Stránka 1 z 1

pro Murphyho Pc se seka

Napsal: 14 lis 2011 14:13
od Ver
pro Murphyho

Dobrej den,

tak jse tu zase ale tentokrat je to zas jinej pc,
mohl by jste mi na to mrknout, Pc je zasekany, obcas se kousne atd...
diky moc :D

tady je log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by - at 2011-11-14 14:09:54
Microsoft® Windows Vista™ Ultimate Service Pack 2
System drive C: has 133 GB (46%) free of 286 GB
Total RAM: 4093 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:09:56, on 14/11/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE
C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe
C:\UPS\WSTD\WSTDMessaging.exe
C:\UPS\WSTD\UPSNA1Msgr.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files\trend micro\-.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [ToolboxFX] "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Intuit Data Protect.lnk = C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
O23 - Service: QuickBooksDB21 - Intuit, Inc. - C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11903 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
winlogon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\nvvsvc.exe -session -first
taskeng.exe {4ADF6E79-5B42-4A2A-8DC6-8F0583926FF6}
taskeng.exe {F1665DBA-5CA9-4E04-BD25-E7787710BA22}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
"C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe -sUPSWSDBSERVER
"C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe" -Embedding
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
"C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe"
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe"
WLIDSvcM.exe 3228
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
"C:\Program Files\HP\HP LaserJet Professional CM1410 Series\Fax Driver\hppfaxprintersrv.exe" "HP LaserJet Professional CM1410 Series Fax"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
"C:\Windows\ehome\ehtray.exe"
"C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe" /Startup
"C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe"
"C:\Windows\System32\rundll32.exe" P17RunE.dll,RunDLLEntry
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe"
"C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE" -silent
"C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
"C:\UPS\WSTD\WSTDMessaging.exe"
"C:\UPS\WSTD\UPSNA1Msgr.exe"
"C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
"C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
C:\Windows\system32\conime.exe
"C:\Program Files (x86)\Browny02\BrYNSvc.exe"
"C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe" -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding
C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB21
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 752 756 764 65536 760
"C:\Users\-\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1584184]
"HP LaserJet Professional CM1410 Series Fax"=C:\Program Files\HP\HP LaserJet Professional CM1410 Series\Fax Driver\hppfaxprintersrv.exe [2010-04-09 3707704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1555968]
"msnmsgr"=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2011-05-13 4283256]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 138240]
"OfficeSyncProcess"=C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2011-07-21 718720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-09-05 35736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [2011-06-02 6123032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-10-13 17351304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^-^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2 .lnk]
C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry []
"ToolboxFX"=C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe [2010-04-16 58936]
"Intuit SyncManager"=C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2011-06-14 1527128]
"NA1Messenger"=C:\UPS\WSTD\UPSNA1Msgr.exe [2010-12-09 24576]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2010-06-10 2621440]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Intuit Data Protect.lnk - C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
QuickBooks Update Agent.lnk - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickBooks_Standard_21.lnk - C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE
UPS WorldShip Messaging Utility.lnk - C:\UPS\WSTD\WSTDMessaging.exe
UPS WorldShip PLD Reminder Utility.lnk - C:\UPS\WSTD\wstdPldReminder.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ntrexeservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux7"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-11-14 14:05:12 ----D---- C:\rsit
2011-11-14 14:05:12 ----D---- C:\Program Files\trend micro
2011-11-14 13:54:09 ----D---- C:\ProgramData\WindowsSearch
2011-11-10 09:18:54 ----A---- C:\Windows\system32\drivers\tcpip.sys

======List of files/folders modified in the last 1 month======

2011-11-14 14:09:37 ----D---- C:\Windows\Temp
2011-11-14 14:06:40 ----D---- C:\Windows\System32
2011-11-14 14:06:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-14 14:06:39 ----D---- C:\Windows\inf
2011-11-14 14:05:12 ----RD---- C:\Program Files
2011-11-14 14:02:31 ----A---- C:\Windows\wstdUPSWSHIP.INI
2011-11-14 13:54:09 ----HD---- C:\ProgramData
2011-11-14 13:09:08 ----SHD---- C:\System Volume Information
2011-11-14 12:49:33 ----D---- C:\Users\-\AppData\Roaming\Skype
2011-11-14 09:40:54 ----D---- C:\Windows\system32\FxsTmp
2011-11-11 17:27:24 ----D---- C:\Windows\winsxs
2011-11-11 17:27:23 ----D---- C:\Windows\system32\catroot
2011-11-11 10:40:49 ----D---- C:\Windows\Prefetch
2011-11-11 09:01:09 ----D---- C:\Windows\system32\drivers
2011-11-10 18:25:45 ----D---- C:\Program Files\Windows Mail
2011-11-10 18:25:45 ----D---- C:\Program Files (x86)\Windows Mail
2011-11-10 18:25:43 ----SHD---- C:\Windows\Installer
2011-11-10 18:25:38 ----D---- C:\ProgramData\Microsoft Help
2011-11-10 18:25:15 ----D---- C:\Program Files\Common Files\System
2011-11-10 18:23:38 ----A---- C:\Windows\system32\mrt.exe
2011-11-10 09:09:02 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-11-08 09:36:59 ----D---- C:\Windows\system32\Tasks
2011-11-08 09:36:58 ----RD---- C:\Program Files (x86)\Skype
2011-11-08 09:36:57 ----D---- C:\ProgramData\Skype
2011-11-07 19:03:38 ----D---- C:\Windows\system32\catroot2
2011-11-07 15:54:03 ----D---- C:\UPS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-11 160744]
R3 b57nd60a;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60a.sys [2008-10-22 390656]
R3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 275456]
R3 HPFXBULKLEDM;HPFXBULKLEDM; C:\Windows\system32\drivers\hppdbulkio.sys [2010-04-22 22040]
R3 HPFXFAX;HPFXFAX; C:\Windows\system32\drivers\hppdfaxio.sys [2010-04-22 23576]
R3 lvpepf64;Volume Adapter; C:\Windows\system32\DRIVERS\lv302a64.sys [2009-04-30 15896]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2009-05-01 327576]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-01-30 13809384]
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V64.SYS [2009-04-30 2755096]
R3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 98944]
R3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 41984]
S3 Blfp;Broadcom Advanced Server Program Driver; C:\Windows\system32\DRIVERS\basp.sys [2008-10-30 99328]
S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 11008]
S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 7936]
S3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2009-08-03 1289216]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 108544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2008-11-18 307200]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 27648]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000]
R2 MSSQL$UPSWSDBSERVER;SQL Server (UPSWSDBSERVER); c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 27648]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-31 159336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 27648]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2011-07-06 45056]
R2 QBVSS;QBIDPService; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-06-30 1248256]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 153440]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760]
R3 QuickBooksDB21;QuickBooksDB21; C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe [2010-04-27 679936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-06 136176]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-12-23 79360]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-06 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-19 19968]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2009-07-23 61440]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 14:36
od Mc_Murphy
Ahojky Verunko. Obrázek

Jsem velice polichocen, že se obracíš přímo na mě :oops:, tak jdeme na to. :thumbsup:

:???: Microsoft® Windows Vista™ Ultimate - jsou legální? :?:
:arrow: Aktualizuj MS Internet Explorer na poslední verzi. Aktualizace řeší spoustu problémů v systému samotném.

:arrow: Potom fixni v HJT tyto položky:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)


"Fixnout" znamená, že spustíš HJT, zvolíš možnost [Do a system scan only] a zaškrtneš čtvereček vlevo od mnou vypsaných položek. Poté klikneš na [Fix checked] a odsouhlasíš [ANO].
HJT najdeš zde: C:\Program Files\trend micro\-.exe

:arrow: A dále stáhni OTL z tohoto odkazu a ulož jej na Plochu.
  • Pokud používáš Win Vista či Win7, klikni na OTL pravým myšítkem a dej Run As Administrator či Spustit jako správce.
  • Pokud používáš 64bitový OS, zkontroluj, zda-li je zaškrtnutý čtvereček Pro 64 bitové OS. Pokud ne, zaškrtni jej.
  • Zaškrtni okénko Pro všechny uživatele.
  • Zaškrtni okénko Kontrola na havěť "LOP".
  • Zaškrtni okénko Kontrola na havěť "Purity".
  • Stáři souborů změň z 30 dnů na 7 dnů.
  • Do spodního okénka Vlastní skenování/opravy vlož tento script:

Kód: Vybrat vše

safebootminimal 
safebootnetwork
drivers32
savembr:0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
/md5start
scecli.dll
autochk.exe
csrss.exe
explorer.exe
lsass.exe
services.exe
smss.exe
spoolsv.exe
svchost.exe
userinit.exe
winlogon.exe
atapi.sys
cdrom.sys 
ndis.sys
ntfs.sys
tcpip.sys
%SystemDrive%\PhysicalMBR.bin
/md5stop
C:\windows\system32\spool\prtprocs|dll;true;true;true /FP
%systemroot%\system32\drivers\*.sys /5
%systemroot%\system32\drivers\*.sys /X 
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\*.* /5
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\config\*.sav 
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\*.* /U /s
%systemroot%\*. /mp /s
%ALLUSERSPROFILE%\Data Aplikací\*.*
%ALLUSERSPROFILE%\Data Aplikací\*.exe /s
%ALLUSERSPROFILE%\Dáta aplikácií\*.*
%ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s
%APPDATA%\*.
%APPDATA%\*.*
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
*legalizator* /s
*registration* /s
*Office 2010* /s
*AutoRearm* /s
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c
type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5
  • Klikni na tlačítko Prohledat.
  • Po dokončení skenu se objeví logy OTL.txt a Extras.txt, oba mi sem vlož.
  • Logy se nevejdou do jednoho, rozděl je tedy prosím do více příspěvků.

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 16:15
od Ver
No asi jo, neni to primo muj Pc...
takze jsem aktualizovala ten expl.
a tady je ten scan

OTL Extras logfile created on: 14/11/2011 15:55:53 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\-\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 54.10% Memory free
8.20 Gb Paging File | 5.97 Gb Available in Paging File | 72.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 127.85 Gb Free Space | 45.75% Space Free | Partition Type: NTFS
Drive D: | 4.38 Gb Total Space | 3.97 Gb Free Space | 90.65% Space Free | Partition Type: UDF

Computer Name: PC_VERONIKA | User Name: - | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-711281013-1559387861-798609812-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 1
"FirewallOverride" = 0
"VistaSp1" = 7F 77 16 BC A0 AD CB 01 [binary data]
"VistaSp2" = 1B 42 21 DD A6 AD CB 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05B8E91E-AD66-4689-BA55-E33CC31161B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{082DA1C1-B783-4871-A221-EA1523EA0A27}" = rport=137 | protocol=17 | dir=out | app=system |
"{19F2666C-5A14-4A69-8378-390D5C2A133F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1B3E8E65-75FF-4D55-8DD2-92A61BE54DEA}" = rport=10243 | protocol=6 | dir=out | app=system |
"{2A53024E-BC3B-465A-94AD-D0A5F26F557E}" = lport=138 | protocol=17 | dir=in | app=system |
"{2A8D0194-4AD8-4551-97A4-E9AADFFCB9E6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2CA833E4-E3FA-4B9A-8BAD-C036EB1F033E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{54E8F899-A2BC-47B3-905D-76E024DF4DFC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{59B0D351-2C98-41FB-AE0B-947124E130D3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6BCB6B60-F0C7-4E7E-BB2C-388E0F5B2FB0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{741CA5A9-221D-4697-8313-0AEEAA8ED1C3}" = lport=3389 | protocol=6 | dir=in | app=system |
"{76241B8C-9092-48B4-BD0B-C1E9F31EBCFC}" = rport=445 | protocol=6 | dir=out | app=system |
"{83EC9969-6510-4528-904C-01A6B1177F4E}" = rport=138 | protocol=17 | dir=out | app=system |
"{9441C91D-333C-4A5B-A2F0-A42E45F6296B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9E5C9A8B-1B9C-4C36-8D9A-954591A6DB16}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9EA9230F-E26E-46D8-B7D1-71D0C93CFDFF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{9EE0782C-AB9E-4B7D-9B81-B18F37835C85}" = lport=139 | protocol=6 | dir=in | app=system |
"{B456C038-02E3-4533-B50A-6C670728CD06}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{BA030386-A57E-4D6E-A245-09026625F5A3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CFC7C892-A80D-4A82-A8B0-F815FD9D19B2}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DBED456B-3E5F-4430-B27F-0A1B234BF469}" = lport=445 | protocol=6 | dir=in | app=system |
"{EA6CC5F7-5E9B-47B5-BA62-E2C2BEC4BCC0}" = lport=137 | protocol=17 | dir=in | app=system |
"{FF1F49F4-F40E-43C0-864D-B2901D02E27A}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{082FD3F1-933D-493D-8107-15E637CCF347}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{14017775-F7DB-4D0E-A9AE-628C884105DD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{15FA7962-7ABB-460C-AD43-DDB59EE978C9}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{1EEB7502-3E12-4268-A84B-1F97158E885B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1F0B7B87-5DCC-4AB3-BFED-F817971B7F87}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{21A8B8DD-1773-42DB-8822-F53E528F1222}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{263F1C75-FBF5-4039-9094-57C68F2031B6}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{26FD5674-3F31-4AF7-857F-0245A1DA7C9F}" = protocol=6 | dir=out | app=system |
"{2B5C1235-E37A-4EEF-9F5E-B88560191CCC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{31E90EA0-9DA8-44D9-8259-33E59110F597}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{34BB2231-62EF-4B53-ACDD-43DDD8527C4D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{399BA19A-564F-4B4B-94DE-1E2A3FF2EAA0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3B3A6AAE-E9BE-4E7C-B68B-671C1F0CB7E0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3FC79E12-15EB-4B90-9E5B-9C322F8E9DBA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{44E124F0-8AB0-4C40-BCBE-B0C62748DB95}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4B576B6A-CE05-42A3-AD86-206926D2FB66}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4FD2C4CD-6C16-4A5E-941D-209B2673B65A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{57F39CE7-89D0-4BBA-8B3C-CB474C1067A9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{6152B818-FB88-4D62-AEF3-A5838BD5D728}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{71D5D0CC-AF2B-47E5-9268-F2EB69E2E7DF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{7BC9F071-7331-4F0C-A58F-731704A7CDE9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8C37FDAC-CA37-48FB-B634-BBC8DDA93F27}" = protocol=17 | dir=in | app=d:\dvd-start.exe |
"{8EE963A3-BA65-40DA-B6A7-E7EA5A0DBD20}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{96D6029D-E152-47DD-994C-43992C3D87BE}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{975C958C-AEA5-425B-8B1A-4966B566A04F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{98F59A9C-2C58-4413-92F1-0461DEBAF01A}" = protocol=6 | dir=in | app=d:\dvd-start.exe |
"{9B3406F4-8766-47FB-A41C-EA3FCBDF6D12}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9C10CBAC-0D24-494D-9365-83F4CDA943BE}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{A44A6753-457D-4062-B5E8-05706214D2E7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{A71E6719-979A-4D0B-B221-AA8FCB26A971}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{AFCF4EA4-7B50-4A88-A119-4E376769B228}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B01E7A3A-A5DE-4380-8B72-E7C069D52335}" = protocol=6 | dir=in | app=d:\dvd-start.exe |
"{B5D88470-2264-4C66-9AC8-9EEF6405D023}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BA2F2026-95E9-4B14-9A7B-DCB5A8EE2FB8}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{BDA17041-D5CA-4121-8E9F-95599FFAB237}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{C1DACE82-29D0-480A-9FDF-375765BC619C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CB7EB547-F497-4E62-848A-8DC9C0056C07}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{CF92BE05-891D-4EA9-B9C5-D8B7194323A2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D660BB3D-7C8B-49D9-88D9-CBC78EDF4E48}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DA685165-4DBB-4579-A5D3-46CE0D477BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{DF0D9C3B-82A0-45C5-AA12-F41A23304765}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{EFBA3950-7805-4CD4-AF45-D6D743516DB7}" = protocol=17 | dir=in | app=d:\dvd-start.exe |
"{F402E60F-9E33-4217-AF53-36EF3333A7A9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FE3CC0C4-CC16-4755-9AB6-645C8521EE16}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FF32859E-202B-4FB7-BA68-2D84F8E71535}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"TCP Query User{5F320BB5-4B32-4A41-9263-34D30695A107}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{405A032F-E63B-4B1F-8874-1A4A7AB780F1}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{101738D7-D805-37A9-BB91-1F2C351782BF}" = Microsoft .NET Framework 3.5 Language Pack SP1 - nld
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources
"{553BB3BD-7A2A-4E5E-9B2F-2D14DC70093A}" = Windows Live Family Safety
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{7BE034E9-D414-496A-974A-6671F161F02A}" = Broadcom NetXtreme-I Netlink Driver and Management Installer
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
"{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
"{C788B026-20BD-4E96-B698-533F1D6C5013}" = 64 Bit HP CIO Components Installer
"{C92556F2-4950-48CF-ABA3-F0026B05BCE8}" = Microsoft SQL Server 2005 Backward compatibility
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 3.5 Language Pack SP1 - nld" = Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06F8CD93-C722-45E9-A9A4-F48F78E39E84}" = hppFaxUtilityCM1410
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EF0EA0D-F945-4958-85CC-60FF1E86D216}" = HP LaserJet Professional CM1410 Series
"{11E0AC7D-6822-4F67-865F-EE1C13D28C38}" = QuickBooks Pro 2011
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1D70AABC-CB59-4700-A708-EA56D1CA07B0}" = QuickBooks
"{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21749F4E-02A1-4828-9A1E-BBDF5929C5D0}" = HP LJ CM1410 MFP Series HP Scan
"{229D6185-BD7E-494B-A73B-C5215BE0690E}" = HPLJUT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A033A00-FE0D-4609-B0E8-2C49CC494FC8}" = WorldShip
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (UPSWSDBSERVER)
"{33035862-543C-4405-9CC6-08593CF2C25F}" = ReportServer
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{390160B4-D276-4A04-8002-8D3101A0D367}" = UPSICC
"{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AE3EAC8-FAD9-4ECC-A339-BBAD8C72DE71}" = UPSDB
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B59C2A-EFB8-44AC-88F5-3280171E4522}" = PolicyManager
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5AE59A84-B2F3-42CC-A246-5AF80F6EE770}" = Reconciler
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68AF09E3-1167-4771-903C-CCCDCF7E171C}" = NRF
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C5BD501-AD5D-4A75-9321-076509B438FC}" = WebHelp
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9207A8EC-3B2D-4A4A-8BF7-957FC19BB3DE}" = Zebra Setup Utilities
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{92F91A05-8241-4651-B9F4-9D04EE1F2634}" = hppSendFaxCM1410
"{95749C5B-BC37-41E3-8D39-EEF4C21A2825}" = CCC
"{95BFC573-7D09-46C9-B458-A75BA947FFCB}" = UPSVC2008MM
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FA7A537-E6F6-4A6E-95B9-E4152756132D}" = hppCM1410LaserJetService
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A5763105-D1D5-4862-A3FE-EC058F9AA73E}" = ICCHelp
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AABE44D1-0B72-4C6B-9778-20B2317F8064}" = hpzTLBXFX
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B44F3823-52DD-45CA-A916-8B320778715D}" = Messenger Companion
"{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení
"{BC728F95-2D3F-4D05-9E1E-F2A3CEBF3FE8}" = FormsComponent
"{C23415D8-FE94-4F52-B5C4-0FFA2202C6D9}" = UPSVCMM
"{C30E30A6-0AB5-470A-AB67-D322938F5429}" = SupportUtility
"{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9C16E4B-4FDD-4A31-8B8F-EC402082407A}" = HPLaserJetHelp_LearnCenter
"{C9D43B38-34AD-4EC2-B696-46F42D49D174}" = MSIChecker
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF2962CB-E3E7-4AA5-B6CE-EE59A600ECBE}" = UnifiedPrinting
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D44E7219-947E-4F1B-830E-66EF11ACC543}" = NA1Messenger
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D608C59B-424B-45D4-971C-5978F8564CEE}" = hppLaserJetService
"{DA5576B5-EF2A-4E3A-8763-FCA8BA84DA00}" = hppTLBXFXCM1410
"{DB2C58E0-6284-4B48-97F2-22A980B6360B}" = System
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2A97415-BD97-4867-B906-05E39E9EE51F}" = HL-2250DN
"{E358CC1E-4953-4E27-ADEB-8B27D8BBC20E}" = UPSlinkHTTP
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EA9629DA-5715-48BA-B054-28169702B176}" = FOSS
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2979AAA-FDD7-4CB3-93BC-5C24D965D679}" = Windows Live Messenger
"{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"{FFD7B2D9-AC9D-468C-83A2-21017A811623}" = hppFaxDrvCM1410
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AudioCS" = Creative Configuratiescherm voor geluid
"Barcode Generator & Overprinter6.6.10" = Barcode Generator & Overprinter
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"EasyLanguage_is1" = EasyLanguage
"Google Chrome" = Google Chrome
"Great Barcode Generator" = Great Barcode Generator
"Logitech Vid" = Logitech Vid HD
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 8.0 (x86 cs)" = Mozilla Firefox 8.0 (x86 cs)
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"UPS WorldShip" = UPS WorldShip
"VLC media player" = VLC media player 1.1.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YTdetect" = Yahoo! Detect
"Zebra Font Downloader_is1" = Zebra Font Downloader
"Zebra Setup Utilities" = Zebra Setup Utilities

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-711281013-1559387861-798609812-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"PhotoFiltre Studio X" = PhotoFiltre Studio X

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 16:16
od Ver
OTL logfile created on: 14/11/2011 15:55:53 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\-\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.16 Gb Available Physical Memory | 54.10% Memory free
8.20 Gb Paging File | 5.97 Gb Available in Paging File | 72.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 127.85 Gb Free Space | 45.75% Space Free | Partition Type: NTFS
Drive D: | 4.38 Gb Total Space | 3.97 Gb Free Space | 90.65% Space Free | Partition Type: UDF

Computer Name: PC_VERONIKA | User Name: - | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - [2011/11/14 15:54:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\-\Desktop\OTL.exe
PRC - [2011/11/10 09:09:01 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/05 08:26:05 | 005,828,952 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
PRC - [2011/07/06 18:45:32 | 001,178,984 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE
PRC - [2011/07/06 17:39:58 | 000,045,056 | ---- | M] (Intuit) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2011/06/30 12:25:52 | 001,248,256 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
PRC - [2011/03/08 23:49:44 | 000,422,912 | ---- | M] () -- C:\UPS\WSTD\WSTDMessaging.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/12/10 17:29:30 | 029,293,408 | ---- | M] (Microsoft Corporation) -- c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2010/12/09 15:40:28 | 000,024,576 | ---- | M] () -- C:\UPS\WSTD\UPSNA1Msgr.exe
PRC - [2010/04/27 23:36:44 | 000,679,936 | ---- | M] (Intuit, Inc.) -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QBDBMgrN.exe
PRC - [2010/04/16 11:32:48 | 000,058,936 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe
PRC - [2010/04/12 09:13:08 | 000,142,336 | ---- | M] (HP) -- C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
PRC - [2010/01/25 07:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe
PRC - [2010/01/15 13:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/10/14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 00:47:22 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/04/10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/18 13:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/10 09:09:01 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/10/13 09:22:37 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5aab9bc687029a908fc01473f8e5f77b\UIAutomationProvider.ni.dll
MOD - [2011/10/13 09:21:58 | 017,404,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\6b2ee1fdc6a182722db04af9c3cd10c3\System.ServiceModel.ni.dll
MOD - [2011/10/13 09:21:34 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll
MOD - [2011/10/13 09:21:32 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6b88a2bf58d8529fc33f8f3437a7ff06\System.Web.Services.ni.dll
MOD - [2011/10/13 09:21:31 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
MOD - [2011/10/13 09:21:30 | 000,627,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\02768700bc8f762ccfe37785ba8eb498\System.EnterpriseServices.ni.dll
MOD - [2011/10/13 09:21:29 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll
MOD - [2011/10/13 09:21:29 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8f3b3ab45e3e5fa61aa6cbfe2a8b61af\System.Transactions.ni.dll
MOD - [2011/10/13 09:21:15 | 001,801,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\4e0e6e88d80780d87bb74e72d5bb1230\System.Deployment.ni.dll
MOD - [2011/10/13 09:21:14 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f97b31da89858b85c70b4eb45bc91ace\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2011/10/13 09:21:11 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
MOD - [2011/10/13 08:05:58 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll
MOD - [2011/10/13 08:05:46 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
MOD - [2011/10/13 08:05:39 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
MOD - [2011/10/13 08:05:29 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\9e53d9921c4bb153f1ffbe1ae0e1b615\System.Data.ni.dll
MOD - [2011/10/13 08:05:25 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\a272814095d94aad779e9d07b2e877c9\System.Core.ni.dll
MOD - [2011/10/13 08:05:22 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\231b0b42eff55de5c7d7debe555c16b7\PresentationFramework.Aero.ni.dll
MOD - [2011/10/13 08:05:21 | 014,328,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94f892556ec9fa7a508fc9d214ceaedf\PresentationFramework.ni.dll
MOD - [2011/10/13 08:05:08 | 012,216,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll
MOD - [2011/10/13 08:04:57 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll
MOD - [2011/10/13 08:04:54 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/10/13 08:04:49 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/08/05 08:26:05 | 000,083,800 | ---- | M] () -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.XmlSerializers.dll
MOD - [2011/07/06 18:46:36 | 000,100,712 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\ReportBridge.DLL
MOD - [2011/07/06 18:46:14 | 000,125,288 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QBMAPILibrary.dll
MOD - [2011/07/06 18:46:12 | 000,069,992 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QB2WPFBridge.dll
MOD - [2011/07/06 18:46:12 | 000,020,840 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QBCompressor.DLL
MOD - [2011/07/06 18:45:56 | 000,042,344 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\mbpopup.dll
MOD - [2011/07/06 18:45:38 | 000,268,648 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\boost_regex-vc90-mt-p-1_33.dll
MOD - [2011/07/06 18:45:38 | 000,176,488 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-p-1_33.dll
MOD - [2011/07/06 18:45:36 | 000,346,984 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\BackupLib.dll
MOD - [2011/03/08 23:49:44 | 000,422,912 | ---- | M] () -- C:\UPS\WSTD\WSTDMessaging.exe
MOD - [2010/12/09 15:40:28 | 000,024,576 | ---- | M] () -- C:\UPS\WSTD\UPSNA1Msgr.exe
MOD - [2010/12/09 15:40:26 | 000,045,056 | ---- | M] () -- C:\UPS\WSTD\POLICYMGR\UPS.Components.NA1MessengerServer.dll
MOD - [2010/12/09 15:39:44 | 000,024,576 | ---- | M] () -- C:\UPS\WSTD\POLICYMGR\Microsoft.ApplicationBlocks.Data.dll
MOD - [2010/12/09 15:39:42 | 000,053,248 | ---- | M] () -- C:\UPS\WSTD\POLICYMGR\UPS.Components.PolicyHolder.dll
MOD - [2010/12/09 14:57:30 | 000,018,432 | ---- | M] () -- C:\UPS\WSTD\UPSResourceManager.dll
MOD - [2010/04/16 11:29:52 | 000,119,864 | ---- | M] () -- C:\Program Files (x86)\HP\ToolboxFX\bin\NativeUtils.dll
MOD - [2009/10/14 12:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/10/14 12:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2009/03/29 21:42:20 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/29 21:42:18 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/03/26 14:46:42 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009/02/06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
MOD - [2005/07/19 23:18:00 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Intuit\QuickBooks 2011\zlib1.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/10/07 00:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2008/01/19 09:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/01/19 09:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/07/06 17:39:58 | 000,045,056 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2011/06/30 12:25:52 | 001,248,256 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe -- (QBVSS)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/12/23 16:47:05 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/12/10 17:29:30 | 029,293,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$UPSWSDBSERVER) SQL Server (UPSWSDBSERVER)
SRV - [2010/04/27 23:36:44 | 000,679,936 | ---- | M] (Intuit, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\Intuit\QuickBooks 2011\QBDBMgrN.exe -- (QuickBooksDB21)
SRV - [2010/04/12 09:13:08 | 000,142,336 | ---- | M] (HP) [Auto | Running] -- C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe -- (HP LaserJet Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/25 07:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2010/01/15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/07/23 21:10:38 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2009/03/29 21:42:16 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/11/18 13:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/04/22 23:33:08 | 000,023,576 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hppdfaxio.sys -- (HPFXFAX)
DRV:64bit: - [2010/04/22 23:33:08 | 000,022,040 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hppdbulkio.sys -- (HPFXBULKLEDM)
DRV:64bit: - [2009/10/07 00:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009/10/07 00:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009/08/03 11:12:00 | 001,289,216 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\P17.sys -- (P17)
DRV:64bit: - [2009/05/01 00:01:34 | 000,327,576 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2009/04/30 23:55:56 | 002,755,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV:64bit: - [2009/04/30 23:55:46 | 000,015,896 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lv302a64.sys -- (lvpepf64)
DRV:64bit: - [2008/10/30 17:40:18 | 000,099,328 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\basp.sys -- (Blfp)
DRV:64bit: - [2008/10/22 20:40:22 | 000,390,656 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys -- (b57nd60a)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-711281013-1559387861-798609812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-711281013-1559387861-798609812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-711281013-1559387861-798609812-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "www.seznam.cz"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.3.3
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.3.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.8.20100713041928
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p="


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/10 09:09:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/15 07:18:06 | 000,000,000 | ---D | M]

[2011/01/06 09:44:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\-\AppData\Roaming\Mozilla\Extensions
[2011/11/08 18:09:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions
[2011/01/06 12:18:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/25 16:54:04 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/08 18:09:12 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/05/09 07:44:14 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\engine@conduit.com
[2011/11/10 09:09:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/10 09:09:01 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 15:38:25 | 000,002,208 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\heureka-cz.xml
[2011/10/04 15:38:25 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2010/12/03 19:08:29 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
[2011/10/04 15:38:25 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2011/10/04 15:38:25 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011/10/04 15:38:25 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4dda1b7a&v=7.4 ... earchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/comple ... earchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.106\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U20 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.23\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\-\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Poppit = C:\Users\-\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2006/09/18 22:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HP LaserJet Professional CM1410 Series Fax] C:\Program Files\HP\HP LaserJet Professional CM1410 Series\Fax Driver\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe ()
O4 - HKLM..\Run: [P17RunE] C:\Windows\SysWow64\P17RunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [ToolboxFX] C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D1CC4B1-AE00-4A33-9A2D-598FB46DC5A8}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: ntrexeservice - Service
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: ntrexeservice - Service
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 60 Days ==========

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 16:17
od Ver
[2011/11/14 15:54:28 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\-\Desktop\OTL.exe
[2011/11/14 15:37:57 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/11/14 15:37:56 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011/11/14 15:37:56 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011/11/14 15:37:56 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/11/14 15:37:55 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011/11/14 15:37:55 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011/11/14 15:37:55 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/11/14 15:37:55 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011/11/14 15:37:55 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/11/14 15:37:55 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011/11/14 15:37:55 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011/11/14 15:37:54 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011/11/14 15:37:54 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011/11/14 15:37:54 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011/11/14 15:37:54 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011/11/14 15:37:54 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011/11/14 15:37:54 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011/11/14 15:37:54 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011/11/14 15:37:54 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011/11/14 15:37:54 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011/11/14 15:37:54 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011/11/14 15:37:54 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011/11/14 15:37:53 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011/11/14 15:37:53 | 000,479,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011/11/14 15:37:53 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011/11/14 15:37:53 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011/11/14 15:37:52 | 001,538,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011/11/14 15:35:30 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advpack.dll
[2011/11/14 15:35:30 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011/11/14 15:35:30 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\corpol.dll
[2011/11/14 15:35:29 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011/11/14 15:35:29 | 000,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011/11/14 15:35:29 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
[2011/11/14 15:35:29 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011/11/14 15:35:29 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011/11/14 15:35:29 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011/11/14 15:35:29 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011/11/14 15:35:29 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011/11/14 15:35:29 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011/11/14 15:35:29 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\corpol.dll
[2011/11/14 15:35:28 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011/11/14 15:35:28 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011/11/14 15:35:28 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011/11/14 15:35:28 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011/11/14 15:35:28 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011/11/14 15:35:28 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011/11/14 15:35:28 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011/11/14 15:35:27 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011/11/14 15:35:27 | 000,481,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011/11/14 15:35:27 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011/11/14 15:35:26 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011/11/14 15:35:26 | 000,241,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011/11/14 15:35:26 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011/11/14 15:35:26 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011/11/14 15:35:26 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011/11/14 15:35:26 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011/11/14 15:35:26 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PDMSetup.exe
[2011/11/14 15:35:26 | 000,129,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/11/14 15:35:26 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/11/14 15:35:26 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetDepNx.exe
[2011/11/14 15:35:26 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011/11/14 15:35:26 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011/11/14 15:35:25 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/11/14 15:35:25 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/11/14 15:35:25 | 000,612,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011/11/14 15:35:25 | 000,278,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinFXDocObj.exe
[2011/11/14 15:35:25 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WinFXDocObj.exe
[2011/11/14 15:35:24 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011/11/14 15:35:24 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011/11/14 15:35:24 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011/11/14 15:35:24 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011/11/14 15:35:24 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PDMSetup.exe
[2011/11/14 15:35:24 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/11/14 15:35:24 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/11/14 15:35:24 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/11/14 15:35:24 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/11/14 15:35:24 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetDepNx.exe
[2011/11/14 15:35:24 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011/11/14 15:35:24 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011/11/14 14:05:12 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/11/14 14:05:12 | 000,000,000 | ---D | C] -- C:\rsit
[2011/11/14 13:54:09 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2011/11/14 09:05:25 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{C116B1B1-F00B-4F2A-9E9C-DFC659236A67}
[2011/11/14 09:05:19 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{20DF2B8F-A5C3-4B05-B68B-1E6F100CBC67}
[2011/11/11 09:03:00 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{CEF9CEBD-C070-471E-B602-1C9F117713FB}
[2011/11/11 09:02:53 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{25BF6BDC-4C4B-4B44-81EE-46F262D9DB36}
[2011/11/10 09:07:17 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8E758CF4-434A-4ABE-9E44-750C1D938B77}
[2011/11/10 09:07:13 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{3AEB354F-D2EC-4D84-A768-E913693C0B32}
[2011/11/09 09:03:48 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DFCFB290-2418-44EE-9EED-7CB3DAD3492A}
[2011/11/09 09:03:40 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{117551BF-7922-4690-A513-530398DBE8D9}
[2011/11/08 09:36:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/08 09:03:25 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{A0E6EE57-FBD8-4F7C-8E13-23D01C26152B}
[2011/11/08 09:03:19 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E43D7CB9-13AB-47BE-AE90-E7D7BF71646C}
[2011/11/07 09:05:56 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{2F876271-5A53-4D77-A472-4097E17F6136}
[2011/11/07 09:05:50 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{A5AFF540-1037-46D3-8090-BAD722739349}
[2011/11/04 10:41:32 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\hats
[2011/11/04 08:58:33 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{C4898856-7004-4A38-9B9B-69B285FAAE25}
[2011/11/04 08:58:27 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{1537CC29-6CA5-4886-AE81-C0705B3E200E}
[2011/11/03 09:01:18 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{83E56FAF-9ECF-462C-8100-0E99A79713E4}
[2011/11/03 09:01:12 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5A75483B-692A-4BC1-A8A0-0D80ADC3DBCB}
[2011/11/02 08:56:17 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{268E89A7-311B-4CF8-A5C8-D6BDED21F9B2}
[2011/11/02 08:56:11 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{FA54F92E-3163-4971-A436-51E32A5D9013}
[2011/10/31 10:09:28 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\more names
[2011/10/31 09:06:49 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{4292A6AC-0FDC-4536-86CD-510867CB7654}
[2011/10/31 09:06:43 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8BEC2D03-A064-4FAE-9366-D321BF995A8E}
[2011/10/28 07:59:49 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{B9243AC6-CCAD-4EF6-94E1-33ADE716C1A4}
[2011/10/28 07:59:43 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E03749AB-B0EA-4042-AC80-2241335BA5B2}
[2011/10/27 07:56:35 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{17B7ED67-0218-4727-9835-EE5637EC1EEE}
[2011/10/27 07:56:29 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{61AE950A-CD80-4BAC-B48B-BCA050A2B81D}
[2011/10/26 15:58:07 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\mikado prices
[2011/10/26 07:58:30 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{80E031B0-1FC7-4098-8FB4-4F8BEADAB26E}
[2011/10/26 07:58:23 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{ABA4F1EC-F04A-44DE-832B-A9ADCDF5CCCB}
[2011/10/25 12:34:49 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\PRINT
[2011/10/25 07:51:49 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E27A9C3A-AE91-42BA-8844-89831B47230D}
[2011/10/25 07:51:43 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{17C855B3-88F5-46B4-A6A0-251A62ECE3E8}
[2011/10/24 08:10:55 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\pictures
[2011/10/24 07:58:57 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{592B911C-BE83-4647-988A-3457EA39D422}
[2011/10/24 07:58:49 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{1AEDEE06-356F-47CB-933D-B237C3A44CB1}
[2011/10/24 07:56:53 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{891407E7-2888-4A58-9E9F-1E410AE3187A}
[2011/10/24 07:56:48 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{9DD1A0D2-D8CE-4FB5-AD92-73948015E0D0}
[2011/10/22 09:42:25 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{057A3022-F5CB-4742-9EEA-726A454DADFC}
[2011/10/22 09:42:19 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5DD215B5-D3CD-4A71-A95A-53C324090A15}
[2011/10/21 19:50:38 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{FA017067-C515-4D4C-8E6D-6C076D6AA39F}
[2011/10/21 19:50:36 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{91A8C15E-251A-463B-B04F-9509CE2C09BD}
[2011/10/21 07:50:16 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E8196EFC-1F7A-4306-B78C-2BD8701994C1}
[2011/10/21 07:50:10 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{AC807D5D-3394-4E9B-9077-527D10E8107E}
[2011/10/20 08:10:00 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{44B0CFEB-BA05-4EFC-AB9E-1BEF04D5E8CC}
[2011/10/20 08:09:53 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DBA1758F-96D6-4752-89FD-074B56127FD5}
[2011/10/19 08:28:33 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{A1D3D555-CCFA-4318-9CCF-47B06A3E165A}
[2011/10/19 08:28:31 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{CF76A40E-6FD0-4645-9906-19F0F4EAE0B7}
[2011/10/19 08:28:18 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5E07D047-2F89-4737-BE11-D8B732B099FD}
[2011/10/19 08:28:05 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{CC3DBD73-9491-43C0-94C4-EE935678B7A3}
[2011/10/18 08:10:51 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{7C606C07-E782-4555-88D4-3B93011BC015}
[2011/10/18 08:10:50 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{03285DCE-4C55-4DB4-B662-8CABCC228511}
[2011/10/18 08:10:27 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{C76CD244-EAA6-4C68-AB71-7BC4C18C1C35}
[2011/10/18 08:10:21 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{A5FBE171-FE3E-4106-ADFD-8FDE0793B539}
[2011/10/17 08:06:02 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{7EE0DE87-55AE-46BA-8475-C402C23DEDB6}
[2011/10/17 08:05:55 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{CDD1C30F-6D29-4208-BE49-B9D933F5456F}
[2011/10/14 08:03:22 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{18EC3601-D2F1-4699-ADB2-3DE188B12C2D}
[2011/10/14 08:03:20 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{3E1E424E-94B9-4236-A1C3-8814AE4A0435}
[2011/10/13 08:02:32 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{A92105F5-0A50-4759-B1AE-6ABB3EF2829B}
[2011/10/13 08:02:24 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DE0EDA79-626C-47EC-A9AC-7821326F7565}
[2011/10/12 08:18:48 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2011/10/12 08:18:47 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2011/10/12 08:18:47 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 08:18:47 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 08:18:47 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 08:18:47 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 08:18:43 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2011/10/12 08:18:43 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 08:18:43 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2011/10/12 08:18:43 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 08:18:43 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 08:18:43 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 08:18:43 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 08:18:43 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/12 08:08:50 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{527DDB79-DD39-4E2A-B827-8604532B67AE}
[2011/10/12 08:08:45 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{F44032C4-36FF-4C22-8A58-1B89C685DF41}
[2011/10/11 08:09:05 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E14AA9AE-A3EA-4885-BBA3-702B3756C5A4}
[2011/10/10 20:08:59 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8AE68CB7-128F-4653-9F49-7BB84853E40D}
[2011/10/10 20:08:58 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{E50C18BB-6D4A-4359-A4F9-B45E384E9DFC}
[2011/10/10 08:08:37 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{1E06EF09-16DA-4130-B404-BB7E6F1FEE10}
[2011/10/10 08:08:31 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5D7DE07B-FE09-41F8-BB3E-516290EB0E63}
[2011/10/07 08:10:53 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{0A005F49-D913-45C1-A11C-07B06C8527E4}
[2011/10/07 08:10:47 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{AD4ACCE5-DA03-4D59-B045-8D485F8E2478}
[2011/10/06 13:27:07 | 000,000,000 | ---D | C] -- C:\Users\-\Desktop\EPICOR
[2011/10/06 08:07:06 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{B55E9102-3167-43FE-8836-9FAB3E2C41D2}
[2011/10/06 08:07:00 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{D84459C6-87A2-4E7A-A7E4-370132A37F0E}
[2011/10/05 07:59:03 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{1C5B524E-052B-4A12-8C21-A50088620652}
[2011/10/05 07:58:57 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{2B66FB7A-F683-4053-93D8-7C5B165BE635}
[2011/10/04 07:43:39 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{6069F706-668F-41DE-A140-242F781D63DB}
[2011/10/04 07:43:32 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DCD2FEEA-ADCA-4879-8B97-213FB7FB4869}
[2011/09/30 14:11:34 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8DBFF504-065C-47F4-A763-55216A594735}
[2011/09/30 14:11:31 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{88852D7C-5E04-4863-8E8F-1B2543D8C1C9}
[2011/09/30 07:44:58 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{2BDF91D2-2E16-4B49-AEF4-40E4715C02C4}
[2011/09/30 07:30:05 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{7119602D-8399-4E3C-B4C1-4E775D258BB8}
[2011/09/29 07:23:12 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8F1CC8D9-69A1-4B88-829C-B222308B2EE6}
[2011/09/29 07:23:04 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5668C2D1-443F-4B72-9D73-902BEAD231A3}
[2011/09/28 07:39:35 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{3EA5C5C9-BB2F-4898-8AB0-5D0096630A38}
[2011/09/28 07:39:29 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8796464B-6924-4A3D-B70D-3A0A19C0619E}
[2011/09/27 07:22:48 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{B1D096C0-87F0-4B8F-AC4B-53362F2102AD}
[2011/09/27 07:22:41 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{93451CC8-A931-4035-ADB9-44ACB709FB91}
[2011/09/26 07:13:19 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{66886453-FCD4-41EA-A464-3C560130160F}
[2011/09/26 07:13:13 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{94DB62B8-151D-46EC-8A92-74E6EDE21770}
[2011/09/23 07:21:05 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{47604B87-9F14-46FD-99B4-DBF6DA2F2055}
[2011/09/23 07:20:58 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{FB093A29-D46F-4441-A95E-0A9DAAD8A743}
[2011/09/22 07:16:21 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{433CBDF3-FA05-4527-925B-CA7409519082}
[2011/09/22 07:16:15 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{34822956-8B2D-4395-88CF-F02139E2FF10}
[2011/09/21 07:18:53 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{CC293285-505C-449F-BB53-76B5EC42EA1C}
[2011/09/21 07:18:47 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DD928A99-8921-4F53-A503-8D11C37BEEB8}
[2011/09/20 07:10:45 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{5D283CB0-C876-4889-BA08-D2BF1CC2DC9B}
[2011/09/20 07:10:39 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{DB9A1EA8-0A64-4B0B-AD2B-A03B93114776}
[2011/09/19 07:16:36 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{F5B451DE-4C7F-44FA-81DF-D4F82C2D40D2}
[2011/09/19 07:16:30 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{C324FFDB-11A7-41B8-8503-B5B36CF33538}
[2011/09/16 07:14:43 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{40D4E48B-F49A-4A1A-8C72-83C4638E55D6}
[2011/09/16 07:14:41 | 000,000,000 | ---D | C] -- C:\Users\-\AppData\Local\{8DF96F67-C699-4A7E-BAEF-35FF2A89EC37}

========== Files - Modified Within 60 Days ==========

[2011/11/14 15:57:22 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011/11/14 15:54:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\-\Desktop\OTL.exe
[2011/11/14 15:50:00 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/14 15:47:30 | 001,629,350 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/14 15:47:30 | 000,728,576 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2011/11/14 15:47:30 | 000,658,084 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/14 15:47:30 | 000,152,528 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2011/11/14 15:47:30 | 000,127,002 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/14 15:42:59 | 000,000,199 | ---- | M] () -- C:\Windows\wstdUPSWSHIP.INI
[2011/11/14 15:42:40 | 000,105,107 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/11/14 15:42:37 | 000,105,107 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/11/14 15:42:13 | 000,000,973 | ---- | M] () -- C:\Users\-\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/14 15:42:09 | 000,000,384 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{FE197E05-FC77-408F-910F-BB7BEEAF432C}.job
[2011/11/14 15:42:06 | 000,001,042 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/14 15:41:09 | 000,003,552 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 15:41:09 | 000,003,552 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 15:41:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/14 15:40:39 | 4292,440,064 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/14 14:09:21 | 000,000,867 | ---- | M] () -- C:\Users\-\Desktop\RSITx64 - Shortcut.lnk
[2011/11/14 13:08:14 | 000,278,306 | ---- | M] () -- C:\Users\-\Documents\PROFORMA 47 + 48.pdf
[2011/11/14 10:54:23 | 000,143,934 | ---- | M] () -- C:\Users\-\Documents\BADEN BADEN.pdf
[2011/11/14 10:17:30 | 000,164,356 | ---- | M] () -- C:\Users\-\Documents\scan.pdf
[2011/11/14 09:18:24 | 000,405,775 | ---- | M] () -- C:\Users\-\Documents\scan0049.pdf
[2011/11/09 14:14:46 | 000,373,394 | ---- | M] () -- C:\Users\-\Documents\provision for agents for oktober.pdf
[2011/11/08 14:39:47 | 000,369,332 | ---- | M] () -- C:\Users\-\Documents\scan0048.pdf
[2011/11/08 14:38:25 | 000,588,063 | ---- | M] () -- C:\Users\-\Documents\Scan0011.jpg
[2011/11/08 14:38:25 | 000,504,544 | ---- | M] () -- C:\Users\-\Documents\Scan0010.jpg
[2011/11/08 11:22:19 | 002,709,289 | ---- | M] () -- C:\Users\-\Documents\Roubin-Ruth-CZ-AP-SCROLL.jpg
[2011/11/07 16:16:43 | 001,485,177 | ---- | M] () -- C:\Users\-\Documents\PAULI C..pdf
[2011/11/07 09:42:57 | 000,514,968 | ---- | M] () -- C:\Users\-\Documents\Rasch.pdf
[2011/11/04 14:38:21 | 000,983,497 | ---- | M] () -- C:\Users\-\Documents\hangzhou invoices.pdf
[2011/11/04 10:10:04 | 000,007,680 | ---- | M] () -- C:\Users\-\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/04 09:32:01 | 000,341,600 | ---- | M] () -- C:\Users\-\Documents\scan0047.pdf
[2011/10/31 11:06:41 | 002,116,944 | ---- | M] () -- C:\Users\-\Documents\Universal Music GmbH.pdf
[2011/10/31 09:50:52 | 000,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/10/28 12:26:46 | 004,550,535 | ---- | M] () -- C:\Users\-\Documents\WINTER CAT. CHANGES.pdf
[2011/10/27 10:35:25 | 000,226,387 | ---- | M] () -- C:\Users\-\Desktop\Thalia.pdf
[2011/10/27 10:34:15 | 000,348,677 | ---- | M] () -- C:\Users\-\Documents\Scan0009.jpg
[2011/10/26 12:28:49 | 000,686,155 | ---- | M] () -- C:\Users\-\Documents\scan0046.pdf
[2011/10/26 08:42:17 | 000,366,295 | ---- | M] () -- C:\Users\-\Documents\scan0045.pdf
[2011/10/25 15:12:33 | 000,099,636 | ---- | M] () -- C:\Users\-\Documents\Thalia.pdf
[2011/10/13 11:05:23 | 632,822,166 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/10/13 08:01:11 | 000,422,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/12 13:06:06 | 000,381,066 | ---- | M] () -- C:\Users\-\Documents\scan0040.pdf
[2011/10/12 13:06:06 | 000,258,314 | ---- | M] () -- C:\Users\-\Documents\scan0039.pdf
[2011/10/12 13:06:06 | 000,226,743 | ---- | M] () -- C:\Users\-\Documents\scan0041.pdf
[2011/10/12 13:06:06 | 000,222,629 | ---- | M] () -- C:\Users\-\Documents\scan0043.pdf
[2011/10/12 13:06:06 | 000,171,969 | ---- | M] () -- C:\Users\-\Documents\scan0044.pdf
[2011/10/12 13:06:06 | 000,072,312 | ---- | M] () -- C:\Users\-\Documents\scan0042.pdf
[2011/10/12 09:57:11 | 000,162,927 | ---- | M] () -- C:\Users\-\Documents\proforma 0036 Mikado 27.05.11.pdf
[2011/10/11 09:06:43 | 000,230,534 | ---- | M] () -- C:\Users\-\Documents\scan0037.pdf
[2011/10/11 09:06:43 | 000,177,266 | ---- | M] () -- C:\Users\-\Documents\scan0038.pdf
[2011/10/07 13:25:25 | 000,321,503 | ---- | M] () -- C:\Users\-\Documents\SANDDORN & MEER0001.pdf
[2011/10/07 13:25:25 | 000,216,793 | ---- | M] () -- C:\Users\-\Documents\SANDDORN & MEER0002.pdf
[2011/10/07 11:48:17 | 000,011,264 | ---- | M] () -- C:\Users\-\Documents\CR1900.qbr
[2011/10/07 09:32:59 | 000,412,710 | ---- | M] () -- C:\Users\-\Documents\scan0036.pdf
[2011/10/07 09:32:58 | 000,127,782 | ---- | M] () -- C:\Users\-\Documents\scan0034.pdf
[2011/10/07 09:32:58 | 000,097,941 | ---- | M] () -- C:\Users\-\Documents\scan0035.pdf
[2011/10/06 16:06:40 | 000,235,046 | ---- | M] () -- C:\Users\-\Documents\eggert.pdf
[2011/10/06 12:03:28 | 000,229,144 | ---- | M] () -- C:\Users\-\Documents\missing invoices S-0108 Käthe Wohlfahrt0001.pdf
[2011/10/06 12:03:28 | 000,146,410 | ---- | M] () -- C:\Users\-\Documents\missing invoices S-0108 Käthe Wohlfahrt0002.pdf
[2011/10/06 10:00:07 | 000,171,779 | ---- | M] () -- C:\Users\-\Documents\letter.pdf
[2011/10/04 07:56:23 | 000,000,090 | ---- | M] () -- C:\Windows\QBChanUtil_Trigger.ini
[2011/09/30 14:57:33 | 000,145,742 | ---- | M] () -- C:\Users\-\Documents\RECHNUNG 2.pdf
[2011/09/30 14:50:32 | 000,278,925 | ---- | M] () -- C:\Users\-\Documents\Rechnung0001.pdf
[2011/09/30 14:50:32 | 000,116,141 | ---- | M] () -- C:\Users\-\Documents\Rechnung0002.pdf
[2011/09/29 07:42:06 | 000,518,729 | ---- | M] () -- C:\Users\-\Documents\KARTA KLIENTA VERONIKA SILAROVA 20.07.2011.pdf
[2011/09/26 11:16:01 | 002,783,407 | ---- | M] () -- C:\Users\-\Documents\PROFORMA INVOICES AUGUST 2011.pdf
[2011/09/23 11:08:18 | 000,648,507 | ---- | M] () -- C:\Users\-\Documents\Stephanie sent to me before to make a credit.pdf
[2011/09/23 10:15:55 | 000,217,633 | ---- | M] () -- C:\Users\-\Documents\NATEX INVOICE 2928 FITC0002.pdf
[2011/09/23 10:15:54 | 000,369,643 | ---- | M] () -- C:\Users\-\Documents\NATEX INVOICE 2928 FITC0001.pdf
[2011/09/22 13:10:14 | 000,175,261 | ---- | M] () -- C:\Users\-\Documents\scan0033.pdf
[2011/09/22 13:10:13 | 000,234,676 | ---- | M] () -- C:\Users\-\Documents\scan0032.pdf
[2011/09/22 13:10:13 | 000,189,566 | ---- | M] () -- C:\Users\-\Documents\scan0031.pdf
[2011/09/22 10:37:03 | 000,250,525 | ---- | M] () -- C:\Users\-\Documents\kreis duren.pdf
[2011/09/21 12:02:02 | 000,207,730 | ---- | M] () -- C:\Users\-\Documents\HETZENECKER.pdf
[2011/09/19 11:56:40 | 000,251,776 | ---- | M] () -- C:\Users\-\Documents\SCAN0029.pdf
[2011/09/19 11:56:40 | 000,241,302 | ---- | M] () -- C:\Users\-\Documents\SCAN0026.pdf
[2011/09/19 11:56:40 | 000,202,075 | ---- | M] () -- C:\Users\-\Documents\SCAN0024.pdf
[2011/09/19 11:56:40 | 000,194,275 | ---- | M] () -- C:\Users\-\Documents\SCAN0028.pdf
[2011/09/19 11:56:40 | 000,187,335 | ---- | M] () -- C:\Users\-\Documents\SCAN0030.pdf
[2011/09/19 11:56:40 | 000,170,334 | ---- | M] () -- C:\Users\-\Documents\SCAN0025.pdf
[2011/09/19 11:56:40 | 000,159,620 | ---- | M] () -- C:\Users\-\Documents\SCAN0027.pdf
[2011/09/19 11:56:39 | 000,262,199 | ---- | M] () -- C:\Users\-\Documents\SCAN0022.pdf
[2011/09/19 11:56:39 | 000,221,896 | ---- | M] () -- C:\Users\-\Documents\SCAN0023.pdf
[2011/09/19 11:56:39 | 000,188,694 | ---- | M] () -- C:\Users\-\Documents\SCAN0021.pdf
[2011/09/19 11:56:39 | 000,150,257 | ---- | M] () -- C:\Users\-\Documents\SCAN0020.pdf
[2011/09/19 11:56:39 | 000,149,666 | ---- | M] () -- C:\Users\-\Documents\SCAN0019.pdf

========== Files Created - No Company Name ==========

[2011/11/14 15:57:22 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011/11/14 15:42:09 | 000,000,384 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{FE197E05-FC77-408F-910F-BB7BEEAF432C}.job
[2011/11/14 15:37:54 | 000,057,667 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/11/14 15:37:54 | 000,057,667 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/11/14 14:09:21 | 000,000,867 | ---- | C] () -- C:\Users\-\Desktop\RSITx64 - Shortcut.lnk
[2011/11/14 13:08:14 | 000,278,306 | ---- | C] () -- C:\Users\-\Documents\PROFORMA 47 + 48.pdf
[2011/11/14 10:54:23 | 000,143,934 | ---- | C] () -- C:\Users\-\Documents\BADEN BADEN.pdf
[2011/11/14 09:18:23 | 000,405,775 | ---- | C] () -- C:\Users\-\Documents\scan0049.pdf
[2011/11/09 14:14:46 | 000,373,394 | ---- | C] () -- C:\Users\-\Documents\provision for agents for oktober.pdf
[2011/11/08 14:39:46 | 000,369,332 | ---- | C] () -- C:\Users\-\Documents\scan0048.pdf
[2011/11/08 14:38:25 | 000,588,063 | ---- | C] () -- C:\Users\-\Documents\Scan0011.jpg
[2011/11/08 14:38:25 | 000,504,544 | ---- | C] () -- C:\Users\-\Documents\Scan0010.jpg
[2011/11/08 11:22:07 | 002,709,289 | ---- | C] () -- C:\Users\-\Documents\Roubin-Ruth-CZ-AP-SCROLL.jpg
[2011/11/07 16:16:42 | 001,485,177 | ---- | C] () -- C:\Users\-\Documents\PAULI C..pdf
[2011/11/07 09:42:56 | 000,514,968 | ---- | C] () -- C:\Users\-\Documents\Rasch.pdf
[2011/11/04 14:38:20 | 000,983,497 | ---- | C] () -- C:\Users\-\Documents\hangzhou invoices.pdf
[2011/11/04 10:10:02 | 000,007,680 | ---- | C] () -- C:\Users\-\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/04 09:32:00 | 000,341,600 | ---- | C] () -- C:\Users\-\Documents\scan0047.pdf
[2011/10/31 11:06:39 | 002,116,944 | ---- | C] () -- C:\Users\-\Documents\Universal Music GmbH.pdf
[2011/10/28 12:26:43 | 004,550,535 | ---- | C] () -- C:\Users\-\Documents\WINTER CAT. CHANGES.pdf
[2011/10/27 10:35:24 | 000,226,387 | ---- | C] () -- C:\Users\-\Desktop\Thalia.pdf
[2011/10/27 10:34:15 | 000,348,677 | ---- | C] () -- C:\Users\-\Documents\Scan0009.jpg
[2011/10/26 12:28:48 | 000,686,155 | ---- | C] () -- C:\Users\-\Documents\scan0046.pdf
[2011/10/26 08:42:17 | 000,366,295 | ---- | C] () -- C:\Users\-\Documents\scan0045.pdf
[2011/10/25 15:12:33 | 000,099,636 | ---- | C] () -- C:\Users\-\Documents\Thalia.pdf
[2011/10/13 11:05:23 | 632,822,166 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/10/12 13:06:06 | 000,381,066 | ---- | C] () -- C:\Users\-\Documents\scan0040.pdf
[2011/10/12 13:06:06 | 000,226,743 | ---- | C] () -- C:\Users\-\Documents\scan0041.pdf
[2011/10/12 13:06:06 | 000,222,629 | ---- | C] () -- C:\Users\-\Documents\scan0043.pdf
[2011/10/12 13:06:06 | 000,171,969 | ---- | C] () -- C:\Users\-\Documents\scan0044.pdf
[2011/10/12 13:06:06 | 000,072,312 | ---- | C] () -- C:\Users\-\Documents\scan0042.pdf
[2011/10/12 13:06:05 | 000,258,314 | ---- | C] () -- C:\Users\-\Documents\scan0039.pdf
[2011/10/12 09:57:11 | 000,162,927 | ---- | C] () -- C:\Users\-\Documents\proforma 0036 Mikado 27.05.11.pdf
[2011/10/11 09:06:43 | 000,230,534 | ---- | C] () -- C:\Users\-\Documents\scan0037.pdf
[2011/10/11 09:06:43 | 000,177,266 | ---- | C] () -- C:\Users\-\Documents\scan0038.pdf
[2011/10/07 13:25:25 | 000,216,793 | ---- | C] () -- C:\Users\-\Documents\SANDDORN & MEER0002.pdf
[2011/10/07 13:25:24 | 000,321,503 | ---- | C] () -- C:\Users\-\Documents\SANDDORN & MEER0001.pdf
[2011/10/07 11:46:37 | 000,011,264 | ---- | C] () -- C:\Users\-\Documents\CR1900.qbr
[2011/10/07 09:32:58 | 000,412,710 | ---- | C] () -- C:\Users\-\Documents\scan0036.pdf
[2011/10/07 09:32:58 | 000,127,782 | ---- | C] () -- C:\Users\-\Documents\scan0034.pdf
[2011/10/07 09:32:58 | 000,097,941 | ---- | C] () -- C:\Users\-\Documents\scan0035.pdf
[2011/10/06 16:06:39 | 000,235,046 | ---- | C] () -- C:\Users\-\Documents\eggert.pdf
[2011/10/06 12:03:28 | 000,229,144 | ---- | C] () -- C:\Users\-\Documents\missing invoices S-0108 Käthe Wohlfahrt0001.pdf
[2011/10/06 12:03:28 | 000,146,410 | ---- | C] () -- C:\Users\-\Documents\missing invoices S-0108 Käthe Wohlfahrt0002.pdf
[2011/10/06 10:00:07 | 000,171,779 | ---- | C] () -- C:\Users\-\Documents\letter.pdf
[2011/09/30 14:57:33 | 000,145,742 | ---- | C] () -- C:\Users\-\Documents\RECHNUNG 2.pdf
[2011/09/30 14:50:32 | 000,278,925 | ---- | C] () -- C:\Users\-\Documents\Rechnung0001.pdf
[2011/09/30 14:50:32 | 000,116,141 | ---- | C] () -- C:\Users\-\Documents\Rechnung0002.pdf
[2011/09/26 11:15:57 | 002,783,407 | ---- | C] () -- C:\Users\-\Documents\PROFORMA INVOICES AUGUST 2011.pdf
[2011/09/23 11:08:18 | 000,648,507 | ---- | C] () -- C:\Users\-\Documents\Stephanie sent to me before to make a credit.pdf
[2011/09/23 10:46:31 | 000,164,356 | ---- | C] () -- C:\Users\-\Documents\scan.pdf
[2011/09/23 10:15:54 | 000,369,643 | ---- | C] () -- C:\Users\-\Documents\NATEX INVOICE 2928 FITC0001.pdf
[2011/09/23 10:15:54 | 000,217,633 | ---- | C] () -- C:\Users\-\Documents\NATEX INVOICE 2928 FITC0002.pdf
[2011/09/22 13:10:13 | 000,234,676 | ---- | C] () -- C:\Users\-\Documents\scan0032.pdf
[2011/09/22 13:10:13 | 000,189,566 | ---- | C] () -- C:\Users\-\Documents\scan0031.pdf
[2011/09/22 13:10:13 | 000,175,261 | ---- | C] () -- C:\Users\-\Documents\scan0033.pdf
[2011/09/22 10:37:03 | 000,250,525 | ---- | C] () -- C:\Users\-\Documents\kreis duren.pdf
[2011/09/21 12:02:02 | 000,207,730 | ---- | C] () -- C:\Users\-\Documents\HETZENECKER.pdf
[2011/09/19 11:56:40 | 000,251,776 | ---- | C] () -- C:\Users\-\Documents\SCAN0029.pdf
[2011/09/19 11:56:40 | 000,241,302 | ---- | C] () -- C:\Users\-\Documents\SCAN0026.pdf
[2011/09/19 11:56:40 | 000,194,275 | ---- | C] () -- C:\Users\-\Documents\SCAN0028.pdf
[2011/09/19 11:56:40 | 000,187,335 | ---- | C] () -- C:\Users\-\Documents\SCAN0030.pdf
[2011/09/19 11:56:40 | 000,170,334 | ---- | C] () -- C:\Users\-\Documents\SCAN0025.pdf
[2011/09/19 11:56:40 | 000,159,620 | ---- | C] () -- C:\Users\-\Documents\SCAN0027.pdf
[2011/09/19 11:56:39 | 000,262,199 | ---- | C] () -- C:\Users\-\Documents\SCAN0022.pdf
[2011/09/19 11:56:39 | 000,221,896 | ---- | C] () -- C:\Users\-\Documents\SCAN0023.pdf
[2011/09/19 11:56:39 | 000,202,075 | ---- | C] () -- C:\Users\-\Documents\SCAN0024.pdf
[2011/09/19 11:56:39 | 000,188,694 | ---- | C] () -- C:\Users\-\Documents\SCAN0021.pdf
[2011/09/19 11:56:39 | 000,150,257 | ---- | C] () -- C:\Users\-\Documents\SCAN0020.pdf
[2011/09/19 11:56:39 | 000,149,666 | ---- | C] () -- C:\Users\-\Documents\SCAN0019.pdf
[2011/07/20 13:32:07 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\BRTCPCON.DLL
[2011/07/20 13:32:07 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI
[2011/05/25 10:13:29 | 000,001,960 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/03/17 17:06:01 | 000,000,199 | ---- | C] () -- C:\Windows\wstdUPSWSHIP.INI
[2011/03/17 17:03:33 | 001,515,848 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/17 17:01:20 | 000,001,058 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/01/06 14:02:03 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2011/01/06 14:01:45 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2011/01/06 14:01:22 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011/01/06 14:01:22 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011/01/06 10:20:29 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2011/01/06 10:12:02 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/30 16:35:02 | 000,000,090 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2010/12/23 16:46:37 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2010/12/23 16:46:37 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2010/12/23 15:49:27 | 000,105,107 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/12/23 15:49:27 | 000,105,107 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/12/09 14:51:08 | 000,016,384 | ---- | C] () -- C:\Windows\SysWow64\GetHostIP.exe
[2010/12/09 10:58:20 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\nssckbi.dll
[2008/11/13 06:07:24 | 000,002,177 | ---- | C] () -- C:\Windows\P17EP.ini
[2006/11/02 16:35:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 13:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 13:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 10:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

========== LOP Check ==========

[2010/12/29 11:37:29 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\AVG10
[2010/12/29 12:20:28 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\GetRightToGo
[2011/04/01 13:28:47 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Leadertech
[2011/01/06 10:46:16 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\OpenOffice.org
[2011/01/26 12:50:41 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\PhotoFiltre Studio X
[2011/03/18 13:35:19 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\TeamViewer
[2011/01/07 09:42:13 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Windows Live Writer
[2011/11/14 15:39:36 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/14 15:42:09 | 000,000,384 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{FE197E05-FC77-408F-910F-BB7BEEAF432C}.job

========== Purity Check ==========

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 16:28
od Ver
========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009/04/11 00:10:54 | 001,555,968 | ---- | M] (Microsoft Corporation)
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008/01/19 09:00:14 | 000,138,240 | ---- | M] (Microsoft Corporation)


< MD5 for: ATAPI.SYS >
[2010/12/28 12:10:58 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=05001E1FACCE49DB895B8526B05C7302 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_37cb142cf6008bc1\atapi.sys
[2008/01/19 09:07:46 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2010/12/28 12:10:58 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=BB55C79E0595D8CFBE4A80A3C9EB77EA -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\atapi.sys
[2009/04/11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009/04/11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2009/04/10 23:27:22 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\SysWOW64\autochk.exe
[2009/04/10 23:27:22 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2008/01/19 08:33:01 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2006/11/02 12:15:40 | 000,730,112 | ---- | M] (Microsoft Corporation) MD5=B56DB371DC4C6F791B2708EAA4814BB7 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_3bdbc6d17d338351\autochk.exe
[2006/11/02 10:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe
[2009/04/11 00:10:00 | 000,734,720 | ---- | M] (Microsoft Corporation) MD5=E24D4475713CB382A720D003BDDA9628 -- C:\Windows\SysNative\autochk.exe
[2009/04/11 00:10:00 | 000,734,720 | ---- | M] (Microsoft Corporation) MD5=E24D4475713CB382A720D003BDDA9628 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_3ffe01d977405f71\autochk.exe
[2008/01/19 09:00:03 | 000,733,696 | ---- | M] (Microsoft Corporation) MD5=F74203F70337352EEABADAE16A05EAEA -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_3e1288cd7a1e9425\autochk.exe

< MD5 for: CDROM.SYS >
[2008/01/19 07:29:04 | 000,079,872 | ---- | M] (Microsoft Corporation) MD5=3B2FB35363423ED60C8FBF15FC8680BD -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.0.6001.18000_none_bbc7f7665c24db80\cdrom.sys
[2009/04/10 22:34:40 | 000,079,872 | ---- | M] (Microsoft Corporation) MD5=C025AA69BE3D0D25C7A2E746EF6F94FC -- C:\Windows\SysNative\drivers\cdrom.sys
[2009/04/10 22:34:40 | 000,079,872 | ---- | M] (Microsoft Corporation) MD5=C025AA69BE3D0D25C7A2E746EF6F94FC -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_bdb370725946a6cc\cdrom.sys

< MD5 for: CSRSS.EXE >
[2006/11/02 12:15:47 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=2C1B6476C4E84B885A54B7C6CDE7DC97 -- C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.0.6000.16386_none_b2cbbd5f9f880eae\csrss.exe
[2008/01/19 09:00:10 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=B4ABE68596B173FF2AB2076BC7C35EB4 -- C:\Windows\SysNative\csrss.exe
[2008/01/19 09:00:10 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=B4ABE68596B173FF2AB2076BC7C35EB4 -- C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.0.6001.18000_none_b5027f5b9c731f82\csrss.exe

< MD5 for: EXPLORER.EXE >
[2010/12/28 12:21:19 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2010/12/28 12:21:19 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2010/12/28 12:21:19 | 003,087,360 | ---- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2010/12/28 12:21:18 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2006/11/02 12:15:52 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=5D768BEB711FF67ADC8FAD4E2F6ABB02 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_ab9c809a352ecf21\explorer.exe
[2009/04/11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\explorer.exe
[2009/04/11 00:10:18 | 003,079,168 | ---- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2010/12/28 12:18:39 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_b61f6f46696c67ab\explorer.exe
[2010/12/28 12:21:19 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2010/12/28 12:18:38 | 003,086,848 | ---- | M] (Microsoft Corporation) MD5=819D88EC82C2C44B556DC32ED22044DE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_ac3dc19d4e3a6405\explorer.exe
[2010/12/28 12:21:19 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2010/12/28 12:18:38 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_b6926bef829b2600\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SysWOW64\explorer.exe
[2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2010/12/28 12:21:18 | 003,081,216 | ---- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2010/12/28 12:21:19 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/19 09:00:15 | 003,080,704 | ---- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2010/12/28 12:18:39 | 003,087,360 | ---- | M] (Microsoft Corporation) MD5=FCBF8AC1855EF986CDEC2387760F71C6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_abcac4f4350ba5b0\explorer.exe
[2006/11/02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_b5f12aec698f911c\explorer.exe
[2008/01/19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe

< MD5 for: LSASS.EXE >
[2010/12/28 13:25:31 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=02474FBCB00AA5C622E92F620DB9A041 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_02bcb9272e6ecc60\lsass.exe
[2010/12/28 12:17:07 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=1104B18819392FEA12FB5F9E170E66B3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_00fbc3d9312b9991\lsass.exe
[2010/12/29 11:58:22 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=1979F94B28107233315DD6220F2304DD -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_02ad19252e799f25\lsass.exe
[2010/12/29 11:58:23 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=1B461E9F6DB0EF829B4369F47A24BBEC -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_026926461528a96c\lsass.exe
[2010/12/29 11:58:23 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=1B461E9F6DB0EF829B4369F47A24BBEC -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_02635b98152c3e5e\lsass.exe
[2010/12/29 11:58:23 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=1B461E9F6DB0EF829B4369F47A24BBEC -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_04549f52124a74b8\lsass.exe
[2010/12/28 13:25:33 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=1E766E4C5BF9E230AD37A56BF7DB6C94 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_00d282d7314a3edc\lsass.exe
[2010/12/28 12:17:07 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=306E4503E083A498AE797FF59FA72839 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_00373bf8183ad660\lsass.exe
[2010/12/28 12:17:06 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=40348DCEC0712ED42231C5F90A69A690 -- C:\Windows\SysNative\lsass.exe
[2010/12/28 12:17:06 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=40348DCEC0712ED42231C5F90A69A690 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_041a8e8e12769b11\lsass.exe
[2010/12/28 12:17:05 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=41FB90DF49F203672F459122EF1F13B1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_02effd0d2e47247b\lsass.exe
[2010/12/29 11:58:24 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=563B71CEF1D46A24C5980FA2988DB67F -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_0101906d312801c6\lsass.exe
[2006/11/02 12:15:57 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=7B6AA93EEE1F354B3A4AC2ADE5EE334E -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16386_none_0032644a183d9898\lsass.exe
[2010/12/28 12:17:06 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=80F4593E92FF960E4763380D3168E498 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_021f7b32155f99ff\lsass.exe
[2010/12/28 12:17:06 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=BBBCE2DACDCCD5EA60A50D0023AE2DE9 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_04c69d972b7a16dd\lsass.exe
[2010/12/29 11:58:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=E231BDBD7D69857EEFFDEB3A48A53824 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_006d4b9418124aab\lsass.exe
[2010/12/28 13:25:32 | 000,011,264 | ---- | M] (Microsoft Corporation) MD5=EBDAEE60E442BEA413E5D7CEDFB09463 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_04a52ba32b935432\lsass.exe

< MD5 for: NDIS.SYS >
[2008/01/19 09:12:09 | 000,739,384 | ---- | M] (Microsoft Corporation) MD5=2A2EE457AF36C5C9A6808C768BD3A12B -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_03e5c74ad46c7e4e\ndis.sys
[2009/04/11 00:15:36 | 000,738,264 | ---- | M] (Microsoft Corporation) MD5=65950E07329FCEE8E6516B17C8D0ABB6 -- C:\Windows\SysNative\drivers\ndis.sys
[2009/04/11 00:15:36 | 000,738,264 | ---- | M] (Microsoft Corporation) MD5=65950E07329FCEE8E6516B17C8D0ABB6 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_05d14056d18e499a\ndis.sys
[2006/11/02 12:52:20 | 000,641,128 | ---- | M] (Microsoft Corporation) MD5=CCA69C9493A13AF86DCF0AE272AFBB72 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_01af054ed7816d7a\ndis.sys

< MD5 for: NTFS.SYS >
[2010/12/28 12:22:00 | 001,486,904 | ---- | M] (Microsoft Corporation) MD5=0A866BB6A63DE7A3D50C1BBA2F6C3EC4 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.20740_none_0107e3b5f1608966\ntfs.sys
[2010/12/28 12:10:59 | 001,486,904 | ---- | M] (Microsoft Corporation) MD5=545F5AD3BB69D9437162709F070E5C68 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.20709_none_013c25fff137fdb1\ntfs.sys
[2010/12/28 12:10:59 | 001,486,904 | ---- | M] (Microsoft Corporation) MD5=721FB94CF2FFFBFC7DA96D6D7C1FE1BE -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16586_none_00590710d85df443\ntfs.sys
[2009/04/11 00:15:36 | 001,515,496 | ---- | M] (Microsoft Corporation) MD5=BAC869DFB98E499BA4D9BB1FB43270E1 -- C:\Windows\SysNative\drivers\ntfs.sys
[2009/04/11 00:15:36 | 001,515,496 | ---- | M] (Microsoft Corporation) MD5=BAC869DFB98E499BA4D9BB1FB43270E1 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6002.18005_none_047b3e4cd26ad615\ntfs.sys
[2010/12/28 12:22:00 | 001,486,904 | ---- | M] (Microsoft Corporation) MD5=E6C330FCF62257B645D853FFC829AEF8 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16615_none_00a3b820d826147c\ntfs.sys
[2006/11/02 12:52:28 | 001,483,368 | ---- | M] (Microsoft Corporation) MD5=E7E6F1A73B055F738E95E7E4608B7EB8 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6000.16386_none_00590344d85df9f5\ntfs.sys
[2008/01/19 09:12:16 | 001,540,152 | ---- | M] (Microsoft Corporation) MD5=FE86BA5AC3B50E2CA911E9C60C07B638 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6001.18000_none_028fc540d5490ac9\ntfs.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006/11/02 12:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008/01/19 09:03:55 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006/11/02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009/04/10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009/04/11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< MD5 for: SERVICES.EXE >
[2006/11/02 12:16:09 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=0A87F57DFC2C0EB9BBA8BE1C87BAFE1A -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_294799ef88bb616c\services.exe
[2008/01/19 08:33:28 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 10:45:40 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/11 00:10:52 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 -- C:\Windows\SysNative\services.exe
[2009/04/11 00:10:52 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009/04/10 23:28:00 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\SysWOW64\services.exe
[2009/04/10 23:28:00 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2008/01/19 09:00:35 | 000,384,512 | ---- | M] (Microsoft Corporation) MD5=DFAC660F0F139276CC9299812DE42719 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe

< MD5 for: SMSS.EXE >
[2006/11/02 12:16:12 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=362C49C769D938B1FB6648D240BF5C76 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.0.6000.16386_none_06228184d4a4001c\smss.exe
[2008/01/19 09:00:39 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=9FC8E8C0F344EAE043740B72794DA3CC -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_08594380d18f10f0\smss.exe
[2009/04/11 00:10:56 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=C17704EA5B0F83D78F1377075FFE1C89 -- C:\Windows\SysNative\smss.exe
[2009/04/11 00:10:56 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=C17704EA5B0F83D78F1377075FFE1C89 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_0a44bc8cceb0dc3c\smss.exe

< MD5 for: SPOOLSV.EXE >
[2010/08/17 15:54:44 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=439017BE66398AB809D81B3AE8393883 -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.22468_none_34a17b8490538c82\spoolsv.exe
[2006/11/02 12:16:13 | 000,271,360 | ---- | M] (Microsoft Corporation) MD5=504D2FB001400D8E1100B3B8D6A82DA2 -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6000.16386_none_30337ca97cfb2578\spoolsv.exe
[2010/08/17 15:02:18 | 000,270,848 | ---- | M] (Microsoft Corporation) MD5=7F59AA690212241B398D6DBE4071EE3C -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.22743_none_32cba802932180c9\spoolsv.exe
[2010/08/17 15:04:48 | 000,267,776 | ---- | M] (Microsoft Corporation) MD5=92E6738D25C2123BE9515C0EAC0776CD -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18511_none_3260788179ed5d57\spoolsv.exe
[2008/01/19 09:00:40 | 000,267,264 | ---- | M] (Microsoft Corporation) MD5=E6519A9E756D74DC51C697BA62162F51 -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_326a3ea579e6364c\spoolsv.exe
[2009/04/11 00:10:58 | 000,268,288 | ---- | M] (Microsoft Corporation) MD5=EADA445EAEDD1D7DF4C5EB42B3612729 -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18005_none_3455b7b177080198\spoolsv.exe
[2010/08/17 15:54:20 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=F66FF751E7EFC816D266977939EF5DC3 -- C:\Windows\SysNative\spoolsv.exe
[2010/08/17 15:54:20 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=F66FF751E7EFC816D266977939EF5DC3 -- C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18294_none_33f36be77751de08\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 10:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\SysWOW64\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2006/11/02 12:16:13 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=6B30067D55E10E4DEBDC842FB1911479 -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_0fa33328c0c01e47\svchost.exe
[2008/01/19 09:00:40 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D -- C:\Windows\SysNative\svchost.exe
[2008/01/19 09:00:40 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe

< MD5 for: TCPIP.SYS >
[2010/06/16 18:14:29 | 001,424,264 | ---- | M] (Microsoft Corporation) MD5=0011810B5211FDACD784DE585262ECFE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_119c298735134c99\tcpip.sys
[2011/06/17 21:14:30 | 001,424,272 | ---- | M] (Microsoft Corporation) MD5=19A7321E3A5F1DDB215D2815DCC8F8E4 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_116decc535366aa6\tcpip.sys
[2011/09/20 22:06:18 | 001,426,304 | ---- | M] (Microsoft Corporation) MD5=2CC45D932BD193CD4117321D469AD6B2 -- C:\Windows\SysNative\drivers\tcpip.sys
[2011/09/20 22:06:18 | 001,426,304 | ---- | M] (Microsoft Corporation) MD5=2CC45D932BD193CD4117321D469AD6B2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18519_none_1121619c1be9f088\tcpip.sys
[2010/12/28 13:23:52 | 001,420,688 | ---- | M] (Microsoft Corporation) MD5=30C4ABC8075DEA44D7E775D434AF1753 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_0f2e179c1ecd900b\tcpip.sys
[2010/12/28 12:15:48 | 001,200,640 | ---- | M] (Microsoft Corporation) MD5=34B30202AECCB530FDDC6C6CCFA2FB46 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_bbc5fabc4a894d2a\tcpip.sys
[2010/12/28 13:23:54 | 001,200,640 | ---- | M] (Microsoft Corporation) MD5=396CF3FD8D2A4FDF55570C01894DB9DF -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_bba931004aa006ed\tcpip.sys
[2010/12/28 12:15:44 | 001,418,840 | ---- | M] (Microsoft Corporation) MD5=3BCD46BE9988B09D3510A0EF54F0D65B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_0f32e3e61ecadee9\tcpip.sys
[2010/12/28 13:23:52 | 001,414,032 | ---- | M] (Microsoft Corporation) MD5=4680D08A2E8A2509CD9B751D7AF59606 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_0fabe61737f42f96\tcpip.sys
[2010/12/28 13:23:53 | 001,423,752 | ---- | M] (Microsoft Corporation) MD5=4AD4600DF1F09EE7462152C061B683C8 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_118286a1352721f8\tcpip.sys
[2011/06/17 21:14:30 | 001,427,344 | ---- | M] (Microsoft Corporation) MD5=4DAD14118FBCF7C609F2A4CE21FBCC5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18484_none_10d0aed01c273845\tcpip.sys
[2010/12/28 12:10:20 | 001,193,472 | ---- | M] (Microsoft Corporation) MD5=5833A92EDC82BA178E4915A8E81A1FC2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_bbaf54e84a9a7440\tcpip.sys
[2010/12/28 12:10:20 | 001,192,448 | ---- | M] (Microsoft Corporation) MD5=616E40EA154BECBB549A87790AA0D667 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_bc13807d63d4e92a\tcpip.sys
[2011/09/20 22:06:18 | 001,423,744 | ---- | M] (Microsoft Corporation) MD5=73BED5067ED53A9DF05FA8EAB42578D0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys
[2010/12/28 12:15:44 | 001,413,208 | ---- | M] (Microsoft Corporation) MD5=74B776CA1B328095FE23A3306B1613A3 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_0f6c030d3823f645\tcpip.sys
[2008/01/19 09:12:15 | 001,421,368 | ---- | M] (Microsoft Corporation) MD5=7A1183FBB802F5ABAD7FA18BC67E0858 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_0f3cadd61ec3b22c\tcpip.sys
[2010/12/28 13:23:53 | 001,198,080 | ---- | M] (Microsoft Corporation) MD5=7B0B928E318CADC23C87226BE0A1097D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_bc37d12363b92291\tcpip.sys
[2010/06/16 17:40:37 | 001,420,176 | ---- | M] (Microsoft Corporation) MD5=7D86275FB640011B372FD566C0EAFA8D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_0ede67001f09ee46\tcpip.sys
[2010/06/16 18:11:35 | 001,426,816 | ---- | M] (Microsoft Corporation) MD5=973658A2EA9C06B2976884B9046DFC6C -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_10d97a5c1c20ef58\tcpip.sys
[2009/04/11 00:15:50 | 001,426,408 | ---- | M] (Microsoft Corporation) MD5=99D07AD0EF2C535610F6573C29BC045E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_112826e21be57d78\tcpip.sys
[2010/12/28 12:15:46 | 001,425,992 | ---- | M] (Microsoft Corporation) MD5=A7BFF59C2F610F62E6C292074FF36A1E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_10c2d66e1c321395\tcpip.sys
[2010/12/28 13:23:53 | 001,427,336 | ---- | M] (Microsoft Corporation) MD5=B4B7B375FDD672AF79B0CBE9B9A48B47 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_112c2bd61be1dd22\tcpip.sys
[2010/06/17 00:28:33 | 001,414,544 | ---- | M] (Microsoft Corporation) MD5=D43D5336BE9DD93E02EE124297295713 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_0fbe86f737e6a8d6\tcpip.sys
[2010/12/28 12:15:46 | 001,424,952 | ---- | M] (Microsoft Corporation) MD5=D45D67A18C9FD4CC637BC9D4585C0646 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_11acc42135079bb6\tcpip.sys
[2010/12/28 12:15:47 | 001,196,032 | ---- | M] (Microsoft Corporation) MD5=D4E30E6BADFF21865C3A075457CF9C00 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_bc4f6fa963a72036\tcpip.sys
[2006/11/02 10:48:29 | 001,193,472 | ---- | M] (Microsoft Corporation) MD5=DB08D7CB8D64A07E4D59F8983CD13758 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_bb6d6f644acc0b1a\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006/11/02 12:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008/01/19 09:00:41 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008/01/19 09:00:41 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009/04/11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/19 09:00:45 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009/04/10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 12:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006/11/02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2010/03/25 17:33:32 | 000,323,584 | ---- | M] (Hewlett-Packard Corporation) --
[2006/11/02 16:03:24 | 000,027,648 | ---- | M] (Microsoft Corporation) --
[2011/01/06 10:24:47 | 000,003,584 | ---- | M] (Lexmark International Inc.) --
[2006/11/02 20:21:28 | 000,003,584 | ---- | M] (Lexmark International Inc.) --

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2006/09/18 22:26:46 | 003,440,660 | ---- | M] () -- C:\Windows\system32\drivers\gm.dls
[2006/09/18 22:26:46 | 000,000,646 | ---- | M] () -- C:\Windows\system32\drivers\gmreadme.txt

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\*.* /5 >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\config\*.sav >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[8 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[537 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\6a27b0af42dbb3bf16ecb2fc9232789f\*.tmp files -> C:\Windows\SoftwareDistribution\Download\6a27b0af42dbb3bf16ecb2fc9232789f\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\7dc0dd12ea673c0662e55cd11e7a81da\*.tmp files -> C:\Windows\SoftwareDistribution\Download\7dc0dd12ea673c0662e55cd11e7a81da\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\a8810c535b71093e64212047a855b627\*.tmp files -> C:\Windows\SoftwareDistribution\Download\a8810c535b71093e64212047a855b627\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\ab1e47576aa2c30bfa0e4996e97d7bcb\*.tmp files -> C:\Windows\SoftwareDistribution\Download\ab1e47576aa2c30bfa0e4996e97d7bcb\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\c6504e2a297b032199116b40fde551f2\*.tmp files -> C:\Windows\SoftwareDistribution\Download\c6504e2a297b032199116b40fde551f2\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\fc657881ab689074782a9162eb085351\*.tmp files -> C:\Windows\SoftwareDistribution\Download\fc657881ab689074782a9162eb085351\*.tmp -> ]
[17 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011/01/26 13:05:20 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Adobe
[2010/12/29 11:37:29 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\AVG10
[2011/08/16 12:43:34 | 000,000,000 | R--D | M] -- C:\Users\-\AppData\Roaming\Brother
[2010/12/30 16:26:40 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Download Manager
[2010/12/29 12:20:28 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\GetRightToGo
[2011/01/14 13:22:09 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Hewlett-Packard Company
[2011/02/01 09:06:20 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\HP
[2011/01/26 12:50:26 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Identities
[2010/12/23 15:56:36 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\InstallShield
[2011/05/04 13:58:32 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Intuit
[2011/04/01 13:28:47 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Leadertech
[2010/12/23 15:40:33 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Macromedia
[2006/11/02 16:06:33 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Media Center Programs
[2011/10/05 16:21:55 | 000,000,000 | --SD | M] -- C:\Users\-\AppData\Roaming\Microsoft
[2011/01/06 09:44:27 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Mozilla
[2011/01/06 10:46:16 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\OpenOffice.org
[2011/03/23 09:28:45 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\OpenOffice.org2
[2011/01/26 12:50:41 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\PhotoFiltre Studio X
[2011/11/14 12:49:33 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Skype
[2011/08/12 10:42:30 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\skypePM
[2011/03/18 13:35:19 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\TeamViewer
[2011/07/15 15:55:57 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\vlc
[2011/01/07 09:42:13 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\Windows Live Writer
[2011/01/28 16:05:20 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\WinRAR

< %APPDATA%\*.* >

< %APPDATA%\*.exe /s >

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 08:44:20 | 000,855,040 | ---- | M] (Microsoft Corporation) -- C:\install.exe

< *crack* /s >

< *keygen* /s >

< *loader* /s >
[2009/11/12 09:44:34 | 000,035,616 | ---- | M] () -- \Program Files (x86)\Common Files\Intuit\DocManager\1.0\AppDomainLoader.dll
[2010/03/24 19:12:34 | 000,249,680 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2010/03/24 19:12:34 | 000,018,264 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2011/07/06 18:45:50 | 000,021,352 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\ERDownloader.dll
[2011/07/06 18:46:10 | 000,098,152 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\PRLoader.dll
[2011/07/06 18:46:10 | 000,053,608 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\PRNotificationLoader.dll
[2010/12/29 11:29:32 | 000,105,736 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\PatchStaging\Setup\PSMLoader.dll
[2010/12/29 11:29:28 | 000,049,928 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\PatchStaging\VMP\Loader.dll
[2010/12/29 11:29:28 | 000,009,992 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\PatchStaging\VMP\loadershim.dll
[2010/12/29 11:29:32 | 000,105,736 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\Setup\PSMLoader.dll
[2010/12/29 11:29:28 | 000,049,928 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\vmp\loader.dll
[2010/12/29 11:29:28 | 000,009,992 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\Components\Payroll\vmp\loadershim.dll
[2005/10/14 02:49:48 | 000,017,624 | ---- | M] () -- \Program Files (x86)\MICROSOFT SQL SERVER\90\Tools\Binn\SqlResourceLoader.dll
[2011/02/25 10:46:26 | 000,005,987 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\scripts\io\downloader.js
[2010/03/15 11:28:23 | 000,045,056 | ---- | M] () -- \Program Files (x86)\WinRAR\RarExtLoader.exe
[2009/10/15 12:54:18 | 003,288,064 | ---- | M] () -- \Program Files (x86)\Zebra Technologies\Zebra Font Downloader\Font Download\ZDDownloader2.exe
[2010/03/24 19:35:48 | 000,370,512 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2010/03/24 19:35:48 | 000,018,264 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2011/03/22 13:57:24 | 000,001,347 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Zebra Technologies\Zebra Font Downloader\Zebra Font Downloader.lnk
[2005/10/14 02:49:48 | 000,017,624 | ---- | M] () -- \UPS\WSTD\MSSQL.1\MSSQL\Binn\SqlResourceLoader.dll
[2010/09/22 13:16:48 | 000,005,273 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Toolbar\Applications\loader.xap
[2011/08/29 11:24:24 | 000,001,737 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7NPU5ATK\allinclusive-loader[1].gif
[2011/08/29 11:25:11 | 000,002,140 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7NPU5ATK\wizzloader-1.0.0[1].js
[2011/08/29 11:23:46 | 000,008,787 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MC9XGJOO\skylights_loader[1].gif
[2011/08/29 11:25:13 | 000,008,787 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MC9XGJOO\skylights_loader[2].gif
[2011/08/29 11:23:41 | 000,002,140 | ---- | M] () -- \Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MC9XGJOO\wizzloader-1.0.0[1].js
[2011/11/08 06:53:58 | 000,010,144 | ---- | M] () -- \Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\ExternalLibraryLoader.jsm
[2011/03/22 13:57:24 | 000,001,347 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Zebra Technologies\Zebra Font Downloader\Zebra Font Downloader.lnk
[2011/11/14 15:54:26 | 000,028,768 | ---- | M] () -- \Windows\Prefetch\RAREXTLOADER.EXE-4B76CB3C.pf
[2008/01/19 08:34:04 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2008/01/19 08:34:04 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2011/01/06 13:36:32 | 000,005,276 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9.manifest
[2011/01/06 13:36:32 | 000,026,112 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9_winload.efi.mui_35ee487d
[2011/01/06 13:36:32 | 000,026,112 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9_winload.exe.mui_3bc5b827
[2011/01/06 13:36:32 | 000,019,456 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9_winresume.efi.mui_f412814e
[2011/01/06 13:36:32 | 000,019,456 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9_winresume.exe.mui_ff8b5358
[2011/01/06 13:36:41 | 000,005,276 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0.manifest
[2011/01/06 13:36:41 | 000,026,112 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0_winload.efi.mui_35ee487d
[2011/01/06 13:36:41 | 000,028,160 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0_winload.exe.mui_3bc5b827
[2011/01/06 13:36:41 | 000,019,456 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0_winresume.efi.mui_f412814e
[2011/01/06 13:36:41 | 000,019,968 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0_winresume.exe.mui_ff8b5358
[2011/04/15 17:45:27 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb.manifest
[2011/04/15 17:45:27 | 001,076,608 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb_winload.efi_75834aa0
[2011/04/15 17:45:27 | 001,063,296 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb_winload.exe_75835076
[2011/04/15 17:45:27 | 000,991,104 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb_winresume.efi_85cd069f
[2011/04/15 17:45:27 | 000,979,840 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb_winresume.exe_85cd1215
[2011/01/06 14:17:46 | 000,004,168 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6002.18005_none_c93d3cc9069b2134.manifest
[2011/01/06 14:17:46 | 000,019,432 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6002.18005_none_c93d3cc9069b2134_spldr.sys_98bd87a0
[2010/12/29 11:43:13 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_de-de_27bb02f6b077b2c1.manifest
[2010/12/29 11:42:55 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_en-us_d0abd8ef9f55be86.manifest
[2010/12/29 11:43:21 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_es-es_d07735d39f7cb02b.manifest
[2010/12/29 11:42:56 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_fr-fr_732eabd2924ec68d.manifest
[2010/12/29 11:43:37 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_it-it_5d56a2196980ac0b.manifest
[2010/12/29 11:43:40 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_ja-jp_ff7c21265c9bbde6.manifest
[2010/12/29 11:43:52 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_nl-nl_89b7ca4e285dba8d.manifest
[2010/12/29 11:43:13 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_de-de_28155ee9c9b95cf3.manifest
[2010/12/29 11:42:55 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_en-us_d10634e2b89768b8.manifest
[2010/12/29 11:43:20 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_es-es_d0d191c6b8be5a5d.manifest
[2010/12/29 11:42:56 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_fr-fr_738907c5ab9070bf.manifest
[2010/12/29 11:43:37 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_it-it_5db0fe0c82c2563d.manifest
[2010/12/29 11:43:40 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_ja-jp_ffd67d1975dd6818.manifest
[2010/12/29 11:43:51 | 000,004,353 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_nl-nl_8a122641419f64bf.manifest
[2011/01/06 10:20:46 | 000,005,276 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_en-us_d2b755899c6147a9.manifest
[2008/01/19 06:27:14 | 000,005,276 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_8bc346e8256943b0.manifest
[2010/12/29 11:42:47 | 000,005,771 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.16646_none_b539d91c27f8c85b.manifest
[2010/12/29 11:42:47 | 000,005,771 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.20782_none_b594350f413a728d.manifest
[2008/01/19 00:25:08 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18000_none_b74555b62504517e.manifest
[2010/12/29 11:42:24 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18027_none_b736b7e4250e3ac1.manifest
[2011/02/28 09:28:48 | 000,007,115 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18606_none_b74b62d624fed872.manifest
[2010/12/29 11:42:23 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.22125_none_b7be541b3e2da7dd.manifest
[2011/02/28 09:28:48 | 000,007,115 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.22861_none_b78f208d3e519e56.manifest
[2009/04/11 00:40:12 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_b930cec222261cca.manifest
[2011/02/24 17:59:25 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18411_none_b92205462231c7fb.manifest
[2011/02/24 17:45:29 | 000,006,704 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.22596_none_b95a24233b8bc600.manifest
[2006/11/02 13:21:14 | 000,004,253 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6000.16386_none_c51b01c10c8e4514.manifest
[2008/01/19 00:28:52 | 000,004,176 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_c751c3bd097955e8.manifest
[2009/04/11 00:43:16 | 000,004,168 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6002.18005_none_c93d3cc9069b2134.manifest
[2006/11/02 16:00:07 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6000.16386_none_43bd59f592b7be86\dmloader.dll
[2008/01/19 08:34:04 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6001.18000_none_45f41bf18fa2cf5a\dmloader.dll
[2008/01/19 08:34:04 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6002.18005_none_47df94fd8cc49aa6\dmloader.dll

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >

< *activator* /s >

< *serial* /s >
[2011/08/05 08:26:05 | 000,083,800 | ---- | M] () -- \Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.XmlSerializers.dll
[2011/06/14 04:18:38 | 000,079,704 | ---- | M] () -- \Program Files (x86)\Common Files\Intuit\Sync\Intuit.IntuitSyncManager.IDSTypes.XmlSerializers.dll
[2011/07/06 18:45:38 | 000,282,984 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-1_35.dll
[2011/07/06 18:45:38 | 000,176,488 | ---- | M] () -- \Program Files (x86)\Intuit\QuickBooks 2011\boost_serialization-vc90-mt-p-1_33.dll
[2011/08/30 16:58:34 | 000,413,696 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\4.0.60831.0\System.Runtime.Serialization.dll
[2011/10/12 16:30:21 | 001,186,816 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\4.0.60831.0\System.Runtime.Serialization.ni.dll
[2010/04/12 13:21:01 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2009/02/18 18:14:46 | 000,090,112 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\nl\System.RunTime.Serialization.Resources.dll
[2010/04/14 18:20:46 | 000,415,592 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Runtime.Serialization.dll
[2010/04/14 18:20:46 | 000,141,168 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Runtime.Serialization.Json.dll
[2010/04/14 18:20:46 | 000,321,376 | ---- | M] () -- \Program Files (x86)\Windows Live\Mesh\System.Xml.Serialization.dll
[2010/04/12 13:20:54 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\nl\System.RunTime.Serialization.Resources.dll
[2011/10/21 07:56:19 | 000,083,800 | ---- | M] () -- \ProgramData\Intuit\QuickBooks 2011\Components\DataProtect\OCD\IntuitDataProtect.XmlSerializers.dll
[2011/07/08 07:30:04 | 000,083,800 | ---- | M] () -- \ProgramData\Intuit\QuickBooks 2011\Components\DataProtect\ROLLBACK\IntuitDataProtect.XmlSerializers.dll
[2011/10/12 08:11:25 | 000,079,704 | ---- | M] () -- \ProgramData\Intuit\QuickBooks 2011\Components\SyncMgr\OCD\Intuit.IntuitSyncManager.IDSTypes.XmlSerializers.dll
[2011/11/14 15:57:05 | 000,000,461 | ---- | M] () -- \UPS\WSTD\Serial.txt
[2010/12/09 11:01:02 | 000,073,728 | ---- | M] () -- \UPS\WSTD\UPS.NRF.Data.XmlSerializers.dll
[2010/09/10 09:21:18 | 183,568,384 | ---- | M] () -- \Users\-\Desktop\HOLLAND COMPUTER\New Folder (2)\Přátelé CZ\S09\Pratele.09x20.Serialovy.vecirek.avi
[2011/10/21 07:56:19 | 000,083,800 | ---- | M] () -- \Users\All Users\Intuit\QuickBooks 2011\Components\DataProtect\OCD\IntuitDataProtect.XmlSerializers.dll
[2011/07/08 07:30:04 | 000,083,800 | ---- | M] () -- \Users\All Users\Intuit\QuickBooks 2011\Components\DataProtect\ROLLBACK\IntuitDataProtect.XmlSerializers.dll
[2011/10/12 08:11:25 | 000,079,704 | ---- | M] () -- \Users\All Users\Intuit\QuickBooks 2011\Components\SyncMgr\OCD\Intuit.IntuitSyncManager.IDSTypes.XmlSerializers.dll
[2009/03/31 11:05:16 | 000,011,264 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_nl_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009/03/29 21:42:20 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.resources\3.0.0.0_nl_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2010/04/12 13:21:01 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2011/10/13 09:22:00 | 002,346,496 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\4b4c359912c1241246f50a4c47dbab3c\System.Runtime.Serialization.ni.dll
[2011/10/13 09:21:14 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f97b31da89858b85c70b4eb45bc91ace\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2011/10/13 08:16:38 | 003,072,512 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\0923cf543f311891eeae4e5ce30ca46c\System.Runtime.Serialization.ni.dll
[2011/10/13 08:15:21 | 000,396,288 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\d526d3a3a6657c8cd4508ebe888d50ad\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2011/04/18 11:16:41 | 003,072,512 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP626D.tmp\System.Runtime.Serialization.dll
[2011/10/13 09:24:19 | 002,647,040 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\993f89ba22499c379d2a9dd25d13cd94\System.Runtime.Serialization.ni.dll
[2011/10/13 09:24:23 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\bed774dde4b62ed1d2d55c2d1769d600\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2011/10/13 09:26:18 | 000,009,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\3a2ab56bb224b871516526753985ff69\System.Xml.Serialization.ni.dll
[2011/10/13 08:21:51 | 000,376,832 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\6cd778cd2c8c61130ff71ee7a685222b\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2011/10/13 08:21:42 | 003,412,992 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\f68180d9f4ade9c313f9ad20422eb1c0\System.Runtime.Serialization.ni.dll
[2011/10/13 09:20:51 | 000,010,240 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\59e70022e798ce28f9f5b8870c5c8bf2\System.Xml.Serialization.ni.dll
[2010/09/29 15:13:28 | 000,083,216 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\CBAA07D195BC00747A80AE651DAC700B\21.0.4005\intuitdataprotect.xmlseriali
[2011/10/12 16:26:32 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011/10/12 16:26:31 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2011/10/12 16:26:35 | 000,011,120 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2009/03/29 21:42:20 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2009/03/31 11:04:20 | 000,011,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\nl\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/04/12 13:21:15 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010/03/18 13:16:28 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010/03/18 13:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2011/04/06 15:48:20 | 000,011,120 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2009/03/29 21:39:58 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2009/03/31 11:05:16 | 000,011,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\nl\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010/04/12 13:21:10 | 000,847,872 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010/03/18 13:16:28 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2010/03/18 13:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2011/04/06 15:48:20 | 000,011,120 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
[2008/01/19 08:36:21 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2011/01/06 10:27:31 | 000,005,632 | ---- | M] () -- \Windows\System32\en-US\serialui.dll.mui
[2006/11/02 20:20:32 | 000,006,144 | ---- | M] () -- \Windows\System32\nl-NL\serialui.dll.mui
[2008/01/19 08:36:21 | 000,015,360 | ---- | M] () -- \Windows\SysWOW64\serialui.dll
[2011/01/06 10:27:31 | 000,005,632 | ---- | M] () -- \Windows\SysWOW64\en-US\serialui.dll.mui
[2006/11/02 20:20:32 | 000,006,144 | ---- | M] () -- \Windows\SysWOW64\nl-NL\serialui.dll.mui
[2011/01/06 10:26:42 | 000,010,240 | ---- | M] () -- \Windows\winsxs\amd64_hiddigi.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_90d48ed991e520d7\serial.sys.mui
[2006/11/02 20:19:10 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_hiddigi.inf.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_49e080381aed1cde\serial.sys.mui
[2008/01/19 07:28:41 | 000,094,208 | ---- | M] () -- \Windows\winsxs\amd64_hiddigi.inf_31bf3856ad364e35_6.0.6001.18000_none_f17ae014fe39679d\serial.sys
[2006/11/02 20:23:38 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_16768135d6cacbe5\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010/12/29 11:47:45 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16754_nl-nl_1694f7fdd6b43a00\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010/12/29 11:47:37 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20921_nl-nl_173c0594efbc3719\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2008/01/05 23:24:52 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_18ad4331d3b5dcb9\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010/12/29 11:47:26 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18145_nl-nl_188706d9d3d1c857\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2010/12/29 11:47:19 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22269_nl-nl_18ff04f4ecfc055f\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2009/03/31 11:05:16 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_nl-nl_1a98bc3dd0d7a805\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2011/01/06 10:26:34 | 000,005,120 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_en-us_eba906758617813c\serialui.dll.mui
[2006/11/02 20:18:55 | 000,005,632 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_a4b4f7d40f1f7d43\serialui.dll.mui
[2006/11/02 12:19:09 | 000,017,920 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6000.16386_none_4ee97b15da1d1d1b\serialui.dll
[2008/01/19 09:03:58 | 000,017,920 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6001.18000_none_51203d11d7082def\serialui.dll
[2008/01/19 09:03:58 | 000,017,920 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_530bb61dd429f93b\serialui.dll
[2006/11/02 20:25:59 | 000,086,016 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_b3be28d37df39222\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:49 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16730_nl-nl_b3ee3e4b7dd062ff\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:48 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.20895_nl-nl_b43bfd00971a2922\System.RunTime.Serialization.Resources.dll
[2008/01/05 23:24:56 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_b5f4eacf7adea2f6\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:44 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18121_nl-nl_b5e04d277aedf156\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:43 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.22243_nl-nl_b6564aae9419fbb0\System.RunTime.Serialization.Resources.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_nl-nl_b7e063db78006e42\System.RunTime.Serialization.Resources.dll
[2011/01/06 10:27:52 | 000,010,240 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_61f44769eea920e5\serial.sys.mui
[2006/11/02 20:21:05 | 000,011,264 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_1b0038c877b11cec\serial.sys.mui
[2008/01/19 07:28:41 | 000,094,208 | ---- | M] () -- \Windows\winsxs\amd64_msports.inf_31bf3856ad364e35_6.0.6001.18000_none_54b64c3570bbb569\serial.sys
[2006/10/20 02:12:49 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16386_none_d575eec458838ab3\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:58 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16720_none_d570752858885a27\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:58 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.20883_none_bea88bcc722a9f1a\System.Runtime.Serialization.Formatters.Soap.dll
[2008/01/05 12:26:00 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18000_none_d54a708058db337f\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:15 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18111_none_d54b59de58da66c8\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:15 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.22230_none_be7fca7a727fdfdb\System.Runtime.Serialization.Formatters.Soap.dll
[2009/03/29 21:39:58 | 000,131,072 | ---- | M] () -- \Windows\winsxs\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6002.18005_none_d525f5bc592cc793\System.Runtime.Serialization.Formatters.Soap.dll
[2011/01/06 10:26:42 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_smartcrd.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_537bf23090f0aff5\grserial.sys.mui
[2006/11/02 20:19:09 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_smartcrd.inf.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_0c87e38f19f8abfc\grserial.sys.mui
[2008/01/19 07:28:41 | 000,037,888 | ---- | M] () -- \Windows\winsxs\amd64_smartcrd.inf_31bf3856ad364e35_6.0.6001.18000_none_cec87ce2ec9b3e39\grserial.sys
[2006/11/02 16:02:49 | 000,888,832 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.16386_none_84e7e239b7e8fbc9\System.Runtime.Serialization.dll
[2010/12/29 11:40:31 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.16708_none_84dfb1c9b7f06597\System.Runtime.Serialization.dll
[2010/12/29 11:40:31 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.20864_none_6e1867e5d191f723\System.Runtime.Serialization.dll
[2008/01/05 12:23:05 | 000,929,792 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.18000_none_84bc63f5b840a495\System.Runtime.Serialization.dll
[2010/12/29 11:40:06 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.18096_none_84c4dddfb839226a\System.Runtime.Serialization.dll
[2010/12/29 11:40:06 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.22208_none_6dee06d1d1e8d1f4\System.Runtime.Serialization.dll
[2009/02/18 11:39:14 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.18005_none_8497e931b89238a9\System.Runtime.Serialization.dll
[2010/04/12 13:21:10 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.18239_none_849a8ea7b88febd4\System.Runtime.Serialization.dll
[2010/04/12 13:21:16 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.22380_none_6dd2b661d231e3e4\System.Runtime.Serialization.dll
[2006/11/02 16:02:47 | 000,888,832 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_bfbeef040be0f662\System.Runtime.Serialization.dll
[2010/12/29 11:40:17 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_bfb6be940be86030\System.Runtime.Serialization.dll
[2010/12/29 11:40:17 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_a8ef74b02589f1bc\System.Runtime.Serialization.dll
[2008/01/05 12:23:04 | 000,929,792 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_bf9370c00c389f2e\System.Runtime.Serialization.dll
[2010/12/29 11:39:56 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_bf9beaaa0c311d03\System.Runtime.Serialization.dll
[2010/12/29 11:39:56 | 000,843,776 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_a8c5139c25e0cc8d\System.Runtime.Serialization.dll
[2009/02/18 11:39:10 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_bf6ef5fc0c8a3342\System.Runtime.Serialization.dll
[2010/04/12 13:20:54 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_bf719b720c87e66d\System.Runtime.Serialization.dll
[2010/04/12 13:21:00 | 000,847,872 | ---- | M] () -- \Windows\winsxs\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_a8a9c32c2629de7d\System.Runtime.Serialization.dll
[2011/04/15 17:45:27 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18411_none_6fb0d8326235d6c8.manifest

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 16:29
od Ver
[2011/04/15 17:45:27 | 000,017,792 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18411_none_6fb0d8326235d6c8_kdcom.dll_db5e7744
[2011/01/06 10:30:51 | 000,005,120 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_en-us_eba906758617813c_serialui.dll.mui_7d29d2a3
[2006/11/02 20:29:04 | 000,005,632 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_a4b4f7d40f1f7d43_serialui.dll.mui_7d29d2a3
[2011/01/06 14:17:39 | 000,017,920 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_530bb61dd429f93b_serialui.dll_bea29328
[2011/01/06 10:30:54 | 000,005,632 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_en-us_8f8a6af1cdba1006_serialui.dll.mui_7d29d2a3
[2006/11/02 20:29:32 | 000,006,144 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_48965c5056c20c0d_serialui.dll.mui_7d29d2a3
[2011/01/06 14:17:55 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_f6ed1a9a1bcc8805_serialui.dll_bea29328
[2006/11/02 13:23:12 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6000.16386_none_6b9d66a6681d4f77.manifest
[2008/01/19 00:25:46 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6001.18000_none_6dd428a26508604b.manifest
[2011/02/28 09:28:48 | 000,003,928 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6001.18606_none_6dda35c26502e73f.manifest
[2011/02/28 09:28:48 | 000,003,928 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6001.22861_none_6e1df3797e55ad23.manifest
[2009/04/11 00:41:10 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18005_none_6fbfa1ae622a2b97.manifest
[2011/02/24 18:00:43 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18411_none_6fb0d8326235d6c8.manifest
[2011/02/24 17:46:09 | 000,003,750 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.22596_none_6fe8f70f7b8fd4cd.manifest
[2006/11/02 13:15:08 | 000,001,404 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.0.6000.16386_none_86a4ac6fc1e857fa.manifest
[2006/11/02 15:58:19 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.16386_none_84e7e239b7e8fbc9.manifest
[2010/12/29 11:38:55 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.16708_none_84dfb1c9b7f06597.manifest
[2010/12/29 11:38:55 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6000.20864_none_6e1867e5d191f723.manifest
[2008/01/19 00:33:00 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.18000_none_84bc63f5b840a495.manifest
[2010/12/29 11:36:09 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.18096_none_84c4dddfb839226a.manifest
[2010/12/29 11:36:09 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6001.22208_none_6dee06d1d1e8d1f4.manifest
[2009/04/11 00:45:56 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.18005_none_8497e931b89238a9.manifest
[2010/04/12 20:12:28 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.18239_none_849a8ea7b88febd4.manifest
[2010/04/12 20:19:19 | 000,004,098 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.0.6002.22380_none_6dd2b661d231e3e4.manifest
[2006/11/02 15:58:18 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_bfbeef040be0f662.manifest
[2010/12/29 11:37:47 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_bfb6be940be86030.manifest
[2010/12/29 11:37:46 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_a8ef74b02589f1bc.manifest
[2008/01/19 00:33:26 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_bf9370c00c389f2e.manifest
[2010/12/29 11:34:28 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_bf9beaaa0c311d03.manifest
[2010/12/29 11:34:27 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_a8c5139c25e0cc8d.manifest
[2009/04/11 00:46:16 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_bf6ef5fc0c8a3342.manifest
[2010/04/12 20:12:47 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_bf719b720c87e66d.manifest
[2010/04/12 20:19:46 | 000,004,123 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_a8a9c32c2629de7d.manifest
[2006/11/02 15:58:19 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16386_none_d24e4473b7df83f3.manifest
[2010/12/29 11:38:34 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16708_none_d2461403b7e6edc1.manifest
[2010/12/29 11:38:33 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.20864_none_bb7eca1fd1887f4d.manifest
[2008/01/19 00:05:26 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18000_none_d222c62fb8372cbf.manifest
[2010/12/29 11:34:56 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18096_none_d22b4019b82faa94.manifest
[2010/12/29 11:34:56 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.22208_none_bb54690bd1df5a1e.manifest
[2009/04/11 00:16:00 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18005_none_d1fe4b6bb888c0d3.manifest
[2010/04/12 19:29:50 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18239_none_d200f0e1b88673fe.manifest
[2010/04/12 20:40:05 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.22380_none_bb39189bd2286c0e.manifest
[2006/11/02 16:11:01 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_en-us_bb16054302d6ef1f.manifest
[2006/11/02 20:13:46 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_nl-nl_5421236e100eef90.manifest
[2010/12/29 11:36:40 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16708_en-us_bb0dd4d302de58ed.manifest
[2010/12/29 11:49:20 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16730_nl-nl_541caa1c1012d85b.manifest
[2010/12/29 11:36:40 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20864_en-us_a4468aef1c7fea79.manifest
[2010/12/29 11:49:19 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20895_nl-nl_3d54933029b55090.manifest
[2008/01/19 06:26:36 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18000_nl-nl_53f5a52a1066985c.manifest
[2010/12/29 11:33:23 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18096_en-us_baf300e9032715c0.manifest
[2010/12/29 11:49:06 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18121_nl-nl_53f78ed21064e4fc.manifest
[2010/12/29 11:33:23 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22208_en-us_a41c29db1cd6c54a.manifest
[2010/12/29 11:49:05 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22243_nl-nl_3d2bbb162a0aaaf2.manifest
[2009/04/28 13:38:56 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18005_nl-nl_53d12a6610b82c70.manifest
[2010/04/12 19:12:07 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_en-us_bac8b1b1037ddf2a.manifest
[2010/04/12 23:56:12 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_nl-nl_53d3cfdc10b5df9b.manifest
[2010/04/12 19:24:45 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_en-us_a400d96b1d1fd73a.manifest
[2010/04/13 00:25:29 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_nl-nl_3d0bf7962a57d7ab.manifest
[2006/11/02 15:58:19 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16386_none_02917a0ddf868526.manifest
[2010/12/29 11:38:33 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16708_none_0289499ddf8deef4.manifest
[2010/12/29 11:38:33 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.20864_none_ebc1ffb9f92f8080.manifest
[2008/01/19 00:04:20 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18000_none_0265fbc9dfde2df2.manifest
[2010/12/29 11:34:56 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18096_none_026e75b3dfd6abc7.manifest
[2010/12/29 11:34:55 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.22208_none_eb979ea5f9865b51.manifest
[2009/04/11 00:15:32 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18005_none_02418105e02fc206.manifest
[2010/04/12 19:29:29 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531.manifest
[2010/04/12 20:39:45 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41.manifest
[2006/11/02 15:58:20 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_076c25db205d1f68.manifest
[2010/12/29 11:37:47 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_0763f56b20648936.manifest
[2010/12/29 11:37:46 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_f09cab873a061ac2.manifest
[2008/01/19 00:13:44 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_0740a79720b4c834.manifest
[2010/12/29 11:34:28 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_0749218120ad4609.manifest
[2010/12/29 11:34:27 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_f0724a733a5cf593.manifest
[2009/04/11 00:18:56 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_071c2cd321065c48.manifest
[2010/04/12 19:32:33 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73.manifest
[2010/04/12 20:42:39 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783.manifest
[2006/10/20 02:14:53 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16386_none_483e6ea12378b3a8\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:55 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16720_none_4838f505237d831c\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:55 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.20883_none_31710ba93d1fc80f\System.Runtime.Serialization.Formatters.Soap.dll
[2008/01/05 12:26:58 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18000_none_4812f05d23d05c74\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:12 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18111_none_4813d9bb23cf8fbd\System.Runtime.Serialization.Formatters.Soap.dll
[2010/12/28 12:45:12 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.22230_none_31484a573d7508d0\System.Runtime.Serialization.Formatters.Soap.dll
[2009/03/29 21:42:20 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6002.18005_none_47ee75992421f088\System.Runtime.Serialization.Formatters.Soap.dll
[2006/11/02 20:20:48 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.16386_nl-nl_f58f1d4e65f40824\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:49 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.16754_nl-nl_f58c497065f68a21\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:49 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.20921_nl-nl_debbe6067fa05190\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008/01/05 23:24:52 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.18000_nl-nl_f5639f0a664bb0f0\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:29 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.18145_nl-nl_f5672e26664896c2\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:29 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.22269_nl-nl_de9b2cda7fee8ffa\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009/03/31 11:05:16 | 000,011,264 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6002.18005_nl-nl_f53f2446669d4504\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2006/11/02 16:02:49 | 000,888,832 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16386_none_d24e4473b7df83f3\System.Runtime.Serialization.dll
[2010/12/29 11:40:26 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16708_none_d2461403b7e6edc1\System.Runtime.Serialization.dll
[2010/12/29 11:40:26 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.20864_none_bb7eca1fd1887f4d\System.Runtime.Serialization.dll
[2008/01/05 12:21:39 | 000,929,792 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18000_none_d222c62fb8372cbf\System.Runtime.Serialization.dll
[2010/12/29 11:40:02 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18096_none_d22b4019b82faa94\System.Runtime.Serialization.dll
[2010/12/29 11:40:02 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.22208_none_bb54690bd1df5a1e\System.Runtime.Serialization.dll
[2009/02/18 11:38:44 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18005_none_d1fe4b6bb888c0d3\System.Runtime.Serialization.dll
[2010/04/12 13:21:15 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18239_none_d200f0e1b88673fe\System.Runtime.Serialization.dll
[2010/04/12 13:22:49 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.22380_none_bb39189bd2286c0e\System.Runtime.Serialization.dll
[2006/11/02 20:25:54 | 000,086,016 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_nl-nl_5421236e100eef90\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:51 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16730_nl-nl_541caa1c1012d85b\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:51 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20895_nl-nl_3d54933029b55090\System.RunTime.Serialization.Resources.dll
[2008/01/05 23:24:56 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18000_nl-nl_53f5a52a1066985c\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:46 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18121_nl-nl_53f78ed21064e4fc\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:46 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22243_nl-nl_3d2bbb162a0aaaf2\System.RunTime.Serialization.Resources.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18005_nl-nl_53d12a6610b82c70\System.RunTime.Serialization.Resources.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_nl-nl_53d3cfdc10b5df9b\System.RunTime.Serialization.Resources.dll
[2009/02/18 18:15:14 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_nl-nl_3d0bf7962a57d7ab\System.RunTime.Serialization.Resources.dll
[2006/11/02 16:02:49 | 000,888,832 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16386_none_02917a0ddf868526\System.Runtime.Serialization.dll
[2010/12/29 11:40:26 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16708_none_0289499ddf8deef4\System.Runtime.Serialization.dll
[2010/12/29 11:40:26 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.20864_none_ebc1ffb9f92f8080\System.Runtime.Serialization.dll
[2008/01/05 12:21:38 | 000,929,792 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18000_none_0265fbc9dfde2df2\System.Runtime.Serialization.dll
[2010/12/29 11:40:02 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18096_none_026e75b3dfd6abc7\System.Runtime.Serialization.dll
[2010/12/29 11:40:02 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.22208_none_eb979ea5f9865b51\System.Runtime.Serialization.dll
[2009/02/18 11:38:40 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18005_none_02418105e02fc206\System.Runtime.Serialization.dll
[2010/04/12 13:21:01 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531\System.Runtime.Serialization.dll
[2010/04/12 13:22:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41\System.Runtime.Serialization.dll
[2006/11/02 20:19:18 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_ba57e5b21e6d5aaf\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:41 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16754_nl-nl_ba765c7a1e56c8ca\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:32 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20921_nl-nl_bb1d6a11375ec5e3\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008/01/06 07:56:55 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_bc8ea7ae1b586b83\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:22 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18145_nl-nl_bc686b561b745721\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010/12/29 11:47:15 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22269_nl-nl_bce06971349e9429\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009/03/31 11:04:20 | 000,011,264 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_nl-nl_be7a20ba187a36cf\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2011/01/06 10:27:31 | 000,005,632 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_en-us_8f8a6af1cdba1006\serialui.dll.mui
[2006/11/02 20:20:32 | 000,006,144 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_48965c5056c20c0d\serialui.dll.mui
[2006/11/02 10:46:12 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6000.16386_none_f2cadf9221bfabe5\serialui.dll
[2008/01/19 08:36:21 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6001.18000_none_f501a18e1eaabcb9\serialui.dll
[2008/01/19 08:36:21 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_f6ed1a9a1bcc8805\serialui.dll
[2006/11/02 20:26:04 | 000,086,016 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_nl-nl_579f8d4fc59620ec\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:49 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16730_nl-nl_57cfa2c7c572f1c9\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:48 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.20895_nl-nl_581d617cdebcb7ec\System.RunTime.Serialization.Resources.dll
[2008/01/06 07:56:58 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_nl-nl_59d64f4bc28131c0\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:44 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18121_nl-nl_59c1b1a3c2908020\System.RunTime.Serialization.Resources.dll
[2010/12/29 11:49:43 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.22243_nl-nl_5a37af2adbbc8a7a\System.RunTime.Serialization.Resources.dll
[2009/02/18 18:14:46 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_nl-nl_5bc1c857bfa2fd0c\System.RunTime.Serialization.Resources.dll
[2006/11/02 16:02:52 | 000,888,832 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_076c25db205d1f68\System.Runtime.Serialization.dll
[2010/12/29 11:40:17 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_0763f56b20648936\System.Runtime.Serialization.dll
[2010/12/29 11:40:17 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_f09cab873a061ac2\System.Runtime.Serialization.dll
[2008/01/05 12:21:38 | 000,929,792 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_0740a79720b4c834\System.Runtime.Serialization.dll
[2010/12/29 11:39:56 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_0749218120ad4609\System.Runtime.Serialization.dll
[2010/12/29 11:39:56 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_f0724a733a5cf593\System.Runtime.Serialization.dll
[2009/02/18 11:38:40 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_071c2cd321065c48\System.Runtime.Serialization.dll
[2010/04/12 13:21:01 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73\System.Runtime.Serialization.dll
[2010/04/12 13:22:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783\System.Runtime.Serialization.dll

< *w7lxe* /s >

< *legalizator* /s >

< *registration* /s >
[2011/03/18 08:45:17 | 000,001,567 | ---- | M] () -- \Program Files (x86)\Java\jre6\lib\servicetag\registration.xml
[2011/02/01 18:58:07 | 000,000,483 | ---- | M] () -- \ProgramData\Common Files\INTUIT\QUICKBOOKS\qbregistration.dat
[2011/02/01 18:58:55 | 000,000,096 | ---- | M] () -- \ProgramData\Common Files\INTUIT\Statement Writer\iswregistration.dat
[2011/01/14 13:22:11 | 000,000,787 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/07/20 13:33:01 | 000,002,056 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\HL-2250DN LAN\On-Line Registration.lnk
[2010/12/09 10:58:28 | 000,001,324 | ---- | M] () -- \UPS\WSTD\XML\wstdFileRegistrationInput.xml
[2011/01/06 17:30:24 | 000,001,648 | ---- | M] () -- \Users\-\AppData\Roaming\OpenOffice.org\3\user\registration.xml
[2011/02/01 18:58:07 | 000,000,483 | ---- | M] () -- \Users\All Users\Common Files\INTUIT\QUICKBOOKS\qbregistration.dat
[2011/02/01 18:58:55 | 000,000,096 | ---- | M] () -- \Users\All Users\Common Files\INTUIT\Statement Writer\iswregistration.dat
[2011/01/14 13:22:11 | 000,000,787 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/07/20 13:33:01 | 000,002,056 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Brother\HL-2250DN LAN\On-Line Registration.lnk
[2006/11/02 13:16:01 | 000,001,341 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-shell-registration_31bf3856ad364e35_6.0.6000.16386_none_1b94861c5c4dc6ca.manifest
[2006/11/02 15:57:53 | 000,004,265 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-t..client-registration_31bf3856ad364e35_6.0.6000.16386_none_d579d9751b2da26d.manifest
[2006/11/02 13:17:51 | 000,009,406 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-xwizards-registration_31bf3856ad364e35_6.0.6000.16386_none_7300a78ca412e514.manifest
[2006/11/02 15:58:01 | 000,002,846 | ---- | M] () -- \Windows\winsxs\Manifests\wow64_microsoft-windows-t..client-registration_31bf3856ad364e35_6.0.6000.16386_none_dfce83c74f8e6468.manifest
[2006/11/02 11:03:15 | 000,001,337 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-shell-registration_31bf3856ad364e35_6.0.6000.16386_none_bf75ea98a3f05594.manifest
[2006/11/02 11:06:46 | 000,009,386 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-xwizards-registration_31bf3856ad364e35_6.0.6000.16386_none_16e20c08ebb573de.manifest

< *Office 2010* /s >
[2011/06/28 08:15:18 | 000,001,908 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Language Preferences.lnk
[2011/06/28 08:15:18 | 000,001,950 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk
[2011/06/28 08:15:18 | 000,001,908 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Language Preferences.lnk
[2011/06/28 08:15:18 | 000,001,950 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk

< *AutoRearm* /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
PENDINGFILERENAMEOPERATIONS REG_MULTI_SZ \??\C:\Windows\TEMP\logishrd\LVPrcInj01.dll\0\??\C:\Windows\TEMP\logishrd\\0\??\C:\Windows\TEMP\logishrd\LVPrcInj02.dll\0\??\C:\Windows\TEMP\logishrd\

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2011/11/14 15:57:22 | 000,000,512 | ---- | M] () MD5=B51B9673DC794E5C33764BA90C3F2DBC -- C:\PhysicalMBR.bin

< End of report >

Re: pro Murphyho Pc se seka

Napsal: 14 lis 2011 19:19
od Mc_Murphy
:arrow: "Asi jo", jo? :D
:arrow: Explorer jsi aktualizovala na verzi 8, takže ještě jednou na verzi 9. ;)

:arrow: Znovu spusť OTL.
  • Pokud používáš Win Vista či Win7, klikni na OTL pravým myšítkem a dej Run As Administrator či Spustit jako správce.
  • Pokud používáš 64bitový OS, zkontroluj, zda-li je zaškrtnutý čtvereček Pro 64 bitové OS. Pokud ne, zaškrtni jej.
  • Do spodního okénka Vlastní skenování/opravy vlož tento skript:

Kód: Vybrat vše

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.3.3
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.3.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.8.20100713041928
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p="
[2011/10/25 16:54:04 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/08 18:09:12 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/05/09 07:44:14 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\engine@conduit.com
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4dda1b7a&v=7.4 ... -chrome&q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/comple ... =chrome&q={searchTerms}
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKU\S-1-5-21-711281013-1559387861-798609812-1000\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
[2010/12/29 11:37:29 | 000,000,000 | ---D | M] -- C:\Users\-\AppData\Roaming\AVG10
[8 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[537 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\6a27b0af42dbb3bf16ecb2fc9232789f\*.tmp files -> C:\Windows\SoftwareDistribution\Download\6a27b0af42dbb3bf16ecb2fc9232789f\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\7dc0dd12ea673c0662e55cd11e7a81da\*.tmp files -> C:\Windows\SoftwareDistribution\Download\7dc0dd12ea673c0662e55cd11e7a81da\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\a8810c535b71093e64212047a855b627\*.tmp files -> C:\Windows\SoftwareDistribution\Download\a8810c535b71093e64212047a855b627\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\ab1e47576aa2c30bfa0e4996e97d7bcb\*.tmp files -> C:\Windows\SoftwareDistribution\Download\ab1e47576aa2c30bfa0e4996e97d7bcb\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\c6504e2a297b032199116b40fde551f2\*.tmp files -> C:\Windows\SoftwareDistribution\Download\c6504e2a297b032199116b40fde551f2\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\fc657881ab689074782a9162eb085351\*.tmp files -> C:\Windows\SoftwareDistribution\Download\fc657881ab689074782a9162eb085351\*.tmp -> ]
[17 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

:Services
gupdate
gupdatem

:Reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^-^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2 .lnk]

:Files
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{FE197E05-FC77-408F-910F-BB7BEEAF432C}.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
%windir%\*.tmp /s
%windir%\system32\SET*.tmp /s
%windir%\system32\*.tmp.dll /s

:Commands
[emptytemp]
[emptyflash]
[resethosts]
[purity]
[clearallrestorepoints]
  • Klikni na tlačítko [Opravit].
  • Po dokončení skenu se objeví log, ten mi sem vlož.
  • Pokud se log nevejde do jednoho příspěvku, rozděl jej na více částí.

Re: pro Murphyho Pc se seka

Napsal: 16 lis 2011 10:16
od Ver
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "Yahoo" removed from browser.search.defaultenginename
Prefs.js: "http://search.yahoo.com/search?fr=ffsp1&p=" removed from browser.search.defaulturl
Prefs.js: "Yahoo" removed from browser.search.selectedEngine
Prefs.js: engine@conduit.com:3.2.3.3 removed from extensions.enabledItems
Prefs.js: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.3.3 removed from extensions.enabledItems
Prefs.js: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.8.20100713041928 removed from extensions.enabledItems
Prefs.js: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209 removed from extensions.enabledItems
Prefs.js: "http://search.yahoo.com/search?fr=ffds1&p=" removed from keyword.URL
Folder C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\ not found.
Folder C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
Folder C:\Users\-\AppData\Roaming\Mozilla\Firefox\Profiles\u5dhv6yc.default\extensions\engine@conduit.com\ not found.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ not found.
File C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\ not found.
File C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_USERS\S-1-5-21-711281013-1559387861-798609812-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry value HKEY_USERS\S-1-5-21-711281013-1559387861-798609812-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}\ not found.
Registry value HKEY_USERS\S-1-5-21-711281013-1559387861-798609812-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xporteren naar Microsoft Excel\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xporteren naar Microsoft Excel\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-help-qb4\ not found.
File Protocol\Handler\intu-help-qb4 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ not found.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ not found.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ not found.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\qbwc\ not found.
File Protocol\Handler\qbwc - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ not found.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ not found.
File Protocol\Handler\wlpg - No CLSID value found not found.
Folder C:\Users\-\AppData\Roaming\AVG10\ not found.
File/Folder C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp not found.
File/Folder C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp not found.
File/Folder C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\6a27b0af42dbb3bf16ecb2fc9232789f\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\7dc0dd12ea673c0662e55cd11e7a81da\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\a8810c535b71093e64212047a855b627\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\ab1e47576aa2c30bfa0e4996e97d7bcb\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\c6504e2a297b032199116b40fde551f2\*.tmp not found.
File/Folder C:\Windows\SoftwareDistribution\Download\fc657881ab689074782a9162eb085351\*.tmp not found.
File delete failed. C:\Windows\Temp\CR_74CF1.tmp\SETUP_PATCH.PACKED.7Z scheduled to be deleted on reboot.
Folder delete failed. C:\Windows\Temp\CR_74CF1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Windows\Temp\sqla0001.tmp scheduled to be deleted on reboot.
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^-^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2 .lnk\ not found.
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\User_Feed_Synchronization-{FE197E05-FC77-408F-910F-BB7BEEAF432C}.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\Temp\CR_74CF1.tmp folder moved successfully.
File move failed. C:\Windows\Temp\sqla0001.tmp scheduled to be moved on reboot.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: -
->Temp folder emptied: 355103449 bytes
->Temporary Internet Files folder emptied: 248302187 bytes
->Java cache emptied: 40000 bytes
->FireFox cache emptied: 427610364 bytes
->Google Chrome cache emptied: 6714930 bytes
->Flash cache emptied: 167972117 bytes

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 64337684 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 195118804 bytes

Total Files Cleaned = 1,397.00 mb


[EMPTYFLASH]

User: -
->Flash cache emptied: 0 bytes

User: All Users

User: AppData

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb

File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.31.0 log created on 11162011_095818

Files\Folders moved on Reboot...
File\Folder C:\Windows\Temp\CR_74CF1.tmp\SETUP_PATCH.PACKED.7Z not found!
File\Folder C:\Windows\Temp\CR_74CF1.tmp not found!
File\Folder C:\Windows\Temp\sqla0001.tmp not found!
C:\Users\-\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.
File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: pro Murphyho Pc se seka

Napsal: 16 lis 2011 11:51
od Mc_Murphy
:???: Jak je na tom počítač?

Re: pro Murphyho Pc se seka

Napsal: 16 lis 2011 12:06
od Ver
Ja myslim ze super.

Dekuji mnohokrat :D

Re: pro Murphyho Pc se seka

Napsal: 16 lis 2011 12:56
od Mc_Murphy
Tak ještě dočistíme a máme hotovo, ju? ;)

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stáhni a spusť.
  • Klikni na CleanUp a potvrď YES.
  • Program uklidí a může (nemusí) restartovat PC.

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stáhni a spusť.
  • Klikni na Start a potvrď OK.
  • Program uklidí a může (nemusí) restartovat PC.
  • Po použití utilitu smaž.
:arrow: Pokud nemáš, stáhni CCleaner z tohoto odkazu.
  • Panel čistič
  • Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
  • Panel registry
  • Klikni na Hledej problémy.
  • Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
  • Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
  • Panel nástroje
  • Zde můžeš odinstalovat nepotřebné programy.
Obrázek CCleaner doporučuji používat cca jednou za týden.

... a pokud nejsou žádné dotazy, bylo by to z mé strany vše. :worship: