
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Ubývající místo na C:
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní: http://forum.viry.cz/viewtopic.php?f=12&t=123975 . Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní: http://forum.viry.cz/viewtopic.php?f=12&t=123975 . Děkujeme za pochopení.
Re: Ubývající místo na C:
Crack je myslím, jen když se přepíše originální *.exe soubor a tady se do programu nijak nezasahovalo, jen to našlo klíč a vložil se.
Proč jsem to tam měl? Protože v jednu dobu jsem to pravděpodobně používal, ten "program" se automaticky spouštěl při každém zapnutí PC, nějakej autorun to spouštěl a vždy jen zkontroloval jestli ten klíč pořád funguje a pak už nevím jak, ale myslím, že když jsem nahrával zálohu přes Acronis nebo Ghost, tak jak jsem ji nahrál, tak asi od té doby, se to už nespouštělo. Jelikož v tu dobu (v té starší záloze Acronisu či Ghostu) jsem ani ESET neměl a měl jsem tam jinej antivir, asi Avast to byl. Pak jsem dostal ten key k ESETU a nainstaloval jsem si ho znova a vložil tam ten klíč a na ten "crack", jak vy říkáte, jsem úplně zapoměl. Takže asi nějak takto:)
Proč jsem to tam měl? Protože v jednu dobu jsem to pravděpodobně používal, ten "program" se automaticky spouštěl při každém zapnutí PC, nějakej autorun to spouštěl a vždy jen zkontroloval jestli ten klíč pořád funguje a pak už nevím jak, ale myslím, že když jsem nahrával zálohu přes Acronis nebo Ghost, tak jak jsem ji nahrál, tak asi od té doby, se to už nespouštělo. Jelikož v tu dobu (v té starší záloze Acronisu či Ghostu) jsem ani ESET neměl a měl jsem tam jinej antivir, asi Avast to byl. Pak jsem dostal ten key k ESETU a nainstaloval jsem si ho znova a vložil tam ten klíč a na ten "crack", jak vy říkáte, jsem úplně zapoměl. Takže asi nějak takto:)
Re: Ubývající místo na C:
At to nazveme crackem\keygenem ci simulatorem akvarijnich rybicek - stale je to neco na obchazeni licence a toto tu nepodporujem...
Poslete mi do mailu objednavku lic.klice od ESETu a pak se mozna dale pohneme...
Poslete mi do mailu objednavku lic.klice od ESETu a pak se mozna dale pohneme...
Re: Ubývající místo na C:
Popravdě já ten klíč vyhrál
je to par let zpatky, bylo to na konferenci v Praze, za Junior Internet www.juniorinternet.cz. Klíč napsanej v zadní části krabičky s CD a to už je dávno někde "zašantročený", nedej bože, vyhozený :/:/

Re: Ubývající místo na C:
A ten klic je dozivotni?? Ze uz ho mate par let?? O tom pochybuji 

Re: Ubývající místo na C:
Nee, to bylo tak, že 1. místo – na 3 roky ESET, 2. místo na 2 roky a 3. místo na 1 rok + nějaký další ceny k tomu.
Re: Ubývající místo na C:
Hmm a jak dlouho uz ho pouzivate 

Re: Ubývající místo na C:
Třetím rokem, expirace se blíží 

Re: Ubývající místo na C:

- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
- Zaskrtnete okenko Pro vsechny uzivatele
- Zaskrtnete okenko Kontrola na havet "LOP"
- Zaskrtnete okenko Kontrola na havet "Purity"
- Stari souboru zmente z 30 dnu na 7 dnu
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
CREATERESTOREPOINT netsvcs drivers32 savembr:0 /md5start atapi.sys autochk.exe cdrom.sys explorer.exe hal.dll scecli.dll services.exe svchost.exe tcpip.sys userinit.exe winlogon.exe /md5stop %systemroot%*.* /U /s %SYSTEMDRIVE%\*.exe %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %systemroot%\system32\drivers\*.sys /3 %systemroot%\system32\*.* /3 %SYSTEMDRIVE%\*.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 %PROGRAMFILES%\Opera\opera.exe /md5 %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 %SystemDrive%\PhysicalMBR.bin /md5 *crack* /s *keygen* /s *loader* /s
- Kliknete na tlacitko Prohledat
- Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
- Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku
Re: Ubývající místo na C:
OTL logfile created on: 30.12.2012 0:23:57 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\McDan\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 33,28% Memory free
7,98 Gb Paging File | 3,77 Gb Available in Paging File | 47,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 0,70 Gb Free Space | 1,40% Space Free | Partition Type: NTFS
Drive D: | 440,01 Gb Total Space | 79,10 Gb Free Space | 17,98% Space Free | Partition Type: NTFS
Drive E: | 440,01 Gb Total Space | 114,03 Gb Free Space | 25,92% Space Free | Partition Type: NTFS
Drive I: | 1,49 Gb Total Space | 1,22 Gb Free Space | 81,81% Space Free | Partition Type: FAT32
Drive K: | 1862,89 Gb Total Space | 1211,80 Gb Free Space | 65,05% Space Free | Partition Type: NTFS
Computer Name: PRIVATE | User Name: McDan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012.12.30 00:19:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
PRC - [2012.12.13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.12.12 08:22:17 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012.12.08 01:32:23 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.11.11 14:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011.09.30 23:58:10 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.09.23 20:35:54 | 000,393,216 | ---- | M] (AMD) -- C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2010.12.07 11:32:02 | 002,228,008 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2010.07.06 16:03:00 | 000,173,352 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010.04.27 03:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.03.06 03:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2009.12.25 13:58:46 | 002,480,048 | R--- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2009.11.20 19:17:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009.08.04 17:29:52 | 000,346,320 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
PRC - [2009.02.06 14:23:36 | 000,727,720 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2007.04.30 18:43:54 | 003,450,608 | ---- | M] (Stardock) -- C:\Program Files (x86)\ObjectDock\ObjectDock.exe
PRC - [2006.12.19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\SysWOW64\IoctlSvc.exe
PRC - [2006.03.06 16:15:42 | 000,289,792 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\G-series Software\Applets\LCDMedia.exe
========== Modules (No Company Name) ==========
MOD - [2012.12.12 08:22:17 | 014,586,296 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012.12.08 01:32:23 | 002,397,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011.09.23 20:35:12 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\ATI Technologies\HydraVision\hydracsy.dll
MOD - [2010.05.07 18:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010.05.07 18:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010.05.07 18:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010.05.07 18:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010.05.07 18:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2009.07.30 18:15:32 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
MOD - [2007.04.30 18:18:50 | 000,112,400 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\DockShellHook.dll
MOD - [2007.04.21 12:47:52 | 000,059,592 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\zlib.dll
MOD - [2007.04.19 13:23:48 | 000,095,944 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\CrashRpt.dll
MOD - [2002.11.19 13:11:40 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Common Files\Stardock\ODimg.dll
MOD - [2002.03.13 18:46:32 | 000,118,784 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\ODimg.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012.09.28 02:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.11.11 13:00:32 | 000,467,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:64bit: - [2010.11.11 13:00:32 | 000,306,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:64bit: - [2010.11.11 12:59:36 | 008,251,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV:64bit: - [2010.01.16 16:09:25 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009.12.08 19:25:45 | 005,009,920 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
SRV:64bit: - [2009.11.17 10:31:46 | 000,036,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2009.07.20 12:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009.02.06 14:27:10 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2009.02.06 14:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV - [2012.12.13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.12.12 08:22:19 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.08 01:32:23 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.09.30 23:58:10 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.12.07 11:32:02 | 002,228,008 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.07.06 16:03:00 | 000,173,352 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010.01.16 16:09:21 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.01.09 15:39:23 | 000,607,048 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.12.25 17:01:06 | 000,321,320 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.12.25 13:58:46 | 002,480,048 | R--- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009.11.26 17:47:06 | 000,894,480 | R--- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009.11.20 19:17:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009.11.17 10:36:48 | 001,353,544 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009.11.17 10:31:38 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.07 10:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2007.05.31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006.12.19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.10.22 14:32:03 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.09.28 10:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.09.28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.09.28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.09.28 02:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.05.14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.01.18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2010.05.14 23:00:28 | 000,271,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64)
DRV:64bit: - [2010.05.07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2010.05.07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2010.04.27 02:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.04.27 02:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.01.28 15:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.01.07 18:34:04 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2010.01.07 18:34:04 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2009.12.25 15:58:36 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.12.25 13:58:48 | 000,251,488 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2009.12.25 13:58:45 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258)
DRV:64bit: - [2009.12.25 13:58:42 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2009.12.25 13:58:36 | 000,257,120 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2009.10.09 23:55:56 | 000,022,568 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons)
DRV:64bit: - [2009.10.01 21:03:40 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2009.08.20 17:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.07.20 03:27:34 | 000,027,136 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.06.17 17:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009.06.17 17:54:38 | 000,112,144 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouKE.Sys -- (LMouKE)
DRV:64bit: - [2009.06.17 17:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 17:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.17 17:53:42 | 000,089,616 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L8042mou.Sys -- (L8042mou)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.21 14:40:06 | 000,103,272 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Tpkd.sys -- (Tpkd)
DRV:64bit: - [2009.04.06 04:14:06 | 000,050,688 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (TEAM)
DRV:64bit: - [2009.04.06 04:14:06 | 000,050,688 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV:64bit: - [2009.02.06 14:24:48 | 000,044,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2009.02.06 14:24:44 | 000,033,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:64bit: - [2009.02.06 14:24:42 | 000,163,400 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2009.02.06 14:23:20 | 000,132,464 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2009.02.06 14:19:56 | 000,141,728 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:64bit: - [2008.12.26 11:56:04 | 000,021,504 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vcsvad.sys -- (VCSVADHWSer)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.04.28 12:03:46 | 000,047,160 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmdTools64.sys -- (AmdTools64)
DRV:64bit: - [2007.12.03 03:20:54 | 000,024,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan60.sys -- (RTVLANPT)
DRV:64bit: - [2007.08.20 11:05:02 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV - [2010.11.06 13:34:52 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2009.10.14 07:24:44 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.05.07 21:05:22 | 000,146,928 | ---- | M] (CyberLink Corp.) [2009/12/26 16:02:02] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl -- ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2008.08.14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2004.06.22 15:44:50 | 000,005,632 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\Entech64.sys -- (ENTECH64)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AB 34 77 1E 53 85 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {172C5E00-138F-4c69-B3DA-61483238893F}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKCU\..\SearchScopes\{172C5E00-138F-4c69-B3DA-61483238893F}: "URL" = http://uk.search.yahoo.com/search?p={se ... &type=IEBD
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2269050
IE - HKCU\..\SearchScopes\{D3E8A867-13AA-400d-B450-27895C4621DB}: "URL" = http://www.google.com/custom?client=pub ... earchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.cz/ig"
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.8.3
FF - prefs.js..extensions.enabledAddons: istockzoom%40kanjar.art.pl:0.3.10.0
FF - prefs.js..extensions.enabledAddons: scriptish%40erikvold.com:0.1.8
FF - prefs.js..extensions.enabledAddons: %7B003D3EDC-99B9-4a34-9C20-60CB94F7E829%7D:2010.03
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.5
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {44658024-1a78-446b-90c0-ce912bf6f44b}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {003D3EDC-99B9-4a34-9C20-60CB94F7E829}:2010.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: refspoof@mozdev.org:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=0.80.0: C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: D:\Games\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\McDan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002010-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\McDan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\McDan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\McDan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\McDan\AppData\Local\Facebook\Messenger\2.1.4587.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\albumcopier@biro.solutions: C:\Program Files (x86)\BiroSolutions\Web Album Copier\\FirefoxExtensions\albumcopier
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.08 01:32:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.12.08 01:32:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5\extensions\\albumcopier@biro.solutions: C:\Program Files (x86)\BiroSolutions\Web Album Copier\\FirefoxExtensions\albumcopier
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009.12.25 13:50:32 | 000,000,000 | ---D | M]
[2009.12.25 12:15:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Extensions
[2012.11.23 19:27:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions
[2009.12.25 20:00:25 | 000,000,000 | ---D | M] (WebTran) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
[2012.11.08 17:35:35 | 000,000,000 | ---D | M] (restock notifier Community Toolbar) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}
[2010.09.21 07:03:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}-trash
[2011.03.25 08:32:13 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\engine@conduit.com
[2012.09.27 16:01:04 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\firefox@ghostery.com
[2011.10.09 13:09:18 | 000,000,000 | ---D | M] (stock zoom) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\istockzoom@kanjar.art.pl
[2010.08.06 13:26:28 | 000,000,000 | ---D | M] (refspoof) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\refspoof@mozdev.org
[2012.09.16 23:39:39 | 000,005,381 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\505655c3c3baf@505655c3c3be9.com.xpi
[2012.10.08 15:32:27 | 000,235,457 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\scriptish@erikvold.com.xpi
[2012.10.19 16:20:16 | 000,087,353 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{24cea704-946d-11da-a72b-0800200c9a66}.xpi
[2012.11.23 19:27:31 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.01.02 22:59:57 | 000,048,903 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{E10A6337-382E-4FE6-96DE-936ADC34DD04}.xpi
[2012.11.21 19:21:24 | 000,243,496 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.12.13 20:10:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.12.08 01:32:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.12.08 01:32:23 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.12.18 01:31:54 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.10.13 10:10:52 | 000,002,208 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\heureka-cz.xml
[2012.10.13 10:10:52 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.10.13 10:10:52 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2012.10.13 10:10:52 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.10.13 10:10:52 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml
========== Chrome ==========
CHR - homepage: http://www.google.cz/ig
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.cz/ig
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\McDan\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002010-0-npoctoshape.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Java(TM) Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\McDan\AppData\Local\Facebook\Messenger\2.1.4520.0\npFbDesktopPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\McDan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\McDan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\McDan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: iTunes Application Detector (Enabled) = E:\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: YouTube = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Download FB Album mod = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok\0.12.12.2_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: AdBlock = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
CHR - Extension: We Heart It = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblenkmcolcdonmlfknbpbgjebabcoae\2.6.2_0\
CHR - Extension: Skype Click to Call = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.5.0.11422_0\
CHR - Extension: Gmail = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012.12.25 12:27:25 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {074C1DC5-9320-4A9A-947D-C042949C6216} - No CLSID value found.
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - Startup: C:\Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Download Using &BitSpirit - D:\BitSpirit\bsurl.htm ()
O8:64bit: - Extra context menu item: Download With Album Copier - C:\Program Files (x86)\BiroSolutions\Web Album Copier\\InternetExplorerExtensions\albumcopier.htm File not found
O8:64bit: - Extra context menu item: Stáhnout pomocí &BitSpiritu - E:\BitSpirit\bsurl.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download Using &BitSpirit - D:\BitSpirit\bsurl.htm ()
O8 - Extra context menu item: Download With Album Copier - C:\Program Files (x86)\BiroSolutions\Web Album Copier\\InternetExplorerExtensions\albumcopier.htm File not found
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - E:\BitSpirit\bsurl.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([https] in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95384038-7513-457A-AD5E-26B2DDE2C2D1}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\SysNative\WPDShServiceObj.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.12.30 00:19:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
[2012.12.25 14:08:40 | 000,000,000 | ---D | C] -- C:\Users\McDan\AppData\Roaming\Malwarebytes
[2012.12.25 14:08:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.12.25 14:08:23 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.12.25 14:08:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.12.25 14:08:00 | 010,669,952 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\McDan\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.25 13:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.12.25 13:48:01 | 000,000,000 | ---D | C] -- C:\Users\McDan\Desktop\mbar
[2012.12.25 12:27:39 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.12.25 12:25:33 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.12.25 02:12:17 | 005,012,686 | R--- | C] (Swearware) -- C:\Users\McDan\Desktop\ComboFix.exe
[2012.12.25 02:04:18 | 001,754,528 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\McDan\Desktop\rkill.com
[2012.12.24 14:24:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.12.24 14:23:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2011.06.29 15:25:32 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\McDan\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 7 Days ==========
[2012.12.30 00:28:52 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.12.30 00:19:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
[2012.12.29 19:18:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.12.28 19:38:02 | 000,080,828 | ---- | M] () -- C:\Users\McDan\Desktop\418675_188278871316943_245316428_n.jpg
[2012.12.27 23:43:02 | 000,019,968 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.12.27 23:43:02 | 000,019,968 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.12.27 23:37:39 | 3214,483,456 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.27 16:54:15 | 002,219,317 | ---- | M] () -- C:\Users\McDan\Desktop\soulja.png
[2012.12.27 10:19:51 | 000,038,716 | ---- | M] () -- C:\Users\McDan\Desktop\227506_107013689456972_165307172_n.jpg
[2012.12.25 20:00:39 | 000,053,925 | ---- | M] () -- C:\Users\McDan\Desktop\9656_421401191264339_1947756750_n.jpg
[2012.12.25 16:26:03 | 000,443,182 | ---- | M] () -- C:\Users\McDan\Desktop\472077_429236503815775_1690910392_o.jpg
[2012.12.25 14:08:24 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.25 14:08:08 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\McDan\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.25 13:47:49 | 013,485,902 | ---- | M] () -- C:\Users\McDan\Desktop\mbar-1.01.0.1011.zip
[2012.12.25 12:27:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.12.25 02:24:43 | 000,000,000 | ---- | M] () -- C:\Windows\LCDMedia.INI
[2012.12.25 02:12:57 | 005,012,686 | R--- | M] (Swearware) -- C:\Users\McDan\Desktop\ComboFix.exe
[2012.12.25 02:04:35 | 001,754,528 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\McDan\Desktop\rkill.com
[2012.12.25 00:51:07 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.12.24 15:49:25 | 000,007,641 | ---- | M] () -- C:\Users\McDan\AppData\Local\Resmon.ResmonCfg
[2012.12.24 15:38:47 | 000,046,042 | ---- | M] () -- C:\Users\McDan\Desktop\ram_stoupani_2.png
[2012.12.24 15:20:38 | 000,223,788 | ---- | M] () -- C:\Users\McDan\Desktop\RAM_stoupani.png
========== Files Created - No Company Name ==========
[2012.12.30 00:28:51 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.28 19:37:45 | 000,080,828 | ---- | C] () -- C:\Users\McDan\Desktop\418675_188278871316943_245316428_n.jpg
[2012.12.27 16:54:14 | 002,219,317 | ---- | C] () -- C:\Users\McDan\Desktop\soulja.png
[2012.12.27 12:15:22 | 000,038,716 | ---- | C] () -- C:\Users\McDan\Desktop\227506_107013689456972_165307172_n.jpg
[2012.12.26 20:43:45 | 000,115,374 | ---- | C] () -- C:\Users\McDan\Desktop\tumblr_lv2oedWgrL1qgnahoo1_500.jpg
[2012.12.26 20:42:55 | 000,176,834 | ---- | C] () -- C:\Users\McDan\Desktop\tumblr_lwzbyqG8qe1qeui3so1_500.jpg
[2012.12.26 20:42:32 | 000,019,814 | ---- | C] () -- C:\Users\McDan\Desktop\418727_187288511401961_456242504_n.jpg
[2012.12.25 20:00:33 | 000,053,925 | ---- | C] () -- C:\Users\McDan\Desktop\9656_421401191264339_1947756750_n.jpg
[2012.12.25 16:25:58 | 000,443,182 | ---- | C] () -- C:\Users\McDan\Desktop\472077_429236503815775_1690910392_o.jpg
[2012.12.25 14:08:24 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.25 13:47:42 | 013,485,902 | ---- | C] () -- C:\Users\McDan\Desktop\mbar-1.01.0.1011.zip
[2012.12.25 02:24:43 | 000,000,000 | ---- | C] () -- C:\Windows\LCDMedia.INI
[2012.12.24 15:38:47 | 000,046,042 | ---- | C] () -- C:\Users\McDan\Desktop\ram_stoupani_2.png
[2012.12.24 15:20:37 | 000,223,788 | ---- | C] () -- C:\Users\McDan\Desktop\RAM_stoupani.png
[2012.10.22 11:46:31 | 000,045,270 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\room_v3.dat
[2012.10.08 15:42:17 | 000,000,136 | ---- | C] () -- C:\Users\McDan\AppData\Local\configurator.xml
[2012.07.04 21:41:35 | 000,000,144 | ---- | C] () -- C:\Windows\SMM_HCEditor.INI
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.03.03 20:21:10 | 000,000,257 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\com.richardwang.FluffyApp.plist
[2012.02.28 20:55:36 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe Formát GIF CS5 – předvolby
[2012.02.15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.02.15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2012.01.04 23:15:54 | 000,001,480 | ---- | C] () -- C:\Users\McDan\AppData\Local\Adobe Uložit pro web 12.0 Prefs
[2011.12.16 21:58:21 | 000,000,049 | -H-- | C] () -- C:\Users\McDan\AppData\Roaming\eMail Extractor registration.ini
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.06.29 15:25:32 | 000,007,859 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\pcouffin.cat
[2011.06.29 15:25:32 | 000,001,167 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\pcouffin.inf
[2011.06.27 14:55:13 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2011.06.24 14:14:06 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2011.03.19 14:36:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.03.19 14:36:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.03.19 14:36:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.03.19 14:36:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.03.19 14:36:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.03.11 13:54:37 | 000,007,641 | ---- | C] () -- C:\Users\McDan\AppData\Local\Resmon.ResmonCfg
[2011.03.05 19:18:44 | 000,012,800 | ---- | C] () -- C:\Users\McDan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.08 18:27:28 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010.04.18 12:47:06 | 000,000,491 | ---- | C] () -- C:\Users\McDan\.ems.cfg
[2010.02.22 15:43:57 | 000,000,117 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.01.28 14:08:37 | 000,001,024 | ---- | C] () -- C:\Users\McDan\.rnd
[2009.12.25 15:41:51 | 000,000,760 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\setup_ldm.iss
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.10.22 14:28:34 | 014,164,480 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.10.22 14:28:34 | 012,868,096 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011.07.15 11:45:10 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\.minecraft
[2010.02.22 17:12:41 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Acronis
[2011.01.24 16:32:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Antares
[2010.03.25 11:55:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\AnvSoft
[2011.12.05 17:19:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Audacity
[2010.08.04 13:36:26 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Avnex
[2010.02.28 11:55:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BeautyPilot
[2010.02.19 21:04:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Bioshock2
[2010.04.28 16:40:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BitSpirit
[2010.05.29 17:35:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\bizarre creations
[2010.05.15 11:33:59 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.01.05 18:10:31 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CocoonSoftware
[2011.11.13 14:59:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.12.12 08:21:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DAEMON Tools Lite
[2009.12.25 13:51:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ESET
[2010.03.01 22:24:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Facebook
[2012.11.06 20:52:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FileZilla
[2010.08.21 16:34:54 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Firefly Studios
[2011.07.15 15:05:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FreeScreenToVideo
[2012.10.22 11:48:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Garena
[2010.02.23 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\GetRightToGo
[2011.11.17 21:31:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\go
[2010.05.31 14:06:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ICQ
[2012.10.22 13:24:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\IObit
[2009.12.28 14:57:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LangSoft
[2009.12.25 15:41:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Leadertech
[2011.05.16 18:28:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LolClient
[2010.03.02 16:38:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MagicEffect Photo
[2011.06.24 14:16:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MAGIX
[2010.08.29 17:21:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ManyCam
[2011.12.16 21:58:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Maxprog
[2010.10.12 16:29:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mirillis
[2010.02.23 10:11:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Moyea
[2011.04.10 19:19:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mumble
[2010.06.30 18:20:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Need for Speed World
[2010.03.06 17:37:29 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Octoshape
[2011.01.12 18:29:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\OnLive App
[2010.01.30 23:01:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Opera
[2011.09.29 14:22:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Origin
[2012.07.04 21:49:13 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\PACE Anti-Piracy
[2012.08.01 17:32:55 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Pixlromatic
[2010.03.22 13:12:22 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Prison Break
[2009.12.25 21:06:00 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Publish Providers
[2011.12.19 00:43:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\QIP
[2010.05.25 11:17:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Rainmeter
[2010.12.12 11:46:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\RayV
[2010.03.22 19:02:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Red Kawa
[2010.03.22 18:46:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Regensoft
[2010.01.30 16:19:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Softland
[2010.12.19 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony
[2012.07.04 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony Creative Software
[2011.10.28 12:00:45 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\SplitMediaLabs
[2011.10.16 14:22:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.01.07 18:03:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TeamViewer
[2012.08.31 18:45:43 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TS3Client
[2010.01.09 15:39:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TuneUp Software
[2010.03.09 20:20:20 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ubisoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\uTorrent
[2010.10.30 10:26:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vghd
[2010.01.17 12:52:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\VitySoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vso
[2012.09.30 11:14:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\YCanPDF
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\McDan\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 33,28% Memory free
7,98 Gb Paging File | 3,77 Gb Available in Paging File | 47,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 0,70 Gb Free Space | 1,40% Space Free | Partition Type: NTFS
Drive D: | 440,01 Gb Total Space | 79,10 Gb Free Space | 17,98% Space Free | Partition Type: NTFS
Drive E: | 440,01 Gb Total Space | 114,03 Gb Free Space | 25,92% Space Free | Partition Type: NTFS
Drive I: | 1,49 Gb Total Space | 1,22 Gb Free Space | 81,81% Space Free | Partition Type: FAT32
Drive K: | 1862,89 Gb Total Space | 1211,80 Gb Free Space | 65,05% Space Free | Partition Type: NTFS
Computer Name: PRIVATE | User Name: McDan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012.12.30 00:19:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
PRC - [2012.12.13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.12.12 08:22:17 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012.12.08 01:32:23 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.11.11 14:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011.09.30 23:58:10 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.09.23 20:35:54 | 000,393,216 | ---- | M] (AMD) -- C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2010.12.07 11:32:02 | 002,228,008 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2010.07.06 16:03:00 | 000,173,352 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010.04.27 03:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.03.06 03:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2009.12.25 13:58:46 | 002,480,048 | R--- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2009.11.20 19:17:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009.08.04 17:29:52 | 000,346,320 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
PRC - [2009.02.06 14:23:36 | 000,727,720 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2007.04.30 18:43:54 | 003,450,608 | ---- | M] (Stardock) -- C:\Program Files (x86)\ObjectDock\ObjectDock.exe
PRC - [2006.12.19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\SysWOW64\IoctlSvc.exe
PRC - [2006.03.06 16:15:42 | 000,289,792 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\G-series Software\Applets\LCDMedia.exe
========== Modules (No Company Name) ==========
MOD - [2012.12.12 08:22:17 | 014,586,296 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012.12.08 01:32:23 | 002,397,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011.09.23 20:35:12 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\ATI Technologies\HydraVision\hydracsy.dll
MOD - [2010.05.07 18:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010.05.07 18:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010.05.07 18:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010.05.07 18:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010.05.07 18:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2009.07.30 18:15:32 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
MOD - [2007.04.30 18:18:50 | 000,112,400 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\DockShellHook.dll
MOD - [2007.04.21 12:47:52 | 000,059,592 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\zlib.dll
MOD - [2007.04.19 13:23:48 | 000,095,944 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\CrashRpt.dll
MOD - [2002.11.19 13:11:40 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Common Files\Stardock\ODimg.dll
MOD - [2002.03.13 18:46:32 | 000,118,784 | ---- | M] () -- C:\Program Files (x86)\ObjectDock\ODimg.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012.09.28 02:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.11.11 13:00:32 | 000,467,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:64bit: - [2010.11.11 13:00:32 | 000,306,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:64bit: - [2010.11.11 12:59:36 | 008,251,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV:64bit: - [2010.01.16 16:09:25 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009.12.08 19:25:45 | 005,009,920 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
SRV:64bit: - [2009.11.17 10:31:46 | 000,036,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2009.07.20 12:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009.02.06 14:27:10 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2009.02.06 14:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV - [2012.12.13 14:26:20 | 003,290,896 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.12.12 08:22:19 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.08 01:32:23 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.09.30 23:58:10 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.12.07 11:32:02 | 002,228,008 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.07.06 16:03:00 | 000,173,352 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010.01.16 16:09:21 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.01.09 15:39:23 | 000,607,048 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.12.25 17:01:06 | 000,321,320 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.12.25 13:58:46 | 002,480,048 | R--- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009.11.26 17:47:06 | 000,894,480 | R--- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009.11.20 19:17:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009.11.17 10:36:48 | 001,353,544 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009.11.17 10:31:38 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009.08.04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.07 10:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2007.05.31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006.12.19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.10.22 14:32:03 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.09.28 10:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.09.28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.09.28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.09.28 02:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.05.14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.01.18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2010.05.14 23:00:28 | 000,271,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64)
DRV:64bit: - [2010.05.07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2010.05.07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2010.04.27 02:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.04.27 02:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.01.28 15:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.01.07 18:34:04 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2010.01.07 18:34:04 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2009.12.25 15:58:36 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.12.25 13:58:48 | 000,251,488 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2009.12.25 13:58:45 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258)
DRV:64bit: - [2009.12.25 13:58:42 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2009.12.25 13:58:36 | 000,257,120 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2009.10.09 23:55:56 | 000,022,568 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons)
DRV:64bit: - [2009.10.01 21:03:40 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2009.08.20 17:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.07.20 03:27:34 | 000,027,136 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.06.17 17:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009.06.17 17:54:38 | 000,112,144 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouKE.Sys -- (LMouKE)
DRV:64bit: - [2009.06.17 17:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 17:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.17 17:53:42 | 000,089,616 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L8042mou.Sys -- (L8042mou)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.21 14:40:06 | 000,103,272 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Tpkd.sys -- (Tpkd)
DRV:64bit: - [2009.04.06 04:14:06 | 000,050,688 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (TEAM)
DRV:64bit: - [2009.04.06 04:14:06 | 000,050,688 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV:64bit: - [2009.02.06 14:24:48 | 000,044,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2009.02.06 14:24:44 | 000,033,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:64bit: - [2009.02.06 14:24:42 | 000,163,400 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2009.02.06 14:23:20 | 000,132,464 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2009.02.06 14:19:56 | 000,141,728 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:64bit: - [2008.12.26 11:56:04 | 000,021,504 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vcsvad.sys -- (VCSVADHWSer)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.04.28 12:03:46 | 000,047,160 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmdTools64.sys -- (AmdTools64)
DRV:64bit: - [2007.12.03 03:20:54 | 000,024,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan60.sys -- (RTVLANPT)
DRV:64bit: - [2007.08.20 11:05:02 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV - [2010.11.06 13:34:52 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2009.10.14 07:24:44 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.05.07 21:05:22 | 000,146,928 | ---- | M] (CyberLink Corp.) [2009/12/26 16:02:02] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl -- ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2008.08.14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2004.06.22 15:44:50 | 000,005,632 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\Entech64.sys -- (ENTECH64)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AB 34 77 1E 53 85 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {172C5E00-138F-4c69-B3DA-61483238893F}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKCU\..\SearchScopes\{172C5E00-138F-4c69-B3DA-61483238893F}: "URL" = http://uk.search.yahoo.com/search?p={se ... &type=IEBD
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2269050
IE - HKCU\..\SearchScopes\{D3E8A867-13AA-400d-B450-27895C4621DB}: "URL" = http://www.google.com/custom?client=pub ... earchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.cz/ig"
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.8.3
FF - prefs.js..extensions.enabledAddons: istockzoom%40kanjar.art.pl:0.3.10.0
FF - prefs.js..extensions.enabledAddons: scriptish%40erikvold.com:0.1.8
FF - prefs.js..extensions.enabledAddons: %7B003D3EDC-99B9-4a34-9C20-60CB94F7E829%7D:2010.03
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.5
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {44658024-1a78-446b-90c0-ce912bf6f44b}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {003D3EDC-99B9-4a34-9C20-60CB94F7E829}:2010.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: refspoof@mozdev.org:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=0.80.0: C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: D:\Games\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\McDan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002010-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\McDan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\McDan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\McDan\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\McDan\AppData\Local\Facebook\Messenger\2.1.4587.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\albumcopier@biro.solutions: C:\Program Files (x86)\BiroSolutions\Web Album Copier\\FirefoxExtensions\albumcopier
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.08 01:32:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.12.08 01:32:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5\extensions\\albumcopier@biro.solutions: C:\Program Files (x86)\BiroSolutions\Web Album Copier\\FirefoxExtensions\albumcopier
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009.12.25 13:50:32 | 000,000,000 | ---D | M]
[2009.12.25 12:15:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Extensions
[2012.11.23 19:27:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions
[2009.12.25 20:00:25 | 000,000,000 | ---D | M] (WebTran) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
[2012.11.08 17:35:35 | 000,000,000 | ---D | M] (restock notifier Community Toolbar) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}
[2010.09.21 07:03:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}-trash
[2011.03.25 08:32:13 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\engine@conduit.com
[2012.09.27 16:01:04 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\firefox@ghostery.com
[2011.10.09 13:09:18 | 000,000,000 | ---D | M] (stock zoom) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\istockzoom@kanjar.art.pl
[2010.08.06 13:26:28 | 000,000,000 | ---D | M] (refspoof) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\refspoof@mozdev.org
[2012.09.16 23:39:39 | 000,005,381 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\505655c3c3baf@505655c3c3be9.com.xpi
[2012.10.08 15:32:27 | 000,235,457 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\scriptish@erikvold.com.xpi
[2012.10.19 16:20:16 | 000,087,353 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{24cea704-946d-11da-a72b-0800200c9a66}.xpi
[2012.11.23 19:27:31 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.01.02 22:59:57 | 000,048,903 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{E10A6337-382E-4FE6-96DE-936ADC34DD04}.xpi
[2012.11.21 19:21:24 | 000,243,496 | ---- | M] () (No name found) -- C:\Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.12.13 20:10:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.12.08 01:32:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.12.08 01:32:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.12.08 01:32:23 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.12.18 01:31:54 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.10.13 10:10:52 | 000,002,208 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\heureka-cz.xml
[2012.10.13 10:10:52 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.10.13 10:10:52 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2012.10.13 10:10:52 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.10.13 10:10:52 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml
========== Chrome ==========
CHR - homepage: http://www.google.cz/ig
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.cz/ig
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\McDan\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1002010-0-npoctoshape.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Java(TM) Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\McDan\AppData\Local\Facebook\Messenger\2.1.4520.0\npFbDesktopPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\McDan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\McDan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\McDan\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: iTunes Application Detector (Enabled) = E:\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: YouTube = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Download FB Album mod = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok\0.12.12.2_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: AdBlock = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
CHR - Extension: We Heart It = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblenkmcolcdonmlfknbpbgjebabcoae\2.6.2_0\
CHR - Extension: Skype Click to Call = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.5.0.11422_0\
CHR - Extension: Gmail = C:\Users\McDan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012.12.25 12:27:25 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {074C1DC5-9320-4A9A-947D-C042949C6216} - No CLSID value found.
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - Startup: C:\Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Download Using &BitSpirit - D:\BitSpirit\bsurl.htm ()
O8:64bit: - Extra context menu item: Download With Album Copier - C:\Program Files (x86)\BiroSolutions\Web Album Copier\\InternetExplorerExtensions\albumcopier.htm File not found
O8:64bit: - Extra context menu item: Stáhnout pomocí &BitSpiritu - E:\BitSpirit\bsurl.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download Using &BitSpirit - D:\BitSpirit\bsurl.htm ()
O8 - Extra context menu item: Download With Album Copier - C:\Program Files (x86)\BiroSolutions\Web Album Copier\\InternetExplorerExtensions\albumcopier.htm File not found
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - E:\BitSpirit\bsurl.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([https] in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95384038-7513-457A-AD5E-26B2DDE2C2D1}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\SysNative\WPDShServiceObj.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.12.30 00:19:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
[2012.12.25 14:08:40 | 000,000,000 | ---D | C] -- C:\Users\McDan\AppData\Roaming\Malwarebytes
[2012.12.25 14:08:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.12.25 14:08:23 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.12.25 14:08:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.12.25 14:08:00 | 010,669,952 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\McDan\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.25 13:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.12.25 13:48:01 | 000,000,000 | ---D | C] -- C:\Users\McDan\Desktop\mbar
[2012.12.25 12:27:39 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.12.25 12:25:33 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.12.25 02:12:17 | 005,012,686 | R--- | C] (Swearware) -- C:\Users\McDan\Desktop\ComboFix.exe
[2012.12.25 02:04:18 | 001,754,528 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\McDan\Desktop\rkill.com
[2012.12.24 14:24:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.12.24 14:23:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2011.06.29 15:25:32 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\McDan\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 7 Days ==========
[2012.12.30 00:28:52 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.12.30 00:19:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\McDan\Desktop\OTL.exe
[2012.12.29 19:18:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.12.28 19:38:02 | 000,080,828 | ---- | M] () -- C:\Users\McDan\Desktop\418675_188278871316943_245316428_n.jpg
[2012.12.27 23:43:02 | 000,019,968 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.12.27 23:43:02 | 000,019,968 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.12.27 23:37:39 | 3214,483,456 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.27 16:54:15 | 002,219,317 | ---- | M] () -- C:\Users\McDan\Desktop\soulja.png
[2012.12.27 10:19:51 | 000,038,716 | ---- | M] () -- C:\Users\McDan\Desktop\227506_107013689456972_165307172_n.jpg
[2012.12.25 20:00:39 | 000,053,925 | ---- | M] () -- C:\Users\McDan\Desktop\9656_421401191264339_1947756750_n.jpg
[2012.12.25 16:26:03 | 000,443,182 | ---- | M] () -- C:\Users\McDan\Desktop\472077_429236503815775_1690910392_o.jpg
[2012.12.25 14:08:24 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.25 14:08:08 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\McDan\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.25 13:47:49 | 013,485,902 | ---- | M] () -- C:\Users\McDan\Desktop\mbar-1.01.0.1011.zip
[2012.12.25 12:27:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.12.25 02:24:43 | 000,000,000 | ---- | M] () -- C:\Windows\LCDMedia.INI
[2012.12.25 02:12:57 | 005,012,686 | R--- | M] (Swearware) -- C:\Users\McDan\Desktop\ComboFix.exe
[2012.12.25 02:04:35 | 001,754,528 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\McDan\Desktop\rkill.com
[2012.12.25 00:51:07 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.12.24 15:49:25 | 000,007,641 | ---- | M] () -- C:\Users\McDan\AppData\Local\Resmon.ResmonCfg
[2012.12.24 15:38:47 | 000,046,042 | ---- | M] () -- C:\Users\McDan\Desktop\ram_stoupani_2.png
[2012.12.24 15:20:38 | 000,223,788 | ---- | M] () -- C:\Users\McDan\Desktop\RAM_stoupani.png
========== Files Created - No Company Name ==========
[2012.12.30 00:28:51 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.28 19:37:45 | 000,080,828 | ---- | C] () -- C:\Users\McDan\Desktop\418675_188278871316943_245316428_n.jpg
[2012.12.27 16:54:14 | 002,219,317 | ---- | C] () -- C:\Users\McDan\Desktop\soulja.png
[2012.12.27 12:15:22 | 000,038,716 | ---- | C] () -- C:\Users\McDan\Desktop\227506_107013689456972_165307172_n.jpg
[2012.12.26 20:43:45 | 000,115,374 | ---- | C] () -- C:\Users\McDan\Desktop\tumblr_lv2oedWgrL1qgnahoo1_500.jpg
[2012.12.26 20:42:55 | 000,176,834 | ---- | C] () -- C:\Users\McDan\Desktop\tumblr_lwzbyqG8qe1qeui3so1_500.jpg
[2012.12.26 20:42:32 | 000,019,814 | ---- | C] () -- C:\Users\McDan\Desktop\418727_187288511401961_456242504_n.jpg
[2012.12.25 20:00:33 | 000,053,925 | ---- | C] () -- C:\Users\McDan\Desktop\9656_421401191264339_1947756750_n.jpg
[2012.12.25 16:25:58 | 000,443,182 | ---- | C] () -- C:\Users\McDan\Desktop\472077_429236503815775_1690910392_o.jpg
[2012.12.25 14:08:24 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.25 13:47:42 | 013,485,902 | ---- | C] () -- C:\Users\McDan\Desktop\mbar-1.01.0.1011.zip
[2012.12.25 02:24:43 | 000,000,000 | ---- | C] () -- C:\Windows\LCDMedia.INI
[2012.12.24 15:38:47 | 000,046,042 | ---- | C] () -- C:\Users\McDan\Desktop\ram_stoupani_2.png
[2012.12.24 15:20:37 | 000,223,788 | ---- | C] () -- C:\Users\McDan\Desktop\RAM_stoupani.png
[2012.10.22 11:46:31 | 000,045,270 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\room_v3.dat
[2012.10.08 15:42:17 | 000,000,136 | ---- | C] () -- C:\Users\McDan\AppData\Local\configurator.xml
[2012.07.04 21:41:35 | 000,000,144 | ---- | C] () -- C:\Windows\SMM_HCEditor.INI
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.03.03 20:21:10 | 000,000,257 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\com.richardwang.FluffyApp.plist
[2012.02.28 20:55:36 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe Formát GIF CS5 – předvolby
[2012.02.15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.02.15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2012.01.04 23:15:54 | 000,001,480 | ---- | C] () -- C:\Users\McDan\AppData\Local\Adobe Uložit pro web 12.0 Prefs
[2011.12.16 21:58:21 | 000,000,049 | -H-- | C] () -- C:\Users\McDan\AppData\Roaming\eMail Extractor registration.ini
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.06.29 15:25:32 | 000,007,859 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\pcouffin.cat
[2011.06.29 15:25:32 | 000,001,167 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\pcouffin.inf
[2011.06.27 14:55:13 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2011.06.24 14:14:06 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2011.03.19 14:36:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.03.19 14:36:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.03.19 14:36:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.03.19 14:36:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.03.19 14:36:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.03.11 13:54:37 | 000,007,641 | ---- | C] () -- C:\Users\McDan\AppData\Local\Resmon.ResmonCfg
[2011.03.05 19:18:44 | 000,012,800 | ---- | C] () -- C:\Users\McDan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.08 18:27:28 | 000,000,132 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010.04.18 12:47:06 | 000,000,491 | ---- | C] () -- C:\Users\McDan\.ems.cfg
[2010.02.22 15:43:57 | 000,000,117 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.01.28 14:08:37 | 000,001,024 | ---- | C] () -- C:\Users\McDan\.rnd
[2009.12.25 15:41:51 | 000,000,760 | ---- | C] () -- C:\Users\McDan\AppData\Roaming\setup_ldm.iss
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.10.22 14:28:34 | 014,164,480 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.10.22 14:28:34 | 012,868,096 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011.07.15 11:45:10 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\.minecraft
[2010.02.22 17:12:41 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Acronis
[2011.01.24 16:32:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Antares
[2010.03.25 11:55:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\AnvSoft
[2011.12.05 17:19:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Audacity
[2010.08.04 13:36:26 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Avnex
[2010.02.28 11:55:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BeautyPilot
[2010.02.19 21:04:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Bioshock2
[2010.04.28 16:40:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BitSpirit
[2010.05.29 17:35:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\bizarre creations
[2010.05.15 11:33:59 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.01.05 18:10:31 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CocoonSoftware
[2011.11.13 14:59:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.12.12 08:21:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DAEMON Tools Lite
[2009.12.25 13:51:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ESET
[2010.03.01 22:24:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Facebook
[2012.11.06 20:52:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FileZilla
[2010.08.21 16:34:54 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Firefly Studios
[2011.07.15 15:05:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FreeScreenToVideo
[2012.10.22 11:48:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Garena
[2010.02.23 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\GetRightToGo
[2011.11.17 21:31:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\go
[2010.05.31 14:06:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ICQ
[2012.10.22 13:24:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\IObit
[2009.12.28 14:57:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LangSoft
[2009.12.25 15:41:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Leadertech
[2011.05.16 18:28:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LolClient
[2010.03.02 16:38:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MagicEffect Photo
[2011.06.24 14:16:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MAGIX
[2010.08.29 17:21:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ManyCam
[2011.12.16 21:58:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Maxprog
[2010.10.12 16:29:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mirillis
[2010.02.23 10:11:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Moyea
[2011.04.10 19:19:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mumble
[2010.06.30 18:20:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Need for Speed World
[2010.03.06 17:37:29 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Octoshape
[2011.01.12 18:29:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\OnLive App
[2010.01.30 23:01:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Opera
[2011.09.29 14:22:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Origin
[2012.07.04 21:49:13 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\PACE Anti-Piracy
[2012.08.01 17:32:55 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Pixlromatic
[2010.03.22 13:12:22 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Prison Break
[2009.12.25 21:06:00 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Publish Providers
[2011.12.19 00:43:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\QIP
[2010.05.25 11:17:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Rainmeter
[2010.12.12 11:46:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\RayV
[2010.03.22 19:02:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Red Kawa
[2010.03.22 18:46:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Regensoft
[2010.01.30 16:19:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Softland
[2010.12.19 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony
[2012.07.04 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony Creative Software
[2011.10.28 12:00:45 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\SplitMediaLabs
[2011.10.16 14:22:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.01.07 18:03:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TeamViewer
[2012.08.31 18:45:43 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TS3Client
[2010.01.09 15:39:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TuneUp Software
[2010.03.09 20:20:20 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ubisoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\uTorrent
[2010.10.30 10:26:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vghd
[2010.01.17 12:52:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\VitySoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vso
[2012.09.30 11:14:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\YCanPDF
Re: Ubývající místo na C:
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,568 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\ERDNT\cache64\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\SysNative\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\ERDNT\cache86\explorer.exe
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\explorer.exe
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2012.10.22 14:13:46 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2012.10.22 14:13:46 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2012.10.22 14:13:47 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\SysWOW64\explorer.exe
[2012.10.22 14:13:47 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2012.10.22 14:13:46 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2012.10.22 14:13:46 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2009.10.24 22:33:24 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=67B922CB22FABE12B97F48E5C93D9F2F -- C:\Windows\Resources\Themes\Resources\x64 (64-bit)\explorer.exe
[2009.10.25 00:20:06 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=6ACD1B0031B0E3E9DF179138CC1EFBA8 -- C:\Windows\Resources\Themes\Resources\x86 (32-bit)\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2012.10.22 14:13:46 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2012.10.22 14:13:46 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\SysNative\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache86\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\ERDNT\cache64\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\ERDNT\cache64\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache86\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\ERDNT\cache64\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2010.06.14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\ERDNT\cache64\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\SysNative\drivers\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache86\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\ERDNT\cache64\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< >
< %systemroot%*.* /U /s >
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[15 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[3 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[286 C:\Windows\temp\*.tmp files -> C:\Windows\temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.07.15 11:45:10 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\.minecraft
[2010.02.22 17:12:41 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Acronis
[2012.11.20 22:42:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Adobe
[2011.10.27 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Adobe Mini Bridge CS5
[2011.01.24 16:32:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Antares
[2010.03.25 11:55:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\AnvSoft
[2012.03.19 23:27:16 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Apple Computer
[2011.04.10 14:44:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ArcSoft
[2010.01.09 15:32:15 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ATI
[2011.12.05 17:19:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Audacity
[2010.08.04 13:36:26 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Avnex
[2010.02.28 11:55:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BeautyPilot
[2010.02.19 21:04:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Bioshock2
[2010.04.28 16:40:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BitSpirit
[2010.05.29 17:35:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\bizarre creations
[2010.05.15 11:33:59 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.01.05 18:10:31 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CocoonSoftware
[2011.11.13 14:59:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.12.26 16:17:06 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CyberLink
[2012.12.12 08:21:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DAEMON Tools Lite
[2010.07.10 19:27:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DivX
[2009.12.25 13:51:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ESET
[2010.03.01 22:24:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Facebook
[2012.11.06 20:52:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FileZilla
[2010.08.21 16:34:54 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Firefly Studios
[2011.07.15 15:05:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FreeScreenToVideo
[2012.10.22 11:48:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Garena
[2010.02.23 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\GetRightToGo
[2011.11.17 21:31:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\go
[2010.05.31 14:06:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ICQ
[2009.12.25 12:10:12 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Identities
[2009.12.25 15:38:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\InstallShield
[2012.07.15 16:02:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\InstallShield Installation Information
[2012.10.22 13:24:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\IObit
[2009.12.28 14:57:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LangSoft
[2009.12.25 15:41:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Leadertech
[2009.12.25 15:42:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Logitech
[2011.05.16 18:28:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LolClient
[2009.12.25 12:20:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Macromedia
[2010.03.02 16:38:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MagicEffect Photo
[2011.06.24 14:16:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MAGIX
[2012.12.25 14:08:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Malwarebytes
[2010.08.29 17:21:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ManyCam
[2011.12.16 21:58:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Maxprog
[2009.07.14 16:36:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Media Center Programs
[2012.12.24 16:17:49 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Media Player Classic
[2012.06.17 20:41:18 | 000,000,000 | --SD | M] -- C:\Users\McDan\AppData\Roaming\Microsoft
[2010.10.12 16:29:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mirillis
[2010.02.23 10:11:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Moyea
[2010.03.06 17:37:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mozilla
[2011.04.10 19:19:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mumble
[2010.06.30 18:20:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Need for Speed World
[2010.01.28 14:08:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Nero
[2010.03.06 17:37:29 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Octoshape
[2011.01.12 18:29:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\OnLive App
[2010.01.30 23:01:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Opera
[2011.09.29 14:22:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Origin
[2012.07.04 21:49:13 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\PACE Anti-Piracy
[2012.08.01 17:32:55 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Pixlromatic
[2010.03.22 13:12:22 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Prison Break
[2009.12.25 21:06:00 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Publish Providers
[2011.12.19 00:43:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\QIP
[2010.05.25 11:17:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Rainmeter
[2010.12.12 11:46:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\RayV
[2010.03.22 19:02:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Red Kawa
[2010.03.22 18:46:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Regensoft
[2010.01.16 09:52:19 | 000,000,000 | RH-D | M] -- C:\Users\McDan\AppData\Roaming\SecuROM
[2012.11.25 00:33:15 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Skype
[2011.05.28 09:44:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\skypePM
[2010.01.30 16:19:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Softland
[2010.12.19 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony
[2012.07.04 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony Creative Software
[2011.10.28 12:00:45 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\SplitMediaLabs
[2011.10.16 14:22:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.01.07 18:03:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TeamViewer
[2012.08.31 18:45:43 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TS3Client
[2010.01.09 15:39:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TuneUp Software
[2010.03.09 20:20:20 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ubisoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\uTorrent
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ventrilo
[2010.10.30 10:26:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vghd
[2010.04.05 14:12:53 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vidalia
[2010.01.17 12:52:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\VitySoft
[2012.12.27 18:54:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vlc
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vso
[2012.12.12 08:21:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Winamp
[2009.12.25 12:39:57 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\WinRAR
[2012.09.30 11:14:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\YCanPDF
< %APPDATA%\*.exe /s >
[2009.11.06 07:04:40 | 010,377,728 | ---- | M] () -- C:\Users\McDan\AppData\Roaming\CocoonSoftware\QMC\ffmpeg.exe
[2008.04.02 12:35:18 | 007,945,216 | ---- | M] () -- C:\Users\McDan\AppData\Roaming\CocoonSoftware\QMC\ffmpegHD.exe
[2010.03.01 22:24:32 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\McDan\AppData\Roaming\Facebook\uninstall.exe
[2012.07.15 16:00:21 | 000,331,776 | ---- | M] (Epic Games ) -- C:\Users\McDan\AppData\Roaming\InstallShield Installation Information\{6530FDAA-5B1F-4830-95BB-650E9804D239}\setup.exe
[2012.08.01 17:32:23 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\McDan\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2009.12.25 15:41:58 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_41028B857B5E6028C62C61.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_6FEFF9B68218417F98F549.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_DFE7BD1355D98DF3F18F46.exe
[2012.10.08 15:41:54 | 000,355,574 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{62FF6AF0-A718-4E31-A499-016BD655F060}\WebAlbum.exe
[2012.05.15 12:27:12 | 000,001,078 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{6C472DFC-6D44-4947-9E1A-F79A2469D953}\_511E40F8F51A826696DCAB.exe
[2012.05.15 12:27:12 | 000,001,078 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{6C472DFC-6D44-4947-9E1A-F79A2469D953}\_A17AA8D98E556D75E7296B.exe
[2012.10.03 20:56:18 | 000,005,430 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{80074966-5231-428D-9AE7-B7D5D2DC3246}\_45E5F1A4BC29289B0B1E70.exe
[2012.10.03 20:56:18 | 000,005,430 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{80074966-5231-428D-9AE7-B7D5D2DC3246}\_55F11AB420338FF650F1F4.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_1A1C4CB03D5FBD832295B4.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_437CE7B227D9C1C3DD188F.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_6FEFF9B68218417F98F549.exe
[2009.01.08 14:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"HydraVisionDesktopManager" = "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" -- [2011.09.23 20:35:54 | 000,393,216 | ---- | M] (AMD)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.12.08 01:32:23 | 000,916,960 | ---- | M] (Mozilla Corporation) MD5=5744FFF8E72D105C138DAE9E17BB29FE -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2011.06.11 21:08:57 | 000,748,336 | ---- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.12.30 00:28:52 | 000,000,512 | ---- | M] () MD5=E2F121627E32FE0375EFF1D35A8E1DF7 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2012.08.01 17:32:58 | 000,003,178 | ---- | M] () -- \Users\McDan\AppData\Roaming\Pixlromatic\Local Store\data\border\grunge\thumb\crack_multiply_stretch.jpg
< *keygen* /s >
< *loader* /s >
[2009.12.25 12:44:30 | 000,000,003 | ---- | M] () -- \7Loader.TAG
[2008.08.26 01:32:24 | 000,217,088 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS4\MXF_SDK_MetaMetadata_BinaryLoader_r.4.1.1.223.dll
[2012.08.27 20:33:18 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2008.02.28 14:26:06 | 000,111,912 | ---- | M] () -- \Program Files (x86)\Common Files\Nero\Shared\NSCLoader.dll
[2009.05.11 19:07:42 | 000,010,789 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\mm\MediaCtrl\ImageLoader.kc
[2009.05.11 19:07:44 | 000,003,500 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\widget\langloader.kc
[2009.05.11 19:07:44 | 000,012,803 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\widget\layoutloader.kc
[2007.12.27 05:47:44 | 000,046,080 | ---- | M] () -- \Program Files (x86)\Cheat Engine\Kernelmoduleunloader.exe
[2012.10.22 13:24:10 | 000,605,568 | ---- | M] () -- \Program Files (x86)\IObit\Advanced SystemCare 3\free-software-downloader.exe
[2009.10.26 21:52:34 | 000,214,528 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.exe
[2010.10.10 22:59:14 | 000,594,713 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.jar
[2009.10.06 23:48:58 | 000,000,113 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\img\hosterlogos\uploader.pl.png
[2009.10.30 19:18:06 | 000,003,264 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\IPAUploaderCom.class
[2010.10.10 22:59:53 | 000,006,975 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\UploaderPl.class
[2009.10.26 21:48:22 | 000,032,222 | ---- | M] () -- \Program Files (x86)\JDownloader\licenses\jdownloader.license
[2011.12.26 12:05:44 | 000,666,624 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.1\MTA\loader.dll
[2011.12.23 19:01:46 | 000,586,752 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.2\MTA\loader.dll
[2009.05.31 02:21:00 | 000,071,008 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2009.05.31 02:21:00 | 000,073,568 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll
[2009.10.03 16:11:50 | 000,245,760 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\DownloaderApp.exe
[2010.03.22 18:44:31 | 000,000,063 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\YouTube Downloader App.url
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\components\uriloader.xpt
[2009.09.25 14:00:00 | 000,001,849 | ---- | M] () -- \Program Files (x86)\TuneUp Utilities 2010\data\TuneUpUtilities.gadget\images\loader.gif
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Video Converter App\components\uriloader.xpt
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Wallpaper Maker App\components\uriloader.xpt
[2006.12.23 17:37:56 | 000,044,032 | ---- | M] () -- \Program Files (x86)\WinRAR\RarExtLoader.exe
[2010.03.05 05:55:00 | 000,488,144 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_BinaryLoader_r.4.2.2.319.dll
[2010.03.05 05:55:04 | 000,900,304 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader2_r.4.2.2.319.dll
[2010.03.05 05:55:08 | 000,789,200 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader_r.4.2.2.319.dll
[2008.11.26 16:38:28 | 000,733,184 | ---- | M] () -- \Program Files\Native Instruments\Service Center\Reloader.exe
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Program Files\Rainmeter – záloha\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Program Files\Rainmeter\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2009.09.25 14:00:00 | 000,001,849 | ---- | M] () -- \Program Files\Windows Sidebar\Shared Gadgets\TuneUpUtilities.gadget\images\loader.gif
[2011.12.12 15:39:13 | 000,666,624 | ---- | M] () -- \ProgramData\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2011.12.26 12:05:44 | 000,581,120 | ---- | M] () -- \ProgramData\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp__bak_\MTA\loader.dll
[2008.02.04 12:32:50 | 000,000,232 | ---- | M] () -- \ProgramData\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.02.29 07:49:32 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.02.29 07:49:32 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2011.12.12 15:39:13 | 000,666,624 | ---- | M] () -- \Users\All Users\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2011.12.26 12:05:44 | 000,581,120 | ---- | M] () -- \Users\All Users\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp__bak_\MTA\loader.dll
[2008.02.04 12:32:50 | 000,000,232 | ---- | M] () -- \Users\All Users\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.02.29 07:49:32 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.02.29 07:49:32 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png
[2012.12.29 19:54:38 | 000,000,847 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BH146FUR\loader[1].gif
[2012.12.29 00:05:41 | 000,005,150 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BH146FUR\salmonLoader_24x24[1].gif
[2012.12.29 00:05:41 | 000,003,471 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RJM3UUHA\salmonLoader_16x16[1].gif
[2011.09.05 18:39:46 | 000,515,072 | ---- | M] () -- \Users\McDan\AppData\Local\MTA San Andreas\upcache\_mtasa-1.0.5-rc-03127-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2010.02.26 07:41:34 | 000,847,040 | ---- | M] () -- \Users\McDan\AppData\Roaming\Facebook\axfbootloader.dll
[2010.10.10 22:58:07 | 000,000,394 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader Support.lnk
[2010.10.10 22:58:08 | 000,001,165 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\Uninstall JDownloader.lnk
[2010.03.22 18:44:31 | 000,000,998 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App Uninstall.lnk
[2010.03.22 18:44:31 | 000,001,285 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App Website.lnk
[2010.03.22 18:44:31 | 000,002,178 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App.lnk
[2012.11.07 14:44:34 | 000,010,145 | ---- | M] () -- \Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}\modules\ExternalLibraryLoader.jsm
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Users\McDan\Documents\Rainmeter\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2009.12.25 16:49:20 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2012.12.30 00:22:19 | 000,022,930 | ---- | M] () -- \Windows\Prefetch\RAREXTLOADER.EXE-F523F60B.pf
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2009.07.14 02:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 02:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_66c2596d956d1920\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_67770e0aae6a7c68\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 16:17:49 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2009.07.14 16:17:49 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.efi.mui_35ee487d
[2009.07.14 16:17:49 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.exe.mui_3bc5b827
[2009.07.14 16:17:49 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.efi.mui_f412814e
[2009.07.14 16:17:49 | 000,030,288 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.exe.mui_ff8b5358
[2011.06.11 20:59:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.06.11 20:59:23 | 000,640,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winload.efi_75834aa0
[2011.06.11 20:59:23 | 000,603,976 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winload.exe_75835076
[2011.06.11 20:59:23 | 000,556,928 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winresume.efi_85cd069f
[2011.06.11 20:59:23 | 000,518,160 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winresume.exe_85cd1215
[2009.07.14 03:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2009.07.14 16:15:51 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2009.07.14 03:13:42 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef.manifest
[2011.02.05 14:09:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.02.05 14:04:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2011.02.05 18:34:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.02.05 14:09:57 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 03:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_0aa3bde9dd0fa7ea\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_0b587286f60d0b32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:07 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 600 bytes -> C:\ProgramData\Temp:05EE1EEF
@Alternate Data Stream - 1444 bytes -> C:\ProgramData\Microsoft:mcSoJRGtYDaYSlvdNQcnYc
@Alternate Data Stream - 1297 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:UWyX0MxK8pSntCWFgm4NB7hlnh4
@Alternate Data Stream - 1211 bytes -> C:\ProgramData\Microsoft:sDeIvgDLB2JBm6MbcGhJr72
< End of report >
========== Custom Scans ==========
< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,568 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\ERDNT\cache64\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\SysNative\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\ERDNT\cache86\explorer.exe
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\explorer.exe
[2012.10.22 14:13:47 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2012.10.22 14:13:46 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2012.10.22 14:13:46 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2012.10.22 14:13:47 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\SysWOW64\explorer.exe
[2012.10.22 14:13:47 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2012.10.22 14:13:46 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2012.10.22 14:13:46 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2009.10.24 22:33:24 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=67B922CB22FABE12B97F48E5C93D9F2F -- C:\Windows\Resources\Themes\Resources\x64 (64-bit)\explorer.exe
[2009.10.25 00:20:06 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=6ACD1B0031B0E3E9DF179138CC1EFBA8 -- C:\Windows\Resources\Themes\Resources\x86 (32-bit)\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2012.10.22 14:13:46 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2012.10.22 14:13:46 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\SysNative\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache86\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\ERDNT\cache64\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\ERDNT\cache64\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache86\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\ERDNT\cache64\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2010.06.14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\ERDNT\cache64\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\SysNative\drivers\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache86\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\ERDNT\cache64\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< >
< %systemroot%*.* /U /s >
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[15 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[3 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[286 C:\Windows\temp\*.tmp files -> C:\Windows\temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.07.15 11:45:10 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\.minecraft
[2010.02.22 17:12:41 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Acronis
[2012.11.20 22:42:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Adobe
[2011.10.27 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Adobe Mini Bridge CS5
[2011.01.24 16:32:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Antares
[2010.03.25 11:55:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\AnvSoft
[2012.03.19 23:27:16 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Apple Computer
[2011.04.10 14:44:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ArcSoft
[2010.01.09 15:32:15 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ATI
[2011.12.05 17:19:17 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Audacity
[2010.08.04 13:36:26 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Avnex
[2010.02.28 11:55:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BeautyPilot
[2010.02.19 21:04:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Bioshock2
[2010.04.28 16:40:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\BitSpirit
[2010.05.29 17:35:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\bizarre creations
[2010.05.15 11:33:59 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.01.05 18:10:31 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CocoonSoftware
[2011.11.13 14:59:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.12.26 16:17:06 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\CyberLink
[2012.12.12 08:21:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DAEMON Tools Lite
[2010.07.10 19:27:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\DivX
[2009.12.25 13:51:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ESET
[2010.03.01 22:24:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Facebook
[2012.11.06 20:52:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FileZilla
[2010.08.21 16:34:54 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Firefly Studios
[2011.07.15 15:05:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\FreeScreenToVideo
[2012.10.22 11:48:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Garena
[2010.02.23 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\GetRightToGo
[2011.11.17 21:31:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\go
[2010.05.31 14:06:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ICQ
[2009.12.25 12:10:12 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Identities
[2009.12.25 15:38:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\InstallShield
[2012.07.15 16:02:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\InstallShield Installation Information
[2012.10.22 13:24:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\IObit
[2009.12.28 14:57:51 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LangSoft
[2009.12.25 15:41:58 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Leadertech
[2009.12.25 15:42:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Logitech
[2011.05.16 18:28:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\LolClient
[2009.12.25 12:20:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Macromedia
[2010.03.02 16:38:30 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MagicEffect Photo
[2011.06.24 14:16:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\MAGIX
[2012.12.25 14:08:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Malwarebytes
[2010.08.29 17:21:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\ManyCam
[2011.12.16 21:58:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Maxprog
[2009.07.14 16:36:38 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Media Center Programs
[2012.12.24 16:17:49 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Media Player Classic
[2012.06.17 20:41:18 | 000,000,000 | --SD | M] -- C:\Users\McDan\AppData\Roaming\Microsoft
[2010.10.12 16:29:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mirillis
[2010.02.23 10:11:56 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Moyea
[2010.03.06 17:37:32 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mozilla
[2011.04.10 19:19:50 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Mumble
[2010.06.30 18:20:25 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Need for Speed World
[2010.01.28 14:08:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Nero
[2010.03.06 17:37:29 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Octoshape
[2011.01.12 18:29:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\OnLive App
[2010.01.30 23:01:40 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Opera
[2011.09.29 14:22:35 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Origin
[2012.07.04 21:49:13 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\PACE Anti-Piracy
[2012.08.01 17:32:55 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Pixlromatic
[2010.03.22 13:12:22 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Prison Break
[2009.12.25 21:06:00 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Publish Providers
[2011.12.19 00:43:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\QIP
[2010.05.25 11:17:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Rainmeter
[2010.12.12 11:46:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\RayV
[2010.03.22 19:02:07 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Red Kawa
[2010.03.22 18:46:39 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Regensoft
[2010.01.16 09:52:19 | 000,000,000 | RH-D | M] -- C:\Users\McDan\AppData\Roaming\SecuROM
[2012.11.25 00:33:15 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Skype
[2011.05.28 09:44:05 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\skypePM
[2010.01.30 16:19:09 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Softland
[2010.12.19 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony
[2012.07.04 21:49:14 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Sony Creative Software
[2011.10.28 12:00:45 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\SplitMediaLabs
[2011.10.16 14:22:52 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.01.07 18:03:47 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TeamViewer
[2012.08.31 18:45:43 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TS3Client
[2010.01.09 15:39:19 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\TuneUp Software
[2010.03.09 20:20:20 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ubisoft
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\uTorrent
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Ventrilo
[2010.10.30 10:26:11 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vghd
[2010.04.05 14:12:53 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vidalia
[2010.01.17 12:52:04 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\VitySoft
[2012.12.27 18:54:18 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\vlc
[2012.04.11 22:42:28 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Vso
[2012.12.12 08:21:01 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\Winamp
[2009.12.25 12:39:57 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\WinRAR
[2012.09.30 11:14:27 | 000,000,000 | ---D | M] -- C:\Users\McDan\AppData\Roaming\YCanPDF
< %APPDATA%\*.exe /s >
[2009.11.06 07:04:40 | 010,377,728 | ---- | M] () -- C:\Users\McDan\AppData\Roaming\CocoonSoftware\QMC\ffmpeg.exe
[2008.04.02 12:35:18 | 007,945,216 | ---- | M] () -- C:\Users\McDan\AppData\Roaming\CocoonSoftware\QMC\ffmpegHD.exe
[2010.03.01 22:24:32 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\McDan\AppData\Roaming\Facebook\uninstall.exe
[2012.07.15 16:00:21 | 000,331,776 | ---- | M] (Epic Games ) -- C:\Users\McDan\AppData\Roaming\InstallShield Installation Information\{6530FDAA-5B1F-4830-95BB-650E9804D239}\setup.exe
[2012.08.01 17:32:23 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\McDan\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2009.12.25 15:41:58 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_41028B857B5E6028C62C61.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_6FEFF9B68218417F98F549.exe
[2010.02.22 15:43:48 | 000,285,478 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{48EB0E22-B055-44B5-B566-057F145CB7E7}\_DFE7BD1355D98DF3F18F46.exe
[2012.10.08 15:41:54 | 000,355,574 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{62FF6AF0-A718-4E31-A499-016BD655F060}\WebAlbum.exe
[2012.05.15 12:27:12 | 000,001,078 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{6C472DFC-6D44-4947-9E1A-F79A2469D953}\_511E40F8F51A826696DCAB.exe
[2012.05.15 12:27:12 | 000,001,078 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{6C472DFC-6D44-4947-9E1A-F79A2469D953}\_A17AA8D98E556D75E7296B.exe
[2012.10.03 20:56:18 | 000,005,430 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{80074966-5231-428D-9AE7-B7D5D2DC3246}\_45E5F1A4BC29289B0B1E70.exe
[2012.10.03 20:56:18 | 000,005,430 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{80074966-5231-428D-9AE7-B7D5D2DC3246}\_55F11AB420338FF650F1F4.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_1A1C4CB03D5FBD832295B4.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_437CE7B227D9C1C3DD188F.exe
[2011.10.04 12:51:07 | 000,079,307 | R--- | M] () -- C:\Users\McDan\AppData\Roaming\Microsoft\Installer\{915153F8-1429-40AE-B005-E3BFA7097672}\_6FEFF9B68218417F98F549.exe
[2009.01.08 14:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Users\McDan\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"HydraVisionDesktopManager" = "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" -- [2011.09.23 20:35:54 | 000,393,216 | ---- | M] (AMD)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.12.08 01:32:23 | 000,916,960 | ---- | M] (Mozilla Corporation) MD5=5744FFF8E72D105C138DAE9E17BB29FE -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2011.06.11 21:08:57 | 000,748,336 | ---- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.12.30 00:28:52 | 000,000,512 | ---- | M] () MD5=E2F121627E32FE0375EFF1D35A8E1DF7 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2012.08.01 17:32:58 | 000,003,178 | ---- | M] () -- \Users\McDan\AppData\Roaming\Pixlromatic\Local Store\data\border\grunge\thumb\crack_multiply_stretch.jpg
< *keygen* /s >
< *loader* /s >
[2009.12.25 12:44:30 | 000,000,003 | ---- | M] () -- \7Loader.TAG
[2008.08.26 01:32:24 | 000,217,088 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS4\MXF_SDK_MetaMetadata_BinaryLoader_r.4.1.1.223.dll
[2012.08.27 20:33:18 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2008.02.28 14:26:06 | 000,111,912 | ---- | M] () -- \Program Files (x86)\Common Files\Nero\Shared\NSCLoader.dll
[2009.05.11 19:07:42 | 000,010,789 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\mm\MediaCtrl\ImageLoader.kc
[2009.05.11 19:07:44 | 000,003,500 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\widget\langloader.kc
[2009.05.11 19:07:44 | 000,012,803 | ---- | M] () -- \Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\widget\layoutloader.kc
[2007.12.27 05:47:44 | 000,046,080 | ---- | M] () -- \Program Files (x86)\Cheat Engine\Kernelmoduleunloader.exe
[2012.10.22 13:24:10 | 000,605,568 | ---- | M] () -- \Program Files (x86)\IObit\Advanced SystemCare 3\free-software-downloader.exe
[2009.10.26 21:52:34 | 000,214,528 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.exe
[2010.10.10 22:59:14 | 000,594,713 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.jar
[2009.10.06 23:48:58 | 000,000,113 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\img\hosterlogos\uploader.pl.png
[2009.10.30 19:18:06 | 000,003,264 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\IPAUploaderCom.class
[2010.10.10 22:59:53 | 000,006,975 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\UploaderPl.class
[2009.10.26 21:48:22 | 000,032,222 | ---- | M] () -- \Program Files (x86)\JDownloader\licenses\jdownloader.license
[2011.12.26 12:05:44 | 000,666,624 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.1\MTA\loader.dll
[2011.12.23 19:01:46 | 000,586,752 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.2\MTA\loader.dll
[2009.05.31 02:21:00 | 000,071,008 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2009.05.31 02:21:00 | 000,073,568 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll
[2009.10.03 16:11:50 | 000,245,760 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\DownloaderApp.exe
[2010.03.22 18:44:31 | 000,000,063 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\YouTube Downloader App.url
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Regensoft\Downloader App\components\uriloader.xpt
[2009.09.25 14:00:00 | 000,001,849 | ---- | M] () -- \Program Files (x86)\TuneUp Utilities 2010\data\TuneUpUtilities.gadget\images\loader.gif
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Video Converter App\components\uriloader.xpt
[2009.09.21 14:04:18 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Wallpaper Maker App\components\uriloader.xpt
[2006.12.23 17:37:56 | 000,044,032 | ---- | M] () -- \Program Files (x86)\WinRAR\RarExtLoader.exe
[2010.03.05 05:55:00 | 000,488,144 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_BinaryLoader_r.4.2.2.319.dll
[2010.03.05 05:55:04 | 000,900,304 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader2_r.4.2.2.319.dll
[2010.03.05 05:55:08 | 000,789,200 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader_r.4.2.2.319.dll
[2008.11.26 16:38:28 | 000,733,184 | ---- | M] () -- \Program Files\Native Instruments\Service Center\Reloader.exe
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Program Files\Rainmeter – záloha\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Program Files\Rainmeter\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2009.09.25 14:00:00 | 000,001,849 | ---- | M] () -- \Program Files\Windows Sidebar\Shared Gadgets\TuneUpUtilities.gadget\images\loader.gif
[2011.12.12 15:39:13 | 000,666,624 | ---- | M] () -- \ProgramData\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2011.12.26 12:05:44 | 000,581,120 | ---- | M] () -- \ProgramData\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp__bak_\MTA\loader.dll
[2008.02.04 12:32:50 | 000,000,232 | ---- | M] () -- \ProgramData\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.02.29 07:49:32 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.02.29 07:49:32 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2011.12.12 15:39:13 | 000,666,624 | ---- | M] () -- \Users\All Users\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2011.12.26 12:05:44 | 000,581,120 | ---- | M] () -- \Users\All Users\MTA San Andreas All\1.1\upcache\_mtasa-1.1.1-rc-03534-0-000-files-all-signed.exe_tmp__bak_\MTA\loader.dll
[2008.02.04 12:32:50 | 000,000,232 | ---- | M] () -- \Users\All Users\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.02.29 07:49:32 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.02.29 07:49:32 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png
[2010.08.26 10:40:20 | 000,057,728 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png
[2012.12.29 19:54:38 | 000,000,847 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BH146FUR\loader[1].gif
[2012.12.29 00:05:41 | 000,005,150 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BH146FUR\salmonLoader_24x24[1].gif
[2012.12.29 00:05:41 | 000,003,471 | ---- | M] () -- \Users\McDan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RJM3UUHA\salmonLoader_16x16[1].gif
[2011.09.05 18:39:46 | 000,515,072 | ---- | M] () -- \Users\McDan\AppData\Local\MTA San Andreas\upcache\_mtasa-1.0.5-rc-03127-0-000-files-all-signed.exe_tmp_\MTA\loader.dll
[2010.02.26 07:41:34 | 000,847,040 | ---- | M] () -- \Users\McDan\AppData\Roaming\Facebook\axfbootloader.dll
[2010.10.10 22:58:07 | 000,000,394 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader Support.lnk
[2010.10.10 22:58:08 | 000,001,165 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\Uninstall JDownloader.lnk
[2010.03.22 18:44:31 | 000,000,998 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App Uninstall.lnk
[2010.03.22 18:44:31 | 000,001,285 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App Website.lnk
[2010.03.22 18:44:31 | 000,002,178 | ---- | M] () -- \Users\McDan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ostatní programy\Regensoft\YouTube Downloader App\YouTube Downloader App.lnk
[2012.11.07 14:44:34 | 000,010,145 | ---- | M] () -- \Users\McDan\AppData\Roaming\Mozilla\Firefox\Profiles\ak3n1q6b.default\extensions\{44658024-1a78-446b-90c0-ce912bf6f44b}\modules\ExternalLibraryLoader.jsm
[2010.05.18 21:53:54 | 000,001,461 | ---- | M] () -- \Users\McDan\Documents\Rainmeter\Skins\Gnometer\Launcher\Icons\jdownloader.png
[2009.12.25 16:49:20 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2012.12.30 00:22:19 | 000,022,930 | ---- | M] () -- \Windows\Prefetch\RAREXTLOADER.EXE-F523F60B.pf
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2009.07.14 02:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 02:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_66c2596d956d1920\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_67770e0aae6a7c68\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 16:17:49 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2009.07.14 16:17:49 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.efi.mui_35ee487d
[2009.07.14 16:17:49 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.exe.mui_3bc5b827
[2009.07.14 16:17:49 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.efi.mui_f412814e
[2009.07.14 16:17:49 | 000,030,288 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.exe.mui_ff8b5358
[2011.06.11 20:59:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.06.11 20:59:23 | 000,640,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winload.efi_75834aa0
[2011.06.11 20:59:23 | 000,603,976 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winload.exe_75835076
[2011.06.11 20:59:23 | 000,556,928 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winresume.efi_85cd069f
[2011.06.11 20:59:23 | 000,518,160 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66_winresume.exe_85cd1215
[2009.07.14 03:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2009.07.14 16:15:51 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2009.07.14 03:13:42 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef.manifest
[2011.02.05 14:09:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.02.05 14:04:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2011.02.05 18:34:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.02.05 14:09:57 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 03:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_0aa3bde9dd0fa7ea\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_0b587286f60d0b32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:07 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.22 14:18:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 600 bytes -> C:\ProgramData\Temp:05EE1EEF
@Alternate Data Stream - 1444 bytes -> C:\ProgramData\Microsoft:mcSoJRGtYDaYSlvdNQcnYc
@Alternate Data Stream - 1297 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:UWyX0MxK8pSntCWFgm4NB7hlnh4
@Alternate Data Stream - 1211 bytes -> C:\ProgramData\Microsoft:sDeIvgDLB2JBm6MbcGhJr72
< End of report >
Re: Ubývající místo na C:
OTL Extras logfile created on: 30.12.2012 0:23:57 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\McDan\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 33,28% Memory free
7,98 Gb Paging File | 3,77 Gb Available in Paging File | 47,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 0,70 Gb Free Space | 1,40% Space Free | Partition Type: NTFS
Drive D: | 440,01 Gb Total Space | 79,10 Gb Free Space | 17,98% Space Free | Partition Type: NTFS
Drive E: | 440,01 Gb Total Space | 114,03 Gb Free Space | 25,92% Space Free | Partition Type: NTFS
Drive I: | 1,49 Gb Total Space | 1,22 Gb Free Space | 81,81% Space Free | Partition Type: FAT32
Drive K: | 1862,89 Gb Total Space | 1211,80 Gb Free Space | 65,05% Space Free | Partition Type: NTFS
Computer Name: PRIVATE | User Name: McDan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe (Opera Software)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Games\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Games\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitSpirit\BitSpirit.exe" = D:\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client -- (LANSPIRIT.NET)
"D:\BitSpirit\BitSpirit.exe" = D:\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client -- (LANSPIRIT.NET)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0489A3D0-12FD-47DA-B6C6-E95B1077CF0D}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{04B69B15-07C2-4D18-A6DD-A7C6010963C7}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{084D5793-AAF4-4680-9963-A1837F65F11C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0E6FD9C4-C15C-4898-9B63-99C9C7744431}" = lport=137 | protocol=17 | dir=in | app=system |
"{13F4C3B2-6868-4C7D-AE39-3F70F79C36B1}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{16C0262F-306D-4AEB-9FA8-F95ED765CB46}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1AFCED28-4BD7-4C8A-84C6-0EF956DB5438}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C702574-E5B0-4E11-B521-20E200564FF5}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2398E5B0-B4D3-4461-9C51-3480B644D7DF}" = lport=58821 | protocol=17 | dir=in | name=pando media booster |
"{3137879F-9B51-49AB-A85F-DA7D42A3ED78}" = rport=10243 | protocol=6 | dir=out | app=system |
"{35198690-99E8-4394-8C2E-FD1631B5D3BB}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{361C84BE-38C5-4D01-BF48-8C6D650199C9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{41AB98A9-30F0-4B2E-8A84-0F27DF31DCC7}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{436FFCA1-B462-4DD4-BA21-B22027EBE893}" = lport=56770 | protocol=17 | dir=in | name=pando media booster |
"{492D2962-6C15-4345-BBFA-D0950AA6B5C3}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5D89C165-F477-47DF-B268-7191BAE04B79}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6ACADC00-23E3-4B58-A646-828A2CC6DDCB}" = rport=137 | protocol=17 | dir=out | app=system |
"{6BE62B86-5E08-4AE2-846A-98670D353E99}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{7382F18D-DCB4-4F69-AEF8-CF6E6C68B217}" = lport=58821 | protocol=6 | dir=in | name=pando media booster |
"{76AA2155-AE17-4969-8810-1B5C7E97249F}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{79A0CE0B-33E1-416B-B72B-4F167E5C741E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7C13DEB2-E17A-4630-A8A0-3A67102BBB30}" = lport=445 | protocol=6 | dir=in | app=system |
"{81E45406-23BD-448D-8D70-6B54F800091A}" = lport=58821 | protocol=17 | dir=in | name=pando media booster |
"{83A9F1D6-F3CE-4A51-81D6-83FCBD82C2D0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{876466B7-1415-46D3-B1E8-A476C93D6DDC}" = lport=58821 | protocol=6 | dir=in | name=pando media booster |
"{8B6C6A50-6A27-487D-BC76-08411A5D8AB0}" = lport=138 | protocol=17 | dir=in | app=system |
"{92305CD8-76F7-4571-96D1-E507F454C281}" = lport=56770 | protocol=6 | dir=in | name=pando media booster |
"{944F5F98-37FC-4929-8692-C65C68737BB2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9B91CDD1-CDAE-4F79-8B90-EBD37D5C2C56}" = lport=56770 | protocol=6 | dir=in | name=pando media booster |
"{9E9668FF-0571-407D-8EAA-9A5C9C2E67F4}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{AB4AB70A-ACEF-4A24-89E2-B38C6BBA7242}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B7442E57-E71A-4564-BA4C-D888649E9118}" = rport=138 | protocol=17 | dir=out | app=system |
"{B7D1E1EF-D5A8-4A92-A294-C125CFDD1959}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C240F228-DC91-41D0-BD5E-22F63C4EFB96}" = lport=56770 | protocol=17 | dir=in | name=pando media booster |
"{CF7D5126-CDAD-45A4-849D-08E2FE0770D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{D741ABD3-2E49-4BC6-A4D8-C09DE43E54FB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DA7123BC-1366-40DF-8941-4AAF91129440}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{DFA67B3B-C9FC-4AA3-AF1A-76905E3CFD3A}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{ECC87B76-F930-4FA4-991A-E5D844C6C591}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED0ECD59-4008-4C59-A6CA-D1FC00765A97}" = rport=139 | protocol=6 | dir=out | app=system |
"{EDAD54D6-84DD-4A11-AFDD-4DB8F2F028E9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{013F8557-0A36-4F0C-9E46-3FAB39D04CBF}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0268AFD2-4E67-4A96-B4DB-D36AFFACA250}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0321F6F8-019C-438F-99E0-7C8643C301D5}" = protocol=17 | dir=in | app=e:\bitspirit\bitspirit.exe |
"{032785B0-EDB1-4398-BD50-F16EBFB0D622}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{0464213C-15C8-4514-8909-22FC1F438119}" = protocol=17 | dir=in | app=d:\games\crysis\bin64\crysisdedicatedserver.exe |
"{05025785-2535-4905-9B23-0C21E844CB0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{054743CA-E9C5-42BA-8F7C-81B9C3B630CD}" = protocol=6 | dir=in | app=d:\games\wolfenstein\mp\wolf2mplite.exe |
"{05C62F72-A021-4F29-ACA0-84F008D56317}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{0632CCF3-1BF8-4CDE-9DB7-AA6E42FD7E4F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version5\teamviewer.exe |
"{0D5BA73A-2DF0-4E82-B2C4-8B4CDF08811C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0F0E1933-941A-44D3-813E-0C43080AEDAF}" = protocol=6 | dir=in | app=d:\games\rockstar games\rockstar games social club\rgsclauncher.exe |
"{129EB119-FBCD-49D9-8D7C-3D041829624B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{135B024F-1009-4ECC-B5DC-7242DE923F75}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{14D3D352-82CC-44C5-8FBC-62BB5C6E9735}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{1A4FEFBB-D344-40AB-BB76-AFED34066352}" = protocol=17 | dir=in | app=d:\games\crysis\bin64\crysis.exe |
"{1BAE744D-1770-42AB-A6C1-3E7F4658E779}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1C2A09AA-4C96-48D0-8BB7-C389A0A06265}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{1C99E604-9F0E-45D5-9FF4-5D9D55A34988}" = protocol=6 | dir=in | app=d:\games\battlefield bad company 2\bfbc2updater.exe |
"{1FB548B0-4370-4C08-8BCB-E85D4D1836E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{23FBB8F6-2C70-43CE-BA3E-92F3F5DD7D42}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{248531BA-8024-43C2-8137-58DCF37B9D48}" = protocol=17 | dir=in | app=d:\games\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{24857FF2-BC9B-47D4-8E82-64FD89D12B0F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{252B213F-5865-4E3D-A124-4707564DBA3D}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{25694ED3-BCBA-439E-9BFB-4A7420CB0D36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{26400321-A497-4991-91C3-782A7F38444B}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2CAF33FF-8042-4F88-87B5-E60C170C8B4C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2CC8AEE8-13D9-4366-8BF6-0D49A9E238E5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{2D3EDCBF-AD44-4A6A-AD40-9E11EA7A2924}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{309D3FAA-1E6D-4816-9403-F4B42837A6C1}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{353F9765-5A96-402A-8C5D-40104DB0A485}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{37E7D51C-F318-4E76-B0F8-6DB0A25BD091}" = dir=in | app=e:\itunes\itunes.exe |
"{3CBA84B8-EE24-4260-9FED-EFA67AA46BA7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3E094219-BBF8-417C-A424-13BC40C10DA4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F3D04F1-65DD-4DB4-A583-8CA7A6259F47}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F54EB48-2C91-49B0-B148-E6AE898E1C33}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2.exe |
"{40A47B36-A849-4518-B54E-23AD5BD41647}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe |
"{40DE6094-F180-4664-B2FD-6ABFB500042B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{425554B1-DDF5-46FC-810B-772AE00A2084}" = protocol=17 | dir=in | app=d:\games\battlefield bad company 2\bfbc2updater.exe |
"{433765B4-FE6B-4BB7-A068-309037565355}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{495D767A-F8BF-41A2-A6E5-145A2712E3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{49C2C9E8-DC61-4A6F-BA26-A6B38A9AC665}" = protocol=17 | dir=in | app=d:\games\wolfenstein\mp\wolf2mp.exe |
"{4C8B222F-12D0-48A0-846F-A6ED2D682D92}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike beta\hl.exe |
"{4C9434DA-0937-4190-9F78-AA7D6D99E3F4}" = protocol=17 | dir=in | app=d:\games\crysis\bin32\crysisdedicatedserver.exe |
"{4CB5696D-C7DA-42E4-9435-53B7570EB8E8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E973438-7A9D-4E6A-B3BD-6BE9C1F08D51}" = protocol=6 | dir=in | app=d:\games\wolfenstein\mp\wolf2mp.exe |
"{4F68F53B-0DD7-4C71-B595-A56EA07F244E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{4F6CE11A-59C6-450C-9488-B093996E436A}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{4FF9459F-0DC3-443B-A740-9D8252731F21}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{50A4DA97-0F82-4604-87E9-12B3A6A721E4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{519253B2-F845-4EE9-B1AE-C5D69A6786ED}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{536B44C9-14C1-40A5-B1A2-49F4860CB3CE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{56B3DF7A-8A57-41A1-96BF-A78422F897A3}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version5\teamviewer.exe |
"{5DE74087-83CA-48A5-A2C9-75C888F60E5C}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\srcds.exe |
"{5E369F58-08C8-4F14-A679-D39D22454513}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5E386EDC-A611-499B-AE8B-0B39E3E5AB08}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{5EEF754B-221D-4A31-A7D0-75F6E142EEF3}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{603E6709-C6F1-4EA2-9EE5-E8B554F0B2EB}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\swarm.exe |
"{62AA59FE-2ADB-4524-B9AE-5FA38C99FD5B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{63F99224-10DF-44FB-BC54-3A178578B0E4}" = protocol=6 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\gu.exe |
"{64CECCD3-F643-43AA-BA67-F9C644CAB5C3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{688985E5-C6B0-43D6-B067-DA061FC70AB7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72C3B2A4-ADBE-4D5E-8CF9-B71D400EC148}" = protocol=6 | dir=in | app=d:\games\crysis\bin64\crysisdedicatedserver.exe |
"{76853333-97F2-42DC-8101-CE785894E029}" = dir=in | app=c:\users\mcdan\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{76A63ADF-3732-402A-8160-D9E031624527}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{76B2A9BF-4487-42A7-A79B-A1A2DECF8369}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{76FDEAF9-A30E-4768-A300-990160E3FDD2}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{7CF71179-C457-429E-AF06-7494B791A97B}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7DC9181E-713C-4AB8-889B-86DA567A057C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{805F2BF3-6DE5-465B-8849-F857C39A116D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8125FDDE-F415-450C-B147-1CBC5226C401}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{82B2AF7C-6740-4237-B7AB-A3321ACE303C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{83C0C4F1-3FE7-46DE-8A2F-5DCB6C2A0215}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{87741D5B-8322-492A-B991-2EA5F1332142}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8B29388B-D46A-42A3-AE21-1D30A7FCFB11}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8B2B8983-FD3A-4BA8-B4A9-9037F8A77D5F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{8BE2654C-3AA9-4FE4-8060-2737F1A15EA1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8CCA212C-F738-4FDD-92BC-5192A7EF16FE}" = protocol=17 | dir=in | app=d:\games\wolfenstein\mp\wolf2mplite.exe |
"{8D65C746-0750-48C7-B9B2-8FF043054514}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9294046C-BBE6-49B4-9185-CC4691CF6674}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{92DB89E6-D9BB-4B74-AFC0-5C221DFF4E7C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{92F384DA-68FC-471E-8329-397E7C25A49B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{93D24A58-BBDA-4BB7-98CB-B12B16A4387C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{953BD51F-18F3-4111-88B9-6F86F3225CD4}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{959B9661-FB25-4CF9-9E1E-CF5A0D6DBF7C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{95B98B50-83ED-472A-997E-CE3FA18D6FE6}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike beta\hl.exe |
"{95DD295C-F60F-4CFE-B434-2532F06C807A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{971B327F-6D51-4516-A0DC-6B777F226EBF}" = protocol=6 | dir=in | app=d:\games\crysis\bin64\crysis.exe |
"{974778DC-F2C7-4364-AFA1-85CCD10F93D4}" = protocol=6 | dir=in | app=d:\games\crysis\bin32\crysis.exe |
"{9835EEDB-3B45-424C-9552-CE3E5A80AAB6}" = protocol=17 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{987A183D-CF50-4455-A396-0C69890F37D5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{99533A79-25D0-4800-8DE6-D48BE66B7719}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdan\counter-strike\hl.exe |
"{9A3D51C7-3FFE-44E2-A185-B53C1DA96EFC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9D626B26-4462-4B28-9E4A-432371357A34}" = protocol=6 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{9DB71A27-FD05-43CD-9D69-8758F6076E4C}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"{9E96E1B2-6EF8-4077-8C26-B4A7A29E8FF5}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{9FD82C43-9F87-4EBC-A6E5-95B48607FB57}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A3E43E60-F6E2-4BC6-A8DB-66AE109FE3BF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A4BEB285-DB58-4345-BA4D-B996A79AE6EC}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A6A34100-6ACB-468E-AE7B-053C4C9A32CA}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"{A7481187-C0FB-4239-99BE-EC339AB20C4F}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A9671566-0B5F-4179-9C99-4CE20B6F6215}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{AB7292D4-77F7-4544-8135-A4F9D4F500EE}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\half-life\hl.exe |
"{ACAE93F0-AAD2-460C-B432-8C339225DDF8}" = protocol=6 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"{ADBF85B8-2FB3-47DF-B14F-F08A8A58D10D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AF61507F-D2B8-48D1-B0D6-B3E53C437559}" = protocol=17 | dir=in | app=d:\games\crysis\bin32\crysis.exe |
"{B19B041B-9881-4C2A-AA46-7871638126D9}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B2888C4D-AC4F-41FB-9F61-CEAE86A048EA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B3386B27-6940-4679-86B1-84F37EDB7103}" = protocol=17 | dir=in | app=c:\program files (x86)\opera 10.50 labs\opera.exe |
"{B5827DF1-EF0D-4653-910D-7DE1C3824C28}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B7F91828-DAFC-4646-AEBE-4A465F167853}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B887D071-32D6-444E-9196-AD9277F9FB57}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{B8D76146-14C0-4828-8088-DABE1287AEA4}" = protocol=6 | dir=in | app=d:\games\crysis\bin32\crysisdedicatedserver.exe |
"{B9A0D469-5BE1-45DA-985F-DE125B26303F}" = protocol=6 | dir=in | app=e:\bitspirit\bitspirit.exe |
"{BA27073A-2BDF-40E7-A42C-AB4883C55920}" = protocol=6 | dir=in | app=d:\games\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{BB56DBB6-CC08-42B9-97E0-DE0A93570F67}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C0D64C35-EB9B-41E1-A8F4-157AD6E86458}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1CFC975-1AB1-4CAD-8DB5-8B2F0D3D4613}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe |
"{C45869E7-1EEA-411E-BDDF-F201C898C589}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C69C0C06-0830-46CA-A0CF-4BFF1F527490}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{C6F78D38-F355-484B-BDCE-5AE379D457E1}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\srcds.exe |
"{C7BCEFB2-1D90-477A-A5CD-DA4EB74A6CA5}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{C8F5FC51-9A9A-47E5-8B40-72859625DCE0}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{CA185CE8-CDA9-487C-8573-E6A41B2EF319}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CA5AB1F5-BC32-402E-A421-7EFFD47FC37B}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{CEBA2C78-5203-413D-A0F7-F7F314F203C9}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{CF797C54-DA62-43D0-91D0-49862D9B702B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{D03211AC-2F25-4423-A7D9-EF6C6182E6BE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D304916F-F8CF-463E-978A-25A814D22BE1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D354BDEB-FEEA-4E12-81CC-0617AFC1433F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{D36068CE-3071-462E-8CCF-5595B7BCEF06}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dota 2 beta\dota.exe |
"{D4CC42AE-7844-4081-AE0F-03206377BC41}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D4F06E19-5A0A-4EE9-89BA-C94E32FF4835}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D6A14561-3391-40B6-89BD-7AF73B001B1D}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdan\counter-strike\hl.exe |
"{D92ABB93-C376-4DE7-8432-F1878560F672}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DE133F80-B885-4397-AE3A-F01884F3A2B4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF66FCDD-EA0D-49CE-B2EE-52B5FACA2E01}" = protocol=6 | dir=out | app=system |
"{E0AF0F24-A7BB-4437-80BD-EE94C0D71BB1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E142827B-1665-4405-8BB4-4AA3F1205A15}" = protocol=17 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\gu.exe |
"{E358902F-FA58-4A59-B139-7F351B26B7E1}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{E660C072-4676-4A31-B02D-A9334EEDF8A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E66FD5B4-352F-4DB4-BDD9-4EE518FA0E9D}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dota 2 beta\dota.exe |
"{E6D01F78-45A0-4EEB-A80E-0E7A80179738}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\swarm.exe |
"{E92D3778-F798-437D-A52E-623BB21580B4}" = protocol=17 | dir=in | app=d:\games\rockstar games\rockstar games social club\rgsclauncher.exe |
"{EAE1CDC7-FC3F-4A1A-AAD2-4C2F02595091}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{ED2C88B2-D75C-424C-8460-8CBEE8BB6AB0}" = protocol=17 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"{F1190627-E2E7-4E17-969B-7A35F9F2D079}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F2A498D5-9C28-4138-986D-C0F8A1DC9329}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\half-life\hl.exe |
"{F3390635-DF8A-4B4C-A354-E1AEF88B80CE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F77A2E9D-95CF-4E2D-B59A-FAD39086C7B0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe |
"{F79D70F1-3236-4B0F-A7A5-14972F84A63F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F9BD94E3-F86C-412C-AEDC-8F05E840C346}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2.exe |
"{FA73CF2B-36B8-4E59-9401-0E6865322307}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FAB2611B-51BF-4925-BB92-ACA2D5C35931}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FE2D3B6F-38E1-443E-BABC-4DE80E2A1191}" = protocol=6 | dir=in | app=c:\program files (x86)\opera 10.50 labs\opera.exe |
"{FF7CD91A-8BD9-474B-9EF9-482DD732971B}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FF977157-419A-4BBB-BFF7-4DC79B6F013A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{022A31A3-2E3A-419C-BE82-C9FE38DC46F1}D:\games\blur\blur(tm)\blur.exe" = protocol=6 | dir=in | app=d:\games\blur\blur(tm)\blur.exe |
"TCP Query User{1CFFA40B-3A8B-412E-AAB9-A835B958F44B}C:\program files (x86)\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vlc\vlc.exe |
"TCP Query User{1DC59DFE-31A1-4C3B-8FD6-EE44C47E5571}D:\games\modern warfare 2\iw4mp.dat" = protocol=6 | dir=in | app=d:\games\modern warfare 2\iw4mp.dat |
"TCP Query User{1F8035A3-2589-4885-BB49-46842D202C3F}D:\bitspirit\bitspirit.exe" = protocol=6 | dir=in | app=d:\bitspirit\bitspirit.exe |
"TCP Query User{27016D05-9B4A-4F0E-BC19-3488B0BB36FE}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"TCP Query User{3462A736-6B83-44DA-BBB5-9D79C84A7CE2}D:\games\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2_game.exe |
"TCP Query User{34BD5F3B-D401-44AC-8196-DED135B367F2}D:\games\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=d:\games\heroes of newerth\hon.exe |
"TCP Query User{41B7D2CB-4B61-42BC-AD68-BFF8BE8F47FF}C:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe |
"TCP Query User{4D239340-3A37-4BC0-8358-4C4AD83453C3}C:\program files (x86)\qip 2012\qip.exe" = protocol=6 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"TCP Query User{508EB25E-0C6F-4C0D-BB28-C7768805B860}D:\games\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=d:\games\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{73CBC827-34D3-4EFF-AEB7-9A81A87D91EA}D:\games\savage 2 - a tortured soul\savage2.exe" = protocol=6 | dir=in | app=d:\games\savage 2 - a tortured soul\savage2.exe |
"TCP Query User{826A446E-0B23-45AC-86DE-F50F04224E72}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"TCP Query User{A6405A77-6A25-4EAA-915C-BFAE9669654E}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{C992B6E8-F4A3-47BB-8EE5-CD7F28475928}D:\games\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"TCP Query User{CDFE8B8F-1A3C-425C-8D3F-49B531716FEE}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"TCP Query User{E7F6C3BD-2D0A-4F42-A014-BA64814A7180}E:\utorrent\utorrent\utorrent.exe" = protocol=6 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"TCP Query User{EFA66EF1-A4F5-4A6B-A6B6-E57E384789A3}D:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"TCP Query User{EFF6C566-8538-447C-9740-DEC6384C4E41}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{F79BB042-FF14-4252-948E-2CD53C8FF808}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{FB73447A-C729-415A-A72D-F18431D56C72}C:\program files (x86)\qip 2012\qip.exe" = protocol=6 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{08E0E3A3-E842-438F-A1F2-E5D1680A06E0}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{38D4D194-5672-412A-A320-E3E9A4BFA705}E:\utorrent\utorrent\utorrent.exe" = protocol=17 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"UDP Query User{4979D3D4-F293-4131-B605-C044A498D57C}D:\games\savage 2 - a tortured soul\savage2.exe" = protocol=17 | dir=in | app=d:\games\savage 2 - a tortured soul\savage2.exe |
"UDP Query User{5B99943B-0280-4646-B3C9-60873A248D23}D:\games\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=d:\games\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{675CDFF4-4FA2-4104-8B85-1D721B5E1037}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{76DE0FA1-EBDF-4483-A89B-CE636F3310A3}D:\games\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"UDP Query User{7AB03A92-53D4-4E2B-8C76-36B4BAC7FE2E}C:\program files (x86)\qip 2012\qip.exe" = protocol=17 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{8D2110DF-B60F-4A0B-AA79-55919822F1A1}D:\bitspirit\bitspirit.exe" = protocol=17 | dir=in | app=d:\bitspirit\bitspirit.exe |
"UDP Query User{93C35F7A-7848-4323-ADC4-F06C2411B4BD}D:\games\blur\blur(tm)\blur.exe" = protocol=17 | dir=in | app=d:\games\blur\blur(tm)\blur.exe |
"UDP Query User{99429283-B97C-4366-B79F-F88BFF347496}D:\games\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2_game.exe |
"UDP Query User{A255A2CC-5083-4107-89F4-4E87FC2A3AE9}D:\games\modern warfare 2\iw4mp.dat" = protocol=17 | dir=in | app=d:\games\modern warfare 2\iw4mp.dat |
"UDP Query User{A62F5780-3CC9-4AB1-A648-19051A341D6C}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"UDP Query User{AC2867CE-2A76-4665-9DC9-444087A3594F}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"UDP Query User{B80936C3-A879-4A9B-B7F4-F22072A67CD2}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{B922E4E7-9E14-4906-99D1-3E067260131F}C:\program files (x86)\qip 2012\qip.exe" = protocol=17 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{C1D0E10D-E389-4E62-9884-6B44272884A6}C:\program files (x86)\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vlc\vlc.exe |
"UDP Query User{C54C8C8B-2E81-4198-B9D9-D53EA7EAC637}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{D7C49A94-4809-468A-8DAF-FA2214B9BC5E}C:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe |
"UDP Query User{DB36275C-0B4A-48FB-9F7B-A420EDFC7071}D:\games\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=d:\games\heroes of newerth\hon.exe |
"UDP Query User{F0254F69-7ECE-4CEC-8265-3D8B76909D6A}D:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0DCAB5DD-CC69-271A-CF03-F2BD6B60BD8A}" = AMD Media Foundation Decoders
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.3.5818 (64-bit)
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3705C708-1B8A-43A3-8E94-6BAB33A3384B}" = Logitech G-series Keyboard Software
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46DA7FD9-8BC1-7BA8-98D1-27F46647871B}" = AMD Catalyst Install Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{504184A2-1B0E-5D93-603A-517E93E7EDB3}" = AMD Accelerated Video Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Centrum zařízení Windows Mobile
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6B32ED58-8F81-92B9-5061-09EBA3822200}" = AMD Drag and Drop Transcoding
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{7F2E5C3B-DBDF-469D-AD8D-F686D3B71176}" = Debugging Tools for Windows (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{877C9C8D-B811-4286-8140-F868E6C845B9}" = Windows 7 Manager
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{88EAF577-71FA-46F2-8E42-AEA33E35AFB1}" = Vegas Pro 9.0 (64-bit)
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{92DBCA36-9B41-4DD1-941A-AED149DD37F0}" = Aktualizace ovladače pro aplikaci Centrum zařízení Windows Mobile
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{A4F467A8-FCD3-B119-7E8D-D5739F946F4C}" = AMD AVIVO64 Codecs
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CAD041C0-915A-D164-FE87-D621D724052C}" = ATI Problem Report Wizard
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F2DE8060-FEE7-44CA-B9F1-32F01E03622D}" = ESET Smart Security
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"doPDF 7 printer_is1" = doPDF 7.1 printer
"MediaInfo" = MediaInfo 0.7.26
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Zune" = Zune
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}" = Adobe Flash Media Live Encoder 3.2
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{0F7A6FD0-87F5-FB5D-973C-CF604DE1BC6B}" = CCC Help Polish
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{121C477C-5B7B-44E3-B621-BDDB542AE8FD}" = TuneUp Utilities Language Pack (en-GB)
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}" = Risen
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1998BD34-1AAB-4169-ACFF-67342E2AF9B4}" = Gothic III Release Update
"{1A9BE3D6-4D53-2C9D-B77D-562D85936B91}" = CCC Help Norwegian
"{1B199105-397F-4568-9807-F51AE2FB1D5D}" = ArcSoft PhotoImpression 5
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1BBD8D70-721A-41AD-AC8F-7308A0C8FA92}" = Adobe Creative Suite 5 Master Collection
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1DEBA8AA-3FC2-4867-AD29-4CE4A95E1029}" = Nero 8
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1E2FDD18-E514-4631-AF4A-0CC58FD93DCB}" = Quake Live Mozilla Plugin
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{210DFA65-F805-1A2B-4F83-8E27279AE385}" = Catalyst Control Center Graphics Previews Common
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 37
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{29822CAD-C76A-0BEE-55F5-AAA524DA814F}" = CCC Help Greek
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30482B99-CAD6-4370-8A3B-8939BCDC90EC}" = Email Extractor
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A1293DF-7D09-BB0F-9576-EC47EE4A9362}" = CCC Help Italian
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3BEF9769-BA52-18F7-1D02-2362F6A27E38}" = Adobe Media Player
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{41A63ADA-088B-1C2D-43B3-E4087FE79881}" = Pixlr-o-matic
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45C8D17D-B5E0-4e93-8370-4329AB16D2A0}" = Battlefield 3™ Open Beta
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{47416F0B-6589-591E-C6F8-4235D2230B14}" = Catalyst Control Center InstallProxy
"{48530DE6-19F9-489D-809E-AFAA8AACC6DF}" = SplitMediaLabs VH Screen Capture Driver (x86)
"{48EB0E22-B055-44B5-B566-057F145CB7E7}" = ManicTime
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{4D68D398-7760-426D-8395-83EE0676FC7E}" = Antares Auto-Tune Evo RTAS
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{625FC7D1-656D-1BEC-F86F-3EACAFDAA8FE}" = CCC Help English
"{62FF6AF0-A718-4E31-A499-016BD655F060}" = Web Album Copier
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C472DFC-6D44-4947-9E1A-F79A2469D953}" = eTesty - autoškola
"{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}" = Tom Clancy's Splinter Cell Conviction
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7236672F-6430-439E-9B27-27EDEAF1D676}" = Diagnostic Utility
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7351EEF8-9D6C-5F46-5A19-F2C7456CE132}" = CCC Help German
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7F172E34-4107-8964-6AEA-5051FFD265FF}" = CCC Help Portuguese
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{80074966-5231-428D-9AE7-B7D5D2DC3246}" = Readon TV Movie Radio Player 7.6.0.0
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86095E92-1959-8364-920E-82E81F64F8FB}" = Catalyst Control Center
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89D05F35-933A-89C0-B935-C92BEE4229BD}" = CCC Help French
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{915153F8-1429-40AE-B005-E3BFA7097672}" = Audiggle
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{93F85AA6-C06F-4B62-8A1B-1C83479C805C}" = ArcSoft VideoImpression 2
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{959E4378-CCA1-E4E4-2425-793DA92E8D95}" = CCC Help Czech
"{96BB3C67-4EB4-9757-E0C2-C0D2FE9053B1}" = CCC Help Turkish
"{974F4B73-2017-E174-9070-3F58F01B341F}" = CCC Help Danish
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98E20A18-3C29-86FA-50B4-918C2B34A082}" = CCC Help Hungarian
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9E2E5EB3-DC6E-9277-E9DB-13175E7DDA39}" = CCC Help Dutch
"{9FB9BA8A-E711-40E6-BBF0-77ED60A2940F}" = Facebook Messenger 2.1.4587.0
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A64479BE-7DB6-4B07-87B9-70AD85B7EAD2}" = Medal of Honor™ MP Beta
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAACC0A5-4382-04D0-C75E-0669C7B949B6}" = CCC Help Japanese
"{AB49B509-8FCA-45E6-9FB9-9E4AEEB8F148}" = System Requirements Lab CYRI
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_952" = Adobe Acrobat 9.5.2 - CPSID_83708
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Czech
"{ACEF4078-9B86-2455-E18D-34D52D37D9D5}" = CCC Help Chinese Standard
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{B55FB422-B803-11F5-5582-B3666EA1B9AC}" = Catalyst Control Center Localization All
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8010864-15F8-613B-20EF-AC35B14B3E0D}" = CCC Help Russian
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB47D7EA-7EF1-475C-9C14-AF5B8FCA45E2}" = Condemned - Criminal Origins
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}" = Need for Speed™ SHIFT
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C1342411-5A98-DE8A-5629-D0C518E1C280}" = CCC Help Finnish
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5A31DDC-157A-4DD7-9B5C-C692A06F61FD}" = Prison Break
"{C5AF183C-11D5-403F-8B99-85F6BBBF585E}" = Gothic
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{C8793276-2F36-454A-A524-9957B979FDE1}" = SceneGrabber.NET
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{D08B4177-5160-6B66-8934-2F9012134D61}" = CCC Help Thai
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.4 Game
"{D34A6029-FB1A-9EA8-A938-5393F82A3A00}" = CCC Help Korean
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.19.365
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3A09D13-4D40-3CF8-7D32-8BD55F8D1533}" = CCC Help Spanish
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E58C571A-D165-AF15-5CBD-B3B77CFD5B61}" = HydraVision
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EAEAAF8C-8E86-4CAC-AC08-1A33EDCA34AC}" = Prince of Persia The Forgotten Sands™
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EE74D039-45D7-44E9-BF95-B9CFB015964F}_is1" = ArcaniA - Gothic 4 Hotfix
"{EE91E474-9298-47B8-817F-8E0042408998}" = Risen Hotfix 1.01
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F241EC95-C81A-466E-8006-6B0B364B07A0}" = PCMark Vantage
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F2C35491-9323-3AE7-6023-6B4128045153}" = CCC Help Swedish
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX
"{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein
"{FAF34181-8A35-4182-B297-EB7E0F5B7A5A}" = XSplit
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FC66A32F-1A57-AC5C-4F12-DAC2F4CB77A0}" = CCC Help Chinese Traditional
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFF74EC9-1FF4-4456-99E3-4F05129F4FAB}" = Antares Auto-Tune Evo VST
"µTorrent CZ_is1" = µTorrent CZ 1.8.5 (build 17414)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Afterburner" = MSI Afterburner 1.5.0
"All2WAV Recorder_is1" = All2WAV Recorder 3.20
"AMD GPU Clock Tool" = AMD GPU Clock Tool
"Antares Autotune VST RTAS TDM_is1" = Antares Autotune VST RTAS TDM v5.08
"Antares Autotune VST_is1" = Antares Autotune VST v5.09
"Any Video Converter_is1" = Any Video Converter 3.0.3
"ArcaniA" = ArcaniA - Gothic 4
"ASIO4ALL" = ASIO4ALL
"aTube Catcher" = aTube Catcher
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"AV Voice Changer Software 7.0" = AV Voice Changer Software 7.0
"AV Voice Changer Software DIAMOND 5.0" = AV Voice Changer Software DIAMOND 5.0
"AV Voice Changer Software DIAMOND 6.0" = AV Voice Changer Software DIAMOND 6.0
"AviSynth" = AviSynth 2.5
"Battlelog Web Plugins" = Battlelog Web Plugins
"Beauty Pilot Trial_is1" = Beauty Pilot Trial 2.3.0
"BitSpirit_is1" = BitSpirit v3.3.2.352 Stable
"Blu-ray to DVD_is1" = Blu-ray to DVD 1.2.0.14
"Bomber 1.0" = Bomber 1.0
"ClickBall Freeware Edition" = ClickBall Freeware Edition
"Clownfish" = Clownfish for Skype
"Collab" = Collab
"com.adobe.amp.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Media Player
"Counter-Strike: Source" = Counter-Strike: Source
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Email Extractor" = Email Extractor
"eMail Extractor_is1" = eMail Extractor 3.5.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESN Sonar-0.70.0" = ESN Sonar
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30
"FileZilla Client" = FileZilla Client 3.5.1
"FL Studio 8" = FL Studio 8
"FMCODEC" = FM Screen Capture Codec (Remove Only)
"Fraps" = Fraps (remove only)
"Free Screen To Video_is1" = Free Screen To Video V 1.2
"GameParkClient_is1" = GamePark
"Hitman Absolution_is1" = Hitman Absolution
"HyperCam 2" = HyperCam 2
"HyperCam 3" = HyperCam 3
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"IL Download Manager" = IL Download Manager
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein
"JDownloader" = JDownloader
"Logitech Vid" = Logitech Vid HD
"MagicEffect Photo Editor 2010_is1" = MagicEffect Photo Editor 2010.2.4
"MAGIX Photo Manager 9 US" = MAGIX Photo Manager 9
"MAGIX Screenshare US" = MAGIX Screenshare
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.65.1.1000
"ManyCam" = ManyCam 2.6.1 (remove only)
"MediaInfo" = MediaInfo 0.7.34 (32-bit)
"Mozilla Firefox 17.0.1 (x86 cs)" = Mozilla Firefox 17.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MTA:SA" = MTA:SA v1.0.4-rc-02033-2-000
"MTA:SA 1.1" = MTA:SA v1.1
"MTA:SA 1.2" = MTA:SA v1.2.0-full-03585-0-000
"MTA:SA 1.3" = MTA:SA v1.3
"MTA:SA Race" = MTA:SA Race 1.1.2
"Mumble" = Mumble and Murmur
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Service Center" = Native Instruments Service Center
"Native Instruments Traktor" = Native Instruments Traktor
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock" = ObjectDock
"OpenAL" = OpenAL
"Opera 11.62.1347" = Opera 11.62
"Origin" = Origin
"Pixlromatic" = Pixlr-o-matic
"PocketInsanity Wolfenstein 3D for PocketPC (SW)" = PocketInsanity Wolfenstein 3D for PocketPC (SW)
"PocketMoku" = PocketMoku
"PoiZone" = PoiZone
"Rainmeter" = Rainmeter (remove only)
"Savage2" = Savage 2 - A Tortured Soul
"SmartMorph" = SmartMorph
"State of War" = State of War
"State of War - Warmonger" = State of War - Warmonger
"Steam App 10" = Counter-Strike
"Steam App 12840" = DiRT 2
"Steam App 150" = Counter-Strike Steamworks Beta
"Steam App 30" = Day of Defeat
"Steam App 570" = Dota 2
"Steam App 630" = Alien Swarm
"Steam App 70" = Half-Life
"TeamViewer 5" = TeamViewer 5
"TeamViewer 6" = TeamViewer 6
"Toxic Biohazard" = Toxic Biohazard
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"Videora HTC Touch Diamond2 Converter" = Videora HTC Touch Diamond2 Converter 5.04
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 2.0.5
"Wallpaperio HTC Touch Diamond2 Maker" = Wallpaperio HTC Touch Diamond2 Maker 2.03
"Warfare Incorporated(TM) for Pocket PC" = Warfare Incorporated(TM) for Pocket PC
"Winamp" = Winamp
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR
"X-ray Anti-Cheat" = X-ray Anti-Cheat
"YouTube Downloader App" = YouTube Downloader App 2.03
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Hotfile Premium Link Generator" = Hotfile Premium Link Generator
"InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"Octoshape Streaming Services" = Octoshape Streaming Services
"QIP 2012" = QIP 2012 4.0.7000
"QUICKMEDIACONVERTER" = QMC
"Uploadinator" = FluffyApp
"Winamp Detect" = Winamp Application Detect
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\McDan\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 33,28% Memory free
7,98 Gb Paging File | 3,77 Gb Available in Paging File | 47,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 0,70 Gb Free Space | 1,40% Space Free | Partition Type: NTFS
Drive D: | 440,01 Gb Total Space | 79,10 Gb Free Space | 17,98% Space Free | Partition Type: NTFS
Drive E: | 440,01 Gb Total Space | 114,03 Gb Free Space | 25,92% Space Free | Partition Type: NTFS
Drive I: | 1,49 Gb Total Space | 1,22 Gb Free Space | 81,81% Space Free | Partition Type: FAT32
Drive K: | 1862,89 Gb Total Space | 1211,80 Gb Free Space | 65,05% Space Free | Partition Type: NTFS
Computer Name: PRIVATE | User Name: McDan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe (Opera Software)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Games\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera 10.50 Labs\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Games\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitSpirit\BitSpirit.exe" = D:\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client -- (LANSPIRIT.NET)
"D:\BitSpirit\BitSpirit.exe" = D:\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client -- (LANSPIRIT.NET)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0489A3D0-12FD-47DA-B6C6-E95B1077CF0D}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{04B69B15-07C2-4D18-A6DD-A7C6010963C7}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{084D5793-AAF4-4680-9963-A1837F65F11C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0E6FD9C4-C15C-4898-9B63-99C9C7744431}" = lport=137 | protocol=17 | dir=in | app=system |
"{13F4C3B2-6868-4C7D-AE39-3F70F79C36B1}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{16C0262F-306D-4AEB-9FA8-F95ED765CB46}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1AFCED28-4BD7-4C8A-84C6-0EF956DB5438}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C702574-E5B0-4E11-B521-20E200564FF5}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2398E5B0-B4D3-4461-9C51-3480B644D7DF}" = lport=58821 | protocol=17 | dir=in | name=pando media booster |
"{3137879F-9B51-49AB-A85F-DA7D42A3ED78}" = rport=10243 | protocol=6 | dir=out | app=system |
"{35198690-99E8-4394-8C2E-FD1631B5D3BB}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{361C84BE-38C5-4D01-BF48-8C6D650199C9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{41AB98A9-30F0-4B2E-8A84-0F27DF31DCC7}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{436FFCA1-B462-4DD4-BA21-B22027EBE893}" = lport=56770 | protocol=17 | dir=in | name=pando media booster |
"{492D2962-6C15-4345-BBFA-D0950AA6B5C3}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5D89C165-F477-47DF-B268-7191BAE04B79}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6ACADC00-23E3-4B58-A646-828A2CC6DDCB}" = rport=137 | protocol=17 | dir=out | app=system |
"{6BE62B86-5E08-4AE2-846A-98670D353E99}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{7382F18D-DCB4-4F69-AEF8-CF6E6C68B217}" = lport=58821 | protocol=6 | dir=in | name=pando media booster |
"{76AA2155-AE17-4969-8810-1B5C7E97249F}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{79A0CE0B-33E1-416B-B72B-4F167E5C741E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7C13DEB2-E17A-4630-A8A0-3A67102BBB30}" = lport=445 | protocol=6 | dir=in | app=system |
"{81E45406-23BD-448D-8D70-6B54F800091A}" = lport=58821 | protocol=17 | dir=in | name=pando media booster |
"{83A9F1D6-F3CE-4A51-81D6-83FCBD82C2D0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{876466B7-1415-46D3-B1E8-A476C93D6DDC}" = lport=58821 | protocol=6 | dir=in | name=pando media booster |
"{8B6C6A50-6A27-487D-BC76-08411A5D8AB0}" = lport=138 | protocol=17 | dir=in | app=system |
"{92305CD8-76F7-4571-96D1-E507F454C281}" = lport=56770 | protocol=6 | dir=in | name=pando media booster |
"{944F5F98-37FC-4929-8692-C65C68737BB2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9B91CDD1-CDAE-4F79-8B90-EBD37D5C2C56}" = lport=56770 | protocol=6 | dir=in | name=pando media booster |
"{9E9668FF-0571-407D-8EAA-9A5C9C2E67F4}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{AB4AB70A-ACEF-4A24-89E2-B38C6BBA7242}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B7442E57-E71A-4564-BA4C-D888649E9118}" = rport=138 | protocol=17 | dir=out | app=system |
"{B7D1E1EF-D5A8-4A92-A294-C125CFDD1959}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C240F228-DC91-41D0-BD5E-22F63C4EFB96}" = lport=56770 | protocol=17 | dir=in | name=pando media booster |
"{CF7D5126-CDAD-45A4-849D-08E2FE0770D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{D741ABD3-2E49-4BC6-A4D8-C09DE43E54FB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DA7123BC-1366-40DF-8941-4AAF91129440}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{DFA67B3B-C9FC-4AA3-AF1A-76905E3CFD3A}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{ECC87B76-F930-4FA4-991A-E5D844C6C591}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED0ECD59-4008-4C59-A6CA-D1FC00765A97}" = rport=139 | protocol=6 | dir=out | app=system |
"{EDAD54D6-84DD-4A11-AFDD-4DB8F2F028E9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{013F8557-0A36-4F0C-9E46-3FAB39D04CBF}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0268AFD2-4E67-4A96-B4DB-D36AFFACA250}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0321F6F8-019C-438F-99E0-7C8643C301D5}" = protocol=17 | dir=in | app=e:\bitspirit\bitspirit.exe |
"{032785B0-EDB1-4398-BD50-F16EBFB0D622}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{0464213C-15C8-4514-8909-22FC1F438119}" = protocol=17 | dir=in | app=d:\games\crysis\bin64\crysisdedicatedserver.exe |
"{05025785-2535-4905-9B23-0C21E844CB0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{054743CA-E9C5-42BA-8F7C-81B9C3B630CD}" = protocol=6 | dir=in | app=d:\games\wolfenstein\mp\wolf2mplite.exe |
"{05C62F72-A021-4F29-ACA0-84F008D56317}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{0632CCF3-1BF8-4CDE-9DB7-AA6E42FD7E4F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version5\teamviewer.exe |
"{0D5BA73A-2DF0-4E82-B2C4-8B4CDF08811C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0F0E1933-941A-44D3-813E-0C43080AEDAF}" = protocol=6 | dir=in | app=d:\games\rockstar games\rockstar games social club\rgsclauncher.exe |
"{129EB119-FBCD-49D9-8D7C-3D041829624B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{135B024F-1009-4ECC-B5DC-7242DE923F75}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{14D3D352-82CC-44C5-8FBC-62BB5C6E9735}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{1A4FEFBB-D344-40AB-BB76-AFED34066352}" = protocol=17 | dir=in | app=d:\games\crysis\bin64\crysis.exe |
"{1BAE744D-1770-42AB-A6C1-3E7F4658E779}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1C2A09AA-4C96-48D0-8BB7-C389A0A06265}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{1C99E604-9F0E-45D5-9FF4-5D9D55A34988}" = protocol=6 | dir=in | app=d:\games\battlefield bad company 2\bfbc2updater.exe |
"{1FB548B0-4370-4C08-8BCB-E85D4D1836E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{23FBB8F6-2C70-43CE-BA3E-92F3F5DD7D42}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{248531BA-8024-43C2-8137-58DCF37B9D48}" = protocol=17 | dir=in | app=d:\games\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{24857FF2-BC9B-47D4-8E82-64FD89D12B0F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{252B213F-5865-4E3D-A124-4707564DBA3D}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{25694ED3-BCBA-439E-9BFB-4A7420CB0D36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{26400321-A497-4991-91C3-782A7F38444B}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2CAF33FF-8042-4F88-87B5-E60C170C8B4C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2CC8AEE8-13D9-4366-8BF6-0D49A9E238E5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{2D3EDCBF-AD44-4A6A-AD40-9E11EA7A2924}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{309D3FAA-1E6D-4816-9403-F4B42837A6C1}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{353F9765-5A96-402A-8C5D-40104DB0A485}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{37E7D51C-F318-4E76-B0F8-6DB0A25BD091}" = dir=in | app=e:\itunes\itunes.exe |
"{3CBA84B8-EE24-4260-9FED-EFA67AA46BA7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3E094219-BBF8-417C-A424-13BC40C10DA4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F3D04F1-65DD-4DB4-A583-8CA7A6259F47}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F54EB48-2C91-49B0-B148-E6AE898E1C33}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2.exe |
"{40A47B36-A849-4518-B54E-23AD5BD41647}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe |
"{40DE6094-F180-4664-B2FD-6ABFB500042B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{425554B1-DDF5-46FC-810B-772AE00A2084}" = protocol=17 | dir=in | app=d:\games\battlefield bad company 2\bfbc2updater.exe |
"{433765B4-FE6B-4BB7-A068-309037565355}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{495D767A-F8BF-41A2-A6E5-145A2712E3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{49C2C9E8-DC61-4A6F-BA26-A6B38A9AC665}" = protocol=17 | dir=in | app=d:\games\wolfenstein\mp\wolf2mp.exe |
"{4C8B222F-12D0-48A0-846F-A6ED2D682D92}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike beta\hl.exe |
"{4C9434DA-0937-4190-9F78-AA7D6D99E3F4}" = protocol=17 | dir=in | app=d:\games\crysis\bin32\crysisdedicatedserver.exe |
"{4CB5696D-C7DA-42E4-9435-53B7570EB8E8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E973438-7A9D-4E6A-B3BD-6BE9C1F08D51}" = protocol=6 | dir=in | app=d:\games\wolfenstein\mp\wolf2mp.exe |
"{4F68F53B-0DD7-4C71-B595-A56EA07F244E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{4F6CE11A-59C6-450C-9488-B093996E436A}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{4FF9459F-0DC3-443B-A740-9D8252731F21}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{50A4DA97-0F82-4604-87E9-12B3A6A721E4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{519253B2-F845-4EE9-B1AE-C5D69A6786ED}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{536B44C9-14C1-40A5-B1A2-49F4860CB3CE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{56B3DF7A-8A57-41A1-96BF-A78422F897A3}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version5\teamviewer.exe |
"{5DE74087-83CA-48A5-A2C9-75C888F60E5C}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\srcds.exe |
"{5E369F58-08C8-4F14-A679-D39D22454513}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5E386EDC-A611-499B-AE8B-0B39E3E5AB08}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{5EEF754B-221D-4A31-A7D0-75F6E142EEF3}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{603E6709-C6F1-4EA2-9EE5-E8B554F0B2EB}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\swarm.exe |
"{62AA59FE-2ADB-4524-B9AE-5FA38C99FD5B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{63F99224-10DF-44FB-BC54-3A178578B0E4}" = protocol=6 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\gu.exe |
"{64CECCD3-F643-43AA-BA67-F9C644CAB5C3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{688985E5-C6B0-43D6-B067-DA061FC70AB7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72C3B2A4-ADBE-4D5E-8CF9-B71D400EC148}" = protocol=6 | dir=in | app=d:\games\crysis\bin64\crysisdedicatedserver.exe |
"{76853333-97F2-42DC-8101-CE785894E029}" = dir=in | app=c:\users\mcdan\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{76A63ADF-3732-402A-8160-D9E031624527}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{76B2A9BF-4487-42A7-A79B-A1A2DECF8369}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{76FDEAF9-A30E-4768-A300-990160E3FDD2}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{7CF71179-C457-429E-AF06-7494B791A97B}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7DC9181E-713C-4AB8-889B-86DA567A057C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{805F2BF3-6DE5-465B-8849-F857C39A116D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8125FDDE-F415-450C-B147-1CBC5226C401}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{82B2AF7C-6740-4237-B7AB-A3321ACE303C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{83C0C4F1-3FE7-46DE-8A2F-5DCB6C2A0215}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{87741D5B-8322-492A-B991-2EA5F1332142}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8B29388B-D46A-42A3-AE21-1D30A7FCFB11}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8B2B8983-FD3A-4BA8-B4A9-9037F8A77D5F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{8BE2654C-3AA9-4FE4-8060-2737F1A15EA1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8CCA212C-F738-4FDD-92BC-5192A7EF16FE}" = protocol=17 | dir=in | app=d:\games\wolfenstein\mp\wolf2mplite.exe |
"{8D65C746-0750-48C7-B9B2-8FF043054514}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9294046C-BBE6-49B4-9185-CC4691CF6674}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{92DB89E6-D9BB-4B74-AFC0-5C221DFF4E7C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{92F384DA-68FC-471E-8329-397E7C25A49B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{93D24A58-BBDA-4BB7-98CB-B12B16A4387C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{953BD51F-18F3-4111-88B9-6F86F3225CD4}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{959B9661-FB25-4CF9-9E1E-CF5A0D6DBF7C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{95B98B50-83ED-472A-997E-CE3FA18D6FE6}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike beta\hl.exe |
"{95DD295C-F60F-4CFE-B434-2532F06C807A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{971B327F-6D51-4516-A0DC-6B777F226EBF}" = protocol=6 | dir=in | app=d:\games\crysis\bin64\crysis.exe |
"{974778DC-F2C7-4364-AFA1-85CCD10F93D4}" = protocol=6 | dir=in | app=d:\games\crysis\bin32\crysis.exe |
"{9835EEDB-3B45-424C-9552-CE3E5A80AAB6}" = protocol=17 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{987A183D-CF50-4455-A396-0C69890F37D5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{99533A79-25D0-4800-8DE6-D48BE66B7719}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdan\counter-strike\hl.exe |
"{9A3D51C7-3FFE-44E2-A185-B53C1DA96EFC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9D626B26-4462-4B28-9E4A-432371357A34}" = protocol=6 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{9DB71A27-FD05-43CD-9D69-8758F6076E4C}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"{9E96E1B2-6EF8-4077-8C26-B4A7A29E8FF5}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{9FD82C43-9F87-4EBC-A6E5-95B48607FB57}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A3E43E60-F6E2-4BC6-A8DB-66AE109FE3BF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A4BEB285-DB58-4345-BA4D-B996A79AE6EC}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A6A34100-6ACB-468E-AE7B-053C4C9A32CA}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"{A7481187-C0FB-4239-99BE-EC339AB20C4F}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A9671566-0B5F-4179-9C99-4CE20B6F6215}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{AB7292D4-77F7-4544-8135-A4F9D4F500EE}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\half-life\hl.exe |
"{ACAE93F0-AAD2-460C-B432-8C339225DDF8}" = protocol=6 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"{ADBF85B8-2FB3-47DF-B14F-F08A8A58D10D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AF61507F-D2B8-48D1-B0D6-B3E53C437559}" = protocol=17 | dir=in | app=d:\games\crysis\bin32\crysis.exe |
"{B19B041B-9881-4C2A-AA46-7871638126D9}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B2888C4D-AC4F-41FB-9F61-CEAE86A048EA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B3386B27-6940-4679-86B1-84F37EDB7103}" = protocol=17 | dir=in | app=c:\program files (x86)\opera 10.50 labs\opera.exe |
"{B5827DF1-EF0D-4653-910D-7DE1C3824C28}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B7F91828-DAFC-4646-AEBE-4A465F167853}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B887D071-32D6-444E-9196-AD9277F9FB57}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{B8D76146-14C0-4828-8088-DABE1287AEA4}" = protocol=6 | dir=in | app=d:\games\crysis\bin32\crysisdedicatedserver.exe |
"{B9A0D469-5BE1-45DA-985F-DE125B26303F}" = protocol=6 | dir=in | app=e:\bitspirit\bitspirit.exe |
"{BA27073A-2BDF-40E7-A42C-AB4883C55920}" = protocol=6 | dir=in | app=d:\games\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{BB56DBB6-CC08-42B9-97E0-DE0A93570F67}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C0D64C35-EB9B-41E1-A8F4-157AD6E86458}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1CFC975-1AB1-4CAD-8DB5-8B2F0D3D4613}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe |
"{C45869E7-1EEA-411E-BDDF-F201C898C589}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C69C0C06-0830-46CA-A0CF-4BFF1F527490}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{C6F78D38-F355-484B-BDCE-5AE379D457E1}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\srcds.exe |
"{C7BCEFB2-1D90-477A-A5CD-DA4EB74A6CA5}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{C8F5FC51-9A9A-47E5-8B40-72859625DCE0}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe |
"{CA185CE8-CDA9-487C-8573-E6A41B2EF319}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CA5AB1F5-BC32-402E-A421-7EFFD47FC37B}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{CEBA2C78-5203-413D-A0F7-F7F314F203C9}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{CF797C54-DA62-43D0-91D0-49862D9B702B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe |
"{D03211AC-2F25-4423-A7D9-EF6C6182E6BE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D304916F-F8CF-463E-978A-25A814D22BE1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D354BDEB-FEEA-4E12-81CC-0617AFC1433F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{D36068CE-3071-462E-8CCF-5595B7BCEF06}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dota 2 beta\dota.exe |
"{D4CC42AE-7844-4081-AE0F-03206377BC41}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D4F06E19-5A0A-4EE9-89BA-C94E32FF4835}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D6A14561-3391-40B6-89BD-7AF73B001B1D}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdan\counter-strike\hl.exe |
"{D92ABB93-C376-4DE7-8432-F1878560F672}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DE133F80-B885-4397-AE3A-F01884F3A2B4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF66FCDD-EA0D-49CE-B2EE-52B5FACA2E01}" = protocol=6 | dir=out | app=system |
"{E0AF0F24-A7BB-4437-80BD-EE94C0D71BB1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E142827B-1665-4405-8BB4-4AA3F1205A15}" = protocol=17 | dir=in | app=d:\games\tom clancy's splinter cell conviction\src\system\gu.exe |
"{E358902F-FA58-4A59-B139-7F351B26B7E1}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{E660C072-4676-4A31-B02D-A9334EEDF8A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E66FD5B4-352F-4DB4-BDD9-4EE518FA0E9D}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dota 2 beta\dota.exe |
"{E6D01F78-45A0-4EEB-A80E-0E7A80179738}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\alien swarm\swarm.exe |
"{E92D3778-F798-437D-A52E-623BB21580B4}" = protocol=17 | dir=in | app=d:\games\rockstar games\rockstar games social club\rgsclauncher.exe |
"{EAE1CDC7-FC3F-4A1A-AAD2-4C2F02595091}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{ED2C88B2-D75C-424C-8460-8CBEE8BB6AB0}" = protocol=17 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"{F1190627-E2E7-4E17-969B-7A35F9F2D079}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F2A498D5-9C28-4138-986D-C0F8A1DC9329}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\half-life\hl.exe |
"{F3390635-DF8A-4B4C-A354-E1AEF88B80CE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F77A2E9D-95CF-4E2D-B59A-FAD39086C7B0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe |
"{F79D70F1-3236-4B0F-A7A5-14972F84A63F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F9BD94E3-F86C-412C-AEDC-8F05E840C346}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2.exe |
"{FA73CF2B-36B8-4E59-9401-0E6865322307}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FAB2611B-51BF-4925-BB92-ACA2D5C35931}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FE2D3B6F-38E1-443E-BABC-4DE80E2A1191}" = protocol=6 | dir=in | app=c:\program files (x86)\opera 10.50 labs\opera.exe |
"{FF7CD91A-8BD9-474B-9EF9-482DD732971B}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FF977157-419A-4BBB-BFF7-4DC79B6F013A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{022A31A3-2E3A-419C-BE82-C9FE38DC46F1}D:\games\blur\blur(tm)\blur.exe" = protocol=6 | dir=in | app=d:\games\blur\blur(tm)\blur.exe |
"TCP Query User{1CFFA40B-3A8B-412E-AAB9-A835B958F44B}C:\program files (x86)\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vlc\vlc.exe |
"TCP Query User{1DC59DFE-31A1-4C3B-8FD6-EE44C47E5571}D:\games\modern warfare 2\iw4mp.dat" = protocol=6 | dir=in | app=d:\games\modern warfare 2\iw4mp.dat |
"TCP Query User{1F8035A3-2589-4885-BB49-46842D202C3F}D:\bitspirit\bitspirit.exe" = protocol=6 | dir=in | app=d:\bitspirit\bitspirit.exe |
"TCP Query User{27016D05-9B4A-4F0E-BC19-3488B0BB36FE}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"TCP Query User{3462A736-6B83-44DA-BBB5-9D79C84A7CE2}D:\games\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2_game.exe |
"TCP Query User{34BD5F3B-D401-44AC-8196-DED135B367F2}D:\games\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=d:\games\heroes of newerth\hon.exe |
"TCP Query User{41B7D2CB-4B61-42BC-AD68-BFF8BE8F47FF}C:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe |
"TCP Query User{4D239340-3A37-4BC0-8358-4C4AD83453C3}C:\program files (x86)\qip 2012\qip.exe" = protocol=6 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"TCP Query User{508EB25E-0C6F-4C0D-BB28-C7768805B860}D:\games\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=d:\games\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{73CBC827-34D3-4EFF-AEB7-9A81A87D91EA}D:\games\savage 2 - a tortured soul\savage2.exe" = protocol=6 | dir=in | app=d:\games\savage 2 - a tortured soul\savage2.exe |
"TCP Query User{826A446E-0B23-45AC-86DE-F50F04224E72}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"TCP Query User{A6405A77-6A25-4EAA-915C-BFAE9669654E}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{C992B6E8-F4A3-47BB-8EE5-CD7F28475928}D:\games\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"TCP Query User{CDFE8B8F-1A3C-425C-8D3F-49B531716FEE}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"TCP Query User{E7F6C3BD-2D0A-4F42-A014-BA64814A7180}E:\utorrent\utorrent\utorrent.exe" = protocol=6 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"TCP Query User{EFA66EF1-A4F5-4A6B-A6B6-E57E384789A3}D:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
"TCP Query User{EFF6C566-8538-447C-9740-DEC6384C4E41}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{F79BB042-FF14-4252-948E-2CD53C8FF808}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{FB73447A-C729-415A-A72D-F18431D56C72}C:\program files (x86)\qip 2012\qip.exe" = protocol=6 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{08E0E3A3-E842-438F-A1F2-E5D1680A06E0}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{38D4D194-5672-412A-A320-E3E9A4BFA705}E:\utorrent\utorrent\utorrent.exe" = protocol=17 | dir=in | app=e:\utorrent\utorrent\utorrent.exe |
"UDP Query User{4979D3D4-F293-4131-B605-C044A498D57C}D:\games\savage 2 - a tortured soul\savage2.exe" = protocol=17 | dir=in | app=d:\games\savage 2 - a tortured soul\savage2.exe |
"UDP Query User{5B99943B-0280-4646-B3C9-60873A248D23}D:\games\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=d:\games\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{675CDFF4-4FA2-4104-8B85-1D721B5E1037}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{76DE0FA1-EBDF-4483-A89B-CE636F3310A3}D:\games\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"UDP Query User{7AB03A92-53D4-4E2B-8C76-36B4BAC7FE2E}C:\program files (x86)\qip 2012\qip.exe" = protocol=17 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{8D2110DF-B60F-4A0B-AA79-55919822F1A1}D:\bitspirit\bitspirit.exe" = protocol=17 | dir=in | app=d:\bitspirit\bitspirit.exe |
"UDP Query User{93C35F7A-7848-4323-ADC4-F06C2411B4BD}D:\games\blur\blur(tm)\blur.exe" = protocol=17 | dir=in | app=d:\games\blur\blur(tm)\blur.exe |
"UDP Query User{99429283-B97C-4366-B79F-F88BFF347496}D:\games\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\dirt 2\dirt2_game.exe |
"UDP Query User{A255A2CC-5083-4107-89F4-4E87FC2A3AE9}D:\games\modern warfare 2\iw4mp.dat" = protocol=17 | dir=in | app=d:\games\modern warfare 2\iw4mp.dat |
"UDP Query User{A62F5780-3CC9-4AB1-A648-19051A341D6C}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"UDP Query User{AC2867CE-2A76-4665-9DC9-444087A3594F}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"UDP Query User{B80936C3-A879-4A9B-B7F4-F22072A67CD2}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{B922E4E7-9E14-4906-99D1-3E067260131F}C:\program files (x86)\qip 2012\qip.exe" = protocol=17 | dir=in | app=c:\program files (x86)\qip 2012\qip.exe |
"UDP Query User{C1D0E10D-E389-4E62-9884-6B44272884A6}C:\program files (x86)\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vlc\vlc.exe |
"UDP Query User{C54C8C8B-2E81-4198-B9D9-D53EA7EAC637}C:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dsnet corp\atube catcher 2.0\yct.exe |
"UDP Query User{D7C49A94-4809-468A-8DAF-FA2214B9BC5E}C:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\readon technology\readon tv movie radio player 7.6.0.0\internettv.exe |
"UDP Query User{DB36275C-0B4A-48FB-9F7B-A420EDFC7071}D:\games\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=d:\games\heroes of newerth\hon.exe |
"UDP Query User{F0254F69-7ECE-4CEC-8265-3D8B76909D6A}D:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\playmcdaniel\counter-strike\hl.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0DCAB5DD-CC69-271A-CF03-F2BD6B60BD8A}" = AMD Media Foundation Decoders
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.3.5818 (64-bit)
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3705C708-1B8A-43A3-8E94-6BAB33A3384B}" = Logitech G-series Keyboard Software
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46DA7FD9-8BC1-7BA8-98D1-27F46647871B}" = AMD Catalyst Install Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{504184A2-1B0E-5D93-603A-517E93E7EDB3}" = AMD Accelerated Video Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Centrum zařízení Windows Mobile
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6B32ED58-8F81-92B9-5061-09EBA3822200}" = AMD Drag and Drop Transcoding
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{7F2E5C3B-DBDF-469D-AD8D-F686D3B71176}" = Debugging Tools for Windows (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{877C9C8D-B811-4286-8140-F868E6C845B9}" = Windows 7 Manager
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{88EAF577-71FA-46F2-8E42-AEA33E35AFB1}" = Vegas Pro 9.0 (64-bit)
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{92DBCA36-9B41-4DD1-941A-AED149DD37F0}" = Aktualizace ovladače pro aplikaci Centrum zařízení Windows Mobile
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{A4F467A8-FCD3-B119-7E8D-D5739F946F4C}" = AMD AVIVO64 Codecs
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CAD041C0-915A-D164-FE87-D621D724052C}" = ATI Problem Report Wizard
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F2DE8060-FEE7-44CA-B9F1-32F01E03622D}" = ESET Smart Security
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"doPDF 7 printer_is1" = doPDF 7.1 printer
"MediaInfo" = MediaInfo 0.7.26
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Zune" = Zune
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}" = Adobe Flash Media Live Encoder 3.2
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{0F7A6FD0-87F5-FB5D-973C-CF604DE1BC6B}" = CCC Help Polish
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{121C477C-5B7B-44E3-B621-BDDB542AE8FD}" = TuneUp Utilities Language Pack (en-GB)
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}" = Risen
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1998BD34-1AAB-4169-ACFF-67342E2AF9B4}" = Gothic III Release Update
"{1A9BE3D6-4D53-2C9D-B77D-562D85936B91}" = CCC Help Norwegian
"{1B199105-397F-4568-9807-F51AE2FB1D5D}" = ArcSoft PhotoImpression 5
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1BBD8D70-721A-41AD-AC8F-7308A0C8FA92}" = Adobe Creative Suite 5 Master Collection
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1DEBA8AA-3FC2-4867-AD29-4CE4A95E1029}" = Nero 8
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1E2FDD18-E514-4631-AF4A-0CC58FD93DCB}" = Quake Live Mozilla Plugin
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{210DFA65-F805-1A2B-4F83-8E27279AE385}" = Catalyst Control Center Graphics Previews Common
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 37
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{29822CAD-C76A-0BEE-55F5-AAA524DA814F}" = CCC Help Greek
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30482B99-CAD6-4370-8A3B-8939BCDC90EC}" = Email Extractor
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A1293DF-7D09-BB0F-9576-EC47EE4A9362}" = CCC Help Italian
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3BEF9769-BA52-18F7-1D02-2362F6A27E38}" = Adobe Media Player
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{41A63ADA-088B-1C2D-43B3-E4087FE79881}" = Pixlr-o-matic
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45C8D17D-B5E0-4e93-8370-4329AB16D2A0}" = Battlefield 3™ Open Beta
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{47416F0B-6589-591E-C6F8-4235D2230B14}" = Catalyst Control Center InstallProxy
"{48530DE6-19F9-489D-809E-AFAA8AACC6DF}" = SplitMediaLabs VH Screen Capture Driver (x86)
"{48EB0E22-B055-44B5-B566-057F145CB7E7}" = ManicTime
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{4D68D398-7760-426D-8395-83EE0676FC7E}" = Antares Auto-Tune Evo RTAS
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{625FC7D1-656D-1BEC-F86F-3EACAFDAA8FE}" = CCC Help English
"{62FF6AF0-A718-4E31-A499-016BD655F060}" = Web Album Copier
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C472DFC-6D44-4947-9E1A-F79A2469D953}" = eTesty - autoškola
"{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}" = Tom Clancy's Splinter Cell Conviction
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7236672F-6430-439E-9B27-27EDEAF1D676}" = Diagnostic Utility
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7351EEF8-9D6C-5F46-5A19-F2C7456CE132}" = CCC Help German
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7F172E34-4107-8964-6AEA-5051FFD265FF}" = CCC Help Portuguese
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{80074966-5231-428D-9AE7-B7D5D2DC3246}" = Readon TV Movie Radio Player 7.6.0.0
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86095E92-1959-8364-920E-82E81F64F8FB}" = Catalyst Control Center
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89D05F35-933A-89C0-B935-C92BEE4229BD}" = CCC Help French
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{915153F8-1429-40AE-B005-E3BFA7097672}" = Audiggle
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{93F85AA6-C06F-4B62-8A1B-1C83479C805C}" = ArcSoft VideoImpression 2
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{959E4378-CCA1-E4E4-2425-793DA92E8D95}" = CCC Help Czech
"{96BB3C67-4EB4-9757-E0C2-C0D2FE9053B1}" = CCC Help Turkish
"{974F4B73-2017-E174-9070-3F58F01B341F}" = CCC Help Danish
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98E20A18-3C29-86FA-50B4-918C2B34A082}" = CCC Help Hungarian
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9E2E5EB3-DC6E-9277-E9DB-13175E7DDA39}" = CCC Help Dutch
"{9FB9BA8A-E711-40E6-BBF0-77ED60A2940F}" = Facebook Messenger 2.1.4587.0
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A64479BE-7DB6-4B07-87B9-70AD85B7EAD2}" = Medal of Honor™ MP Beta
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAACC0A5-4382-04D0-C75E-0669C7B949B6}" = CCC Help Japanese
"{AB49B509-8FCA-45E6-9FB9-9E4AEEB8F148}" = System Requirements Lab CYRI
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_952" = Adobe Acrobat 9.5.2 - CPSID_83708
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Czech
"{ACEF4078-9B86-2455-E18D-34D52D37D9D5}" = CCC Help Chinese Standard
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{B55FB422-B803-11F5-5582-B3666EA1B9AC}" = Catalyst Control Center Localization All
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8010864-15F8-613B-20EF-AC35B14B3E0D}" = CCC Help Russian
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB47D7EA-7EF1-475C-9C14-AF5B8FCA45E2}" = Condemned - Criminal Origins
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}" = Need for Speed™ SHIFT
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C1342411-5A98-DE8A-5629-D0C518E1C280}" = CCC Help Finnish
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5A31DDC-157A-4DD7-9B5C-C692A06F61FD}" = Prison Break
"{C5AF183C-11D5-403F-8B99-85F6BBBF585E}" = Gothic
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{C8793276-2F36-454A-A524-9957B979FDE1}" = SceneGrabber.NET
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{D08B4177-5160-6B66-8934-2F9012134D61}" = CCC Help Thai
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.4 Game
"{D34A6029-FB1A-9EA8-A938-5393F82A3A00}" = CCC Help Korean
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.19.365
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3A09D13-4D40-3CF8-7D32-8BD55F8D1533}" = CCC Help Spanish
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E58C571A-D165-AF15-5CBD-B3B77CFD5B61}" = HydraVision
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EAEAAF8C-8E86-4CAC-AC08-1A33EDCA34AC}" = Prince of Persia The Forgotten Sands™
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EE74D039-45D7-44E9-BF95-B9CFB015964F}_is1" = ArcaniA - Gothic 4 Hotfix
"{EE91E474-9298-47B8-817F-8E0042408998}" = Risen Hotfix 1.01
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F241EC95-C81A-466E-8006-6B0B364B07A0}" = PCMark Vantage
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F2C35491-9323-3AE7-6023-6B4128045153}" = CCC Help Swedish
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX
"{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein
"{FAF34181-8A35-4182-B297-EB7E0F5B7A5A}" = XSplit
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FC66A32F-1A57-AC5C-4F12-DAC2F4CB77A0}" = CCC Help Chinese Traditional
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFF74EC9-1FF4-4456-99E3-4F05129F4FAB}" = Antares Auto-Tune Evo VST
"µTorrent CZ_is1" = µTorrent CZ 1.8.5 (build 17414)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Afterburner" = MSI Afterburner 1.5.0
"All2WAV Recorder_is1" = All2WAV Recorder 3.20
"AMD GPU Clock Tool" = AMD GPU Clock Tool
"Antares Autotune VST RTAS TDM_is1" = Antares Autotune VST RTAS TDM v5.08
"Antares Autotune VST_is1" = Antares Autotune VST v5.09
"Any Video Converter_is1" = Any Video Converter 3.0.3
"ArcaniA" = ArcaniA - Gothic 4
"ASIO4ALL" = ASIO4ALL
"aTube Catcher" = aTube Catcher
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"AV Voice Changer Software 7.0" = AV Voice Changer Software 7.0
"AV Voice Changer Software DIAMOND 5.0" = AV Voice Changer Software DIAMOND 5.0
"AV Voice Changer Software DIAMOND 6.0" = AV Voice Changer Software DIAMOND 6.0
"AviSynth" = AviSynth 2.5
"Battlelog Web Plugins" = Battlelog Web Plugins
"Beauty Pilot Trial_is1" = Beauty Pilot Trial 2.3.0
"BitSpirit_is1" = BitSpirit v3.3.2.352 Stable
"Blu-ray to DVD_is1" = Blu-ray to DVD 1.2.0.14
"Bomber 1.0" = Bomber 1.0
"ClickBall Freeware Edition" = ClickBall Freeware Edition
"Clownfish" = Clownfish for Skype
"Collab" = Collab
"com.adobe.amp.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Media Player
"Counter-Strike: Source" = Counter-Strike: Source
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Email Extractor" = Email Extractor
"eMail Extractor_is1" = eMail Extractor 3.5.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESN Sonar-0.70.0" = ESN Sonar
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30
"FileZilla Client" = FileZilla Client 3.5.1
"FL Studio 8" = FL Studio 8
"FMCODEC" = FM Screen Capture Codec (Remove Only)
"Fraps" = Fraps (remove only)
"Free Screen To Video_is1" = Free Screen To Video V 1.2
"GameParkClient_is1" = GamePark
"Hitman Absolution_is1" = Hitman Absolution
"HyperCam 2" = HyperCam 2
"HyperCam 3" = HyperCam 3
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"IL Download Manager" = IL Download Manager
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein
"JDownloader" = JDownloader
"Logitech Vid" = Logitech Vid HD
"MagicEffect Photo Editor 2010_is1" = MagicEffect Photo Editor 2010.2.4
"MAGIX Photo Manager 9 US" = MAGIX Photo Manager 9
"MAGIX Screenshare US" = MAGIX Screenshare
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.65.1.1000
"ManyCam" = ManyCam 2.6.1 (remove only)
"MediaInfo" = MediaInfo 0.7.34 (32-bit)
"Mozilla Firefox 17.0.1 (x86 cs)" = Mozilla Firefox 17.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MTA:SA" = MTA:SA v1.0.4-rc-02033-2-000
"MTA:SA 1.1" = MTA:SA v1.1
"MTA:SA 1.2" = MTA:SA v1.2.0-full-03585-0-000
"MTA:SA 1.3" = MTA:SA v1.3
"MTA:SA Race" = MTA:SA Race 1.1.2
"Mumble" = Mumble and Murmur
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Service Center" = Native Instruments Service Center
"Native Instruments Traktor" = Native Instruments Traktor
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock" = ObjectDock
"OpenAL" = OpenAL
"Opera 11.62.1347" = Opera 11.62
"Origin" = Origin
"Pixlromatic" = Pixlr-o-matic
"PocketInsanity Wolfenstein 3D for PocketPC (SW)" = PocketInsanity Wolfenstein 3D for PocketPC (SW)
"PocketMoku" = PocketMoku
"PoiZone" = PoiZone
"Rainmeter" = Rainmeter (remove only)
"Savage2" = Savage 2 - A Tortured Soul
"SmartMorph" = SmartMorph
"State of War" = State of War
"State of War - Warmonger" = State of War - Warmonger
"Steam App 10" = Counter-Strike
"Steam App 12840" = DiRT 2
"Steam App 150" = Counter-Strike Steamworks Beta
"Steam App 30" = Day of Defeat
"Steam App 570" = Dota 2
"Steam App 630" = Alien Swarm
"Steam App 70" = Half-Life
"TeamViewer 5" = TeamViewer 5
"TeamViewer 6" = TeamViewer 6
"Toxic Biohazard" = Toxic Biohazard
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"Videora HTC Touch Diamond2 Converter" = Videora HTC Touch Diamond2 Converter 5.04
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 2.0.5
"Wallpaperio HTC Touch Diamond2 Maker" = Wallpaperio HTC Touch Diamond2 Maker 2.03
"Warfare Incorporated(TM) for Pocket PC" = Warfare Incorporated(TM) for Pocket PC
"Winamp" = Winamp
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR
"X-ray Anti-Cheat" = X-ray Anti-Cheat
"YouTube Downloader App" = YouTube Downloader App 2.03
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Hotfile Premium Link Generator" = Hotfile Premium Link Generator
"InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"Octoshape Streaming Services" = Octoshape Streaming Services
"QIP 2012" = QIP 2012 4.0.7000
"QUICKMEDIACONVERTER" = QMC
"Uploadinator" = FluffyApp
"Winamp Detect" = Winamp Application Detect
Re: Ubývající místo na C:
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 21.3.2012 2:33:16 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 143116
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 144114
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 144114
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 145112
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 145112
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 146111
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 146111
Error - 21.3.2012 2:33:20 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ OSession Events ]
Error - 13.5.2010 11:29:39 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28
seconds with 0 seconds of active time. This session ended with a crash.
Error - 10.11.2010 17:21:41 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 43
seconds with 0 seconds of active time. This session ended with a crash.
Error - 3.2.2011 14:58:23 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 252
seconds with 0 seconds of active time. This session ended with a crash.
Error - 25.9.2011 8:40:59 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 47
seconds with 0 seconds of active time. This session ended with a crash.
Error - 16.12.2011 16:14:08 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 2105
seconds with 360 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 27.12.2012 4:41:54 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 4:42:11 | Computer Name = Private | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (1:30:15, ?27.?12.?2012) bylo neočekávané.
Error - 27.12.2012 4:42:01 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 18:37:34 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 18:37:46 | Computer Name = Private | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (20:00:55, ?27.?12.?2012) bylo neočekávané.
Error - 27.12.2012 18:37:40 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 28.12.2012 13:08:49 | Computer Name = Private | Source = volsnap | ID = 393252
Description = Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného
uživatelem se nepodařilo zvětšit úložiště stínové kopie.
Error - 29.12.2012 7:27:36 | Computer Name = Private | Source = Service Control Manager | ID = 7011
Description = Při čekání na odezvu transakce služby NIHardwareService bylo dosaženo
časového limitu (30000 ms).
Error - 29.12.2012 10:05:15 | Computer Name = Private | Source = DCOM | ID = 10010
Description =
Error - 29.12.2012 14:22:17 | Computer Name = Private | Source = BROWSER | ID = 8032
Description =
< End of report >
[ Application Events ]
Error - 21.3.2012 2:33:16 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 143116
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 144114
Error - 21.3.2012 2:33:17 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 144114
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 145112
Error - 21.3.2012 2:33:18 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 145112
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 146111
Error - 21.3.2012 2:33:19 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 146111
Error - 21.3.2012 2:33:20 | Computer Name = Private | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ OSession Events ]
Error - 13.5.2010 11:29:39 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28
seconds with 0 seconds of active time. This session ended with a crash.
Error - 10.11.2010 17:21:41 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 43
seconds with 0 seconds of active time. This session ended with a crash.
Error - 3.2.2011 14:58:23 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 252
seconds with 0 seconds of active time. This session ended with a crash.
Error - 25.9.2011 8:40:59 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 47
seconds with 0 seconds of active time. This session ended with a crash.
Error - 16.12.2011 16:14:08 | Computer Name = Private | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 2105
seconds with 360 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 27.12.2012 4:41:54 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 4:42:11 | Computer Name = Private | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (1:30:15, ?27.?12.?2012) bylo neočekávané.
Error - 27.12.2012 4:42:01 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 18:37:34 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 27.12.2012 18:37:46 | Computer Name = Private | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (20:00:55, ?27.?12.?2012) bylo neočekávané.
Error - 27.12.2012 18:37:40 | Computer Name = Private | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.
Error - 28.12.2012 13:08:49 | Computer Name = Private | Source = volsnap | ID = 393252
Description = Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného
uživatelem se nepodařilo zvětšit úložiště stínové kopie.
Error - 29.12.2012 7:27:36 | Computer Name = Private | Source = Service Control Manager | ID = 7011
Description = Při čekání na odezvu transakce služby NIHardwareService bylo dosaženo
časového limitu (30000 ms).
Error - 29.12.2012 10:05:15 | Computer Name = Private | Source = DCOM | ID = 10010
Description =
Error - 29.12.2012 14:22:17 | Computer Name = Private | Source = BROWSER | ID = 8032
Description =
< End of report >
Re: Ubývající místo na C:
Z nelegalniho ESETu jste se mozna vyvlekl, jak se vyvleknete nyni z podezreni na nelagalni operacni system??
Re: Ubývající místo na C:
Prosím Vás, je legální, jak jste k tomuto podezření došel?
Re: Ubývající místo na C:
Uz me to tu nejak prestava bavit a dochazi mi trpelivost...
V PC mate crack na ESET a tvrdite ze je legalni, v PC mate crack na Windows a presto tvrdite ze je legalni...
Nejak moc nahod a protikladu se nam tu sbiha nemyslite
V PC mate crack na ESET a tvrdite ze je legalni, v PC mate crack na Windows a presto tvrdite ze je legalni...
Nejak moc nahod a protikladu se nam tu sbiha nemyslite
