulý čas: 22 minut, 48 sekund
Infikované procesy v paměti: 13
Infikované moduly v paměti: 0
Infikované klíče v registru: 10
Infikované hodnoty v registru: 9
Infikované datové položky v registru: 4
Infikované složky: 1
Infikované soubory: 28
Infikované procesy v paměti:
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> 1688 -> Unloaded process successfully.
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> 528 -> Unloaded process successfully.
c:\Windows\update.tray-3-0\svchost.exe (Trojan.Dropper) -> 1984 -> Unloaded process successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> 1992 -> Unloaded process successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> 3336 -> Unloaded process successfully.
c:\Windows\sysdriver32_.exe (Trojan.Agent) -> 2000 -> Unloaded process successfully.
c:\Windows\l1rezerv.exe (Trojan.Agent) -> 2024 -> Unloaded process successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> 1192 -> Unloaded process successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> 2412 -> Unloaded process successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> 2328 -> Unloaded process successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> 2568 -> Unloaded process successfully.
c:\Windows\update.1\svchost.exe (Trojan.Dropper) -> 3696 -> Unloaded process successfully.
c:\Windows\systemup.exe (Trojan.Agent.Gen) -> 2016 -> Unloaded process successfully.
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddservice (Spyware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvbtcclient (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srviecheck (Trojan.Downloader.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpdrivers (Trojan.Dropper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tray_ico0 (Trojan.Dropper) -> Value: tray_ico0 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32.exe (Trojan.Agent) -> Value: sysdriver32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysdriver32_.exe (Trojan.Agent) -> Value: sysdriver32_.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\l1rezerv.exe (Trojan.Agent) -> Value: l1rezerv.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxpdrv (Trojan.Dropper) -> Value: wxpdrv -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\systemup (Trojan.Agent.Gen) -> Value: systemup -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ddservice\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wxpDrivers\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("%1" %*) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> Quarantined and deleted successfully.
Infikované soubory:
c:\Windows\update.7.1\svchostdriver.exe (Spyware.Agent) -> Quarantined and deleted successfully.
c:\Windows\update.tray-3-0\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\sysdriver32_.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\l1rezerv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\update.5.0\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\update.2\svchost.exe (Trojan.Downloader.H) -> Quarantined and deleted successfully.
c:\Windows\update.1\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\services32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\vanda\Music\flash-player.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\update.tray-3-0-lnk\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\systemup.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\1754957.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\4109319.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
to je správné - pokračujeme
Stáhni si zde: ComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Win32/ConMiner
vkládam výpis z ComboFixu
ComboFix 11-08-29.01 - vanda 29.08.2011 15:55:28.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1410 [GMT 2:00]
Spuštěný z: c:\users\vanda\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\vanda\AppData\Roaming\Mikrotik
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\advtool.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\advtool.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\dhcp.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\dhcp.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\hotspot.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\hotspot.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\mpls.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\mpls.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\ppp.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\ppp.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roteros.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roteros.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roting4.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roting4.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\secure.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\secure.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\system.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\system.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\winbox.cfg
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.7.1
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 14:00 . 2011-08-29 14:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\users\vanda\AppData\Roaming\Malwarebytes
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 16:58 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-28 16:58 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 17:33 . 2011-08-28 16:48 -------- d-----w- c:\users\vanda\AppData\Roaming\Sammsoft
2011-08-27 13:46 . 2011-08-27 13:55 -------- d-----w- c:\program files\trend micro
2011-08-27 13:46 . 2011-08-27 13:47 -------- d-----w- C:\rsit
2011-08-27 13:08 . 2011-08-27 13:08 -------- d-----w- c:\program files\CCleaner
2011-08-27 12:30 . 2011-08-27 12:30 -------- d-----w- c:\users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 12:29 . 2011-08-27 14:08 -------- d-----w- c:\users\vanda\AppData\Local\Canon Easy-PhotoPrint EX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJEPPEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJSolutionMenuEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJMyPrinter
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonEPP
2011-08-27 12:21 . 2011-08-27 12:21 -------- d-----w- c:\programdata\CanonIJMSetup
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\program files\Common Files\CANON
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\programdata\CanonIJWSpt
2011-08-27 12:17 . 2010-08-25 03:00 73216 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAF.DLL
2011-08-27 12:17 . 2010-08-25 03:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAF.DLL
2011-08-27 12:16 . 2010-08-25 03:00 290816 ----a-w- c:\windows\system32\CNMLMAF.DLL
2011-08-27 12:16 . 2010-03-11 08:56 180224 ----a-w- c:\windows\system32\CNMIUAF.DLL
2011-08-27 12:02 . 2011-08-27 12:02 -------- d-----w- c:\program files\Common Files\ArcSoft
2011-08-27 12:02 . 2005-04-27 14:36 245408 ----a-r- c:\windows\system32\unicows.dll
2011-08-27 12:02 . 2005-02-23 12:58 11776 ----a-w- c:\windows\system32\drivers\afc.sys
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\program files\Trust Webcam
2011-08-27 11:57 . 2009-06-26 16:13 241664 ----a-w- c:\windows\tsnp2uvc.exe
2011-08-27 11:57 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\users\vanda\AppData\Roaming\InstallShield
2011-08-27 09:19 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6208CBD-4F79-4347-96E3-373C4DB5E666}\mpengine.dll
2011-08-25 17:04 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-25 16:24 . 2011-08-25 16:24 -------- d--h--w- c:\windows\update.8.1
2011-08-23 10:04 . 2011-08-23 10:04 -------- d-----w- C:\ATI
2011-08-23 09:57 . 2011-08-28 17:38 -------- d-----w- c:\windows\ufa
2011-08-23 09:54 . 2011-08-23 09:57 246272 ----a-w- c:\windows\unrar.exe
2011-08-23 09:53 . 2011-08-23 09:53 -------- d-----w- c:\windows\av_ico
2011-08-23 09:52 . 2011-08-28 17:24 -------- d--h--w- c:\windows\update.tray-3-0
2011-08-23 09:52 . 2011-08-28 17:24 -------- d--h--w- c:\windows\update.tray-3-0-lnk
2011-08-14 18:37 . 2011-08-14 18:42 -------- d-----w- c:\users\vanda\AppData\Roaming\vlc
2011-07-31 18:10 . 2011-08-01 20:30 -------- d-----w- c:\programdata\tmp
2011-07-31 18:10 . 2011-07-31 18:10 -------- d-----w- c:\programdata\hps
2011-07-31 18:02 . 2011-07-31 18:02 -------- d-----w- c:\program files\dm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-18 13:13 . 2011-06-18 13:13 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-18 13:13 . 2011-06-18 13:13 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-18 13:13 . 2011-06-18 13:13 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-18 13:13 . 2011-06-18 13:13 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-18 13:13 . 2011-06-18 13:13 367104 ----a-w- c:\windows\system32\html.iec
2011-06-18 13:13 . 2011-06-18 13:13 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-18 13:13 . 2011-06-18 13:13 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-18 13:13 . 2011-06-18 13:13 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-18 13:13 . 2011-06-18 13:13 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-18 13:13 . 2011-06-18 13:13 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-18 13:13 . 2011-06-18 13:13 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-18 13:13 . 2011-06-18 13:13 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-18 13:13 . 2011-06-18 13:13 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-18 13:13 . 2011-06-18 13:13 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-18 13:13 . 2011-06-18 13:13 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-18 13:13 . 2011-06-18 13:13 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-18 13:09 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-14 05:16 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-08 07:29 . 2011-07-12 18:08 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1EA00BE1-6E54-4E2A-8099-680300BF23E1}"= "c:\program files\Seznam.cz\toolbar\toolbar.dll" [2010-10-06 187672]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{1ea00be1-6e54-4e2a-8099-680300bf23e1}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{34AB3C4C-DA1A-4067-96F4-31452C7CFE65}"= "c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll" [2011-04-20 2194464]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{34ab3c4c-da1a-4067-96f4-31452c7cfe65}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programy\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"InternetCalls"="c:\programy\InternetCalls.com\InternetCalls\internetcalls.exe" [2011-08-27 13871928]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programy\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-08 8505888]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-12 37888]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-06-22 662016]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2009-06-26 241664]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.microsoft.com
mStart Page = hxxp://www.microsoft.com
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll
TCP: Interfaces\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
FF - ProfilePath - c:\users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico1 - (no file)
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-08-29 16:02:23
ComboFix-quarantined-files.txt 2011-08-29 14:02
.
Před spuštěním: Volných bajtů: 282 330 181 632
Po spuštění: Volných bajtů: 281 889 292 288
.
- - End Of File - - 3ED24DAF1E4C651AD52C7A5C2380ED33
ComboFix 11-08-29.01 - vanda 29.08.2011 15:55:28.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1410 [GMT 2:00]
Spuštěný z: c:\users\vanda\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\vanda\AppData\Roaming\Mikrotik
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\advtool.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\advtool.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\dhcp.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\dhcp.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\hotspot.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\hotspot.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\mpls.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\mpls.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\ppp.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\ppp.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roteros.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roteros.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roting4.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\roting4.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\secure.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\secure.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\system.crc
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\4.11-2658062600\system.dll
c:\users\vanda\AppData\Roaming\Mikrotik\Winbox\winbox.cfg
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.7.1
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 14:00 . 2011-08-29 14:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\users\vanda\AppData\Roaming\Malwarebytes
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 16:58 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-28 16:58 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 17:33 . 2011-08-28 16:48 -------- d-----w- c:\users\vanda\AppData\Roaming\Sammsoft
2011-08-27 13:46 . 2011-08-27 13:55 -------- d-----w- c:\program files\trend micro
2011-08-27 13:46 . 2011-08-27 13:47 -------- d-----w- C:\rsit
2011-08-27 13:08 . 2011-08-27 13:08 -------- d-----w- c:\program files\CCleaner
2011-08-27 12:30 . 2011-08-27 12:30 -------- d-----w- c:\users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 12:29 . 2011-08-27 14:08 -------- d-----w- c:\users\vanda\AppData\Local\Canon Easy-PhotoPrint EX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJEPPEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJSolutionMenuEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJMyPrinter
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonEPP
2011-08-27 12:21 . 2011-08-27 12:21 -------- d-----w- c:\programdata\CanonIJMSetup
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\program files\Common Files\CANON
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\programdata\CanonIJWSpt
2011-08-27 12:17 . 2010-08-25 03:00 73216 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAF.DLL
2011-08-27 12:17 . 2010-08-25 03:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAF.DLL
2011-08-27 12:16 . 2010-08-25 03:00 290816 ----a-w- c:\windows\system32\CNMLMAF.DLL
2011-08-27 12:16 . 2010-03-11 08:56 180224 ----a-w- c:\windows\system32\CNMIUAF.DLL
2011-08-27 12:02 . 2011-08-27 12:02 -------- d-----w- c:\program files\Common Files\ArcSoft
2011-08-27 12:02 . 2005-04-27 14:36 245408 ----a-r- c:\windows\system32\unicows.dll
2011-08-27 12:02 . 2005-02-23 12:58 11776 ----a-w- c:\windows\system32\drivers\afc.sys
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\program files\Trust Webcam
2011-08-27 11:57 . 2009-06-26 16:13 241664 ----a-w- c:\windows\tsnp2uvc.exe
2011-08-27 11:57 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\users\vanda\AppData\Roaming\InstallShield
2011-08-27 09:19 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6208CBD-4F79-4347-96E3-373C4DB5E666}\mpengine.dll
2011-08-25 17:04 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-25 16:24 . 2011-08-25 16:24 -------- d--h--w- c:\windows\update.8.1
2011-08-23 10:04 . 2011-08-23 10:04 -------- d-----w- C:\ATI
2011-08-23 09:57 . 2011-08-28 17:38 -------- d-----w- c:\windows\ufa
2011-08-23 09:54 . 2011-08-23 09:57 246272 ----a-w- c:\windows\unrar.exe
2011-08-23 09:53 . 2011-08-23 09:53 -------- d-----w- c:\windows\av_ico
2011-08-23 09:52 . 2011-08-28 17:24 -------- d--h--w- c:\windows\update.tray-3-0
2011-08-23 09:52 . 2011-08-28 17:24 -------- d--h--w- c:\windows\update.tray-3-0-lnk
2011-08-14 18:37 . 2011-08-14 18:42 -------- d-----w- c:\users\vanda\AppData\Roaming\vlc
2011-07-31 18:10 . 2011-08-01 20:30 -------- d-----w- c:\programdata\tmp
2011-07-31 18:10 . 2011-07-31 18:10 -------- d-----w- c:\programdata\hps
2011-07-31 18:02 . 2011-07-31 18:02 -------- d-----w- c:\program files\dm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-18 13:13 . 2011-06-18 13:13 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-18 13:13 . 2011-06-18 13:13 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-18 13:13 . 2011-06-18 13:13 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-18 13:13 . 2011-06-18 13:13 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-18 13:13 . 2011-06-18 13:13 367104 ----a-w- c:\windows\system32\html.iec
2011-06-18 13:13 . 2011-06-18 13:13 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-18 13:13 . 2011-06-18 13:13 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-18 13:13 . 2011-06-18 13:13 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-18 13:13 . 2011-06-18 13:13 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-18 13:13 . 2011-06-18 13:13 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-18 13:13 . 2011-06-18 13:13 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-18 13:13 . 2011-06-18 13:13 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-18 13:13 . 2011-06-18 13:13 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-18 13:13 . 2011-06-18 13:13 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-18 13:13 . 2011-06-18 13:13 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-18 13:13 . 2011-06-18 13:13 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-18 13:09 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-14 05:16 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-08 07:29 . 2011-07-12 18:08 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1EA00BE1-6E54-4E2A-8099-680300BF23E1}"= "c:\program files\Seznam.cz\toolbar\toolbar.dll" [2010-10-06 187672]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{1ea00be1-6e54-4e2a-8099-680300bf23e1}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{34AB3C4C-DA1A-4067-96F4-31452C7CFE65}"= "c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll" [2011-04-20 2194464]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{34ab3c4c-da1a-4067-96f4-31452c7cfe65}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programy\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"InternetCalls"="c:\programy\InternetCalls.com\InternetCalls\internetcalls.exe" [2011-08-27 13871928]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programy\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-08 8505888]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-12 37888]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-06-22 662016]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2009-06-26 241664]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.microsoft.com
mStart Page = hxxp://www.microsoft.com
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll
TCP: Interfaces\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
FF - ProfilePath - c:\users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico1 - (no file)
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-08-29 16:02:23
ComboFix-quarantined-files.txt 2011-08-29 14:02
.
Před spuštěním: Volných bajtů: 282 330 181 632
Po spuštění: Volných bajtů: 281 889 292 288
.
- - End Of File - - 3ED24DAF1E4C651AD52C7A5C2380ED33
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
Soubor ulož na plochu jako CFscript.txt a jeho ikonu přetáhni myší nad ikonu ComboFixu - tam pusť.

ComboFix se spustí - počkej na log a vlož ho sem.
CFscript
Kód: Vybrat vše
KillAll::
Folder::
c:\windows\update.8.1
c:\windows\ufa
c:\windows\av_ico
c:\windows\update.tray-3-0
c:\windows\update.tray-3-0-lnk
c:\program files\Ask.com
File::
c:\windows\unrar.exe
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{1ea00be1-6e54-4e2a-8099-680300bf23e1}]
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{34ab3c4c-da1a-4067-96f4-31452c7cfe65}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"Malwarebytes' Anti-Malware"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000000
"DisableThumbnailCache"=dword:00000000
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Win32/ConMiner
Vkládam ten výsledek
ComboFix 11-08-29.01 - vanda 29.08.2011 17:32:23.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1106 [GMT 2:00]
Spuštěný z: c:\users\vanda\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\vanda\Desktop\CFscript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_d00b.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\av_ico
c:\windows\av_ico\ico_NOD_SS_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\ufa
c:\windows\unrar.exe
c:\windows\update.8.1
c:\windows\update.tray-3-0-lnk
c:\windows\update.tray-3-0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 15:37 . 2011-08-29 15:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\users\vanda\AppData\Roaming\Malwarebytes
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 16:58 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-28 16:58 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 17:33 . 2011-08-28 16:48 -------- d-----w- c:\users\vanda\AppData\Roaming\Sammsoft
2011-08-27 13:46 . 2011-08-27 13:55 -------- d-----w- c:\program files\trend micro
2011-08-27 13:46 . 2011-08-27 13:47 -------- d-----w- C:\rsit
2011-08-27 13:08 . 2011-08-27 13:08 -------- d-----w- c:\program files\CCleaner
2011-08-27 12:30 . 2011-08-27 12:30 -------- d-----w- c:\users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 12:29 . 2011-08-27 14:08 -------- d-----w- c:\users\vanda\AppData\Local\Canon Easy-PhotoPrint EX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJEPPEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJSolutionMenuEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJMyPrinter
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonEPP
2011-08-27 12:21 . 2011-08-27 12:21 -------- d-----w- c:\programdata\CanonIJMSetup
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\program files\Common Files\CANON
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\programdata\CanonIJWSpt
2011-08-27 12:17 . 2010-08-25 03:00 73216 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAF.DLL
2011-08-27 12:17 . 2010-08-25 03:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAF.DLL
2011-08-27 12:16 . 2010-08-25 03:00 290816 ----a-w- c:\windows\system32\CNMLMAF.DLL
2011-08-27 12:16 . 2010-03-11 08:56 180224 ----a-w- c:\windows\system32\CNMIUAF.DLL
2011-08-27 12:02 . 2011-08-27 12:02 -------- d-----w- c:\program files\Common Files\ArcSoft
2011-08-27 12:02 . 2005-04-27 14:36 245408 ----a-r- c:\windows\system32\unicows.dll
2011-08-27 12:02 . 2005-02-23 12:58 11776 ----a-w- c:\windows\system32\drivers\afc.sys
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\program files\Trust Webcam
2011-08-27 11:57 . 2009-06-26 16:13 241664 ----a-w- c:\windows\tsnp2uvc.exe
2011-08-27 11:57 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\users\vanda\AppData\Roaming\InstallShield
2011-08-27 09:19 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6208CBD-4F79-4347-96E3-373C4DB5E666}\mpengine.dll
2011-08-25 17:04 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-23 10:04 . 2011-08-23 10:04 -------- d-----w- C:\ATI
2011-08-14 18:37 . 2011-08-14 18:42 -------- d-----w- c:\users\vanda\AppData\Roaming\vlc
2011-07-31 18:10 . 2011-08-01 20:30 -------- d-----w- c:\programdata\tmp
2011-07-31 18:10 . 2011-07-31 18:10 -------- d-----w- c:\programdata\hps
2011-07-31 18:02 . 2011-07-31 18:02 -------- d-----w- c:\program files\dm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-18 13:13 . 2011-06-18 13:13 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-18 13:13 . 2011-06-18 13:13 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-18 13:13 . 2011-06-18 13:13 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-18 13:13 . 2011-06-18 13:13 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-18 13:13 . 2011-06-18 13:13 367104 ----a-w- c:\windows\system32\html.iec
2011-06-18 13:13 . 2011-06-18 13:13 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-18 13:13 . 2011-06-18 13:13 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-18 13:13 . 2011-06-18 13:13 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-18 13:13 . 2011-06-18 13:13 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-18 13:13 . 2011-06-18 13:13 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-18 13:13 . 2011-06-18 13:13 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-18 13:13 . 2011-06-18 13:13 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-18 13:13 . 2011-06-18 13:13 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-18 13:13 . 2011-06-18 13:13 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-18 13:13 . 2011-06-18 13:13 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-18 13:13 . 2011-06-18 13:13 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-18 13:09 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-14 05:16 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-08 07:29 . 2011-07-12 18:08 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programy\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"InternetCalls"="c:\programy\InternetCalls.com\InternetCalls\internetcalls.exe" [2011-08-27 13871928]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programy\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-08 8505888]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-12 37888]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-06-22 662016]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2009-06-26 241664]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.microsoft.com
mStart Page = hxxp://www.microsoft.com
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll
TCP: Interfaces\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
FF - ProfilePath - c:\users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - (no file)
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\programy\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-29 17:41:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-29 15:41
ComboFix2.txt 2011-08-29 14:02
.
Před spuštěním: Volných bajtů: 281 929 216 000
Po spuštění: Volných bajtů: 281 611 390 976
.
- - End Of File - - 150664654FC2E411A90EA2D3DB152EED
ComboFix 11-08-29.01 - vanda 29.08.2011 17:32:23.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1106 [GMT 2:00]
Spuštěný z: c:\users\vanda\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\vanda\Desktop\CFscript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_d00b.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\av_ico
c:\windows\av_ico\ico_NOD_SS_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\ufa
c:\windows\unrar.exe
c:\windows\update.8.1
c:\windows\update.tray-3-0-lnk
c:\windows\update.tray-3-0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 15:37 . 2011-08-29 15:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\users\vanda\AppData\Roaming\Malwarebytes
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 16:58 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-28 16:58 . 2011-08-28 16:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-28 16:58 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 17:33 . 2011-08-28 16:48 -------- d-----w- c:\users\vanda\AppData\Roaming\Sammsoft
2011-08-27 13:46 . 2011-08-27 13:55 -------- d-----w- c:\program files\trend micro
2011-08-27 13:46 . 2011-08-27 13:47 -------- d-----w- C:\rsit
2011-08-27 13:08 . 2011-08-27 13:08 -------- d-----w- c:\program files\CCleaner
2011-08-27 12:30 . 2011-08-27 12:30 -------- d-----w- c:\users\vanda\AppData\Roaming\CD-LabelPrint
2011-08-27 12:29 . 2011-08-27 14:08 -------- d-----w- c:\users\vanda\AppData\Local\Canon Easy-PhotoPrint EX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJEPPEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJSolutionMenuEX
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonIJMyPrinter
2011-08-27 12:29 . 2011-08-27 12:29 -------- d--h--w- c:\programdata\CanonEPP
2011-08-27 12:21 . 2011-08-27 12:21 -------- d-----w- c:\programdata\CanonIJMSetup
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\program files\Common Files\CANON
2011-08-27 12:19 . 2011-08-27 12:19 -------- d-----w- c:\programdata\CanonIJWSpt
2011-08-27 12:17 . 2010-08-25 03:00 73216 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAF.DLL
2011-08-27 12:17 . 2010-08-25 03:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAF.DLL
2011-08-27 12:16 . 2010-08-25 03:00 290816 ----a-w- c:\windows\system32\CNMLMAF.DLL
2011-08-27 12:16 . 2010-03-11 08:56 180224 ----a-w- c:\windows\system32\CNMIUAF.DLL
2011-08-27 12:02 . 2011-08-27 12:02 -------- d-----w- c:\program files\Common Files\ArcSoft
2011-08-27 12:02 . 2005-04-27 14:36 245408 ----a-r- c:\windows\system32\unicows.dll
2011-08-27 12:02 . 2005-02-23 12:58 11776 ----a-w- c:\windows\system32\drivers\afc.sys
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\program files\Trust Webcam
2011-08-27 11:57 . 2009-06-26 16:13 241664 ----a-w- c:\windows\tsnp2uvc.exe
2011-08-27 11:57 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2011-08-27 11:57 . 2011-08-27 11:57 -------- d-----w- c:\users\vanda\AppData\Roaming\InstallShield
2011-08-27 09:19 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6208CBD-4F79-4347-96E3-373C4DB5E666}\mpengine.dll
2011-08-25 17:04 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-23 10:04 . 2011-08-23 10:04 -------- d-----w- C:\ATI
2011-08-14 18:37 . 2011-08-14 18:42 -------- d-----w- c:\users\vanda\AppData\Roaming\vlc
2011-07-31 18:10 . 2011-08-01 20:30 -------- d-----w- c:\programdata\tmp
2011-07-31 18:10 . 2011-07-31 18:10 -------- d-----w- c:\programdata\hps
2011-07-31 18:02 . 2011-07-31 18:02 -------- d-----w- c:\program files\dm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-18 13:13 . 2011-06-18 13:13 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-18 13:13 . 2011-06-18 13:13 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-18 13:13 . 2011-06-18 13:13 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-18 13:13 . 2011-06-18 13:13 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-18 13:13 . 2011-06-18 13:13 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-18 13:13 . 2011-06-18 13:13 367104 ----a-w- c:\windows\system32\html.iec
2011-06-18 13:13 . 2011-06-18 13:13 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-18 13:13 . 2011-06-18 13:13 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-18 13:13 . 2011-06-18 13:13 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-18 13:13 . 2011-06-18 13:13 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-18 13:13 . 2011-06-18 13:13 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-18 13:13 . 2011-06-18 13:13 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-18 13:13 . 2011-06-18 13:13 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-18 13:13 . 2011-06-18 13:13 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-18 13:13 . 2011-06-18 13:13 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-18 13:13 . 2011-06-18 13:13 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-18 13:13 . 2011-06-18 13:13 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-18 13:09 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-14 05:16 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-08 07:29 . 2011-07-12 18:08 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programy\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"InternetCalls"="c:\programy\InternetCalls.com\InternetCalls\internetcalls.exe" [2011-08-27 13871928]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\programy\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-08 8505888]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-12 37888]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2009-06-22 662016]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2009-06-26 241664]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-08 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.microsoft.com
mStart Page = hxxp://www.microsoft.com
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - c:\users\vanda\AppData\Local\Seznam.cz\listicka.dll
TCP: Interfaces\{EC8001FD-872F-4D53-BDD2-478D04F5FD3A}: NameServer = 193.85.1.100,193.85.2.100
FF - ProfilePath - c:\users\vanda\AppData\Roaming\Mozilla\Firefox\Profiles\zpddljay.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - (no file)
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\programy\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-29 17:41:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-29 15:41
ComboFix2.txt 2011-08-29 14:02
.
Před spuštěním: Volných bajtů: 281 929 216 000
Po spuštění: Volných bajtů: 281 611 390 976
.
- - End Of File - - 150664654FC2E411A90EA2D3DB152EED
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
a jestli už nenacházíš nic podivného, tak po sobě uklidím
jdi Start -> Spustit... a zkopíruj ComboFix /Uninstall (pozor, za x je mezera) -> OK
Stáhni a spusť T-cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe - uklidí po použitých čističích.
Po spuštění ignoruj případné varování antiviru - je to v pořádku
Po provedení akce T-cleaner smažeš
Zavři všechny programy a spusť. Po ukončení akce bude PC restartován.
Pokud ne, restartuj sám.
(čistí Temp složky , nečistí URL, historii, prefetch ani cookies)
Ten si můžeš nechat i na budoucí občasné čištění.Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"
zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština
Kdyby něco z návodu nefungovalo, pokračuj dalším krokem.
-
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Win32/ConMiner
zatím díky neni to můj Pc vidim to na sobotu k večeru dam pak vědět.

- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Win32/ConMiner
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Přispějete na provoz fóra?