Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivka

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

preventivka

#1 Příspěvek od alash »

Ahoj, prosím o preventivní kontrolu logu, předem díky!

Logfile of random's system information tool 1.09 (written by random/random)
Run by Ales at 2012-12-13 01:17:30
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 144 GB (50%) free of 288 GB
Total RAM: 4010 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:17:32, on 13.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Program Files\trend micro\Ales.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe

--
End of file - 13240 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Tablet\Pen\Pen_TouchService.exe"
"C:\Program Files\Tablet\Wacom\WTabletServicePro.exe"
C:\Windows\system32\svchost.exe -k NetworkService
/QuitInfo:00000000000003F4;00000000000003F8; /AddRef;
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 21258048
\??\C:\Windows\system32\conhost.exe "-287717826-789544275-2120463424-13300707711230272741804857065-1840430355-554288368
/QuitInfo:0000000000000594;0000000000000598; /AddRef;
/QuitInfo:000000000000057C;00000000000005A0;
"C:\Program Files\Tablet\Pen\Pen_TouchUser.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
/loadhooks /Parent:00000000000006CC
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe"
C:\Windows\system32\CxAudMsg64.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
taskeng.exe {662FF08B-DD6C-49DC-AE38-4B1ABD863532}
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Tablet\Pen\Pen_Tablet.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Lenovo\Screen Reading Optimizer\\SRORest.exe"
WLIDSvcM.exe 3344
"C:\Program Files\Tablet\Pen\Pen_TabletUser.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Tablet\Pen\Pen_Tablet.exe" au
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe"
"C:\Program Files\Tablet\Wacom\WacomHost.exe" "C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe" au
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
"C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe" au
"C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2716.20ba6100.1121998644 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 2716 "\\.\pipe\gecko-crash-server-pipe.2716" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe" --proxy-stub-channel=Flash1684.6E0AB7B8.41 --host-broker-channel=Flash1684.6E0AB7B8.18467 --host-pid=1684 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe" --channel=4352.0030F3CC.2128638596 --proxy-stub-channel=Flash1684.6E0AB7B8.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll" --host-npapi-version=27 --type=renderer
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\igfxsrvc.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Ales\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Ales\AppData\Roaming\Mozilla\Firefox\Profiles\lmi24xdz.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.110 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37]
"Description"=
"Path"=C:\Windows\SysWOW64\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npwacom.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.2]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.110 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.2]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.DEU
nppdf32.dll
nppdf32.FRA
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
QuickTimePlugin.class

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll [2011-03-19 164496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-10-25 329712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-10-25 59376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll [2011-03-19 164496]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-05-19 2789160]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-07-28 1935120]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2011-04-26 310912]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-08-11 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-08-11 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-08-11 416024]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-02-13 3481408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2012-07-27 823224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Antivirus]
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [2011-10-21 198032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2012-07-27 36800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-30 499608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCKRESI.EXE]
C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [2011-05-25 281960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-01-21 112512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-02-13 3481408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ForteConfig]
C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LENOVO.TPKNRRES]
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2011-05-31 40808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTT]
C:\Program Files\PC-Doctor\EnableToolbarW32.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RotateImage]
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-31 55808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks]
C:\Windows\system32\TpShocks.exe [2011-01-14 380776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe [2011-03-25 1219360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ales^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Lingea Update Center.lnk]
C:\PROGRA~2\COMMON~1\LINGEA~1\luc.exe [2012-05-28 275736]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"Lenovo Registration"=C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [2011-07-14 4351712]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
""= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2012-07-27 36800]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2012-07-27 823224]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-09-17 254896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-08-09 390144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-19 22:42:03 ----D---- C:\Program Files\TabletPlugins
2012-11-19 22:42:00 ----A---- C:\Windows\system32\drivers\wacomrouterfilter.sys
2012-11-19 22:41:54 ----A---- C:\Windows\system32\drivers\hidkmdf.sys
2012-11-19 22:41:53 ----A---- C:\Windows\system32\drivers\wachidrouter.sys
2012-11-19 22:41:52 ----A---- C:\Windows\SYSWOW64\Wacom_Touch_Tablet.dll
2012-11-19 22:41:52 ----A---- C:\Windows\SYSWOW64\Wacom_Tablet.dll
2012-11-19 22:41:52 ----A---- C:\Windows\system32\Wacom_Touch_Tablet.dll
2012-11-19 22:41:52 ----A---- C:\Windows\system32\Wacom_Tablet.dll

======List of files/folders modified in the last 1 month======

2012-12-13 01:17:32 ----D---- C:\Program Files\trend micro
2012-12-13 01:13:16 ----D---- C:\Windows\Prefetch
2012-12-13 00:48:22 ----D---- C:\Windows\Temp
2012-12-12 17:23:58 ----D---- C:\Windows\system32\config
2012-12-12 00:27:00 ----D---- C:\_data
2012-12-12 00:26:49 ----D---- C:\Windows\System32
2012-12-12 00:26:49 ----D---- C:\Windows\inf
2012-12-12 00:26:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-12 00:26:28 ----D---- C:\Windows\system32\NDF
2012-12-12 00:23:32 ----A---- C:\Windows\SYSWOW64\log.txt
2012-12-11 23:24:16 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-09 20:49:05 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-12-06 00:00:14 ----SHD---- C:\System Volume Information
2012-11-29 13:05:26 ----D---- C:\Windows\Minidump
2012-11-29 13:05:25 ----D---- C:\Windows
2012-11-22 20:32:52 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-22 20:32:50 ----D---- C:\Windows\system32\drivers
2012-11-19 22:48:59 ----D---- C:\ProgramData\Adobe
2012-11-19 22:48:46 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-11-19 22:42:20 ----D---- C:\Users\Ales\AppData\Roaming\WTablet
2012-11-19 22:42:05 ----D---- C:\Program Files (x86)\TabletPlugins
2012-11-19 22:42:03 ----RD---- C:\Program Files
2012-11-19 22:42:03 ----D---- C:\Windows\system32\catroot
2012-11-19 22:42:02 ----D---- C:\Windows\system32\DriverStore
2012-11-19 22:42:02 ----D---- C:\Program Files\Tablet
2012-11-19 22:41:52 ----D---- C:\Windows\SysWOW64

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2011-01-13 139888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-09-01 564792]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2011-01-13 23664]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-28 283200]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2011-07-09 32104]
R1 SbFw;SbFw; C:\Windows\system32\drivers\SbFw.sys [2011-12-19 256632]
R1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [2011-10-26 57976]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2012-05-02 19784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 sbapifs;sbapifs; C:\Windows\system32\DRIVERS\sbapifs.sys [2011-11-29 74872]
R3 5U877;USB Video Device; C:\Windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-03-24 1576064]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2011-08-11 39024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-08-09 12289472]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 iwdbus;IWD Bus Enumerator; C:\Windows\system32\DRIVERS\iwdbus.sys [2011-06-22 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2012-02-02 40248]
R3 SBFWIMCLMP;GFI Software Firewall NDIS IM Filter Miniport; C:\Windows\system32\DRIVERS\SBFWIM.sys [2011-09-29 119416]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-05-19 1442352]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2009-09-24 41536]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\Windows\system32\DRIVERS\wacommousefilter.sys [2011-09-08 12848]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\Windows\system32\DRIVERS\wacomvhid.sys [2011-09-08 16168]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-02-02 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2012-02-02 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2011-03-16 436776]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-03-03 150568]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2011-02-25 163880]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-22 39976]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2011-02-25 21544]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 hidkmdf;KMDF Driver; C:\Windows\system32\DRIVERS\hidkmdf.sys [2012-10-12 13728]
S3 intaud_WaveExtensible;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2011-06-22 34200]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-05-04 338536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SBFWIMCL;GFI Software Firewall NDIS IM Filter Service; C:\Windows\system32\DRIVERS\sbfwim.sys [2011-09-29 119416]
S3 sbhips;sbhips; C:\Windows\system32\drivers\sbhips.sys [2011-12-19 60536]
S3 sbwtis;sbwtis; C:\Windows\system32\DRIVERS\sbwtis.sys [2011-12-19 84600]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WacHidRouter;Wacom Hid Router; C:\Windows\system32\DRIVERS\wachidrouter.sys [2012-10-12 81312]
S3 wacmoumonitor;Wacom Mode Helper; C:\Windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312]
S3 wacomrouterfilter;Wacom Router Filter Driver; C:\Windows\system32\DRIVERS\wacomrouterfilter.sys [2012-10-12 15776]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2011-03-25 968480]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2010-12-16 198784]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-07-28 1517328]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2011-08-11 45928]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 2375168]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-05-31 59240]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 133992]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-07-28 844560]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2011-07-26 28672]
R2 TabletServicePen;TabletServicePen; C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160]
R2 TouchServicePen;Wacom Consumer Touch Service; C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 51445112]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2012-05-02 1662528]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2012-05-02 1665088]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2011-01-13 47728]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-28 1255736]
S4 Ad-Aware Service;Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-05-03 1226096]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-19 250808]
S4 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2011-07-09 144232]
S4 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2011-05-31 41320]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-12-09 115168]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
S4 SBAMSvc;Ad-Aware; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2011-12-19 3289032]
S4 SROSVC;Screen Reading Optimizer Service Program; C:\Program Files (x86)\Lenovo\Screen Reading Optimizer\SROSVC.exe [2011-09-02 446800]
S4 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#2 Příspěvek od Márty84 »

Zdravim :)


:???: Pouzivate Sunbelt Personal Firewall?



:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#3 Příspěvek od alash »

ad Sunbelt Firewall: nepouzivam
avast sandbox nenavrhl, ale v prubehu skenovani vyskocila chybova hlaska: "can not create cmd.bat" a vypada to, ze se sken zastavil a zadne logy se nevytvorily...jeste prihazuju screenshot toho, v jakem stavu skoncil OTL.

predem dik za rady, co sem udelal spatne:)
Přílohy
OTL.jpg
OTL.jpg (84.33 KiB) Zobrazeno 4366 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#4 Příspěvek od Márty84 »

OK, bezi vam tam jeho zbytky, dame je do pryc.

Spatne jste neudelal nic. Tuhle chybu proste OTLko nekdy vyhodi.

Spustte ho podle stejneho navodu jeste jednou, ale pouzijte tento upraveny skript

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#5 Příspěvek od alash »

ok, diky, tentokrate logy vygenerovany:

OTL Extras logfile created on: 15.12.2012 21:15:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ales\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Czech Republic | Language: CSY | Date Format: d.M.yyyy

3,92 Gb Total Physical Memory | 1,54 Gb Available Physical Memory | 39,42% Memory free
7,83 Gb Paging File | 5,11 Gb Available in Paging File | 65,23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 281,00 Gb Total Space | 146,57 Gb Free Space | 52,16% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 13,03 Gb Free Space | 2,80% Space Free | Partition Type: FAT32
Drive Q: | 15,62 Gb Total Space | 5,79 Gb Free Space | 37,09% Space Free | Partition Type: NTFS

Computer Name: ALES-THINK | User Name: Ales | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-1647806338-2296827418-1155026692-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{009FC848-D11F-4501-A1D0-71B3B97D6BEA}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{2ABF0714-8F7F-42E9-8A99-A37A3667DA05}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{32C94D20-91E5-4127-AC34-63C305C54D89}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.5 |
"{48B93283-56B5-4BFB-829B-363D19B668FA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{D923C800-A449-482D-AD46-F2196997731B}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0035F6C8-945B-43FE-A2BD-F1C721107757}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{0F9F492D-747E-42F6-B057-D4B648C7CF62}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{199945DF-6965-426C-9D62-6DB4AB8383BD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{4545C55F-50D1-4F44-8B95-BEB811339B6F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{476FF92A-3B30-4142-8381-6EDCEDE0AAF0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{678125A0-1E3F-40FE-8B53-3CB715CFB9F3}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{70E80A49-E5D7-4036-A15D-FAD850C006F2}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe |
"{83EE9781-6613-4B50-B1E2-4E6D9DA1CB06}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{851D974E-FB52-451D-945F-57092B567F5B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{89E094D8-F046-4561-AF6A-EBC710CF64C5}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{8D2534D8-9563-45DF-B86D-2BE2ACB4AE8D}" = protocol=6 | dir=in | app=c:\program files (x86)\lenovo\system update\uncserver.exe |
"{999786D1-2B5C-4286-A4BA-6248B226D30F}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{BCE0303C-DB43-402F-AEAB-B4F0F1B4D7E0}" = protocol=17 | dir=in | app=c:\program files (x86)\lenovo\system update\uncserver.exe |
"{F2099700-2296-4834-AB98-D9DD26A4AE51}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"TCP Query User{221ACCC6-26C0-42D5-B5F6-71401BD08471}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{5C2BD0E6-A185-4EB2-A030-FCD513ADBB0B}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{A6309274-7B39-43DD-9739-0EBFA2247B31}C:\users\ales\downloads\utorrent-setup\utorrent.exe" = protocol=6 | dir=in | app=c:\users\ales\downloads\utorrent-setup\utorrent.exe |
"TCP Query User{C195B837-B984-4C52-866B-A1F0E58076B1}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |
"UDP Query User{418B522D-560A-4E89-9F5F-8968BCCD3261}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{43D68C3C-B217-4D3B-AA1F-BACD73AA2DAE}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{6023C088-214E-4E3D-AF11-B6E11997608D}C:\users\ales\downloads\utorrent-setup\utorrent.exe" = protocol=17 | dir=in | app=c:\users\ales\downloads\utorrent-setup\utorrent.exe |
"UDP Query User{C6681C11-D8CD-45F9-93C1-4E1CA429646F}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0369F866-2CE0-4EB9-B426-88FA122C6E82}" = Lenovo Patch Utility 64 bit
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25FBDA9A-E868-4B3B-B9FF-D923818511A1}" = Intel(R) PROSet/Wireless WiFi Software
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
"{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources
"{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources
"{39969C3E-B297-41E5-9A7B-E252B504B21B}" = Lenovo SimpleTap
"{39A04221-294E-4D90-A0F2-CCB1EF15CB56}" = Lenovo Patch Utility 64 bit
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}" = Corel Graphics - Windows Shell Extension 64 Bit
"{57DD35E9-D9BB-4089-BB05-EF933C586CB3}" = Broadcom InConcert Maestro
"{5E2652DF-743F-482B-A593-C95F431A5769}" = RapidBoot
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{669A82E0-43E2-4645-8A2E-1A3DE78F8312}" = Adobe Photoshop Lightroom 4 64-bit
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C6C9D5F7-630C-4125-8C4E-94AF77C1896E}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E224B44B-B5EB-4af3-A80A-A255358E241A}_is1" = ThinkVantage AutoLock
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"01E3B64834B04ABAC85D8E1D3EBDC567D83AD29B" = Windows Driver Package - Lenovo 1.64.00.00 (07/28/2011 1.64.00.00)
"95D0E47871170F0763151CFD697BBAB47A5794F7" = Windows Driver Package - Intel (iaStor) hdc (04/26/2011 10.5.0.1026)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"DDD8A532E361E9A878EBEF69C338B306810DF059" = Windows Driver Package - Synaptics (SynTP) Mouse (05/19/2011 15.3.8.0)
"DisableAMTPopup" = Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7
"EnablePS" = Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
"LENOVO.SMIIF" = Lenovo System Interface Driver
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OnScreenDisplay" = On Screen Display
"Pen Tablet Driver" = Bamboo
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"Wacom Tablet Driver" = Wacom Tablet
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 64 bit

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW(R) Graphics Suite X5
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10F5D9BB-E2F2-4B18-A65D-928B73D22E6F}" = USB-IrDA Adapter
"{13F59938-C595-479C-B479-F171AB9AF64F}" = Lenovo User Guide
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data
"{24E92E7A-6848-4747-A3EA-3AAC0576BE52}" = Lenovo Patch Utility
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA
"{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications (R) Core
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 37
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{356658C7-8C60-4A43-AF50-75CA8E642934}" = CorelDRAW Graphics Suite X5 - CZ
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Integrated Camera TWAIN Driver
"{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
"{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger
"{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}" = Create Recovery Media
"{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect
"{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist
"{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6707C034-ED6B-4B6A-B21F-969B3606FBDE}" = Lenovo Registration
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6E6E7725-C7BC-4C39-8B3F-14B67331A120}" = Lenovo Patch Utility
"{781A93CD-1608-427D-B7F0-D05C07795B25}" = Intel(R) WiDi
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{91A29166-4E1B-4664-B70B-4C4A3B6B3372}" = Lenovo Screen Reading Optimizer
"{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{969E11AA-8F3A-F162-1A5A-0965E216B6CE}" = Adobe Download Assistant
"{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AD7914E1-6453-4440-AEC7-02C72AD6FE5F}" = TIPCI
"{B2CA6F37-1602-4823-81B5-0384B6888AA6}" = Integrated Camera Driver Installer Package Ver.1.1.0.1147
"{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5
"{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení
"{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel(R) Identity Protection Technology 1.1.2.0
"{C0BE2E64-6D5F-45CD-A53E-D4C68EEC153C}" = TOPO 50 v4
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common
"{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications (R) Core - English
"{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = Power Manager
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF7DBA84-0A55-11D6-A0A6-6A7573736972}" = Polar ProTrainer
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
"{fc8208f2-b1c1-4253-9e89-d518e983b7bb}" = Ad-Aware Antivirus
"{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}" = Lenovo Warranty Information
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Free Antivirus
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.dmp.contentviewer" = Adobe Content Viewer
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"DAEMON Tools Lite" = DAEMON Tools Lite
"DC++" = DC++ 0.791
"DtsFilter" = DTS+AC3 Filter
"GOM Player" = GOM Player
"Google Chrome" = Google Chrome
"Hugin" = Hugin 2011.2.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"InstallShield_{AD7914E1-6453-4440-AEC7-02C72AD6FE5F}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"IrfanView" = IrfanView (remove only)
"Lenovo Welcome_is1" = Lenovo Welcome
"Lexicon5" = Lingea Lexicon 5
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Mendeley Desktop" = Mendeley Desktop 1.3.2
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"ProInst" = Intel PROSet Wireless
"uTorrent" = µTorrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 32 bit
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1647806338-2296827418-1155026692-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1.10.2012 17:24:22 | Computer Name = Ales-THINK | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.1.0.0, time
stamp: 0x4d90d339 Faulting module name: WinTab32.dll_unloaded, version: 0.0.0.0,
time stamp: 0x4e694f62 Exception code: 0xc0000005 Fault offset: 0x000007fee995bbda
Faulting
process id: 0x4594 Faulting application start time: 0x01cda01afc0f278e Faulting application
path: C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe Faulting
module path: WinTab32.dll Report Id: 5dae18e6-0c0e-11e2-9663-047d7b38fe17

Error - 1.10.2012 17:27:59 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

Error - 3.10.2012 19:54:08 | Computer Name = Ales-THINK | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_ShellHWDetection, version:
6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: unknown, version: 0.0.0.0,
time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000077ce000a
Faulting
process id: 0x430 Faulting application start time: 0x01cda01b89ca841f Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: unknown Report Id: 9e68232a-0db5-11e2-b444-047d7b38fe17

Error - 3.10.2012 19:56:38 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

Error - 10.10.2012 20:26:29 | Computer Name = Ales-THINK | Source = MsiInstaller | ID = 11500
Description =

Error - 10.10.2012 20:31:30 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

Error - 11.10.2012 4:27:43 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

Error - 12.10.2012 4:21:17 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

Error - 13.10.2012 0:34:37 | Computer Name = Ales-THINK | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc3c1 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x000000007774000a Faulting process id: 0x42c Faulting
application start time: 0x01cda8527d52ff66 Faulting application path: C:\Windows\system32\svchost.exe
Faulting
module path: unknown Report Id: 4b41388d-14ef-11e2-9c7b-047d7b38fe17

Error - 13.10.2012 0:36:29 | Computer Name = Ales-THINK | Source = WinMgmt | ID = 10
Description =

[ Lenovo-Lenovo Patch Utility/Admin Events ]
Error - 28.5.2012 17:04:12 | Computer Name = Ales-THINK | Source = Lenovo Patch Utility | ID = 1
Description = HttpFileDownloader failed to download the file "http://download.lenovo.com/ibmdl/pub/pc ... nifest.xml".
Error message: The remote server returned an error: (404) Not Found.

Error - 28.5.2012 17:04:12 | Computer Name = Ales-THINK | Source = Lenovo Patch Utility | ID = 2
Description = Failed to download the manifest file.

Error - 28.5.2012 17:11:33 | Computer Name = Ales-THINK | Source = Lenovo Patch Utility | ID = 1
Description = HttpFileDownloader failed to download the file "http://download.lenovo.com/ibmdl/pub/pc ... nifest.xml".
Error message: The remote server returned an error: (404) Not Found.

[ Lenovo-Message Center Plus/Admin Events ]
Error - 27.2.2012 15:41:35 | Computer Name = Ales-THINK | Source = Lenovo-Message Center Plus/Admin | ID = 4
Description = The file size of the downloaded file /TOC.cab is not the same as the
file size of the file on the server

Error - 27.2.2012 15:41:40 | Computer Name = Ales-THINK | Source = Lenovo-Message Center Plus/Admin | ID = 4
Description = The file C:\ProgramData\Lenovo\MessageCenterPlus\ServerRepository\temp\nas.php
does not have a Lenovo Digital Signature. The file will be deleted

Error - 22.7.2012 8:05:01 | Computer Name = Ales-THINK | Source = Lenovo-Message Center Plus/Admin | ID = 4
Description = The file C:\ProgramData\Lenovo\MessageCenterPlus\ServerRepository\temp\indywidualna
does not have a Lenovo Digital Signature. The file will be deleted

[ System Events ]
Error - 15.12.2012 8:19:00 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 15.12.2012 8:19:30 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the MMCSS service.

Error - 15.12.2012 8:19:30 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7000
Description = The Multimedia Class Scheduler service failed to start due to the
following error: %%1053

Error - 15.12.2012 8:20:00 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the BITS service.

Error - 15.12.2012 8:20:30 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 15.12.2012 8:21:00 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the MMCSS service.

Error - 15.12.2012 8:21:00 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7000
Description = The Multimedia Class Scheduler service failed to start due to the
following error: %%1053

Error - 15.12.2012 8:22:08 | Computer Name = Ales-THINK | Source = EventLog | ID = 6008
Description = The previous system shutdown at 13:20:30 on ?15.?12.?2012 was unexpected.

Error - 15.12.2012 8:22:38 | Computer Name = Ales-THINK | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 15.12.2012 14:11:15 | Computer Name = Ales-THINK | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.


< End of report >

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#6 Příspěvek od alash »

OTL logfile created on: 15.12.2012 21:15:58 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ales\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Czech Republic | Language: CSY | Date Format: d.M.yyyy

3,92 Gb Total Physical Memory | 1,54 Gb Available Physical Memory | 39,42% Memory free
7,83 Gb Paging File | 5,11 Gb Available in Paging File | 65,23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 281,00 Gb Total Space | 146,57 Gb Free Space | 52,16% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 13,03 Gb Free Space | 2,80% Space Free | Partition Type: FAT32
Drive Q: | 15,62 Gb Total Space | 5,79 Gb Free Space | 37,09% Space Free | Partition Type: NTFS

Computer Name: ALES-THINK | User Name: Ales | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.12.14 20:54:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ales\Desktop\OTL.exe
PRC - [2012.12.09 20:49:05 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.11.19 22:48:46 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.10.08 16:15:50 | 000,039,808 | ---- | M] (Wacom Technology) -- C:\Program Files\Tablet\Wacom\WacomHost.exe
PRC - [2012.07.27 21:51:38 | 000,823,224 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012.07.27 12:51:28 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.05.02 05:30:00 | 000,128,576 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
PRC - [2011.12.09 18:23:30 | 001,596,032 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winamp.exe
PRC - [2011.07.26 08:18:46 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe
PRC - [2011.07.12 08:53:20 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2011.05.31 19:48:36 | 000,059,240 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2011.02.24 09:10:24 | 000,212,944 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
PRC - [2011.02.22 04:19:12 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011.02.22 04:19:08 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011.01.07 04:28:42 | 000,446,592 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\SysWOW64\SASrv.exe


========== Modules (No Company Name) ==========

MOD - [2012.12.09 20:49:04 | 002,397,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.11.19 22:48:45 | 014,586,808 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll
MOD - [2012.09.24 15:27:06 | 000,014,320 | ---- | M] () -- C:\Program Files (x86)\Java\jre6\bin\jp2native.dll
MOD - [2012.02.27 21:30:15 | 000,047,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\zlib.dll
MOD - [2012.02.27 21:30:14 | 000,623,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jnetlib.w5s
MOD - [2012.02.27 21:30:14 | 000,174,080 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\auth.w5s
MOD - [2012.02.27 21:30:14 | 000,154,624 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jpeg.w5s
MOD - [2012.02.27 21:30:14 | 000,103,936 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\png.w5s
MOD - [2012.02.27 21:30:14 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\xml.w5s
MOD - [2012.02.27 21:30:14 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\playlist.w5s
MOD - [2012.02.27 21:30:14 | 000,083,968 | ---- | M] () -- C:\Program Files (x86)\Winamp\tataki.dll
MOD - [2012.02.27 21:30:14 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\devices.w5s
MOD - [2012.02.27 21:30:14 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\timer.w5s
MOD - [2012.02.27 21:30:14 | 000,023,040 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\albumart.w5s
MOD - [2012.02.27 21:30:14 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\tagz.w5s
MOD - [2012.02.27 21:30:14 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gif.w5s
MOD - [2012.02.27 21:30:14 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\bmp.w5s
MOD - [2012.02.27 21:30:14 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\dlmgr.w5s
MOD - [2012.02.27 21:30:14 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gracenote.w5s
MOD - [2012.02.27 21:30:14 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\filereader.w5s
MOD - [2012.02.27 21:30:14 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\primo.w5s
MOD - [2012.02.27 21:30:13 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
MOD - [2012.02.27 21:30:13 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll
MOD - [2012.02.27 21:30:13 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll
MOD - [2012.02.27 21:30:13 | 000,113,664 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll
MOD - [2012.02.27 21:30:13 | 000,083,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_plg.dll
MOD - [2012.02.27 21:30:13 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_android.dll
MOD - [2012.02.27 21:30:13 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll
MOD - [2012.02.27 21:30:13 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
MOD - [2012.02.27 21:30:13 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll
MOD - [2012.02.27 21:30:13 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll
MOD - [2012.02.27 21:30:13 | 000,022,528 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
MOD - [2012.02.27 21:30:13 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll
MOD - [2012.02.27 21:30:13 | 000,018,432 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
MOD - [2012.02.27 21:30:12 | 000,294,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_local.dll
MOD - [2012.02.27 21:30:12 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll
MOD - [2012.02.27 21:30:12 | 000,200,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll
MOD - [2012.02.27 21:30:12 | 000,124,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_online.dll
MOD - [2012.02.27 21:30:12 | 000,082,944 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll
MOD - [2012.02.27 21:30:12 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll
MOD - [2012.02.27 21:30:12 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_history.dll
MOD - [2012.02.27 21:30:12 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll
MOD - [2012.02.27 21:30:12 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll
MOD - [2012.02.27 21:30:11 | 000,318,464 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
MOD - [2012.02.27 21:30:11 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
MOD - [2012.02.27 21:30:11 | 000,290,304 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
MOD - [2012.02.27 21:30:11 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
MOD - [2012.02.27 21:30:11 | 000,185,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
MOD - [2012.02.27 21:30:11 | 000,165,376 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
MOD - [2012.02.27 21:30:11 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
MOD - [2012.02.27 21:30:11 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
MOD - [2012.02.27 21:30:11 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
MOD - [2012.02.27 21:30:11 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
MOD - [2012.02.27 21:30:11 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
MOD - [2012.02.27 21:30:11 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
MOD - [2012.02.27 21:30:11 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_orgler.dll
MOD - [2012.02.27 21:30:11 | 000,052,736 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
MOD - [2012.02.27 21:30:11 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
MOD - [2012.02.27 21:30:11 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
MOD - [2012.02.27 21:30:11 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
MOD - [2012.02.27 21:30:11 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
MOD - [2012.02.27 21:30:11 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
MOD - [2012.02.27 21:30:11 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
MOD - [2012.02.27 21:30:10 | 001,737,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
MOD - [2012.02.27 21:30:10 | 000,027,648 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
MOD - [2012.02.27 21:30:09 | 000,417,280 | ---- | M] () -- C:\Program Files (x86)\Winamp\nsutil.dll
MOD - [2012.02.27 21:30:09 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\libsndfile.dll
MOD - [2012.02.27 21:30:09 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Winamp\nde.dll
MOD - [2010.01.21 01:34:10 | 008,793,952 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010.01.09 20:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF


========== Services (SafeList) ==========

SRV:64bit: - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2012.10.29 08:14:18 | 000,613,760 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Wacom\WTabletServicePro.exe -- (WTabletServicePro)
SRV:64bit: - [2011.09.08 16:48:36 | 006,583,160 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2011.09.08 16:48:36 | 000,528,760 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV:64bit: - [2011.08.11 03:20:42 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:64bit: - [2011.07.28 06:04:48 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.07.28 05:48:34 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.07.28 05:44:18 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.07.12 08:54:00 | 000,133,992 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:64bit: - [2011.07.12 08:53:42 | 000,145,256 | ---- | M] (Lenovo Group Limited) [Disabled | Stopped] -- C:\Program Files\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV:64bit: - [2011.07.12 08:53:26 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Disabled | Stopped] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV:64bit: - [2011.07.12 08:53:20 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV:64bit: - [2011.07.09 02:53:20 | 000,144,232 | ---- | M] (Lenovo Group Limited) [Disabled | Stopped] -- C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe -- (HyperW7Svc)
SRV:64bit: - [2011.05.31 19:48:36 | 000,059,240 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV:64bit: - [2011.05.31 19:48:18 | 000,041,320 | ---- | M] (Lenovo Group Limited) [Disabled | Stopped] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV:64bit: - [2011.03.25 01:42:48 | 000,968,480 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2011.01.13 23:05:46 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:64bit: - [2010.12.16 23:18:08 | 000,198,784 | ---- | M] (Conexant Systems Inc.) [Auto | Running] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg)
SRV:64bit: - [2010.09.23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.12.09 20:49:04 | 000,115,168 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.11.19 22:48:46 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.27 12:51:28 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.05.03 17:37:54 | 001,226,096 | ---- | M] (Lavasoft Limited) [Disabled | Stopped] -- C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe -- (Ad-Aware Service)
SRV - [2012.05.02 05:30:00 | 001,665,088 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc)
SRV - [2012.05.02 05:30:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2011.12.19 12:20:06 | 003,289,032 | ---- | M] (GFI Software) [Disabled | Stopped] -- C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe -- (SBAMSvc)
SRV - [2011.09.02 04:27:08 | 000,446,800 | ---- | M] (Lenovo Group Limited) [Disabled | Stopped] -- C:\Program Files (x86)\Lenovo\Screen Reading Optimizer\SROSVC.exe -- (SROSVC)
SRV - [2011.07.26 08:18:46 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2011.03.07 15:43:30 | 002,375,168 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011.02.24 09:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service)
SRV - [2011.02.22 04:19:12 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011.02.22 04:19:08 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011.01.07 04:28:42 | 000,446,592 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\SASrv.exe -- (SAService)
SRV - [2010.03.18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Disabled | Stopped] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.10.30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.10.15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.10.12 09:54:54 | 000,015,776 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys -- (wacomrouterfilter)
DRV:64bit: - [2012.10.12 09:20:38 | 000,081,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wachidrouter.sys -- (WacHidRouter)
DRV:64bit: - [2012.10.12 09:20:38 | 000,013,728 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidkmdf.sys -- (hidkmdf)
DRV:64bit: - [2012.09.01 11:11:29 | 000,564,792 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2012.05.02 05:30:00 | 000,019,784 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.28 00:51:01 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.02.02 11:15:08 | 000,040,248 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:64bit: - [2012.02.02 10:49:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012.02.02 10:49:41 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.12.19 11:44:24 | 000,256,632 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SbFw.sys -- (SbFw)
DRV:64bit: - [2011.12.19 11:44:24 | 000,084,600 | ---- | M] (GFI Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbwtis.sys -- (sbwtis)
DRV:64bit: - [2011.12.19 11:44:24 | 000,060,536 | ---- | M] (GFI Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbhips.sys -- (sbhips)
DRV:64bit: - [2011.11.29 05:59:46 | 000,074,872 | ---- | M] (GFI Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\sbapifs.sys -- (sbapifs)
DRV:64bit: - [2011.10.26 13:23:36 | 000,057,976 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\sbredrv.sys -- (SBRE)
DRV:64bit: - [2011.09.29 11:16:18 | 000,119,416 | ---- | M] (GFI Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SbFwIm.sys -- (SBFWIMCLMP)
DRV:64bit: - [2011.09.29 11:16:18 | 000,119,416 | ---- | M] (GFI Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SbFwIm.sys -- (SBFWIMCL)
DRV:64bit: - [2011.09.08 16:49:36 | 000,013,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2011.09.08 16:49:26 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2011.09.08 16:49:24 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2011.08.17 08:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2011.08.11 03:20:42 | 000,039,024 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:64bit: - [2011.08.09 15:32:04 | 012,289,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.08.04 02:28:32 | 008,604,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.07.09 02:53:24 | 000,032,104 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Program Files\Lenovo\RapidBoot\PHCORE64.sys -- (PHCORE)
DRV:64bit: - [2011.06.22 00:19:14 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.06.22 00:19:12 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.05.19 13:06:46 | 001,442,352 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011.05.04 15:44:00 | 000,338,536 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2011.04.26 03:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.03.24 07:36:20 | 001,576,064 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2011.03.23 02:20:58 | 000,077,936 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011.03.16 02:29:40 | 000,436,776 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011.03.05 03:18:42 | 000,166,016 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\5U877.sys -- (5U877)
DRV:64bit: - [2011.03.03 07:35:46 | 000,150,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011.02.25 07:11:04 | 000,163,880 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011.02.25 07:11:02 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2011.02.22 15:51:08 | 000,039,976 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011.01.13 23:04:20 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:64bit: - [2011.01.13 23:02:28 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 04:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.19 08:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.15 08:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.07 06:09:36 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:64bit: - [2009.09.24 12:58:38 | 000,041,536 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tvti2c.sys -- (TVTI2C)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 00:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009.07.09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2011.10.26 13:23:40 | 000,101,112 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\SBREDrv.sys -- (SBRE)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENP
IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?sourceid=i ... NP_enCZ473
IE - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0035-ABCDEFFEDCBA%7D:6.0.35
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.2: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.2: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.10.11 01:25:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012.02.29 02:44:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.11.08 10:45:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.09 20:49:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.11 01:25:23 | 000,000,000 | ---D | M]

[2012.02.27 21:02:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ales\AppData\Roaming\Mozilla\Extensions
[2012.11.23 23:39:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ales\AppData\Roaming\Mozilla\Firefox\Profiles\lmi24xdz.default\extensions
[2012.11.23 23:39:07 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Ales\AppData\Roaming\Mozilla\Firefox\Profiles\lmi24xdz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.11.13 01:20:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.07.27 19:45:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.10.11 01:27:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.11.13 01:20:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.12.09 20:49:05 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.12.09 18:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.09.14 09:02:23 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.11.01 20:11:47 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/ig/redirectdomain ... &bmod=LENP
CHR - Extension: Norton Identity Protection = C:\Users\Ales\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\

O1 HOSTS File: ([2012.03.02 02:34:26 | 000,001,451 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip4.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 practivate.adobe
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.newoa
O1 - Hosts: 127.0.0.1 practivate.adobe.ntp
O1 - Hosts: 127.0.0.1 practivate.adobe.ipp
O1 - Hosts: 23 more lines...
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe (Lenovo, Inc.)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.113.44.11 195.113.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{26016041-6506-4761-8950-F07C4960AD53}: DhcpNameServer = 195.113.44.11 195.113.0.2
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 17:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{9ba28746-4d83-11e1-a8ca-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9ba28746-4d83-11e1-a8ca-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009.08.10 22:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2012.12.14 20:54:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ales\Desktop\OTL.exe
[2012.11.19 22:42:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
[2012.11.19 22:42:03 | 000,000,000 | ---D | C] -- C:\Program Files\TabletPlugins
[2012.11.19 22:42:00 | 000,015,776 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys
[2012.11.19 22:41:54 | 000,013,728 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\hidkmdf.sys
[2012.11.19 22:41:53 | 000,081,312 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wachidrouter.sys
[2012.11.19 22:41:52 | 001,981,312 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wacom_Tablet.dll
[2012.11.19 22:41:52 | 001,974,144 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wacom_Touch_Tablet.dll
[2012.11.19 22:41:52 | 001,628,032 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wacom_Tablet.dll
[2012.11.19 22:41:52 | 001,621,376 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll
[2012.11.19 22:26:37 | 000,000,000 | ---D | C] -- C:\Users\Ales\Desktop\wacom intuos tablet driver

========== Files - Modified Within 30 Days ==========

[2012.12.15 21:18:19 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.12.15 21:06:00 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.12.15 21:03:18 | 000,778,730 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.12.15 21:03:18 | 000,652,102 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.12.15 21:03:18 | 000,121,034 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.12.15 20:43:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.12.15 13:29:45 | 000,031,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.12.15 13:29:45 | 000,031,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.12.15 13:22:18 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.12.15 13:22:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.12.15 13:22:06 | 3153,571,840 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.14 20:54:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ales\Desktop\OTL.exe
[2012.12.13 01:13:11 | 000,693,524 | ---- | M] () -- C:\Users\Ales\Desktop\darovadlo Receptář.pdf
[2012.11.29 19:29:10 | 001,333,168 | ---- | M] () -- C:\Users\Ales\Desktop\sazebnik kb - platby za prevody na strane 25.pdf
[2012.11.29 13:05:25 | 519,083,376 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.11.22 20:32:52 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.19 22:48:46 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.11.19 22:48:46 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.11.19 22:41:57 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_wachidrouter_01009.Wdf
[2012.11.18 23:39:40 | 000,007,729 | ---- | M] () -- C:\Users\Ales\AppData\Roaming\.ptbt0
[2012.11.18 21:48:33 | 023,497,845 | ---- | M] () -- C:\Users\Ales\Desktop\D7000_ENnoprint.pdf

========== Files Created - No Company Name ==========

[2012.12.14 20:58:06 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.13 01:13:11 | 000,693,524 | ---- | C] () -- C:\Users\Ales\Desktop\darovadlo Receptář.pdf
[2012.11.29 19:29:10 | 001,333,168 | ---- | C] () -- C:\Users\Ales\Desktop\sazebnik kb - platby za prevody na strane 25.pdf
[2012.11.19 22:41:57 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_wachidrouter_01009.Wdf
[2012.11.18 23:39:40 | 000,007,729 | ---- | C] () -- C:\Users\Ales\AppData\Roaming\.ptbt0
[2012.11.18 21:48:31 | 023,497,845 | ---- | C] () -- C:\Users\Ales\Desktop\D7000_ENnoprint.pdf
[2012.03.01 03:23:47 | 000,001,456 | ---- | C] () -- C:\Users\Ales\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.03.01 01:27:26 | 000,002,773 | ---- | C] () -- C:\Users\Ales\AppData\Roaming\SerialClonerPrefs
[2012.02.02 11:11:29 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012.02.02 11:11:29 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.02.02 11:11:28 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.02.02 11:11:27 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2012.02.02 11:11:26 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012.02.02 11:04:59 | 001,554,650 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.02 10:36:14 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll

========== ZeroAccess Check ==========

[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012.07.17 23:05:01 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus
[2012.02.29 03:50:16 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.02.29 02:51:09 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\com.adobe.dmp.contentviewer
[2012.02.28 22:10:25 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.02.28 00:53:07 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\DAEMON Tools Lite
[2012.06.25 08:30:40 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\DC++
[2012.06.14 21:50:02 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\GARMIN
[2012.02.27 21:43:09 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\IrfanView
[2012.02.25 18:20:49 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Leadertech
[2012.02.25 18:51:42 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Lenovo
[2012.02.29 04:09:58 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PACE Anti-Piracy
[2012.09.20 22:10:41 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PCDr
[2012.02.27 20:52:30 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PwrMgr
[2012.03.01 04:01:35 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\SerialCloner
[2012.02.29 04:11:48 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.05.25 23:45:53 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,022,070 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.02.02 11:16:22 | 000,000,962 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.02.02 11:16:22 | 000,000,966 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.06.25 23:09:21 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010.11.21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2010.11.21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2012.02.02 10:45:11 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2012.02.02 10:45:11 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2012.02.02 10:45:11 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2012.02.02 10:45:11 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2012.02.02 10:45:11 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2012.02.02 10:45:11 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: HAL.DLL >
[2010.11.21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll

< MD5 for: SCECLI.DLL >
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2011.09.29 18:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.21 04:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.03.30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2012.02.02 10:44:14 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2012.02.02 10:47:55 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
[2012.03.30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.03.30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2012.02.02 10:44:14 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2012.02.02 10:47:55 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
[2011.09.29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< >

< %systemroot%*.* /U /s >
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[4 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[42 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.07.17 23:05:01 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus
[2012.10.07 14:42:57 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Adobe
[2012.03.23 00:59:12 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Apple Computer
[2012.02.29 03:50:16 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.02.29 02:51:09 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\com.adobe.dmp.contentviewer
[2012.02.28 22:10:25 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.05.13 00:36:46 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Corel
[2012.02.28 00:53:07 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\DAEMON Tools Lite
[2012.06.25 08:30:40 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\DC++
[2012.06.14 21:50:02 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\GARMIN
[2012.02.28 23:20:56 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Google
[2012.03.02 03:44:48 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\GRETECH
[2012.02.25 18:20:11 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Identities
[2012.02.25 18:17:14 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Intel
[2012.02.27 21:43:09 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\IrfanView
[2012.02.25 18:20:49 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Leadertech
[2012.02.25 18:51:42 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Lenovo
[2012.02.27 22:18:16 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Macromedia
[2012.09.20 22:54:47 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Malwarebytes
[2010.11.21 08:16:41 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Media Center Programs
[2012.05.22 19:07:45 | 000,000,000 | --SD | M] -- C:\Users\Ales\AppData\Roaming\Microsoft
[2012.02.27 21:02:07 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Mozilla
[2012.02.29 04:09:58 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PACE Anti-Piracy
[2012.09.20 22:10:41 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PCDr
[2012.02.27 20:52:30 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\PwrMgr
[2012.03.01 04:01:35 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\SerialCloner
[2012.02.29 04:11:48 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.05.25 23:45:53 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\uTorrent
[2012.02.27 21:44:23 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\Winamp
[2012.11.19 22:42:20 | 000,000,000 | ---D | M] -- C:\Users\Ales\AppData\Roaming\WTablet

< %APPDATA%\*.exe /s >
[2007.03.22 11:46:42 | 000,126,976 | ---- | M] () -- C:\Users\Ales\AppData\Roaming\GRETECH\GomPlayer\GrLauncher.exe
[2012.02.28 22:09:48 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Ales\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.02.29 02:16:29 | 000,010,134 | R--- | M] () -- C:\Users\Ales\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2012.05.28 22:20:54 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Ales\AppData\Roaming\Microsoft\Installer\{0369F866-2CE0-4EB9-B426-88FA122C6E82}\ARPPRODUCTICON.exe
[2012.05.28 22:20:51 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Ales\AppData\Roaming\Microsoft\Installer\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}\ARPPRODUCTICON.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2012.12.15 20:43:00 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.12.15 13:22:18 | 000,000,962 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.12.15 21:06:00 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.12.15 13:24:41 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#7 Příspěvek od alash »

pokracovani predchoziho logu:


< %SYSTEMDRIVE%\*.exe >

< >

< *crack* /s >
[2007.08.19 19:53:30 | 000,001,622 | ---- | M] () -- \_data\programy\chemoffice\crack\crack.reg
[2007.08.19 19:55:28 | 000,000,877 | ---- | M] () -- \_data\programy\chemoffice\crack\crack.txt
[2011.03.22 18:00:32 | 000,003,556 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\Content\Reference\PHP\CrackF.html
[2011.03.30 08:55:56 | 000,004,254 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.thermo.core_1.5.0.308731\com\adobe\thermo\undo\ThermoUndoSystem$UndoableDocumentChangeCracker.class
[2005.03.08 10:30:56 | 000,092,827 | ---- | M] () -- \Program Files (x86)\Corel\CorelDRAW Graphics Suite X5\Custom Data\Bumpmap\Cracks.cpt
[2008.07.14 09:02:56 | 000,017,870 | ---- | M] () -- \Program Files (x86)\Corel\CorelDRAW Graphics Suite X5\Custom Data\Canvas\cracks2c.bmp
[2011.03.03 18:42:04 | 001,159,409 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS5.5\Support Files\Presets\Image - Special Effects\Cracked Tiles.ffx
[2011.03.23 19:03:20 | 000,823,680 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\Plug-ins\en_US\VSTPlugins\DeCrackler1.dll
[2011.03.23 19:03:22 | 000,823,680 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\Plug-ins\en_US\VSTPlugins\DeCrackler2.dll
[2011.03.23 19:03:26 | 000,823,680 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\Plug-ins\en_US\VSTPlugins\DeCrackler6.dll

< *keygen* /s >
[2011.03.22 18:00:30 | 000,013,367 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\Content\Reference\HTML\KEYGEN.html
[2011.03.22 18:01:00 | 000,009,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\TagLibraries\HTML\keygen.vtm
[2011.03.19 00:31:00 | 000,003,248 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIKeygenThread.idl
[2011.03.19 00:31:30 | 000,004,618 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIKeygenThread.h
[2012.04.22 20:53:16 | 570,596,832 | ---- | M] () -- \Users\Ales\Downloads\CorelDRAW-Graphics-Suite-X5-CZ+keygen.rar
[2012.08.03 01:10:58 | 028,403,199 | ---- | M] () -- \Users\Ales\Downloads\noise-ninja-2-3-7-keygen-profiles-igalerie-cz.rar
[2011.12.03 12:24:38 | 000,219,606 | ---- | M] () -- \Users\Ales\Downloads\CorelDRAW Graphics Suite X5 CZ+keygen\Corel Keygen.rar
[2007.10.12 10:29:30 | 000,135,168 | ---- | M] () -- \Users\Ales\Downloads\Noise Ninja 2.3.7\KeyMaker-SSG\keygen.exe

< *loader* /s >
[2012.07.27 12:51:44 | 000,012,278 | ---- | M] () -- \Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\WebPublish\BootStrapLoader.swf
[2011.03.02 21:35:42 | 005,299,048 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\Photodownloader.exe
[2011.03.02 18:57:10 | 000,011,161 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2011.03.02 18:57:10 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2011.03.02 18:57:10 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\de_de\Photodownloader.ini
[2011.03.02 18:57:10 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\en_us\Photodownloader.ini
[2011.03.02 18:57:10 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\es_es\Photodownloader.ini
[2011.03.02 18:57:10 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\it_it\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\no_no\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2011.03.02 18:57:12 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2011.03.02 18:57:14 | 000,000,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2011.03.02 18:57:14 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5.1\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2011.03.19 00:34:52 | 000,004,426 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Contribute CS5.1\App\Configuration\Content\CCWelcome\Assets\dynswfloader.swf
[2011.03.19 00:32:32 | 000,037,112 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Contribute CS5.1\App\Configuration\Shared\MM\Media\FLVLoader.swf
[2011.03.22 18:01:00 | 000,037,112 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\Shared\MM\Media\FLVLoader.swf
[2011.03.22 18:01:02 | 000,000,503 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\Third Party Source Code\jquery-mobile\images\ajax-loader.png
[2011.03.22 18:01:12 | 000,007,931 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\demo\jvmti\hprof\src\hprof_loader.c
[2011.03.22 18:01:12 | 000,002,188 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\demo\jvmti\hprof\src\hprof_loader.h
[2011.03.22 18:01:36 | 000,003,005 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2011.03.22 18:01:36 | 000,000,420 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2011.03.22 18:01:36 | 001,138,236 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\modules\org-openide-loaders.jar
[2011.03.22 18:01:36 | 000,007,002 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2011.03.22 18:01:36 | 000,006,658 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2011.03.22 18:01:36 | 000,000,464 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2011.03.18 18:08:46 | 000,082,592 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\MXF_SDK_MetaMetadata_BinaryLoader_4.3.4.dll
[2011.03.18 18:08:48 | 000,148,640 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\MXF_SDK_MetaMetadata_XSDLoader2_4.3.4.dll
[2011.03.18 18:08:48 | 000,115,360 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\MXF_SDK_MetaMetadata_XSDLoader_4.3.4.dll
[2011.03.14 18:50:30 | 000,061,190 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS5.1\Configuration\Common Library\Animations\Loader01.animation.png
[2011.03.14 18:50:30 | 000,312,906 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS5.1\Configuration\Common Library\Animations\Loader02.animation.png
[2011.03.14 18:50:30 | 000,119,812 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS5.1\Configuration\Common Library\Animations\Loader03.animation.png
[2011.03.14 18:50:30 | 000,237,114 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS5.1\Configuration\Common Library\Animations\Loader04.animation.png
[2011.04.04 09:13:40 | 000,000,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.5.0.308971\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinder.class
[2011.04.04 09:13:40 | 000,000,791 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.5.0.308971\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinderConcrete.class
[2011.04.04 09:14:30 | 000,001,648 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2011.04.04 09:14:22 | 000,005,941 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2011.04.04 09:14:38 | 000,007,791 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2011.04.04 09:14:32 | 000,007,394 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\airframework\src\mx\core\FlexHTMLLoader.as
[2011.04.04 09:14:02 | 000,008,429 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\automation\src\mx\automation\delegates\controls\SWFLoaderAutomationImpl.as
[2011.04.04 09:14:22 | 000,077,955 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.as
[2011.04.04 09:14:12 | 000,000,766 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.png
[2011.04.04 09:14:30 | 000,003,290 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\core\FlexLoader.as
[2011.04.04 09:14:10 | 000,002,622 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\core\ISWFLoader.as
[2011.04.04 09:14:28 | 000,005,562 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\core\MovieClipLoaderAsset.as
[2011.04.04 09:14:26 | 000,006,952 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\core\RSLListLoader.as
[2011.04.04 09:14:42 | 000,002,617 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\messaging\config\LoaderConfig.as
[2011.04.04 09:14:30 | 000,011,048 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\modules\ModuleLoader.as
[2011.04.04 09:14:08 | 000,003,534 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\preloaders\IPreloaderDisplay.as
[2011.04.04 09:14:30 | 000,012,861 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\preloaders\Preloader.as
[2011.04.04 09:14:38 | 000,007,131 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\utils\LoaderUtil.as
[2011.04.04 09:14:28 | 000,009,328 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\wsdl\WSDLLoader.as
[2011.04.04 09:14:28 | 000,008,335 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\xml\SchemaLoader.as
[2011.04.04 09:14:22 | 000,003,482 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\xml\XMLLoader.as
[2011.04.04 09:17:04 | 000,001,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2011.04.04 09:16:20 | 000,006,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2011.04.04 09:16:08 | 000,010,340 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2011.04.04 09:16:18 | 000,012,418 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\airframework\src\mx\core\FlexHTMLLoader.as
[2011.04.04 09:14:48 | 000,009,014 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\automation\src\mx\automation\delegates\controls\SWFLoaderAutomationImpl.as
[2011.04.04 09:16:26 | 000,010,767 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\MovieClipSWFLoader.as
[2011.04.04 09:15:40 | 000,087,759 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\SWFLoader.as
[2011.04.04 09:15:50 | 000,000,766 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\SWFLoader.png
[2011.04.04 09:15:26 | 000,003,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\FlexLoader.as
[2011.04.04 09:17:04 | 000,003,066 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\ISWFLoader.as
[2011.04.04 09:16:36 | 000,006,534 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\MovieClipLoaderAsset.as
[2011.04.04 09:16:26 | 000,008,136 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\RSLListLoader.as
[2011.04.04 09:16:42 | 000,003,886 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\messaging\config\LoaderConfig.as
[2011.04.04 09:15:04 | 000,004,842 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\preloaders\IPreloaderDisplay.as
[2011.04.04 09:14:58 | 000,020,403 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\preloaders\Preloader.as
[2011.04.04 09:15:32 | 000,024,312 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\utils\LoaderUtil.as
[2011.04.04 09:15:14 | 000,014,952 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.as
[2011.04.04 09:17:04 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.png
[2011.04.04 09:15:14 | 000,008,511 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\F4MLoader.as
[2011.04.04 09:16:32 | 000,004,465 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\ImageLoader.as
[2011.04.04 09:16:56 | 000,008,773 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SoundLoader.as
[2011.04.04 09:14:50 | 000,005,733 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SWFLoader.as
[2011.04.04 09:16:20 | 000,007,015 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoader.as
[2011.04.04 09:14:48 | 000,002,829 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoaderEvent.as
[2011.04.04 09:15:12 | 000,002,361 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderLoadTrait.as
[2011.04.04 09:16:02 | 000,009,822 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderUtils.as
[2011.04.04 09:15:34 | 000,004,197 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\events\LoaderEvent.as
[2011.04.04 09:14:58 | 000,005,201 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\DynamicPluginLoader.as
[2011.04.04 09:15:46 | 000,007,943 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\PluginLoader.as
[2011.04.04 09:16:50 | 000,002,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\StaticPluginLoader.as
[2011.04.04 09:16:14 | 000,014,266 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\NetLoader.as
[2011.04.04 09:15:50 | 000,003,370 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\dvr\DVRCastNetLoader.as
[2011.04.04 09:14:52 | 000,005,866 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\httpstreaming\HTTPStreamingNetLoader.as
[2011.04.04 09:15:00 | 000,004,594 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\rtmpstreaming\RTMPDynamicStreamingNetLoader.as
[2011.04.04 09:16:18 | 000,008,881 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\traits\LoaderBase.as
[2011.04.04 09:16:28 | 000,006,698 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\utils\HTTPLoader.as
[2011.04.04 09:16:14 | 000,010,133 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\wsdl\WSDLLoader.as
[2011.04.04 09:16:18 | 000,008,711 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\xml\SchemaLoader.as
[2011.04.04 09:16:38 | 000,004,005 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\xml\XMLLoader.as
[2011.04.04 09:16:00 | 000,001,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\spark\src\spark\core\IContentLoader.as
[2011.04.04 09:15:20 | 000,004,271 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\spark\src\spark\events\LoaderInvalidationEvent.as
[2011.04.04 09:15:26 | 000,021,014 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.as
[2011.04.04 09:16:44 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.png
[2011.04.04 09:15:40 | 000,001,841 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\samples\themes\cobalt\src\assets\SWFLoader_brokenImageSkin.png
[2011.03.30 08:55:50 | 000,000,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flash.codemodel.osgi_1.5.0.308731\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinder.class
[2011.03.30 08:55:50 | 000,000,791 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flash.codemodel.osgi_1.5.0.308731\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinderConcrete.class
[2011.03.30 09:06:20 | 000,253,048 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexide.nativelibs_1.5.0.308731\libs\MFILoaderLibrary_v3.dll
[2011.03.30 09:02:36 | 000,001,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2011.03.30 09:02:10 | 000,006,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2011.03.30 09:02:20 | 000,010,340 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2011.03.30 09:01:52 | 000,012,418 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\airframework\src\mx\core\FlexHTMLLoader.as
[2011.03.30 09:00:56 | 000,009,014 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\automation\src\mx\automation\delegates\controls\SWFLoaderAutomationImpl.as
[2011.03.30 09:01:42 | 000,010,767 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\MovieClipSWFLoader.as
[2011.03.30 09:00:12 | 000,087,759 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\SWFLoader.as
[2011.03.30 09:02:06 | 000,000,766 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\controls\SWFLoader.png
[2011.03.30 09:00:44 | 000,003,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\FlexLoader.as
[2011.03.30 09:02:08 | 000,003,066 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\ISWFLoader.as
[2011.03.30 09:02:28 | 000,006,534 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\MovieClipLoaderAsset.as
[2011.03.30 09:01:40 | 000,008,136 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\core\RSLListLoader.as
[2011.03.30 09:01:04 | 000,003,886 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\messaging\config\LoaderConfig.as
[2011.03.30 09:02:10 | 000,004,842 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\preloaders\IPreloaderDisplay.as
[2011.03.30 09:00:44 | 000,020,403 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\preloaders\Preloader.as
[2011.03.30 09:00:20 | 000,024,312 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\utils\LoaderUtil.as
[2011.03.30 09:01:42 | 000,014,952 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.as
[2011.03.30 09:01:20 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.png
[2011.03.30 09:01:00 | 000,008,511 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\F4MLoader.as
[2011.03.30 09:01:54 | 000,004,465 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\ImageLoader.as
[2011.03.30 09:02:24 | 000,008,773 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SoundLoader.as
[2011.03.30 09:00:14 | 000,005,733 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SWFLoader.as
[2011.03.30 09:00:20 | 000,007,015 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoader.as
[2011.03.30 09:00:34 | 000,002,829 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoaderEvent.as
[2011.03.30 09:01:34 | 000,002,361 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderLoadTrait.as
[2011.03.30 09:01:32 | 000,009,822 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderUtils.as
[2011.03.30 09:00:12 | 000,004,197 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\events\LoaderEvent.as
[2011.03.30 09:02:36 | 000,005,201 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\DynamicPluginLoader.as
[2011.03.30 09:01:08 | 000,007,943 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\PluginLoader.as
[2011.03.30 09:00:22 | 000,002,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\StaticPluginLoader.as
[2011.03.30 09:01:44 | 000,014,266 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\NetLoader.as
[2011.03.30 09:01:18 | 000,003,370 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\dvr\DVRCastNetLoader.as
[2011.03.30 09:00:34 | 000,005,866 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\httpstreaming\HTTPStreamingNetLoader.as
[2011.03.30 09:00:54 | 000,004,594 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\net\rtmpstreaming\RTMPDynamicStreamingNetLoader.as
[2011.03.30 09:01:28 | 000,008,881 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\traits\LoaderBase.as
[2011.03.30 09:01:46 | 000,006,698 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\utils\HTTPLoader.as
[2011.03.30 09:02:08 | 000,010,133 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\wsdl\WSDLLoader.as
[2011.03.30 09:00:48 | 000,008,711 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\xml\SchemaLoader.as
[2011.03.30 09:00:48 | 000,004,005 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\xml\XMLLoader.as
[2011.03.30 09:02:10 | 000,001,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\spark\src\spark\core\IContentLoader.as
[2011.03.30 09:01:50 | 000,004,271 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\spark\src\spark\events\LoaderInvalidationEvent.as
[2011.03.30 09:00:44 | 000,021,014 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.as
[2011.03.30 09:01:04 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.png
[2011.03.30 09:00:44 | 000,001,841 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\samples\themes\cobalt\src\assets\SWFLoader_brokenImageSkin.png
[2011.03.11 13:07:20 | 000,001,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\AIR2.6\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2011.03.11 13:07:18 | 000,006,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\AIR2.6\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2011.03.11 13:07:18 | 000,010,340 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\AIR2.6\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2011.03.17 08:29:56 | 000,043,414 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\display\ProLoader.as
[2011.03.17 08:29:56 | 000,022,438 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\display\ProLoaderInfo.as
[2011.03.17 08:29:56 | 000,000,951 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\events\ProLoaderRSLPreloaderSandboxEvent.as
[2011.03.17 08:29:56 | 000,018,626 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\rsl\RSLPreloader.as
[2011.03.17 08:29:56 | 000,010,604 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\rsls\loader_animation.fla
[2011.03.17 08:29:56 | 000,001,253 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\ActionScript 3.0\rsls\loader_animation.swf
[2011.03.17 08:29:58 | 000,027,163 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\Component Source\ActionScript 3.0\User Interface\fl\containers\UILoader.as
[2011.03.17 08:30:00 | 000,044,966 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\Configuration\Components\User Interface\Loader.swc
[2011.03.17 08:30:06 | 000,000,544 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\FP7\MovieClipLoader.as
[2011.03.17 08:30:06 | 000,000,544 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\FP8\MovieClipLoader.as
[2011.03.17 08:30:06 | 000,000,576 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\FP9\MovieClipLoader.as
[2011.03.17 08:30:08 | 000,010,454 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\mx\controls\Loader.as
[2011.03.17 08:30:00 | 000,033,692 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\en_US\Configuration\Templates\Sample Files\Preloader for External File.fla
[2011.03.17 08:30:00 | 000,036,081 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\en_US\Configuration\Templates\Sample Files\Preloader for SWF.fla
[2011.03.10 22:49:30 | 000,003,754 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe InDesign CS5.5\Scripts\converturltohyperlink\startup scripts\ConvertURLToHyperlinkMenuItemLoader.jsx
[2011.03.18 06:06:00 | 000,301,976 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe OnLocation CS5.1\MXF_SDK_MetaMetadata_BinaryLoader_r.4.2.2.319.dll
[2010.12.20 14:06:02 | 000,011,916 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Photoshop CS5.1\Plug-ins\NoiseNinjaPlugin_Win64_2_4_2\doc\auto_loader.htm
[2011.03.19 00:30:46 | 000,009,728 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\TestStreamLoader.exe
[2011.03.19 00:30:48 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\components\uriloader.xpt
[2011.03.19 00:30:46 | 000,026,243 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\chrome\pageloader.jar
[2011.03.19 00:30:46 | 000,000,049 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\chrome\pageloader.manifest
[2011.03.19 00:30:52 | 000,005,128 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\imgILoader.idl
[2011.03.19 00:30:52 | 000,002,605 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\mozIJSSubScriptLoader.idl
[2011.03.19 00:30:52 | 000,003,317 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsCURILoader.idl
[2011.03.19 00:30:58 | 000,002,858 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDocumentLoader.idl
[2011.03.19 00:30:58 | 000,003,462 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDocumentLoaderFactory.idl
[2011.03.19 00:30:58 | 000,003,603 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDownloader.idl
[2011.03.19 00:31:00 | 000,003,715 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIFrameLoader.idl
[2011.03.19 00:31:00 | 000,002,777 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIModuleLoader.idl
[2011.03.19 00:31:02 | 000,003,452 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIScriptLoaderObserver.idl
[2011.03.19 00:31:04 | 000,004,284 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIStreamLoader.idl
[2011.03.19 00:31:06 | 000,005,092 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIUnicharStreamLoader.idl
[2011.03.19 00:31:04 | 000,007,667 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIURILoader.idl
[2011.03.19 00:31:06 | 000,003,926 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIXPTLoader.idl
[2011.03.19 00:31:06 | 000,004,183 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\xpcIJSModuleLoader.idl
[2011.03.19 00:31:10 | 000,009,035 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\imgILoader.h
[2011.03.19 00:31:16 | 000,003,070 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\mozIJSSubScriptLoader.h
[2011.03.19 00:31:18 | 000,001,749 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsCURILoader.h
[2011.03.19 00:31:20 | 000,010,911 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsDocLoader.h
[2011.03.19 00:31:22 | 000,013,419 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsICSSLoader.h
[2011.03.19 00:31:22 | 000,003,426 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsICSSLoaderObserver.h
[2011.03.19 00:31:28 | 000,004,904 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDocumentLoader.h
[2011.03.19 00:31:28 | 000,007,766 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDocumentLoaderFactory.h
[2011.03.19 00:31:28 | 000,006,884 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDownloader.h
[2011.03.19 00:31:28 | 000,008,783 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIFrameLoader.h
[2011.03.19 00:31:30 | 000,003,586 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIModuleLoader.h
[2011.03.19 00:31:34 | 000,005,474 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIScriptLoaderObserver.h
[2011.03.19 00:31:34 | 000,008,712 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIStreamLoader.h
[2011.03.19 00:31:36 | 000,011,248 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIUnicharStreamLoader.h
[2011.03.19 00:31:36 | 000,011,837 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIURILoader.h
[2011.03.19 00:31:36 | 000,007,515 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIXPTLoader.h
[2011.03.19 00:31:38 | 000,011,156 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsScriptLoader.h
[2011.03.19 00:31:38 | 000,004,155 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsURILoader.h
[2011.03.19 00:31:42 | 000,005,504 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\xpcIJSModuleLoader.h
[2008.07.30 09:06:58 | 000,072,192 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.dll
[2008.07.29 02:43:16 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.tlb
[2009.10.22 01:01:42 | 000,249,672 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2009.10.22 01:01:42 | 000,018,248 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2011.04.05 23:22:14 | 000,012,688 | ---- | M] () -- \Program Files (x86)\Corel\CorelDRAW Graphics Suite X5\Programs\ReflectionLoader.dll
[2011.03.23 05:36:20 | 000,105,984 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS5.5\Support Files\MXF_SDK_MetaMetadata_BinaryLoader_4.3.4.dll
[2011.03.23 05:36:20 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS5.5\Support Files\MXF_SDK_MetaMetadata_XSDLoader2_4.3.4.dll
[2011.03.23 05:36:20 | 000,144,896 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS5.5\Support Files\MXF_SDK_MetaMetadata_XSDLoader_4.3.4.dll
[2011.03.15 11:23:50 | 000,105,984 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5.5\MXF_SDK_MetaMetadata_BinaryLoader_4.3.4.dll
[2011.03.15 11:23:50 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5.5\MXF_SDK_MetaMetadata_XSDLoader2_4.3.4.dll
[2011.03.15 11:23:50 | 000,144,896 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5.5\MXF_SDK_MetaMetadata_XSDLoader_4.3.4.dll
[2010.12.20 14:06:02 | 000,011,916 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Plug-ins\NoiseNinjaPlugin_Win64_2_4_2\doc\auto_loader.htm
[2012.02.22 23:58:36 | 000,078,336 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012.02.22 23:58:36 | 000,155,136 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012.02.22 23:58:36 | 000,117,248 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 4\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2011.03.23 14:50:20 | 000,105,984 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\MXF_SDK_MetaMetadata_BinaryLoader_4.3.4.dll
[2011.03.23 14:50:20 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\MXF_SDK_MetaMetadata_XSDLoader2_4.3.4.dll
[2011.03.23 14:50:20 | 000,144,896 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\MXF_SDK_MetaMetadata_XSDLoader_4.3.4.dll
[2010.12.20 14:06:02 | 000,011,916 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS5.5\Plug-ins\NoiseNinjaPlugin_Win64_2_4_2\doc\auto_loader.htm
[2009.10.22 01:24:38 | 000,370,504 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2009.10.22 01:24:38 | 000,018,248 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2012.08.27 21:50:21 | 000,000,723 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UOHV6WV\downloaderror[1].js
[2012.08.27 21:50:21 | 000,001,174 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UOHV6WV\downloader[1].js
[2012.04.03 00:06:05 | 000,000,673 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7W9H74AI\ajax-loader[1].gif
[2012.04.03 00:06:04 | 000,000,673 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GG0GXU6M\ajax-loader[1].gif
[2012.08.27 21:50:19 | 000,003,784 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GG0GXU6M\bundleloader[1].js
[2012.04.03 00:05:05 | 000,001,172 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z1R7ONAP\ionLoader[2].js
[2012.04.03 00:06:04 | 000,036,922 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z1R7ONAP\Video2brainPreloader[1].swf
[2012.05.13 00:57:10 | 000,000,905 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BG8P1ARW\TooltipLoader[1].css
[2012.05.13 00:57:10 | 000,014,290 | ---- | M] () -- \Users\Ales\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BG8P1ARW\TooltipLoader[1].js
[2011.09.26 17:57:38 | 000,007,791 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\ish172183435\images\loader.gif
[2011.02.28 15:18:38 | 000,005,154 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.50\inc\lib\AutoLoader.pm
[2011.02.28 15:18:38 | 000,014,685 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.50\inc\lib\DynaLoader.pm
[2011.02.28 15:18:38 | 000,002,997 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.50\inc\lib\XSLoader.pm
[2011.07.16 05:53:42 | 000,005,154 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.61\inc\lib\AutoLoader.pm
[2011.07.16 05:53:42 | 000,014,685 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.61\inc\lib\DynaLoader.pm
[2011.07.16 05:53:44 | 000,002,997 | ---- | M] () -- \Users\Ales\AppData\Local\Temp\par-Ales\cache-exiftool-8.61\inc\lib\XSLoader.pm
[2012.02.27 13:07:20 | 000,009,051 | ---- | M] () -- \Users\Ales\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.02.27 13:07:20 | 000,016,119 | ---- | M] () -- \Users\Ales\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.02.27 13:07:20 | 000,018,434 | ---- | M] () -- \Users\Ales\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.02.27 13:07:20 | 000,004,856 | ---- | M] () -- \Users\Ales\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.04.02 00:38:06 | 000,000,121 | ---- | M] () -- \Users\Ales\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\B9C8BY9L\fr-advideum.cdn.videoplaza.tv\com.videoplaza.bootloader.sol
[2012.02.02 10:48:29 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2012.02.02 10:48:29 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2009.07.14 02:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 02:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.02.02 10:48:29 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.02.02 10:48:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2010.11.21 08:06:45 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 08:06:45 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2010.11.21 08:06:45 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2010.11.21 08:06:45 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2010.11.21 08:06:45 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2012.02.02 10:44:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2012.02.02 10:44:31 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2012.02.02 10:44:31 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2012.02.02 10:44:31 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2012.02.02 10:44:31 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009.07.14 03:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2010.11.21 08:05:43 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 04:16:35 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2012.02.02 10:44:30 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2012.02.02 10:44:30 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 03:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.02.02 10:48:29 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.02.02 10:48:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll

< *minodlogin* /s >

< *tnod* /s >
[2011.03.19 00:32:30 | 000,000,679 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Contribute CS5.1\App\Configuration\Shared\Google\FreeSearch\Help\skin_textnode.swf
[2011.03.22 18:00:32 | 000,000,631 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\configuration\Content\Reference\JavaScript\TextNode.html
[2011.04.04 09:15:24 | 000,002,366 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\framework\src\mx\utils\LinkedListNode.as
[2011.03.30 09:02:28 | 000,002,366 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\framework\src\mx\utils\LinkedListNode.as

< *AutoKMS* /s >

< *activator* /s >
[2011.04.04 09:13:40 | 000,002,513 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.5.0.308971\classes\com\ctc\wstx\osgi\WstxBundleActivator.class
[2011.04.04 09:13:44 | 000,000,926 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexide.exportimport_4.5.0.308971\com\adobe\flexide\exportimport\Activator.class
[2011.04.04 09:14:38 | 000,007,593 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\framework\src\mx\skins\halo\ActivatorSkin.as
[2011.04.04 09:14:26 | 000,005,181 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\haloclassic\src\haloclassic\ActivatorSkin.as
[2011.04.04 09:15:40 | 000,008,253 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\mx\src\mx\skins\halo\ActivatorSkin.as
[2011.03.30 08:55:50 | 000,002,513 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flash.codemodel.osgi_1.5.0.308731\classes\com\ctc\wstx\osgi\WstxBundleActivator.class
[2011.03.30 08:55:50 | 000,000,645 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexide.exportimport_1.5.0.308731\com\adobe\flexide\exportimport\Activator.class
[2011.03.30 09:01:56 | 000,008,253 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\mx\src\mx\skins\halo\ActivatorSkin.as
[2011.03.17 08:30:08 | 000,002,319 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\mx\skins\halo\ActivatorSkin.as
[2011.03.17 08:30:08 | 000,001,806 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS5.5\Common\First Run\Classes\mx\skins\sample\ActivatorSkin.as
[2012.03.14 01:56:59 | 000,435,791 | ---- | M] () -- \Users\Ales\AppData\Local\Mendeley Ltd\Mendeley Desktop\Downloaded\Kandasamy et al. - 2004 - Regulation of unsaturated fatty acid biosynthesis in Saccharomyces the endoplasmic reticulum membrane protein, Mga2p, a transcription activator of the OLE.pdf

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#8 Příspěvek od alash »

jeste jedno pokracovani predchoziho logu (mm, vidim, co to u me naslo za spinu...no nebudu to nijak ospravedlnovat... :oops: )


< *serial* /s >
[2012.03.01 01:26:52 | 000,019,070 | ---- | M] () -- \_data\laborka\Win_SerialCloner2-1\Win_SerialCloner2-1\Serial-Cloner-History.txt
[2012.03.01 01:26:52 | 001,313,287 | ---- | M] () -- \_data\laborka\Win_SerialCloner2-1\Win_SerialCloner2-1\SerialCloner (v1-2)-User Manual.pdf
[2012.03.01 01:26:52 | 019,498,239 | ---- | M] () -- \_data\laborka\Win_SerialCloner2-1\Win_SerialCloner2-1\SerialCloner 2-1.exe
[2012.03.01 01:26:52 | 003,996,567 | ---- | M] () -- \_data\laborka\Win_SerialCloner2-1\Win_SerialCloner2-1\Companion Software\Reset Serial Cloner.exe
[2012.02.28 13:05:40 | 010,270,428 | ---- | M] () -- \_data\programy\Win_SerialCloner2-1.zip
[2006.06.09 22:25:48 | 000,000,029 | ---- | M] () -- \_data\programy\Adobe Acrobat 6.0 Professional\Serial.txt
[2007.02.20 01:53:46 | 000,000,141 | ---- | M] () -- \_data\programy\adobe LightRoom\Serial.txt
[2003.12.17 18:30:48 | 000,000,089 | ---- | M] () -- \_data\programy\Origin 7\serial.txt
[2011.03.22 18:01:10 | 000,033,536 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\JDK\bin\serialver.exe
[2011.03.18 10:28:42 | 000,001,673 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\LMResources\BadSerialNumberAlert.exv
[2011.03.18 10:28:42 | 000,001,561 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\LMResources\CantChangeSerialNumberAlert.exv
[2011.03.18 10:28:42 | 000,001,639 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\LMResources\InValidUpGradeSerialNumberAlert.exv
[2011.03.18 10:28:42 | 000,000,849 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\LMResources\ReserializeAlert.exv
[2011.03.18 10:28:42 | 000,027,443 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\LMResources\SerializationWF.exv
[2011.03.18 12:56:02 | 000,090,624 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Encore CS5.1\Plug-ins\Common\DeviceControlSerial.prm
[2011.04.04 09:13:46 | 000,293,200 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\org.apache.xml.serializer_2.7.1.v201005080400.jar
[2011.04.04 09:13:42 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\de_DE\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\de_DE\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,958 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\fr_FR\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,956 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\fr_FR\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,985 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\ja_JP\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,980 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\ja_JP\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,002,003 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\ru_RU\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,002,000 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\ru_RU\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,000,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\xx_XX\serializers\bundles\src\serializer.properties
[2011.04.04 09:13:42 | 000,001,966 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\zh_CN\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,001,961 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.5.0.308971\nl\zh_CN\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,016,397 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project_4.5.0.308971\dcradSwcs\3.6\libs\serializers.swc
[2011.04.04 09:13:42 | 000,001,917 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project_4.5.0.308971\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.04.04 09:13:42 | 000,016,835 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project_4.5.0.308971\dcradSwcs\4.5\libs\serializers.swc
[2011.04.04 09:13:42 | 000,001,949 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\eclipse\plugins\com.adobe.flexbuilder.project_4.5.0.308971\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.04.04 09:14:08 | 000,001,711 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\rpc\src\mx\messaging\errors\MessageSerializationError.as
[2011.04.04 09:14:28 | 000,008,889 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\http\SerializationFilter.as
[2011.04.04 09:15:16 | 000,011,140 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SerialElement.as
[2011.04.04 09:16:28 | 000,005,739 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDisplayObjectTrait.as
[2011.04.04 09:15:34 | 000,005,664 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDynamicStreamTrait.as
[2011.04.04 09:14:48 | 000,001,909 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementSegment.as
[2011.04.04 09:16:48 | 000,006,077 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementTransitionManager.as
[2011.04.04 09:17:02 | 000,002,395 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekOperationInfo.as
[2011.04.04 09:14:46 | 000,015,172 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekTrait.as
[2011.04.04 09:16:56 | 000,002,953 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\events\SerialElementEvent.as
[2011.04.04 09:16:44 | 000,002,248 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\messaging\errors\MessageSerializationError.as
[2011.04.04 09:16:32 | 000,010,400 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\http\SerializationFilter.as
[2011.03.30 08:55:52 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\de_DE\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\de_DE\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,958 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\fr_FR\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,956 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\fr_FR\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,985 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\ja_JP\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,980 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\ja_JP\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,002,003 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\ru_RU\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,002,000 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\ru_RU\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,000,159 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\xx_XX\serializers\bundles\src\serializer.properties
[2011.03.30 08:55:52 | 000,001,966 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\zh_CN\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:52 | 000,001,961 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project.nl1_1.5.0.308731\nl\zh_CN\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 08:55:48 | 000,016,397 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project_1.5.0.308731\dcradSwcs\3.6\libs\serializers.swc
[2011.03.30 08:55:48 | 000,001,917 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project_1.5.0.308731\dcradSwcs\3.6\locale\serializers_rb.swc
[2011.03.30 08:55:48 | 000,016,835 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project_1.5.0.308731\dcradSwcs\4.5\libs\serializers.swc
[2011.03.30 08:55:48 | 000,001,949 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\plugins\com.adobe.flexbuilder.project_1.5.0.308731\dcradSwcs\4.5\locale\serializers_rb.swc
[2011.03.30 09:01:26 | 000,011,140 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\SerialElement.as
[2011.03.30 09:02:32 | 000,005,739 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDisplayObjectTrait.as
[2011.03.30 09:01:18 | 000,005,664 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDynamicStreamTrait.as
[2011.03.30 09:02:34 | 000,001,909 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementSegment.as
[2011.03.30 09:01:42 | 000,006,077 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementTransitionManager.as
[2011.03.30 09:01:52 | 000,002,395 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekOperationInfo.as
[2011.03.30 09:02:12 | 000,015,172 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekTrait.as
[2011.03.30 09:01:34 | 000,002,953 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\osmf\src\org\osmf\events\SerialElementEvent.as
[2011.03.30 09:02:42 | 000,002,248 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\messaging\errors\MessageSerializationError.as
[2011.03.30 09:01:28 | 000,010,400 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Catalyst CS5.5\sdks\4.5.0\frameworks\projects\rpc\src\mx\rpc\http\SerializationFilter.as
[2011.03.11 15:50:06 | 000,356,496 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Illustrator CS5.1\Support Files\Contents\Windows\boost_serialization.dll
[2011.03.19 00:30:46 | 000,009,728 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\TestPlainTextSerializer.exe
[2011.03.19 00:30:56 | 000,002,845 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDOMLSSerializer.idl
[2011.03.19 00:30:56 | 000,002,093 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDOMLSSerializerFilter.idl
[2011.03.19 00:30:58 | 000,003,607 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDOMSerializer.idl
[2011.03.19 00:31:02 | 000,002,512 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIRDFXMLSerializer.idl
[2011.03.19 00:31:04 | 000,002,951 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsISerializable.idl
[2011.03.19 00:31:06 | 000,002,506 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\rdfISerializer.idl
[2011.03.19 00:31:16 | 000,006,263 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\mozISanitizingSerializer.h
[2011.03.19 00:31:22 | 000,004,518 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIContentSerializer.h
[2011.03.19 00:31:24 | 000,007,959 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDOMLSSerializer.h
[2011.03.19 00:31:24 | 000,002,831 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDOMLSSerializerFilter.h
[2011.03.19 00:31:26 | 000,005,289 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDOMSerializer.h
[2011.03.19 00:31:32 | 000,003,854 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIRDFXMLSerializer.h
[2011.03.19 00:31:34 | 000,004,091 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsISerializable.h
[2011.03.19 00:31:42 | 000,003,192 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5.1\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\rdfISerializer.h
[2011.02.09 23:38:08 | 000,707,072 | ---- | M] () -- \Program Files (x86)\Common Files\Intel Corporation\WiDiAgent\serializer.dll
[2010.04.01 10:20:06 | 000,413,696 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.dll
[2012.02.02 11:17:18 | 001,186,304 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.ni.dll
[2006.01.26 23:44:04 | 000,000,612 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 9.0\VB\Snippets\1033\other\connectivity\EnumerateSerialPorts.snippet
[2006.01.26 23:44:04 | 000,001,198 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 9.0\VB\Snippets\1033\other\connectivity\ReadDatafromaSerialPort.snippet
[2006.01.26 23:44:04 | 000,001,512 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 9.0\VB\Snippets\1033\other\connectivity\UseaSerialPorttoDialaPhoneNumber.snippet
[2010.11.21 04:25:11 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2008.06.14 00:32:10 | 000,285,032 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\en\System.Runtime.Serialization.xml
[2010.04.15 03:20:46 | 000,415,592 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Runtime.Serialization.dll
[2010.04.15 03:20:46 | 000,141,168 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Runtime.Serialization.Json.dll
[2010.04.15 03:20:46 | 000,321,376 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Xml.Serialization.dll
[2010.11.21 04:24:53 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2012.03.01 04:01:35 | 000,002,773 | ---- | M] () -- \Users\Ales\AppData\Roaming\SerialClonerPrefs
[2012.03.01 01:19:59 | 010,270,428 | ---- | M] () -- \Users\Ales\Downloads\Win_SerialCloner2-1.zip
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.21 04:24:53 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2012.07.22 13:05:15 | 000,310,784 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.07.23 23:49:42 | 002,347,008 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
[2012.07.22 23:38:27 | 003,073,536 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
[2012.07.22 01:06:03 | 000,396,288 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\807759890a40e4047c35a24e64dc76d5\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.07.18 08:50:44 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\1ea68db6df26604de2e14af08dde4adb\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.07.18 08:51:01 | 002,637,312 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0b065445b421ccf5e2beb5eecc45a48\System.Runtime.Serialization.ni.dll
[2012.07.18 09:20:51 | 003,403,776 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\c855969aa5863b0459caf7af03dd1d74\System.Runtime.Serialization.ni.dll
[2012.07.18 09:21:54 | 000,376,320 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\e452508116ce025d9d217b946bf4da23\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.07.17 23:32:16 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2012.07.17 23:32:15 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2008.06.02 07:01:28 | 000,009,272 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\en\System.Runtime.Serialization.Formatters.Soap.xml
[2010.11.21 04:24:53 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010.03.18 22:16:28 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 22:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.10 21:40:06 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.21 04:24:53 | 000,847,872 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010.03.18 22:16:28 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 22:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2009.07.14 01:00:40 | 000,094,208 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_amd64_neutral_fdcfb86ce78678d1\serial.sys
[2009.06.10 21:37:50 | 000,038,400 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_amd64_neutral_6fb75ea318f84fe5\grserial.sys
[2010.11.21 08:06:15 | 000,005,120 | ---- | M] () -- \Windows\System32\en-US\serialui.dll.mui
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\SysWOW64\serialui.dll
[2010.11.21 08:06:15 | 000,005,120 | ---- | M] () -- \Windows\SysWOW64\en-US\serialui.dll.mui
[2010.11.21 08:06:20 | 000,005,120 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_edb61e94e4562781\serialui.dll.mui
[2009.07.14 02:41:54 | 000,017,920 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_50f69335385bc360\serialui.dll
[2010.11.21 08:06:21 | 000,010,240 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf.resources_31bf3856ad364e35_6.1.7600.16385_en-us_64015f894ce7c72a\serial.sys.mui
[2009.07.14 01:00:40 | 000,094,208 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_548ca258d20f4ada\serial.sys
[2009.06.10 21:40:06 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_a9d1bee515273f56\System.Runtime.Serialization.Formatters.Soap.dll
[2009.06.10 21:37:50 | 000,038,400 | ---- | M] () -- \Windows\winsxs\amd64_smartcrd.inf_31bf3856ad364e35_6.1.7600.16385_none_ce9ed3064deed3aa\grserial.sys
[2010.11.21 04:24:53 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17514_none_5918bfde74e3f722\System.Runtime.Serialization.dll
[2010.11.21 04:24:53 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_93efcca8c8dbf1bb\System.Runtime.Serialization.dll
[2012.02.02 10:44:31 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8.manifest
[2012.02.02 10:44:31 | 000,017,792 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8_kdcom.dll_db5e7744
[2010.11.21 08:06:44 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_edb61e94e4562781_serialui.dll.mui_7d29d2a3
[2009.07.14 03:57:29 | 000,017,920 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_50f69335385bc360_serialui.dll_bea29328
[2010.11.21 08:06:45 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_919783112bf8b64b_serialui.dll.mui_7d29d2a3
[2009.07.14 03:58:37 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a_serialui.dll_bea29328
[2009.07.14 03:15:17 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7600.16385_none_6daa7ec5c65bf5bc.manifest
[2012.02.02 10:44:30 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.17556_none_6fb25371c3691bc8.manifest
[2012.02.02 10:44:30 | 000,002,766 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.1.7601.21655_none_703aeff2dc87a23b.manifest
[2009.07.14 03:11:30 | 000,000,868 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.1.7600.16385_none_88b1c48f2026fe3f.manifest
[2010.11.21 04:17:50 | 000,002,237 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.1.7601.17514_none_5918bfde74e3f722.manifest
[2010.11.21 04:17:50 | 000,002,262 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_93efcca8c8dbf1bb.manifest
[2010.11.21 04:17:50 | 000,002,226 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c.manifest
[2010.11.21 08:05:51 | 000,000,531 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.1.7600.16385_en-us_8f71d563bf7aa3c2.manifest
[2010.11.21 04:17:50 | 000,001,985 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f.manifest
[2010.11.21 04:18:20 | 000,002,260 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1.manifest
[2009.06.10 22:23:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.1.7600.16385_none_1c9a3ec1e01c684b\System.Runtime.Serialization.Formatters.Soap.dll
[2010.11.21 04:24:53 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.1.7601.17514_none_a67f221874da7f4c\System.Runtime.Serialization.dll
[2010.11.21 04:24:53 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.1.7601.17514_none_d6c257b29c81807f\System.Runtime.Serialization.dll
[2010.11.21 08:06:15 | 000,005,120 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.1.7600.16385_en-us_919783112bf8b64b\serialui.dll.mui
[2009.07.14 02:16:13 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.1.7600.16385_none_f4d7f7b17ffe522a\serialui.dll
[2010.11.21 04:25:11 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.1.7601.17514_none_db9d037fdd581ac1\System.Runtime.Serialization.dll

< *w7lxe* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 1071 bytes -> C:\Users\Ales\AppData\Local\RVbWmGe3bb8gwn:gTKGxyocIhNHs46g6iWvQu

< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#9 Příspěvek od Márty84 »

alash píše:jeste jedno pokracovani predchoziho logu (mm, vidim, co to u me naslo za spinu...no nebudu to nijak ospravedlnovat... :oops: )
No je tam toho teda dost :roll:

Ted nemam moc casu, za chvili odchazim do prace. Odpoledne sepisu opravny skript.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#10 Příspěvek od Márty84 »

:???: Jake pouzivate zabezpeceni, krom Avastu?





:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]

:services
AdobeARMservice
gupdate
gupdatem

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:otl
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1647806338-2296827418-1155026692-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[4 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[42 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
@Alternate Data Stream - 1071 bytes -> C:\Users\Ales\AppData\Local\RVbWmGe3bb8gwn:gTKGxyocIhNHs46g6iWvQu

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=-
"{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"=-
"DAEMON Tools Lite"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Antivirus] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTT] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] /64
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=-
""=-
"Adobe ARM"=-
"Adobe Acrobat Speed Launcher"=-
"Acrobat Assistant 8.0"=-
"SunJavaUpdateSched"=-
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#11 Příspěvek od alash »

ad ochrana: pouzivam jen ten avast, cas od casu skenuju nejaky anti-malware programem, ale ten snad nikdy nenajde nic, co by bylo onacene za nejakou vetsi hrozbu...

log:

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: Ales
->Temp folder emptied: 3549444037 bytes
->Temporary Internet Files folder emptied: 227856613 bytes
->Java cache emptied: 9529501 bytes
->FireFox cache emptied: 310902540 bytes
->Google Chrome cache emptied: 22836278 bytes
->Flash cache emptied: 101109 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56475 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 323252777 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50467 bytes
RecycleBin emptied: 6697219607 bytes

Total Files Cleaned = 10 625,00 mb


[EMPTYFLASH]

User: Ales
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
========== SERVICES/DRIVERS ==========
Service AdobeARMservice stopped successfully!
Service AdobeARMservice deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
File C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1647806338-2296827418-1155026692-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4719.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5E03.tmp\ehiWUapi.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5E03.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP6B8E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder deleted successfully.
ADS C:\Users\Ales\AppData\Local\RVbWmGe3bb8gwn:gTKGxyocIhNHs46g6iWvQu deleted successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar\\{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{517BDDE4-E3A7-4570-B21E-2B52B6139FC7}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Antivirus\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTT\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe Acrobat Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Acrobat Assistant 8.0 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 12162012_183001

Files\Folders moved on Reboot...
C:\Users\Ales\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#12 Příspěvek od Márty84 »

alash píše:pouzivam jen ten avast
:???: Takze firewall jen ten windowsacky?

:arrow: V tom pripade si dame OTLko jeste jednou s timto skriptem.

Kód: Vybrat vše

:commands
[CreateRestorePoint]
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]

:services
SbFw
sbwtis
sbhips
sbapifs
SBRE
SBFWIMCLMP
SBFWIMCL

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Program Files (x86)\Ad-Aware Antivirus
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus
C:\ProgramData\Ad-Aware Browsing Protection
C:\Windows\SysNative\drivers\SbFw.sys
C:\Windows\SysNative\drivers\sbwtis.sys
C:\Windows\SysNative\drivers\sbhips.sys
C:\Windows\SysNative\drivers\sbapifs.sys
C:\Windows\SysNative\drivers\sbredrv.sys
C:\Windows\SysNative\drivers\SbFwIm.sys
C:\Windows\SysNative\drivers\SbFwIm.sys
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#13 Příspěvek od alash »

jo, firewall opravdu jen ten windowsovy
...jinak asi nastal problem: po poslednim spusteni OTL se nemuzu pripojit na internet (prez LAN)...windowsy to diagnostikujou jako problem s driverama (prikladam screenshot)...(akorat mam problem, ze nemam dostupnou wifi...takze ted mam jako prioritu obnovit to pripojeni na net)

prikladam i log:
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: Ales
->Temp folder emptied: 7391350 bytes
->Temporary Internet Files folder emptied: 7451796 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 173988212 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1599 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 180,00 mb


[EMPTYFLASH]

User: Ales
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

========== SERVICES/DRIVERS ==========
Error: Unable to stop service SbFw!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SbFw deleted successfully.
Service sbwtis stopped successfully!
Service sbwtis deleted successfully!
Service sbhips stopped successfully!
Service sbhips deleted successfully!
Service sbapifs stopped successfully!
Service sbapifs deleted successfully!
Service SBRE stopped successfully!
Service SBRE deleted successfully!
Error: Unable to stop service SBFWIMCLMP!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SBFWIMCLMP deleted successfully.
Service SBFWIMCL stopped successfully!
Service SBFWIMCL deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Program Files (x86)\Ad-Aware Antivirus\x64 folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\x32 folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\i386\wxp folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\i386\wlh folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\i386\w2k folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\i386 folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\amd64\wnet folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\amd64\wlh folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers\amd64 folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Drivers folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\WDBF folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\Staging folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\LKGD folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus\Definitions folder moved successfully.
C:\Program Files (x86)\Ad-Aware Antivirus folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs\20120730T010837.174505PID11976 folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs\20120717T221814.371155PID6192 folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs\20120717T220123.847732PID5196 folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs\20120717T213756.585042PID5644 folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs\20120716T190000.180202PID10804 folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus\Logs folder moved successfully.
C:\Users\Ales\AppData\Roaming\Ad-Aware Antivirus folder moved successfully.
C:\ProgramData\Ad-Aware Browsing Protection folder moved successfully.
C:\Windows\SysNative\drivers\SbFw.sys moved successfully.
C:\Windows\SysNative\drivers\sbwtis.sys moved successfully.
C:\Windows\SysNative\drivers\sbhips.sys moved successfully.
C:\Windows\SysNative\drivers\sbapifs.sys moved successfully.
C:\Windows\SysNative\drivers\sbredrv.sys moved successfully.
C:\Windows\SysNative\drivers\SbFwIm.sys moved successfully.
File\Folder C:\Windows\SysNative\drivers\SbFwIm.sys not found.

OTL by OldTimer - Version 3.2.69.0 log created on 12172012_011356

Files\Folders moved on Reboot...
C:\Users\Ales\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Přílohy
connection problem.jpg
connection problem.jpg (59.74 KiB) Zobrazeno 4317 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#14 Příspěvek od Márty84 »

Pro tento pripad jsem zadal OTLku, aby udelal bod obnovy. Takze obnovte system k datu a casu, kdy bylo podruhe spusteno OTL.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
alash
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 19 črc 2010 23:07

Re: preventivka

#15 Příspěvek od alash »

diky; system obnoveny a pripojeni ok

Zamčeno