Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus v instalacke

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Virus v instalacke

#1 Příspěvek od GAMELASTER »

Dobry den... Pri instalaci vsechnych aplikaci pri instalaci noveho windowsu 8 se my nainstalovalo neake claro, pritom sem to odskrtol... Od vtedy se mi pocitac strasne laguje, prehrieva a furt mi pise ze zlyhal neaky mnsg.exe (ikonku to ma, ako keby to chrani internet..)... Nevim absolutne co to je, snazil sem se to sam vymazat, no nenasel sem ten subor..

Logfile of random's system information tool 1.09 (written by random/random)
Run by Marek at 2012-11-22 22:01:14
Microsoft Windows 8 Pro
System drive C: has 33 GB (47%) free of 72 GB
Total RAM: 1789 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:03:25, on 22.11.2012
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16384)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
D:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\BlueStacks\HD-Agent.exe
C:\Program Files (x86)\Altap Salamander\salamand.exe
C:\Program Files (x86)\WinSCP\WinSCP.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe
C:\Program Files\trend micro\Marek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.claro-search.com/?affID=1174 ... 210055d7ce
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Claro LTD Helper Object - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (file missing)
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - D:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O3 - Toolbar: Claro LTD Toolbar - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (file missing)
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Game Fire] C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe /START
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~3\browse~1\25911~1.18\{c16c1~1\mngr.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Browser Manager - Unknown owner - C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9072 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
dashost.exe {569a1563-6d11-4f02-9b4617f79993878a}
C:\Windows\slsvc.exe
C:\Windows\PersonalizeEnabler.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android
"C:\Program Files (x86)\BlueStacks\HD-Network.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe"
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-743bbc50-3318-45a8-9d82-81578bc5748d -SystemEventPortName:HostProcess-1b1f4c1e-8a89-45ca-8dfb-ae28c4e842bc -IoCancelEventPortName:HostProcess-fb59b794-e80f-4541-8bc5-7a09cefe6b41 -NonStateChangingEventPortName:HostProcess-8c1eca43-1771-4f1b-b7de-b0b44bb1906a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:04aae3e3-944a-4393-b1bd-d2606cd0a7ae -DeviceGroupId:WudfDefaultDevicePool
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe"
"C:\Windows\system32\schtasks.exe" /create /tn "Browser Manager" /ru "SYSTEM" /sc minute /mo 1 /tr "C:\Windows\system32\sc.exe start Browser Manager" /st 00:00:00
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Windows\system32\schtasks.exe" /create /tn "Browser Manager" /ru "SYSTEM" /sc minute /mo 1 /tr "C:\Windows\system32\sc.exe start Browser Manager" /st 00:00:00
\??\C:\Windows\system32\conhost.exe 0x4
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
taskhostex.exe
C:\Windows\Explorer.EXE
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"D:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\BlueStacks\HD-Agent.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Altap Salamander\salamand.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\WinSCP\WinSCP.exe"
"C:\Program Files (x86)\Notepad++\notepad++.exe" C:\Users\Marek\AppData\Local\Temp\scp42667\var\www\domeny\areasixtyone.net\control\index.php
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Windows\system32\schtasks.exe" /create /tn "Browser Manager" /ru "SYSTEM" /sc minute /mo 1 /tr "C:\Windows\system32\sc.exe start Browser Manager" /st 00:00:00
\??\C:\Windows\system32\conhost.exe 0x4
"C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe" /PROTECT
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=182124.6977e00.1211879466 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 182124 "\\.\pipe\gecko-crash-server-pipe.182124" plugin
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe" --proxy-stub-channel=Flash182900.6CCD3AA0.41 --host-broker-channel=Flash182900.6CCD3AA0.18467 --host-pid=182900 --host-npapi-version=27 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_4_402_287.dll"
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe" --channel=182792.0099F338.217241914 --proxy-stub-channel=Flash182900.6CCD3AA0.41 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_4_402_287.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Marek\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\xi0fsvv6.default

prefs.js - "browser.startup.homepage" - "http://www.claro-search.com/?affID=1174 ... 210055d7ce"
prefs.js - "keyword.URL" - "http://www.claro-search.com/?affID=1174 ... 055d7ce&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\plugins\
npwachk.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
babylon.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\xi0fsvv6.default\searchplugins\
mngr.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-11-01 537576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-11-01 193512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}]
Claro LTD Helper Object - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-30 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-30 155384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - D:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
{9E131A93-EED7-4BEB-B015-A0ADB30B5646} - Claro LTD Toolbar - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-10-19 17884848]
"uTorrent"=D:\Program Files (x86)\uTorrent\uTorrent.exe [2012-10-31 963984]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2012-09-12 445624]
"Game Fire"=C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [2011-12-02 44032]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2012-06-28 74752]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-07-04 641704]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2012-10-25 593784]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-22 22:01:20 ----D---- C:\Program Files\trend micro
2012-11-22 22:01:14 ----D---- C:\rsit
2012-11-22 15:31:20 ----A---- C:\Windows\system32\netcfg-156214752.txt
2012-11-22 15:31:20 ----A---- C:\Windows\system32\netcfg-156214596.txt
2012-11-21 17:54:12 ----D---- C:\Macromedia
2012-11-21 17:52:40 ----A---- C:\Windows\fonts\billd.txt
2012-11-21 17:52:40 ----A---- C:\Windows\fonts\big_noodle_titling.txt
2012-11-21 17:52:40 ----A---- C:\Windows\fonts\beatles.txt
2012-11-21 17:52:40 ----A---- C:\Windows\fonts\BATTLEST.TXT
2012-11-21 17:52:39 ----A---- C:\Windows\fonts\barmee-info.txt
2012-11-21 17:52:39 ----A---- C:\Windows\fonts\ATLAS.TXT
2012-11-21 17:52:39 ----A---- C:\Windows\fonts\ARTISTAM.TXT
2012-11-21 17:52:38 ----A---- C:\Windows\fonts\andinistas_freeware_license.txt

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#2 Příspěvek od GAMELASTER »

2012-11-21 17:39:42 ----D---- C:\Users\Marek\AppData\Roaming\Claro
2012-11-21 17:39:31 ----A---- C:\Windows\system32\roboot64.exe
2012-11-21 17:39:22 ----D---- C:\Users\Marek\AppData\Roaming\systweak
2012-11-21 17:38:49 ----D---- C:\ProgramData\Browser Manager
2012-11-21 17:38:23 ----D---- C:\Users\Marek\AppData\Roaming\Babylon
2012-11-21 17:38:23 ----D---- C:\ProgramData\Babylon
2012-11-21 17:22:32 ----A---- C:\Windows\SYSWOW64\dx8vb.dll
2012-11-21 16:34:35 ----A---- C:\Windows\system32\netcfg-73615967.txt
2012-11-21 16:34:33 ----A---- C:\Windows\system32\netcfg-73614453.txt
2012-11-18 10:35:40 ----D---- C:\Program Files (x86)\Smart PC Utilities
2012-11-18 09:09:30 ----A---- C:\Windows\system32\netcfg-413410090.txt
2012-11-18 09:09:29 ----A---- C:\Windows\system32\netcfg-413409622.txt
2012-11-17 19:13:36 ----A---- C:\Windows\system32\netcfg-363261120.txt
2012-11-17 19:13:32 ----A---- C:\Windows\system32\netcfg-363256752.txt
2012-11-17 12:48:33 ----D---- C:\Program Files (x86)\directx
2012-11-17 12:47:26 ----D---- C:\Program Files (x86)\gta2gh
2012-11-17 10:17:31 ----A---- C:\Windows\system32\netcfg-331158641.txt
2012-11-17 10:17:31 ----A---- C:\Windows\system32\netcfg-331158501.txt
2012-11-16 17:06:16 ----D---- C:\Users\Marek\AppData\Roaming\Unity
2012-11-15 21:18:00 ----A---- C:\Windows\system32\netcfg-198004955.txt
2012-11-15 20:26:04 ----A---- C:\Windows\system32\netcfg-194951485.txt
2012-11-15 20:21:28 ----D---- C:\Users\Marek\AppData\Roaming\EM-Creations
2012-11-15 19:06:42 ----D---- C:\ProgramData\MTA San Andreas All
2012-11-15 19:06:42 ----D---- C:\Program Files (x86)\MTA San Andreas 1.3
2012-11-14 16:52:23 ----A---- C:\Windows\system32\netcfg-95738952.txt
2012-11-14 16:52:22 ----A---- C:\Windows\system32\netcfg-95738187.txt
2012-11-11 22:14:38 ----A---- C:\Windows\system32\netcfg-99311656.txt
2012-11-11 22:14:37 ----A---- C:\Windows\system32\netcfg-99309830.txt
2012-11-11 09:09:21 ----A---- C:\Windows\system32\netcfg-52268322.txt
2012-11-11 09:09:21 ----A---- C:\Windows\system32\netcfg-52267776.txt
2012-11-10 18:37:26 ----A---- C:\Windows\system32\netcfg-694422881.txt
2012-11-10 18:20:43 ----A---- C:\Windows\system32\netcfg-693419764.txt
2012-11-10 18:20:32 ----A---- C:\Windows\system32\netcfg-693408906.txt
2012-11-08 20:54:07 ----D---- C:\Users\Marek\AppData\Roaming\gltechnic
2012-11-08 14:53:19 ----A---- C:\Windows\system32\netcfg-508344998.txt
2012-11-08 14:53:17 ----A---- C:\Windows\system32\netcfg-508342939.txt
2012-11-04 20:07:25 ----A---- C:\Windows\system32\netcfg-181627174.txt
2012-11-04 20:07:17 ----A---- C:\Windows\system32\netcfg-181619983.txt
2012-11-04 20:06:18 ----A---- C:\Windows\system32\netcfg-181560687.txt
2012-11-04 20:06:11 ----A---- C:\Windows\system32\netcfg-181553245.txt
2012-11-04 20:05:57 ----A---- C:\Windows\system32\netcfg-181539065.txt
2012-11-04 20:05:55 ----A---- C:\Windows\system32\netcfg-181537053.txt
2012-11-04 20:04:14 ----A---- C:\Windows\system32\netcfg-181436307.txt
2012-11-04 20:04:08 ----A---- C:\Windows\system32\netcfg-181430348.txt
2012-11-04 17:33:20 ----A---- C:\Users\Marek\AppData\Roaming\technic-launcher.jar
2012-11-04 17:33:17 ----D---- C:\Users\Marek\AppData\Roaming\logs
2012-11-04 17:33:17 ----D---- C:\Users\Marek\AppData\Roaming\.techniclauncher
2012-11-04 14:59:04 ----A---- C:\Users\Marek\AppData\Roaming\mcupdater.exe
2012-11-04 14:36:40 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-11-04 11:13:04 ----D---- C:\Program Files (x86)\MonoGame
2012-11-03 15:05:26 ----D---- C:\Users\Marek\AppData\Roaming\Google
2012-11-03 15:02:19 ----D---- C:\ProgramData\Google
2012-11-02 20:51:55 ----D---- C:\ProgramData\Microsoft Team Foundation Local Workspaces
2012-11-02 18:55:28 ----D---- C:\3D Rad
2012-11-02 14:47:22 ----D---- C:\ProgramData\Microsoft Visual Studio
2012-11-02 14:14:37 ----D---- C:\Windows\SYSWOW64\xlive
2012-11-02 14:14:28 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-11-02 13:30:26 ----A---- C:\Windows\SYSWOW64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2012-11-02 13:30:26 ----A---- C:\Windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2012-11-02 13:29:58 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2012-11-02 13:29:58 ----A---- C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2012-11-02 13:27:31 ----D---- C:\Windows\system32\RsFx
2012-11-02 13:26:17 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2012-11-02 13:25:17 ----D---- C:\Program Files\Microsoft.NET
2012-11-02 13:14:10 ----D---- C:\Program Files\Microsoft Sync Framework
2012-11-02 13:13:45 ----D---- C:\Program Files\Microsoft Synchronization Services
2012-11-02 13:13:25 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2012-11-02 12:58:15 ----D---- C:\Program Files (x86)\Microsoft F#
2012-11-02 12:53:57 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2012-11-02 12:53:18 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2012-11-02 12:53:18 ----D---- C:\Program Files\Microsoft Help Viewer
2012-11-02 12:51:45 ----D---- C:\Windows\PCHEALTH
2012-11-02 12:21:29 ----D---- C:\ProgramData\ALM
2012-11-02 12:01:26 ----D---- C:\Program Files (x86)\Adobe Media Player
2012-11-02 12:01:02 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2012-11-02 12:01:02 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2012-11-02 12:01:02 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2012-11-02 12:01:02 ----D---- C:\Program Files (x86)\My Company Name
2012-11-02 11:58:03 ----D---- C:\Program Files\Common Files\Adobe
2012-11-02 11:57:55 ----D---- C:\Program Files\Adobe
2012-11-02 11:55:47 ----D---- C:\Program Files (x86)\Adobe
2012-11-02 11:49:19 ----D---- C:\Adobe
2012-11-02 11:47:32 ----D---- C:\ProgramData\Adobe
2012-11-02 10:29:18 ----A---- C:\Windows\system32\netcfg-4446402.txt
2012-11-02 10:29:15 ----A---- C:\Windows\system32\netcfg-4443002.txt
2012-11-02 10:25:39 ----A---- C:\Windows\system32\netcfg-4227112.txt
2012-11-02 10:25:38 ----A---- C:\Windows\system32\netcfg-4226519.txt
2012-11-02 10:24:33 ----A---- C:\Windows\system32\netcfg-4161591.txt
2012-11-02 10:24:18 ----A---- C:\Windows\system32\netcfg-4146537.txt
2012-11-02 09:27:58 ----D---- C:\Program Files (x86)\BlueStacks
2012-11-02 09:27:09 ----D---- C:\ProgramData\BlueStacksSetup
2012-11-02 09:27:07 ----D---- C:\ProgramData\BlueStacks
2012-11-02 09:15:36 ----D---- C:\Windows\Minidump
2012-11-01 19:52:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-11-01 19:52:17 ----D---- C:\ProgramData\Sony
2012-11-01 19:52:17 ----D---- C:\Program Files (x86)\Sony
2012-11-01 19:41:02 ----A---- C:\Windows\system32\netcfg-47611.txt
2012-11-01 19:41:00 ----A---- C:\Windows\system32\netcfg-45396.txt
2012-11-01 19:37:27 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-11-01 19:37:27 ----A---- C:\Windows\system32\javaws.exe
2012-11-01 19:37:27 ----A---- C:\Windows\system32\deployJava1.dll
2012-11-01 19:37:18 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2012-11-01 19:37:18 ----A---- C:\Windows\system32\javaw.exe
2012-11-01 19:37:17 ----A---- C:\Windows\system32\java.exe
2012-11-01 19:36:23 ----D---- C:\Program Files\Java
2012-11-01 19:23:09 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-11-01 19:20:02 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-11-01 19:19:55 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-11-01 19:18:51 ----D---- C:\Program Files\Application Verifier
2012-11-01 19:18:51 ----D---- C:\Program Files (x86)\Application Verifier
2012-11-01 19:18:45 ----D---- C:\ProgramData\Windows App Certification Kit
2012-11-01 19:16:14 ----D---- C:\ProgramData\PreEmptive Solutions
2012-11-01 19:12:56 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2012-11-01 19:12:14 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2012-11-01 19:11:22 ----D---- C:\Program Files\Microsoft
2012-11-01 19:10:50 ----D---- C:\Program Files\IIS Express
2012-11-01 19:10:50 ----D---- C:\Program Files (x86)\IIS Express
2012-11-01 19:08:22 ----D---- C:\Program Files (x86)\NuGet
2012-11-01 19:08:08 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2012-11-01 19:07:59 ----D---- C:\Program Files\IIS
2012-11-01 19:07:59 ----D---- C:\Program Files (x86)\IIS
2012-11-01 19:01:07 ----D---- C:\Program Files (x86)\Windows Kits
2012-11-01 18:53:54 ----D---- C:\Program Files (x86)\HTML Help Workshop
2012-11-01 18:53:36 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2012-11-01 18:52:27 ----D---- C:\Windows\SYSWOW64\1033
2012-11-01 18:52:05 ----D---- C:\Program Files\Microsoft SQL Server
2012-11-01 18:52:05 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2012-11-01 18:44:50 ----D---- C:\Windows\system32\1033
2012-11-01 18:43:59 ----D---- C:\Windows\symbols
2012-11-01 18:43:55 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2012-11-01 18:43:55 ----D---- C:\Program Files (x86)\Microsoft SDKs
2012-11-01 18:43:04 ----D---- C:\ProgramData\Package Cache
2012-11-01 18:38:17 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-11-01 18:38:12 ----D---- C:\Users\Marek\AppData\Roaming\DAEMON Tools Lite
2012-11-01 18:38:09 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2012-11-01 18:35:44 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-11-01 11:04:35 ----D---- C:\Users\Marek\AppData\Roaming\Notepad++
2012-11-01 11:04:35 ----D---- C:\Program Files (x86)\Notepad++
2012-10-31 21:07:54 ----D---- C:\Program Files (x86)\Microsoft XNA
2012-10-31 20:32:14 ----A---- C:\Windows\system32\netcfg-15196790.txt
2012-10-31 20:30:54 ----A---- C:\Windows\system32\netcfg-15116730.txt
2012-10-31 20:30:33 ----A---- C:\Windows\system32\netcfg-15095062.txt
2012-10-31 20:30:26 ----A---- C:\Windows\system32\netcfg-15088447.txt
2012-10-31 20:06:58 ----D---- C:\Users\Marek\AppData\Roaming\Cobalt
2012-10-31 20:06:01 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-10-31 20:06:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-10-31 20:06:01 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-10-31 20:06:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-10-31 20:06:01 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-10-31 20:06:01 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-10-31 20:06:01 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-10-31 20:06:01 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-10-31 20:06:00 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-10-31 20:06:00 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-10-31 20:06:00 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-10-31 20:06:00 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-10-31 20:05:59 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-10-31 20:05:59 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-10-31 20:05:59 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-10-31 20:05:59 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-10-31 20:05:58 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-10-31 20:05:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-10-31 20:05:58 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-10-31 20:05:58 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-10-31 20:05:57 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-10-31 20:05:57 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-10-31 20:05:57 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-10-31 20:05:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-10-31 20:05:57 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-10-31 20:05:57 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-10-31 20:05:57 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-10-31 20:05:57 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-10-31 20:05:56 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-10-31 20:05:56 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-10-31 20:05:56 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-10-31 20:05:56 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-10-31 20:05:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-10-31 20:05:55 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-10-31 20:05:55 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-10-31 20:05:55 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-10-31 20:05:54 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-10-31 20:05:54 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-10-31 20:05:52 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-10-31 20:05:52 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-10-31 20:05:52 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-10-31 20:05:52 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-10-31 20:05:51 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-10-31 20:05:51 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-10-31 20:05:51 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-10-31 20:05:51 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-10-31 20:05:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-10-31 20:05:51 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-10-31 20:05:51 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-10-31 20:05:51 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-10-31 20:05:50 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-10-31 20:05:50 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-10-31 20:05:49 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-10-31 20:05:49 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-10-31 20:05:49 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-10-31 20:05:49 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-10-31 20:05:49 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-10-31 20:05:49 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-10-31 20:05:49 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-10-31 20:05:49 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-10-31 20:05:48 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-10-31 20:05:48 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-10-31 20:05:48 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-10-31 20:05:48 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-10-31 20:05:48 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-10-31 20:05:48 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-10-31 20:05:47 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-10-31 20:05:47 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-10-31 20:05:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-10-31 20:05:47 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-10-31 20:05:47 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-10-31 20:05:47 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-10-31 20:05:46 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-10-31 20:05:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-10-31 20:05:46 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-10-31 20:05:46 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-10-31 20:05:46 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-10-31 20:05:46 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-10-31 20:05:45 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-10-31 20:05:45 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-10-31 20:05:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-10-31 20:05:45 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-10-31 20:05:45 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-10-31 20:05:45 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-10-31 20:05:44 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-10-31 20:05:44 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-10-31 20:05:43 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-10-31 20:05:43 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-10-31 20:05:42 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-10-31 20:05:42 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-10-31 20:05:42 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-10-31 20:05:42 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-10-31 20:05:41 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-10-31 20:05:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-10-31 20:05:41 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-10-31 20:05:41 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-10-31 20:05:40 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-10-31 20:05:40 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-10-31 20:05:37 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-10-31 20:05:37 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-10-31 20:05:34 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-10-31 20:05:34 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-10-31 20:05:34 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-10-31 20:05:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-10-31 20:05:34 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-10-31 20:05:34 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-10-31 20:05:34 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-10-31 20:05:34 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-10-31 20:05:33 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-10-31 20:05:33 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-10-31 20:05:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-10-31 20:05:33 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-10-31 20:05:33 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-10-31 20:05:33 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-10-31 20:05:32 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-10-31 20:05:32 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-10-31 20:05:32 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-10-31 20:05:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-10-31 20:05:32 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-10-31 20:05:32 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-10-31 20:05:32 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-10-31 20:05:32 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-10-31 20:05:31 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-10-31 20:05:31 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-10-31 20:05:31 ----A---- C:\Windows\system32\xinput1_3.dll
2012-10-31 20:05:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-10-31 20:05:30 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-10-31 20:05:30 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-10-31 20:05:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-10-31 20:05:30 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-10-31 20:05:30 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-10-31 20:05:30 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-10-31 20:05:29 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-10-31 20:05:29 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-10-31 20:05:29 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-10-31 20:05:29 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-10-31 20:05:28 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-10-31 20:05:28 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-10-31 20:05:28 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-10-31 20:05:28 ----A---- C:\Windows\system32\d3dx10.dll
2012-10-31 20:05:27 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-10-31 20:05:27 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-10-31 20:05:27 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-10-31 20:05:27 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-10-31 20:05:27 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-10-31 20:05:27 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-10-31 20:05:26 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-10-31 20:05:26 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-10-31 20:05:26 ----A---- C:\Windows\system32\xinput1_2.dll
2012-10-31 20:05:26 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-10-31 20:05:26 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-10-31 20:05:25 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-10-31 20:05:25 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-10-31 20:05:25 ----A---- C:\Windows\system32\xinput1_1.dll
2012-10-31 20:05:25 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-10-31 20:05:24 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-10-31 20:05:24 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-10-31 20:05:23 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-10-31 20:05:23 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-10-31 20:05:23 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-10-31 20:05:23 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-10-31 20:05:23 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-10-31 20:05:23 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-10-31 20:05:22 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-10-31 20:05:22 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-10-31 20:05:22 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-10-31 20:05:22 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-10-31 20:05:21 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-10-31 20:05:21 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-10-31 20:05:21 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-10-31 20:05:21 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-10-31 20:05:20 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-10-31 20:05:19 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-10-31 20:05:19 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-10-31 19:59:54 ----D---- C:\Windows\SYSWOW64\directx
2012-10-31 19:50:24 ----D---- C:\Program Files (x86)\OpenAL
2012-10-31 19:50:24 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2012-10-31 19:50:24 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2012-10-31 19:50:24 ----A---- C:\Windows\system32\wrap_oal.dll
2012-10-31 19:50:24 ----A---- C:\Windows\system32\OpenAL32.dll
2012-10-31 16:19:29 ----A---- C:\Windows\system32\netcfg-31715.txt
2012-10-31 16:19:27 ----A---- C:\Windows\system32\netcfg-29390.txt
2012-10-31 15:42:47 ----A---- C:\Windows\BcdLog.txt
2012-10-31 15:41:12 ----A---- C:\Windows\SYSWOW64\setupempdrv03.exe
2012-10-31 15:41:12 ----A---- C:\Windows\SYSWOW64\EuGdiDrv.sys
2012-10-31 15:41:12 ----A---- C:\Windows\SYSWOW64\EuEpmGdi.dll
2012-10-31 15:41:12 ----A---- C:\Windows\SYSWOW64\epmntdrv.sys
2012-10-31 15:41:12 ----A---- C:\Windows\SYSWOW64\BootMan.exe
2012-10-31 15:41:12 ----A---- C:\Windows\system32\setupempdrvx64.exe
2012-10-31 15:41:12 ----A---- C:\Windows\system32\EuGdiDrv.sys
2012-10-31 15:41:12 ----A---- C:\Windows\system32\EuEpmGdi.dll
2012-10-31 15:41:12 ----A---- C:\Windows\system32\epmntdrv.sys
2012-10-31 15:41:12 ----A---- C:\Windows\system32\BootMan.exe
2012-10-31 15:41:02 ----D---- C:\Program Files (x86)\EaseUS
2012-10-31 14:25:07 ----D---- C:\Android
2012-10-31 14:18:11 ----D---- C:\Users\Marek\AppData\Roaming\GameMaker-Studio
2012-10-31 14:16:42 ----A---- C:\Windows\system32\perfh01B.dat
2012-10-31 14:16:42 ----A---- C:\Windows\system32\perfc01B.dat
2012-10-31 14:15:16 ----D---- C:\Program Files (x86)\Reference Assemblies
2012-10-31 14:15:16 ----D---- C:\Program Files (x86)\MSBuild
2012-10-31 14:14:44 ----D---- C:\Program Files\Reference Assemblies
2012-10-31 14:14:44 ----D---- C:\Program Files\MSBuild
2012-10-31 14:12:00 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2012-10-31 14:12:00 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2012-10-31 14:12:00 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2012-10-31 14:11:53 ----A---- C:\Windows\system32\TsWpfWrp.exe
2012-10-31 14:11:53 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2012-10-31 14:11:53 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2012-10-31 13:29:21 ----D---- C:\Users\Marek\AppData\Roaming\uTorrent
2012-10-31 12:22:59 ----D---- C:\Program Files (x86)\Putty
2012-10-31 11:18:10 ----D---- C:\Users\Marek\AppData\Roaming\TeamViewer
2012-10-31 11:12:24 ----A---- C:\Windows\slsvc.exe
2012-10-31 11:12:24 ----A---- C:\Windows\SLCHook.dll
2012-10-31 11:12:24 ----A---- C:\Windows\PersonalizeEnabler.exe
2012-10-31 11:12:24 ----A---- C:\Windows\EasyHook64.dll
2012-10-31 11:11:26 ----RSHD---- C:\Windows Activation Technologies
2012-10-31 10:32:57 ----A---- C:\Windows\system32\netcfg-53595578.txt
2012-10-31 10:32:54 ----A---- C:\Windows\system32\netcfg-53592177.txt
2012-10-30 21:31:25 ----D---- C:\Program Files (x86)\WinSCP
2012-10-30 21:12:31 ----D---- C:\Users\Marek\AppData\Roaming\Skype
2012-10-30 21:12:24 ----RD---- C:\Program Files (x86)\Skype
2012-10-30 21:12:18 ----D---- C:\ProgramData\Skype
2012-10-30 20:10:26 ----D---- C:\Users\Marek\AppData\Roaming\.minecraft
2012-10-30 20:09:51 ----D---- C:\ProgramData\Sun
2012-10-30 20:09:31 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2012-10-30 20:09:31 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-10-30 20:09:31 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-10-30 20:09:24 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2012-10-30 20:09:24 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-10-30 20:09:24 ----A---- C:\Windows\SYSWOW64\java.exe
2012-10-30 20:09:13 ----D---- C:\Program Files (x86)\Java
2012-10-30 19:47:47 ----D---- C:\Users\Marek\AppData\Roaming\ATI
2012-10-30 19:47:47 ----D---- C:\ProgramData\ATI
2012-10-30 19:28:42 ----D---- C:\ProgramData\AMD
2012-10-30 19:28:40 ----D---- C:\Program Files (x86)\AMD AVT
2012-10-30 19:28:39 ----D---- C:\Program Files (x86)\AMD APP
2012-10-30 19:28:35 ----D---- C:\Program Files\Common Files\ATI Technologies
2012-10-30 19:27:56 ----D---- C:\Program Files (x86)\ATI Technologies
2012-10-30 19:27:51 ----D---- C:\Program Files\ATI
2012-10-30 19:23:17 ----D---- C:\Program Files\ATI Technologies
2012-10-30 19:19:09 ----D---- C:\AMD
2012-10-30 18:12:14 ----D---- C:\Users\Marek\AppData\Roaming\WinRAR
2012-10-30 18:11:58 ----D---- C:\Program Files\WinRAR
2012-10-30 18:01:52 ----D---- C:\Program Files (x86)\Altap Salamander
2012-10-30 17:36:21 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-10-30 17:36:19 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-10-30 17:35:34 ----D---- C:\Program Files (x86)\Winamp Detect
2012-10-30 17:35:03 ----D---- C:\Users\Marek\AppData\Roaming\Winamp
2012-10-30 17:35:03 ----D---- C:\Program Files (x86)\Winamp
2012-10-30 17:31:42 ----D---- C:\Users\Marek\AppData\Roaming\Mozilla
2012-10-30 17:31:31 ----D---- C:\ProgramData\Mozilla
2012-10-30 17:31:30 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-10-30 17:31:26 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-10-30 17:17:27 ----D---- C:\Windows\SoftwareDistribution
2012-10-30 17:13:08 ----D---- C:\Users\Marek\AppData\Roaming\Macromedia
2012-10-30 17:08:37 ----D---- C:\Users\Marek\AppData\Roaming\Adobe
2012-10-30 17:07:53 ----D---- C:\ProgramData\PRICache
2012-10-30 17:07:30 ----SD---- C:\Users\Marek\AppData\Roaming\Microsoft
2012-10-30 17:07:25 ----D---- C:\Windows\CSC
2012-10-30 17:05:41 ----A---- C:\Windows\system32\netcfg-133880.txt
2012-10-30 17:05:40 ----A---- C:\Windows\system32\netcfg-132616.txt
2012-10-30 17:05:35 ----A---- C:\Windows\system32\netcfg-127749.txt
2012-10-30 17:04:04 ----SHD---- C:\Recovery
2012-10-30 17:03:33 ----ASH---- C:\hiberfil.sys
2012-10-30 17:01:35 ----A---- C:\Windows\system32\netcfg-95051.txt
2012-10-30 17:01:32 ----A---- C:\Windows\system32\netcfg-92336.txt
2012-10-30 17:01:31 ----A---- C:\Windows\system32\netcfg-91151.txt
2012-10-30 17:01:22 ----A---- C:\Windows\system32\netcfg-82196.txt
2012-10-30 17:01:21 ----A---- C:\Windows\system32\netcfg-81775.txt
2012-10-30 17:01:21 ----A---- C:\Windows\system32\netcfg-81260.txt
2012-10-30 17:01:20 ----A---- C:\Windows\system32\netcfg-80293.txt
2012-10-30 17:01:19 ----A---- C:\Windows\system32\netcfg-79934.txt
2012-10-30 17:01:19 ----A---- C:\Windows\system32\netcfg-79622.txt
2012-10-30 17:01:19 ----A---- C:\Windows\system32\netcfg-79326.txt
2012-10-30 17:01:18 ----A---- C:\Windows\system32\netcfg-78733.txt
2012-10-30 17:01:18 ----A---- C:\Windows\system32\netcfg-78328.txt
2012-10-30 17:01:17 ----A---- C:\Windows\system32\netcfg-77750.txt
2012-10-30 17:01:10 ----D---- C:\Windows\Prefetch
2012-10-30 17:00:16 ----ASH---- C:\swapfile.sys
2012-10-30 17:00:16 ----ASH---- C:\pagefile.sys
2012-10-30 17:00:12 ----SHD---- C:\System Volume Information
2012-10-30 16:59:31 ----D---- C:\Windows\Panther
2012-10-30 16:59:19 ----RASH---- C:\BOOTSECT.BAK
2012-10-30 16:59:15 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 month======

2012-11-22 22:01:20 ----RD---- C:\Program Files
2012-11-22 22:00:08 ----D---- C:\Windows\system32\sru
2012-11-22 21:57:51 ----D---- C:\Windows\system32\Tasks
2012-11-22 20:51:23 ----D---- C:\Windows\Microsoft.NET
2012-11-22 17:01:29 ----D---- C:\Windows\system32\config
2012-11-22 16:59:27 ----D---- C:\Windows\Temp
2012-11-22 15:31:20 ----RD---- C:\Windows\System32
2012-11-21 17:57:00 ----RSD---- C:\Windows\Fonts
2012-11-21 17:56:21 ----RD---- C:\Program Files (x86)
2012-11-21 17:39:46 ----SHD---- C:\Windows\Installer
2012-11-21 17:38:49 ----HD---- C:\ProgramData
2012-11-21 17:37:39 ----D---- C:\Windows\SysWOW64
2012-11-20 20:14:37 ----D---- C:\Windows\Inf
2012-11-20 20:14:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-18 15:44:45 ----HD---- C:\Program Files\WindowsApps
2012-11-18 10:35:44 ----RSD---- C:\Windows\assembly
2012-11-17 12:38:57 ----D---- C:\Windows\AUInstallAgent
2012-11-15 21:13:43 ----D---- C:\Windows\system32\NDF
2012-11-15 19:05:46 ----D---- C:\Windows\WinSxS
2012-11-15 17:05:01 ----D---- C:\Program Files (x86)\Common Files
2012-11-09 20:44:05 ----D---- C:\Windows\Logs
2012-11-03 14:18:53 ----D---- C:\Windows\rescache
2012-11-03 11:56:34 ----D---- C:\Windows\system32\Drivers
2012-11-03 11:22:44 ----SD---- C:\ProgramData\Microsoft
2012-11-02 13:25:17 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-11-02 13:21:00 ----D---- C:\Program Files\Common Files\microsoft shared
2012-11-02 12:51:45 ----D---- C:\Windows
2012-11-02 12:01:02 ----D---- C:\Windows\system32\catroot
2012-11-02 11:58:03 ----D---- C:\Program Files\Common Files
2012-11-02 09:37:11 ----D---- C:\Windows\system32\LogFiles
2012-11-01 19:58:38 ----D---- C:\Windows\system32\DriverStore
2012-11-01 19:09:37 ----D---- C:\Windows\CbsTemp
2012-11-01 18:44:14 ----D---- C:\Windows\system32\drivers\UMDF
2012-11-01 18:44:13 ----SD---- C:\Windows\system32\Microsoft
2012-11-01 18:43:04 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2012-10-31 21:08:01 ----SHD---- C:\$Recycle.Bin
2012-10-31 16:20:31 ----D---- C:\Windows\system32\wdi
2012-10-31 14:14:47 ----D---- C:\Windows\SYSWOW64\en-US
2012-10-31 14:14:46 ----D---- C:\Windows\system32\en-US
2012-10-31 11:11:07 ----D---- C:\Windows\system32\sk-SK
2012-10-30 20:22:18 ----D---- C:\Windows\system32\catroot2
2012-10-30 18:12:23 ----D---- C:\Windows\Tasks
2012-10-30 17:35:44 ----D---- C:\Windows\system32\restore
2012-10-30 17:13:31 ----D---- C:\Windows\system32\CodeIntegrity
2012-10-30 17:07:55 ----D---- C:\Windows\WinStore
2012-10-30 17:07:53 ----RD---- C:\Windows\ImmersiveControlPanel
2012-10-30 17:07:30 ----RD---- C:\Users
2012-10-30 17:04:51 ----D---- C:\Windows\debug
2012-10-30 17:04:04 ----D---- C:\Windows\system32\Recovery

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ACPI;@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver; C:\Windows\System32\drivers\ACPI.sys [2012-07-26 424688]
R0 acpiex;Microsoft ACPIEx Driver; C:\Windows\System32\Drivers\acpiex.sys [2012-07-26 77040]
R0 atapi;@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel; C:\Windows\System32\drivers\atapi.sys [2012-07-26 25840]
R0 CLFS;@%SystemRoot%\system32\drivers\clfs.sys,-100; C:\Windows\System32\drivers\CLFS.sys [2012-07-26 361200]
R0 CNG;CNG; C:\Windows\System32\Drivers\cng.sys [2012-07-26 562400]
R0 disk;@disk.inf,%disk_ServiceDesc%;Disk Driver; C:\Windows\System32\drivers\disk.sys [2012-07-26 102640]
R0 EhStorClass;@%SystemRoot%\system32\drivers\EhStorClass.sys,-100; C:\Windows\System32\drivers\EhStorClass.sys [2012-07-26 81136]
R0 FileInfo;@%SystemRoot%\system32\drivers\fileinfo.sys,-100; C:\Windows\System32\drivers\fileinfo.sys [2012-07-26 71920]
R0 FltMgr;@%SystemRoot%\system32\drivers\fltmgr.sys,-10001; C:\Windows\system32\drivers\fltmgr.sys [2012-07-26 374512]
R0 fvevol;@%SystemRoot%\system32\drivers\fvevol.sys,-100; C:\Windows\System32\DRIVERS\fvevol.sys [2012-07-26 465136]
R0 KSecDD;KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [2012-07-26 100080]
R0 KSecPkg;KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [2012-07-26 172272]
R0 mountmgr;@%SystemRoot%\system32\drivers\mountmgr.sys,-100; C:\Windows\System32\drivers\mountmgr.sys [2012-07-26 93936]
R0 msisadrv;msisadrv; C:\Windows\System32\drivers\msisadrv.sys [2012-07-26 17136]
R0 Mup;@%systemroot%\system32\drivers\mup.sys,-101; C:\Windows\System32\Drivers\mup.sys [2012-07-26 83696]
R0 NDIS;@%SystemRoot%\system32\drivers\ndis.sys,-200; C:\Windows\system32\drivers\ndis.sys [2012-07-26 1000688]
R0 partmgr;@%SystemRoot%\system32\drivers\partmgr.sys,-100; C:\Windows\System32\drivers\partmgr.sys [2012-07-26 91888]
R0 pci;@machine.inf,%pci_svcdesc%;PCI Bus Driver; C:\Windows\System32\drivers\pci.sys [2012-07-26 234224]
R0 pciide;pciide; C:\Windows\System32\drivers\pciide.sys [2012-07-26 14064]
R0 pcw;Performance Counters for Windows Driver; C:\Windows\System32\drivers\pcw.sys [2012-07-26 52464]
R0 pdc;@%SystemRoot%\system32\drivers\pdc.sys,-100; C:\Windows\system32\drivers\pdc.sys [2012-07-26 68848]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2012-07-26 217328]
R0 spaceport;@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver; C:\Windows\System32\drivers\spaceport.sys [2012-07-26 283888]
R0 Tcpip;@%SystemRoot%\system32\tcpipcfg.dll,-50003; C:\Windows\System32\drivers\tcpip.sys [2012-07-26 2224880]
R0 vdrvroot;@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator; C:\Windows\System32\drivers\vdrvroot.sys [2012-07-26 36080]
R0 volmgr;@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver; C:\Windows\System32\drivers\volmgr.sys [2012-07-26 83184]
R0 volmgrx;@%SystemRoot%\system32\drivers\volmgrx.sys,-100; C:\Windows\System32\drivers\volmgrx.sys [2012-07-26 378608]
R0 volsnap;@volume.inf,%VolumeClassName%;Storage volumes; C:\Windows\System32\drivers\volsnap.sys [2012-07-26 332016]
R0 Wdf01000;@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000; C:\Windows\system32\drivers\Wdf01000.sys [2012-07-26 785512]
R0 WFPLWFS;@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000; C:\Windows\system32\DRIVERS\wfplwfs.sys [2012-07-26 96496]
R1 AFD;@%systemroot%\system32\drivers\afd.sys,-1000; C:\Windows\system32\drivers\afd.sys [2012-07-26 561152]
R1 BasicDisplay;BasicDisplay; C:\Windows\System32\drivers\BasicDisplay.sys [2012-07-26 48640]
R1 BasicRender;BasicRender; C:\Windows\System32\drivers\BasicRender.sys [2012-07-26 29696]
R1 Beep;Beep; C:\Windows\system32\drivers\Beep.sys [2012-07-26 7680]
R1 cdrom;@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver; C:\Windows\System32\drivers\cdrom.sys [2012-07-26 174080]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2012-07-26 571392]
R1 Dfsc;@%systemroot%\system32\wkssvc.dll,-1008; C:\Windows\System32\Drivers\dfsc.sys [2012-07-26 118784]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2012-07-26 50688]
R1 dtsoftbus01;@oem2.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2012-11-01 283200]
R1 Msfs;Msfs; C:\Windows\system32\drivers\Msfs.sys [2012-07-26 26112]
R1 mssmbios;@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver; C:\Windows\System32\drivers\mssmbios.sys [2012-07-26 37616]
R1 NetBIOS;@netnb.inf,%NetBIOS_Desc%;NetBIOS Interface; C:\Windows\system32\DRIVERS\netbios.sys [2012-07-26 46080]
R1 NetBT;@%SystemRoot%\system32\drivers\netbt.sys,-2; C:\Windows\System32\DRIVERS\netbt.sys [2012-07-26 331776]
R1 Npfs;Npfs; C:\Windows\system32\drivers\Npfs.sys [2012-07-26 49152]
R1 npsvctrig;@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider; C:\Windows\System32\drivers\npsvctrig.sys [2012-07-26 23552]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2012-07-26 34304]
R1 Null;Null; C:\Windows\system32\drivers\Null.sys [2012-07-26 5632]
R1 Psched;@%SystemRoot%\System32\drivers\pacer.sys,-101; C:\Windows\system32\DRIVERS\pacer.sys [2012-07-26 145408]
R1 rdbss;@%systemroot%\system32\wkssvc.dll,-1000; C:\Windows\system32\DRIVERS\rdbss.sys [2012-07-26 423936]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2012-07-26 117248]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2012-07-26 64000]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2012-07-26 83456]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2012-10-25 71032]
R2 lltdio;@%SystemRoot%\system32\lltdres.dll,-6; C:\Windows\system32\DRIVERS\lltdio.sys [2012-07-26 60416]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2012-07-26 134144]
R2 NativeWifiP;@%SystemRoot%\System32\drivers\nwifi.sys,-101; C:\Windows\system32\DRIVERS\nwifi.sys [2012-07-26 427520]
R2 Ndu;@%SystemRoot%\system32\drivers\Ndu.sys,-10001; C:\Windows\system32\drivers\Ndu.sys [2012-07-26 97792]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2012-07-26 804864]
R2 rspndr;@%SystemRoot%\system32\lltdres.dll,-5; C:\Windows\system32\DRIVERS\rspndr.sys [2012-07-26 78848]
R2 secdrv;Security Driver; C:\Windows\system32\drivers\secdrv.sys [2012-07-26 23040]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2012-07-26 45056]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 AmdPPM;@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver; C:\Windows\System32\drivers\amdppm.sys [2012-07-26 88064]
R3 BCM43XX;@netbc63a.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2012-06-02 5139968]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2012-07-26 101888]
R3 CmBatt;@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver; C:\Windows\System32\drivers\CmBatt.sys [2012-07-26 25600]
R3 CompositeBus;@CompositeBus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver; C:\Windows\System32\drivers\CompositeBus.sys [2012-07-26 36352]
R3 condrv;Console Driver; C:\Windows\System32\drivers\condrv.sys [2012-07-26 33792]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2012-07-26 1448688]
R3 HdAudAddService;@hdaudio.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2012-07-26 339968]
R3 HDAudBus;@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio; C:\Windows\System32\drivers\HDAudBus.sys [2012-07-26 71168]
R3 HidUsb;@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver; C:\Windows\System32\drivers\hidusb.sys [2012-07-26 27648]
R3 HTTP;@%SystemRoot%\system32\drivers\http.sys,-1; C:\Windows\system32\drivers\HTTP.sys [2012-07-26 859136]
R3 i8042prt;@keyboard.inf,%i8042prt.SvcDesc%;i8042 Keyboard and PS/2 Mouse Port Driver; C:\Windows\System32\drivers\i8042prt.sys [2012-07-26 112640]
R3 kbdclass;@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver; C:\Windows\System32\drivers\kbdclass.sys [2012-07-26 48368]
R3 kdnic;@kdnic.inf,%KdNic.Service.DispName%;Microsoft Kernel Debug Network Miniport (NDIS 6.20); C:\Windows\system32\DRIVERS\kdnic.sys [2012-07-26 18432]
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys [2012-07-26 21376]
R3 monitor;@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service; C:\Windows\system32\DRIVERS\monitor.sys [2012-07-26 30720]
R3 mouclass;@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver; C:\Windows\System32\drivers\mouclass.sys [2012-07-26 45808]
R3 mouhid;@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver; C:\Windows\System32\drivers\mouhid.sys [2012-07-26 26112]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2012-07-26 74752]
R3 mrxsmb;@%systemroot%\system32\wkssvc.dll,-1002; C:\Windows\system32\DRIVERS\mrxsmb.sys [2012-07-26 368128]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2012-07-26 279552]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2012-07-26 214016]
R3 NdisTapi;@%systemroot%\system32\rascfg.dll,-32001; C:\Windows\system32\DRIVERS\ndistapi.sys [2012-07-26 25088]
R3 Ndisuio;@ndisuio.inf,%NDISUIO_Desc%;NDIS Usermode I/O Protocol; C:\Windows\system32\DRIVERS\ndisuio.sys [2012-07-26 58880]
R3 NdisWan;@%systemroot%\system32\rascfg.dll,-32002; C:\Windows\system32\DRIVERS\ndiswan.sys [2012-07-26 174080]
R3 NDProxy;NDIS Proxy; C:\Windows\system32\drivers\NDProxy.sys [2012-07-26 60416]
R3 Ntfs;Ntfs; C:\Windows\system32\drivers\Ntfs.sys [2012-07-26 1934064]
R3 PptpMiniport;@%systemroot%\system32\rascfg.dll,-32006; C:\Windows\system32\DRIVERS\raspptp.sys [2012-07-26 114176]
R3 RasAgileVpn;@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2012-07-26 68608]
R3 Rasl2tp;@%systemroot%\system32\rascfg.dll,-32005; C:\Windows\system32\DRIVERS\rasl2tp.sys [2012-07-26 124928]
R3 RasPppoe;@%systemroot%\system32\rascfg.dll,-32007; C:\Windows\system32\DRIVERS\raspppoe.sys [2012-07-26 81920]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2012-07-26 92672]
R3 rdpbus;@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver; C:\Windows\System32\drivers\rdpbus.sys [2012-07-26 22528]
R3 RDPDR;@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100; C:\Windows\System32\drivers\rdpdr.sys [2012-07-26 179712]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-07-26 27888]
R3 SensorsSimulatorDriver;@oem3.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 198656]
R3 srv;@%systemroot%\system32\srvsvc.dll,-102; C:\Windows\System32\DRIVERS\srv.sys [2012-07-26 416768]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2012-07-26 619520]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2012-07-26 248832]
R3 swenum;@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver; C:\Windows\System32\drivers\swenum.sys [2012-07-26 13680]
R3 TPM;@tpm.inf,%TPM%;TPM; C:\Windows\system32\drivers\tpm.sys [2012-07-26 148720]
R3 tunnel;@nettun.inf,%TUNNEL.Service.DisplayName%;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2012-07-26 149504]
R3 umbus;@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver; C:\Windows\System32\drivers\umbus.sys [2012-07-26 48128]
R3 usbccgp;@usb.inf,%GenericParent.SvcDesc%;Microsoft USB Generic Parent Driver; C:\Windows\System32\drivers\usbccgp.sys [2012-07-26 120832]
R3 usbehci;@usbport.inf,%EHCIMP.SvcDesc%;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\Windows\System32\drivers\usbehci.sys [2012-07-26 78576]
R3 usbhub;@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver; C:\Windows\System32\drivers\usbhub.sys [2012-07-26 496368]
R3 usbohci;@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\System32\drivers\usbohci.sys [2012-07-26 27136]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2012-07-26 210304]
R3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2012-07-26 24064]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2012-07-26 17920]
R3 WmiAcpi;@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI; C:\Windows\System32\drivers\wmiacpi.sys [2012-07-26 17408]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 87040]
R3 WUDFRd;@hidbthle.inf,%WudfRdDisplayName%;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\Windows\System32\drivers\WUDFRd.sys [2012-07-26 198656]
S0 3ware;3ware; C:\Windows\System32\drivers\3ware.sys [2012-07-26 106736]
S0 adp94xx;adp94xx; C:\Windows\System32\drivers\adp94xx.sys [2012-07-26 492272]
S0 adpahci;adpahci; C:\Windows\System32\drivers\adpahci.sys [2012-07-26 340720]
S0 adpu320;adpu320; C:\Windows\System32\drivers\adpu320.sys [2012-07-26 184048]
S0 agp440;@machine.inf,%agp440_svcdesc%;Intel AGP Bus Filter; C:\Windows\System32\drivers\agp440.sys [2012-07-26 63216]
S0 amdsata;amdsata; C:\Windows\System32\drivers\amdsata.sys [2012-07-26 76016]
S0 amdsbs;amdsbs; C:\Windows\System32\drivers\amdsbs.sys [2012-07-26 258288]
S0 amdxata;amdxata; C:\Windows\System32\drivers\amdxata.sys [2012-07-26 26352]
S0 arc;arc; C:\Windows\System32\drivers\arc.sys [2012-07-26 104688]
S0 arcsas;@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Windows Inbox Miniport Driver; C:\Windows\System32\drivers\arcsas.sys [2012-07-26 108272]
S0 b06bdrv;@netbvbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II VBD; C:\Windows\System32\drivers\bxvbda.sys [2012-07-26 539376]
S0 ebdrv;@netevbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\System32\drivers\evbda.sys [2012-07-26 3295984]
S0 EhStorTcgDrv;@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols; C:\Windows\System32\drivers\EhStorTcgDrv.sys [2012-07-26 113904]
S0 gagp30kx;@machine.inf,%gagp30kx_svcdesc%;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\System32\drivers\gagp30kx.sys [2012-07-26 66800]
S0 HpSAMD;HpSAMD; C:\Windows\System32\drivers\HpSAMD.sys [2012-07-26 64752]
S0 hwpolicy;@%systemroot%\system32\drivers\hwpolicy.sys,-101; C:\Windows\System32\drivers\hwpolicy.sys [2012-07-26 24816]
S0 iaStorV;@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7; C:\Windows\System32\drivers\iaStorV.sys [2012-07-26 411888]
S0 iirsp;iirsp; C:\Windows\System32\drivers\iirsp.sys [2012-07-26 45296]
S0 intelide;intelide; C:\Windows\System32\drivers\intelide.sys [2012-07-26 18672]
S0 isapnp;isapnp; C:\Windows\System32\drivers\isapnp.sys [2012-07-26 22256]
S0 LSI_SAS;LSI_SAS; C:\Windows\System32\drivers\lsi_sas.sys [2012-07-26 108784]
S0 LSI_SAS2;LSI_SAS2; C:\Windows\System32\drivers\lsi_sas2.sys [2012-07-26 92400]
S0 LSI_SCSI;LSI_SCSI; C:\Windows\System32\drivers\lsi_scsi.sys [2012-07-26 116976]
S0 LSI_SSS;LSI_SSS; C:\Windows\System32\drivers\lsi_sss.sys [2012-07-26 81136]
S0 megasas;megasas; C:\Windows\System32\drivers\megasas.sys [2012-07-26 51952]
S0 MegaSR;MegaSR; C:\Windows\System32\drivers\MegaSR.sys [2012-07-26 353008]
S0 mvumis;mvumis; C:\Windows\System32\drivers\mvumis.sys [2012-07-26 64240]
S0 nfrd960;nfrd960; C:\Windows\System32\drivers\nfrd960.sys [2012-07-26 52464]
S0 nv_agp;@machine.inf,%agpnvidia_svcdesc%;NVIDIA nForce AGP Bus Filter; C:\Windows\System32\drivers\nv_agp.sys [2012-07-26 125168]
S0 nvraid;nvraid; C:\Windows\System32\drivers\nvraid.sys [2012-07-26 150256]
S0 nvstor;nvstor; C:\Windows\System32\drivers\nvstor.sys [2012-07-26 168176]
S0 pcmcia;pcmcia; C:\Windows\System32\drivers\pcmcia.sys [2012-07-26 237808]
S0 sbp2port;@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver; C:\Windows\System32\drivers\sbp2port.sys [2012-07-26 107760]
S0 SiSRaid2;SiSRaid2; C:\Windows\System32\drivers\SiSRaid2.sys [2012-07-26 44784]
S0 SiSRaid4;SiSRaid4; C:\Windows\System32\drivers\sisraid4.sys [2012-07-26 81648]
S0 stexstor;stexstor; C:\Windows\System32\drivers\stexstor.sys [2012-07-26 30960]
S0 storahci;@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver; C:\Windows\System32\drivers\storahci.sys [2012-07-26 77552]
S0 storflt;@%SystemRoot%\system32\vmstorfltres.dll,-1000; C:\Windows\system32\DRIVERS\vmstorfl.sys [2012-07-26 45160]
S0 storvsc;storvsc; C:\Windows\System32\drivers\storvsc.sys [2012-07-26 37992]
S0 uagp35;@machine.inf,%uagp35_svcdesc%;Microsoft AGPv3.5 Filter; C:\Windows\System32\drivers\uagp35.sys [2012-07-26 65776]
S0 uliagpkx;@machine.inf,%uliagpkx_svcdesc%;Uli AGP Bus Filter; C:\Windows\System32\drivers\uliagpkx.sys [2012-07-26 66800]
S0 viaide;viaide; C:\Windows\System32\drivers\viaide.sys [2012-07-26 19184]
S0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\System32\drivers\vmbus.sys [2012-07-26 137832]
S0 vsmraid;vsmraid; C:\Windows\System32\drivers\vsmraid.sys [2012-07-26 164080]
S0 VSTXRAID;@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage Controller Windows Driver; C:\Windows\System32\drivers\vstxraid.sys [2012-07-26 322800]
S0 Wd;@wd.inf,%WdServiceDisplayName%;Microsoft Watchdog Timer Driver; C:\Windows\System32\drivers\wd.sys [2012-07-26 23792]
S1 dam;@%SystemRoot%\system32\drivers\dam.sys,-100; C:\Windows\system32\drivers\dam.sys [2012-07-26 55024]
S3 1394ohci;@1394.inf,%PCI\CC_0C0010.DeviceDesc%;1394 OHCI Compliant Host Controller; C:\Windows\System32\drivers\1394ohci.sys [2012-07-26 226304]
S3 acpipagr;@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver; C:\Windows\System32\drivers\acpipagr.sys [2012-07-26 10240]
S3 AcpiPmi;@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver; C:\Windows\System32\drivers\acpipmi.sys [2012-07-26 12288]
S3 acpitime;@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver; C:\Windows\System32\drivers\acpitime.sys [2012-07-26 10752]
S3 AmdK8;@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver; C:\Windows\System32\drivers\amdk8.sys [2012-07-26 90624]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2012-07-26 79360]
S3 AsyncMac;@%systemroot%\system32\rascfg.dll,-32000; C:\Windows\system32\DRIVERS\asyncmac.sys [2012-07-26 26624]
S3 BthAvrcpTg;@bthaudhid.inf,%BthAvrcpTg_SvcDesc%;Bluetooth Audio/Video Remote Control HID; C:\Windows\System32\drivers\BthAvrcpTg.sys [2012-07-26 31104]
S3 BthHFEnum;@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio and Call Control HID Enumerator; C:\Windows\System32\drivers\bthhfenum.sys [2012-07-26 51200]
S3 bthhfhid;@bthaudhid.inf,%BthAudioHFHid.SVCDESC%;Bluetooth Hands-Free Call Control HID; C:\Windows\System32\drivers\BthHFHid.sys [2012-07-26 29952]
S3 BTHMODEM;@bthspp.inf,%BthSerial.DisplayName%;Bluetooth Serial Communications Driver; C:\Windows\System32\drivers\bthmodem.sys [2012-07-26 65536]
S3 circlass;@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices; C:\Windows\System32\drivers\circlass.sys [2012-07-26 45056]
S3 dmvsc;dmvsc; C:\Windows\System32\drivers\dmvsc.sys [2012-07-26 33280]
S3 drmkaud;@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2012-07-26 5632]
S3 epmntdrv;epmntdrv; \??\C:\Windows\syswow64\epmntdrv.sys [2011-07-29 14216]
S3 ErrDev;@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver; C:\Windows\System32\drivers\errdev.sys [2012-07-26 10240]
S3 EuGdiDrv;EuGdiDrv; \??\C:\Windows\syswow64\EuGdiDrv.sys [2011-07-29 8456]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2012-07-26 194560]
S3 fastfat;FAT12/16/32 File System Driver; C:\Windows\system32\drivers\fastfat.sys [2012-07-26 210672]
S3 fdc;@fdc.inf,%fdc_ServiceDesc%;Floppy Disk Controller Driver; C:\Windows\System32\drivers\fdc.sys [2012-07-26 30720]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2012-07-26 34816]
S3 flpydisk;@flpydisk.inf,%floppy_ServiceDesc%;Floppy Disk Driver; C:\Windows\System32\drivers\flpydisk.sys [2012-07-26 24576]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2012-07-26 57584]
S3 FxPPM;@cpu.inf,%FxPPM.SvcDesc%;Power Framework Processor Driver; C:\Windows\System32\drivers\fxppm.sys [2012-07-26 22528]
S3 gencounter;@wgencounter.inf,%GenCounter.SVCDESC%;Microsoft Hyper-V Generation Counter; C:\Windows\System32\drivers\vmgencounter.sys [2012-07-26 12288]
S3 GPIOClx0101;Microsoft GPIO Class Extension Driver; C:\Windows\System32\Drivers\msgpioclx.sys [2012-07-26 120048]
S3 HidBatt;@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver; C:\Windows\System32\drivers\HidBatt.sys [2012-07-26 27136]
S3 HidBth;@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport; C:\Windows\System32\drivers\hidbth.sys [2012-07-26 95744]
S3 hidi2c;@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver; C:\Windows\System32\drivers\hidi2c.sys [2012-07-26 38400]
S3 HidIr;@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver; C:\Windows\System32\drivers\hidir.sys [2012-07-26 46080]
S3 hyperkbd;hyperkbd; C:\Windows\System32\drivers\hyperkbd.sys [2012-07-26 11776]
S3 HyperVideo;HyperVideo; C:\Windows\system32\DRIVERS\HyperVideo.sys [2012-07-26 24576]
S3 intelppm;@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver; C:\Windows\System32\drivers\intelppm.sys [2012-07-26 89088]
S3 IpFilterDriver;@%systemroot%\system32\rascfg.dll,-32013; C:\Windows\system32\DRIVERS\ipfltdrv.sys [2012-07-26 89088]
S3 IPMIDRV;IPMIDRV; C:\Windows\System32\drivers\IPMIDrv.sys [2012-07-26 78336]
S3 IPNAT;IP Network Address Translator; C:\Windows\System32\drivers\ipnat.sys [2012-07-26 145920]
S3 IRENUM;@%SystemRoot%\system32\drivers\irenum.sys,-100; C:\Windows\system32\drivers\irenum.sys [2012-07-26 17920]
S3 iScsiPrt;@iscsi.inf,%iScsiPortName%;iScsiPort Driver; C:\Windows\System32\drivers\msiscsi.sys [2012-07-26 277744]
S3 kbdhid;@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver; C:\Windows\System32\drivers\kbdhid.sys [2012-07-26 29184]
S3 Modem;Modem; C:\Windows\system32\drivers\modem.sys [2012-07-26 40448]
S3 MRxDAV;@%systemroot%\system32\webclnt.dll,-104; C:\Windows\system32\drivers\mrxdav.sys [2012-07-26 141312]
S3 MsBridge;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2012-07-26 129536]
S3 msgpiowin32;@msgpiowin32.inf,%GPIO.SvcDesc%;GPIO Buttons Driver; C:\Windows\System32\drivers\msgpiowin32.sys [2012-07-26 28400]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2012-07-26 8704]
S3 mshidumdf;@%SystemRoot%\system32\drivers\mshidumdf.sys,-100; C:\Windows\System32\drivers\mshidumdf.sys [2012-07-26 10752]
S3 MSKSSRV;@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2012-07-26 11008]
S3 MsLldp;@C:\Windows\system32\DRIVERS\mslldp.sys,-200; C:\Windows\system32\DRIVERS\mslldp.sys [2012-07-26 68608]
S3 MSPCLOCK;@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2012-07-26 7168]
S3 MSPQM;@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2012-07-26 6912]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2012-07-26 390896]
S3 MSTEE;@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2012-07-26 8192]
S3 MTConfig;@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver; C:\Windows\System32\drivers\MTConfig.sys [2012-07-26 14848]
S3 NdisCap;@%SystemRoot%\System32\drivers\ndiscap.sys,-5000; C:\Windows\system32\DRIVERS\ndiscap.sys [2012-07-26 46592]
S3 NdisImPlatform;@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501; C:\Windows\system32\DRIVERS\NdisImPlatform.sys [2012-07-26 126464]
S3 NDISWANLEGACY;@%systemroot%\system32\rascfg.dll,-32014; C:\Windows\system32\DRIVERS\ndiswan.sys [2012-07-26 174080]
S3 Parport;@msports.inf,%Parport.SVCDESC%;Parallel port driver; C:\Windows\System32\drivers\parport.sys [2012-07-26 105984]
S3 Processor;@cpu.inf,%Processor.SvcDesc%;Processor Driver; C:\Windows\System32\drivers\processr.sys [2012-07-26 87552]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2012-07-26 46592]
S3 RasAcd;Remote Access Auto Connection Driver; C:\Windows\System32\DRIVERS\rasacd.sys [2012-07-26 16384]
S3 RDPWD;RDP Winstation Driver; C:\Windows\system32\drivers\RDPWD.sys [2012-07-26 208384]
S3 s3cap;s3cap; C:\Windows\System32\drivers\vms3cap.sys [2012-07-26 7168]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2012-07-26 36864]
S3 sdbus;sdbus; C:\Windows\System32\drivers\sdbus.sys [2012-07-26 193264]
S3 sdstor;@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver; C:\Windows\System32\drivers\sdstor.sys [2012-07-26 56560]
S3 SerCx;Serial UART Support Library; C:\Windows\system32\drivers\SerCx.sys [2012-07-26 62976]
S3 Serenum;@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver; C:\Windows\System32\drivers\serenum.sys [2012-07-26 23040]
S3 Serial;@msports.inf,%Serial.SVCDESC%;Serial port driver; C:\Windows\System32\drivers\serial.sys [2012-07-26 76800]
S3 sermouse;@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver; C:\Windows\System32\drivers\sermouse.sys [2012-07-26 27136]
S3 sfloppy;@flpydisk.inf,%sfloppy_devdesc%;High-Capacity Floppy Disk Drive; C:\Windows\System32\drivers\sfloppy.sys [2012-07-26 16896]
S3 SpbCx;Simple Peripheral Bus Support Library; C:\Windows\system32\drivers\SpbCx.sys [2012-07-26 59392]
S3 storvsp;storvsp; C:\Windows\System32\drivers\storvsp.sys [2012-07-26 67584]
S3 TCPIP6;@netip6.inf,%MS_TCPIP6.TCPIP6.ServiceDescription%;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2012-07-26 2224880]
S3 terminpt;@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver; C:\Windows\System32\drivers\terminpt.sys [2012-07-26 36592]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-07-26 57344]
S3 TsUsbGD;@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device; C:\Windows\System32\drivers\TsUsbGD.sys [2012-07-26 30208]
S3 UASPStor;@uaspstor.inf,%UASPortName%;USB Attached SCSI (UAS) Driver; C:\Windows\System32\drivers\uaspstor.sys [2012-07-26 97008]
S3 UCX01000;USB Controller Extension; C:\Windows\System32\drivers\ucx01000.sys [2012-07-26 212208]
S3 UmPass;@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver; C:\Windows\System32\drivers\umpass.sys [2012-07-26 11776]
S3 usbcir;@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR); C:\Windows\System32\drivers\usbcir.sys [2012-07-26 99328]
S3 USBHUB3;@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub; C:\Windows\System32\drivers\UsbHub3.sys [2012-07-26 445168]
S3 usbprint;@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class; C:\Windows\System32\drivers\usbprint.sys [2012-07-26 25600]
S3 USBSTOR;@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver; C:\Windows\System32\drivers\USBSTOR.SYS [2012-07-26 119024]
S3 usbuhci;@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver; C:\Windows\System32\drivers\usbuhci.sys [2012-07-26 32256]
S3 USBXHCI;@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller; C:\Windows\System32\drivers\USBXHCI.SYS [2012-07-26 337136]
S3 VerifierExt;@%SystemRoot%\system32\drivers\VerifierExt.sys,-1000; C:\Windows\system32\drivers\VerifierExt.sys [2012-07-26 106224]
S3 vhdmp;vhdmp; C:\Windows\System32\drivers\vhdmp.sys [2012-07-26 496368]
S3 Vid;Vid; C:\Windows\System32\drivers\Vid.sys [2012-07-26 203776]
S3 VMBusHID;VMBusHID; C:\Windows\System32\drivers\VMBusHID.sys [2012-07-26 22144]
S3 vmbusr;@%SystemRoot%\system32\vmbusres.dll,-1001; C:\Windows\System32\drivers\vmbusr.sys [2012-07-26 117248]
S3 vpci;@wvpci.inf,%vpci.SVCDESC%;Microsoft Hyper-V Virtual PCI Bus; C:\Windows\System32\drivers\vpci.sys [2012-07-26 67824]
S3 vpcivsp;@wvpcivsp.inf,%vpcivsp.SVCDESC%;Microsoft Hyper-V PCI Server; C:\Windows\System32\drivers\vpcivsp.sys [2012-07-26 66048]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\D:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\D:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
S3 WacomPen;@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver; C:\Windows\System32\drivers\wacompen.sys [2012-07-26 27008]
S3 Wanarp;@%systemroot%\system32\rascfg.dll,-32011; C:\Windows\system32\DRIVERS\wanarp.sys [2012-07-26 83456]
S3 WdBoot;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390; C:\Windows\system32\drivers\WdBoot.sys [2012-07-26 34216]
S3 WdFilter;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330; C:\Windows\system32\drivers\WdFilter.sys [2012-07-26 258288]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2012-07-26 33520]
S3 WinUSB;@oem42.inf,%WinUSB_SvcDesc%;Sony Ericsson USB Device sa0101 Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2012-07-26 57344]
S3 wpcfltr;Family Safety Filter Driver; C:\Windows\system32\DRIVERS\wpcfltr.sys [2012-07-26 45056]
S3 WpdUpFltr;@%systemroot%\System32\drivers\WpdUpFltr.sys,-100; C:\Windows\System32\drivers\WpdUpFltr.sys [2012-07-26 19968]
S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\Windows\System32\drivers\WSDPrint.sys [2012-07-26 21504]
S4 cdfs;CD/DVD File System Reader; C:\Windows\system32\DRIVERS\cdfs.sys [2012-07-26 108544]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
S4 udfs;udfs; C:\Windows\system32\DRIVERS\udfs.sys [2012-07-26 321024]
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys [2012-07-26 22528]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-07-04 361984]
R2 AudioEndpointBuilder;@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 Audiosrv;@%SystemRoot%\system32\audiosrv.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 BITS;@%SystemRoot%\system32\qmgr.dll,-1000; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 BrokerInfrastructure;@%windir%\system32\bisrv.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Browser Manager;Browser Manager; C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe [2012-11-12 2402840]
R2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2012-10-25 393080]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2012-10-25 384888]
R2 CryptSvc;@%SystemRoot%\system32\cryptsvc.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 DcomLaunch;@combase.dll,-5012; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 DeviceAssociationService;@%SystemRoot%\system32\das.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Dhcp;@%SystemRoot%\system32\dhcpcore.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Dnscache;@%SystemRoot%\System32\dnsapi.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2012-07-26 35840]
R2 EventLog;@%SystemRoot%\system32\wevtsvc.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 EventSystem;@comres.dll,-2450; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 LanmanServer;@%systemroot%\system32\srvsvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 LanmanWorkstation;@%systemroot%\system32\wkssvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 lmhosts;@%SystemRoot%\system32\lmhsvc.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 LSM;@%windir%\system32\lsm.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 RpcSs;@combase.dll,-5010; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 SamSs;@%SystemRoot%\system32\samsrv.dll,-1; C:\Windows\system32\lsass.exe [2012-07-26 35840]
R2 SENS;@%SystemRoot%\system32\Sens.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 ShellHWDetection;@%SystemRoot%\System32\shsvcs.dll,-12288; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 Schedule;@%SystemRoot%\system32\schedsvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 slsvc;Software Licensing Service; C:\Windows\slsvc.exe [2012-09-25 10240]
R2 Spooler;@%systemroot%\system32\spoolsv.exe,-1; C:\Windows\System32\spoolsv.exe [2012-07-26 769024]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Themes;@%SystemRoot%\System32\themeservice.dll,-8192; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 TrkWks;@%SystemRoot%\system32\trkwks.dll,-1; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 Wcmsvc;@%SystemRoot%\System32\wcmsvc.dll,-4097; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 Winmgmt;@%Systemroot%\system32\wbem\wmisvc.dll,-205; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 WlanSvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R2 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files\Windows Media Player\wmpnetwk.exe [2012-07-26 1314304]
R2 wscsvc;@%SystemRoot%\System32\wscsvc.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2012-07-26 816128]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 Browser;@%systemroot%\system32\browser.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2012-07-26 35840]
R3 NcdAutoSetup;@%SystemRoot%\system32\NcdAutoSetup.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 netprofm;@%SystemRoot%\system32\netprofmsvc.dll,-202; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 PlugPlay;@%SystemRoot%\system32\umpnpmgr.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 PolicyAgent;@%SystemRoot%\System32\polstore.dll,-5010; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 seclogon;@%SystemRoot%\system32\seclogon.dll,-7001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 SSDPSRV;@%systemroot%\system32\ssdpsrv.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 SystemEventsBroker;@%windir%\system32\SystemEventsBrokerServer.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 TermService;@%SystemRoot%\System32\termsrv.dll,-268; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 TimeBroker;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 upnphost;@%systemroot%\system32\upnphost.dll,-213; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2012-07-26 35840]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2012-07-26 30208]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
R3 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2012-07-26 4881408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 250808]
S3 ALG;@%SystemRoot%\system32\Alg.exe,-112; C:\Windows\System32\alg.exe [2012-07-26 94208]
S3 AllUserInstallAgent;@%SystemRoot%\System32\AUInstallAgent.dll,-101; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-12 51648]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2012-07-26 30208]

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#3 Příspěvek od GAMELASTER »

S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 COMSysApp;@comres.dll,-947; C:\Windows\system32\dllhost.exe [2012-07-26 10752]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 DeviceInstall;@%SystemRoot%\system32\umpnpmgr.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 dot3svc;@%systemroot%\system32\dot3svc.dll,-1102; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 DsmSvc;@%SystemRoot%\system32\DeviceSetupManager.dll,-1000; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 Eaphost;@%systemroot%\system32\eapsvc.dll,-1; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2012-07-26 669696]
S3 fhsvc;@%systemroot%\system32\fhsvc.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-06 43616]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 hidserv;@%SystemRoot%\System32\hidserv.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 hkmsvc;@%SystemRoot%\system32\kmsvc.dll,-6; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-24 115168]
S3 MSDTC;@comres.dll,-2797; C:\Windows\System32\msdtc.exe [2012-07-26 144384]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 msiserver;@%SystemRoot%\system32\msimsg.dll,-27; C:\Windows\system32\msiexec.exe [2012-07-26 124416]
S3 napagent;@%SystemRoot%\system32\qagentrt.dll,-6; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 NcaSvc;@%SystemRoot%\system32\ncasvc.dll,-3009; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 Netlogon;@%SystemRoot%\System32\netlogon.dll,-102; C:\Windows\system32\lsass.exe [2012-07-26 35840]
S3 Netman;@%SystemRoot%\system32\netman.dll,-109; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2012-07-26 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 PrintNotify;@C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 RasAuto;@%Systemroot%\system32\rasauto.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 RasMan;@%Systemroot%\system32\rasmans.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 RpcLocator;@%systemroot%\system32\Locator.exe,-2; C:\Windows\system32\locator.exe [2012-07-26 9728]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2012-07-26 14848]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 stisvc;@%SystemRoot%\system32\wiaservc.dll,-9; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 svsvc;@%SystemRoot%\system32\svsvc.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 swprv;@%SystemRoot%\System32\swprv.dll,-103; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 TapiSrv;@%SystemRoot%\system32\tapisrv.dll,-10100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2012-07-26 94208]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2012-07-26 40960]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2012-07-26 680960]
S3 vmickvpexchange;@%systemroot%\system32\vmicres.dll,-201; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 vmicrdv;@%systemroot%\system32\vmicres.dll,-601; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 vmicshutdown;@%systemroot%\system32\vmicres.dll,-301; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 vmictimesync;@%systemroot%\system32\vmicres.dll,-401; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 vmicvss;@%systemroot%\system32\vmicres.dll,-501; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 vmicheartbeat;@%systemroot%\system32\vmicres.dll,-101; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 VSS;@%systemroot%\system32\vssvc.exe,-102; C:\Windows\system32\vssvc.exe [2012-07-26 1482752]
S3 W32Time;@%SystemRoot%\system32\w32time.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2012-07-26 1616896]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 WebClient;@%systemroot%\system32\webclnt.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 WiaRpc;@%SystemRoot%\system32\wiarpc.dll,-2; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 WinDefend;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310; C:\Program Files\Windows Defender\MsMpEng.exe [2012-07-26 15440]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 wlidsvc;@%SystemRoot%\system32\wlidsvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 wmiApSrv;@%Systemroot%\system32\wbem\wmiapsrv.exe,-110; C:\Windows\system32\wbem\WmiApSrv.exe [2012-07-26 198144]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S3 WSService;@%SystemRoot%\system32\WSService.dll,-103; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S3 wuauserv;@%systemroot%\system32\wuaueng.dll,-105; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-12 139696]
S4 RemoteAccess;@%Systemroot%\system32\mprdim.dll,-200; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S4 RemoteRegistry;@regsvc.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S4 SCardSvr;@%SystemRoot%\System32\SCardSvr.dll,-1; C:\Windows\system32\svchost.exe [2012-07-26 30208]
S4 SharedAccess;@%SystemRoot%\system32\ipnathlp.dll,-106; C:\Windows\System32\svchost.exe [2012-07-26 30208]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus v instalacke

#4 Příspěvek od vyosek »

Zdravim :)

:arrow: Jen na uvod, system je legalni = zakoupena licence na W8?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#5 Příspěvek od GAMELASTER »

vyosek píše:Zdravim :)

:arrow: Jen na uvod, system je legalni = zakoupena licence na W8?
ano, je legalni... Ale jako rikam, zacalo to delat, az sem zacal instalovat zakladne veci...(To byl neakej tejden od upgradu)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus v instalacke

#6 Příspěvek od vyosek »

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Search
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#7 Příspěvek od GAMELASTER »

# AdwCleaner v2.008 - Logfile created 11/23/2012 at 21:05:01
# Updated 17/11/2012 by Xplode
# Operating system : Windows 8 Pro (64 bits)
# User : Marek - GAMELASTER
# Boot Mode : Normal
# Running from : C:\Users\Marek\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****

Found : Browser Manager

***** [Files / Folders] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\Browser Manager
Folder Found : C:\Users\Marek\AppData\Roaming\Babylon
Folder Found : C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager

***** [Registry] *****

Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\25911~1.18\{c16c1~1\mngr.dll
Key Found : HKCU\Software\Claro LTD
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKLM\Software\Babylon
Key Found : HKLM\Software\Claro LTD
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{05340575-7D2A-4266-9A84-7EEBDC476884}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97C47A30-3CFB-474B-94E3-6019A7EE0610}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EE4FC43F-84CE-4E20-88C2-2188525B47FB}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\claro
Key Found : HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9E131A93-EED7-4BEB-B015-A0ADB30B5646}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.10.9200.16384

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.claro-search.com/?affID=117423&tt=4 ... 210055d7ce
[HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://www.claro-search.com/?affID=117423&tt=4 ... 210055d7ce

-\\ Mozilla Firefox v16.0.2 (sk)

Profile name : default
File : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\xi0fsvv6.default\prefs.js

Found : user_pref("browser.search.defaultenginename", "Claro Search");
Found : user_pref("browser.search.order.1", "Claro Search");
Found : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=117423&tt=4712_6&babsrc=HP[...]
Found : user_pref("extensions.BabylonToolbar_i.newTab", false);
Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "");
Found : user_pref("extensions.claro.admin", false);
Found : user_pref("extensions.claro.aflt", "babsst");
Found : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}");
Found : user_pref("extensions.claro.dfltLng", "en");
Found : user_pref("extensions.claro.excTlbr", false);
Found : user_pref("extensions.claro.id", "80f7978100000000000002210055d7ce");
Found : user_pref("extensions.claro.instlDay", "15665");
Found : user_pref("extensions.claro.instlRef", "sst");
Found : user_pref("extensions.claro.prdct", "claro");
Found : user_pref("extensions.claro.prtnrId", "claro");
Found : user_pref("extensions.claro.tlbrId", "irhnew");
Found : user_pref("extensions.claro.tlbrSrchUrl", "");
Found : user_pref("extensions.claro.vrsn", "1.8.3.10");
Found : user_pref("extensions.claro.vrsni", "1.8.3.10");
Found : user_pref("extensions.claro_i.smplGrp", "none");
Found : user_pref("extensions.claro_i.vrsnTs", "1.8.3.1017:38:44");
Found : user_pref("keyword.URL", "hxxp://www.claro-search.com/?affID=117423&tt=4 ... &mntrId=80[...]

*************************

AdwCleaner[R1].txt - [5643 octets] - [23/11/2012 21:05:01]

########## EOF - C:\AdwCleaner[R1].txt - [5703 octets] ##########

//EDIT: Virus co raz silnejsie zatazuje CPU a obmedzuje flash... :/

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus v instalacke

#8 Příspěvek od vyosek »

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Delete
  • PC provede opravu, restartuje se a da Vam log (C:\AdwCleaner [S1].txt) , jeho obsah vlozte sem
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#9 Příspěvek od GAMELASTER »

# AdwCleaner v2.008 - Logfile created 11/23/2012 at 21:14:32
# Updated 17/11/2012 by Xplode
# Operating system : Windows 8 Pro (64 bits)
# User : Marek - GAMELASTER
# Boot Mode : Normal
# Running from : C:\Users\Marek\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : Browser Manager

***** [Files / Folders] *****

Deleted on reboot : C:\ProgramData\Browser Manager
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\Marek\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager

***** [Registry] *****

Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\25911~1.18\{c16c1~1\mngr.dll
Key Deleted : HKCU\Software\Claro LTD
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Claro LTD
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{05340575-7D2A-4266-9A84-7EEBDC476884}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97C47A30-3CFB-474B-94E3-6019A7EE0610}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EE4FC43F-84CE-4E20-88C2-2188525B47FB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60295942-9E5F-4EE8-B785-3A655904D24F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\claro
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9E131A93-EED7-4BEB-B015-A0ADB30B5646}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.10.9200.16384

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.claro-search.com/?affID=117423&tt=4 ... 210055d7ce --> hxxp://www.google.com
Deleted : [HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page]

-\\ Mozilla Firefox v16.0.2 (sk)

Profile name : default
File : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\xi0fsvv6.default\prefs.js

C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\xi0fsvv6.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultenginename", "Claro Search");
Deleted : user_pref("browser.search.order.1", "Claro Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=117423&tt=4712_6&babsrc=HP[...]
Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "");
Deleted : user_pref("extensions.claro.admin", false);
Deleted : user_pref("extensions.claro.aflt", "babsst");
Deleted : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}");
Deleted : user_pref("extensions.claro.dfltLng", "en");
Deleted : user_pref("extensions.claro.excTlbr", false);
Deleted : user_pref("extensions.claro.id", "80f7978100000000000002210055d7ce");
Deleted : user_pref("extensions.claro.instlDay", "15665");
Deleted : user_pref("extensions.claro.instlRef", "sst");
Deleted : user_pref("extensions.claro.prdct", "claro");
Deleted : user_pref("extensions.claro.prtnrId", "claro");
Deleted : user_pref("extensions.claro.tlbrId", "irhnew");
Deleted : user_pref("extensions.claro.tlbrSrchUrl", "");
Deleted : user_pref("extensions.claro.vrsn", "1.8.3.10");
Deleted : user_pref("extensions.claro.vrsni", "1.8.3.10");
Deleted : user_pref("extensions.claro_i.smplGrp", "none");
Deleted : user_pref("extensions.claro_i.vrsnTs", "1.8.3.1017:38:44");
Deleted : user_pref("keyword.URL", "hxxp://www.claro-search.com/?affID=117423&tt=4 ... &mntrId=80[...]

*************************

AdwCleaner[R1].txt - [5770 octets] - [23/11/2012 21:05:01]
AdwCleaner[S1].txt - [5729 octets] - [23/11/2012 21:14:32]

########## EOF - C:\AdwCleaner[S1].txt - [5789 octets] ##########


Malwarebytes Anti-Malware 1.65.1.1000
http://www.malwarebytes.org

Verzia databázy: v2012.11.23.08

Windows 7 x64 NTFS
Internet Explorer 9.10.9200.16384
Marek :: GAMELASTER [administrátor]

23.11.2012 21:25:43
mbam-log-2012-11-23 (23-44-09).txt

Typ kontroly: Úplná kontrola (C:\|D:\|)
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 716125
Uplynutý čas: 2 hod, 12 min, 17 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 0
(Škodlivé položky neboli zistené)

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 3
C:\Users\Marek\AppData\Local\Temp\DSUQ.exe (Riskware.InstallMonetizer) -> Žiadna úloha nevykonaná.
D:\full zaloha\Visual Studio 2012\Projects\Client\Client\bin\Debug\Client.exe (Trojan.MSIL) -> Žiadna úloha nevykonaná.
D:\full zaloha\Visual Studio 2012\Projects\Client\Client\obj\Debug\Client.exe (Trojan.MSIL) -> Žiadna úloha nevykonaná.
(koniec)


WTF???? Jak to ze moj projekt je virus? :/ Nepouzival sem zadnou pridavnu library, jenom cisty .NET a pouzival som packety :/ A to mam original :/

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus v instalacke

#10 Příspěvek od vyosek »

:arrow: Klidne to muze byt falesny poplach, MBAMu se nemuseji zdat treba nektere stringy a proto jej detekuje

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#11 Příspěvek od GAMELASTER »

Ok, jdu nato, jenom mala otazka... Mam dat vo Malaware Bytes odstranit te viri ci jako?
//EDIT: Ja mam ten program po anglicky , tak som dal run scan, dobre som dal? :D

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#12 Příspěvek od GAMELASTER »

OTL logfile created on: 24.11.2012 12:06:56 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marek\Downloads
64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16384)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d.M.yyyy

1,75 Gb Total Physical Memory | 0,43 Gb Available Physical Memory | 24,83% Memory free
3,87 Gb Paging File | 1,71 Gb Available in Paging File | 44,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 70,00 Gb Total Space | 32,06 Gb Free Space | 45,80% Space Free | Partition Type: NTFS
Drive D: | 162,88 Gb Total Space | 52,42 Gb Free Space | 32,18% Space Free | Partition Type: NTFS

Computer Name: GAMELASTER | User Name: Marek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.11.24 12:04:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marek\Downloads\OTL.exe
PRC - [2012.11.06 21:41:42 | 009,193,912 | ---- | M] (Martin Prikryl) -- C:\Program Files (x86)\WinSCP\WinSCP.exe
PRC - [2012.10.31 13:29:41 | 000,963,984 | ---- | M] (BitTorrent, Inc.) -- D:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012.10.31 12:22:35 | 000,483,328 | ---- | M] (Simon Tatham) -- C:\Program Files (x86)\Putty\putty.exe
PRC - [2012.10.30 18:12:23 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe
PRC - [2012.10.30 18:03:40 | 001,774,992 | ---- | M] (ALTAP) -- C:\Program Files (x86)\Altap Salamander\salamand.exe
PRC - [2012.10.25 17:33:34 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
PRC - [2012.10.25 17:33:14 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-Service.exe
PRC - [2012.10.25 17:33:10 | 000,366,456 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
PRC - [2012.10.25 17:33:02 | 000,260,472 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
PRC - [2012.10.25 17:33:00 | 000,375,672 | ---- | M] (BlueStack Systems) -- C:\Program Files (x86)\BlueStacks\HD-Network.exe
PRC - [2012.10.24 18:49:10 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.10.09 23:26:10 | 001,634,304 | ---- | M] (Don HO don.h@free.fr) -- C:\Program Files (x86)\Notepad++\notepad++.exe
PRC - [2012.09.29 19:54:26 | 000,981,656 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012.09.25 13:32:36 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\slsvc.exe
PRC - [2012.09.12 12:17:12 | 000,445,624 | ---- | M] (Sony) -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
PRC - [2012.06.28 16:41:58 | 002,206,888 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winamp.exe
PRC - [2012.06.28 16:40:52 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
PRC - [2012.02.27 19:39:58 | 000,412,160 | ---- | M] () -- D:\Rockstar Games\GTA San Andreas\samp.exe
PRC - [2010.03.06 04:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe


========== Modules (No Company Name) ==========

MOD - [2012.11.12 11:04:04 | 000,537,112 | ---- | M] () -- C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\mngr-16.0.dll
MOD - [2012.11.12 11:03:58 | 002,147,352 | ---- | M] () -- c:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.dll
MOD - [2012.10.30 18:12:21 | 009,814,968 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
MOD - [2012.10.30 17:36:33 | 000,091,136 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\xml.w5s
MOD - [2012.10.30 17:36:33 | 000,083,968 | ---- | M] () -- C:\Program Files (x86)\Winamp\tataki.dll
MOD - [2012.10.30 17:36:33 | 000,064,512 | ---- | M] () -- C:\Program Files (x86)\Winamp\zlib.dll
MOD - [2012.10.30 17:36:32 | 000,623,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jnetlib.w5s
MOD - [2012.10.30 17:36:32 | 000,174,080 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\auth.w5s
MOD - [2012.10.30 17:36:32 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll
MOD - [2012.10.30 17:36:32 | 000,154,624 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jpeg.w5s
MOD - [2012.10.30 17:36:32 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll
MOD - [2012.10.30 17:36:32 | 000,113,664 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll
MOD - [2012.10.30 17:36:32 | 000,087,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\png.w5s
MOD - [2012.10.30 17:36:32 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\read_file.dll
MOD - [2012.10.30 17:36:32 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\playlist.w5s
MOD - [2012.10.30 17:36:32 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_android.dll
MOD - [2012.10.30 17:36:32 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll
MOD - [2012.10.30 17:36:32 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\devices.w5s
MOD - [2012.10.30 17:36:32 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\timer.w5s
MOD - [2012.10.30 17:36:32 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\albumart.w5s
MOD - [2012.10.30 17:36:32 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\tagz.w5s
MOD - [2012.10.30 17:36:32 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll
MOD - [2012.10.30 17:36:32 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gif.w5s
MOD - [2012.10.30 17:36:32 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\bmp.w5s
MOD - [2012.10.30 17:36:32 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\dlmgr.w5s
MOD - [2012.10.30 17:36:32 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gracenote.w5s
MOD - [2012.10.30 17:36:32 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\filereader.w5s
MOD - [2012.10.30 17:36:32 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\primo.w5s
MOD - [2012.10.30 17:36:31 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
MOD - [2012.10.30 17:36:31 | 000,294,912 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_local.dll
MOD - [2012.10.30 17:36:31 | 000,290,816 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
MOD - [2012.10.30 17:36:31 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
MOD - [2012.10.30 17:36:31 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll
MOD - [2012.10.30 17:36:31 | 000,240,640 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
MOD - [2012.10.30 17:36:31 | 000,201,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll
MOD - [2012.10.30 17:36:31 | 000,164,864 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
MOD - [2012.10.30 17:36:31 | 000,124,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_online.dll
MOD - [2012.10.30 17:36:31 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll
MOD - [2012.10.30 17:36:31 | 000,083,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_plg.dll
MOD - [2012.10.30 17:36:31 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
MOD - [2012.10.30 17:36:31 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll
MOD - [2012.10.30 17:36:31 | 000,052,736 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
MOD - [2012.10.30 17:36:31 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
MOD - [2012.10.30 17:36:31 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_history.dll
MOD - [2012.10.30 17:36:31 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
MOD - [2012.10.30 17:36:31 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll
MOD - [2012.10.30 17:36:31 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll
MOD - [2012.10.30 17:36:31 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll
MOD - [2012.10.30 17:36:31 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll
MOD - [2012.10.30 17:36:31 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
MOD - [2012.10.30 17:36:31 | 000,022,528 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
MOD - [2012.10.30 17:36:31 | 000,018,432 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
MOD - [2012.10.30 17:36:31 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
MOD - [2012.10.30 17:36:30 | 001,737,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
MOD - [2012.10.30 17:36:30 | 000,318,976 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
MOD - [2012.10.30 17:36:30 | 000,185,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
MOD - [2012.10.30 17:36:30 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
MOD - [2012.10.30 17:36:30 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
MOD - [2012.10.30 17:36:30 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
MOD - [2012.10.30 17:36:30 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
MOD - [2012.10.30 17:36:30 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
MOD - [2012.10.30 17:36:30 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_orgler.dll
MOD - [2012.10.30 17:36:30 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
MOD - [2012.10.30 17:36:30 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
MOD - [2012.10.30 17:36:30 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
MOD - [2012.10.30 17:36:30 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
MOD - [2012.10.30 17:36:29 | 000,417,280 | ---- | M] () -- C:\Program Files (x86)\Winamp\nsutil.dll
MOD - [2012.10.30 17:36:29 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\libsndfile.dll
MOD - [2012.10.30 17:36:29 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Winamp\nde.dll
MOD - [2012.10.24 18:49:23 | 002,295,264 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.05.24 11:50:32 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
MOD - [2012.04.30 11:57:42 | 000,067,072 | ---- | M] () -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
MOD - [2012.04.30 11:57:42 | 000,039,936 | ---- | M] () -- C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
MOD - [2012.02.27 19:39:58 | 000,412,160 | ---- | M] () -- D:\Rockstar Games\GTA San Andreas\samp.exe
MOD - [2011.09.21 21:46:28 | 001,673,728 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll
MOD - [2011.07.18 22:07:28 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
MOD - [2010.09.02 12:06:18 | 000,242,176 | ---- | M] () -- C:\Program Files (x86)\Altap Salamander\lang\czech.slg
MOD - [2010.09.02 12:06:18 | 000,056,832 | ---- | M] () -- C:\Program Files (x86)\Altap Salamander\plugins\zip\lang\czech.slg


========== Services (SafeList) ==========

SRV:64bit: - [2012.07.26 05:46:56 | 002,366,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2012.07.26 04:30:05 | 002,675,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2012.07.26 04:17:59 | 000,015,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2012.07.26 04:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2012.07.26 04:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2012.07.26 04:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2012.07.26 04:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2012.07.26 04:07:30 | 000,169,984 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2012.07.26 04:07:27 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2012.07.26 04:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2012.07.26 04:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2012.07.26 04:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2012.07.26 04:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2012.07.26 04:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2012.07.26 04:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2012.07.26 04:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2012.07.26 04:05:38 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2012.07.26 04:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2012.07.26 04:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2012.07.26 04:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2012.07.26 04:05:11 | 000,174,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2012.07.26 04:05:08 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2012.07.26 04:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
SRV:64bit: - [2012.07.26 04:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2012.07.04 07:20:54 | 000,238,080 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012.07.04 01:36:06 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012.10.30 18:12:23 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.25 17:33:34 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012.10.25 17:33:14 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012.10.24 18:49:17 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.19 16:33:26 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.09.25 13:32:36 | 000,010,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\slsvc.exe -- (slsvc)
SRV - [2012.07.26 04:30:05 | 002,675,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.07.26 04:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2012.07.25 18:58:26 | 000,126,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe -- (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe -- (fussvc)
SRV - [2012.01.18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.11.01 18:38:17 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.07.26 06:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.07.26 06:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
DRV:64bit: - [2012.07.26 06:00:58 | 000,445,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2012.07.26 06:00:58 | 000,337,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2012.07.26 06:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2012.07.26 06:00:58 | 000,212,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2012.07.26 06:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2012.07.26 06:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2012.07.26 06:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2012.07.26 06:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2012.07.26 06:00:55 | 000,120,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2012.07.26 06:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
DRV:64bit: - [2012.07.26 06:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2012.07.26 06:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2012.07.26 06:00:55 | 000,028,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2012.07.26 06:00:54 | 000,056,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2012.07.26 06:00:52 | 003,295,984 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2012.07.26 06:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2012.07.26 06:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2012.07.26 06:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2012.07.26 06:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2012.07.26 06:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2012.07.26 06:00:49 | 000,539,376 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2012.07.26 06:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2012.07.26 06:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
DRV:64bit: - [2012.07.26 06:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012.07.26 06:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2012.07.26 05:59:35 | 000,193,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2012.07.26 05:59:35 | 000,148,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
DRV:64bit: - [2012.07.26 05:59:32 | 000,055,024 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
DRV:64bit: - [2012.07.26 05:58:00 | 000,068,848 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
DRV:64bit: - [2012.07.26 05:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2012.07.26 05:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2012.07.26 05:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
DRV:64bit: - [2012.07.26 05:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2012.07.26 05:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2012.07.26 04:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2012.07.26 04:17:38 | 000,027,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.07.26 03:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2012.07.26 03:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2012.07.26 03:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2012.07.26 03:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2012.07.26 03:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2012.07.26 03:28:27 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2012.07.26 03:27:58 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2012.07.26 03:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2012.07.26 03:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2012.07.26 03:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2012.07.26 03:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2012.07.26 03:27:31 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2012.07.26 03:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2012.07.26 03:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2012.07.26 03:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2012.07.26 03:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2012.07.26 03:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2012.07.26 03:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.07.26 03:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2012.07.26 03:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2012.07.26 03:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.07.26 03:25:54 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2012.07.26 03:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
DRV:64bit: - [2012.07.26 03:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
DRV:64bit: - [2012.07.26 03:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2012.07.26 03:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
DRV:64bit: - [2012.07.26 03:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
DRV:64bit: - [2012.07.26 03:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2012.07.26 03:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2012.07.26 03:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2012.07.04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.04 06:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.06.02 15:31:51 | 000,287,232 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\yk63x64.sys -- (yukonw8)
DRV:64bit: - [2012.06.02 15:31:33 | 005,139,968 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\BCMWL63A.SYS -- (BCM43XX)
DRV:64bit: - [2011.07.29 13:54:56 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2011.07.29 13:54:56 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2009.07.09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2012.10.25 17:33:26 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2012.07.13 16:13:14 | 000,070,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys -- (VSPerfDrv110)
DRV - [2011.07.29 13:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2011.07.29 13:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2010.03.17 23:34:36 | 000,068,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys -- (VSPerfDrv100)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US,en;q=0.7,sk;q=0.3
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 0A A2 F6 BC B6 CD 01 [binary data]
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE10SR
IE - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledAddons: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10
FF - prefs.js..extensions.enabledAddons: undoclosedtabsbutton@supernova00.biz:3.7.3
FF - prefs.js..extensions.enabledAddons: {41a40cb1-aa9e-47c6-a207-66b9f5875870}:0.5.0.2
FF - prefs.js..extensions.enabledAddons: {58bd07eb-0ee0-4df0-8121-dc9b693373df}:2.5.911.18
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Marek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: D:\Adobius\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012.11.02 12:34:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.10.30 17:31:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.30 17:35:33 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df}: C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2012.11.21 17:38:54 | 000,000,000 | ---D | M]

[2012.10.30 17:31:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\Extensions
[2012.11.21 21:35:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\Firefox\Profiles\xi0fsvv6.default\extensions
[2012.11.17 15:10:12 | 002,042,908 | ---- | M] () (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\xi0fsvv6.default\extensions\firebug@software.joehewitt.com.xpi
[2012.11.02 20:56:48 | 000,033,396 | ---- | M] () (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\xi0fsvv6.default\extensions\undoclosedtabsbutton@supernova00.biz.xpi
[2012.11.02 20:56:48 | 000,020,386 | ---- | M] () (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\xi0fsvv6.default\extensions\{41a40cb1-aa9e-47c6-a207-66b9f5875870}.xpi
[2012.10.30 18:08:16 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\xi0fsvv6.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012.11.21 17:38:52 | 000,002,514 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\xi0fsvv6.default\searchplugins\mngr.xml
[2012.10.30 17:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.11.21 17:38:54 | 000,000,000 | ---D | M] (Browser Manager) -- C:\PROGRAMDATA\BROWSER MANAGER\2.5.911.18\{C16C1CCB-7046-4E5C-A2F3-533AD2FEC8E8}\FIREFOXEXTENSION
[2012.10.24 18:50:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.28 16:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.10.24 22:01:45 | 000,001,583 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\atlas-sk.xml
[2012.10.24 22:01:45 | 000,001,380 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\azet-sk.xml
[2012.10.24 22:01:45 | 000,001,479 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\dunaj-sk.xml
[2012.10.24 22:01:46 | 000,001,473 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slovnik-sk.xml
[2012.10.24 22:01:46 | 000,001,104 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sk.xml
[2012.10.24 22:01:46 | 000,000,830 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2012.11.02 12:40:50 | 000,001,314 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - D:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Adobius\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml File not found
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001..\Run: [Game Fire] C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe (Smart PC Utilities, Ltd.)
O4 - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001..\Run: [Sony PC Companion] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-21-2331816091-2394518104-2338911075-1001..\Run: [uTorrent] D:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EDF67FE2-A120-4A07-9735-9773F363C9D7}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\25911~1.18\{c16c1~1\mngr.dll) - c:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: aux - File not found
Drivers32:64bit: midi - File not found
Drivers32:64bit: midimapper - File not found
Drivers32:64bit: mixer - File not found
Drivers32:64bit: msacm.imaadpcm - File not found
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - File not found
Drivers32:64bit: msacm.msg711 - File not found
Drivers32:64bit: msacm.msgsm610 - File not found
Drivers32:64bit: MSVideo8 - File not found
Drivers32:64bit: VIDC.FPS1 - File not found
Drivers32:64bit: vidc.i420 - File not found
Drivers32:64bit: VIDC.IYUV - File not found
Drivers32:64bit: vidc.mrle - File not found
Drivers32:64bit: vidc.msvc - File not found
Drivers32:64bit: VIDC.UYVY - File not found
Drivers32:64bit: VIDC.YUY2 - File not found
Drivers32:64bit: VIDC.YVU9 - File not found
Drivers32:64bit: VIDC.YVYU - File not found
Drivers32:64bit: wave - File not found
Drivers32:64bit: wavemapper - File not found
Drivers32: aux - wdmaud.drv File not found
Drivers32: midi - wdmaud.drv File not found
Drivers32: midimapper - midimap.dll File not found
Drivers32: mixer - wdmaud.drv File not found
Drivers32: msacm.imaadpcm - imaadp32.acm File not found
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm File not found
Drivers32: msacm.msg711 - msg711.acm File not found
Drivers32: msacm.msgsm610 - msgsm32.acm File not found
Drivers32: vidc.cvid - iccvid.dll File not found
Drivers32: VIDC.FPS1 - frapsvid.dll File not found
Drivers32: vidc.i420 - iyuv_32.dll File not found
Drivers32: vidc.iyuv - iyuv_32.dll File not found
Drivers32: vidc.mrle - msrle32.dll File not found
Drivers32: vidc.msvc - msvidc32.dll File not found
Drivers32: vidc.uyvy - msyuv.dll File not found
Drivers32: vidc.yuy2 - msyuv.dll File not found
Drivers32: vidc.yvu9 - tsbyuv.dll File not found
Drivers32: vidc.yvyu - msyuv.dll File not found
Drivers32: wave - wdmaud.drv File not found
Drivers32: wavemapper - msacm32.drv File not found
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.11.23 21:23:41 | 000,000,000 | ---D | C] -- C:\Users\Marek\AppData\Roaming\Malwarebytes
[2012.11.23 21:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.23 21:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.11.23 21:23:25 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.11.23 21:23:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.11.23 17:27:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Condition Zero
[2012.11.23 17:27:52 | 000,720,896 | ---- | C] (Indigo Rose Corporation) -- C:\Windows\iun6002.exe
[2012.11.22 22:01:20 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.11.22 22:01:14 | 000,000,000 | ---D | C] -- C:\rsit
[2012.11.21 17:54:12 | 000,000,000 | ---D | C] -- C:\Macromedia
[2012.11.21 17:39:42 | 000,000,000 | ---D | C] -- C:\Users\Marek\AppData\Roaming\Claro
[2012.11.21 17:39:31 | 000,018,816 | ---- | C] (Systweak Inc., (www.systweak.com)) -- C:\Windows\SysNative\roboot64.exe
[2012.11.21 17:39:22 | 000,000,000 | ---D | C] -- C:\Users\Marek\AppData\Roaming\systweak
[2012.11.21 17:38:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Browser Manager
[2012.11.21 17:37:40 | 000,000,000 | ---D | C] -- C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2012.11.21 17:22:32 | 001,227,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dx8vb.dll
[2012.11.18 15:51:27 | 000,000,000 | ---D | C] -- C:\Users\Marek\Documents\Games for Windows - LIVE Demos
[2012.11.18 10:35:41 | 000,000,000 | ---D | C] -- C:\Users\Marek\Documents\Smart PC Utilities
[2012.11.18 10:35:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Smart PC Utilities
[2012.11.17 12:48:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\directx
[2012.11.17 12:47:27 | 000,000,000 | ---D | C] -- C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GTA2GH
[2012.11.17 12:47:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GTA2GH
[2012.11.17 12:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gta2gh
[2012.11.04 14:59:04 | 000,354,816 | ---- | C] (FerdaSoft inc.) -- C:\Users\Marek\AppData\Roaming\mcupdater.exe

========== Files - Modified Within 7 Days ==========

[2012.11.24 12:09:45 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.11.24 12:07:55 | 000,252,508 | ---- | M] () -- C:\Users\Marek\Documents\Freezy.tar.gz
[2012.11.24 12:00:07 | 000,445,353 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-150.png
[2012.11.24 11:47:03 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.24 11:02:46 | 000,000,600 | ---- | M] () -- C:\Users\Marek\AppData\Local\PUTTY.RND
[2012.11.24 10:37:37 | 001,079,523 | ---- | M] () -- C:\Users\Marek\Documents\IMG_26112012_104113.png
[2012.11.24 09:11:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.23 23:14:02 | 000,000,600 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\winscp.rnd
[2012.11.23 23:04:06 | 000,001,456 | ---- | M] () -- C:\Users\Marek\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.11.23 23:04:05 | 000,020,007 | ---- | M] () -- C:\Users\Marek\Documents\header.png
[2012.11.23 21:24:25 | 001,174,640 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.23 21:24:25 | 000,810,396 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.23 21:24:25 | 000,170,740 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.23 21:24:25 | 000,148,906 | ---- | M] () -- C:\Windows\SysNative\perfh01B.dat
[2012.11.23 21:24:25 | 000,050,132 | ---- | M] () -- C:\Windows\SysNative\perfc01B.dat
[2012.11.23 21:23:27 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.23 21:16:41 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2012.11.23 21:16:38 | 1500,606,464 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.23 21:04:18 | 000,543,531 | ---- | M] () -- C:\Users\Marek\Desktop\adwcleaner.exe
[2012.11.23 20:29:50 | 000,307,724 | ---- | M] () -- C:\Users\Marek\Documents\IMG_25112012_203409.png
[2012.11.23 20:01:30 | 000,057,895 | ---- | M] () -- C:\Users\Marek\Documents\IMG_23112012_200211.png
[2012.11.23 17:27:54 | 000,000,646 | ---- | M] () -- C:\Users\Marek\Desktop\Condition Zero.lnk
[2012.11.23 17:22:48 | 000,014,150 | ---- | M] () -- C:\Users\Marek\Documents\IMG_23112012_172253_1.png
[2012.11.23 17:16:51 | 000,720,896 | ---- | M] (Indigo Rose Corporation) -- C:\Windows\iun6002.exe
[2012.11.23 17:06:16 | 000,101,123 | ---- | M] () -- C:\Users\Marek\Documents\IMG_7900.JPG
[2012.11.23 15:39:38 | 005,787,640 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.11.22 20:21:50 | 000,020,528 | ---- | M] () -- C:\Users\Marek\Documents\dsfffffffffff.png
[2012.11.22 18:11:28 | 000,840,261 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-149.png
[2012.11.21 20:58:39 | 000,006,656 | ---- | M] () -- C:\Users\Marek\Desktop\ConsoleApplication2.exe
[2012.11.21 20:18:05 | 000,854,041 | ---- | M] () -- C:\Users\Marek\sa-mp-650.png
[2012.11.21 20:17:49 | 000,878,565 | ---- | M] () -- C:\Users\Marek\sa-mp-656.png
[2012.11.21 20:17:42 | 001,003,210 | ---- | M] () -- C:\Users\Marek\sa-mp-651.png
[2012.11.21 20:17:41 | 001,045,518 | ---- | M] () -- C:\Users\Marek\sa-mp-653.png
[2012.11.21 20:17:40 | 000,986,429 | ---- | M] () -- C:\Users\Marek\sa-mp-652.png
[2012.11.21 20:17:37 | 000,641,279 | ---- | M] () -- C:\Users\Marek\sa-mp-659.png
[2012.11.21 20:17:36 | 000,486,216 | ---- | M] () -- C:\Users\Marek\sa-mp-658.png
[2012.11.21 20:17:28 | 001,125,678 | ---- | M] () -- C:\Users\Marek\sa-mp-644.png
[2012.11.21 20:17:22 | 000,613,642 | ---- | M] () -- C:\Users\Marek\sa-mp-647.png
[2012.11.21 20:17:19 | 000,382,852 | ---- | M] () -- C:\Users\Marek\sa-mp-655.png
[2012.11.21 20:17:17 | 001,083,030 | ---- | M] () -- C:\Users\Marek\sa-mp-646.png
[2012.11.21 20:17:02 | 000,894,027 | ---- | M] () -- C:\Users\Marek\sa-mp-645.png
[2012.11.21 20:17:02 | 000,779,305 | ---- | M] () -- C:\Users\Marek\sa-mp-648.png
[2012.11.21 20:16:58 | 000,770,531 | ---- | M] () -- C:\Users\Marek\sa-mp-649.png
[2012.11.21 18:24:42 | 000,296,097 | ---- | M] () -- C:\Users\Marek\Documents\gallery53.jpg
[2012.11.21 18:05:30 | 000,710,674 | ---- | M] () -- C:\Users\Marek\Documents\back.png
[2012.11.21 18:05:03 | 000,370,673 | ---- | M] () -- C:\Users\Marek\Documents\back.gif
[2012.11.21 17:37:40 | 000,000,516 | ---- | M] () -- C:\Users\Marek\Desktop\Fraps.lnk
[2012.11.21 17:22:34 | 001,227,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dx8vb.dll
[2012.11.21 17:03:33 | 000,000,983 | ---- | M] () -- C:\Users\Marek\Desktop\WinSCP.lnk
[2012.11.20 21:12:13 | 000,079,908 | ---- | M] () -- C:\Users\Marek\Documents\IMG_20112012_211223.png
[2012.11.20 15:28:03 | 000,007,586 | ---- | M] () -- C:\Users\Marek\Documents\race.pwn
[2012.11.19 20:55:35 | 001,044,092 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-640.png
[2012.11.19 20:55:25 | 001,163,341 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-638.png
[2012.11.19 20:55:24 | 000,856,509 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-637.png
[2012.11.19 20:55:21 | 000,682,248 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-641.png
[2012.11.19 20:55:19 | 001,182,730 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-639.png
[2012.11.19 20:55:13 | 001,022,480 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-642.png
[2012.11.19 20:55:11 | 000,889,220 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-643.png
[2012.11.19 20:55:07 | 000,664,236 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-633.png
[2012.11.19 20:55:06 | 000,660,571 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-634.png
[2012.11.19 20:54:48 | 000,566,674 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-632.png
[2012.11.19 20:54:32 | 000,367,605 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-636.png
[2012.11.19 20:54:19 | 000,651,251 | ---- | M] () -- C:\Users\Marek\Documents\sa-mp-635.png
[2012.11.19 18:26:09 | 000,055,326 | ---- | M] () -- C:\Users\Marek\Documents\freecashlogo.png
[2012.11.19 18:24:42 | 000,161,078 | ---- | M] () -- C:\Users\Marek\Documents\head.png
[2012.11.19 17:08:06 | 000,095,875 | ---- | M] () -- C:\Users\Marek\Documents\FreeCash.rar
[2012.11.18 13:55:18 | 005,938,017 | ---- | M] () -- C:\Users\Marek\Documents\DMgiampa_ft_TonyX_-_Lost_World.zip
[2012.11.18 13:55:12 | 006,232,983 | ---- | M] () -- C:\Users\Marek\Documents\DMRoyaLFtGerdomi-DeadOrAlive.zip
[2012.11.18 13:54:32 | 003,091,794 | ---- | M] () -- C:\Users\Marek\Documents\DMWaNTeD-_-vol2-_-My-_-Dreams.zip
[2012.11.18 13:54:22 | 003,617,777 | ---- | M] () -- C:\Users\Marek\Documents\DMJoxte_ft_Stailok_-_Earth_Batteries.zip
[2012.11.18 13:54:04 | 002,469,550 | ---- | M] () -- C:\Users\Marek\Documents\DMARmadaftLabiVila-Specialization.zip
[2012.11.18 13:52:12 | 000,058,933 | ---- | M] () -- C:\Users\Marek\Documents\dm-deadangel-feat-marki-all-the-above.zip
[2012.11.18 13:45:13 | 005,684,146 | ---- | M] () -- C:\Users\Marek\Documents\[DM]ALV-8-AimAndWin.zip
[2012.11.18 13:44:49 | 003,674,983 | ---- | M] () -- C:\Users\Marek\Documents\[DM] LabiVila ft. Scar - Daylight.zip
[2012.11.18 13:44:37 | 004,230,842 | ---- | M] () -- C:\Users\Marek\Documents\[DM]ALV #7 - Through the jungle II.zip
[2012.11.18 13:44:07 | 003,612,659 | ---- | M] () -- C:\Users\Marek\Documents\alv9.zip
[2012.11.18 13:43:41 | 002,558,370 | ---- | M] () -- C:\Users\Marek\Documents\[DM]ALV#4-MordeIsOP.zip
[2012.11.18 13:42:52 | 001,980,251 | ---- | M] () -- C:\Users\Marek\Documents\[DM]ALV #6-Through the jungle.zip
[2012.11.18 10:35:41 | 000,002,149 | ---- | M] () -- C:\Users\Public\Desktop\Game Fire.lnk
[2012.11.17 12:47:27 | 000,000,963 | ---- | M] () -- C:\Users\Marek\Desktop\Game Hunter.lnk

========== Files Created - No Company Name ==========

[2012.11.24 12:09:45 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.11.24 12:07:54 | 000,252,508 | ---- | C] () -- C:\Users\Marek\Documents\Freezy.tar.gz
[2012.11.24 12:00:02 | 000,445,353 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-150.png
[2012.11.24 10:37:32 | 001,079,523 | ---- | C] () -- C:\Users\Marek\Documents\IMG_26112012_104113.png
[2012.11.23 23:03:19 | 000,020,007 | ---- | C] () -- C:\Users\Marek\Documents\header.png
[2012.11.23 22:48:55 | 000,258,807 | ---- | C] () -- C:\Users\Marek\Desktop\header.psd
[2012.11.23 21:23:27 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.23 21:04:18 | 000,543,531 | ---- | C] () -- C:\Users\Marek\Desktop\adwcleaner.exe
[2012.11.23 20:29:47 | 000,307,724 | ---- | C] () -- C:\Users\Marek\Documents\IMG_25112012_203409.png
[2012.11.23 20:01:26 | 000,057,895 | ---- | C] () -- C:\Users\Marek\Documents\IMG_23112012_200211.png
[2012.11.23 17:27:54 | 000,000,646 | ---- | C] () -- C:\Users\Marek\Desktop\Condition Zero.lnk
[2012.11.23 17:22:47 | 000,014,150 | ---- | C] () -- C:\Users\Marek\Documents\IMG_23112012_172253_1.png
[2012.11.23 17:06:02 | 000,101,123 | ---- | C] () -- C:\Users\Marek\Documents\IMG_7900.JPG
[2012.11.22 20:21:49 | 000,020,528 | ---- | C] () -- C:\Users\Marek\Documents\dsfffffffffff.png
[2012.11.22 18:11:18 | 000,840,261 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-149.png
[2012.11.21 20:55:28 | 000,006,656 | ---- | C] () -- C:\Users\Marek\Desktop\ConsoleApplication2.exe
[2012.11.21 20:13:32 | 001,125,678 | ---- | C] () -- C:\Users\Marek\sa-mp-644.png
[2012.11.21 20:13:32 | 001,083,030 | ---- | C] () -- C:\Users\Marek\sa-mp-646.png
[2012.11.21 20:13:32 | 001,045,518 | ---- | C] () -- C:\Users\Marek\sa-mp-653.png
[2012.11.21 20:13:32 | 001,003,210 | ---- | C] () -- C:\Users\Marek\sa-mp-651.png
[2012.11.21 20:13:32 | 000,986,429 | ---- | C] () -- C:\Users\Marek\sa-mp-652.png
[2012.11.21 20:13:32 | 000,894,027 | ---- | C] () -- C:\Users\Marek\sa-mp-645.png
[2012.11.21 20:13:32 | 000,878,565 | ---- | C] () -- C:\Users\Marek\sa-mp-656.png
[2012.11.21 20:13:32 | 000,854,041 | ---- | C] () -- C:\Users\Marek\sa-mp-650.png
[2012.11.21 20:13:32 | 000,779,305 | ---- | C] () -- C:\Users\Marek\sa-mp-648.png
[2012.11.21 20:13:32 | 000,770,531 | ---- | C] () -- C:\Users\Marek\sa-mp-649.png
[2012.11.21 20:13:32 | 000,641,279 | ---- | C] () -- C:\Users\Marek\sa-mp-659.png
[2012.11.21 20:13:32 | 000,613,642 | ---- | C] () -- C:\Users\Marek\sa-mp-647.png
[2012.11.21 20:13:32 | 000,486,216 | ---- | C] () -- C:\Users\Marek\sa-mp-658.png
[2012.11.21 20:13:32 | 000,382,852 | ---- | C] () -- C:\Users\Marek\sa-mp-655.png
[2012.11.21 18:24:39 | 000,296,097 | ---- | C] () -- C:\Users\Marek\Documents\gallery53.jpg
[2012.11.21 18:05:24 | 000,710,674 | ---- | C] () -- C:\Users\Marek\Documents\back.png
[2012.11.21 18:05:04 | 000,001,456 | ---- | C] () -- C:\Users\Marek\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.11.21 18:05:02 | 000,370,673 | ---- | C] () -- C:\Users\Marek\Documents\back.gif
[2012.11.21 17:37:40 | 000,000,516 | ---- | C] () -- C:\Users\Marek\Desktop\Fraps.lnk
[2012.11.21 17:03:33 | 000,001,039 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
[2012.11.21 17:03:33 | 000,000,983 | ---- | C] () -- C:\Users\Marek\Desktop\WinSCP.lnk
[2012.11.20 21:12:07 | 000,079,908 | ---- | C] () -- C:\Users\Marek\Documents\IMG_20112012_211223.png
[2012.11.20 17:04:07 | 000,019,418 | ---- | C] () -- C:\Users\Marek\Desktop\los_santos_elegy_race.map
[2012.11.20 15:28:02 | 000,007,586 | ---- | C] () -- C:\Users\Marek\Documents\race.pwn
[2012.11.19 20:53:16 | 001,182,730 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-639.png
[2012.11.19 20:53:16 | 001,163,341 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-638.png
[2012.11.19 20:53:16 | 001,044,092 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-640.png
[2012.11.19 20:53:16 | 001,022,480 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-642.png
[2012.11.19 20:53:16 | 000,889,220 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-643.png
[2012.11.19 20:53:16 | 000,856,509 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-637.png
[2012.11.19 20:53:16 | 000,682,248 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-641.png

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#13 Příspěvek od GAMELASTER »

[2012.11.19 20:53:16 | 000,664,236 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-633.png
[2012.11.19 20:53:16 | 000,660,571 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-634.png
[2012.11.19 20:53:16 | 000,651,251 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-635.png
[2012.11.19 20:53:16 | 000,566,674 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-632.png
[2012.11.19 20:53:16 | 000,367,605 | ---- | C] () -- C:\Users\Marek\Documents\sa-mp-636.png
[2012.11.19 18:26:08 | 000,055,326 | ---- | C] () -- C:\Users\Marek\Documents\freecashlogo.png
[2012.11.19 18:24:40 | 000,161,078 | ---- | C] () -- C:\Users\Marek\Documents\head.png
[2012.11.19 17:08:01 | 000,095,875 | ---- | C] () -- C:\Users\Marek\Documents\FreeCash.rar
[2012.11.18 17:10:49 | 012,958,496 | ---- | C] () -- C:\Users\Marek\Desktop\NFS-MW-Cracked-by-RG-andropalace.net.apk
[2012.11.18 13:52:13 | 003,617,777 | ---- | C] () -- C:\Users\Marek\Documents\DMJoxte_ft_Stailok_-_Earth_Batteries.zip
[2012.11.18 13:52:11 | 003,091,794 | ---- | C] () -- C:\Users\Marek\Documents\DMWaNTeD-_-vol2-_-My-_-Dreams.zip
[2012.11.18 13:52:10 | 005,938,017 | ---- | C] () -- C:\Users\Marek\Documents\DMgiampa_ft_TonyX_-_Lost_World.zip
[2012.11.18 13:52:09 | 002,469,550 | ---- | C] () -- C:\Users\Marek\Documents\DMARmadaftLabiVila-Specialization.zip
[2012.11.18 13:52:07 | 000,058,933 | ---- | C] () -- C:\Users\Marek\Documents\dm-deadangel-feat-marki-all-the-above.zip
[2012.11.18 13:52:05 | 006,232,983 | ---- | C] () -- C:\Users\Marek\Documents\DMRoyaLFtGerdomi-DeadOrAlive.zip
[2012.11.18 13:40:22 | 003,674,983 | ---- | C] () -- C:\Users\Marek\Documents\[DM] LabiVila ft. Scar - Daylight.zip
[2012.11.18 13:40:20 | 005,684,146 | ---- | C] () -- C:\Users\Marek\Documents\[DM]ALV-8-AimAndWin.zip
[2012.11.18 13:40:19 | 002,558,370 | ---- | C] () -- C:\Users\Marek\Documents\[DM]ALV#4-MordeIsOP.zip
[2012.11.18 13:40:17 | 004,230,842 | ---- | C] () -- C:\Users\Marek\Documents\[DM]ALV #7 - Through the jungle II.zip
[2012.11.18 13:40:15 | 001,980,251 | ---- | C] () -- C:\Users\Marek\Documents\[DM]ALV #6-Through the jungle.zip
[2012.11.18 13:40:10 | 003,612,659 | ---- | C] () -- C:\Users\Marek\Documents\alv9.zip
[2012.11.18 10:35:41 | 000,002,149 | ---- | C] () -- C:\Users\Public\Desktop\Game Fire.lnk
[2012.11.17 12:47:27 | 000,000,963 | ---- | C] () -- C:\Users\Marek\Desktop\Game Hunter.lnk
[2012.11.04 17:33:20 | 000,579,274 | ---- | C] () -- C:\Users\Marek\AppData\Roaming\technic-launcher.jar
[2012.10.31 15:41:12 | 002,468,520 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2012.10.31 15:41:12 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2012.10.31 15:41:12 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2012.10.31 15:41:12 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2012.10.31 15:41:12 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2012.10.31 12:24:08 | 000,000,600 | ---- | C] () -- C:\Users\Marek\AppData\Local\PUTTY.RND
[2012.10.31 11:12:24 | 000,102,912 | ---- | C] () -- C:\Windows\EasyHook64.dll
[2012.10.31 11:12:24 | 000,087,040 | ---- | C] () -- C:\Windows\PersonalizeEnabler.exe
[2012.10.31 11:12:24 | 000,084,992 | ---- | C] () -- C:\Windows\SLCHook.dll
[2012.10.30 18:07:02 | 000,000,600 | ---- | C] () -- C:\Users\Marek\AppData\Roaming\winscp.rnd
[2012.10.30 17:01:31 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.07.26 09:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012.07.26 09:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012.07.26 08:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012.07.26 02:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012.07.26 01:48:53 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2012.07.25 21:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012.07.25 21:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012.07.04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.07.04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.06.02 15:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012.04.18 19:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2012.10.31 20:04:54 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.09.19 10:25:39 | 019,778,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.07.26 04:19:59 | 017,559,552 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012.11.14 17:55:30 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\.minecraft
[2012.11.04 20:59:08 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\.techniclauncher
[2012.11.21 17:39:42 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Claro
[2012.10.31 20:06:58 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Cobalt
[2012.11.01 18:40:24 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\DAEMON Tools Lite
[2012.11.15 20:21:28 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\EM-Creations
[2012.11.01 19:49:26 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio
[2012.11.08 20:54:07 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\gltechnic
[2012.11.04 20:58:49 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\logs
[2012.11.01 11:15:16 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Notepad++
[2012.11.21 17:56:18 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\systweak
[2012.10.31 11:20:19 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\TeamViewer
[2012.11.16 17:06:16 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Unity
[2012.11.24 12:12:33 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< >
[2012.07.26 08:22:10 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2012.10.30 18:12:23 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< MD5 for: ATAPI.SYS >
[2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\SysNative\drivers\atapi.sys
[2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_69660e2be041f47b\atapi.sys
[2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.2.9200.16384_none_3601cf7eab4e0493\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2012.07.26 04:08:17 | 000,887,296 | ---- | M] (Microsoft Corporation) MD5=490B7921C6DC58022FAA908E6310CF24 -- C:\Windows\SysNative\autochk.exe
[2012.07.26 04:08:17 | 000,887,296 | ---- | M] (Microsoft Corporation) MD5=490B7921C6DC58022FAA908E6310CF24 -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.2.9200.16384_none_3abd94ae4b8558e6\autochk.exe
[2012.07.26 04:20:43 | 000,792,064 | ---- | M] (Microsoft Corporation) MD5=55653D86D712641DB6930FAB64F452FF -- C:\Windows\SysWOW64\autochk.exe
[2012.07.26 04:20:43 | 000,792,064 | ---- | M] (Microsoft Corporation) MD5=55653D86D712641DB6930FAB64F452FF -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.2.9200.16384_none_de9ef92a9327e7b0\autochk.exe

< MD5 for: CDROM.SYS >
[2012.07.26 03:26:36 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=339BFF85D788268752DA8C9644B188EE -- C:\Windows\SysNative\drivers\cdrom.sys
[2012.07.26 03:26:36 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=339BFF85D788268752DA8C9644B188EE -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_cf04adb457be1724\cdrom.sys
[2012.07.26 03:26:36 | 000,174,080 | ---- | M] (Microsoft Corporation) MD5=339BFF85D788268752DA8C9644B188EE -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.2.9200.16384_none_b87303472d8ba041\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2012.07.26 04:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\SysWOW64\explorer.exe
[2012.07.26 04:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012.07.26 05:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\explorer.exe
[2012.07.26 05:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe

< MD5 for: HAL.DLL >
[2012.07.26 06:26:45 | 000,395,504 | ---- | M] (Microsoft Corporation) MD5=05CB11FF0DF114E05879CC0A3157004C -- C:\Windows\SysNative\hal.dll
[2012.07.26 06:26:45 | 000,395,504 | ---- | M] (Microsoft Corporation) MD5=05CB11FF0DF114E05879CC0A3157004C -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.2.9200.16384_none_03f29a08e36e6d4c\hal.dll

< MD5 for: SCECLI.DLL >
[2012.07.26 04:07:07 | 000,224,768 | ---- | M] (Microsoft Corporation) MD5=4F6E1CA672370A9BCAC049CE3AB7F666 -- C:\Windows\SysNative\scecli.dll
[2012.07.26 04:07:07 | 000,224,768 | ---- | M] (Microsoft Corporation) MD5=4F6E1CA672370A9BCAC049CE3AB7F666 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.2.9200.16384_none_90d789c062dfa509\scecli.dll
[2012.07.26 04:19:52 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=B95DC83FF580DD92F487C2F4D0854B6A -- C:\Windows\SysWOW64\scecli.dll
[2012.07.26 04:19:52 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=B95DC83FF580DD92F487C2F4D0854B6A -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.2.9200.16384_none_9b2c341297406704\scecli.dll

< MD5 for: SERVICES.EXE >
[2012.07.26 06:26:45 | 000,410,624 | ---- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 -- C:\Windows\SysNative\services.exe
[2012.07.26 06:26:45 | 000,410,624 | ---- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe

< MD5 for: SVCHOST.EXE >
[2012.07.26 04:20:58 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=0A175AF8B65797BD22C11903A8BFEB2D -- C:\Windows\SysWOW64\svchost.exe
[2012.07.26 04:20:58 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=0A175AF8B65797BD22C11903A8BFEB2D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_b2666581d6b482a6\svchost.exe
[2012.07.26 04:08:47 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=57350BEDE3834915B6145B67C71C7BDA -- C:\Windows\SysNative\svchost.exe
[2012.07.26 04:08:47 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=57350BEDE3834915B6145B67C71C7BDA -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_0e8501058f11f3dc\svchost.exe
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: TCPIP.SYS >
[2012.07.26 06:26:47 | 002,224,880 | ---- | M] (Microsoft Corporation) MD5=AF6A8D27FCABFF85DDC1D4599582B4FE -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.07.26 06:26:47 | 002,224,880 | ---- | M] (Microsoft Corporation) MD5=AF6A8D27FCABFF85DDC1D4599582B4FE -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16384_none_0be7b9b6f02a76ed\tcpip.sys

< MD5 for: USERINIT.EXE >
[2012.07.26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe
[2012.07.26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
[2012.07.26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe
[2012.07.26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012.07.26 04:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\SysNative\winlogon.exe
[2012.07.26 04:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe

< >

< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[6 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[36 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Panther\*.tmp files -> C:\Windows\Panther\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.11.14 17:55:30 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\.minecraft
[2012.11.04 20:59:08 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\.techniclauncher
[2012.11.21 18:04:50 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Adobe
[2012.10.30 19:47:47 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\ATI
[2012.11.21 17:39:42 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Claro
[2012.10.31 20:06:58 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Cobalt
[2012.11.01 18:40:24 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\DAEMON Tools Lite
[2012.11.15 20:21:28 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\EM-Creations
[2012.11.01 19:49:26 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio
[2012.11.08 20:54:07 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\gltechnic
[2012.11.03 15:05:26 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Google
[2012.11.04 20:58:49 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\logs
[2012.10.30 17:13:08 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Macromedia
[2012.11.23 21:23:41 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Malwarebytes
[2012.11.03 11:22:45 | 000,000,000 | --SD | M] -- C:\Users\Marek\AppData\Roaming\Microsoft
[2012.10.30 17:31:47 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Mozilla
[2012.11.01 11:15:16 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Notepad++
[2012.11.24 12:28:39 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Skype
[2012.11.21 17:56:18 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\systweak
[2012.10.31 11:20:19 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\TeamViewer
[2012.11.16 17:06:16 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Unity
[2012.11.24 12:27:48 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\uTorrent
[2012.10.30 17:55:36 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\Winamp
[2012.10.30 18:12:44 | 000,000,000 | ---D | M] -- C:\Users\Marek\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2012.11.04 14:58:30 | 000,354,816 | ---- | M] (FerdaSoft inc.) -- C:\Users\Marek\AppData\Roaming\mcupdater.exe
[2012.10.31 13:35:48 | 008,130,944 | ---- | M] (YoYo Games Ltd) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\5piceIDE.exe
[2012.10.31 14:18:41 | 012,312,576 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\ffmpeg.exe
[2012.10.31 14:18:41 | 000,110,976 | ---- | M] (YoYo Games Ltd.) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\GameMaker-Studio.exe
[2012.10.31 14:18:42 | 000,556,928 | ---- | M] (YoYo Games Ltd.) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\GMAssetCompiler.exe
[2012.10.31 14:18:46 | 002,918,784 | ---- | M] (YoYo Games Ltd. ) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\Runner.exe
[2012.10.31 14:18:45 | 000,496,128 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\makensis.exe
[2012.10.31 14:18:44 | 000,005,632 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\default.exe
[2012.10.31 14:18:44 | 000,006,144 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern.exe
[2012.10.31 14:18:44 | 000,004,096 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_headerbmp.exe
[2012.10.31 14:18:44 | 000,004,096 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_headerbmpr.exe
[2012.10.31 14:18:44 | 000,003,584 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_nodesc.exe
[2012.10.31 14:18:44 | 000,003,584 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_smalldesc.exe
[2012.10.31 14:18:44 | 000,006,144 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\sdbarker_tiny.exe
[2012.10.31 14:18:45 | 001,445,888 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\nginx-1.0.4\nginx.exe
[2012.10.31 14:18:45 | 000,372,224 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\OpenSSL\openssl.exe
[2012.10.31 14:18:45 | 000,303,104 | ---- | M] (Simon Tatham) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\putty\plink.exe
[2012.10.31 14:18:45 | 000,315,392 | ---- | M] (Simon Tatham) -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\putty\pscp.exe
[2012.10.31 14:18:55 | 000,013,312 | ---- | M] () -- C:\Users\Marek\AppData\Roaming\GameMaker-Studio\Windows8\LaunchMetroApp.exe
[2012.11.02 12:01:08 | 000,010,134 | R--- | M] () -- C:\Users\Marek\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2012.07.26 04:18:40 | 013,736,448 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2012.07.26 04:18:40 | 000,117,248 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\iepeers.dll

< %systemroot%\Tasks\*.job >
[2012.11.24 11:47:03 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >
[2012.07.26 04:18:40 | 013,736,448 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[2012.07.26 04:18:40 | 000,117,248 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\iepeers.dll

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.11.21 17:22:34 | 001,227,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dx8vb.dll

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Skype" = "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun -- [2012.10.19 16:38:46 | 017,884,848 | R--- | M] (Skype Technologies S.A.)
"uTorrent" = "D:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED -- [2012.10.31 13:29:41 | 000,963,984 | ---- | M] (BitTorrent, Inc.)
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.08.28 14:52:56 | 003,671,904 | ---- | M] (DT Soft Ltd)
"Sony PC Companion" = "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background -- [2012.09.12 12:17:12 | 000,445,624 | ---- | M] (Sony)
"Game Fire" = C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe /START -- [2011.12.02 05:13:00 | 000,044,032 | ---- | M] (Smart PC Utilities, Ltd.)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.10.24 18:49:10 | 000,917,984 | ---- | M] (Mozilla Corporation) MD5=E60E9D5F229CB8DA347D48ADD6E8DC47 -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.07.26 04:36:56 | 000,770,504 | ---- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.11.24 12:09:45 | 000,000,512 | ---- | M] () MD5=D7317F5FFA39213990C678EB551AF34F -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2012.11.18 19:33:30 | 000,055,716 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.3\mods\deathmatch\resources\Speedo\img\speed_crack.png
[2012.10.30 14:50:56 | 012,958,496 | ---- | M] () -- \ProgramData\BlueStacks\UserData\SharedFolder\NFS-MW-Cracked-by-RG-andropalace.net.apk
[2012.10.30 14:50:56 | 012,958,496 | ---- | M] () -- \Users\All Users\BlueStacks\UserData\SharedFolder\NFS-MW-Cracked-by-RG-andropalace.net.apk
[2012.11.18 17:15:37 | 000,000,698 | ---- | M] () -- \Users\Marek\AppData\Roaming\Microsoft\Windows\Recent\NFS-MW-Cracked-by-RG-andropalace.net.lnk
[2012.10.30 14:50:56 | 012,958,496 | ---- | M] () -- \Users\Marek\Desktop\NFS-MW-Cracked-by-RG-andropalace.net.apk
[2010.09.04 02:22:52 | 000,032,590 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - Advanced Installer 7.5.2 crk.xm
[2010.09.04 03:11:40 | 000,049,544 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - EmEditor 10.0.1 32-64 crk.xm
[2010.08.19 16:26:02 | 000,039,581 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - EmEditor 10.x 32-64 crk.xm
[2010.08.19 16:23:38 | 000,037,633 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - EmEditor 9.12 x32 crk.xm
[2011.06.20 23:47:22 | 000,172,768 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - Foxit Phantom 5.x x86 crk.s3m
[2010.09.26 15:53:50 | 000,022,716 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - PDF-Xchange Viewer 2.0.52 crk.xm
[2010.06.01 23:44:04 | 000,038,854 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - Revo Uninstaller Pro 2.1.5.0crk.xm
[2011.02.23 23:19:42 | 000,068,340 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - WinRAR 4.00beta5 crk.xm
[2011.01.09 19:51:42 | 000,016,832 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ADMINCRACK - xrecode II 1.0.0.1xx crk.xm
[2010.12.10 01:35:14 | 000,011,750 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\AT4RE - Armor Tools 7.2 crack.mod
[2010.10.28 00:27:38 | 000,019,496 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\DCrack - LingvoSoft 2008 English-Polish crk.mod
[2005.07.09 12:50:28 | 000,007,415 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - Alcohol 120% 1.9.2.1705 Crack.xm
[2006.03.23 01:21:50 | 000,012,715 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - BlindWrite Suite 5.2.16.154 - CRACK.xm
[2004.11.08 17:49:52 | 000,056,989 | R--- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - PainKiller cracktro.xm
[2006.12.26 16:40:18 | 000,047,826 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - TuneUp Utilities 2006 5.0.2331 crack.mod
[2007.06.20 17:23:16 | 000,025,740 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ICU - CrackMe v0.2.xm
[2011.03.16 22:51:14 | 000,164,552 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\IREC - Rar Password Cracker 4.12 crk.mod
[2006.03.22 13:11:22 | 000,020,956 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\LaFarge - crackme2.xm
[2006.06.02 12:38:06 | 000,003,406 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Lazzy - CrackMe#1.xm
[2010.08.20 20:13:32 | 000,014,993 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\MTCT - PDF Password Cracker Enterprise 3.2 kg.XM
[2011.03.13 22:23:06 | 000,005,481 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\NAPALM - Virtua Fighter crack.amd
[2010.11.08 02:03:30 | 000,019,055 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\PIONEER - PDF Password Cracker 2.0 crk.xm
[2004.11.08 18:09:20 | 000,011,008 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\PRESTiGE - Diablo II Cracktro.mod
[2005.07.19 01:20:38 | 000,041,995 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Razor1911 - Half-Life Blue Shift Cracktro.xm
[2011.03.19 14:16:36 | 000,049,176 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\RobotCracker - Amadis Video Converter Suite 3.7.9 crk.mod
[2010.10.26 00:29:18 | 000,020,242 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\RobotCracker - ISOMagic 5.0.8.0609 crk.xm
[2006.12.26 16:29:08 | 000,024,324 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\SnD - IncrediMail for Office Generic Crack 1.5.xm
[2008.07.31 09:51:42 | 000,075,678 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\SnD - MD5 Crack Fast 1.0kg.xm
[2006.06.02 12:40:12 | 000,030,483 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\SnD - PE Explorer & Resource Tuner v1.9x Crack 1.01.xm
[2009.03.31 15:02:14 | 000,195,974 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\SoS - Crackme25.XM
[2005.07.10 21:08:00 | 000,029,652 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Team.Lucid.Cracktro.xm
[2006.10.02 23:26:10 | 000,105,047 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TLG - Alawar Crack+keyfinder.xm
[2007.08.06 20:56:56 | 000,059,485 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TLG - Alawar Games UniCrack v0.5.v2m
[2007.09.25 20:17:52 | 000,122,513 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TLG - Alawar Universal Crack v0.4.1.XM
[2006.04.24 14:19:04 | 000,039,081 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - AVD Volume Calculator 5.0 crack.IT
[2006.04.13 18:54:26 | 000,038,002 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - Easy File & Folder Protector 4.1crack.MOD
[2006.04.15 18:17:34 | 000,008,742 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - GlowingWorld screensaver 3.0 crack.XM
[2006.04.28 13:21:36 | 000,038,194 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - ReGet Deluxe 4.2crack.it
[2006.04.29 00:50:40 | 000,083,103 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - WinTools.net Professional 6.5.1crack.v2m
[2005.07.12 19:58:38 | 000,043,029 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TSRh - bitdefender.professional.edition.7.2.silent.update.crack.xm
[2002.05.20 11:48:18 | 000,099,980 | ---- | M] () -- \Windows\Fonts\crackdr2.ttf
[1998.12.07 14:45:08 | 000,034,348 | ---- | M] () -- \Windows\Fonts\CRACKMAN.TTF

< *keygen* /s >
[2012.08.06 17:33:15 | 000,002,272 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\security\spec\RSAKeyGenParameterSpec.java
[2012.08.06 17:33:09 | 000,008,568 | R--- | M] () -- \Android\android-sdk\sources\android-15\javax\crypto\KeyGenerator.java
[2012.08.06 17:33:09 | 000,002,696 | R--- | M] () -- \Android\android-sdk\sources\android-15\javax\crypto\KeyGeneratorSpi.java
[2012.08.06 17:33:19 | 000,003,182 | R--- | M] () -- \Android\android-sdk\sources\android-15\org\apache\harmony\crypto\tests\javax\crypto\KeyGeneratorSpiTest.java
[2012.08.06 17:33:09 | 000,019,346 | R--- | M] () -- \Android\android-sdk\sources\android-15\org\apache\harmony\crypto\tests\javax\crypto\KeyGeneratorTest.java
[2012.08.06 17:33:10 | 000,001,240 | R--- | M] () -- \Android\android-sdk\sources\android-15\org\apache\harmony\crypto\tests\javax\crypto\func\KeyGeneratorFunctionalTest.java
[2012.08.06 17:33:09 | 000,002,357 | R--- | M] () -- \Android\android-sdk\sources\android-15\org\apache\harmony\crypto\tests\javax\crypto\func\KeyGeneratorThread.java
[2012.08.06 17:33:15 | 000,001,990 | R--- | M] () -- \Android\android-sdk\sources\android-15\org\apache\harmony\crypto\tests\support\MyKeyGeneratorSpi.java
[2010.03.27 14:32:28 | 000,003,248 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIKeygenThread.idl
[2010.03.27 14:32:56 | 000,004,618 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIKeygenThread.h
[2012.11.20 20:25:12 | 000,000,625 | ---- | M] () -- \Users\Marek\AppData\Roaming\Microsoft\Windows\Recent\2500KeygenMusicPack.lnk
[2012.11.03 14:59:35 | 000,000,641 | ---- | M] () -- \Users\Marek\AppData\Roaming\Microsoft\Windows\Recent\Google.Sketchup.Pro.v8.0.3117.Incl.Keygen-MESMERiZE.lnk
[2012.11.20 20:25:12 | 132,218,925 | ---- | M] () -- \Users\Marek\Downloads\2500KeygenMusicPack.zip
[2006.03.12 17:33:28 | 000,029,483 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\AGRESSION - SuperRam v5.12.5.2005 keygen.xm
[2006.04.09 21:47:36 | 000,018,790 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Blizzard - 1Click DVDCopy 4.1.1.4 keygen.xm
[2008.02.07 09:34:52 | 000,018,284 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\BRD - RinjaniSoft Products Universal keygen v1.1.xm
[2009.11.30 13:45:56 | 000,113,336 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\CORE - Adobe All Products MacOSX keygenv1.1.MOD
[2006.07.15 11:19:10 | 000,050,786 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\CORE - Ashampoo UnInstaller Suite 1.3 keygen.xm
[2005.07.07 13:14:24 | 000,023,553 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\CORE - BoostSpeed3.0.2.451Keygen.xm
[2005.07.07 13:14:24 | 000,026,104 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Eclipse - DivxPro5.03keygen.xm
[2005.07.16 22:14:46 | 000,031,072 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_1).mod
[2005.07.16 22:14:46 | 000,021,792 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_2).mod
[2005.07.16 22:14:46 | 000,014,550 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_3).mod
[2005.07.16 22:14:46 | 000,011,430 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_4).mod
[2005.07.16 22:14:46 | 000,017,968 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_5).mod
[2005.07.16 22:14:46 | 000,019,244 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Epsilon.Business.Music.System.v.2.05.Keygen.(Music_6).mod
[2006.04.09 21:47:34 | 000,028,659 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - All DVDIdle Products - Feb. 2005 keygen.xm
[2007.02.25 17:13:44 | 000,090,349 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FFF - EA Games Multikeygen 140.XM
[2007.05.15 21:20:40 | 000,029,507 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Flash of Lightning - HAANDI's multikeygen.mid
[2007.10.12 20:53:32 | 000,299,025 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Lz0 - Universal Reflexive DRM keygen v1.1.xm
[2005.07.09 12:53:46 | 000,009,716 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\N-Gen - UltraFractal.3.0.Keygen.xm
[2006.04.10 00:29:32 | 000,022,934 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\PARADOX - nVidia DVD Decoder 1.00.58 keygen.xm
[2006.03.30 21:05:40 | 000,087,456 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\SND - Nero v7 - All Product Keygen v1.0.xm
[2008.02.10 19:01:42 | 000,021,892 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - Multikeygen for Godlike Developers.XM
[2006.04.28 13:18:30 | 000,006,090 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - PrinterExpress 1.25 keygen.xm
[2006.04.14 21:20:42 | 000,068,890 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TSRh - Slide Show to Go 8.3.0.19 keygen.xm

< *loader* /s >
[2012.11.15 19:50:51 | 000,705,024 | ---- | M] () -- \$Recycle.Bin\S-1-5-21-2331816091-2394518104-2338911075-1001\$RF7TG43.rar_tmp__bak_\MTA\loader.dll
[2012.09.24 18:28:10 | 000,705,024 | ---- | M] () -- \$Recycle.Bin\S-1-5-21-2331816091-2394518104-2338911075-1001\$RLSOBNQ.rar_tmp_\MTA\loader.dll
[2011.09.09 10:04:28 | 000,075,104 | ---- | M] () -- \3D Rad\PhysXLoader.dll
[2012.08.06 17:16:22 | 000,000,679 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw\loaderror.html
[2012.08.06 17:16:14 | 000,000,659 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-ar\loaderror.html
[2012.08.06 17:15:16 | 000,000,682 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-cs\loaderror.html
[2012.08.06 17:16:10 | 000,000,612 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-da\loaderror.html
[2012.08.06 17:16:26 | 000,000,605 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-de\loaderror.html
[2012.08.06 17:15:16 | 000,000,579 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-en-rGB\loaderror.html
[2012.08.06 17:16:25 | 000,000,607 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-es\loaderror.html
[2012.08.06 17:16:13 | 000,000,633 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-fi\loaderror.html
[2012.08.06 17:16:23 | 000,000,613 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-fr\loaderror.html
[2012.08.06 17:16:15 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-hu\loaderror.html
[2012.08.06 17:16:27 | 000,000,622 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-it\loaderror.html
[2012.08.06 17:16:26 | 000,000,654 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-iw\loaderror.html
[2012.08.06 17:16:22 | 000,000,656 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-ja\loaderror.html
[2012.08.06 17:16:21 | 000,000,648 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-ko\loaderror.html
[2012.08.06 17:16:11 | 000,000,592 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-nl\loaderror.html
[2012.08.06 17:16:09 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-pl\loaderror.html
[2012.08.06 17:16:22 | 000,000,676 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-pt-rBR\loaderror.html
[2012.08.06 17:16:02 | 000,000,617 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-rm\loaderror.html
[2012.08.06 17:16:18 | 000,000,705 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-ru\loaderror.html
[2012.08.06 17:16:20 | 000,000,678 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-th\loaderror.html
[2012.08.06 17:15:16 | 000,000,570 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-tr\loaderror.html
[2012.08.06 17:16:20 | 000,000,556 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-zh-rCN\loaderror.html
[2012.08.06 17:16:15 | 000,000,635 | ---- | M] () -- \Android\android-sdk\platforms\android-11\data\res\raw-zh-rTW\loaderror.html
[2012.08.07 17:27:56 | 000,000,679 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw\loaderror.html
[2012.08.07 17:27:46 | 000,000,659 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-ar\loaderror.html
[2012.08.07 17:27:56 | 000,000,682 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-cs\loaderror.html
[2012.08.07 17:27:58 | 000,000,612 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-da\loaderror.html
[2012.08.07 17:27:52 | 000,000,605 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-de\loaderror.html
[2012.08.07 17:27:56 | 000,000,579 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-en-rGB\loaderror.html
[2012.08.07 17:27:53 | 000,000,607 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-es\loaderror.html
[2012.08.07 17:27:57 | 000,000,633 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-fi\loaderror.html
[2012.08.07 17:27:48 | 000,000,613 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-fr\loaderror.html
[2012.08.07 17:27:50 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-hu\loaderror.html
[2012.08.07 17:27:57 | 000,000,622 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-it\loaderror.html
[2012.08.07 17:27:56 | 000,000,654 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-iw\loaderror.html
[2012.08.07 17:27:46 | 000,000,656 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-ja\loaderror.html
[2012.08.07 17:27:53 | 000,000,648 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-ko\loaderror.html
[2012.08.07 17:27:54 | 000,000,592 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-nl\loaderror.html
[2012.08.07 17:27:57 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-pl\loaderror.html
[2012.08.07 17:28:13 | 000,000,676 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-pt-rBR\loaderror.html
[2012.08.07 17:28:13 | 000,000,617 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-rm\loaderror.html
[2012.08.07 17:28:11 | 000,000,705 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-ru\loaderror.html
[2012.08.07 17:27:48 | 000,000,678 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-th\loaderror.html
[2012.08.07 17:27:56 | 000,000,570 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-tr\loaderror.html
[2012.08.07 17:28:09 | 000,000,556 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-zh-rCN\loaderror.html
[2012.08.07 17:27:52 | 000,000,635 | ---- | M] () -- \Android\android-sdk\platforms\android-13\data\res\raw-zh-rTW\loaderror.html
[2012.08.06 17:05:52 | 000,000,679 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw\loaderror.html
[2012.08.06 17:05:42 | 000,000,659 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-ar\loaderror.html
[2012.08.06 17:05:45 | 000,000,682 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-cs\loaderror.html
[2012.08.06 17:05:52 | 000,000,612 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-da\loaderror.html
[2012.08.06 17:05:51 | 000,000,605 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-de\loaderror.html
[2012.08.06 17:05:50 | 000,000,579 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-en-rGB\loaderror.html
[2012.08.06 17:05:51 | 000,000,607 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-es\loaderror.html
[2012.08.06 17:05:47 | 000,000,633 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-fi\loaderror.html
[2012.08.06 17:05:50 | 000,000,613 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-fr\loaderror.html
[2012.08.06 17:05:43 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-hu\loaderror.html
[2012.08.06 17:05:45 | 000,000,622 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-it\loaderror.html
[2012.08.06 17:05:48 | 000,000,654 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-iw\loaderror.html
[2012.08.06 17:05:47 | 000,000,656 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-ja\loaderror.html
[2012.08.06 17:05:44 | 000,000,648 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-ko\loaderror.html
[2012.08.06 17:05:43 | 000,000,592 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-nl\loaderror.html
[2012.08.06 17:05:49 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-pl\loaderror.html
[2012.08.06 17:05:50 | 000,000,676 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-pt-rBR\loaderror.html
[2012.08.06 17:05:51 | 000,000,617 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-rm\loaderror.html
[2012.08.06 17:05:47 | 000,000,705 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-ru\loaderror.html
[2012.08.06 17:05:52 | 000,000,678 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-th\loaderror.html
[2012.08.06 17:05:50 | 000,000,570 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-tr\loaderror.html
[2012.08.06 17:05:44 | 000,000,556 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-zh-rCN\loaderror.html
[2012.08.06 17:05:52 | 000,000,635 | ---- | M] () -- \Android\android-sdk\platforms\android-15\data\res\raw-zh-rTW\loaderror.html
[2012.08.06 17:28:24 | 000,000,677 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw\loaderror.html
[2012.08.06 17:28:19 | 000,000,643 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-ar\loaderror.html
[2012.08.06 17:28:26 | 000,000,682 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-cs\loaderror.html
[2012.08.06 17:28:25 | 000,000,612 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-da\loaderror.html
[2012.08.06 17:28:23 | 000,000,605 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-de\loaderror.html
[2012.08.06 17:28:24 | 000,000,579 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-en-rGB\loaderror.html
[2012.08.06 17:28:19 | 000,000,607 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-es\loaderror.html
[2012.08.06 17:28:27 | 000,000,633 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-fi\loaderror.html
[2012.08.06 17:28:25 | 000,000,613 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-fr\loaderror.html
[2012.08.06 17:28:26 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-hu\loaderror.html
[2012.08.06 17:28:19 | 000,000,622 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-it\loaderror.html
[2012.08.06 17:28:24 | 000,000,638 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-iw\loaderror.html
[2012.08.06 17:28:26 | 000,000,656 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-ja\loaderror.html
[2012.08.06 17:28:19 | 000,000,648 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-ko\loaderror.html
[2012.08.06 17:28:23 | 000,000,592 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-nl\loaderror.html
[2012.08.06 17:28:23 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-pl\loaderror.html
[2012.08.06 17:28:19 | 000,000,676 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-pt-rBR\loaderror.html
[2012.08.06 17:28:26 | 000,000,705 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-ru\loaderror.html
[2012.08.06 17:28:24 | 000,000,678 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-th\loaderror.html
[2012.08.06 17:28:22 | 000,000,570 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-tr\loaderror.html
[2012.08.06 17:28:26 | 000,000,556 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-zh-rCN\loaderror.html
[2012.08.06 17:28:24 | 000,000,635 | ---- | M] () -- \Android\android-sdk\platforms\android-7\data\res\raw-zh-rTW\loaderror.html
[2012.08.06 17:22:03 | 000,000,677 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw\loaderror.html
[2012.08.06 17:22:11 | 000,000,643 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-ar\loaderror.html
[2012.08.06 17:22:03 | 000,000,682 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-cs\loaderror.html
[2012.08.06 17:22:12 | 000,000,612 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-da\loaderror.html
[2012.08.06 17:22:10 | 000,000,605 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-de\loaderror.html
[2012.08.06 17:22:12 | 000,000,579 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-en-rGB\loaderror.html
[2012.08.06 17:22:03 | 000,000,607 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-es\loaderror.html
[2012.08.06 17:22:03 | 000,000,633 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-fi\loaderror.html
[2012.08.06 17:22:11 | 000,000,613 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-fr\loaderror.html
[2012.08.06 17:22:13 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-hu\loaderror.html
[2012.08.06 17:22:03 | 000,000,622 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-it\loaderror.html
[2012.08.06 17:22:03 | 000,000,638 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-iw\loaderror.html
[2012.08.06 17:22:09 | 000,000,656 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-ja\loaderror.html
[2012.08.06 17:22:02 | 000,000,648 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-ko\loaderror.html
[2012.08.06 17:22:09 | 000,000,592 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-nl\loaderror.html
[2012.08.06 17:22:03 | 000,000,628 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-pl\loaderror.html
[2012.08.06 17:22:10 | 000,000,676 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-pt-rBR\loaderror.html
[2012.08.06 17:22:11 | 000,000,705 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-ru\loaderror.html
[2012.08.06 17:22:04 | 000,000,678 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-th\loaderror.html
[2012.08.06 17:22:11 | 000,000,570 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-tr\loaderror.html
[2012.08.06 17:22:03 | 000,000,556 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-zh-rCN\loaderror.html
[2012.08.06 17:22:12 | 000,000,635 | ---- | M] () -- \Android\android-sdk\platforms\android-8\data\res\raw-zh-rTW\loaderror.html
[2012.08.06 17:30:46 | 000,006,648 | R--- | M] () -- \Android\android-sdk\samples\android-11\ApiDemos\src\com\example\android\apis\app\FragmentListCursorLoader.java
[2012.08.06 17:30:49 | 000,018,802 | R--- | M] () -- \Android\android-sdk\samples\android-11\ApiDemos\src\com\example\android\apis\app\LoaderThrottle.java
[2012.08.06 17:30:46 | 000,013,960 | R--- | M] () -- \Android\android-sdk\samples\android-11\XmlAdapters\src\com\example\android\xmladapters\ImageDownloader.java
[2012.08.07 17:29:10 | 000,006,874 | R--- | M] () -- \Android\android-sdk\samples\android-13\ApiDemos\src\com\example\android\apis\app\LoaderCursor.java
[2012.08.07 17:29:12 | 000,017,034 | R--- | M] () -- \Android\android-sdk\samples\android-13\ApiDemos\src\com\example\android\apis\app\LoaderCustom.java
[2012.08.07 17:29:08 | 000,019,083 | R--- | M] () -- \Android\android-sdk\samples\android-13\ApiDemos\src\com\example\android\apis\app\LoaderThrottle.java
[2012.08.07 17:29:11 | 000,013,960 | R--- | M] () -- \Android\android-sdk\samples\android-13\XmlAdapters\src\com\example\android\xmladapters\ImageDownloader.java
[2012.08.06 17:29:51 | 000,006,874 | R--- | M] () -- \Android\android-sdk\samples\android-15\ApiDemos\src\com\example\android\apis\app\LoaderCursor.java
[2012.08.06 17:29:50 | 000,017,034 | R--- | M] () -- \Android\android-sdk\samples\android-15\ApiDemos\src\com\example\android\apis\app\LoaderCustom.java
[2012.08.06 17:29:51 | 000,019,083 | R--- | M] () -- \Android\android-sdk\samples\android-15\ApiDemos\src\com\example\android\apis\app\LoaderThrottle.java
[2012.08.06 17:29:51 | 000,014,054 | R--- | M] () -- \Android\android-sdk\samples\android-15\XmlAdapters\src\com\example\android\xmladapters\ImageDownloader.java
[2012.08.06 17:33:17 | 000,002,335 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\app\ApplicationLoaders.java
[2012.08.06 17:33:09 | 000,035,496 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\app\LoaderManager.java
[2012.08.06 17:33:13 | 000,010,942 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\content\AsyncTaskLoader.java
[2012.08.06 17:33:13 | 000,006,955 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\content\CursorLoader.java
[2012.08.06 17:33:12 | 000,015,862 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\content\Loader.java
[2012.08.06 17:33:24 | 000,011,876 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\core\ClassLoaderTest.java
[2012.08.06 17:33:24 | 000,034,727 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\support\v4\app\LoaderManager.java
[2012.08.06 17:33:13 | 000,010,356 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\support\v4\content\AsyncTaskLoader.java
[2012.08.06 17:33:24 | 000,006,561 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\support\v4\content\CursorLoader.java
[2012.08.06 17:33:24 | 000,013,444 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\support\v4\content\Loader.java
[2012.08.06 17:33:12 | 000,003,941 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\test\LoaderTestCase.java
[2012.08.06 17:33:15 | 000,002,639 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\CacheLoader.java
[2012.08.06 17:33:15 | 000,003,264 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\ContentLoader.java
[2012.08.06 17:33:16 | 000,002,494 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\DataLoader.java
[2012.08.06 17:33:16 | 000,007,788 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\FileLoader.java
[2012.08.06 17:33:24 | 000,016,709 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\FrameLoader.java
[2012.08.06 17:33:14 | 000,007,226 | R--- | M] () -- \Android\android-sdk\sources\android-15\android\webkit\StreamLoader.java
[2012.08.06 17:33:13 | 000,003,894 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\dumprendertree2\TestsListPreloaderThread.java
[2012.08.06 17:33:11 | 000,009,796 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\internal\telephony\AdnRecordLoader.java
[2012.08.06 17:33:08 | 000,011,868 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\internal\telephony\cat\IconLoader.java
[2012.08.06 17:33:13 | 000,013,896 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\layoutlib\bridge\impl\FontLoader.java
[2012.08.06 17:33:14 | 000,005,917 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\server\location\GpsXtraDownloader.java
[2012.08.06 17:33:20 | 000,012,748 | R--- | M] () -- \Android\android-sdk\sources\android-15\com\android\systemui\recent\RecentTasksLoader.java
[2012.08.06 17:33:14 | 000,030,125 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\lang\ClassLoader.java
[2012.08.06 17:33:17 | 000,003,058 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\lang\VMClassLoader.java
[2012.08.06 17:33:22 | 000,037,216 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\net\URLClassLoader.java
[2012.08.06 17:33:13 | 000,005,549 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\security\SecureClassLoader.java
[2012.08.06 17:33:22 | 000,009,736 | R--- | M] () -- \Android\android-sdk\sources\android-15\java\util\ServiceLoader.java
[2012.08.06 17:33:08 | 000,001,291 | R--- | M] () -- \Android\android-sdk\sources\android-15\javax\xml\validation\SchemaFactoryLoader.java
[2012.08.06 17:33:23 | 000,000,539 | R--- | M] () -- \Android\android-sdk\sources\android-15\junit\runner\ReloadingTestSuiteLoader.java
[2012.08.06 17:33:22 | 000,000,544 | R--- | M] () -- \Android\android-sdk\sources\android-15\junit\runner\StandardTestSuiteLoader.java
[2012.08.06 17:33:24 | 000,005,610 | R--- | M] () -- \Android\android-sdk\sources\android-15\junit\runner\TestCaseClassLoader.java
[2012.08.06 17:33:21 | 000,000,286 | R--- | M] () -- \Android\android-sdk\sources\android-15\junit\runner\TestSuiteLoader.java
[2010.03.05 11:48:54 | 000,299,216 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_BinaryLoader_r.4.2.2.319.dll
[2010.03.05 11:48:56 | 000,540,880 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader2_r.4.2.2.319.dll
[2010.03.05 11:49:00 | 000,491,728 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader_r.4.2.2.319.dll
[2010.03.27 14:32:10 | 000,009,728 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\TestStreamLoader.exe
[2010.03.27 14:32:12 | 000,002,713 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\components\uriloader.xpt
[2010.03.27 14:32:10 | 000,026,243 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\chrome\pageloader.jar
[2010.03.27 14:32:10 | 000,000,049 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\bin\chrome\pageloader.manifest
[2010.03.27 14:32:18 | 000,005,128 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\imgILoader.idl
[2010.03.27 14:32:18 | 000,002,605 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\mozIJSSubScriptLoader.idl
[2010.03.27 14:32:18 | 000,003,317 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsCURILoader.idl
[2010.03.27 14:32:26 | 000,002,858 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDocumentLoader.idl
[2010.03.27 14:32:26 | 000,003,462 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDocumentLoaderFactory.idl
[2010.03.27 14:32:26 | 000,003,603 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIDownloader.idl
[2010.03.27 14:32:28 | 000,003,715 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIFrameLoader.idl
[2010.03.27 14:32:30 | 000,002,777 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIModuleLoader.idl
[2010.03.27 14:32:32 | 000,003,452 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIScriptLoaderObserver.idl
[2010.03.27 14:32:32 | 000,004,284 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIStreamLoader.idl
[2010.03.27 14:32:34 | 000,005,092 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIUnicharStreamLoader.idl
[2010.03.27 14:32:34 | 000,007,667 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIURILoader.idl
[2010.03.27 14:32:36 | 000,003,926 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\nsIXPTLoader.idl
[2010.03.27 14:32:36 | 000,004,183 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\idl\xpcIJSModuleLoader.idl
[2010.03.27 14:32:38 | 000,009,035 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\imgILoader.h
[2010.03.27 14:32:40 | 000,003,070 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\mozIJSSubScriptLoader.h
[2010.03.27 14:32:42 | 000,001,749 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsCURILoader.h
[2010.03.27 14:32:42 | 000,010,911 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsDocLoader.h
[2010.03.27 14:32:46 | 000,013,419 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsICSSLoader.h
[2010.03.27 14:32:46 | 000,003,426 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsICSSLoaderObserver.h
[2010.03.27 14:32:54 | 000,004,904 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDocumentLoader.h
[2010.03.27 14:32:54 | 000,007,766 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDocumentLoaderFactory.h
[2010.03.27 14:32:54 | 000,006,884 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIDownloader.h
[2010.03.27 14:32:56 | 000,008,783 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIFrameLoader.h
[2010.03.27 14:32:58 | 000,003,586 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIModuleLoader.h
[2010.03.27 14:33:02 | 000,005,474 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIScriptLoaderObserver.h
[2010.03.27 14:33:02 | 000,008,712 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIStreamLoader.h
[2010.03.27 14:33:04 | 000,011,248 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIUnicharStreamLoader.h
[2010.03.27 14:33:04 | 000,011,837 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIURILoader.h
[2010.03.27 14:33:06 | 000,007,515 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsIXPTLoader.h
[2010.03.27 14:33:08 | 000,011,156 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsScriptLoader.h
[2010.03.27 14:33:08 | 000,004,155 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\nsURILoader.h
[2010.03.27 14:33:12 | 000,005,504 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Adobe Contribute CS5\App\Configuration\Browsers\Mozilla Run Time Libraries\dist\include\xpcIJSModuleLoader.h
[2012.07.26 19:08:06 | 000,102,864 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\coloader80.dll
[2012.07.26 13:20:02 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\coloader80.tlb
[2012.04.10 17:58:58 | 000,268,368 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2012.04.10 17:58:58 | 000,019,024 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2012.06.07 14:43:34 | 000,007,825 | ---- | M] () -- \Program Files (x86)\Microsoft ASP.NET\ASP.NET MVC 4\Packages\jquery.mobile.1.1.0.1\content\Content\images\ajax-loader.gif
[2012.06.07 14:43:34 | 000,000,340 | ---- | M] () -- \Program Files (x86)\Microsoft ASP.NET\ASP.NET MVC 4\Packages\jquery.mobile.1.1.0.1\content\Content\images\ajax-loader.png
[2009.07.22 09:17:52 | 000,019,992 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2012.07.10 14:38:22 | 000,015,472 | ---- | M] () -- \Program Files (x86)\Microsoft Web Tools\Page Inspector\Microsoft.VisualStudio.Web.PageInspector.Loader.dll
[2012.11.15 19:50:51 | 000,705,024 | ---- | M] () -- \Program Files (x86)\MTA San Andreas 1.3\MTA\loader.dll
[2011.07.18 22:33:32 | 000,008,787 | ---- | M] () -- \Program Files (x86)\Notepad++\user.manual\sites\all\modules\fancy_login\images\ajax-loader.gif
[2012.07.25 13:12:10 | 000,013,831 | ---- | M] () -- \Program Files (x86)\Windows Kits\8.0\Include\um\libloaderapi.h
[2012.07.25 18:46:28 | 000,211,456 | ---- | M] () -- \Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Te.Loaders.dll
[2012.07.25 18:46:28 | 000,211,456 | ---- | M] () -- \Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\x64\Te.Loaders.dll
[2010.03.05 05:55:00 | 000,488,144 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_BinaryLoader_r.4.2.2.319.dll
[2010.03.05 05:55:04 | 000,900,304 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader2_r.4.2.2.319.dll
[2010.03.05 05:55:08 | 000,789,200 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS5\MXF_SDK_MetaMetadata_XSDLoader_r.4.2.2.319.dll
[2012.04.10 17:58:58 | 000,364,112 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2012.04.10 17:58:58 | 000,019,024 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2012.11.01 19:36:34 | 000,000,948 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2012.11.01 19:36:34 | 000,000,411 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2012.11.01 19:36:35 | 001,170,520 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\modules\org-openide-loaders.jar
[2012.11.01 19:36:35 | 000,006,244 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2012.11.01 19:36:35 | 000,005,873 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2012.11.01 19:36:36 | 000,000,457 | ---- | M] () -- \Program Files\Java\jdk1.7.0_09\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2009.07.22 09:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2009.07.22 09:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SqlResourceLoader.dll
[2012.07.26 11:34:00 | 000,039,485 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.Bing_1.2.0.137_x64__8wekyb3d8bbwe\shell\js\backgroundImageLoader.js
[2012.07.26 11:33:02 | 000,002,809 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\DependencyLoader\DependencyLoader.js
[2012.07.26 11:33:02 | 000,001,583 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernAttachmentWell\AttachmentWellComposeDependencyLoader.js
[2012.07.26 11:33:02 | 000,001,711 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernAttachmentWell\AttachmentWellReadDependencyLoader.js
[2012.07.26 11:33:02 | 000,002,509 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernAttachmentWell\AttachmentWellShareAnythingControlDependencyLoader.js
[2012.07.26 11:33:02 | 000,002,394 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernPeople\appframe\BackgroundLoader.js
[2012.07.26 11:33:03 | 000,005,028 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernShareAnything\ShareDataLoader.js
[2012.07.26 11:33:58 | 000,049,108 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.XboxLIVEGames_1.0.927.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2012.07.26 11:33:36 | 000,049,108 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.ZuneMusic_1.0.927.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2012.10.31 17:21:36 | 000,054,797 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.ZuneMusic_1.1.134.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2012.10.31 17:21:36 | 000,054,797 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.ZuneMusic_1.1.137.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2012.07.26 11:33:43 | 000,049,108 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.ZuneVideo_1.0.927.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2012.02.17 20:55:10 | 000,055,296 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2012.10.19 15:48:08 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.10.19 15:48:08 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.10.19 15:48:08 | 000,009,772 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\retina\loader@2x.png
[2012.10.19 15:48:08 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.10.19 15:48:08 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.10.19 15:48:08 | 000,009,772 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\retina\loader@2x.png
[2012.11.21 17:38:27 | 000,000,404 | ---- | M] () -- \Users\Marek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9W0P956M\downloader[1].htm
[2012.10.30 21:13:16 | 000,105,903 | ---- | M] () -- \Users\Marek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ACICDGGK\AdLoader-427d9fd2a91e2f2c023aefe9f69a01d0.min[1].js
[2012.11.21 17:38:32 | 000,001,962 | ---- | M] () -- \Users\Marek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DND1N9ZH\downloader[1].htm
[2012.10.30 21:13:16 | 000,000,753 | ---- | M] () -- \Users\Marek\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GP4ZZDJ5\AdLoader[1].htm
[2012.11.04 21:28:47 | 000,064,896 | ---- | M] () -- \Users\Marek\AppData\Roaming\.techniclauncher\tekkit\ForgeModLoader-0.log
[2012.11.04 20:06:59 | 000,064,482 | ---- | M] () -- \Users\Marek\AppData\Roaming\.techniclauncher\tekkit\ForgeModLoader-1.log
[2012.11.04 17:39:34 | 000,062,576 | ---- | M] () -- \Users\Marek\AppData\Roaming\.techniclauncher\tekkit\ForgeModLoader-2.log
[2012.11.04 17:36:08 | 000,001,980 | ---- | M] () -- \Users\Marek\AppData\Roaming\.techniclauncher\tekkit\mods\ComputerCraft\org\luaj\vm2\luajc\JavaLoader.class
[2012.10.31 14:18:20 | 000,072,156 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\AntClassLoader.html
[2012.10.31 14:18:21 | 000,016,505 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\loader\AntClassLoader2.html
[2012.10.31 14:18:21 | 000,019,956 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\loader\AntClassLoader5.html
[2012.10.31 14:18:21 | 000,026,318 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\taskdefs\Classloader.html
[2012.10.31 14:18:26 | 000,010,607 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\types\resources\AbstractClasspathResource.ClassLoaderWithFlag.html
[2012.10.31 14:18:27 | 000,016,191 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\util\LoaderUtils.html
[2012.10.31 14:18:28 | 000,020,098 | ---- | M] () -- \Users\Marek\AppData\Roaming\GameMaker-Studio\Android\apache-ant-1.8.2\docs\manual\api\org\apache\tools\ant\util\SplitClassLoader.html
[2011.09.09 10:04:28 | 000,075,104 | ---- | M] () -- \Users\Marek\Desktop\RacinGame_20121102194529\PhysXLoader.dll
[2010.10.27 22:53:58 | 000,815,245 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\FOFF - Hulu Downloader 2.33 kg.xm
[2005.06.26 11:08:50 | 000,031,233 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\ORiON - MassDownloader2.4.295SR1kg.xm
[2010.11.19 00:44:34 | 000,027,681 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\TLG - Pica Loader 1.6.6 kg.xm
[2007.10.17 17:56:10 | 000,002,982 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - Amor Photo Downloader 1.4crk.XM
[2007.08.19 18:38:00 | 000,016,881 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - MetaProducts Mass Downloader 3.3.691 SR1kg.v2m
[2007.10.10 22:14:52 | 000,025,047 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\tPORt - MetaProducts Picture Downloader 1.0.589kg.v2m
[2010.09.15 21:05:40 | 000,502,099 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Under SEH - Google Maps Downloader 6.30 crk.v2m
[2010.11.01 04:05:04 | 000,283,277 | ---- | M] () -- \Users\Marek\Downloads\2500.Keygen.Music.Pack\Under SEH - MLDownloader 7.1.0.9 crk.v2m
[2012.11.01 18:50:49 | 000,024,760 | ---- | M] () -- \Windows\assembly\GAC_32\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader\11.0.0.0__b03f5f7f11d50a3a\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.dll
[2012.11.01 18:50:49 | 000,023,224 | ---- | M] () -- \Windows\assembly\GAC_64\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader\11.0.0.0__b03f5f7f11d50a3a\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.dll
[2012.11.11 14:27:56 | 000,020,480 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Tde5bef3b#\4a088e8987f29c42bc0a97aeae2ac534\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.ni.dll
[2012.11.11 14:27:56 | 000,000,376 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Tde5bef3b#\4a088e8987f29c42bc0a97aeae2ac534\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.ni.dll.aux
[2012.11.11 16:22:24 | 000,577,536 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V09707a24#\53ec859750fa157b7aca17b7cd77ee95\Microsoft.VisualStudio.Repository.Code.Native.Loader.ni.dll
[2012.11.11 16:22:24 | 000,001,324 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V09707a24#\53ec859750fa157b7aca17b7cd77ee95\Microsoft.VisualStudio.Repository.Code.Native.Loader.ni.dll.aux
[2012.11.11 16:22:29 | 002,489,856 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Vbd7eeb5a#\bdba90794f72f54ff98d1ed97ccf5ac4\Microsoft.VisualStudio.Repository.Runtime.Loader.ni.dll
[2012.11.11 16:22:29 | 000,001,708 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Vbd7eeb5a#\bdba90794f72f54ff98d1ed97ccf5ac4\Microsoft.VisualStudio.Repository.Runtime.Loader.ni.dll.aux

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#14 Příspěvek od GAMELASTER »

[2012.11.09 20:50:01 | 000,027,136 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Tde5bef3b#\a48181287797e486eef52377c6d92965\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.ni.dll
[2012.11.09 20:50:01 | 000,000,376 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Tde5bef3b#\a48181287797e486eef52377c6d92965\Microsoft.TeamFoundation.WorkItemTracking.Client.DataStoreLoader.ni.dll.aux
[2010.03.18 23:21:56 | 000,063,312 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\AF4640CBAB0A83E358FBCDB5A304F184\10.0.30319\FL_coloader80_dll_128691_128691_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.18 00:17:14 | 000,004,096 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\AF4640CBAB0A83E358FBCDB5A304F184\10.0.30319\FL_coloader80_tlb_128927_128927_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2012.11.01 18:59:09 | 000,375,936 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualStudio.Repository.Code.Native.Loader\v4.0_11.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Repository.Code.Native.Loader.dll
[2012.11.01 18:59:09 | 001,408,624 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualStudio.Repository.Runtime.Loader\v4.0_11.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Repository.Runtime.Loader.dll
[2012.11.01 19:12:47 | 000,015,472 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualStudio.Web.PageInspector.Loader\v4.0_1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Web.PageInspector.Loader.dll
[2012.07.26 03:46:24 | 000,003,072 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.07.26 03:46:25 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-1.dll
[2012.07.26 03:46:36 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-stringloader-l1-1-0.dll
[2012.07.26 04:18:20 | 000,036,352 | ---- | M] () -- \Windows\System32\dmloader.dll
[2012.07.26 03:46:24 | 000,003,072 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.07.26 03:46:25 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-1.dll
[2012.07.26 03:46:36 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-stringloader-l1-1-0.dll
[2012.07.26 04:18:20 | 000,036,352 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2012.07.26 05:53:16 | 001,084,144 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.2.9200.16384_none_891afac5ef497dae\hvloader.efi
[2012.07.26 05:53:16 | 000,998,128 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.2.9200.16384_none_891afac5ef497dae\hvloader.exe
[2012.07.26 04:05:30 | 000,047,616 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.2.9200.16384_none_9ebdc35619670551\dmloader.dll
[2012.07.26 03:35:54 | 000,003,072 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_637b975b05942933\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.07.26 03:35:54 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_637b975b05942933\api-ms-win-core-libraryloader-l1-1-1.dll
[2012.07.26 03:35:58 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_637b975b05942933\api-ms-win-core-stringloader-l1-1-0.dll
[2012.07.26 11:29:45 | 000,004,656 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a.manifest
[2012.07.26 11:29:45 | 000,029,936 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a_winload.efi.mui_35ee487d
[2012.07.26 11:29:45 | 000,029,936 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a_winload.exe.mui_3bc5b827
[2012.07.26 11:29:45 | 000,020,208 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a_winresume.efi.mui_f412814e
[2012.07.26 11:29:45 | 000,020,208 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a_winresume.exe.mui_ff8b5358
[2012.07.26 09:12:05 | 000,005,810 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f.manifest
[2012.07.26 09:12:05 | 001,403,784 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f_winload.efi_75834aa0
[2012.07.26 09:12:05 | 001,266,920 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f_winload.exe_75835076
[2012.07.26 09:12:05 | 001,217,336 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f_winresume.efi_85cd069f
[2012.07.26 09:12:05 | 001,093,888 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f_winresume.exe_85cd1215
[2012.07.26 09:11:35 | 000,000,596 | ---- | M] () -- \Windows\WinSxS\FileMaps\programdata_microsoft_network_downloader_7fafaef6d33e4371.cdf-ms
[2012.07.26 11:28:25 | 000,004,656 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.2.9200.16384_en-us_cf62616a6dc80c6a.manifest
[2012.07.26 06:00:58 | 000,005,810 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.2.9200.16384_none_b3f06196f66b163f.manifest
[2012.07.26 04:18:20 | 000,036,352 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.2.9200.16384_none_429f27d26109941b\dmloader.dll
[2012.07.26 03:46:24 | 000,003,072 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_075cfbd74d36b7fd\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.07.26 03:46:25 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_075cfbd74d36b7fd\api-ms-win-core-libraryloader-l1-1-1.dll
[2012.07.26 03:46:36 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.2.9200.16384_none_075cfbd74d36b7fd\api-ms-win-core-stringloader-l1-1-0.dll

< End of report >

EXTRA

OTL Extras logfile created on: 24.11.2012 12:06:56 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marek\Downloads
64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16384)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d.M.yyyy

1,75 Gb Total Physical Memory | 0,43 Gb Available Physical Memory | 24,83% Memory free
3,87 Gb Paging File | 1,71 Gb Available in Paging File | 44,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 70,00 Gb Total Space | 32,06 Gb Free Space | 45,80% Space Free | Partition Type: NTFS
Drive D: | 162,88 Gb Total Space | 52,42 Gb Free Space | 32,18% Space Free | Partition Type: NTFS

Computer Name: GAMELASTER | User Name: Marek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.reg [@ = regfile] -- regedit.exe "%1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] -- regedit.exe "%1"

[HKEY_USERS\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [open] -- regedit.exe "%1"
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [Bridge] -- D:\Adobius\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [open] -- regedit.exe "%1"
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [Bridge] -- D:\Adobius\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V"
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2326E797-1BA6-4335-BF7D-80CF942AC859}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{23AB76CD-19EB-46A2-8113-C56898A1A767}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2BC0163D-F599-44F5-9F6C-F3F6F69634D4}" = lport=6919 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{3A431E35-1834-4E21-944E-7AC03BFDA814}" = rport=445 | protocol=6 | dir=out | app=system |
"{404DB710-7AAD-4AFB-B077-BBAD8220268E}" = rport=139 | protocol=6 | dir=out | app=system |
"{45DA0902-2AFE-4B11-A868-95F6D2775144}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52FD671E-13BD-413F-B220-1235EB26D19B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{54E7BEB1-162A-42EE-B969-52184C0DD2E6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5E464621-A864-49DE-AFCC-D1B049017EB8}" = lport=6918 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{62A3BC52-DCF9-4F1B-8061-CDCD0FAEB1FF}" = lport=6916 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{6514B5D6-81A5-49E1-A113-88E768F02304}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{68D418F6-519A-463B-B4BE-62B98DBB32DE}" = rport=138 | protocol=17 | dir=out | app=system |
"{6B8BBA8D-7EA0-428E-B830-4E3592F1662F}" = lport=445 | protocol=6 | dir=in | app=system |
"{77D8F438-B80D-4205-9421-A17FFC80AE2E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7A80A5D8-98EE-4D7C-A5DC-06056CF5C11D}" = lport=6915 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{A1A4A1A3-107E-4753-9366-E69AB6236D45}" = lport=139 | protocol=6 | dir=in | app=system |
"{A42500BD-F054-4CDB-BE99-EF10546D6667}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AC166C11-254C-44AE-8D1B-F895C1B12B66}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AF2CBCB5-F7E1-4201-8294-B04823AF4125}" = lport=3702 | protocol=17 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{B17E7720-FBB6-4CDF-AE62-FDAB8EC7242E}" = lport=137 | protocol=17 | dir=in | app=system |
"{BE28BEA1-496C-467D-ACA3-C30781CA71B8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D4DF7229-6E66-4D7E-986A-8238ADEAD31F}" = rport=137 | protocol=17 | dir=out | app=system |
"{D93FB9B3-22C9-429B-A284-FDC8189F92F2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E2D0B936-4DC2-4E29-B982-00E6DDD8FF8F}" = lport=6917 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{E8056C22-7029-4C36-926B-075018BD239B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E91F34A7-5B46-41B7-B47E-FD658197775B}" = lport=6920 | protocol=6 | dir=in | app=d:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{EBB32DEC-F80D-4B3E-A924-378C5811A257}" = lport=138 | protocol=17 | dir=in | app=system |
"{F9F35FDE-CCD0-4A61-A5AC-3C01689EC120}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D3B36D-B6D2-4B5A-B61E-FE0C00EC89E3}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{02DAA0DE-0681-44CF-B44F-F4DC6E58BFA1}" = dir=out | name=google search |
"{03A1ECAE-3BFA-4A79-A3D4-03FE00810BF5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1036FE95-9677-440D-8713-2D553C9F03BF}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{1495AFCA-2A84-479C-8FB5-6D13EF121AC0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{18A85B2B-398A-472B-B218-45B095760C79}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2311B9B2-ACCA-4C1A-926C-2EB0BDA8C94C}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{2A7A03BC-F5DE-486B-8BF7-3DE985005A7C}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{2CD5EF96-FC20-47BF-A51E-4142682A43C7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{32D48877-22F2-461F-97ED-0C6B256788F3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{35F67D53-2E23-43AB-95AC-155687AEFFB1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3E371607-5836-443E-B4A3-C43E39A250B9}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{3E487879-EC40-419A-9F07-541AB7AB3BB0}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{414A8642-A871-4E72-852B-CEF7332AA124}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{44A581F8-F3F2-4A3B-8E2F-B375561739B8}" = dir=in | app=c:\program files (x86)\common files\microsoft shared\xna\xnatrans\v3.0\xnatransx.exe |
"{4BB5D68B-2690-4374-B4BA-C8DE3EE0AE66}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4BD48B1A-B0E2-4B07-B064-FD967B5F6761}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{4D4E1248-3B59-4330-AB51-6DAB0F0AD863}" = protocol=17 | dir=in | app=d:\program files (x86)\utorrent\utorrent.exe |
"{507BF719-1497-4CB7-91D7-F6B7EA8D8010}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5819B920-CC0C-4B6E-9304-E78F32E505D9}" = dir=out | name=game1 |
"{5A8178D3-430B-40D5-9B41-27CFE047DFF2}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{636B24B1-3367-4F6F-9437-B02314EC019C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6903C591-446B-414A-A378-5C4248A2946E}" = protocol=6 | dir=in | app=d:\program files (x86)\utorrent\utorrent.exe |
"{6D7528DC-C68D-4455-996C-DA2F2DD6A2B0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{76FAAAF3-6BAE-46D3-8227-EAD6C968B1ED}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{80225109-19F7-47F5-86DB-F00BFA2F8794}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{8A58F14E-F0B2-4FD1-9850-5615F38F81E2}" = protocol=6 | dir=out | app=system |
"{8BED7C89-DD1C-4C84-8060-8123C9CB1F16}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9A876B1C-DBC4-4B7E-B019-E9481D79167A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B088DEE9-904D-4EE4-9635-1F13E14FF14B}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{B78A4891-8C10-4524-B0AF-131F6F0236A4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BF8EA3F2-1F79-4B14-A496-DB2427921F93}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C604DE87-D8DC-4B06-914C-555CAE696E8A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C77D3BA9-5FB3-4124-8422-9186C4DFDDEE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CCEDDB6A-F9F4-4C68-9ACF-EEA28475C790}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{D712F7E1-EB0B-4662-9EFE-775A54DA175F}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{DEF5E1D9-C752-4596-8EC8-3812F0713F94}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{EA18F939-E6A5-483E-8892-96C8803BC22D}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{ED116DE3-F325-4EE2-91F3-9E4BE60CF074}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F1CFC917-6806-4C41-8897-BCB577050E8D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F2322C6B-291F-4082-9AC5-9708272ACA57}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{FE451B99-6D7C-42F9-B1FA-F896742D517D}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{FEE51978-0DA3-44B6-A8DD-9CC3A57FC3B8}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{FFD593E4-CAC1-45B5-B749-C40332331053}" = dir=in | app=c:\program files (x86)\microsoft xna\xna game studio\v4.0\bin\xnaliveproxy.exe |
"TCP Query User{CD19A65E-2106-4F1F-B852-5158D28EF9CF}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{E9F6A373-B2B1-434B-A65E-AF266512AEEB}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034106B5-54B7-467F-B477-5B7DBB492624}" = Microsoft Sync Framework Services v1.0 SP1 (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0E8670B8-3965-4930-ADA6-570348B67153}" = Microsoft SQL Server 2012 Transact-SQL ScriptDom
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{1012456A-D118-37E0-E837-34AA28602013}" = AMD Drag and Drop Transcoding
"{13417784-A359-3CDD-8DE1-B7108707D647}" = Visual Studio 2012 Prerequisites - ENU Language Pack
"{13D558FE-A863-402C-B115-160007277033}" = Microsoft SQL Server 2012 Express LocalDB
"{1AB7EDC5-D891-34C5-9FF1-BE6A85ACC44B}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{1CB6C387-65A7-327F-B4A5-7DDC75A291AF}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{24C3AEE0-4BCE-3190-8EE0-BBA0BF72CAC1}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{27EF252D-800C-ED42-9904-459FE0046225}" = Windows Software Development Kit for Windows Store Apps DirectX x64 Remote
"{28D85F24-B685-3364-BB7C-284C88C2FFE5}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding
"{2B997E80-3BEC-3222-9114-98DBE1182B2E}" = Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{36E619BC-A234-4EC3-849B-779A7C865A45}" = Microsoft SQL Server 2012 Data-Tier App Framework
"{3FA063D7-EDC1-AFA8-54AF-0563C7DEE070}" = Windows App Certification Kit Native Components
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4701DEDE-1888-49E0-BAE5-857875924CA2}" = Microsoft SQL Server System CLR Types (x64)
"{49D665A2-4C2A-476E-9AB8-FCC425F526FC}" = Microsoft SQL Server 2012 Native Client
"{4F2B8F3E-70FA-AA71-4526-3BFDEDE502EF}" = AMD Fuel
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{55EFD1A6-ED8E-3A4C-9581-5E1A1FF244CD}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU
"{572E796D-C52B-3797-A685-2FB6F895D4BE}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{594E1ED0-F915-791B-2739-760DF91291DF}" = ccc-utility64
"{5FB4C443-6BD6-1514-2717-3827D65AE6FB}" = Windows Software Development Kit DirectX x64 Remote
"{61862D7C-CDBC-48D5-8AE1-3B8BD1E23BC5}" = Visual Studio 2012 Prerequisites
"{633AB014-DDE6-403E-A302-8920CC32C543}" = Microsoft Visual Studio 2012 Performance Collection Tools
"{64A3A4F4-B792-11D6-A78A-00B0D0170090}" = Java SE Development Kit 7 Update 9 (64-bit)
"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English
"{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU
"{6AAF4427-3039-4C8A-BE53-D6F01C21AD46}" = Microsoft Visual Studio 2012 IntelliTrace Core amd64
"{6BB150E8-6CBB-5F8F-CAE7-BE21B2C92D31}" = AMD Accelerated Video Transcoding
"{6F07A6C2-9068-3673-A120-DC10012468C6}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model
"{78909610-D229-459C-A936-25D92283D3FD}" = Microsoft SQL Server Compact 4.0 SP1 x64 ENU
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}" = IIS 8.0 Express
"{8438EC02-B8A9-462D-AC72-1B521349C001}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64)
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{88BAE373-00F4-3E33-828F-96E89E5E0CB9}" = Microsoft Visual Studio 2010 IntelliTrace Collection (x64)
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8C49F61F-FCA6-A096-3E92-71128D8425ED}" = AMD Catalyst Install Manager
"{8FF0ACBD-17A5-3637-95F4-D7C69723E2BF}" = Microsoft Visual Studio 2010 Performance Collection Tools - ENU
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}" = Microsoft SQL Server 2012 Command Line Utilities
"{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb" = IIS Express Application Compatibility Database for x64
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}" = Microsoft Web Deploy 3.0
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
"{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}" = Microsoft SQL Server 2012 Transact-SQL Compiler Service
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D9F3D00D-E946-3B3D-A4A6-93D5020DB9F7}" = Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727
"{DA3372D5-F228-5C71-3FAC-177D4AEE8659}" = AMD Media Foundation Decoders
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{E2B8249D-895C-4685-8C83-00F3B1A13028}" = Microsoft Web Platform Installer 4.0
"{F1949145-EB64-4DE7-9D81-E6D27937146C}" = Microsoft System CLR Types for SQL Server 2012 (x64)
"{F5079164-1DB9-3BDA-853B-F78AF67CE071}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{FA0A244E-F3C2-4589-B42A-3D522DE79A42}" = Microsoft SQL Server 2012 Management Objects (x64)
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb" = IIS Express Application Compatibility Database for x86
"{FE74AC04-F248-4641-B3A9-89C6AA4339CD}" = Microsoft Visual Studio 2012 Performance Collection Tools - ENU
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}" = Microsoft NuGet - Visual Studio 2012
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{02213A81-CB13-7262-5ABE-1FFA2C75559F}" = Windows App Certification Kit x64
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03D45A4B-D7F5-C03E-1650-885756303D13}" = CCC Help Norwegian
"{046806D1-0A38-3FCA-AF84-F71C50A0C363}" = Microsoft Visual Studio Premium 2012
"{05CDC06E-4C55-4EAE-9401-8EF62F60CB69}" = Microsoft XNA Game Studio 4.0 Refresh (Visual Studio)
"{069B290F-5398-4629-A009-85B4BCB4B1B9}" = Claro Chrome Toolbar
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A1A1D48-DB23-443A-BC7B-49255D138020}" = Entity Framework Designer for Visual Studio 2012 - enu
"{0BCC836F-0B28-4090-B58A-64883BAA3B2F}" = WCF Data Services 5.0 (for OData v3) Primary Components
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0DDCEC37-369C-484B-B16D-B4413FD42FB9}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}" = Microsoft Sync Framework SDK v1.0 SP1
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{1172AC15-080E-30E3-85B0-FF59AD2E6315}" = Microsoft Visual Studio Ultimate 2012 - ENU
"{148878BD-A2A5-4CF1-A103-2BA632F41953}" = WCF Data Services Tools for Microsoft Visual Studio 2012
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1690CE56-2231-4E59-9006-A0876D949EA8}" = Tools for .Net 3.5
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}" = Microsoft Silverlight 4 SDK
"{1948E039-EC79-4591-951D-9867A8C14C90}" = Microsoft .NET Framework 4.5 SDK
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU
"{1C163D33-33B3-33EB-A617-0D4D852BE8E1}" = Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727
"{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}" = Microsoft Report Viewer Add-On for Visual Studio 2012
"{1F8E06E2-BA93-40DC-B183-E024CBD853A8}" = Microsoft Visual C++ 2012 Compilers
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{23176E97-26CB-C72A-19EB-BFB21AC1D15A}" = Windows Software Development Kit DirectX x86 Remote
"{246B0F46-F84E-4857-8C47-F2A86B598BC5}" = Microsoft Visual Studio 2012 Preparation
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{284E9E9A-D8BE-3588-D0BA-E9BB61970A1D}" = CCC Help Hungarian
"{288DB08D-0708-4A94-B055-55B99E39EB62}" = Adobe Creative Suite 5 Master Collection
"{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
"{29F259D7-C517-3EED-84B4-237573CFD39C}" = Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries
"{2C0CC01A-DDBC-3AED-AF18-E741242FD727}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer enu Resources
"{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}" = PreEmptive Analytics Visual Studio Components
"{2D9FEBEE-F1B7-344F-BFDF-760E18332D96}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{2F6CE32A-018D-4656-895B-9E5E20D7740A}" = Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{30E18A93-982E-AF1B-D646-E8C5DAECA390}" = CCC Help French
"{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}" = Microsoft Visual Studio 2012 Devenv
"{372D17F6-A54E-4A01-B264-1314890FFE61}" = Dotfuscator and Analytics Community Edition
"{384FA0C0-BB19-4CA0-8DB4-5FD4E938277F}" = Notification Center
"{38FC6E9A-F719-431A-A83D-4C86D5FD6555}" = Microsoft Visual Studio 2012 Shell (Minimum) Resources
"{3A523AF9-D32F-4C85-8388-0335731F3405}" = WCF RIA Services V1.0 SP2
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3AB65E95-37D6-4DD7-8862-29AED3AFD54B}" = Google SketchUp Pro 8
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}" = Dotfuscator Software Services - Community Edition
"{42F61556-29ED-8122-F39E-6F04EA5FF279}" = Windows Software Development Kit for Windows Store Apps DirectX x86 Remote
"{470D66DF-B597-124E-EDCE-8B966AA5F230}" = CCC Help Portuguese
"{483924A6-52C5-9169-0280-14272D5FBA70}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{532DBCC8-9468-435C-AEF6-30B7F50735A2}" = Blend for Visual Studio 2012 ENU resources
"{57AE1BE1-24E8-4169-D52C-ABE31BD91562}" = CCC Help Finnish
"{57D782D7-49FD-48DE-AB47-A690A1519A2D}" = Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools
"{57F20F04-014D-453F-B6A3-AE9485C4DFAB}" = Blend for Visual Studio 2012
"{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}" = Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools
"{5B5745F7-23EF-9E5E-6689-512C9FA08222}" = CCC Help English
"{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}" = Microsoft .NET Framework 4.5 Multi-Targeting Pack
"{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}" = Windows Software Development Kit
"{625031C9-E249-2A53-C282-C1E9872B211E}" = CCC Help Turkish
"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{655E0B5A-7ADF-A052-587F-64F0E59B58E7}" = CCC Help Dutch
"{6A7387C0-B74F-47D0-A217-B384E55FE0C9}" = Microsoft XNA Game Studio 4.0 Refresh (Redists)
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6D6D43E5-218C-4B05-92D3-2240810F4760}" = Microsoft SQL Server 2012 T-SQL Language Service
"{6DAB46E3-D017-3E2B-85D8-F57A230384C0}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{6F066545-40A2-4C38-A8F7-78581CC5C442}" = Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools
"{6FC3B79F-47C6-38AF-B9A9-67DE3C639598}" = Microsoft Visual Studio Premium 2012 - ENU
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{731C183B-86A0-3442-BE55-68A7C92581E9}" = Microsoft Visual C++ 2012 Extended Libraries
"{7437A4B9-314F-3B8F-827B-22909146E471}" = Microsoft LightSwitch for Visual Studio 2012 Core
"{74437563-D720-0307-90FC-1C351B1041D7}" = Catalyst Control Center Localization All
"{789A4D10-821B-3FA5-52B0-F0FAEEDED9F4}" = CCC Help Czech
"{78C3657E-742C-40B1-9F53-E5A921D40F17}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{790E9425-8570-493F-9AE7-81AFC9E46930}" = Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)
"{7BA14A92-C229-5E00-3ADE-8D22F81B849E}" = CCC Help German
"{800F484E-9D69-492D-B656-7BAA32586142}" = Microsoft Visual Studio 2012 Shell (Minimum)
"{80A5B901-C7BD-D300-17BA-9E02F18EAB77}" = CCC Help Danish
"{820C677A-41B2-48C3-8136-FEE35A052E73}" = Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies
"{82F505E6-5879-B30A-12B7-7795969D3BBB}" = CCC Help Polish
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{8476003F-6927-8393-C6F4-FAF47D61D00B}" = CCC Help Korean
"{89217401-A2E5-4BFA-8973-803076698A3D}" = Game Fire
"{89690B51-2E21-4E93-914E-F9CAC5B24A84}" = Microsoft XNA Game Studio Platform Tools
"{89A2D79E-B3AD-A83A-795F-5645EFF922D3}" = CCC Help Greek
"{89B4532E-19CE-4FA9-9692-10BFD5A38532}" = Visual Studio Extensions for Windows Library for JavaScript
"{89C0F58F-9E5B-2B45-D9DF-7988A54BECA8}" = CCC Help Italian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B91D776-792D-F02B-DE43-BF398549C729}" = CCC Help Spanish
"{9169C939-ED01-446A-BD0C-29873BAF4E48}" = Prerequisites for SSDT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{93489CA8-6656-33A0-A5AC-E0EDEDB17C3E}" = Microsoft Visual Studio Professional 2012
"{942CC691-5B98-42A3-8BC5-A246BA69D983}" = Microsoft ASP.NET MVC 4 Runtime
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{983BE967-28E9-5C78-8851-638DAC4AF66E}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A240191E-4302-435E-86FC-A5717EF0CF38}" = Microsoft XNA Game Studio 4.0 Refresh (Shared Components)
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}" = Microsoft Visual Studio 2012 SharePoint Developer Tools
"{A4366F69-CE22-4DB7-9C8C-46A5845AF997}" = Microsoft Visual C++ 2012 Compilers - ENU Resources
"{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}" = Microsoft SQL Server System CLR Types
"{A707240D-18D3-07F4-AE2E-6AE76C220192}" = CCC Help Japanese
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}" = Microsoft Visual C++ 2012 Core Libraries
"{B1465D1D-6427-4CA1-AE29-8B699209E663}" = Microsoft Visual Studio 2012 Devenv Resources
"{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}" = Microsoft Visual Studio 2012 IntelliTrace Core x86
"{B5DA9D49-9BD8-0F2F-52FC-C7E66BC8D944}" = LocalESPCui for en-us
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B95AC87D-630B-603F-3F12-AA22B3BBA69C}" = CCC Help Chinese Traditional
"{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}" = Microsoft Web Developer Tools - Visual Studio 2012
"{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}" = Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack
"{BAD0254F-9BDB-3D14-A5AC-9C0EF51F3D09}" = Microsoft Portable Library Multi-Targeting Pack Language Pack - enu
"{BC0464FA-A0BA-3E38-85BF-DC5B3A401F48}" = Microsoft Visual Studio 2010 Ultimate - ENU
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{BDBE5D2A-AAB7-77BD-7A0E-5006665CE7C6}" = LocalESPC
"{C1BE4600-7D15-3D1E-8AA2-B3241DB1D063}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core
"{C4CAD994-6EA2-3121-8352-DA593150B322}" = Microsoft Portable Library Multi-Targeting Pack
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}" = Windows Runtime Intellisense Content - en-us
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFFDC0EC-6924-3347-B047-13339EDBEC28}" = Microsoft Visual Studio Professional 2012 - ENU
"{D11F66FF-82B3-DDB8-1146-525370552BE1}" = Windows Software Development Kit for Windows Store Apps
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D971780F-A609-4F78-92AA-B56FBC3955B9}" = Microsoft Visual Studio 2012 IntelliTrace Front End x86
"{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}" = Microsoft SQL Server 2012 Management Objects
"{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}" = Microsoft ASP.NET MVC 3
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DF56EB5C-7E7A-D405-1B01-ECC0CAD8E709}" = Catalyst Control Center InstallProxy
"{E1FBB3D4-ADB0-4949-B101-855DA061C735}" = Microsoft Silverlight 5 SDK
"{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}" = Microsoft System CLR Types for SQL Server 2012
"{e238e1a0-7fbd-4146-a4ac-d48badcdf3ae}" = Microsoft Visual Studio Ultimate 2012
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}" = Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU
"{E4C33F5B-1B2F-466E-957E-B274F08151A0}" = Microsoft Web Deploy dbSqlPackage Provider - enu
"{E5AE9031-79A5-4627-9641-BEFA82819B08}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{E818AE7C-244B-4A50-9C86-C0E4A8B69159}" = Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EB1C554C-5343-9A69-1B8C-666AF192CA19}" = CCC Help Russian
"{EE3A5B79-C147-4BD9-952A-E894298C2ACA}" = Microsoft XNA Game Studio 4.0 Refresh (ARP entry)
"{EFA87714-E75A-3BFC-A698-A3AABA5A8A0C}" = Microsoft Visual Studio Ultimate 2012
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.108
"{F32D24DD-D787-10F9-D21E-BC3FAB3064CB}" = Catalyst Control Center Graphics Previews Common
"{F836B1C1-180C-7D44-F720-17E4C4CD5E7C}" = AMD VISION Engine Control Center
"{F8D90583-7BB5-75A9-B23F-A353AD4674BC}" = CCC Help Thai
"{FA804794-2CCB-4301-954F-2C2894698876}" = Microsoft SQL Server Data Tools - enu (11.1.20627.00)
"{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}" = Microsoft SQL Server 2012 Data-Tier App Framework
"{FBBC8076-BB21-4E06-9FA0-309AEF6E35EE}" = Microsoft ASP.NET Web Pages 2 Runtime
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}" = Microsoft Help Viewer 2.0
"3D Rad_is1" = 3D Rad v7.22
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Altap Salamander 2.54" = Altap Salamander 2.54
"BlueStacks App Player" = BlueStacks App Player
"Cobalt" = Cobalt
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Condition_Zero_3" = Condition Zero 3
"DAEMON Tools Lite" = DAEMON Tools Lite
"EaseUS Partition Master Home Edition_is1" = EaseUS Partition Master 9.1.1 Home Edition
"Fraps" = Fraps (remove only)
"GTA2 Game Hunter" = GTA2 Game Hunter
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verzia 1.65.1.1000
"Microsoft Help Viewer 2.0" = Microsoft Help Viewer 2.0
"Microsoft Visual Studio 2010 Ultimate - ENU" = Microsoft Visual Studio 2010 Ultimate - ENU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"MonoGame" = MonoGame
"Mozilla Firefox 16.0.2 (x86 sk)" = Mozilla Firefox 16.0.2 (x86 sk)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MTA:SA 1.3" = MTA:SA v1.3.1
"Notepad++" = Notepad++
"OpenAL" = OpenAL
"uTorrent" = µTorrent
"Winamp" = Winamp
"winscp3_is1" = WinSCP 5.1.1
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0 Refresh

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2331816091-2394518104-2338911075-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GameMaker-Studio11" = GameMaker-Studio 1.1
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 23.11.2012 16:03:45 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program Skype.exe version 6.0.60.120 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 388 Start
Time: 01cdc9887b903b6e Termination Time: 4294967295 Application Path: C:\Program
Files (x86)\Skype\Phone\Skype.exe Report Id: df4225d4-35a8-11e2-be72-0022645fc0e5

Faulting
package full name: Faulting package-relative application ID:

Error - 23.11.2012 16:17:49 | Computer Name = GAMELASTER | Source = Software Protection Platform Service | ID = 8198
Description = License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line
arguments: RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error - 23.11.2012 16:17:49 | Computer Name = GAMELASTER | Source = Software Protection Platform Service | ID = 8198
Description = License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line
arguments: RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable

Error - 23.11.2012 17:28:42 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program WinSCP.exe version 5.1.1.2735 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1210 Start
Time: 01cdc9c131445e61 Termination Time: 0 Application Path: C:\Program Files (x86)\WinSCP\WinSCP.exe

Report
Id: bd69d8c0-35b4-11e2-be73-0022645fc0e5 Faulting package full name: Faulting package-relative
application ID:

Error - 24.11.2012 4:11:29 | Computer Name = GAMELASTER | Source = Software Protection Platform Service | ID = 8198
Description = License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line
arguments: RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable

Error - 24.11.2012 4:40:12 | Computer Name = GAMELASTER | Source = Application Error | ID = 1000
Description = Názov chybujúcej aplikácie: winamp.exe, verzia: 5.6.3.3235, časová
značka: 0x4fec7b3e Názov chybujúceho modulu: in_mod.dll, verzia: 0.0.0.0, časová
značka: 0x4fec7b50 Kód výnimky: 0xc0000094 Odstup chyby: 0x0001342a Identifikácia
chybujúceho procesu: 0xcec Čas spustenia chybujúcej aplikácie: 0x01cdca1c9a73108e
Cesta
chybujúcej aplikácie: C:\Program Files (x86)\Winamp\winamp.exe Cesta chybujúceho
modulu: C:\Program Files (x86)\Winamp\Plugins\in_mod.dll Identifikácia hlásenia:
8f3764a0-3612-11e2-be73-0022645fc0e5 Celé meno chybujúceho balíka: Identifikácia
chybujúcej aplikácie vzhľadom na balík:

Error - 24.11.2012 6:12:11 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program gta_sa.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 13e4 Start Time:
01cdca2c01e8efa7 Termination Time: 4294967295 Application Path: D:\Rockstar Games\GTA
San Andreas\gta_sa.exe Report Id: 6703ff9d-361f-11e2-be73-0022645fc0e5 Faulting package
full name: Faulting package-relative application ID:

Error - 24.11.2012 6:16:27 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program gta_sa.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 3d4 Start Time:
01cdca2ca980c210 Termination Time: 4294967295 Application Path: D:\Rockstar Games\GTA
San Andreas\gta_sa.exe Report Id: ff600e60-361f-11e2-be73-0022645fc0e5 Faulting package
full name: Faulting package-relative application ID:

Error - 24.11.2012 6:27:02 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program gta_sa.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 4a0 Start Time:
01cdca2e163cd403 Termination Time: 4294967295 Application Path: D:\Rockstar Games\GTA
San Andreas\gta_sa.exe Report Id: 7a12e451-3621-11e2-be73-0022645fc0e5 Faulting package
full name: Faulting package-relative application ID:

Error - 24.11.2012 7:10:51 | Computer Name = GAMELASTER | Source = Application Hang | ID = 1002
Description = The program WinSCP.exe version 5.1.1.2735 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 10f4 Start
Time: 01cdca1d930f9069 Termination Time: 78 Application Path: C:\Program Files (x86)\WinSCP\WinSCP.exe

Report
Id: 9833b94e-3627-11e2-be73-0022645fc0e5 Faulting package full name: Faulting package-relative
application ID:

[ System Events ]
Error - 23.11.2012 15:55:11 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7009
Description = Počas čakania na pripojenie služby Browser Manager bol dosiahnutý
časový limit (30000 ms).

Error - 23.11.2012 15:55:11 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Browser Manager zlyhalo kvôli nasledujúcej chybe:
%%1053

Error - 23.11.2012 15:56:17 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7031
Description = Služba Browser Manager sa neočakávane ukončila. Služba sa týmto spôsobom
ukončila už 2 krát. O 30000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať
službu.

Error - 23.11.2012 15:59:22 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7031
Description = Služba Browser Manager sa neočakávane ukončila. Služba sa týmto spôsobom
ukončila už 3 krát. O 30000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať
službu.

Error - 23.11.2012 15:59:56 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7009
Description = Počas čakania na pripojenie služby Browser Manager bol dosiahnutý
časový limit (30000 ms).

Error - 23.11.2012 15:59:56 | Computer Name = GAMELASTER | Source = Service Control Manager | ID = 7000
Description = Spustenie služby Browser Manager zlyhalo kvôli nasledujúcej chybe:
%%1053

Error - 23.11.2012 16:09:47 | Computer Name = GAMELASTER | Source = DCOM | ID = 10016
Description =

Error - 23.11.2012 16:09:47 | Computer Name = GAMELASTER | Source = DCOM | ID = 10016
Description =

Error - 23.11.2012 17:54:32 | Computer Name = GAMELASTER | Source = Schannel | ID = 36888
Description = A fatal alert was generated and sent to the remote endpoint. This
may result in termination of the connection. The TLS protocol defined fatal error
code is 10. The Windows SChannel error state is 10.

Error - 23.11.2012 18:45:02 | Computer Name = GAMELASTER | Source = Microsoft-Windows-Kernel-Power | ID = 137
Description =


< End of report >

GAMELASTER
Návštěvník
Návštěvník
Příspěvky: 107
Registrován: 13 led 2012 16:53

Re: Virus v instalacke

#15 Příspěvek od GAMELASTER »

Virus zase nainstaloval tie blbosti ako regclean a zmenil vsetko na claro(prebehlo to pocas instalovania ESETu...).. (ESET sa este furt instaluje)

Odpovědět