Stránka 1 z 2

Po návšteve PR SR

Napsal: 21 led 2013 17:49
od fefed
Pred niečo cez mesiac dozadu som zmrzol pri stránke zablokovaný počítač políciou, nejako sa mi to podarilo odblokovať potvrdom reštarte. V podstate nejaké problémy nemám, aspoň som si ich neni vedomý, chcel by som požiadať o kontrolu logu. Ďakujem


Logfile of random's system information tool 1.09 (written by random/random)
Run by fefed at 2013-01-21 17:26:45
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 183 GB (40%) free of 463 GB
Total RAM: 3835 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:26:55, on 21. 1. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Protected Search\ProtectedSearch.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
C:\Users\fefed\Desktop\SALAMAND.EXE
C:\Program Files\trend micro\fefed.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si= ... e&tid=2996
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si= ... e&tid=2996
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O2 - BHO: DownTango Launcher - {584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O3 - Toolbar: DownTango Launcher - {584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [EPSON SX130 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /FU "C:\Windows\TEMP\E_S8974.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odoslať obrázok do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odoslať stránku do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Prevziať pomocou FDM - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Prevziať video pomocou FDM - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Prevziať vybrané pomocou FDM - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Prevziať všetko pomocou FDM - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {64682b28-2d9c-4607-bd0b-3fbcabfdc213} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NTI, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16078 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 34173280
\??\C:\Windows\system32\conhost.exe "10139472886479940901940319694-3810536871811692126332805674-18893257211054893619
"C:\Program Files\Alwil Software\Avast5\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Acer\Registration\GREGsvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 2816
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
atieclxx
"taskhost.exe"
taskeng.exe {1D9DEEF6-B619-4E6A-BE03-10BF22F0929F}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Protected Search\ProtectedSearch.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Program Files (x86)\Free Download Manager\fdm.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=16832.aa37300.1625835286 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 16832 "\\.\pipe\gecko-crash-server-pipe.16832" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe" --proxy-stub-channel=Flash4852.625BFFC0.41 --host-broker-channel=Flash4852.625BFFC0.18467 --host-pid=4852 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe" --channel=15176.001DF744.395188190 --proxy-stub-channel=Flash4852.625BFFC0.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll" --host-npapi-version=27 --type=renderer
"C:\Users\fefed\Desktop\SALAMAND.EXE"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe127_ Global\UsGthrCtrlFltPipeMssGthrPipe127 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\fefed\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\DriverScanner.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default

prefs.js - "browser.search.useDBForOrder" - false
prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "extensions.enabledItems" - "fdm_ffext@freedownloadmanager.org:1.3.4, xmlfiller@software602.cz:3.16.2, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.certified-toolbar.com?si= ... bs=true&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
xmlfiller@software602.cz
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIFillerPlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdnu.dll
npdnu.xpt
npdnupdater2.dll
npdnupdater2.xpt
npfiller.dll
NPOFF12.DLL
nppdf32.dll
npwachk.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
Web Search.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\extensions\
fdm_ffext@freedownloadmanager.org
{0b38152b-1b20-484d-a11f-5e04a9b0661f}

C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\searchplugins\
Web Search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2012-10-30 1502288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-01-11 253584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2011-09-28 1937736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{584d7c26-4cba-4eeb-9e1b-5298a374ebb0}]
DownTango Launcher - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll [2012-11-01 1029480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-12 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-11 192144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
Free Download Manager - C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2012-05-14 231424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-12 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2012-10-30 1502288]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-01-11 253584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2011-09-28 1937736]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]
{584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - DownTango Launcher - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll [2012-11-01 1029480]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-11 192144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-06-22 10920552]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-04-13 649608]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-09-19 206208]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-06-11 861216]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-07-15 39408]
"Free Download Manager"=C:\Program Files (x86)\Free Download Manager\fdm.exe [2012-12-26 6859264]
"EPSON SX130 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE [2010-12-07 232448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2010-06-28 265984]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-04-21 98304]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-06-22 968272]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-10-30 4297136]
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-10-26 74752]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-08-30 979328]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-01-21 17:26:46 ----D---- C:\Program Files\trend micro
2013-01-21 17:26:45 ----D---- C:\rsit
2013-01-21 11:35:16 ----D---- C:\Users\fefed\AppData\Roaming\vlc
2013-01-21 11:34:33 ----D---- C:\Program Files (x86)\VideoLAN
2013-01-19 09:13:10 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-01-16 16:56:30 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-01-16 16:56:30 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-01-16 16:56:30 ----A---- C:\Windows\SYSWOW64\java.exe
2013-01-16 16:55:39 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-01-13 18:54:23 ----D---- C:\Program Files\Microsoft Silverlight
2013-01-13 18:54:23 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-01-13 08:40:25 ----D---- C:\ProgramData\Free Download Manager
2013-01-09 05:34:01 ----A---- C:\Windows\system32\win32spl.dll
2013-01-09 05:34:00 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-09 05:33:45 ----A---- C:\Windows\system32\msxml6.dll
2013-01-09 05:33:43 ----A---- C:\Windows\system32\msxml3.dll
2013-01-09 05:33:42 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-09 05:33:42 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-09 05:33:32 ----A---- C:\Windows\system32\Wpc.dll
2013-01-09 05:33:31 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-09 05:33:31 ----A---- C:\Windows\system32\gameux.dll
2013-01-09 05:33:30 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-09 05:33:09 ----A---- C:\Windows\system32\usp10.dll
2013-01-09 05:33:08 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-09 05:33:07 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 05:33:06 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-09 05:32:40 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-09 05:32:38 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-09 05:32:37 ----A---- C:\Windows\system32\kernel32.dll
2013-01-09 05:32:35 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-09 05:32:34 ----A---- C:\Windows\system32\wow64win.dll
2013-01-09 05:32:34 ----A---- C:\Windows\system32\wow64.dll
2013-01-09 05:32:34 ----A---- C:\Windows\system32\winsrv.dll
2013-01-09 05:32:34 ----A---- C:\Windows\system32\conhost.exe
2013-01-09 05:32:33 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-09 05:32:33 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-09 05:32:33 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-09 05:32:33 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-09 05:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 05:32:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 05:32:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 05:32:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 05:32:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 05:32:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 05:32:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 05:32:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 05:32:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 05:32:24 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 05:32:23 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 05:32:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 05:32:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 05:32:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 05:32:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 05:32:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 05:32:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 05:32:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 05:32:21 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 05:32:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 05:32:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 05:32:20 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 05:32:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 05:32:19 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 05:32:18 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 05:32:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 05:32:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 05:32:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 05:32:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 05:32:16 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-09 05:32:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 05:32:15 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 05:32:15 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-09 05:32:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 05:32:14 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 05:32:13 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-09 05:31:40 ----A---- C:\Windows\system32\taskhost.exe
2013-01-09 05:31:37 ----A---- C:\Windows\system32\win32k.sys
2013-01-03 10:41:55 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-01-03 10:41:55 ----A---- C:\Windows\system32\atmlib.dll
2013-01-03 10:41:51 ----A---- C:\Windows\system32\atmfd.dll
2013-01-03 10:41:48 ----A---- C:\Windows\SYSWOW64\atmfd.dll

======List of files/folders modified in the last 1 month======

2013-01-21 17:26:55 ----D---- C:\Windows\Prefetch
2013-01-21 17:26:49 ----D---- C:\Windows\Temp
2013-01-21 17:26:46 ----RD---- C:\Program Files
2013-01-21 17:26:31 ----D---- C:\downloads
2013-01-21 14:51:37 ----D---- C:\Windows\system32\config
2013-01-21 11:34:33 ----RD---- C:\Program Files (x86)
2013-01-20 16:11:08 ----D---- C:\Windows\system32\FxsTmp
2013-01-20 11:17:43 ----D---- C:\ProgramData\DVD Shrink
2013-01-20 11:14:45 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-01-17 21:06:57 ----D---- C:\Users\fefed\AppData\Roaming\Free Download Manager
2013-01-17 02:41:14 ----SHD---- C:\System Volume Information
2013-01-17 00:54:04 ----D---- C:\Windows\rescache
2013-01-16 16:56:43 ----SHD---- C:\Windows\Installer
2013-01-16 16:56:30 ----D---- C:\Windows\SysWOW64
2013-01-16 16:56:30 ----D---- C:\Program Files (x86)\Java
2013-01-14 19:53:34 ----D---- C:\Windows\System32
2013-01-14 19:53:34 ----D---- C:\Windows\inf
2013-01-14 19:53:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-13 23:24:12 ----D---- C:\Windows\Microsoft.NET
2013-01-13 23:24:10 ----RSD---- C:\Windows\assembly
2013-01-13 19:47:37 ----D---- C:\Windows\winsxs
2013-01-13 19:46:03 ----D---- C:\Windows
2013-01-13 19:38:15 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-01-13 19:38:15 ----D---- C:\Windows\system32\sk-SK
2013-01-13 19:38:13 ----D---- C:\Windows\AppPatch
2013-01-13 19:27:45 ----D---- C:\ProgramData\Microsoft Help
2013-01-13 19:24:06 ----D---- C:\Windows\debug
2013-01-13 19:24:02 ----A---- C:\Windows\system32\MRT.exe
2013-01-13 10:41:10 ----D---- C:\Windows\system32\NDF
2013-01-13 08:40:25 ----HD---- C:\ProgramData
2013-01-09 05:31:30 ----D---- C:\Windows\system32\catroot
2013-01-09 05:31:19 ----D---- C:\Windows\system32\catroot2
2013-01-09 03:36:50 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-01-08 12:41:17 ----A---- C:\odkazy.txt
2013-01-08 10:56:26 ----D---- C:\Program Files (x86)\Share Rapid Uploader
2013-01-04 10:55:14 ----D---- C:\Skeny
2013-01-03 10:46:41 ----D---- C:\Program Files (x86)\Free Download Manager
2013-01-03 10:18:22 ----D---- C:\Users\fefed\AppData\Roaming\Media Player Classic
2013-01-02 11:02:56 ----D---- C:\Users\fefed\AppData\Roaming\Winamp
2012-12-31 16:42:06 ----D---- C:\up
2012-12-22 12:30:47 ----D---- C:\hotovo

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2010-12-31 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-10-30 262656]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-10-30 132864]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-30 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 91568]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-04-21 6406144]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-04-20 188928]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-06-03 4171328]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-04-13 135560]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-06-22 2399848]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-05-15 384040]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2010-04-28 18432]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-01-27 231328]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2010-04-28 17408]
R3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys [2010-06-25 342056]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-06-25 102952]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-06-25 135720]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-06-25 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-06-25 21544]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-12-29 82816]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-06-17 246376]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\Windows\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\Windows\system32\DRIVERS\ZTEusbser6k.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-04-21 202752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe [2012-10-30 133912]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-06-25 952096]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-06-22 321104]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
R2 IviRegMgr;IviRegMgr; C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2010-05-21 110736]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-29 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 251400]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-29 135664]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-19 194032]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-19 115608]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-30 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: Po návšteve PR SR

Napsal: 21 led 2013 18:18
od vyosek
Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Search
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: Po návšteve PR SR

Napsal: 21 led 2013 19:28
od fefed
AdwC:


# AdwCleaner v2.107 - Logfile created 01/21/2013 at 19:10:20
# Updated 21/01/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : fefed - FEFED-PC
# Boot Mode : Normal
# Running from : C:\Users\fefed\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\END
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt
File Found : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\searchplugins\Web Search.xml
Folder Found : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Found : C:\Program Files (x86)\Protected Search
Folder Found : C:\Program Files (x86)\Winamp Toolbar
Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search
Folder Found : C:\ProgramData\Partner
Folder Found : C:\ProgramData\Winamp Toolbar
Folder Found : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
Folder Found : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\WinampToolbarData
Folder Found : C:\Users\fefed\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Found : HKCU\Software\ProtectedSearch
Key Found : HKCU\Software\Winamp Toolbar
Key Found : HKCU\Software\Zugo
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678}
Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
Key Found : HKLM\SOFTWARE\Classes\dnUpdate
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Found : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Found : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Found : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Found : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper
Key Found : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\Software\Winamp Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Found : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Found : HKU\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKU\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://newtab.certified-toolbar.com/nie?si=41460&tid=2996&new=true
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=

-\\ Mozilla Firefox v18.0.1 (sk)

File : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\prefs.js

Found : user_pref("browser.newtab.url", "hxxp://newtab.certified-toolbar.com/nff?si=41460&tid=2996&new=true"[...]
Found : user_pref("browser.search.defaultengine", "Web Search");
Found : user_pref("browser.search.defaultenginename", "Web Search");
Found : user_pref("browser.search.order.1", "Web Search");
Found : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=");

-\\ Google Chrome v12.0.742.91

File : C:\Users\fefed\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [11995 octets] - [21/01/2013 19:10:20]

########## EOF - C:\AdwCleaner[R1].txt - [12056 octets] ##########

Re: Po návšteve PR SR

Napsal: 21 led 2013 19:29
od fefed
MBAM

Malwarebytes Anti-Malware (Skúšobná verzia) 1.70.0.1100
www.malwarebytes.org

Verzia databázy: v2013.01.21.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
fefed :: FEFED-PC [administrátor]

Ochrana: Zapnuté

21. 1. 2013 19:13:21
MBAM-log-2013-01-21 (19-28-28).txt

Typ kontroly: Rýchla kontrola
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 210248
Uplynutý čas: 3 min, 22 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 0
(Škodlivé položky neboli zistené)

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 10
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... e&tid=2996) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com/) -> Žiadna úloha nevykonaná.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... e&tid=2996) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com) -> Žiadna úloha nevykonaná.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Škodlivý: (http://search.certified-toolbar.com?si= ... bs=true&q=) Dobrý: (http://www.google.com/) -> Žiadna úloha nevykonaná.

Detegované priečinky: 1
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search (PUP.ProtectedSearch) -> Žiadna úloha nevykonaná.

Detegované súbory: 2
C:\ProgramData\dsgsdgdsgdsgw.pad (Exploit.Drop.GSA) -> Žiadna úloha nevykonaná.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search\Protected Search Settings.lnk (PUP.ProtectedSearch) -> Žiadna úloha nevykonaná.

(koniec)

Re: Po návšteve PR SR

Napsal: 21 led 2013 20:17
od vyosek
:arrow: Nalezy MBAMu smazte

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Delete
  • PC provede opravu, restartuje se a da Vam log (C:\AdwCleaner [S1].txt) , jeho obsah vlozte sem

Re: Po návšteve PR SR

Napsal: 21 led 2013 20:42
od fefed
Opytam sa ako lama: v MBAM všetko čo je zaškrtnuté dať odstániť? nezaškrtnuté sú tam dve položky pup.protected search

Re: Po návšteve PR SR

Napsal: 21 led 2013 21:21
od fefed
tu je ten log

# AdwCleaner v2.107 - Logfile created 01/21/2013 at 21:13:43
# Updated 21/01/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : fefed - FEFED-PC
# Boot Mode : Normal
# Running from : C:\Users\fefed\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\END
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt
File Deleted : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\searchplugins\Web Search.xml
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Deleted : C:\Program Files (x86)\Protected Search
Folder Deleted : C:\Program Files (x86)\Winamp Toolbar
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\ProgramData\Winamp Toolbar
Folder Deleted : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
Folder Deleted : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\WinampToolbarData
Folder Deleted : C:\Users\fefed\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Deleted : HKCU\Software\ProtectedSearch
Key Deleted : HKCU\Software\Winamp Toolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\Software\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://newtab.certified-toolbar.com/nie?si=41460&tid=2996&new=true --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q= --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q= --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q= --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q= --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2996 --> hxxp://www.google.com

-\\ Mozilla Firefox v18.0.1 (sk)

File : C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\prefs.js

C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\user.js ... Deleted !

Deleted : user_pref("browser.newtab.url", "hxxp://newtab.certified-toolbar.com/nff?si=41460&tid=2996&new=true"[...]
Deleted : user_pref("browser.search.defaultengine", "Web Search");
Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Deleted : user_pref("browser.search.order.1", "Web Search");
Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=41460&tid=2996&bs=true&q=");

-\\ Google Chrome v12.0.742.91

File : C:\Users\fefed\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [12100 octets] - [21/01/2013 19:10:20]
AdwCleaner[S1].txt - [11071 octets] - [21/01/2013 21:13:43]

########## EOF - C:\AdwCleaner[S1].txt - [11132 octets] ##########

Re: Po návšteve PR SR

Napsal: 21 led 2013 22:32
od vyosek
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku

Re: Po návšteve PR SR

Napsal: 21 led 2013 23:39
od fefed
Tu je OTL part1

OTL logfile created on: 1/21/2013 10:51:04 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\fefed\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

3.75 Gb Total Physical Memory | 2.19 Gb Available Physical Memory | 58.48% Memory free
7.49 Gb Paging File | 5.67 Gb Available in Paging File | 75.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.66 Gb Total Space | 178.79 Gb Free Space | 39.58% Space Free | Partition Type: NTFS

Computer Name: FEFED-PC | User Name: fefed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2013/01/21 22:48:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\fefed\Desktop\OTL.exe
PRC - [2013/01/19 09:13:20 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/01/09 03:36:50 | 001,808,392 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
PRC - [2012/12/26 22:50:24 | 006,859,264 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files (x86)\Free Download Manager\fdm.exe
PRC - [2012/12/18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/10/30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\afwServ.exe
PRC - [2012/06/11 15:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2011/10/26 19:48:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/09/19 07:17:32 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010/08/30 08:32:24 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2010/06/28 23:22:46 | 000,265,984 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2010/06/22 07:34:48 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/06/22 07:34:48 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/22 07:34:46 | 000,968,272 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/05/21 00:15:00 | 000,110,736 | R--- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2010/04/14 10:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) -- C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2010/04/12 09:40:16 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2010/03/11 22:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/02/09 19:57:46 | 000,704,032 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
PRC - [2010/01/30 00:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/05/14 16:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe


========== Modules (No Company Name) ==========

MOD - [2013/01/19 09:13:18 | 003,022,232 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013/01/13 20:00:00 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll
MOD - [2013/01/13 19:59:45 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/13 19:59:40 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d908c91e24616e6b8d38c9da61038b25\Accessibility.ni.dll
MOD - [2013/01/13 19:59:09 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/13 19:59:03 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/13 19:59:01 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/13 19:58:52 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2013/01/09 03:36:50 | 014,586,888 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
MOD - [2012/12/26 08:13:54 | 003,547,136 | ---- | M] () -- C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll
MOD - [2012/12/26 08:11:36 | 000,105,984 | ---- | M] () -- C:\Program Files (x86)\Free Download Manager\fdmumsp.dll
MOD - [2012/08/12 16:38:18 | 000,173,056 | ---- | M] () -- C:\Users\fefed\AppData\Roaming\Mozilla\Firefox\Profiles\pdpm3e1z.default\extensions\fdm_ffext@freedownloadmanager.org\components\vmsfdmff.dll
MOD - [2010/09/19 07:17:32 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2010/06/28 23:20:54 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2012/10/30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\afwServ.exe -- (avast! Firewall)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/25 17:08:30 | 000,952,096 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/06/11 22:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2010/04/21 00:34:40 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/01/19 09:13:19 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/09 03:36:51 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/06/11 15:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/06/11 15:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010/06/28 23:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/06/22 07:34:48 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010/05/21 00:15:00 | 000,110,736 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2010/04/14 10:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) [Auto | Running] -- C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/11 22:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/01/30 00:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/05/14 16:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/10/30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012/10/30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012/10/30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012/10/30 23:51:55 | 000,262,656 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis2.sys -- (aswNdis2)
DRV:64bit: - [2012/10/30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012/10/30 23:51:55 | 000,021,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2012/10/30 23:51:53 | 000,132,864 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswFW.sys -- (aswFW)
DRV:64bit: - [2012/10/30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012/10/15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/03/08 17:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/10/01 08:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 08:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 08:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 08:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/31 20:41:01 | 000,012,368 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis.sys -- (aswNdis)
DRV:64bit: - [2010/12/29 21:42:50 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/06/25 18:13:18 | 000,342,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010/06/25 18:12:26 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010/06/25 18:12:26 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/06/25 18:12:24 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010/06/25 18:12:24 | 000,102,952 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010/06/17 10:18:28 | 000,246,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/06/03 20:59:00 | 004,171,328 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/05/15 13:48:28 | 000,384,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2010/04/28 07:21:38 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2010/04/28 07:21:38 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2010/04/21 02:15:04 | 006,406,144 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/04/20 23:39:36 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010/04/12 09:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2010/01/27 04:05:00 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009/08/23 10:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://search.certified-toolbar.com?si= ... earchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=i ... AW_skSK412
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: fdm_ffext%40freedownloadmanager.org:1.5.7.6
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.6
FF - prefs.js..extensions.enabledAddons: xmlfiller%40software602.cz:3.16.2
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4
FF - prefs.js..extensions.enabledItems: xmlfiller@software602.cz:3.16.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/11/19 21:34:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/19 09:13:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/21 21:13:48 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/19 09:13:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/21 21:13:48 | 000,000,000 | ---D | M]

[2011/01/09 14:25:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\fefed\AppData\Roaming\mozilla\Extensions
[2011/01/09 14:25:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\fefed\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/01/21 21:13:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\fefed\AppData\Roaming\mozilla\Firefox\Profiles\pdpm3e1z.default\extensions
[2012/12/14 22:01:22 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\Users\fefed\AppData\Roaming\mozilla\Firefox\Profiles\pdpm3e1z.default\extensions\fdm_ffext@freedownloadmanager.org
[2013/01/16 23:53:17 | 000,266,840 | ---- | M] () (No name found) -- C:\Users\fefed\AppData\Roaming\mozilla\firefox\profiles\pdpm3e1z.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2013/01/19 09:13:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/01/19 09:13:11 | 000,000,000 | ---D | M] ("602XML Filler") -- C:\Program Files (x86)\Mozilla Firefox\extensions\xmlfiller@software602.cz
[2013/01/19 09:13:21 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/03/29 12:04:14 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npfiller.dll
[2011/10/26 19:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011/05/06 22:56:46 | 000,001,583 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\atlas-sk.xml
[2011/05/06 22:56:46 | 000,001,380 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\azet-sk.xml
[2011/05/06 22:56:46 | 000,001,479 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\dunaj-sk.xml
[2011/05/06 22:56:46 | 000,001,473 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slovnik-sk.xml
[2012/11/03 17:29:18 | 000,003,269 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml
[2011/05/06 22:56:46 | 000,001,104 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sk.xml
[2011/05/06 22:56:46 | 000,000,830 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\zoznam-sk.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - Extension: DownTango Launcher = C:\Users\fefed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecnaacakjgamipjegmbmblnedllkfiof\1.7_0\
CHR - Extension: avast! WebRep = C:\Users\fefed\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (DownTango Launcher) - {584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll (Simplytech Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (DownTango Launcher) - {584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll (Simplytech Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-304799025-448869381-3581200875-1000..\Run: [EPSON SX130 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /FU "C:\Windows\TEMP\E_S8974.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-304799025-448869381-3581200875-1000..\Run: [Free Download Manager] C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Odoslať obrázok do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Odoslať stránku do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: Prevziať pomocou FDM - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8:64bit: - Extra context menu item: Prevziať video pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Prevziať všetko pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Prevziať vybrané pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Odoslať obrázok do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odoslať stránku do &Zariadenia s rozhraním Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Prevziať pomocou FDM - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Prevziať video pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Prevziať všetko pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Prevziať vybrané pomocou FDM - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://195.28.70.134/kapor2/lib/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E696022-B5E1-4311-A9B3-63F0C5EBB5C3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIV3 - C:\Windows\SysWow64\DivXc32.dll (Hacked with Joy !)
Drivers32: VIDC.DIV4 - C:\Windows\SysWow64\DivXc32f.dll (Hacked with Joy !)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2013/01/21 22:48:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\fefed\Desktop\OTL.exe
[2013/01/21 19:11:37 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Roaming\Malwarebytes
[2013/01/21 19:11:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/21 19:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/01/21 19:11:26 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/01/21 19:11:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/21 19:11:06 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\Programs
[2013/01/21 18:47:42 | 010,156,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\fefed\Desktop\mbam-setup.exe
[2013/01/21 17:26:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013/01/21 17:26:45 | 000,000,000 | ---D | C] -- C:\rsit
[2013/01/21 12:06:49 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{3C507AEE-B29A-45A4-8E65-CFA8356C1A3B}
[2013/01/21 11:35:16 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Roaming\vlc
[2013/01/21 11:35:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/01/21 11:34:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2013/01/21 00:06:34 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{2BC4A48C-F3BC-49C6-BED2-0A1C0F2A88CD}
[2013/01/20 12:06:18 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{F649C941-C95A-4753-9249-540E2E58338F}
[2013/01/20 00:05:59 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{9C272313-DCBF-4116-87F4-9ED65534BC1A}
[2013/01/19 12:05:29 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{E15BF83C-4194-41B9-B120-704EE6214670}
[2013/01/19 09:13:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/01/18 13:13:45 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{0E845860-B2B7-43E6-8C3C-9F5717C30B5C}
[2013/01/18 01:13:29 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{7BC5EF03-39A7-4CAF-A11F-2B74A756AC71}
[2013/01/17 13:13:16 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{8868ABAB-C75B-422F-BB9F-398DC55846DA}
[2013/01/16 23:15:58 | 000,000,000 | ---D | C] -- C:\Users\fefed\Desktop\napalovanie a uprava
[2013/01/16 23:14:19 | 000,000,000 | ---D | C] -- C:\Users\fefed\Desktop\download
[2013/01/16 23:12:38 | 000,000,000 | ---D | C] -- C:\Users\fefed\Desktop\upload
[2013/01/16 16:56:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/01/16 16:56:30 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/01/16 16:56:30 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/16 16:55:39 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2013/01/16 12:22:19 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{A6326E74-1983-4242-A868-8E9725EB4064}
[2013/01/16 00:21:57 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{0CCBDB02-25FE-4090-9BB9-7DBE926C4C35}
[2013/01/15 12:21:29 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{41D13317-61FB-4136-8691-2EBAF5FA247D}
[2013/01/15 00:21:11 | 000,000,000 | ---D | C] -- C:\Users\fefed\AppData\Local\{00045E7C-A877-4442-9061-349BA5B3457C}
[2010/12/29 21:42:50 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\fefed\AppData\Roaming\pcouffin.sys
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2013/01/21 22:53:50 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013/01/21 22:53:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/21 22:48:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\fefed\Desktop\OTL.exe
[2013/01/21 22:36:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/21 21:23:47 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/21 21:23:47 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/21 21:16:21 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/21 21:15:57 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2013/01/21 21:15:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/21 21:15:29 | 3015,884,800 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/21 19:11:28 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/21 18:48:41 | 010,156,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\fefed\Desktop\mbam-setup.exe
[2013/01/21 18:46:20 | 000,574,315 | ---- | M] () -- C:\Users\fefed\Desktop\adwcleaner.exe
[2013/01/21 17:26:15 | 000,935,175 | ---- | M] () -- C:\Users\fefed\Desktop\RSITx64.exe
[2013/01/21 11:35:00 | 000,001,070 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013/01/16 23:53:06 | 000,007,598 | ---- | M] () -- C:\Users\fefed\AppData\Local\Resmon.ResmonCfg
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/21 22:53:50 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013/01/21 19:11:28 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/21 18:46:10 | 000,574,315 | ---- | C] () -- C:\Users\fefed\Desktop\adwcleaner.exe
[2013/01/21 17:26:11 | 000,935,175 | ---- | C] () -- C:\Users\fefed\Desktop\RSITx64.exe
[2013/01/21 11:35:00 | 000,001,070 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/08 16:00:14 | 000,000,809 | ---- | C] () -- C:\Windows\NTIWVEDT.INI
[2012/11/25 19:28:25 | 000,000,201 | ---- | C] () -- C:\Windows\level.ini
[2012/11/03 17:29:14 | 000,015,432 | ---- | C] () -- C:\Windows\Launcher.exe
[2012/08/17 17:14:35 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2011/12/26 20:17:51 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2011/07/26 13:31:14 | 000,007,598 | ---- | C] () -- C:\Users\fefed\AppData\Local\Resmon.ResmonCfg
[2011/05/20 19:09:21 | 000,000,000 | ---- | C] () -- C:\Windows\JCMKR32.INI
[2011/05/09 15:31:54 | 000,000,550 | ---- | C] () -- C:\Users\fefed\AppData\Roaming\AutoGK.ini
[2011/01/27 13:09:13 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/01/27 13:09:07 | 002,582,016 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011/01/27 13:09:07 | 000,810,496 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/01/27 13:09:07 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/01/27 13:09:07 | 000,121,344 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2011/01/27 13:09:06 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/01/05 11:05:09 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/12/29 21:42:50 | 000,099,384 | ---- | C] () -- C:\Users\fefed\AppData\Roaming\inst.exe
[2010/12/29 21:42:50 | 000,007,859 | ---- | C] () -- C:\Users\fefed\AppData\Roaming\pcouffin.cat
[2010/12/29 21:42:50 | 000,001,167 | ---- | C] () -- C:\Users\fefed\AppData\Roaming\pcouffin.inf

Re: Po návšteve PR SR

Napsal: 21 led 2013 23:40
od fefed
OTL part2

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/03/31 08:46:19 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\602XML
[2012/03/28 16:52:51 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Ashampoo
[2011/12/05 16:24:54 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Downloaded Installations
[2012/11/03 17:29:14 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar
[2012/05/05 14:31:05 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\DVDFab
[2012/07/22 19:50:11 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Epson
[2011/04/01 12:29:41 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\EurekaLog
[2013/01/17 21:06:57 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Free Download Manager
[2011/11/02 13:22:07 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\GHISLER
[2011/04/01 12:18:58 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\HamsterSoft
[2011/04/27 17:33:51 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\HandBrake
[2012/12/15 22:47:21 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Jewel Match 3
[2011/12/05 16:14:28 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Nitro PDF
[2011/01/27 19:02:40 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Paradoxx
[2012/04/20 05:44:58 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\SoftGrid Client
[2011/01/09 14:25:43 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Thunderbird
[2011/01/06 15:21:57 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\TP
[2011/05/06 16:34:53 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Uniblue
[2011/06/28 20:46:03 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\VitySoft
[2011/04/27 13:50:00 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\VobSub
[2012/04/04 11:06:48 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Vso
[2011/09/07 13:08:30 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Windows Live Writer
[2011/04/01 11:36:55 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\XMedia Recode

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009/07/14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 06:08:49 | 000,028,842 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/29 12:48:04 | 000,000,932 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2010/12/29 12:48:06 | 000,000,936 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2011/05/06 16:11:46 | 000,000,340 | ---- | C] () -- C:\Windows\Tasks\DriverScanner.job
[2012/04/25 20:22:13 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010/11/20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010/11/20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009/07/14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009/07/14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010/11/20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010/11/20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2011/02/26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/02/04 11:49:48 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/02/04 11:49:48 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/02/04 11:49:48 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/02/04 11:49:48 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: HAL.DLL >
[2009/07/14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010/11/20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010/11/20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll

< MD5 for: SCECLI.DLL >
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SERVICES.EXE >
[2009/07/14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | ---- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2011/04/25 06:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2011/09/29 18:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010/11/20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011/06/21 07:16:55 | 001,888,128 | ---- | M] (Microsoft Corporation) MD5=5279D4DD69C7C71524B8E7A5746D15CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_0f8ed978993fa916\tcpip.sys
[2010/06/14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2012/03/30 11:19:17 | 001,877,872 | ---- | M] (Microsoft Corporation) MD5=5EFD096DEF47F8B88EF591DA92143440 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_0faa5514992a39a7\tcpip.sys
[2011/04/25 06:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
[2012/03/30 12:09:53 | 001,895,280 | ---- | M] (Microsoft Corporation) MD5=624C5B3AA4C99B3184BB922D9ECE3FF0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_0f140fa780164fde\tcpip.sys
[2012/08/22 19:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2010/04/09 12:06:28 | 001,898,376 | ---- | M] (Microsoft Corporation) MD5=7FC877A25796D8ADF539E64703FCA7E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16569_none_0f2ca8c580036f65\tcpip.sys
[2012/03/30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2010/06/14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009/07/14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2011/04/25 06:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2011/06/21 07:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
[2010/04/09 08:56:29 | 001,892,232 | ---- | M] (Microsoft Corporation) MD5=A9C0F786AC1F736891D05CE0A1D29DEB -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20687_none_0f9ea52499331463\tcpip.sys
[2011/09/29 17:17:51 | 001,886,064 | ---- | M] (Microsoft Corporation) MD5=AC3E29880DB5659532A1AA3439304A43 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_0fad20ca992955d7\tcpip.sys
[2012/03/30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011/04/25 07:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011/06/21 07:27:14 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=B9D87C7707F058AC652A398CD28DE14B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_0f4d1e3b7feb1307\tcpip.sys
[2012/10/03 18:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2011/06/21 07:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
[2011/09/29 17:24:44 | 001,897,328 | ---- | M] (Microsoft Corporation) MD5=F18F56EFC0BFB9C87BA01C37B27F4DA5 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_0f170e9f80139ebc\tcpip.sys
[2012/08/22 19:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
[2011/09/29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010/11/20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | ---- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< >

< %systemroot%*.* /U /s >
[6 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[9 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[4 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp files -> C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\1c30e7b906a90a38f6bb46680cbf352b\*.tmp files -> C:\Windows\SoftwareDistribution\Download\1c30e7b906a90a38f6bb46680cbf352b\*.tmp -> ]
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[3 C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp -> ]
[3 C:\Windows\SysWOW64\*.tmp files -> C:\Windows\SysWOW64\*.tmp -> ]
[3 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp -> ]
[77 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011/03/31 08:46:19 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\602XML
[2012/09/06 19:14:21 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Adobe
[2012/03/28 16:52:51 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Ashampoo
[2010/12/29 12:14:26 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\ATI
[2011/01/05 11:05:17 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Corel
[2011/12/05 16:24:54 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Downloaded Installations
[2012/11/03 17:29:14 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar
[2011/04/01 13:28:37 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\dvdcss
[2012/05/05 14:31:05 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\DVDFab
[2012/07/22 19:50:11 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Epson
[2011/04/01 12:29:41 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\EurekaLog
[2013/01/17 21:06:57 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Free Download Manager
[2011/11/02 13:22:07 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\GHISLER
[2010/12/29 12:43:08 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Google
[2011/04/01 12:18:58 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\HamsterSoft
[2011/04/27 17:33:51 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\HandBrake
[2010/12/29 12:12:35 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Identities
[2012/07/22 19:33:59 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\InstallShield
[2012/12/15 22:47:21 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Jewel Match 3
[2010/12/29 12:13:08 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Macromedia
[2013/01/21 19:11:37 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Malwarebytes
[2009/07/14 08:44:38 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Media Center Programs
[2013/01/03 10:18:22 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Media Player Classic
[2012/06/19 12:44:35 | 000,000,000 | --SD | M] -- C:\Users\fefed\AppData\Roaming\Microsoft
[2010/12/29 12:49:45 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Mozilla
[2011/12/05 16:14:28 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Nitro PDF
[2011/01/27 19:02:40 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Paradoxx
[2012/04/20 05:44:58 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\SoftGrid Client
[2011/01/09 14:25:43 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Thunderbird
[2011/01/06 15:21:57 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\TP
[2011/05/06 16:34:53 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Uniblue
[2011/06/28 20:46:03 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\VitySoft
[2013/01/21 11:35:29 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\vlc
[2011/04/27 13:50:00 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\VobSub
[2012/04/04 11:06:48 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Vso
[2013/01/02 11:02:56 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Winamp
[2011/09/07 13:08:30 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\Windows Live Writer
[2010/12/29 22:23:47 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\WinRAR
[2011/04/01 11:36:55 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\XMedia Recode

< %APPDATA%\*.exe /s >
[2012/04/04 11:06:47 | 000,099,384 | ---- | M] () -- C:\Users\fefed\AppData\Roaming\inst.exe
[2013/01/02 17:42:18 | 007,679,249 | ---- | M] (FreeDownloadManager.ORG ) -- C:\Users\fefed\AppData\Roaming\Free Download Manager\Update\fdminst.exe
[2002/12/11 09:20:18 | 000,061,440 | ---- | M] (Gabest) -- C:\Users\fefed\AppData\Roaming\VobSub\submux.exe
[2002/12/11 09:20:40 | 000,098,304 | ---- | M] (Gabest) -- C:\Users\fefed\AppData\Roaming\VobSub\subresync.exe
[2011/04/27 13:50:00 | 000,059,134 | ---- | M] () -- C:\Users\fefed\AppData\Roaming\VobSub\Uninstall VobSub.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2012/11/14 03:14:59 | 009,738,240 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[3 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2013/01/21 22:36:00 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/01/21 21:15:57 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\DriverScanner.job
[2013/01/21 21:16:21 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013/01/21 22:53:00 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >
[2012/11/14 03:14:59 | 009,738,240 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[3 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[3 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"swg" = "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2010/07/15 12:43:07 | 000,039,408 | ---- | M] (Google Inc.)
"Free Download Manager" = "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun -- [2012/12/26 22:50:24 | 006,859,264 | ---- | M] (FreeDownloadManager.ORG)
"EPSON SX130 Series" = C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /FU "C:\Windows\TEMP\E_S8974.tmp" /EF "HKCU"

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2013/01/19 09:13:20 | 000,917,400 | ---- | M] (Mozilla Corporation) MD5=D7826A7440444F40E0406CF37FD2FA88 -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012/11/14 03:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013/01/21 22:53:50 | 000,000,512 | ---- | M] () MD5=EED49572995C16F0318AC76E426D7D2D -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2010/05/17 21:33:31 | 003,727,613 | ---- | M] () -- \hudba\Armageddon (1998)\14. Ben Affleck, Liv Tyler, Steven Tyler - Animal Crackers.mp3
[1996/12/24 23:32:00 | 000,019,344 | ---- | M] () -- \Program Files (x86)\Oldgames\Settlers 2\C\S2\univbe\crack.exe
[2012/11/03 18:15:03 | 000,005,369 | ---- | M] () -- \Users\fefed\AppData\Roaming\VitySoft\FRD\plugins\crackle.frp
[2012/12/19 23:25:22 | 732,299,264 | ---- | M] () -- \video\xxx\XXXParody\Nutcracker-XXX Parody-www.parody.cc\nutcracker1 by_tecci.avi
[2012/12/28 09:13:46 | 734,533,632 | ---- | M] () -- \video\xxx\XXXParody\Nutcracker-XXX Parody-www.parody.cc\nutcracker2 by_tecci.avi

< *keygen* /s >

< *loader* /s >
[2011/01/09 18:49:03 | 000,545,792 | ---- | M] () -- \fero\Downloads\USDownloader.exe
[2011/01/09 18:38:35 | 000,000,506 | -HS- | M] () -- \fero\Downloads\USDownloader.exe.manifest
[2011/01/11 12:02:19 | 000,003,089 | ---- | M] () -- \fero\Downloads\USDownloader.ini
[2011/01/11 11:36:42 | 007,124,920 | ---- | M] () -- \fero\Downloads\USDownloader.log
[2011/01/11 12:02:19 | 000,000,009 | ---- | M] () -- \fero\Downloads\USDownloader.lst
[2011/01/11 12:02:18 | 000,000,009 | ---- | M] () -- \fero\Downloads\USDownloader.lst1.bak
[2011/01/11 11:36:43 | 000,000,282 | ---- | M] () -- \fero\Downloads\USDownloader.lst2.bak
[2011/01/11 11:30:43 | 000,000,216 | ---- | M] () -- \fero\Downloads\USDownloader.lst3.bak
[2011/01/11 11:30:23 | 000,000,009 | ---- | M] () -- \fero\Downloads\USDownloader.lst4.bak
[2011/01/11 04:05:06 | 000,006,132 | ---- | M] () -- \fero\Downloads\USDownloader.lst5.bak
[2011/01/11 03:01:24 | 000,006,136 | ---- | M] () -- \fero\Downloads\USDownloader.lst6.bak
[2011/01/11 01:34:31 | 000,006,069 | ---- | M] () -- \fero\Downloads\USDownloader.lst7.bak
[2011/01/11 00:08:23 | 000,006,002 | ---- | M] () -- \fero\Downloads\USDownloader.lst8.bak
[2011/01/10 22:41:35 | 000,005,935 | ---- | M] () -- \fero\Downloads\USDownloader.lst9.bak
[2011/01/09 18:37:59 | 006,241,261 | ---- | M] () -- \fero\Downloads\USDownloader135.zip
[2011/01/09 18:47:09 | 000,034,304 | ---- | M] () -- \fero\Downloads\Plugins\SexUploader.plg
[2010/10/12 14:35:38 | 000,616,448 | ---- | M] () -- \Program Files (x86)\CobraShare_DUploader\CSDUploader.exe
[2007/10/24 01:52:00 | 000,114,688 | ---- | M] () -- \Program Files (x86)\Epson Software\Easy Photo Print\APFLoaderV13.dll
[2007/10/24 01:52:00 | 000,069,632 | ---- | M] () -- \Program Files (x86)\Epson Software\Easy Photo Print\EpAPFLoader.dll
[2007/10/24 01:52:00 | 000,102,400 | ---- | M] () -- \Program Files (x86)\Epson Software\Easy Photo Print\EpAPFLoader2006.dll
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\chat\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\facebook\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\facebooklike\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\fbsharedservices\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\featured\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\games\7.1.391\js\shared\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Program Files (x86)\Microsoft\BingBar\7.1.391.0\scripts\io\downloader.js
[2011/01/23 16:43:09 | 000,159,744 | ---- | M] () -- \Program Files (x86)\Share Rapid Uploader\sr_uploader.exe
[2009/12/12 15:11:16 | 000,054,784 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2011/11/12 06:43:36 | 000,001,040 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\CobraShare DUploader\CS DUploader.lnk
[2011/11/12 06:43:36 | 000,001,025 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\CobraShare DUploader\Uninstall CobraShare DUploader.lnk
[2011/01/23 16:10:33 | 000,000,053 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Aplikace Share Rapid Uploader na internetu.url
[2011/01/23 16:10:33 | 000,001,025 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Odinstalovat aplikaci Share Rapid Uploader.lnk
[2011/01/23 16:10:33 | 000,001,040 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Share Rapid Uploader.lnk
[2011/11/12 06:42:30 | 004,005,808 | ---- | M] () -- \up\DUploader131.exe
[2013/01/12 11:59:22 | 000,074,276 | ---- | M] () -- \up\FileUploader.err
[2012/12/30 14:08:19 | 001,414,144 | ---- | M] () -- \up\FileUploader.exe
[2013/01/12 09:34:24 | 000,077,191 | ---- | M] () -- \up\FileUploader.log
[2013/01/14 20:50:48 | 000,117,664 | ---- | M] () -- \up\FileUploader.nast
[2012/12/12 10:48:09 | 000,536,064 | ---- | M] () -- \up\USDownloader.exe
[2011/01/09 13:30:34 | 000,000,506 | -HS- | M] () -- \up\USDownloader.exe.manifest
[2012/12/31 16:42:06 | 000,003,453 | ---- | M] () -- \up\USDownloader.ini
[2012/12/31 16:42:01 | 583,788,908 | ---- | M] () -- \up\USDownloader.log
[2012/12/31 16:42:06 | 000,002,785 | ---- | M] () -- \up\USDownloader.lst
[2012/12/31 16:38:55 | 000,002,763 | ---- | M] () -- \up\USDownloader.lst1.bak
[2012/12/31 16:37:57 | 000,000,009 | ---- | M] () -- \up\USDownloader.lst2.bak
[2012/12/12 11:00:03 | 000,000,009 | ---- | M] () -- \up\USDownloader.lst3.bak
[2012/12/12 11:00:02 | 000,000,009 | ---- | M] () -- \up\USDownloader.lst4.bak
[2012/12/12 10:50:11 | 000,005,127 | ---- | M] () -- \up\USDownloader.lst5.bak
[2012/12/12 10:49:34 | 000,005,353 | ---- | M] () -- \up\USDownloader.lst6.bak
[2012/12/12 10:49:19 | 000,000,009 | ---- | M] () -- \up\USDownloader.lst7.bak
[2012/12/12 10:49:14 | 000,000,009 | ---- | M] () -- \up\USDownloader.lst8.bak
[2012/12/12 10:48:56 | 000,000,448 | ---- | M] () -- \up\USDownloader.lst9.bak
[2011/01/09 13:51:09 | 000,015,737 | ---- | M] () -- \up\Langs\USDownloader.ara.lng
[2011/01/09 13:51:10 | 000,017,772 | ---- | M] () -- \up\Langs\USDownloader.bul.lng
[2007/06/14 14:02:10 | 000,018,268 | ---- | M] () -- \up\Langs\USDownloader.cat.lng
[2011/01/11 23:02:09 | 000,013,529 | ---- | M] () -- \up\Langs\USDownloader.chs.lng
[2012/12/31 16:41:27 | 000,016,996 | ---- | M] () -- \up\Langs\USDownloader.cze.lng
[2011/01/09 13:51:11 | 000,017,527 | ---- | M] () -- \up\Langs\USDownloader.de.lng
[2011/01/09 13:51:13 | 000,017,786 | ---- | M] () -- \up\Langs\USDownloader.du.lng
[2007/06/14 14:03:14 | 000,017,427 | ---- | M] () -- \up\Langs\USDownloader.ell.lng
[2008/06/24 23:56:06 | 000,016,557 | ---- | M] () -- \up\Langs\USDownloader.eng.lng
[2011/01/09 13:51:14 | 000,016,526 | ---- | M] () -- \up\Langs\USDownloader.est.lng
[2008/04/20 01:05:08 | 000,019,089 | ---- | M] () -- \up\Langs\USDownloader.fre.lng
[2011/01/09 13:51:14 | 000,017,548 | ---- | M] () -- \up\Langs\USDownloader.gal.lng
[2011/01/09 13:51:15 | 000,017,916 | ---- | M] () -- \up\Langs\USDownloader.hrv.lng
[2011/01/09 13:51:16 | 000,019,443 | ---- | M] () -- \up\Langs\USDownloader.hu.lng
[2007/06/19 13:48:14 | 000,017,335 | ---- | M] () -- \up\Langs\USDownloader.it.lng
[2011/01/09 13:51:17 | 000,015,407 | ---- | M] () -- \up\Langs\USDownloader.ko.lng
[2011/01/09 13:51:18 | 000,016,525 | ---- | M] () -- \up\Langs\USDownloader.lit.lng
[2011/01/09 13:51:19 | 000,018,195 | ---- | M] () -- \up\Langs\USDownloader.lv.lng
[2007/12/16 04:50:52 | 000,016,839 | ---- | M] () -- \up\Langs\USDownloader.nor.lng
[2011/01/09 13:51:22 | 000,017,898 | ---- | M] () -- \up\Langs\USDownloader.pl.lng
[2007/06/18 22:11:58 | 000,017,909 | ---- | M] () -- \up\Langs\USDownloader.ptbr.lng
[2011/01/09 13:51:23 | 000,017,758 | ---- | M] () -- \up\Langs\USDownloader.ro.lng
[2011/01/09 13:51:24 | 000,013,851 | ---- | M] () -- \up\Langs\USDownloader.rus.lng
[2011/01/09 13:51:25 | 000,016,918 | ---- | M] () -- \up\Langs\USDownloader.ser.lng
[2011/12/19 04:20:51 | 000,016,760 | ---- | M] () -- \up\Langs\USDownloader.sk.lng
[2011/01/09 13:51:26 | 000,018,346 | ---- | M] () -- \up\Langs\USDownloader.spa.lng
[2011/01/09 13:51:27 | 000,016,308 | ---- | M] () -- \up\Langs\USDownloader.swe.lng
[2011/01/09 13:51:27 | 000,017,057 | ---- | M] () -- \up\Langs\USDownloader.thai.lng
[2011/01/11 23:02:10 | 000,017,726 | ---- | M] () -- \up\Langs\USDownloader.tr.lng
[2008/05/06 01:41:22 | 000,013,624 | ---- | M] () -- \up\Langs\USDownloader.tw.lng
[2007/06/14 14:05:38 | 000,017,043 | ---- | M] () -- \up\Langs\USDownloader.ukr.lng
[2011/01/09 13:48:26 | 000,034,304 | ---- | M] () -- \up\Plugins\SexUploader.plg
[2011/11/12 06:43:36 | 000,001,040 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\CobraShare DUploader\CS DUploader.lnk
[2011/11/12 06:43:36 | 000,001,025 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\CobraShare DUploader\Uninstall CobraShare DUploader.lnk
[2011/01/23 16:10:33 | 000,000,053 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Aplikace Share Rapid Uploader na internetu.url
[2011/01/23 16:10:33 | 000,001,025 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Odinstalovat aplikaci Share Rapid Uploader.lnk
[2011/01/23 16:10:33 | 000,001,040 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Share Rapid Uploader\Share Rapid Uploader.lnk
[2012/01/31 15:16:24 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\Chat_cf57b0088a3b4f61a0bfaad0ba784240\7.1.361\js\downloader.js
[2012/01/31 15:16:24 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\Facebook_76c7b5062c4e4be69d843ace834517ec\7.1.361\js\downloader.js
[2011/10/12 15:04:18 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\Facebook_76c7b5062c4e4be69d843ace834517ec\7.1.403\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\FacebookLike_08e57417866d4faa981702780b0d36c4\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\fbsharedservices_bb9c6e8b961d477e9ec95f9698bde610\7.1.391\js\downloader.js
[2011/10/12 14:04:18 | 000,006,643 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\BingBar\Apps\Featured_ce53daa069a4a3ad2e3d7d81081f340d\7.1.391\js\downloader.js
[2010/09/22 13:16:48 | 000,005,273 | ---- | M] () -- \Users\fefed\AppData\Local\Microsoft\Toolbar\Applications\loader.xap
[2011/01/23 16:10:33 | 000,001,046 | ---- | M] () -- \Users\fefed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Share Rapid Uploader.lnk
[2011/11/12 06:43:36 | 000,001,022 | ---- | M] () -- \Users\fefed\Desktop\download\DUploader.lnk
[2011/01/11 22:31:27 | 000,000,869 | ---- | M] () -- \Users\fefed\Desktop\download\USDownloader.lnk
[2013/01/16 23:15:17 | 000,001,040 | ---- | M] () -- \Users\fefed\Desktop\upload\CS DUploader.lnk
[2011/10/21 20:28:49 | 000,000,869 | ---- | M] () -- \Users\fefed\Desktop\upload\FileUploader.lnk
[2011/01/23 16:10:33 | 000,001,022 | ---- | M] () -- \Users\fefed\Desktop\upload\Share Rapid Uploader.lnk
[2011/05/16 13:42:58 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2012/11/30 05:45:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009/07/14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[3 \Windows\System32\*.tmp files -> \Windows\System32\*.tmp -> ]
[2012/11/30 05:45:15 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009/07/14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[3 \Windows\SysWOW64\*.tmp files -> \Windows\SysWOW64\*.tmp -> ]
[2009/07/14 02:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009/07/14 02:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 08:18:33 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16816_none_66f39ad995474166\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/02 07:23:09 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16823_none_66e5ca0f95521152\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 06:04:54 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_66c2596d956d1920\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/18 16:22:27 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17107_none_66ff46fd953e6c5c\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 18:28:57 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17135_none_66dcd6a595588d81\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 06:41:11 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17179_none_66b5981d957562a1\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 07:39:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.20978_none_673e58b0ae93bb84\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 06:06:43 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_67770e0aae6a7c68\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 19:46:36 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21306_none_6787e564ae5ceff6\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 18:26:17 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21335_none_67667556ae762a72\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 06:36:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21386_none_67316604ae9dcf7e\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 08:04:21 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17617_none_68daf829926cc6a9\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 07:44:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_68ce27a99276afec\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 06:21:03 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 19:38:32 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17932_none_68c05c919281774d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 18:38:48 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_68a2edab92971725\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 06:38:44 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_68d8d569926ebeb2\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 08:00:38 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21728_none_695ac552ab919bbb\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 07:40:10 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_694ff566ab99b7ac\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 06:12:44 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 19:09:47 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22091_none_6907efc6abd0db81\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 18:35:00 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_6957a248ab947a6d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 06:39:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_69239340abbb38d0\api-ms-win-core-libraryloader-l1-1-0.dll
[2009/07/14 06:37:37 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2009/07/14 06:37:37 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2009/07/14 06:37:37 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2009/07/14 06:37:37 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2009/07/14 06:37:37 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2011/04/28 18:39:30 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011/04/28 18:39:30 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2011/04/28 18:39:30 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2011/04/28 18:39:30 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2011/04/28 18:39:30 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009/07/14 03:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009/07/14 03:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2009/07/14 03:44:20 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2009/07/14 03:13:42 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef.manifest
[2010/01/22 09:31:14 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16508_none_b7752fe386144dba.manifest
[2011/02/05 14:09:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2010/01/22 11:00:30 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20624_none_b7e52bae9f45c00a.manifest
[2011/02/05 14:04:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2010/11/20 05:12:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011/02/05 18:34:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011/02/05 14:09:57 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009/07/14 03:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009/07/14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009/07/14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 07:22:35 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16816_none_0ad4ff55dce9d030\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/02 06:45:50 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16823_none_0ac72e8bdcf4a01c\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 05:19:58 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_0aa3bde9dd0fa7ea\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/18 12:09:17 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17107_none_0ae0ab79dce0fb26\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 17:45:38 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17135_none_0abe3b21dcfb1c4b\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 05:56:23 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.17179_none_0a96fc99dd17f16b\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 06:50:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.20978_none_0b1fbd2cf6364a4e\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 05:12:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_0b587286f60d0b32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 18:42:56 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21306_none_0b6949e0f5ff7ec0\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 17:48:05 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21335_none_0b47d9d2f618b93c\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 05:44:10 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21386_none_0b12ca80f6405e48\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 07:13:36 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17617_none_0cbc5ca5da0f5573\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 06:47:28 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_0caf8c25da193eb6\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 18:32:13 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17932_none_0ca1c10dda240617\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 17:40:37 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_0c845227da39a5ef\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 05:45:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_0cba39e5da114d7c\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/05/14 08:15:40 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21728_none_0d3c29cef3342a85\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/06/03 07:56:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_0d3159e2f33c4676\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/16 05:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/20 18:23:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22091_none_0ce95442f3736a4b\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/04 17:29:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_0d3906c4f3370937\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/11/30 05:46:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_0d04f7bcf35dc79a\api-ms-win-core-libraryloader-l1-1-0.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CC02DF48

< End of report >

Re: Po návšteve PR SR

Napsal: 21 led 2013 23:41
od fefed
Extras

OTL Extras logfile created on: 1/21/2013 10:51:04 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\fefed\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

3.75 Gb Total Physical Memory | 2.19 Gb Available Physical Memory | 58.48% Memory free
7.49 Gb Paging File | 5.67 Gb Available in Paging File | 75.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.66 Gb Total Space | 178.79 Gb Free Space | 39.58% Space Free | Partition Type: NTFS

Computer Name: FEFED-PC | User Name: fefed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{064F8CDB-68CC-45C7-B103-77849DFF24CB}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{116A0A14-5647-400B-8B51-87124C34B189}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{21C10486-20B5-4FCD-AE1D-4896D3C2DE10}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2764A9C6-78EA-4DE3-A9C7-FBBD0C009A1A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{304A688E-8EB1-4123-9ED1-B564C0B5EDE7}" = rport=137 | protocol=17 | dir=out | app=system |
"{3698EB87-86F5-4821-991C-606EA1FDB60E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{3C445670-C5B4-4913-AA5A-4842BA962362}" = lport=138 | protocol=17 | dir=in | app=system |
"{45DF38A1-CA9D-48FF-A211-ED44B10D5B3A}" = rport=138 | protocol=17 | dir=out | app=system |
"{63033F24-D191-45BF-972B-C72707641427}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{6BCFA58D-40C2-4143-B870-B461A89FC7BA}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{79F422C3-ECD1-429E-9A79-8D819A94AD56}" = lport=139 | protocol=6 | dir=in | app=system |
"{7B1F04B5-8B24-45B5-8FB4-064B60B50691}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{8BCF5723-F0E6-4542-B712-451B90E38BC8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8EE09E65-2A92-45B6-9B11-9461FF369448}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A2CFE676-9B9F-4510-8535-9C7EB1635C2A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AEC68428-A577-4D74-8D36-4162CB179188}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{B10F6AA6-021F-45F6-B23B-30CB287E4B82}" = lport=137 | protocol=17 | dir=in | app=system |
"{C4A91D2F-C1D7-4089-A4F5-3D25A93E061E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CA0C05FE-2362-4AED-99E6-3BF3F97A1BFE}" = lport=445 | protocol=6 | dir=in | app=system |
"{D331A724-4FA9-4C92-BD72-599C0D4C7BEA}" = rport=139 | protocol=6 | dir=out | app=system |
"{D9544022-3CC7-4A64-8DFA-169E516F269F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{DBBF9283-8846-4BF0-8C36-5453EBFEBCBB}" = rport=2869 | protocol=6 | dir=out | app=system |
"{DFEB934A-D2F8-463D-96E5-5B5AE821A7CE}" = rport=445 | protocol=6 | dir=out | app=system |
"{EA411F4E-5D88-430C-9398-FCD5CD072664}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0BB013B0-CF2D-45DE-A6D6-9758F5A5A480}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\launch4j-tmp\frd.exe |
"{188A9308-2DA3-4C8B-B5EC-43C8F850C108}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{1FF56833-AC06-44F3-B2E5-A917BF4FA574}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{211F1A9E-EBD4-438A-B591-11DB591ABD4F}" = dir=in | app=c:\program files (x86)\protected search\protectedsearch.exe |
"{23815EC8-9E25-4B72-9AF4-6E93CDDCFF92}" = dir=in | app=c:\program files (x86)\acer\acer vcm\vc.exe |
"{26BCC1A7-C074-4805-86A8-A611FE570195}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2A350582-1E20-4D14-BB6A-9A36C06DAE06}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2AA21F68-F99B-4B3B-94BC-AB57FF70858B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{37760614-62AE-442E-B6BA-437C0849793E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{50938D25-2251-4C21-8539-E9328260208C}" = dir=in | app=c:\program files (x86)\acer\acer vcm\rs_service.exe |
"{55E426DC-1537-4845-8195-41595F2E538F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6AB2CFF9-02E8-4015-AA90-ED8F194B95BC}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{76FE045E-C48C-450A-ADC9-0DE2BD31D204}" = dir=out | app=c:\program files (x86)\protected search\protectedsearch.exe |
"{8343A8B2-1BA2-4506-A197-C0AE5914AE61}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{868CDDF5-71F6-4DD6-825F-7DE9F01532B1}" = dir=in | app=c:\program files (x86)\protected search\protectedsearch.exe |
"{8CFCDA83-9660-4AE3-B331-9FB1BA16176F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{98C2F7B2-F3F9-48A1-9449-6688FDCE6832}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{ABCE4A1A-FB43-496F-BC62-7B5A6BD4E4A5}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{C239F387-7501-40DA-99C4-BE3A1FBAE24E}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CDB4A266-DEDE-4A73-BEA2-8ED4B9CC6C5B}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{D1FE6B52-B976-4B50-B05D-DE9FF25486B4}" = dir=out | app=c:\program files (x86)\protected search\protectedsearch.exe |
"{E5ADF7A7-99DE-4D5C-855F-F47B7403DCE9}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{EC997D00-BF2C-4137-A298-21D7D70DEAEB}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\launch4j-tmp\frd.exe |
"{F910B18F-CF33-4BB8-B52D-1AE5467F3630}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{FCA4333E-A717-4951-AD52-FD87D708F259}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"TCP Query User{2BA18089-9507-4355-80D2-B1C1926DA277}C:\program files (x86)\free download manager\fdm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\free download manager\fdm.exe |
"TCP Query User{3322235F-CBB0-449F-9C30-CC7FA5A53BDF}C:\program files (x86)\atube catcher\yct.exe" = protocol=6 | dir=in | app=c:\program files (x86)\atube catcher\yct.exe |
"TCP Query User{7CF343E6-165E-4BA4-B22B-2EDA880EA337}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"TCP Query User{C7121FC3-55D5-4874-9192-712F94C42980}C:\program files (x86)\free download manager\fdm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\free download manager\fdm.exe |
"TCP Query User{DB27D191-1D1C-43B1-B150-5EF81A839990}C:\program files (x86)\java\jre6\launch4j-tmp\frd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\launch4j-tmp\frd.exe |
"UDP Query User{01FD00B1-9F75-4413-81B1-96C445EE417B}C:\program files (x86)\java\jre6\launch4j-tmp\frd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\launch4j-tmp\frd.exe |
"UDP Query User{A9157244-DD54-4C05-8D8C-91269CBCEBB0}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{B4401B7C-7B39-4DE6-9048-26BAFCD2535D}C:\program files (x86)\atube catcher\yct.exe" = protocol=17 | dir=in | app=c:\program files (x86)\atube catcher\yct.exe |
"UDP Query User{DE1EDBB8-E12B-44F6-96C9-BCB1303D5600}C:\program files (x86)\free download manager\fdm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\free download manager\fdm.exe |
"UDP Query User{EFD1A417-F936-4C0B-86B4-89F286A7157F}C:\program files (x86)\free download manager\fdm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\free download manager\fdm.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{16D8AAE0-EA5A-F5AC-D9B7-4B802EC1CB46}" = ccc-utility64
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{21958FA9-A346-4745-E831-98013FA0C203}" = ATI Catalyst Install Manager
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software
"{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources
"{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-041B-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Slovak) 2007
"{90140000-006D-041B-1000-0000000FF1CE}" = Microsoft Office Klikni a spusti 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A0CC1C12-528A-42A3-B9A3-10C4F9E65C9E}" = Windows Live Family Safety
"{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"DVDFab 8 Qt Retail_is1" = DVDFab 8.0.9.2 (12/05/2011) Qt
"Elantech" = ETDWare PS/2-x64 7.0.6.5_WHQL
"EPSON SX130 Series" = EPSON SX130 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"WinRAR archiver" = WinRAR

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{191348A7-13EC-2650-6ABC-1C1D2423A40C}" = CCC Help German
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23D5D3E2-26F4-556E-B798-09B7CC796BD1}" = CCC Help Portuguese
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24B0F483-4D4D-49BD-858A-AFCA5C3552FD}_is1" = CobraShare DUploader 1.3.1
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 11
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3653CD74-6658-CEBB-CD6D-C0307AD95C42}" = CCC Help Dutch
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{4460DD07-4171-C90E-1D90-B77AC15A1091}" = CCC Help Danish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B0E901E-F7E0-E568-85C8-2EA65A1BDAF5}" = CCC Help Turkish
"{4D20ABBF-B73C-A373-5BAB-D4B0339B6A0A}" = CCC Help Japanese
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5A3D0EE7-72E0-B579-425A-098B091709A8}" = CCC Help Chinese Standard
"{5C1F18D2-F6B7-4242-B803-B5A78648185D}" = Corel WinDVD
"{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack
"{5FB9AC96-BC36-7EED-7DCF-8B2FF4437A59}" = ccc-core-static
"{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials
"{65E556A8-6CA0-22A4-6818-6CD068DA0AFD}" = Catalyst Control Center Graphics Full New
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D2F0A26-ECEA-49CE-833C-9A6125F3D5E8}" = Doplnok programu Messenger
"{6F29746D-92E6-F783-A0F4-4F096E78D050}" = Catalyst Control Center Graphics Full Existing
"{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B96F0C0-BDD3-A367-11CC-45597C63ABEB}" = Catalyst Control Center Graphics Light
"{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8595562C-577E-5EF2-D41B-ED9179C11148}" = CCC Help Thai
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{892994D3-5963-4877-A8DB-629607E8E928}" = 602XML Filler
"{8A17C27D-0325-400C-8AA9-DAA6B16CBD74}" = Epson Event Manager
"{8A7F7E19-9019-D754-4BCF-48C6439F99C3}" = CCC Help English
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DB37F8B-12E1-E616-3D73-8D09FC012107}" = CCC Help Swedish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0016-041B-0000-0000000FF1CE}_HOMESTUDENTR_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}_HOMESTUDENTR_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}_HOMESTUDENTR_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_HOMESTUDENTR_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-040E-0000-0000000FF1CE}_HOMESTUDENTR_{0AD4BB83-13B4-4C9D-9BAC-7F64E0B2D5D7}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_HOMESTUDENTR_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-041B-1000-0000000FF1CE}_HOMESTUDENTR_{8382BA92-20E3-47B6-971B-F673F0492D4E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}_HOMESTUDENTR_{8382BA92-20E3-47B6-971B-F673F0492D4E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-041B-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Slovak) 2007
"{90120000-00A1-041B-0000-0000000FF1CE}_HOMESTUDENTR_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90140011-0066-041B-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Slovenčina
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.3
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A02D7029-C4EF-44C1-9FD4-C0D3CA518113}" = Epson Easy Photo Print 2
"{A23514CE-CE89-43D1-BAB2-685E49538766}" = CCC Help Hungarian
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3389C72-1782-4BB4-BBAA-33345DE52E3F}" = Windows Live Messenger
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.5) - Czech
"{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B2F7D09B-E3AE-8BCA-A798-C8DA98D0A9AC}" = CCC Help Norwegian
"{B376DE99-5243-D03D-B51D-4BE193EA7985}" = CCC Help Greek
"{B536CA63-8BB3-4027-A495-84DD9FED17EC}" = Windows Live Sync
"{bc67079b-1f07-409b-8ac3-b4edd9b1957c}_is1" = DownTango Launcher 1.7
"{BDBAEB81-FACA-1CF6-9A74-8EB532F0012D}" = CCC Help Spanish
"{C2BE0404-9252-8657-6839-EA2B60EA3CE8}" = Catalyst Control Center Localization All
"{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}" = Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia
"{CB8D8129-4592-3EB9-4976-68515DC4D0C1}" = CCC Help French
"{CC757D67-711D-4459-AB6A-8835CA5BF699}" = CCC Help Chinese Traditional
"{CC9D85AF-30DB-55A0-1E00-976BFDAF04D0}" = CCC Help Russian
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.188.706
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC8F6F65-558C-1C57-8F08-D367F6C19988}" = CCC Help Korean
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF57F301-0416-55BA-8287-5E929615D967}" = CCC Help Polish
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3CA43BE-C574-1938-E60B-E7A4486A1DAD}" = CCC Help Finnish
"{E4CD072D-13E1-5EAB-A350-76E7F8A2DD51}" = Catalyst Control Center Graphics Previews Common
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EF48185C-1BE3-3EE0-22C5-EDE82A08C105}" = CCC Help Italian
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F26A271D-5602-CA19-6456-AEB22BEFE1EA}" = Catalyst Control Center Core Implementation
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail
"{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker
"{FC635D8E-FFBA-4B2C-BE68-A37D56BDFB74}" = Catalyst Control Center - Branding
"{FDAEEEC4-E57E-D75A-E885-EE4E3BEE916B}" = CCC Help Czech
"{FF6BA6F7-67C8-5F93-89B7-F6679D51D869}" = Catalyst Control Center InstallProxy
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Burning Studio 11_is1" = Ashampoo Burning Studio 11 v.11.0.2
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.80
"aTube Catcher" = aTube Catcher
"avast" = avast! Internet Security
"AviSynth" = AviSynth 2.5
"DVD Shrink_is1" = DVD Shrink 3.2
"EPSON Scanner" = EPSON Scan
"EPSON SX130 Series Useg" = Používateľská príručka EPSON SX130 Series
"Free Download Manager_is1" = Free Download Manager 3.9.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Acer Backup Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.8.0
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verzia 1.70.0.1100
"Mozilla Firefox 18.0.1 (x86 sk)" = Mozilla Firefox 18.0.1 (x86 sk)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.Click2Run" = Microsoft Office Klikni a spusti 2010
"PowerISO" = PowerISO
"Protected Search_is1" = Protected Search 1.1
"Share Rapid Uploader_is1" = Uploader 1.0
"Totalcmd" = Total Commander (Remove or Repair)
"upnito.sk Manager_is1" = upnito.sk Manager 2 X64
"VLC media player" = VLC media player 2.0.5
"VobSub" = VobSub v2.23 (Remove Only)
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"7f4182272b52fd8f" = CZShare Manager
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 12/14/2012 6:19:47 PM | Computer Name = fefed-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/15/2012 6:11:08 AM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/15/2012 6:11:09 AM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/15/2012 6:21:51 AM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/15/2012 6:21:51 AM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/16/2012 3:22:39 PM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/16/2012 3:22:39 PM | Computer Name = fefed-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Unable to read the performance counter strings defined for the 01B
language ID. The first DWORD in the Data section contains the Win32 error code.

Error - 12/17/2012 7:31:46 PM | Computer Name = fefed-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/19/2012 3:49:33 PM | Computer Name = fefed-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/20/2012 7:12:18 AM | Computer Name = fefed-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 1/18/2013 10:56:44 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/18/2013 10:56:47 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/18/2013 10:57:58 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/20/2013 6:04:14 AM | Computer Name = fefed-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR6.

Error - 1/20/2013 6:04:14 AM | Computer Name = fefed-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR6.

Error - 1/20/2013 6:04:15 AM | Computer Name = fefed-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR6.

Error - 1/20/2013 1:03:29 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/20/2013 1:03:31 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/20/2013 1:05:08 PM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =

Error - 1/21/2013 3:11:24 AM | Computer Name = fefed-PC | Source = ipnathlp | ID = 31004
Description =


< End of report >

Re: Po návšteve PR SR

Napsal: 22 led 2013 10:17
od vyosek
:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://search.certified-toolbar.com?si= ... id=2996&q={searchTerms}
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5x4712q292
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_skSK412
    IE - HKU\S-1-5-21-304799025-448869381-3581200875-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (DownTango Launcher) - {584d7c26-4cba-4eeb-9e1b-5298a374ebb0} - C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll (Simplytech Ltd.)
    O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Value error.)
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O18 - Protocol\Handler\gopher - No CLSID value found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    [2012/11/03 17:29:14 | 000,000,000 | ---D | M] -- C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar
    [6 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [9 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
    [4 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp files -> C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\Download\1c30e7b906a90a38f6bb46680cbf352b\*.tmp files -> C:\Windows\SoftwareDistribution\Download\1c30e7b906a90a38f6bb46680cbf352b\*.tmp -> ]
    [3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
    [3 C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp files -> C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp -> ]
    [3 C:\Windows\SysWOW64\*.tmp files -> C:\Windows\SysWOW64\*.tmp -> ]
    [3 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp files -> C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\*.tmp -> ]
    [2013/01/21 22:36:00 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
    [2013/01/21 21:15:57 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\DriverScanner.job
    [2013/01/21 21:16:21 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/21 22:53:00 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CC02DF48
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "PWRISOVM.EXE"=-
    "WinampAgent"=-
    "SunJavaUpdateSched"=-
    "Adobe ARM"=-
    
    :files
    C:\Users\fefed\AppData\Local\{*}
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Po návšteve PR SR

Napsal: 22 led 2013 10:35
od fefed
Celý deň som mimo domov, keď budem pri svojom NB, spustím to.

Re: Po návšteve PR SR

Napsal: 22 led 2013 10:54
od vyosek
OK, ja tu budu tez az nejak navecer

Re: Po návšteve PR SR

Napsal: 22 led 2013 19:53
od fefed
Spravil som, ale pri reštarte vyhodilo
The instruction at 0x77811 cca referenced memory at 0x0172fac0. The memory could not be read.
Program ukončíte kliknutím na OK.
Po dlhom vypínaní vyhodilo, že bol náhle vypnutý, odsúhlasil som start normally, po spustení je tu log

1.časť

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Search Bar| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Search Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Start Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Search Page| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Start Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-304799025-448869381-3581200875-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found.
Registry key HKEY_USERS\S-1-5-21-304799025-448869381-3581200875-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{584d7c26-4cba-4eeb-9e1b-5298a374ebb0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{584d7c26-4cba-4eeb-9e1b-5298a374ebb0}\ deleted successfully.
C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\DownTangoToolbar1Toolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\ deleted successfully.
C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\gopher\ deleted successfully.
File Protocol\Handler\gopher - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar\64 folder moved successfully.
C:\Users\fefed\AppData\Roaming\DownTangoToolbar1Toolbar folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3BCA.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3EF6.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8BCA.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA2C4.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC40D.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP3B79.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP44EC.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5AFB.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5CDF.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP6279.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP8B3E.tmp\Microsoft.Ink.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP8B3E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPD58.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder deleted successfully.
C:\Windows\Installer\MSI24CE.tmp deleted successfully.
C:\Windows\Installer\MSIAAFD.tmp deleted successfully.
C:\Windows\Installer\MSIE6EF.tmp deleted successfully.
C:\Windows\Installer\MSIE984.tmp deleted successfully.
C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\wlt4866.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\1c30e7b906a90a38f6bb46680cbf352b\BIT7F4E.tmp deleted successfully.
C:\Windows\System32\sho2123.tmp deleted successfully.
C:\Windows\System32\shoB5DF.tmp deleted successfully.
C:\Windows\System32\shoC6E8.tmp deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\ico29FB.tmp deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icoC5F8.tmp deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icoD328.tmp deleted successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\Tasks\DriverScanner.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
ADS C:\ProgramData\TEMP:CC02DF48 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\PWRISOVM.EXE deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
========== FILES ==========
C:\Users\fefed\AppData\Local\{00045E7C-A877-4442-9061-349BA5B3457C} folder moved successfully.
C:\Users\fefed\AppData\Local\{0017956D-39F4-4EFE-A493-A03496249FA3} folder moved successfully.
C:\Users\fefed\AppData\Local\{004447B8-A88F-49B6-BEDF-62101E07C2DF} folder moved successfully.
C:\Users\fefed\AppData\Local\{0064608A-5D07-4ABA-8F8D-BBE4F113639B} folder moved successfully.
C:\Users\fefed\AppData\Local\{01089812-D84B-4BF3-8B63-2DA49B5B43D7} folder moved successfully.
C:\Users\fefed\AppData\Local\{011B4AC5-84D1-482F-9685-A513FC858208} folder moved successfully.
C:\Users\fefed\AppData\Local\{0151A6C8-89E7-43E1-87B0-B2BEF237893A} folder moved successfully.
C:\Users\fefed\AppData\Local\{0151C3C1-99A4-4255-B8F3-3AA9055AFAE7} folder moved successfully.
C:\Users\fefed\AppData\Local\{0180156D-095F-4135-8AAC-F704890C1191} folder moved successfully.
C:\Users\fefed\AppData\Local\{018BE7A3-F8B4-4BB9-8FC3-F3C5F3F268D1} folder moved successfully.
C:\Users\fefed\AppData\Local\{02229D58-5D06-4D4D-91A6-81F9689F889C} folder moved successfully.
C:\Users\fefed\AppData\Local\{02591333-9B23-417A-84A7-B595BE945439} folder moved successfully.
C:\Users\fefed\AppData\Local\{028DCFCF-16D1-4898-9A73-8C2FC66E881D} folder moved successfully.
C:\Users\fefed\AppData\Local\{02AB9052-3389-4626-B562-255C3F9A540D} folder moved successfully.
C:\Users\fefed\AppData\Local\{02E8AE29-D4B2-4DC9-B263-38E5B288913B} folder moved successfully.
C:\Users\fefed\AppData\Local\{03049DFA-4645-417C-A33B-3EE37B86C1F0} folder moved successfully.
C:\Users\fefed\AppData\Local\{032E59EF-8F0F-4F37-8340-AE481075A1FC} folder moved successfully.
C:\Users\fefed\AppData\Local\{03910A95-A493-4241-986B-E642DE61113A} folder moved successfully.
C:\Users\fefed\AppData\Local\{03AB57D1-F69E-4C36-AE1B-3CC95EE29AF1} folder moved successfully.
C:\Users\fefed\AppData\Local\{03F211D1-FF52-4189-ACA8-C207F38FC22B} folder moved successfully.
C:\Users\fefed\AppData\Local\{040C469A-6309-459F-8869-8201C4F5A1C7} folder moved successfully.
C:\Users\fefed\AppData\Local\{044946A0-5CB9-4108-8737-FEA0C0F7EC15} folder moved successfully.
C:\Users\fefed\AppData\Local\{0486F647-98F0-4212-ABC1-62272E030D4B} folder moved successfully.
C:\Users\fefed\AppData\Local\{04D62C62-5F45-4569-BB02-AD6595F11863} folder moved successfully.
C:\Users\fefed\AppData\Local\{04D7C817-4798-4BEF-B27B-A83CFF818094} folder moved successfully.
C:\Users\fefed\AppData\Local\{04F25125-29E1-4184-8B82-3A5736C70BE9} folder moved successfully.
C:\Users\fefed\AppData\Local\{05126FE7-9369-44CF-B8E0-E6FDFB848EAD} folder moved successfully.
C:\Users\fefed\AppData\Local\{05418341-D9E5-400A-BAFB-7BDE10E5E774} folder moved successfully.
C:\Users\fefed\AppData\Local\{0565CD9D-9131-4E8B-828B-4D4B41BE96F2} folder moved successfully.
C:\Users\fefed\AppData\Local\{057F8C7C-3C1F-4931-81CF-4E764A022581} folder moved successfully.
C:\Users\fefed\AppData\Local\{05899F0C-4F64-4F44-B4AE-5C4DE8AFFCBF} folder moved successfully.
C:\Users\fefed\AppData\Local\{05A70F2A-3A7A-40A6-8565-98A93ACA339C} folder moved successfully.
C:\Users\fefed\AppData\Local\{05BB41E8-AF72-4E16-B3EA-8A2BA31293CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{05FEFC15-79FA-43EB-9218-D254ADE260BF} folder moved successfully.
C:\Users\fefed\AppData\Local\{0654785F-9350-4AE7-9F12-9F54839D1315} folder moved successfully.
C:\Users\fefed\AppData\Local\{06A4B34A-5C3E-452B-818C-41922A823B40} folder moved successfully.
C:\Users\fefed\AppData\Local\{06BD197B-71BD-4F9D-8DBB-1E5179B524B6} folder moved successfully.
C:\Users\fefed\AppData\Local\{06CE410D-5EA5-4437-86A7-8664A390E30A} folder moved successfully.
C:\Users\fefed\AppData\Local\{06E8D156-9963-4EB3-9A77-C84E46327587} folder moved successfully.
C:\Users\fefed\AppData\Local\{06F561DC-5669-43CD-9598-B7299CFCA2A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{070FCA47-3391-43DA-82D1-A3C10EC15556} folder moved successfully.
C:\Users\fefed\AppData\Local\{0714981D-3E02-41BD-996B-E7C1B1447AFA} folder moved successfully.
C:\Users\fefed\AppData\Local\{07639AA0-8DB5-4C6F-8A23-89E21CCDB45C} folder moved successfully.
C:\Users\fefed\AppData\Local\{076912DB-2B54-42FA-81A9-A7DFE3C6BA0C} folder moved successfully.
C:\Users\fefed\AppData\Local\{0778906F-765A-4D56-BC84-7BCA686EE489} folder moved successfully.
C:\Users\fefed\AppData\Local\{07938DEB-C7F3-4C05-855C-11C126CBCF5A} folder moved successfully.
C:\Users\fefed\AppData\Local\{07BE1F69-C033-48EB-B78F-16001DAC1162} folder moved successfully.
C:\Users\fefed\AppData\Local\{07CE7F48-7052-4C19-AB82-2627C4E5B9AB} folder moved successfully.
C:\Users\fefed\AppData\Local\{07F76A3D-246D-4504-A624-2FB92E3E6D0F} folder moved successfully.
C:\Users\fefed\AppData\Local\{082BE3AE-C0B1-4AC5-A82F-CE14C196DDB9} folder moved successfully.
C:\Users\fefed\AppData\Local\{0839E0CD-0774-44E2-B601-D387B737DCDA} folder moved successfully.
C:\Users\fefed\AppData\Local\{085759E1-2527-4C1F-9A67-F049A4D1FFEF} folder moved successfully.
C:\Users\fefed\AppData\Local\{08B5E020-6D1D-4F53-A281-036EA2AA4393} folder moved successfully.
C:\Users\fefed\AppData\Local\{08CA4B9D-9D66-4390-B4EE-B72F84AB8C43} folder moved successfully.
C:\Users\fefed\AppData\Local\{08CAD742-AF1F-48A2-B6E0-7DA157803F10} folder moved successfully.
C:\Users\fefed\AppData\Local\{08E6070D-458E-4D62-8FC4-9EDE9A69974E} folder moved successfully.
C:\Users\fefed\AppData\Local\{09229656-CA56-4FAE-A035-94DDAA6E4CDB} folder moved successfully.
C:\Users\fefed\AppData\Local\{0931FA79-A9C1-4425-A304-0F4C0582EF75} folder moved successfully.
C:\Users\fefed\AppData\Local\{09C1D2B3-84B7-4B8A-A17F-A4912568DF61} folder moved successfully.
C:\Users\fefed\AppData\Local\{09C73FB6-F3BC-4231-93F2-8C7F715C079D} folder moved successfully.
C:\Users\fefed\AppData\Local\{09D4D3D2-FC7A-42EF-8E26-A3A9309950EC} folder moved successfully.
C:\Users\fefed\AppData\Local\{0A1A7318-2FCA-48D3-88FB-123FB9379054} folder moved successfully.
C:\Users\fefed\AppData\Local\{0ACF04A2-27FF-4205-AC7B-F82C9967F4A7} folder moved successfully.
C:\Users\fefed\AppData\Local\{0BB99B60-B28B-4B3A-8F56-FCAC6CD7B06F} folder moved successfully.
C:\Users\fefed\AppData\Local\{0BD74E30-4A2A-4584-9B92-0758B2E77839} folder moved successfully.
C:\Users\fefed\AppData\Local\{0C1BD13B-BEEF-4990-94A6-80F1574905AF} folder moved successfully.
C:\Users\fefed\AppData\Local\{0C2E3ACE-2B01-4462-AA0A-84154EB3EF48} folder moved successfully.
C:\Users\fefed\AppData\Local\{0C5F50B1-404E-461A-87CB-A83FE0525AAD} folder moved successfully.
C:\Users\fefed\AppData\Local\{0C697A80-88A2-4F43-997C-5F8643466D5D} folder moved successfully.
C:\Users\fefed\AppData\Local\{0C9CE8F1-DC66-40E3-A757-50128A91AC44} folder moved successfully.
C:\Users\fefed\AppData\Local\{0CB4DB3F-95B5-42FA-9D96-26A7153A5EBD} folder moved successfully.
C:\Users\fefed\AppData\Local\{0CBA60B2-C88B-4E87-AA29-8DD86C79E1A0} folder moved successfully.
C:\Users\fefed\AppData\Local\{0CCBDB02-25FE-4090-9BB9-7DBE926C4C35} folder moved successfully.
C:\Users\fefed\AppData\Local\{0D08CD02-DB0C-43BE-8112-02F69449937F} folder moved successfully.
C:\Users\fefed\AppData\Local\{0D1A22C2-F93B-48A1-B839-BB5A2447C4F6} folder moved successfully.
C:\Users\fefed\AppData\Local\{0D202423-B43B-4594-8DCA-698068A8B572} folder moved successfully.
C:\Users\fefed\AppData\Local\{0D57174C-3D39-4022-A5E3-50F2869793A4} folder moved successfully.
C:\Users\fefed\AppData\Local\{0DCA9FBB-B985-4719-A72B-63CDC1B47D45} folder moved successfully.
C:\Users\fefed\AppData\Local\{0DFB72EA-7120-48FA-B7F2-666F1FA1AA09} folder moved successfully.
C:\Users\fefed\AppData\Local\{0E845860-B2B7-43E6-8C3C-9F5717C30B5C} folder moved successfully.
C:\Users\fefed\AppData\Local\{0EDAD215-62C7-42F3-8204-70954FC8F359} folder moved successfully.
C:\Users\fefed\AppData\Local\{0EE9F41D-578C-4F84-8972-1DB62848019D} folder moved successfully.
C:\Users\fefed\AppData\Local\{0EEBA1FC-362F-402A-80D7-0A23FD5E32C5} folder moved successfully.
C:\Users\fefed\AppData\Local\{0EF01BEB-4486-44E2-A361-F2D0775C59AE} folder moved successfully.
C:\Users\fefed\AppData\Local\{0F798AF9-3F4E-4172-9E2C-9B6E91F70B75} folder moved successfully.
C:\Users\fefed\AppData\Local\{0F9A7623-BDAC-486E-8F91-2C44E6A12D9B} folder moved successfully.
C:\Users\fefed\AppData\Local\{0FBF8154-998D-46AF-A268-820CBEBB270C} folder moved successfully.
C:\Users\fefed\AppData\Local\{0FCEB3FF-0D20-4728-B35B-306AADADA6B0} folder moved successfully.
C:\Users\fefed\AppData\Local\{1048E3B6-3422-484A-9C33-2BA425AE3448} folder moved successfully.
C:\Users\fefed\AppData\Local\{10513B81-D4E9-4B1B-A74C-9B4548B7B602} folder moved successfully.
C:\Users\fefed\AppData\Local\{10882B5E-4182-4F70-BC18-EA01703C5023} folder moved successfully.
C:\Users\fefed\AppData\Local\{10AD5F2C-D90C-4593-90F5-2266C6A6328E} folder moved successfully.
C:\Users\fefed\AppData\Local\{112EC0C7-413B-4F4D-83BF-91CB437CCA40} folder moved successfully.
C:\Users\fefed\AppData\Local\{119F83FE-7BBC-41FF-A61D-06112E94C819} folder moved successfully.
C:\Users\fefed\AppData\Local\{11B06794-6D0C-409C-BDAF-4E36DAA24FE7} folder moved successfully.
C:\Users\fefed\AppData\Local\{11CCAE52-62F7-49C3-9AEC-BD66C10FC1FC} folder moved successfully.
C:\Users\fefed\AppData\Local\{11D6E774-E983-4286-AD38-0B51CB88C351} folder moved successfully.
C:\Users\fefed\AppData\Local\{12351683-341D-4F52-A376-AA23E2834AE1} folder moved successfully.
C:\Users\fefed\AppData\Local\{1252CFB9-049F-45AC-8A45-AA0C56381CCE} folder moved successfully.
C:\Users\fefed\AppData\Local\{129BDE0F-BADA-4E17-B572-3AA4402AB48B} folder moved successfully.
C:\Users\fefed\AppData\Local\{12CB6202-DB9B-4329-88C5-8873E23DE466} folder moved successfully.
C:\Users\fefed\AppData\Local\{12D47484-CDEF-426E-A3D4-34B48A540B78} folder moved successfully.
C:\Users\fefed\AppData\Local\{12D4F03E-19D9-43EA-935C-473C0A911096} folder moved successfully.
C:\Users\fefed\AppData\Local\{12D77947-1745-4859-BFB3-01A112673D88} folder moved successfully.
C:\Users\fefed\AppData\Local\{12E071D6-0D6C-42DA-AA6A-6CA40B26C9D6} folder moved successfully.
C:\Users\fefed\AppData\Local\{132ED581-F8CD-49A6-BA95-286DC7F95509} folder moved successfully.
C:\Users\fefed\AppData\Local\{138363CF-B280-4CD7-9CF4-453343E77942} folder moved successfully.
C:\Users\fefed\AppData\Local\{13C220FC-8F14-4CB6-B2E7-DD7435A87F06} folder moved successfully.
C:\Users\fefed\AppData\Local\{141932C4-9B49-45FB-AA0D-1966851B88A6} folder moved successfully.
C:\Users\fefed\AppData\Local\{145254DB-B5AF-41A3-8149-7FFE892F36F8} folder moved successfully.
C:\Users\fefed\AppData\Local\{146D3099-1D92-49C8-B7EF-102F81C2CC33} folder moved successfully.
C:\Users\fefed\AppData\Local\{14B1F9B7-09EA-453E-86DD-87F490CB16F3} folder moved successfully.
C:\Users\fefed\AppData\Local\{14ED2868-CB8A-4E26-AF25-62D1E7257DE4} folder moved successfully.
C:\Users\fefed\AppData\Local\{14FF88E7-48A5-41C5-B209-3118E36C44D2} folder moved successfully.
C:\Users\fefed\AppData\Local\{15170C87-995B-4BC4-B252-64AB3E19EB6A} folder moved successfully.
C:\Users\fefed\AppData\Local\{1555BD34-3B3E-4A00-B43D-059D0B15AEDA} folder moved successfully.
C:\Users\fefed\AppData\Local\{159FB0FD-0EB9-400D-9F55-22E326610AED} folder moved successfully.
C:\Users\fefed\AppData\Local\{15D28D54-E84E-4B44-8894-6D47B4570703} folder moved successfully.
C:\Users\fefed\AppData\Local\{15F2CA55-0466-4A12-9107-02D1C31936D4} folder moved successfully.
C:\Users\fefed\AppData\Local\{16166ADC-B70A-4429-8C7C-02637F725E1A} folder moved successfully.
C:\Users\fefed\AppData\Local\{1655BFE5-C484-4F06-B1C9-4627F21483A1} folder moved successfully.
C:\Users\fefed\AppData\Local\{173D25C1-A72D-4A4E-9476-1A73F440A4AF} folder moved successfully.
C:\Users\fefed\AppData\Local\{1785D8C1-B11E-4D4B-94F4-257F6E209715} folder moved successfully.
C:\Users\fefed\AppData\Local\{17A746B6-F334-4CF0-9000-90AB459D37B0} folder moved successfully.
C:\Users\fefed\AppData\Local\{1830DCD7-495C-4B87-A6A9-DEC4D67464AD} folder moved successfully.
C:\Users\fefed\AppData\Local\{1836DAB3-5484-4500-8D94-2C72FE816FB1} folder moved successfully.
C:\Users\fefed\AppData\Local\{1869C4B5-996E-443E-93FC-5B416CEF7FE0} folder moved successfully.
C:\Users\fefed\AppData\Local\{18D5E98B-E58D-451C-9B28-F0859729FD03} folder moved successfully.
C:\Users\fefed\AppData\Local\{18ED3522-74BA-4DB9-BA19-2E0B91794922} folder moved successfully.
C:\Users\fefed\AppData\Local\{18FF9937-7957-4221-AB54-3B0F002FE712} folder moved successfully.
C:\Users\fefed\AppData\Local\{19003815-D092-4708-B893-8160E9E30CE7} folder moved successfully.
C:\Users\fefed\AppData\Local\{196D28E2-7C95-44C8-8D95-4F0C95058606} folder moved successfully.
C:\Users\fefed\AppData\Local\{19723996-D7EF-4A57-A0A3-67F9FA4DF4C5} folder moved successfully.
C:\Users\fefed\AppData\Local\{19DCCD81-F8F6-4B55-AE2B-6DD298C3503B} folder moved successfully.
C:\Users\fefed\AppData\Local\{19E19479-8111-4122-AE24-6D03A91FAB84} folder moved successfully.
C:\Users\fefed\AppData\Local\{19E66200-C36E-4724-B126-5E30F556D3D6} folder moved successfully.
C:\Users\fefed\AppData\Local\{1A1625B1-2323-4FF8-A47C-C667C19DDA1B} folder moved successfully.
C:\Users\fefed\AppData\Local\{1A1960BC-C75C-4484-8834-7A665D15A5FF} folder moved successfully.
C:\Users\fefed\AppData\Local\{1A31D204-DB59-47C9-B2EB-543C6A78ED6B} folder moved successfully.
C:\Users\fefed\AppData\Local\{1A71DD7A-03CC-4E78-88E3-A7E0372EA148} folder moved successfully.
C:\Users\fefed\AppData\Local\{1A856F45-55BF-46B5-8ACA-3258EEF24D7F} folder moved successfully.
C:\Users\fefed\AppData\Local\{1AA28DAC-41AA-4E09-B7E3-5E71312DD4A1} folder moved successfully.
C:\Users\fefed\AppData\Local\{1ABA80B5-2437-4636-82D1-B1224009B95D} folder moved successfully.
C:\Users\fefed\AppData\Local\{1AE68BE7-3181-4BB2-B9B4-4FFADDE29243} folder moved successfully.
C:\Users\fefed\AppData\Local\{1B33C116-9F7E-46DF-8CAE-321725AF64A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{1BC39B66-B6E0-4F06-9362-896BBCBBAA16} folder moved successfully.
C:\Users\fefed\AppData\Local\{1BCAC51F-4852-4258-B95A-3AD13C108A7D} folder moved successfully.
C:\Users\fefed\AppData\Local\{1BF02837-4661-4B51-9775-C238698ACA27} folder moved successfully.
C:\Users\fefed\AppData\Local\{1BF7C95D-EF86-4782-A43B-175F834A4626} folder moved successfully.
C:\Users\fefed\AppData\Local\{1BFF6999-0706-488D-871F-51FD638C6EF0} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C0C8AB7-FFC7-49BD-B228-E1B7F232462E} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C15B69D-D78A-481B-BA65-7D1EE72FD732} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C2570ED-A469-4816-8312-361D7CF8BE94} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C30D5FE-2618-45BF-A2DB-C677F7E06669} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C7AE5E7-C8DD-4650-9D6D-351D739982E0} folder moved successfully.
C:\Users\fefed\AppData\Local\{1C87CD2A-BF61-4C60-9B17-9A00507152C6} folder moved successfully.
C:\Users\fefed\AppData\Local\{1D23AF7A-BF66-4BEC-8AD5-B10B1C9081B7} folder moved successfully.
C:\Users\fefed\AppData\Local\{1DCB9120-5C09-4940-871A-54228C82D1C8} folder moved successfully.
C:\Users\fefed\AppData\Local\{1DD8BF8D-95F6-427E-83BD-3AEB1C00284D} folder moved successfully.
C:\Users\fefed\AppData\Local\{1E83522D-BB80-41E7-9689-40F0DC6C82FB} folder moved successfully.
C:\Users\fefed\AppData\Local\{1E85C56B-7F15-46A6-9D01-CF60A39B3F84} folder moved successfully.
C:\Users\fefed\AppData\Local\{1ECA4A3D-D517-4865-BB2E-224424F25504} folder moved successfully.
C:\Users\fefed\AppData\Local\{1FF7FB55-792E-4012-A14C-481B0C5D4B16} folder moved successfully.
C:\Users\fefed\AppData\Local\{20699B68-E5D0-4AF2-8157-682E7A8D6C62} folder moved successfully.
C:\Users\fefed\AppData\Local\{2098C6E1-411C-43B5-8C48-52C62BDCF603} folder moved successfully.
C:\Users\fefed\AppData\Local\{20A97837-7FF3-43CE-BC03-B3B2907B484A} folder moved successfully.
C:\Users\fefed\AppData\Local\{20BFA582-F887-4313-AAC4-53AD6AB03EE4} folder moved successfully.
C:\Users\fefed\AppData\Local\{20D11EDE-D6F6-4D1F-AED5-9A8D9786091E} folder moved successfully.
C:\Users\fefed\AppData\Local\{210B8717-4B56-469D-B5F4-5EDA36346E28} folder moved successfully.
C:\Users\fefed\AppData\Local\{213556EE-BAA5-4B5E-80DC-E28937E8AD8F} folder moved successfully.
C:\Users\fefed\AppData\Local\{214BD41C-B72F-47E1-A1D8-3E638017A813} folder moved successfully.
C:\Users\fefed\AppData\Local\{2173C103-745D-4946-B29F-ED11D6DCD559} folder moved successfully.
C:\Users\fefed\AppData\Local\{2187BBC5-887D-4A1C-B6A9-AF88D8505292} folder moved successfully.
C:\Users\fefed\AppData\Local\{21966E43-D124-4155-AB51-A02176EE1AC9} folder moved successfully.
C:\Users\fefed\AppData\Local\{21EBF03E-8370-40C4-9579-BCAE70B38044} folder moved successfully.
C:\Users\fefed\AppData\Local\{22302892-6A08-4C21-AEFD-3BDD44000FE0} folder moved successfully.
C:\Users\fefed\AppData\Local\{225AD781-7D4E-421E-A6F6-284A4ED97883} folder moved successfully.
C:\Users\fefed\AppData\Local\{22A3C1B9-E6FB-4721-91A2-C755E2004DBF} folder moved successfully.
C:\Users\fefed\AppData\Local\{22BC2626-1202-4CA6-9E21-51952CBDED66} folder moved successfully.
C:\Users\fefed\AppData\Local\{22FC1524-7BC2-4E4B-BD12-ACDB4AFDF9EB} folder moved successfully.
C:\Users\fefed\AppData\Local\{2312EF31-B02C-4FBE-91ED-49603E82AF66} folder moved successfully.
C:\Users\fefed\AppData\Local\{235E8464-B82C-425A-BABD-BDBD19B93FBB} folder moved successfully.
C:\Users\fefed\AppData\Local\{2367F623-3A52-4D8F-B84E-0D756F4263FF} folder moved successfully.
C:\Users\fefed\AppData\Local\{2398BC96-0221-4860-ADD3-A392E2C68E25} folder moved successfully.
C:\Users\fefed\AppData\Local\{23B5A407-E57F-4E5D-82B2-7F515686660E} folder moved successfully.
C:\Users\fefed\AppData\Local\{24670041-0B75-4F6C-B74F-28D6616823B2} folder moved successfully.
C:\Users\fefed\AppData\Local\{24DC2FC4-97F4-4C6B-92EF-5346F3CAB51E} folder moved successfully.
C:\Users\fefed\AppData\Local\{252EA510-D425-4812-A7FE-44876080A665} folder moved successfully.
C:\Users\fefed\AppData\Local\{2577E20B-3EA5-4CF3-9BAA-9EDB94608513} folder moved successfully.
C:\Users\fefed\AppData\Local\{257E37C8-F5E5-4960-BE5A-6F577C90D9C4} folder moved successfully.
C:\Users\fefed\AppData\Local\{25A14E4A-6C35-45C5-A5D5-B4625691E51E} folder moved successfully.
C:\Users\fefed\AppData\Local\{25E99CF7-7747-42FD-875C-8390B28635F0} folder moved successfully.
C:\Users\fefed\AppData\Local\{25F4AA4F-0BCF-4477-9A26-55CFB3894198} folder moved successfully.
C:\Users\fefed\AppData\Local\{26515C3C-673E-4124-B8A9-05C530DC4322} folder moved successfully.
C:\Users\fefed\AppData\Local\{266D68D9-1615-43C7-94E3-A228193E6CEF} folder moved successfully.
C:\Users\fefed\AppData\Local\{2704F7B7-45D2-4E1D-8F03-5700B7C676ED} folder moved successfully.
C:\Users\fefed\AppData\Local\{27056BA6-37F8-4006-B356-26109E75B4AF} folder moved successfully.
C:\Users\fefed\AppData\Local\{274AABED-3DFA-4C20-B9C1-29EF8FDFAEB5} folder moved successfully.
C:\Users\fefed\AppData\Local\{278D01AD-07E4-4A48-9A9E-635ED5376888} folder moved successfully.
C:\Users\fefed\AppData\Local\{27AE83EA-150F-4031-9BB8-33F94DD8194B} folder moved successfully.
C:\Users\fefed\AppData\Local\{2866E2ED-5B88-4765-BDFA-2328E06DD164} folder moved successfully.
C:\Users\fefed\AppData\Local\{287332FE-E0A1-47C4-824D-E1F6CE9F7A11} folder moved successfully.
C:\Users\fefed\AppData\Local\{2874730A-28E0-4796-88BC-F4DBC7673DDB} folder moved successfully.
C:\Users\fefed\AppData\Local\{28A6C585-2F7D-4C91-B0C5-D721E087B508} folder moved successfully.
C:\Users\fefed\AppData\Local\{28ADD0D6-33B9-4CFD-B45F-38955FF56D15} folder moved successfully.
C:\Users\fefed\AppData\Local\{28D197AE-9515-4D79-B7D2-8406A78E415A} folder moved successfully.
C:\Users\fefed\AppData\Local\{28EE2967-A875-40B4-9232-A93D49984671} folder moved successfully.
C:\Users\fefed\AppData\Local\{28EEC9FB-13B9-47DD-B001-7E2D8117C91B} folder moved successfully.
C:\Users\fefed\AppData\Local\{28F71140-10FD-4FA9-9BFD-AA8FB0ACF21A} folder moved successfully.
C:\Users\fefed\AppData\Local\{294C67BD-BB77-4242-8E1D-51E6444F9AC5} folder moved successfully.
C:\Users\fefed\AppData\Local\{297B86AB-5A8F-42CE-BC31-968991DF567B} folder moved successfully.
C:\Users\fefed\AppData\Local\{29A0221F-4A79-470B-BA10-1BDBD877D707} folder moved successfully.
C:\Users\fefed\AppData\Local\{29BC0895-1D6D-4B49-840B-58E7CBB56673} folder moved successfully.
C:\Users\fefed\AppData\Local\{29CEB3C2-DD57-47B5-A1D8-253A11C50BCD} folder moved successfully.
C:\Users\fefed\AppData\Local\{2A11C310-4526-4DE0-AF4A-5B0980579898} folder moved successfully.
C:\Users\fefed\AppData\Local\{2A3351A6-88D8-4BAA-8C08-FF2EB1689472} folder moved successfully.
C:\Users\fefed\AppData\Local\{2A47823D-96A0-4CCF-A05E-5A5895C6F73D} folder moved successfully.
C:\Users\fefed\AppData\Local\{2A5A1A39-2D54-4985-B44F-7049F034E39A} folder moved successfully.
C:\Users\fefed\AppData\Local\{2A9AE1DB-113A-4B1A-9667-0BC90BD342CF} folder moved successfully.
C:\Users\fefed\AppData\Local\{2B0A08E3-BC65-4D8A-9158-EB9D856CD49D} folder moved successfully.
C:\Users\fefed\AppData\Local\{2B1EFBCC-0028-4287-9F08-1A531ED06AB4} folder moved successfully.
C:\Users\fefed\AppData\Local\{2B520DB5-0EF9-447E-804E-62B593BE1825} folder moved successfully.
C:\Users\fefed\AppData\Local\{2BB184BB-B60A-41A1-99B1-02F45625F55D} folder moved successfully.
C:\Users\fefed\AppData\Local\{2BC4A48C-F3BC-49C6-BED2-0A1C0F2A88CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{2BFEF855-87D0-46A8-9E2F-365F0E68FCF6} folder moved successfully.
C:\Users\fefed\AppData\Local\{2C3BEDF9-09D6-485E-9C8C-94D1C4879AEA} folder moved successfully.
C:\Users\fefed\AppData\Local\{2C6714D4-3278-4E30-9758-821FF8E5EFF0} folder moved successfully.
C:\Users\fefed\AppData\Local\{2D39C773-6DE4-4205-AE07-0BEA5F5938D3} folder moved successfully.
C:\Users\fefed\AppData\Local\{2E59C61F-BA0E-4FE6-A528-B9A7949D950D} folder moved successfully.
C:\Users\fefed\AppData\Local\{2E5FFA1C-E0D4-4C79-BFEE-981B096C235B} folder moved successfully.
C:\Users\fefed\AppData\Local\{2E7D6479-4F9C-46DE-8513-E564D99B84D2} folder moved successfully.
C:\Users\fefed\AppData\Local\{2E8FC1CC-01B0-4EEA-A733-FE3BCE29AE92} folder moved successfully.
C:\Users\fefed\AppData\Local\{2EC10D73-FD36-43D1-9187-B42E881C23BA} folder moved successfully.
C:\Users\fefed\AppData\Local\{2F421D3E-8301-4C15-8E7C-8311781A3ADB} folder moved successfully.
C:\Users\fefed\AppData\Local\{2F77E766-F045-47A6-B26C-27298FE3A952} folder moved successfully.
C:\Users\fefed\AppData\Local\{2F93DCD0-822C-4C04-B5E7-CCFD099C0931} folder moved successfully.
C:\Users\fefed\AppData\Local\{2FE21EA7-AE26-47AC-A624-6A968241C101} folder moved successfully.
C:\Users\fefed\AppData\Local\{2FE3025A-6C9B-4980-B171-B3F6FEBF340D} folder moved successfully.
C:\Users\fefed\AppData\Local\{30624F19-0665-4697-975A-166E7DD286AA} folder moved successfully.
C:\Users\fefed\AppData\Local\{306CA25B-A7D9-4652-AB6F-6D6729E4091F} folder moved successfully.
C:\Users\fefed\AppData\Local\{30713617-7741-4178-B2DD-6AED150D0355} folder moved successfully.
C:\Users\fefed\AppData\Local\{307750CA-660F-4BA5-B044-C2361FA7F63E} folder moved successfully.
C:\Users\fefed\AppData\Local\{30B70F6C-6E49-4813-B147-894A49A146F6} folder moved successfully.
C:\Users\fefed\AppData\Local\{310A5B61-B344-42A1-A8AE-40498048DFEF} folder moved successfully.
C:\Users\fefed\AppData\Local\{313A9986-5CFC-4A1F-8A07-20B3AA818182} folder moved successfully.
C:\Users\fefed\AppData\Local\{313CAD08-BAC8-4C3F-9361-3DF4D65CCB1E} folder moved successfully.
C:\Users\fefed\AppData\Local\{3169CDB4-D12D-4801-A540-7C2428FAF0A4} folder moved successfully.
C:\Users\fefed\AppData\Local\{31FC3F81-7D4F-4F27-89CA-54AB464DB6B0} folder moved successfully.
C:\Users\fefed\AppData\Local\{31FD0609-D077-45BE-BB2D-B172294DF100} folder moved successfully.
C:\Users\fefed\AppData\Local\{321E05DB-69FD-473B-85BE-A76372E2EC13} folder moved successfully.
C:\Users\fefed\AppData\Local\{322E6B1B-E19D-4CFC-9162-DC83BB6E1068} folder moved successfully.
C:\Users\fefed\AppData\Local\{32E8DE0D-FBC2-4E7E-8899-4759242E0E5A} folder moved successfully.
C:\Users\fefed\AppData\Local\{3355CF79-B8B6-4D57-8DD5-A3168A416484} folder moved successfully.
C:\Users\fefed\AppData\Local\{336F3805-8EE3-4DE1-8A3D-74C887DE09CB} folder moved successfully.
C:\Users\fefed\AppData\Local\{33F489B5-AA87-4620-92E6-4EB89324F8BB} folder moved successfully.
C:\Users\fefed\AppData\Local\{33F489C0-8A56-4AC6-BC79-73B484A047A4} folder moved successfully.
C:\Users\fefed\AppData\Local\{3409D5B1-543E-431F-BA5D-D549FBCAEEC5} folder moved successfully.
C:\Users\fefed\AppData\Local\{343B9656-1901-494D-9364-4B32A14B51A0} folder moved successfully.
C:\Users\fefed\AppData\Local\{346D20B9-DD3F-4FE4-9DB2-7345065627E5} folder moved successfully.
C:\Users\fefed\AppData\Local\{34900FCB-2A09-4DB2-9574-6446039E884D} folder moved successfully.
C:\Users\fefed\AppData\Local\{34916B5F-44D3-4628-9330-552B29506B0A} folder moved successfully.
C:\Users\fefed\AppData\Local\{349AF9BC-0DF2-4722-9656-6711C63B6E58} folder moved successfully.
C:\Users\fefed\AppData\Local\{34B93FD7-6AC2-4109-896C-93F90160A1D0} folder moved successfully.
C:\Users\fefed\AppData\Local\{34D929F2-FA4E-45FC-BC83-989CC2CDAA91} folder moved successfully.
C:\Users\fefed\AppData\Local\{34F36479-98DC-40CB-8CAA-6BD9175ED8B4} folder moved successfully.
C:\Users\fefed\AppData\Local\{35113F55-3714-4390-9251-8397E3E77C2C} folder moved successfully.
C:\Users\fefed\AppData\Local\{355459C0-847D-40A6-BA7F-7C033D548533} folder moved successfully.
C:\Users\fefed\AppData\Local\{35626949-A96F-49A9-A104-905C5CFC6283} folder moved successfully.
C:\Users\fefed\AppData\Local\{35F63ED0-DDA1-433A-ACA0-21F5796E524D} folder moved successfully.
C:\Users\fefed\AppData\Local\{35F88F45-14FF-46FA-B284-DA768E948965} folder moved successfully.
C:\Users\fefed\AppData\Local\{364F1930-A3F0-4382-8B5B-070EAE31F44E} folder moved successfully.
C:\Users\fefed\AppData\Local\{365621BF-BC7A-4322-A026-80B51647BDE3} folder moved successfully.
C:\Users\fefed\AppData\Local\{367A5F9C-2DAF-4929-BA0A-44B3F4277366} folder moved successfully.
C:\Users\fefed\AppData\Local\{36F0291C-2D4C-4ABC-BF35-0039C84185E9} folder moved successfully.
C:\Users\fefed\AppData\Local\{37257471-DE42-481A-87F3-CB27FC5F30CE} folder moved successfully.
C:\Users\fefed\AppData\Local\{378E6722-E613-4FAF-B2E0-C06EB5AC208F} folder moved successfully.
C:\Users\fefed\AppData\Local\{37A3C6D8-A5BD-4BE8-B068-AB46CE4CC1ED} folder moved successfully.
C:\Users\fefed\AppData\Local\{37CB9696-26E8-4584-8C56-ED276997B0FF} folder moved successfully.
C:\Users\fefed\AppData\Local\{387FD0DB-3EBB-4FA2-85E3-393B2ACC5E18} folder moved successfully.
C:\Users\fefed\AppData\Local\{38B1BB5E-A180-4E0D-B955-0A8AC3634259} folder moved successfully.
C:\Users\fefed\AppData\Local\{38CC556E-E414-42ED-B659-CE04C53F37E3} folder moved successfully.
C:\Users\fefed\AppData\Local\{38CDE827-46D1-4F35-AB3D-06C6CBFBC00E} folder moved successfully.
C:\Users\fefed\AppData\Local\{38D221CC-0DE3-493B-9C58-56AB8A81132F} folder moved successfully.
C:\Users\fefed\AppData\Local\{38FBC749-7147-4764-B66B-33164F2534BD} folder moved successfully.
C:\Users\fefed\AppData\Local\{3907EF2E-5E55-4BE1-BFA7-B4E4915F0979} folder moved successfully.
C:\Users\fefed\AppData\Local\{3938A81C-CEE3-4A80-AF41-EDD6A66AB4A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{39DD258B-B2EA-4B79-9BE2-0BE1D6F94BB3} folder moved successfully.
C:\Users\fefed\AppData\Local\{39F5C50E-58D9-47B6-BBAA-3BB750C8E191} folder moved successfully.
C:\Users\fefed\AppData\Local\{3A0932E0-9E01-444F-8F7C-B62910AC4A42} folder moved successfully.
C:\Users\fefed\AppData\Local\{3A41D148-42AF-4F83-BDE3-22EC754A610C} folder moved successfully.
C:\Users\fefed\AppData\Local\{3A72F699-7C1A-4E35-9E29-B37E3D20125C} folder moved successfully.
C:\Users\fefed\AppData\Local\{3ABA47CF-6156-40D3-A12C-83C88CF0FEE4} folder moved successfully.
C:\Users\fefed\AppData\Local\{3AC87F21-9D31-4E78-9F0B-4A5608A02659} folder moved successfully.
C:\Users\fefed\AppData\Local\{3ACD2207-6F23-4A40-9723-5FF2791BC535} folder moved successfully.
C:\Users\fefed\AppData\Local\{3AF1E276-3074-4C30-8ECA-3BA7C0C054C1} folder moved successfully.
C:\Users\fefed\AppData\Local\{3AFCECBC-3E3F-434B-9AF0-77F4D5F1A4FC} folder moved successfully.
C:\Users\fefed\AppData\Local\{3B25796E-9951-4416-BE45-4F8960DE0DF1} folder moved successfully.
C:\Users\fefed\AppData\Local\{3B92C1D0-7352-4062-9D6F-C1C86EC7ABCC} folder moved successfully.
C:\Users\fefed\AppData\Local\{3C138751-18C1-4527-951A-F6DDB168661D} folder moved successfully.
C:\Users\fefed\AppData\Local\{3C3E8C71-ED1A-48E3-9A12-13EBC6082D01} folder moved successfully.
C:\Users\fefed\AppData\Local\{3C507AEE-B29A-45A4-8E65-CFA8356C1A3B} folder moved successfully.
C:\Users\fefed\AppData\Local\{3C72D697-E434-4963-872D-0D07773B481B} folder moved successfully.
C:\Users\fefed\AppData\Local\{3C78C37A-2A5D-4998-970E-C674D128C6D8} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CABC89C-EADB-4EFE-B002-55213F3363CC} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CBA92B0-405D-4780-A41D-454635204139} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CC47A91-8661-4A18-8C55-96F2CF88809B} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CC78C11-3BE9-4BEE-A76A-2398D5C3844C} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CD4F839-FD26-4AB7-B999-554BDAF4D926} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CDA74EE-9D5D-47A8-93AE-B837F0A9DA93} folder moved successfully.
C:\Users\fefed\AppData\Local\{3CE2DF7A-5786-4581-A3F3-C0D5087D9728} folder moved successfully.
C:\Users\fefed\AppData\Local\{3D3BA78D-8E0C-4AB1-8E8D-B930DF45D5E8} folder moved successfully.
C:\Users\fefed\AppData\Local\{3D7621FA-E861-4B0E-BE02-2C76E1788E27} folder moved successfully.
C:\Users\fefed\AppData\Local\{3DB10FA7-2E1D-4F7D-AC07-72DA4EDA1A4E} folder moved successfully.
C:\Users\fefed\AppData\Local\{3DC26E49-E0D7-48C8-9A0F-D0AF28029682} folder moved successfully.
C:\Users\fefed\AppData\Local\{3DD6BF38-75DB-476B-B57B-BCDD49C191DB} folder moved successfully.
C:\Users\fefed\AppData\Local\{3DDCBB3D-CEC4-4AD3-A392-B78F6C8048BC} folder moved successfully.
C:\Users\fefed\AppData\Local\{3DE3961E-82CE-48D9-B6C4-31711748699B} folder moved successfully.
C:\Users\fefed\AppData\Local\{3E5E87B0-AB0E-425C-8E37-CBB3072FDC8E} folder moved successfully.
C:\Users\fefed\AppData\Local\{3E7B8636-84F9-4ACB-9C56-D9BDB4F9564D} folder moved successfully.
C:\Users\fefed\AppData\Local\{3E8F8F6C-36FB-4309-8CC2-84508AE1AD4C} folder moved successfully.
C:\Users\fefed\AppData\Local\{3E978E65-12CB-43A6-94C2-300C0E31AE5E} folder moved successfully.
C:\Users\fefed\AppData\Local\{3E9F1198-A9FE-4806-8736-0057E2D530FE} folder moved successfully.
C:\Users\fefed\AppData\Local\{3ED2C006-9A6A-438C-87E8-A4F5F3F9C8DE} folder moved successfully.
C:\Users\fefed\AppData\Local\{3EF92012-FAD1-4F17-930C-B9D379986A53} folder moved successfully.
C:\Users\fefed\AppData\Local\{3F6D7D24-CAC1-4544-B351-B0218B024739} folder moved successfully.
C:\Users\fefed\AppData\Local\{3F9ABF4A-D3DB-40F1-B780-0ED8D3FE1B53} folder moved successfully.
C:\Users\fefed\AppData\Local\{40A4B32A-1DB9-4037-965D-06373F462B4B} folder moved successfully.
C:\Users\fefed\AppData\Local\{410EEE17-004B-492F-9FE0-540211A0AE5A} folder moved successfully.
C:\Users\fefed\AppData\Local\{4124F575-74C7-4C8D-9707-859E7529FB79} folder moved successfully.
C:\Users\fefed\AppData\Local\{41475769-B0BD-433A-955A-DECF440919FB} folder moved successfully.
C:\Users\fefed\AppData\Local\{4196C2CE-EB43-485B-A3B9-639E8A7EBBD9} folder moved successfully.
C:\Users\fefed\AppData\Local\{41B6C18A-EE11-4407-8B23-3CC00D0B26A8} folder moved successfully.
C:\Users\fefed\AppData\Local\{41BBA5AB-FCD9-4A53-AF59-369F7D06F0CA} folder moved successfully.
C:\Users\fefed\AppData\Local\{41D13317-61FB-4136-8691-2EBAF5FA247D} folder moved successfully.
C:\Users\fefed\AppData\Local\{41D90306-9192-453E-87C9-01C201D0FE79} folder moved successfully.
C:\Users\fefed\AppData\Local\{41F9AEA5-DC13-415D-824A-DE8BB7D467BD} folder moved successfully.
C:\Users\fefed\AppData\Local\{4201D990-B019-4EE0-9258-2FF9900ED47F} folder moved successfully.
C:\Users\fefed\AppData\Local\{42076408-07B0-4778-BB94-E5E4BE8C1B94} folder moved successfully.
C:\Users\fefed\AppData\Local\{420F083B-A099-4A85-9761-B29ADC7C3E26} folder moved successfully.
C:\Users\fefed\AppData\Local\{421A546E-7AA6-487B-AD94-DE9E3DFD0EDC} folder moved successfully.
C:\Users\fefed\AppData\Local\{42451D5A-34F0-45A9-9F2B-DF4032D5723C} folder moved successfully.
C:\Users\fefed\AppData\Local\{42D4A172-B70E-481D-8798-12209B5D719F} folder moved successfully.
C:\Users\fefed\AppData\Local\{42E59509-C24B-4267-B149-FA4521054F92} folder moved successfully.
C:\Users\fefed\AppData\Local\{43D31867-3286-4410-AC11-225421E9520B} folder moved successfully.
C:\Users\fefed\AppData\Local\{441D801C-82D3-4607-B909-2289AF7DB587} folder moved successfully.
C:\Users\fefed\AppData\Local\{4488C632-57BB-47FA-AA31-BD9D458AC30E} folder moved successfully.
C:\Users\fefed\AppData\Local\{449A3578-95F0-4F4D-8D09-B0E48D4FF78C} folder moved successfully.
C:\Users\fefed\AppData\Local\{45689736-4880-4E99-A8AC-95DCD79DC673} folder moved successfully.
C:\Users\fefed\AppData\Local\{45AC348A-65F8-41E3-93FA-205FDA1C605D} folder moved successfully.
C:\Users\fefed\AppData\Local\{45D9E0F7-A736-4350-9F3E-756631C79A44} folder moved successfully.
C:\Users\fefed\AppData\Local\{46088F76-025E-42B3-8372-D2768164150F} folder moved successfully.
C:\Users\fefed\AppData\Local\{463E86B8-DE21-4CDC-8FB6-98BBFFE74DA4} folder moved successfully.
C:\Users\fefed\AppData\Local\{4644E00A-E27A-4AD1-BAD2-58D41D7DF644} folder moved successfully.
C:\Users\fefed\AppData\Local\{46CA8E6B-A3CD-4256-91D3-8E2767767E5B} folder moved successfully.
C:\Users\fefed\AppData\Local\{46FF1F49-94CE-4751-836A-5BBFFF123BF9} folder moved successfully.
C:\Users\fefed\AppData\Local\{4757AC6F-9AE6-441E-9065-80E0A5D25C03} folder moved successfully.
C:\Users\fefed\AppData\Local\{479662D6-2AC2-4E27-AFDF-1A08AD278CD1} folder moved successfully.
C:\Users\fefed\AppData\Local\{47BA06FD-A195-47A2-8D2A-D9905A805534} folder moved successfully.
C:\Users\fefed\AppData\Local\{47BFA215-3736-458A-95F1-7A6F1014F545} folder moved successfully.
C:\Users\fefed\AppData\Local\{47C05816-F8B9-44F0-A4A3-7A9C44F0507D} folder moved successfully.
C:\Users\fefed\AppData\Local\{47F388B7-9FFB-4A63-B2CF-DF8FCEB70889} folder moved successfully.
C:\Users\fefed\AppData\Local\{48332670-423B-4922-82B9-0E3B132C50C6} folder moved successfully.
C:\Users\fefed\AppData\Local\{4833E432-FCBD-4CD2-9DF4-5107BD5742A5} folder moved successfully.
C:\Users\fefed\AppData\Local\{48BE8FDE-42F3-44DB-A336-71075B767882} folder moved successfully.
C:\Users\fefed\AppData\Local\{49048DBA-072F-47C1-8997-F2237B2FD3F5} folder moved successfully.
C:\Users\fefed\AppData\Local\{4915CFAE-3455-4AB1-BCE9-8070C91D24CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{4981A2C9-F6BA-446F-A43D-DCD951BA141E} folder moved successfully.
C:\Users\fefed\AppData\Local\{49B3FA43-04A3-496D-9A2B-5F345C29BFD8} folder moved successfully.
C:\Users\fefed\AppData\Local\{49F5F078-66D8-4AA0-B03B-ED3947E19637} folder moved successfully.
C:\Users\fefed\AppData\Local\{4A6629D3-84BF-4686-8C4A-E605B2F1CF33} folder moved successfully.
C:\Users\fefed\AppData\Local\{4A668BB5-0E44-4312-99E1-162D677D314F} folder moved successfully.
C:\Users\fefed\AppData\Local\{4AA36FFB-2494-4A8B-8783-29B246208BBD} folder moved successfully.
C:\Users\fefed\AppData\Local\{4AEE22A1-67BF-4511-8A5B-8EB367C0089E} folder moved successfully.
C:\Users\fefed\AppData\Local\{4B4D0959-3167-4315-A0D9-8C103D492AEA} folder moved successfully.
C:\Users\fefed\AppData\Local\{4B8382AC-8DC4-43AA-90E1-C3AD4E988220} folder moved successfully.
C:\Users\fefed\AppData\Local\{4BEB3E0D-6899-4CFA-BD50-9CDC94F98EDD} folder moved successfully.
C:\Users\fefed\AppData\Local\{4BF467C6-63A5-4A9E-B331-6C869691A430} folder moved successfully.
C:\Users\fefed\AppData\Local\{4BF9BB68-6F1F-455B-9E5B-EB1CF24ACC9C} folder moved successfully.
C:\Users\fefed\AppData\Local\{4C5AAE01-FCD8-4C6E-A6D5-C9C7596BD129} folder moved successfully.
C:\Users\fefed\AppData\Local\{4C9424EB-B063-4327-BF3D-D0751D29972D} folder moved successfully.
C:\Users\fefed\AppData\Local\{4CA53B70-1D38-4875-ADE4-24829FF3FA08} folder moved successfully.
C:\Users\fefed\AppData\Local\{4D286892-399E-46E9-BCF2-6EE214E0A247} folder moved successfully.
C:\Users\fefed\AppData\Local\{4D2EB37E-3202-4ADA-A26A-64AB02F1F53C} folder moved successfully.
C:\Users\fefed\AppData\Local\{4D453FAC-565E-44C0-A0FD-991834B737EE} folder moved successfully.
C:\Users\fefed\AppData\Local\{4D6A9F0B-11D9-4701-BD7B-3C900BA87B00} folder moved successfully.
C:\Users\fefed\AppData\Local\{4D9B399B-7490-474F-BA08-F740D1B3BAF9} folder moved successfully.
C:\Users\fefed\AppData\Local\{4DB9226E-1FD3-4149-9EF6-EF9B2889E0D0} folder moved successfully.
C:\Users\fefed\AppData\Local\{4DC2CA96-57D7-4489-A958-2CD3A8F0633D} folder moved successfully.
C:\Users\fefed\AppData\Local\{4DCC19CB-6627-45A3-ABC7-4340801321CE} folder moved successfully.
C:\Users\fefed\AppData\Local\{4DF0EF2F-035E-44BE-A330-CF48E7B7C235} folder moved successfully.
C:\Users\fefed\AppData\Local\{4E2606F0-5B74-4F3B-A4CC-425DD356F7CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{4E519A9D-C2D9-4A06-9801-1E4FD5297BD9} folder moved successfully.
C:\Users\fefed\AppData\Local\{4E81DEDB-021A-4726-B4F7-45E4E3CFBA15} folder moved successfully.
C:\Users\fefed\AppData\Local\{4E947853-771D-4613-BAA7-DDE4D4D7B38A} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F1BFA24-E251-4D9E-92DC-7AA2B29D4961} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F2E0BFC-4C69-446A-9FEA-C7C2CAA9DD11} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F40F62B-B904-455F-9A3E-CABF530DFC24} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F4B3264-EAA3-4787-B183-880EB5B9A2E2} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F827C51-02A3-4A23-8441-FE380B536D34} folder moved successfully.
C:\Users\fefed\AppData\Local\{4F9A5580-A908-4AD4-AEBA-65E1344CA2F4} folder moved successfully.
C:\Users\fefed\AppData\Local\{4FB02871-1F59-455E-B518-610A8C9BB8FB} folder moved successfully.
C:\Users\fefed\AppData\Local\{4FD454BE-E1F8-48D4-B687-BED76D4D714F} folder moved successfully.
C:\Users\fefed\AppData\Local\{504114BF-907C-4E50-BE9E-30757DF9FD07} folder moved successfully.
C:\Users\fefed\AppData\Local\{505AA40C-9E7A-4568-BEF9-D7B022AECB15} folder moved successfully.
C:\Users\fefed\AppData\Local\{50A71F8F-EBFC-4F9F-AFF8-C34404347970} folder moved successfully.
C:\Users\fefed\AppData\Local\{50AF550D-D99A-42F0-843A-FFC07E6B20F4} folder moved successfully.
C:\Users\fefed\AppData\Local\{50BEDE6C-4DBB-473F-B7BF-E1B6EE2C1A49} folder moved successfully.
C:\Users\fefed\AppData\Local\{50D97D98-5CCF-4ED2-A091-C3866C67BF3E} folder moved successfully.
C:\Users\fefed\AppData\Local\{50E18351-AFC7-40D7-83EA-BACBEB240E53} folder moved successfully.
C:\Users\fefed\AppData\Local\{50EA0509-CBEC-4786-BCFE-6C9C0ACC28CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{50F8BF79-036A-44EC-96A1-897B8A14AFC8} folder moved successfully.
C:\Users\fefed\AppData\Local\{510EAE71-A81C-4585-AE45-68159AD1B9E2} folder moved successfully.
C:\Users\fefed\AppData\Local\{51266417-D542-4479-A410-4B6E868C4802} folder moved successfully.
C:\Users\fefed\AppData\Local\{515F111B-9978-40BD-B20F-384A40BEB94B} folder moved successfully.
C:\Users\fefed\AppData\Local\{51BCCD03-1389-4475-9C8F-E87E61DAAA3C} folder moved successfully.
C:\Users\fefed\AppData\Local\{51E6388B-22EE-441B-B91F-1C1EA3A24A93} folder moved successfully.
C:\Users\fefed\AppData\Local\{520B787F-5027-44D3-963E-BCB5F94A4A67} folder moved successfully.
C:\Users\fefed\AppData\Local\{520E6063-4D9A-41F0-8E4C-4822961AA95F} folder moved successfully.
C:\Users\fefed\AppData\Local\{5249DEEA-52FC-4361-96ED-DA26EE4CBA50} folder moved successfully.
C:\Users\fefed\AppData\Local\{52613BF1-A405-41E2-90DA-5BA460B2A82E} folder moved successfully.
C:\Users\fefed\AppData\Local\{5294E183-3E20-4BC4-A3CD-2B80CFA668ED} folder moved successfully.
C:\Users\fefed\AppData\Local\{52EA5DCC-57D8-44D2-B61A-845A1B13429E} folder moved successfully.
C:\Users\fefed\AppData\Local\{52ED5411-9E83-4042-82E5-18C9F31B6BAA} folder moved successfully.
C:\Users\fefed\AppData\Local\{530757AB-DE15-413F-8B6B-3CB099B906A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{530D89E3-3AA0-40EE-B297-9686FFD24D8D} folder moved successfully.
C:\Users\fefed\AppData\Local\{530DD6ED-12B3-4CA0-B8D8-0B8CBDBDF69E} folder moved successfully.
C:\Users\fefed\AppData\Local\{53DB8105-E3C3-4A32-BEAC-4DC34DF97C7A} folder moved successfully.
C:\Users\fefed\AppData\Local\{53DD241D-9523-41B0-BE4C-FCDB61889CAD} folder moved successfully.
C:\Users\fefed\AppData\Local\{53E9CD4F-CD32-4E99-8019-21D832335841} folder moved successfully.
C:\Users\fefed\AppData\Local\{53F1F0D5-7943-44A2-BA9C-2FEA61E806FF} folder moved successfully.
C:\Users\fefed\AppData\Local\{53F54FC8-5928-452C-AB00-4C89A74A5A3A} folder moved successfully.
C:\Users\fefed\AppData\Local\{54308FB7-E18A-45E4-BE42-44C190E02D89} folder moved successfully.
C:\Users\fefed\AppData\Local\{547387F8-830E-477F-9A48-73514AE3583F} folder moved successfully.
C:\Users\fefed\AppData\Local\{548F047D-19F7-4DB7-982A-3A7584209E75} folder moved successfully.
C:\Users\fefed\AppData\Local\{54B0E633-587A-43C4-BD81-D326D3696536} folder moved successfully.
C:\Users\fefed\AppData\Local\{54BBF943-27F3-402C-8E55-61F838F315AE} folder moved successfully.
C:\Users\fefed\AppData\Local\{55176F65-C9AF-4E28-B949-659E095B0123} folder moved successfully.
C:\Users\fefed\AppData\Local\{55527B42-9283-463D-A0CA-8479F2EAF768} folder moved successfully.
C:\Users\fefed\AppData\Local\{556D3B09-FD12-410E-BC84-51EBD784D929} folder moved successfully.
C:\Users\fefed\AppData\Local\{558EE5B4-C2E8-4090-A79E-BF6775A42737} folder moved successfully.
C:\Users\fefed\AppData\Local\{56001D98-0C2C-4EB8-BEF2-8264EBC0C606} folder moved successfully.
C:\Users\fefed\AppData\Local\{561F7B6C-927B-4C93-A3E2-E0513E98F762} folder moved successfully.
C:\Users\fefed\AppData\Local\{5649124E-8C7B-4952-97B7-348B420ED71D} folder moved successfully.
C:\Users\fefed\AppData\Local\{564E1244-B11F-4C59-8063-87F6019FFEE8} folder moved successfully.
C:\Users\fefed\AppData\Local\{5698372B-380E-40CC-AAF8-19C6807F9FD2} folder moved successfully.
C:\Users\fefed\AppData\Local\{573E3031-9F40-4ED0-9A31-DF520B7D643F} folder moved successfully.
C:\Users\fefed\AppData\Local\{5819594E-5D0F-4733-84A3-F7221CA730E7} folder moved successfully.
C:\Users\fefed\AppData\Local\{582CED41-1919-4A4F-856A-A7ACDE0B8381} folder moved successfully.
C:\Users\fefed\AppData\Local\{582E9DDF-D018-4E09-9596-306DDCEC0801} folder moved successfully.
C:\Users\fefed\AppData\Local\{584B990F-69C2-4ED8-AE1F-5EC9B9BF4F1E} folder moved successfully.
C:\Users\fefed\AppData\Local\{589EA2AE-64CD-44B9-A829-97ADC3AFC51B} folder moved successfully.
C:\Users\fefed\AppData\Local\{58B74F73-ACCD-4CFA-9D83-7AA1E10B21F6} folder moved successfully.
C:\Users\fefed\AppData\Local\{58E06DAD-ABD3-4A58-9C82-E30C34C6611A} folder moved successfully.
C:\Users\fefed\AppData\Local\{592C3699-11DC-40D1-A100-65768B679400} folder moved successfully.
C:\Users\fefed\AppData\Local\{597802BC-5E10-444D-BFE4-5554B877C6E6} folder moved successfully.
C:\Users\fefed\AppData\Local\{59790F1E-C85A-49FF-8B7C-C550512F4694} folder moved successfully.
C:\Users\fefed\AppData\Local\{59868097-F2FE-42AC-A6DF-DA8C43ED2EB6} folder moved successfully.
C:\Users\fefed\AppData\Local\{59DBE665-D6FA-41D6-AAF6-5030FE920355} folder moved successfully.
C:\Users\fefed\AppData\Local\{5A180341-7BE1-4FDF-A49A-16341CF2B00B} folder moved successfully.
C:\Users\fefed\AppData\Local\{5A1DD44B-9122-4097-B657-FD3D82E87693} folder moved successfully.
C:\Users\fefed\AppData\Local\{5A383105-875A-402C-A751-5526D63F08BD} folder moved successfully.
C:\Users\fefed\AppData\Local\{5A822C93-FE86-476E-962A-1548C85C199B} folder moved successfully.
C:\Users\fefed\AppData\Local\{5AE40C8A-0206-46DD-84ED-D8A7449B609F} folder moved successfully.
C:\Users\fefed\AppData\Local\{5B631DAB-A617-4B81-9D85-60839ABE1E9D} folder moved successfully.
C:\Users\fefed\AppData\Local\{5C2F7D16-4362-4C2F-9424-10CC6218F1B9} folder moved successfully.
C:\Users\fefed\AppData\Local\{5C4F180E-5A64-46D6-9D54-043E3020B394} folder moved successfully.
C:\Users\fefed\AppData\Local\{5C61FDAA-9E9E-4418-AB0D-1011D9A01055} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CA22FFD-630A-4F15-B121-96DB01A6DC8F} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CA9E9E4-BBE8-4738-9F47-73D9FCA6E589} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CAC3675-F99F-4CF7-9F70-BFA15D4B7AF5} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CADA499-1383-46F8-916F-7188B36B4847} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CC146F1-4F0C-4367-BAAE-7D1A8A8B015B} folder moved successfully.
C:\Users\fefed\AppData\Local\{5CEDA003-17BA-42EE-AF56-15FC04C20D85} folder moved successfully.
C:\Users\fefed\AppData\Local\{5D4552A8-E1D6-4350-A23E-096436EAFC54} folder moved successfully.
C:\Users\fefed\AppData\Local\{5E52D712-68C4-4B9C-A1E4-75AF76C9BFAF} folder moved successfully.
C:\Users\fefed\AppData\Local\{5E98CCF0-FE5D-43C4-A48E-37EC84BC9BEA} folder moved successfully.
C:\Users\fefed\AppData\Local\{5EAFC3EE-C6BD-4B79-9168-6C33378F92BE} folder moved successfully.
C:\Users\fefed\AppData\Local\{5EB0334A-9BEC-4203-809A-E5B318C4FC73} folder moved successfully.
C:\Users\fefed\AppData\Local\{5EE0E27C-95DA-4F7F-AE5E-951A8F85A7B7} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F60F7B8-0847-4A02-A6E9-66442FB98C43} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F67BC70-801E-4CAA-98D2-9CD834E57550} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F7EB297-52B8-4713-9D82-AE038CE70EDB} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F82F0A6-6D8C-4483-B6BF-1605D295D3E6} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F866A1E-2491-436F-95C3-201AB866F670} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F87090B-B1B1-440D-9C1A-B8A0126F4C69} folder moved successfully.
C:\Users\fefed\AppData\Local\{5F8F8E80-4A79-4A9C-9BCC-2DDA190B05C2} folder moved successfully.
C:\Users\fefed\AppData\Local\{5FA74344-B9C4-49AF-8C6A-AEB051AC2582} folder moved successfully.
C:\Users\fefed\AppData\Local\{5FA75558-1467-43B3-B104-4071B5DD9F73} folder moved successfully.
C:\Users\fefed\AppData\Local\{5FAC2EC8-A7BE-48E1-A0DD-4FD9A43A5D7D} folder moved successfully.
C:\Users\fefed\AppData\Local\{6010094B-6C47-4EF9-A1EB-1702FCBE1402} folder moved successfully.
C:\Users\fefed\AppData\Local\{601CB5E3-A039-4E6D-A701-65E0CC7C7424} folder moved successfully.
C:\Users\fefed\AppData\Local\{601F4E5A-C3E0-4D6B-B459-9012765B33E5} folder moved successfully.
C:\Users\fefed\AppData\Local\{603FEB69-55EB-4CED-8148-0A36F436407F} folder moved successfully.
C:\Users\fefed\AppData\Local\{6070D96C-1673-4326-863F-15586711C84B} folder moved successfully.
C:\Users\fefed\AppData\Local\{60B918E8-8A65-48A7-BF56-8DBCB97A540B} folder moved successfully.
C:\Users\fefed\AppData\Local\{60CC965B-D5FD-446F-8BDB-314EDD4F82DC} folder moved successfully.
C:\Users\fefed\AppData\Local\{61270C75-9040-4A37-875E-2CF1483C30E6} folder moved successfully.
C:\Users\fefed\AppData\Local\{614506AE-1D2E-43CF-8939-7251458464F8} folder moved successfully.
C:\Users\fefed\AppData\Local\{614ABF33-D4C9-4662-BE7E-9DB5FD34B976} folder moved successfully.
C:\Users\fefed\AppData\Local\{6188C75D-6624-4563-9760-A4B32EC488A9} folder moved successfully.
C:\Users\fefed\AppData\Local\{61D3F05E-24C6-45E8-8F5D-973FDC7ABD2F} folder moved successfully.
C:\Users\fefed\AppData\Local\{61D77D36-DD16-4B65-BC7F-3DD9530557F6} folder moved successfully.
C:\Users\fefed\AppData\Local\{61EBA057-249A-4B51-913E-FF6F41D443A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{624C5072-F28E-405B-9E0B-38F1F8F91BB3} folder moved successfully.
C:\Users\fefed\AppData\Local\{629CCD3D-DCB4-420B-A3F0-5733C02DE259} folder moved successfully.
C:\Users\fefed\AppData\Local\{6319B95C-BEB7-4F15-AF27-D4C53CA66323} folder moved successfully.
C:\Users\fefed\AppData\Local\{63319BDE-FA26-4BC4-9BAA-4FD10DE88F10} folder moved successfully.
C:\Users\fefed\AppData\Local\{633765CC-E33E-4197-8285-36FE3A0E838D} folder moved successfully.
C:\Users\fefed\AppData\Local\{63746C72-FC6A-47B4-8EB5-AA7BA0C26E18} folder moved successfully.
C:\Users\fefed\AppData\Local\{63B32B84-69D5-4980-A98D-84F6DBFE3B71} folder moved successfully.
C:\Users\fefed\AppData\Local\{63B9FE20-39BA-4F7E-A2A2-2A8A953F4512} folder moved successfully.
C:\Users\fefed\AppData\Local\{63BDC6C2-42BE-4F13-B142-4FABABD472B8} folder moved successfully.
C:\Users\fefed\AppData\Local\{63D5D812-1621-4CD9-BEE1-730E042BF589} folder moved successfully.
C:\Users\fefed\AppData\Local\{646A23D6-34AA-468A-8164-CFBA6291977A} folder moved successfully.
C:\Users\fefed\AppData\Local\{64CACDB2-99F0-40EB-8433-8F6F5D48DD62} folder moved successfully.
C:\Users\fefed\AppData\Local\{6530BA33-50BE-4107-82E1-ABD0E59F8194} folder moved successfully.
C:\Users\fefed\AppData\Local\{65B174A9-DA48-4D23-9333-236B3F144BA2} folder moved successfully.
C:\Users\fefed\AppData\Local\{65BD6460-2CCA-46DC-8539-3D47D5CE9B12} folder moved successfully.
C:\Users\fefed\AppData\Local\{65DC36DE-8BBF-46B1-9F59-D115582F7806} folder moved successfully.
C:\Users\fefed\AppData\Local\{65FC0FE5-22C6-44F9-91A0-8152539E3428} folder moved successfully.
C:\Users\fefed\AppData\Local\{664A5672-79E6-4E20-A440-2035D7FC34A1} folder moved successfully.
C:\Users\fefed\AppData\Local\{665C7412-CF01-4D04-B4F9-19235B51F085} folder moved successfully.
C:\Users\fefed\AppData\Local\{668F861C-94F2-43F5-9C7F-55DD60EDC928} folder moved successfully.
C:\Users\fefed\AppData\Local\{66BC791E-CF45-4371-971E-10A226DEB8F9} folder moved successfully.
C:\Users\fefed\AppData\Local\{66D76B98-D921-44A2-A489-480ED9287615} folder moved successfully.
C:\Users\fefed\AppData\Local\{66FA1256-A26B-4982-BD8F-999A22E6B77A} folder moved successfully.
C:\Users\fefed\AppData\Local\{675520C5-99A1-401C-9543-926297204730} folder moved successfully.
C:\Users\fefed\AppData\Local\{67AB452E-A5F2-4BBF-982A-84E314C10A7E} folder moved successfully.
C:\Users\fefed\AppData\Local\{68343244-478C-4142-82DA-90C77670F206} folder moved successfully.
C:\Users\fefed\AppData\Local\{6837D843-C213-4F76-89CB-0A8D43D698C1} folder moved successfully.
C:\Users\fefed\AppData\Local\{6850EDF2-0521-4AA9-AE1F-44B2149B1CF5} folder moved successfully.
C:\Users\fefed\AppData\Local\{685F8B7D-2740-4188-8C45-A8CA98AAEFB9} folder moved successfully.
C:\Users\fefed\AppData\Local\{68AA5286-714E-475D-8F9C-B9AF4FBBF327} folder moved successfully.
C:\Users\fefed\AppData\Local\{68C51DEC-7BB8-4F88-B367-B85EC2A2776B} folder moved successfully.
C:\Users\fefed\AppData\Local\{691061F8-0CF7-4F0D-93C7-0A4D089D6847} folder moved successfully.
C:\Users\fefed\AppData\Local\{69E214DE-2918-4DBB-9D93-8667BB7FCAA1} folder moved successfully.
C:\Users\fefed\AppData\Local\{69FCF05E-4884-4819-8E69-FED6078BFC09} folder moved successfully.
C:\Users\fefed\AppData\Local\{6A0971F0-AB10-436A-965F-66CF94ADDAAC} folder moved successfully.
C:\Users\fefed\AppData\Local\{6A57586D-1A47-45BB-B5EE-21070E818591} folder moved successfully.
C:\Users\fefed\AppData\Local\{6A9C2E4B-7EBA-4F1B-B549-085A6FF67BD1} folder moved successfully.
C:\Users\fefed\AppData\Local\{6AA89770-E958-46C4-B533-0D5D63F350E9} folder moved successfully.
C:\Users\fefed\AppData\Local\{6AAE9D38-74B9-4CB4-986C-AB8463D76751} folder moved successfully.
C:\Users\fefed\AppData\Local\{6AF32282-23AD-486F-931F-E5330F69FEB9} folder moved successfully.
C:\Users\fefed\AppData\Local\{6B45B576-B2AC-4757-968D-2F8C8D7F2A91} folder moved successfully.
C:\Users\fefed\AppData\Local\{6BA8A63B-64EE-4FEF-9F3C-79F284F9B23B} folder moved successfully.
C:\Users\fefed\AppData\Local\{6BCCE014-7835-453C-A561-FC395705C1DD} folder moved successfully.
C:\Users\fefed\AppData\Local\{6BD4F730-7630-4A97-93DF-E1A72F798589} folder moved successfully.
C:\Users\fefed\AppData\Local\{6BE24F9B-CAEA-410C-B4A5-DFCBBF5B0BF8} folder moved successfully.
C:\Users\fefed\AppData\Local\{6BEEFA17-FAC2-467F-937B-899F6163F9BE} folder moved successfully.
C:\Users\fefed\AppData\Local\{6C1383EE-8D43-4C1F-95A2-0CB5B267F7D9} folder moved successfully.
C:\Users\fefed\AppData\Local\{6C71B62D-7DA5-484A-BA20-3CE08A75EA47} folder moved successfully.
C:\Users\fefed\AppData\Local\{6CC70A17-3375-40D0-A6C4-E188667D12B5} folder moved successfully.
C:\Users\fefed\AppData\Local\{6CDB63DA-F9AA-4AB1-A457-7C6ECAF87372} folder moved successfully.
C:\Users\fefed\AppData\Local\{6D1D231D-C8A9-4519-9E57-196FE72E252F} folder moved successfully.
C:\Users\fefed\AppData\Local\{6DA6D5D4-9A3E-44F4-B02C-0A03C0F40E5B} folder moved successfully.
C:\Users\fefed\AppData\Local\{6DDB7B21-3B32-4D8A-A88A-8007DAA50F60} folder moved successfully.
C:\Users\fefed\AppData\Local\{6DDEB01A-3745-497E-B489-730CCACB354A} folder moved successfully.
C:\Users\fefed\AppData\Local\{6E4AF493-88D0-4682-A409-D306CDC795D3} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F20E80E-CA11-41C6-8329-DD70F6C23E01} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F25384E-8A84-4532-837E-D7CA511E63DF} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F3DC7D7-F83C-49BA-8F68-BE80E9EC94A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F4958FA-8B3D-4FE1-96DB-C56F3C2D47A2} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F8F86D5-2DEE-421B-B867-AD2157D549F0} folder moved successfully.
C:\Users\fefed\AppData\Local\{6F94EA51-14DD-4E9C-9F27-9DC313B1AF8F} folder moved successfully.
C:\Users\fefed\AppData\Local\{6FC87F77-55C1-4B1A-8CD0-18CE289A811C} folder moved successfully.
C:\Users\fefed\AppData\Local\{702CE58F-A4B0-4DA2-A3BA-F77E51C4DC3F} folder moved successfully.
C:\Users\fefed\AppData\Local\{704CF871-9EA8-48C1-B36B-EFBB89F7F844} folder moved successfully.
C:\Users\fefed\AppData\Local\{709D0304-E2DB-4721-824B-3602BA8B6603} folder moved successfully.
C:\Users\fefed\AppData\Local\{70B5E33A-5281-4845-900D-D9E488E18997} folder moved successfully.
C:\Users\fefed\AppData\Local\{70E63850-44BC-4B09-8D74-B1293D04C488} folder moved successfully.
C:\Users\fefed\AppData\Local\{70FABA1B-97F1-4D65-9547-5EE864F79212} folder moved successfully.
C:\Users\fefed\AppData\Local\{712ADE5E-B791-4B44-ABC0-23AD0DB3072F} folder moved successfully.
C:\Users\fefed\AppData\Local\{7159644D-65B7-44A2-888A-97C89FF130F5} folder moved successfully.
C:\Users\fefed\AppData\Local\{715B776D-92FC-4635-9341-9E848EA77E1C} folder moved successfully.
C:\Users\fefed\AppData\Local\{715EB964-3F45-45C5-9B36-FC225388C6FD} folder moved successfully.
C:\Users\fefed\AppData\Local\{7175BF87-DFFD-48BB-A695-A9AF3030DC27} folder moved successfully.
C:\Users\fefed\AppData\Local\{72126A12-C801-4965-BF1F-A578525E37A4} folder moved successfully.
C:\Users\fefed\AppData\Local\{722BED36-3396-4719-A0A3-4D7EB9270BE0} folder moved successfully.
C:\Users\fefed\AppData\Local\{72410646-07A0-4609-86E0-D889C30413FA} folder moved successfully.
C:\Users\fefed\AppData\Local\{727803C3-9944-460A-9BB9-54D30E9A93CC} folder moved successfully.
C:\Users\fefed\AppData\Local\{72EAFCB3-54D1-447B-942E-B9240F2A85D5} folder moved successfully.
C:\Users\fefed\AppData\Local\{733E04A6-9E28-4E08-9DAB-FCF0260C6F23} folder moved successfully.
C:\Users\fefed\AppData\Local\{737B9033-4BFF-4862-9CD7-FB53B857C927} folder moved successfully.
C:\Users\fefed\AppData\Local\{73AC12EE-764E-426C-8E82-20B09495F20D} folder moved successfully.
C:\Users\fefed\AppData\Local\{7437E1F4-7AC3-44E4-A4FF-AAFF1934A3AD} folder moved successfully.
C:\Users\fefed\AppData\Local\{748AB907-24F3-4466-BAA2-1459D54A97C9} folder moved successfully.
C:\Users\fefed\AppData\Local\{74A2D729-0D28-4744-A076-C3EAA96F1165} folder moved successfully.
C:\Users\fefed\AppData\Local\{74D3A214-2DA2-4566-8964-B2041E671F08} folder moved successfully.
C:\Users\fefed\AppData\Local\{74DE5598-1B41-4F32-9E5A-A7C8F42888E2} folder moved successfully.
C:\Users\fefed\AppData\Local\{74E7B935-3943-4444-9DC0-7201DBE87073} folder moved successfully.
C:\Users\fefed\AppData\Local\{75419EAB-EAD5-406F-BB5E-A0784C28F5AA} folder moved successfully.
C:\Users\fefed\AppData\Local\{75B76322-0B18-4BFC-877D-04B2A6DFC4EF} folder moved successfully.
C:\Users\fefed\AppData\Local\{76132C4B-1828-4C67-93AE-D18CFC722D06} folder moved successfully.
C:\Users\fefed\AppData\Local\{762C2B99-DC14-4A46-908A-8BB6D41C58F7} folder moved successfully.
C:\Users\fefed\AppData\Local\{76335BD0-82CA-4D7B-AC4D-5B0AF8EE3048} folder moved successfully.
C:\Users\fefed\AppData\Local\{765C0746-9951-43EB-8A1D-23AC171EBFF8} folder moved successfully.
C:\Users\fefed\AppData\Local\{76B4FE98-BC00-403A-AF66-5C0D0FB40615} folder moved successfully.
C:\Users\fefed\AppData\Local\{76EC610A-FE6C-469A-86A2-D1CDC01D49D0} folder moved successfully.
C:\Users\fefed\AppData\Local\{770A34B9-0B3A-4205-A536-E5DF7C15F2DB} folder moved successfully.
C:\Users\fefed\AppData\Local\{7779B77A-EDD6-4B78-ADAB-D5BECC973248} folder moved successfully.
C:\Users\fefed\AppData\Local\{77895376-2E8C-4AB6-B6AD-83B550FC9815} folder moved successfully.
C:\Users\fefed\AppData\Local\{77EA3675-2A46-4B88-9055-65491E2039CD} folder moved successfully.
C:\Users\fefed\AppData\Local\{781FFC45-F263-41E7-9F6C-FA8CB2C1A4DE} folder moved successfully.
C:\Users\fefed\AppData\Local\{784DEC6C-D901-4F92-AB3B-617FA3D86B24} folder moved successfully.
C:\Users\fefed\AppData\Local\{78796E17-8928-4855-9218-D1EE3D5DF182} folder moved successfully.
C:\Users\fefed\AppData\Local\{78D5AD6F-41F6-44B1-9A71-BDAB5D3D3BA5} folder moved successfully.
C:\Users\fefed\AppData\Local\{78E312B5-3B23-4FC0-A2B3-9CA903E2FA05} folder moved successfully.
C:\Users\fefed\AppData\Local\{7929B86D-D04F-4B8F-9205-215C33FC160B} folder moved successfully.
C:\Users\fefed\AppData\Local\{796D846A-95ED-4F45-B86B-40CB2A0AAD7B} folder moved successfully.
C:\Users\fefed\AppData\Local\{7995B0BF-2775-4409-9FC8-45C74F42F1B2} folder moved successfully.
C:\Users\fefed\AppData\Local\{79D6E03D-D56A-42AC-9EC9-09793C7F9417} folder moved successfully.
C:\Users\fefed\AppData\Local\{79F42E93-834C-4374-9217-ED1D286B9A2E} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A100838-853A-4064-99DE-A66537DE34B6} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A3B9E91-A24F-4583-A086-74BBDF14D8B0} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A7BF5F7-26D5-459C-988B-3FDADD3276E7} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A92DF55-EFA3-4B6B-96BB-F36F29779E6D} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A9714DA-610B-4C60-9F2B-979BE6DB36D2} folder moved successfully.
C:\Users\fefed\AppData\Local\{7A978892-111E-4C4B-8A2A-4B729204FFD2} folder moved successfully.
C:\Users\fefed\AppData\Local\{7AA76F9F-8A9B-4240-B96A-3A8B1A35F494} folder moved successfully.
C:\Users\fefed\AppData\Local\{7AD7EDB4-0F09-4E4B-83BF-56A6BA5CEB9F} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B02F0AF-566F-40CC-9798-226041816309} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B072E3B-5D17-4B37-8BE2-F8EC7A45D890} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B12648F-14E4-4EA0-A146-52D41202C94C} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B16A49A-2BF2-4D53-AE1D-CF84526C07BB} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B8ABC20-984D-4765-A3B7-3F417E2D5A99} folder moved successfully.
C:\Users\fefed\AppData\Local\{7B9748AA-FC8A-439A-AB9C-97992793DB3F} folder moved successfully.
C:\Users\fefed\AppData\Local\{7BC5EF03-39A7-4CAF-A11F-2B74A756AC71} folder moved successfully.
C:\Users\fefed\AppData\Local\{7C60F2CA-2E0B-4D88-90F1-8CE4188BB435} folder moved successfully.
C:\Users\fefed\AppData\Local\{7C7EFD42-D7B7-4B6A-9903-3DBC694E9937} folder moved successfully.
C:\Users\fefed\AppData\Local\{7C9AB738-B033-4699-BBC2-82BE6E417169} folder moved successfully.
C:\Users\fefed\AppData\Local\{7CDF22D2-6F00-44FC-B7BE-02745EDB0524} folder moved successfully.
C:\Users\fefed\AppData\Local\{7D17DEB5-3362-4C0A-8075-4E3DBBE91317} folder moved successfully.
C:\Users\fefed\AppData\Local\{7D1B2EA1-A9C2-4420-ACBD-B7BF106E9E4F} folder moved successfully.
C:\Users\fefed\AppData\Local\{7D94943B-AC3C-44F7-827B-F0F2EABAB7E9} folder moved successfully.
C:\Users\fefed\AppData\Local\{7DD4DE18-726F-40C8-BDD4-A8F8DF89CDA7} folder moved successfully.
C:\Users\fefed\AppData\Local\{7DDBB0C2-FAB1-4F30-AF2A-EC5C14F8EF06} folder moved successfully.
C:\Users\fefed\AppData\Local\{7DF74C8B-46ED-4C02-B23F-060F394BB2B5} folder moved successfully.
C:\Users\fefed\AppData\Local\{7DFF122B-D08B-430B-B04E-8BD83D4EE9C8} folder moved successfully.
C:\Users\fefed\AppData\Local\{7E0EDC85-1827-42EF-8475-D13C6C2FA8B3} folder moved successfully.
C:\Users\fefed\AppData\Local\{7E166E1F-FDA1-4586-B12C-90533E30E7D5} folder moved successfully.
C:\Users\fefed\AppData\Local\{7F3E49E2-4D0C-4109-8FAB-A8F032D911A4} folder moved successfully.
C:\Users\fefed\AppData\Local\{7F79CB0A-CB59-47D1-B659-1EE2E13093FC} folder moved successfully.
C:\Users\fefed\AppData\Local\{7FD05D8B-92B6-4750-ADD1-281913098CB6} folder moved successfully.
C:\Users\fefed\AppData\Local\{805B1A52-147E-4B2F-911A-E0E47D49B76E} folder moved successfully.
C:\Users\fefed\AppData\Local\{809922CD-3501-4ADD-B223-24371A323D87} folder moved successfully.
C:\Users\fefed\AppData\Local\{80B96277-D686-4634-A5FB-B7E9221B064C} folder moved successfully.
C:\Users\fefed\AppData\Local\{80CF44EB-2486-4E0C-8D30-2159499F8B7D} folder moved successfully.
C:\Users\fefed\AppData\Local\{80E039CF-52EC-4002-B4EC-C9331C004317} folder moved successfully.
C:\Users\fefed\AppData\Local\{80E30C7E-DD9F-4BBE-A039-532FEE2CE059} folder moved successfully.
C:\Users\fefed\AppData\Local\{80FA8E59-E472-4DD8-9A2D-0CC7D6316BFB} folder moved successfully.
C:\Users\fefed\AppData\Local\{8102D7EB-37FF-46C5-A7E1-31EAEACC19E7} folder moved successfully.
C:\Users\fefed\AppData\Local\{81369659-9C5B-416D-B026-4D248EBE373B} folder moved successfully.
C:\Users\fefed\AppData\Local\{8179B421-3BFF-4C93-BF23-51FAB5ADDB33} folder moved successfully.
C:\Users\fefed\AppData\Local\{81AA4698-AB11-459C-9B79-DF2E33175CEE} folder moved successfully.
C:\Users\fefed\AppData\Local\{81FDC3AD-BECD-4ADF-9490-F6F7DFE65647} folder moved successfully.
C:\Users\fefed\AppData\Local\{8202966A-6A70-4944-8E04-4A06631C5F2D} folder moved successfully.
C:\Users\fefed\AppData\Local\{8204C23A-C64B-476E-8E11-3F33DEF18052} folder moved successfully.
C:\Users\fefed\AppData\Local\{820EDA90-1ADD-4F64-A974-BA5F76EC2094} folder moved successfully.
C:\Users\fefed\AppData\Local\{821E9D3B-F52D-4A2C-B287-F971B570808A} folder moved successfully.
C:\Users\fefed\AppData\Local\{8265AF54-B127-41F9-869B-322FDEA3C488} folder moved successfully.
C:\Users\fefed\AppData\Local\{832470CF-2765-4D38-B4C8-E8EA9DE59CBB} folder moved successfully.
C:\Users\fefed\AppData\Local\{8344ED9D-1B24-4107-ADF5-F5775AA8D080} folder moved successfully.
C:\Users\fefed\AppData\Local\{838EB31B-F537-4FA5-A02D-40E9042A239D} folder moved successfully.
C:\Users\fefed\AppData\Local\{8394131E-BB9E-4533-A8BF-17F899DD6A23} folder moved successfully.
C:\Users\fefed\AppData\Local\{83E2636B-9751-4CEA-8100-21476268980D} folder moved successfully.
C:\Users\fefed\AppData\Local\{84171B1C-02EB-43EE-8EF4-EB56E1812334} folder moved successfully.
C:\Users\fefed\AppData\Local\{841CA719-D105-415E-81CB-976B34257EB1} folder moved successfully.
C:\Users\fefed\AppData\Local\{8420AC79-97B4-4582-A53E-A5335EB7EE84} folder moved successfully.
C:\Users\fefed\AppData\Local\{847D672E-F07A-41F6-ACB9-34B8AA65B4A1} folder moved successfully.
C:\Users\fefed\AppData\Local\{8491CAD7-F3D8-4672-A625-C2B35EB2A9AB} folder moved successfully.
C:\Users\fefed\AppData\Local\{84F13EFE-7515-4B07-A949-8E84CB2FF025} folder moved successfully.
C:\Users\fefed\AppData\Local\{851FFAAD-BD6A-4492-8A25-27890BDB511B} folder moved successfully.
C:\Users\fefed\AppData\Local\{854E1A7A-F666-443D-B2CB-660944910E39} folder moved successfully.
C:\Users\fefed\AppData\Local\{85884270-356C-4FE3-94C6-959D5A7A7F7F} folder moved successfully.
C:\Users\fefed\AppData\Local\{85D35BE7-55CE-420D-8EC8-DD4602C0A1D6} folder moved successfully.
C:\Users\fefed\AppData\Local\{85EB1ECE-6C87-4630-BCA7-27CF0E0F84E3} folder moved successfully.
C:\Users\fefed\AppData\Local\{863C6CE0-B068-458F-8E4D-A887A2CE7309} folder moved successfully.
C:\Users\fefed\AppData\Local\{866DAA7A-AF88-47E6-B4AD-F00E1DF71FA1} folder moved successfully.
C:\Users\fefed\AppData\Local\{8675F5BD-05E9-4D4A-B3BC-5BED5D16BB7C} folder moved successfully.
C:\Users\fefed\AppData\Local\{8690E1A9-46A8-4129-A232-3A6BF6B9D731} folder moved successfully.
C:\Users\fefed\AppData\Local\{86958515-8957-4F42-B8AA-E6D70D0C79EC} folder moved successfully.
C:\Users\fefed\AppData\Local\{869F2D3E-0F1C-46B0-9898-B585C4D18A01} folder moved successfully.
C:\Users\fefed\AppData\Local\{86B8BED8-6AF2-47F8-AFAC-E7268C4017E1} folder moved successfully.
C:\Users\fefed\AppData\Local\{86E5DCE6-D2EE-485B-8B8C-F2CEFAE5AEE7} folder moved successfully.
C:\Users\fefed\AppData\Local\{870A2C15-1953-4470-8E32-1579B798A337} folder moved successfully.
C:\Users\fefed\AppData\Local\{874FBFB8-ECC5-4A55-ADB4-82FF4D53BDDD} folder moved successfully.
C:\Users\fefed\AppData\Local\{87FF701B-5DDB-4188-B38E-F29F2652F238} folder moved successfully.
C:\Users\fefed\AppData\Local\{88028994-A086-4DDC-8BB5-F773A44446F4} folder moved successfully.
C:\Users\fefed\AppData\Local\{8834869C-F733-4790-B0C6-780BD07238B9} folder moved successfully.
C:\Users\fefed\AppData\Local\{8868ABAB-C75B-422F-BB9F-398DC55846DA} folder moved successfully.
C:\Users\fefed\AppData\Local\{888096C0-3DB4-45E3-8A37-6FEA97101AF1} folder moved successfully.
C:\Users\fefed\AppData\Local\{88892A4D-3A18-443F-9037-70152BF2B1D7} folder moved successfully.
C:\Users\fefed\AppData\Local\{889CCF33-27EC-4698-8EC0-90BA36B45885} folder moved successfully.
C:\Users\fefed\AppData\Local\{88E9A225-E91C-4F27-8822-41A676FC7198} folder moved successfully.
C:\Users\fefed\AppData\Local\{8909EBBE-FC44-4248-B568-4648358DF68B} folder moved successfully.
C:\Users\fefed\AppData\Local\{8966B3D3-78B4-4DD5-A8DD-EA4645F4C21C} folder moved successfully.
C:\Users\fefed\AppData\Local\{897AD6CD-38A2-4A37-BE94-5401A26F5D51} folder moved successfully.
C:\Users\fefed\AppData\Local\{89821E99-B0DD-43EF-88AF-824037BA8EED} folder moved successfully.
C:\Users\fefed\AppData\Local\{898FE7F1-5896-404D-A7B0-424806EB005F} folder moved successfully.
C:\Users\fefed\AppData\Local\{8A0416B5-3CD2-4359-96F0-35BB33CD6B05} folder moved successfully.
C:\Users\fefed\AppData\Local\{8A05DE56-4FB0-41D7-9A6C-49552EF249BC} folder moved successfully.
C:\Users\fefed\AppData\Local\{8A09C0AF-B502-4871-BB38-21321DFCC9A2} folder moved successfully.