Stránka 1 z 1

Problemy s pravami

Napsal: 25 dub 2015 22:20
od Piccolo
Zdravim pani,
vcera mi zacal blbnut komp, vzdy ked som chcel nieco kopirovat na C alebo stahovat tak to chcelo aby som to robil ako admin (pritom som...), tak myslim ze sa mi nejaky cervik zavrtal do systemu...
skuste mi niekto na to mrknut :) vdaka moc

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Piccolo at 2015-04-25 23:07:48
Microsoft Windows 7 Ultimate  Service Pack 1
System drive C: has 85 GB (9%) free of 954 GB
Total RAM: 3999 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:07:49, on 25. 4. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files\trend micro\Piccolo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe                                                                                                                                                                                                               
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"                                                                                                                                                                                                         
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices                                                                                                                                                                                            
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3BF2F46-5EBC-45F3-83C1-2ED48274C9ED}: NameServer = 8.8.8.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10431 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe"
taskeng.exe {F15790D5-B64C-458E-946F-71731A6C8D4C}
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {CE4F9DE2-BBFF-4FA8-9715-2729B76A6D44}
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
"C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe"
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\RocketDock\RocketDock.exe" 
"C:\Program Files (x86)\Winamp\winampa.exe" 
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2056
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe" /TUStart /pid:2968
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k HPService
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\totalcmd\TOTALCMD.EXE" 
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"D:\Downloads\RSITx64.exe" 

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe  
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS\AutoKMS.exe  

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-01-19 553896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-01-19 211880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-08-07 6827664]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"RocketDock"=C:\Program Files (x86)\RocketDock\RocketDock.exe [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2009-04-22 37888]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-20 767176]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2015-04-25 22:33:10 ----D---- C:\rsit
2015-04-25 22:33:10 ----D---- C:\Program Files\trend micro
2015-04-25 20:47:10 ----SHD---- C:\$RECYCLE.BIN
2015-04-25 20:46:33 ----A---- C:\ComboFix.txt
2015-04-25 17:23:53 ----HD---- C:\Config.Msi
2015-04-25 17:03:41 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-25 17:03:41 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-25 17:03:41 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-25 17:03:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-25 17:03:40 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-25 17:03:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-25 17:03:39 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-25 17:03:39 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-25 17:03:39 ----A---- C:\Windows\system32\iernonce.dll
2015-04-25 17:03:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-25 17:03:38 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-25 17:03:38 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-25 17:03:38 ----A---- C:\Windows\system32\urlmon.dll
2015-04-25 17:03:38 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-25 17:03:37 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-25 17:03:37 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-25 17:03:37 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-25 17:03:37 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-25 17:03:36 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-25 17:03:36 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-25 17:03:36 ----A---- C:\Windows\system32\iesetup.dll
2015-04-25 17:03:36 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-25 17:03:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-25 17:03:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-25 17:03:35 ----A---- C:\Windows\system32\iertutil.dll
2015-04-25 17:03:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-25 17:03:34 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-25 17:03:34 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-25 17:03:34 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-25 17:03:34 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-25 17:03:34 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\jscript9.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\ieui.dll
2015-04-25 17:03:33 ----A---- C:\Windows\system32\ieframe.dll
2015-04-25 17:03:32 ----A---- C:\Windows\system32\wininet.dll
2015-04-25 17:03:32 ----A---- C:\Windows\system32\vbscript.dll
2015-04-25 17:03:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-25 17:03:31 ----A---- C:\Windows\system32\msrating.dll
2015-04-25 17:03:31 ----A---- C:\Windows\system32\mshtml.dll
2015-04-25 17:03:26 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-04-25 17:03:26 ----A---- C:\Windows\system32\drmv2clt.dll
2015-04-25 17:03:26 ----A---- C:\Windows\system32\blackbox.dll
2015-04-25 17:03:25 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-04-25 17:03:24 ----A---- C:\Windows\system32\wmp.dll
2015-04-25 17:03:23 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-04-25 17:03:23 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-04-25 17:03:23 ----A---- C:\Windows\system32\mf.dll
2015-04-25 17:03:22 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-04-25 17:03:22 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-04-25 17:03:21 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-04-25 17:03:21 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-04-25 17:03:21 ----A---- C:\Windows\system32\crypt32.dll
2015-04-25 17:03:20 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-04-25 17:03:20 ----A---- C:\Windows\system32\winload.exe
2015-04-25 17:03:20 ----A---- C:\Windows\system32\quartz.dll
2015-04-25 17:03:20 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-04-25 17:03:20 ----A---- C:\Windows\system32\cryptsvc.dll
2015-04-25 17:03:20 ----A---- C:\Windows\system32\ci.dll
2015-04-25 17:03:19 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-04-25 17:03:19 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-04-25 17:03:19 ----A---- C:\Windows\system32\wintrust.dll
2015-04-25 17:03:19 ----A---- C:\Windows\system32\winresume.exe
2015-04-25 17:03:19 ----A---- C:\Windows\system32\evr.dll
2015-04-25 17:03:18 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-04-25 17:03:18 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-04-25 17:03:18 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-04-25 17:03:18 ----A---- C:\Windows\system32\pcasvc.dll
2015-04-25 17:03:18 ----A---- C:\Windows\system32\mfplat.dll
2015-04-25 17:03:18 ----A---- C:\Windows\system32\cryptui.dll
2015-04-25 17:03:17 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-04-25 17:03:17 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-04-25 17:03:17 ----A---- C:\Windows\system32\msscp.dll
2015-04-25 17:03:17 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-04-25 17:03:17 ----A---- C:\Windows\system32\cryptsp.dll
2015-04-25 17:03:16 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-04-25 17:03:16 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-04-25 17:03:16 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-04-25 17:03:16 ----A---- C:\Windows\system32\msnetobj.dll
2015-04-25 17:03:16 ----A---- C:\Windows\system32\drivers\appid.sys
2015-04-25 17:03:16 ----A---- C:\Windows\system32\cryptnet.dll
2015-04-25 17:03:16 ----A---- C:\Windows\system32\audiosrv.dll
2015-04-25 17:03:16 ----A---- C:\Windows\system32\audiodg.exe
2015-04-25 17:03:16 ----A---- C:\Windows\system32\appidsvc.dll
2015-04-25 17:03:16 ----A---- C:\Windows\system32\appidapi.dll
2015-04-25 17:03:15 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-04-25 17:03:15 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-04-25 17:03:15 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-04-25 17:03:15 ----A---- C:\Windows\system32\rrinstaller.exe
2015-04-25 17:03:15 ----A---- C:\Windows\system32\qdvd.dll
2015-04-25 17:03:15 ----A---- C:\Windows\system32\AudioSes.dll
2015-04-25 17:03:15 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-04-25 17:03:14 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-04-25 17:03:14 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-04-25 17:03:14 ----A---- C:\Windows\system32\pcadm.dll
2015-04-25 17:03:14 ----A---- C:\Windows\system32\mfps.dll
2015-04-25 17:03:14 ----A---- C:\Windows\system32\AudioEng.dll
2015-04-25 17:03:14 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-04-25 17:03:12 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-04-25 17:03:12 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-04-25 17:03:12 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-04-25 17:03:12 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-04-25 17:03:12 ----A---- C:\Windows\system32\pcawrk.exe
2015-04-25 17:03:12 ----A---- C:\Windows\system32\pcalua.exe
2015-04-25 17:03:12 ----A---- C:\Windows\system32\msmmsp.dll
2015-04-25 17:03:12 ----A---- C:\Windows\system32\mfpmp.exe
2015-04-25 17:03:12 ----A---- C:\Windows\system32\EncDump.dll
2015-04-25 17:03:11 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-04-25 17:03:08 ----A---- C:\Windows\system32\spwmp.dll
2015-04-25 17:03:06 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-04-25 17:03:06 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-04-25 17:03:06 ----A---- C:\Windows\system32\dxmasf.dll
2015-04-25 17:03:05 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-04-25 17:03:05 ----A---- C:\Windows\system32\pcaevts.dll
2015-04-25 17:03:05 ----A---- C:\Windows\system32\mferror.dll
2015-04-25 17:03:04 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-04-25 17:03:04 ----A---- C:\Windows\system32\wmploc.DLL
2015-04-25 17:02:55 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-04-25 17:02:55 ----A---- C:\Windows\system32\pku2u.dll
2015-04-25 17:02:50 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-25 17:02:50 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-25 17:02:49 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-25 17:02:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-25 17:02:49 ----A---- C:\Windows\system32\wuapp.exe
2015-04-25 17:02:48 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wups2.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wups.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wudriver.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wucltux.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wuapi.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-25 17:02:48 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-25 17:02:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-25 17:02:27 ----A---- C:\Windows\system32\ntdll.dll
2015-04-25 17:02:27 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-25 17:02:26 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-25 17:02:26 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-25 17:02:26 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-25 17:02:26 ----A---- C:\Windows\system32\schannel.dll
2015-04-25 17:02:26 ----A---- C:\Windows\system32\kerberos.dll
2015-04-25 17:02:25 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-25 17:02:25 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-25 17:02:25 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-25 17:02:25 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-25 17:02:25 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-25 17:02:25 ----A---- C:\Windows\system32\kernel32.dll
2015-04-25 17:02:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-25 17:02:25 ----A---- C:\Windows\system32\drivers\cng.sys
2015-04-25 17:02:24 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-25 17:02:24 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-25 17:02:24 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-25 17:02:24 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-25 17:02:24 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\wow64win.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\wow64.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\wdigest.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\srcore.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\smss.exe
2015-04-25 17:02:24 ----A---- C:\Windows\system32\rstrui.exe
2015-04-25 17:02:24 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-25 17:02:24 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-25 17:02:24 ----A---- C:\Windows\system32\conhost.exe
2015-04-25 17:02:24 ----A---- C:\Windows\system32\adtschema.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-25 17:02:23 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\winsrv.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\sspicli.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\srclient.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\secur32.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\msaudite.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\lsass.exe
2015-04-25 17:02:23 ----A---- C:\Windows\system32\credssp.dll
2015-04-25 17:02:23 ----A---- C:\Windows\system32\auditpol.exe
2015-04-25 17:02:23 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-25 17:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-25 17:02:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-25 17:02:22 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-25 17:02:22 ----A---- C:\Windows\system32\msobjs.dll
2015-04-25 17:02:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-25 17:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-25 17:02:21 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-25 17:02:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-25 17:02:08 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-04-25 17:02:08 ----A---- C:\Windows\system32\shell32.dll
2015-04-25 17:02:06 ----A---- C:\Windows\system32\nlasvc.dll
2015-04-25 17:02:05 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-04-25 17:02:05 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-04-25 17:02:05 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-04-25 17:02:05 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-04-25 17:02:05 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-04-25 17:02:05 ----A---- C:\Windows\system32\lpk.dll
2015-04-25 17:02:05 ----A---- C:\Windows\system32\dciman32.dll
2015-04-25 17:02:05 ----A---- C:\Windows\system32\atmlib.dll
2015-04-25 17:02:05 ----A---- C:\Windows\system32\atmfd.dll
2015-04-25 17:02:04 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-04-25 17:02:04 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-25 17:02:04 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-04-25 17:02:04 ----A---- C:\Windows\system32\profsvc.dll
2015-04-25 17:02:04 ----A---- C:\Windows\system32\gdi32.dll
2015-04-25 17:02:04 ----A---- C:\Windows\system32\fontsub.dll
2015-04-25 17:02:04 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-04-25 17:02:03 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-04-25 17:02:02 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-04-25 17:02:02 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-04-25 17:02:01 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-25 17:02:01 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-04-25 17:02:01 ----A---- C:\Windows\system32\msxml3.dll
2015-04-25 17:02:01 ----A---- C:\Windows\system32\msctf.dll
2015-04-25 17:02:00 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-25 17:02:00 ----A---- C:\Windows\system32\rdpudd.dll
2015-04-25 17:02:00 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-04-25 17:02:00 ----A---- C:\Windows\system32\rdpcorets.dll
2015-04-25 17:02:00 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-25 17:01:59 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-04-25 17:01:59 ----A---- C:\Windows\system32\ubpm.dll
2015-04-25 17:01:57 ----A---- C:\Windows\system32\win32k.sys
2015-04-25 17:01:52 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-04-25 17:01:52 ----A---- C:\Windows\system32\scesrv.dll
2015-04-25 17:01:41 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-25 17:01:41 ----A---- C:\Windows\system32\clfs.sys
2015-04-25 17:01:40 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-25 17:01:40 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-25 16:56:07 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-04-25 16:56:07 ----A---- C:\Windows\system32\WMPhoto.dll
2015-04-25 16:24:28 ----D---- C:\ProgramData\Malwarebytes
2015-04-23 22:39:12 ----A---- C:\Windows\zip.exe
2015-04-23 22:39:12 ----A---- C:\Windows\SWSC.exe
2015-04-23 22:39:12 ----A---- C:\Windows\SWREG.exe
2015-04-23 22:39:12 ----A---- C:\Windows\sed.exe
2015-04-23 22:39:12 ----A---- C:\Windows\PEV.exe
2015-04-23 22:39:12 ----A---- C:\Windows\NIRCMD.exe
2015-04-23 22:39:12 ----A---- C:\Windows\MBR.exe
2015-04-23 22:39:12 ----A---- C:\Windows\grep.exe
2015-04-23 22:37:34 ----D---- C:\Windows\ERDNT
2015-04-23 22:37:01 ----D---- C:\Qoobox
2015-04-22 13:42:41 ----D---- C:\Program Files\Rockstar Games
2015-04-14 19:45:37 ----D---- C:\Program Files (x86)\Hearthstone
2015-04-11 16:37:37 ----D---- C:\Users\Piccolo\AppData\Roaming\Kalypso Media
2015-04-11 16:22:04 ----D---- C:\Program Files (x86)\Kalypso Media
2015-04-11 12:10:37 ----D---- C:\Users\Piccolo\AppData\Roaming\Running with rifles
2015-04-11 11:59:16 ----D---- C:\Program Files (x86)\Modulaatio Games

======List of files/folders modified in the last 1 month======

2015-04-25 23:07:23 ----D---- C:\Windows\Tasks
2015-04-25 23:06:59 ----D---- C:\Windows\Temp
2015-04-25 23:06:26 ----D---- C:\Windows\system32\config
2015-04-25 22:33:10 ----RD---- C:\Program Files
2015-04-25 22:06:37 ----D---- C:\Users\Piccolo\AppData\Roaming\Skype
2015-04-25 21:01:51 ----D---- C:\Program Files (x86)\Heroes of the Storm
2015-04-25 20:58:23 ----D---- C:\Windows\System32
2015-04-25 20:58:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-25 20:36:01 ----D---- C:\Windows
2015-04-25 20:36:01 ----A---- C:\Windows\system.ini
2015-04-25 20:27:59 ----D---- C:\Windows\SYSWOW64\drivers
2015-04-25 20:27:59 ----D---- C:\Windows\SysWOW64
2015-04-25 20:27:59 ----D---- C:\Windows\AppPatch
2015-04-25 20:27:58 ----D---- C:\Program Files (x86)\Common Files
2015-04-25 20:17:46 ----D---- C:\Windows\system32\drivers
2015-04-25 20:15:01 ----D---- C:\Windows\system32\Tasks
2015-04-25 20:13:25 ----D---- C:\Windows\Minidump
2015-04-25 18:30:45 ----D---- C:\Windows\Microsoft.NET
2015-04-25 18:14:19 ----RSD---- C:\Windows\assembly
2015-04-25 17:42:03 ----D---- C:\Windows\system32\catroot2
2015-04-25 17:35:00 ----D---- C:\Windows\winsxs
2015-04-25 17:30:42 ----D---- C:\Windows\system32\catroot
2015-04-25 17:30:02 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-04-25 17:30:02 ----D---- C:\Windows\SYSWOW64\Dism
2015-04-25 17:30:02 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-04-25 17:30:02 ----D---- C:\Program Files\Windows Media Player
2015-04-25 17:30:02 ----D---- C:\Program Files (x86)\Windows Media Player
2015-04-25 17:30:01 ----D---- C:\Windows\system32\sk-SK
2015-04-25 17:30:01 ----D---- C:\Windows\system32\en-US
2015-04-25 17:30:01 ----D---- C:\Windows\system32\Dism
2015-04-25 17:30:01 ----D---- C:\Windows\system32\cs-CZ
2015-04-25 17:30:01 ----D---- C:\Windows\system32\CodeIntegrity
2015-04-25 17:30:01 ----D---- C:\Windows\system32\Boot
2015-04-25 17:29:58 ----D---- C:\Windows\SYSWOW64\en-US
2015-04-25 17:29:57 ----D---- C:\Program Files\Internet Explorer
2015-04-25 17:29:56 ----D---- C:\Windows\PolicyDefinitions
2015-04-25 17:29:55 ----D---- C:\Program Files (x86)\Internet Explorer
2015-04-25 17:28:47 ----SHD---- C:\Windows\Installer
2015-04-25 17:28:46 ----D---- C:\ProgramData\Microsoft Help
2015-04-25 17:27:29 ----D---- C:\Program Files\SharePoint Client Components
2015-04-25 17:18:01 ----D---- C:\Windows\system32\MRT
2015-04-25 17:13:46 ----D---- C:\Windows\debug
2015-04-25 17:13:38 ----A---- C:\Windows\win.ini
2015-04-25 17:10:18 ----D---- C:\Program Files\Microsoft Security Client
2015-04-25 17:10:17 ----D---- C:\Program Files (x86)\Microsoft Security Client
2015-04-25 17:05:14 ----SHD---- C:\System Volume Information
2015-04-25 16:49:30 ----RD---- C:\Program Files (x86)
2015-04-25 16:46:21 ----D---- C:\Windows\Downloaded Program Files
2015-04-25 16:44:22 ----D---- C:\Downloads
2015-04-25 16:24:28 ----D---- C:\ProgramData
2015-04-25 16:06:08 ----D---- C:\Windows\system32\drivers\etc
2015-04-25 15:55:22 ----D---- C:\Windows\Prefetch
2015-04-24 19:18:59 ----D---- C:\Users\Piccolo\AppData\Roaming\Winamp
2015-04-24 17:36:19 ----D---- C:\Users\Piccolo\AppData\Roaming\uTorrent
2015-04-23 22:36:49 ----D---- C:\Windows\inf
2015-04-23 22:35:16 ----D---- C:\Users\Piccolo\AppData\Roaming\DAEMON Tools Lite
2015-04-23 22:35:15 ----D---- C:\Users\Piccolo\AppData\Roaming\Media Player Classic
2015-04-23 22:35:15 ----D---- C:\Program Files (x86)\Steam
2015-04-23 22:35:04 ----D---- C:\Windows\Panther
2015-04-23 22:34:56 ----D---- C:\Windows\SoftwareDistribution
2015-04-23 22:34:46 ----D---- C:\Windows\Logs
2015-04-23 22:33:33 ----D---- C:\Program Files (x86)\GMT-MAX.ORG
2015-04-22 13:42:48 ----D---- C:\Program Files (x86)\Rockstar Games
2015-04-21 18:48:32 ----D---- C:\Program Files (x86)\Freight Tycoon
2015-04-20 21:30:28 ----D---- C:\ProgramData\Epic
2015-04-17 18:29:52 ----D---- C:\Program Files (x86)\Battle.net
2015-04-14 22:56:48 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-10 19:06:39 ----D---- C:\Games
2015-04-09 19:55:07 ----D---- C:\Program Files (x86)\FTL
2015-04-09 18:01:21 ----D---- C:\VYMAZ
2015-04-09 17:53:42 ----D---- C:\Program Files (x86)\F1 2013
2015-04-09 17:46:40 ----D---- C:\Program Files (x86)\Age of Mythology Extended Edition
2015-04-06 14:09:27 ----D---- C:\Windows\system32\wdi
2015-04-02 16:48:48 ----D---- C:\Program Files (x86)\Sid Meier's Civilization V
2015-04-01 11:16:02 ----A---- C:\Windows\system32\MRT.exe
2015-03-30 13:00:24 ----D---- C:\aaa
2015-03-30 12:55:37 ----D---- C:\ProgramData\Unity
2015-03-27 23:37:06 ----D---- C:\Users\Piccolo\AppData\Roaming\.minecraft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-03-02 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2012-10-12 15232]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2012-10-12 14464]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [2009-09-17 145448]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-11-03 130536]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-11-03 395752]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-08-07 4102928]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-06-12 726160]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [2012-09-19 11880]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
S1 MpKsl4f960931;MpKsl4f960931; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8B9AB968-2383-4DF4-9C4C-56D40DF67A5B}\MpKsl4f960931.sys []
S1 PQNTDrv;PQNTDrv; C:\Windows\system32\drivers\PQNTDrv.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys [2010-07-29 29720]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 taphss6;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2013-02-22 42184]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S4 RsFx0105;RsFx0105 Driver; C:\Windows\system32\DRIVERS\RsFx0105.sys [2011-09-22 311144]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2014-11-20 344064]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [2012-10-12 920736]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [2012-10-12 951936]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [2012-10-12 149120]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2014-07-12 58387104]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-10-20 130024]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2012-11-02 2365792]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2014-12-03 448384]
S3 c2wts;@%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2010-02-03 15768]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2015-01-01 182304]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2013-08-22 142336]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-03-13 114688]
S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-04 87728]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-07-18 9216]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-03 1900400]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2014-07-12 441504]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2011-09-22 255336]
S4 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2015-01-17 762320]

-----------------EOF-----------------

Re: Problemy s pravami

Napsal: 26 dub 2015 07:15
od Márty84
Zdravim :)

:arrow: Nedavejte logy do Code, spatne se to cte.

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Problemy s pravami

Napsal: 26 dub 2015 09:54
od Piccolo
tu je ten OTL.txt (dal som to takto lebo je toho strasne vela a bolo by to na 7 stran :/ )

Kód: Vybrat vše

https://www.dropbox.com/s/gmkxqsa4mw8xjyw/OTL.Txt?dl=0

-----------

Extras.txt

OTL Extras logfile created on: 26. 4. 2015 8:42:00 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Piccolo\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17728)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy

3,91 Gb Total Physical Memory | 2,18 Gb Available Physical Memory | 55,87% Memory free
7,81 Gb Paging File | 5,51 Gb Available in Paging File | 70,60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 83,39 Gb Free Space | 8,95% Space Free | Partition Type: NTFS
Drive D: | 1397,25 Gb Total Space | 143,12 Gb Free Space | 10,24% Space Free | Partition Type: NTFS

Computer Name: PICCOLOPC | User Name: Piccolo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2341083737-2633030218-564279663-1000\SOFTWARE\Classes\<extension>]
.html [@ = Max3.Association.HTML] -- C:\Program Files\MaxthonC\Bin\Maxthon.exe (Maxthon International ltd.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{053650F2-6F24-4B9F-B11D-400B59F2A4DC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0A4421F0-AC43-4D7E-9ECD-AA6B86295DFA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{20EAE6FC-66B3-4A1A-A641-FC55DC33FCDE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2BC102A0-BDD5-4757-9DBA-7B4CD0B14010}" = lport=10243 | protocol=6 | dir=in | app=system |
"{33D8DC29-242C-4DEB-A34A-C42875EF30DF}" = lport=139 | protocol=6 | dir=in | app=system |
"{4AE159FA-CFFB-4D21-B878-F198B3E41226}" = rport=445 | protocol=6 | dir=out | app=system |
"{4DD756F9-0A5F-4DA3-BD37-C8728DFFBBEA}" = rport=138 | protocol=17 | dir=out | app=system |
"{6306E763-6F31-41FB-B644-62FD97EE4319}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{66E942A6-5954-4517-86E5-57C4D11A2A2A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{777CF831-A61C-4083-BA22-5FA4DA335727}" = lport=138 | protocol=17 | dir=in | app=system |
"{8018D34A-6B9B-4C40-9ADA-7BBBD53EBA52}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{83EBD474-D58D-4E66-AB51-CF20D519F437}" = lport=137 | protocol=17 | dir=in | app=system |
"{91CE3B86-2367-4EE2-ACFB-798957C1BA64}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{93873470-51C4-4D06-B09D-774B3B50CB81}" = lport=3702 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft visual studio 12.0\common7\ide\devenv.exe |
"{96C220CE-81BE-4415-BEA0-B6C84CA95B61}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{A773BE9A-20B9-43EA-9C8F-9B3A6DB8C661}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AC1A9FE3-BE10-4E39-9617-42DE27A6623E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B20D64DB-F246-4FE6-9AC9-36787FF7B1F8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B297350C-81AE-4D4E-AE20-09E731E4282A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BA07A81D-4AFE-4A53-B19B-1CC4BC01F3C2}" = rport=137 | protocol=17 | dir=out | app=system |
"{D647B92B-C3EA-43E2-96C2-28B98B542D8D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D9469E44-0B0E-4CFE-B43F-1B380721D4BB}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{DF352997-6D76-4C8A-B529-B53896CEC133}" = lport=445 | protocol=6 | dir=in | app=system |
"{E07945FB-ACC1-4977-A5D8-61B70FD92544}" = rport=139 | protocol=6 | dir=out | app=system |
"{E7FBB4FE-97D7-4883-9E2C-21888F246829}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F2CC5728-11AF-4353-B9B8-0829A92F0928}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{F3661655-E58A-47BE-9B15-5E9BF047F676}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F5420099-3B40-4009-8DE8-6DBFFF37215D}" = lport=5353 | protocol=17 | dir=in | app=c:\users\piccolo\appdata\local\yandex\yandexbrowser\application\browser.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0494F3F3-AF1B-4AF4-95D2-1A3C2A7BC962}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{060063A6-D6A9-48DB-B4C5-BF4C18FF60CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe |
"{0A3DBEE1-1AAD-4118-AB68-B0CA2879416F}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{0B0D5D09-6431-4CF6-97AE-41DF193D870D}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{0E78D2A0-5A76-43F9-8CF8-642936992965}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\bioshock 2\mp\builds\binaries\bioshock2.exe |
"{11919D20-444B-45C0-A7BC-E834BFDFEE59}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{13320B77-532D-4A2B-82E6-3EA7A898F2F4}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{149754D4-C907-4B71-B1CA-02BF830C653E}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{159BC3D1-03CB-4111-9CA2-6471D23504C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{1CF4F1D8-6507-449C-AB8D-17196C9D8F9B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1D5736A3-10BD-4A04-B011-803B99D93D1D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{260DADF6-770A-43B4-9A6B-131DED1B5B45}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{2B40F0B5-E675-45B8-9729-74AC87198860}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2FF241D9-3376-4BB9-9531-58004CCFB45D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{323856A5-E75B-40DB-B75C-863980279686}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{35C42715-FF87-4FDC-9A19-5F307DD7DC14}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{36A414E9-D60C-4160-B759-5DE9EA8B0146}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{376183C6-B35D-40E7-8765-8A6A3919C693}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{38AF342E-800A-41C8-B3DE-45AB11A032A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{39FE2DD2-C4EA-4BF0-A689-9B62D3A2F32B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{3CF15900-1494-471A-B337-05AB4442A799}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{43D63748-544A-41E5-BEB6-3358B348C24A}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\bioshock 2\sp\builds\binaries\bioshock2.exe |
"{4521871D-0B75-4C20-B535-BB5F1E05C9D5}" = dir=out | app=%programfiles% (x86)\amplitude\endless space - disharmony\endlessspace.exe |
"{467453C9-66F9-4D8C-BA33-D97A880C556E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe |
"{471FC901-8A27-410D-A15B-39D8A2F59463}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{477ED9B7-6077-4747-8326-CF7C20798FCA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{4E11006E-4CBB-4555-8439-B16F8C9F87A2}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{4F2BC916-0028-4213-A926-BB39F8F59E76}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{4FFC5C42-9E6E-48C4-AB0D-1108F1552407}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{538E119E-CF69-4016-8794-586BC01CEE3F}" = dir=in | app=%programfiles% (x86)\kalypso media\disciples iii resurrection\disciplesiii.exe |
"{56EBDDAC-1C30-4ADD-B9A5-FF14DB9EF343}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{570B35A7-A413-41B3-990F-1E98D13F7FEA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{5737B884-73BC-4759-B7A3-041B121FED4A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{57FBA951-2FD3-496F-8CA9-C01D18161E54}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{58324B31-1A80-44BF-9A77-B3CC8770B058}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{585AB1B8-C519-4265-92DB-740B8D75B4E0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{59F94077-2871-43E1-B45D-C199E878CF6B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5EC2C05F-7957-4BDA-907D-43750F4BB5AF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{61642780-F580-41F2-B2B2-0375C6D808CA}" = protocol=17 | dir=in | app=c:\program files\maxthonc\bin\maxthon.exe |
"{624904F5-C87E-4848-83F2-45F553AF98FA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{63A07B5F-7489-4061-9574-73429E52860D}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\bioshock 2\mp\builds\binaries\bioshock2.exe |
"{63E2EAC3-4FA1-48A4-B278-BE94C724EC1E}" = protocol=17 | dir=in | app=c:\users\piccolo\appdata\roaming\utorrent\utorrent.exe |
"{64DDA543-77CC-4D57-8574-FFD255F1259E}" = protocol=17 | dir=in | app=c:\program files\maxthonc\bin\mxup.exe |
"{679D813E-16A4-44B4-9C0A-F9F00027B47A}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{68E7EED8-75AC-48FF-9432-245A21A69A51}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6B49239D-CF6C-48CD-8B15-1DB5582228D5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7B660EBC-3803-4D7A-AC57-25769A6264D3}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{7CBACB5D-33B3-4B9C-BFA3-38104D56228B}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{81F114AC-CDC8-4011-85B5-D4A6E2004E3C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal\hl2.exe |
"{845B03E6-E241-41D8-AE9C-B7225ACD81E4}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{88359BE4-5675-4C79-AF9C-20974D7B1346}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{886C0F03-1058-4C63-B5F7-9E1E9639F374}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"{8C01C951-8B3F-4D56-8597-B59F93D1C993}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{8D5CB23D-E382-4798-A145-3415016D2367}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal\hl2.exe |
"{8FDB97D3-950E-492C-8CD6-D607D1687108}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{9028BB8C-AEAC-4F6F-A3EA-376AE6E0F915}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{91FE7C59-8F48-4610-946D-E69283EDF12F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{99504B55-0F87-4D83-A74B-902A48AC9ED4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz_be.exe |
"{9BBF609B-8403-487E-9575-905C83E70F5D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{9CEEACAC-0BB6-4606-99BD-79E4B71E1AD4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9DC98804-C3DA-4011-8750-C8221FA14767}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1394C90-0838-44D7-9552-42949F28BE51}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{A13DD034-8127-40D6-830E-42374EA490E5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{A3318590-8B63-474E-B608-BA3B80DD323C}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"{A53ECEB8-3891-4657-9069-53258F3EE59F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A7662B5C-88EA-4963-BDCD-8A006723B5A8}" = protocol=6 | dir=in | app=c:\program files\maxthonc\bin\mxup.exe |
"{A835573B-DFC9-410E-B5D4-131E71B15E50}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{AADD795D-493A-46B3-9779-F65D10F7AF3C}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{AC73879B-7C82-4BFC-B922-A262C5D51ADF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{AE273C4D-1ADE-448B-8047-4276D0B74C24}" = protocol=6 | dir=in | app=c:\users\piccolo\appdata\roaming\utorrent\utorrent.exe |
"{AE70A1D3-632E-4A9C-B5D1-9D7EEAEF4943}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\robocraft\robocraft.exe |
"{AFAD9B1A-ED5A-499B-9853-04A4FC57590A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{B0D2B9B4-904F-40ED-AC5F-3B8F2154FB6C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B299B766-CB32-4772-9E84-BD3DA9A61FD9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{B47DB228-CD38-4B75-96B5-150A6C57C9A1}" = dir=out | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"{B50AA321-DB0C-480E-BA9A-B45D3D093C96}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{B55A2D33-60D4-4346-AB38-13E7238C662D}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{B8FB785C-9305-4C3D-A6E1-3C24864DD6C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{C3B137DE-F546-49DB-8AB4-AAC94ABDB1AB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{C556379A-1217-40DF-AF3E-A334B5A6D758}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C56F4ED9-DC9B-4DF9-ABC7-408D99A135EA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{C6626766-96CD-4B05-BA06-B218C38542A5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C8362EA8-B5A8-46D8-A499-619B2D712E7E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CAFF9642-1E2A-4887-9D5A-9B03C5D22301}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CCC232DC-664A-4F51-B5F9-5DDB4913268E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz.exe |
"{CEAD4D05-E3D2-4650-98ED-511296DC89F6}" = dir=out | app=%programfiles% (x86)\kalypso media\disciples iii resurrection\disciplesiii.exe |
"{CFF431BE-9CC3-4F0A-86C6-B7DB6BDA55AF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D7A849F2-F072-4FD9-AA86-294BF25A08B8}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{DDA3C0EB-2E82-4B2D-858F-2C72F5A4DEFC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dayz\dayz_be.exe |
"{E0BB2361-0866-4BC2-8284-7F5FC4868AD0}" = protocol=6 | dir=out | app=system |
"{E8B0932D-F8EC-4F71-B3F4-380B6B2EF0EE}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{EDB49C0A-2EBB-4129-9863-7435583605A4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\robocraft\robocraft.exe |
"{F00FD52D-14BD-4DF1-979D-E81D6BEAD918}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{F3C69C01-686A-44FA-A4B0-89F7EB28D320}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{F404DA27-8D01-439B-91B9-95C4C2B4DDC0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F54EC171-D6BF-4894-A15D-8DB836FBDB3D}" = protocol=6 | dir=in | app=c:\program files\maxthonc\bin\maxthon.exe |
"{F7B724E1-08D0-43BA-822C-6BB04B3C1B60}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F7FE969A-10E5-4674-985E-4D9E7659783D}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\bioshock 2\sp\builds\binaries\bioshock2.exe |
"TCP Query User{010BBAD1-7BC7-4A9D-A0A4-7E86A357954B}C:\program files (x86)\qip 2010\qip.exe" = protocol=6 | dir=in | app=c:\program files (x86)\qip 2010\qip.exe |
"TCP Query User{016C7E05-A37F-465D-9CBC-9C6C31E2F4AA}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"TCP Query User{0BC2AD62-0674-4184-A142-456BC6C3F150}C:\program files\epic games\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe" = protocol=6 | dir=in | app=c:\program files\epic games\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe |
"TCP Query User{0CAE64D3-F394-4270-BDCF-B1220674CEF7}C:\program files (x86)\r.g. mechanics\need for speed most wanted black edition\speed.exe" = protocol=6 | dir=in | app=c:\program files (x86)\r.g. mechanics\need for speed most wanted black edition\speed.exe |
"TCP Query User{15F8CAA8-BB07-4285-AC14-ED61BC2718B8}C:\program files (x86)\unity\editor\unity.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unity\editor\unity.exe |
"TCP Query User{179F24DF-53AC-4A4A-9066-4162F84CBA1B}C:\program files (x86)\space run\ospacegame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\space run\ospacegame.exe |
"TCP Query User{180F74B8-11C3-43A4-900F-250C2D7DD008}C:\games\starcraft ii\starfriend\starfriend_client.exe" = protocol=6 | dir=in | app=c:\games\starcraft ii\starfriend\starfriend_client.exe |
"TCP Query User{36861898-F1C8-488C-AF00-17098379CD89}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe |
"TCP Query User{3EB18083-3E97-4B4C-A2A1-76F791429AD3}C:\games\spacebase df-9 v1.06\space.exe" = protocol=6 | dir=in | app=c:\games\spacebase df-9 v1.06\space.exe |
"TCP Query User{598D3C2E-CFF9-4648-8511-038A092336E8}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{6D7DCA30-7D62-420B-9B52-94AEE15ACE2A}C:\program files (x86)\unityfree\monodevelop\bin\monodevelop.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unityfree\monodevelop\bin\monodevelop.exe |
"TCP Query User{8F7CA669-C783-4AD6-BD35-DD4E53A02F18}C:\program files (x86)\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terraria\terrariaserver.exe |
"TCP Query User{91AFA60E-BF3B-43D6-89C8-C422A2364446}C:\program files (x86)\unityfree\editor\unity.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unityfree\editor\unity.exe |
"TCP Query User{A165BFDE-CBE9-4C22-A7A1-F580FD9F1CC7}C:\downloads\ps2\planetside2.exe" = protocol=6 | dir=in | app=c:\downloads\ps2\planetside2.exe |
"TCP Query User{C4A4C64A-925C-4127-88D8-6A6E68C1CA8D}C:\gog games\the witcher 2 enhanced edition\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\gog games\the witcher 2 enhanced edition\bin\witcher2.exe |
"TCP Query User{C6E35E88-B55C-44EF-B1DF-C16DD67B2D24}C:\program files (x86)\strongdc++\strongdc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\strongdc++\strongdc.exe |
"TCP Query User{CC9D30FB-9210-4AB3-9902-A2EA516BA75D}C:\games\distance\distance.exe" = protocol=6 | dir=in | app=c:\games\distance\distance.exe |
"TCP Query User{DCD8AB59-C199-4860-BC72-62E94DEDCCC7}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe |
"TCP Query User{E02CED3A-95BF-47FE-9392-1A241EC265E5}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
"TCP Query User{E191F2A5-F260-4137-BCE3-860713749024}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unity\monodevelop\bin\monodevelop.exe |
"TCP Query User{E91A9438-6C88-4978-8570-203B1F44C172}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"TCP Query User{FF5C8B0E-2A90-4449-A26A-70E4AA269ADA}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{35276E30-34B7-49EE-88F9-3E2E64FC3AAE}C:\games\distance\distance.exe" = protocol=17 | dir=in | app=c:\games\distance\distance.exe |
"UDP Query User{3892577D-C775-41A8-B9A0-C96164AC6B02}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe |
"UDP Query User{3E7C58D4-D81D-44FE-9475-08D059E71D71}C:\program files (x86)\qip 2010\qip.exe" = protocol=17 | dir=in | app=c:\program files (x86)\qip 2010\qip.exe |
"UDP Query User{4495B3EA-F8B0-48F5-925E-092726F5D3DD}C:\program files\epic games\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe" = protocol=17 | dir=in | app=c:\program files\epic games\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe |
"UDP Query User{5FA035D0-AA1D-48DE-80FC-DAA72BC7D891}C:\program files (x86)\unity\editor\unity.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unity\editor\unity.exe |
"UDP Query User{8422B2DF-6159-4E1F-ADA0-4CFE179B5A57}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
"UDP Query User{84BFB05A-4B5E-4A63-BBA0-DB5AD9317C38}C:\downloads\ps2\planetside2.exe" = protocol=17 | dir=in | app=c:\downloads\ps2\planetside2.exe |
"UDP Query User{8623AA45-02EF-4AD9-BD4E-9D4BFC0908B3}C:\program files (x86)\r.g. mechanics\need for speed most wanted black edition\speed.exe" = protocol=17 | dir=in | app=c:\program files (x86)\r.g. mechanics\need for speed most wanted black edition\speed.exe |
"UDP Query User{921A0EA7-0FA2-4CDC-8CB2-DBA72872810B}C:\program files (x86)\unityfree\editor\unity.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unityfree\editor\unity.exe |
"UDP Query User{922FD422-1220-4E31-971B-BED427095BD3}C:\games\starcraft ii\starfriend\starfriend_client.exe" = protocol=17 | dir=in | app=c:\games\starcraft ii\starfriend\starfriend_client.exe |
"UDP Query User{9A6F5547-33AE-4F0E-8BB6-4DEBDD50D968}C:\program files (x86)\unity\monodevelop\bin\monodevelop.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unity\monodevelop\bin\monodevelop.exe |
"UDP Query User{A00A8E14-7AC2-401E-81AA-BE7BE234F38D}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{ADD40422-7F30-47CD-954E-B17C756FCCB6}C:\program files (x86)\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terraria\terrariaserver.exe |
"UDP Query User{B207C335-C4C1-4E94-912F-D6828A77C533}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{B8618B59-15AD-4B4F-ACFD-E7076C21F158}C:\program files (x86)\space run\ospacegame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\space run\ospacegame.exe |
"UDP Query User{C09EF3CE-5F59-45EF-9243-FA5C8BBA872F}C:\program files (x86)\strongdc++\strongdc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\strongdc++\strongdc.exe |
"UDP Query User{C1F4D579-63F2-4984-A071-832C83E6DA0A}C:\program files (x86)\unityfree\monodevelop\bin\monodevelop.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unityfree\monodevelop\bin\monodevelop.exe |
"UDP Query User{CB6DD545-FFF1-4B77-9151-18DA76A0BF5A}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe |
"UDP Query User{DC6F88A1-F07C-44D9-ADA0-02A31B3BD51E}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe |
"UDP Query User{E5F487A3-B402-4420-A655-BDACD63A591B}C:\games\spacebase df-9 v1.06\space.exe" = protocol=17 | dir=in | app=c:\games\spacebase df-9 v1.06\space.exe |
"UDP Query User{F00F3370-B9A3-4ADD-AF4A-7B775C7C2987}C:\gog games\the witcher 2 enhanced edition\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\gog games\the witcher 2 enhanced edition\bin\witcher2.exe |
"UDP Query User{F70ED068-1FBC-478E-A57C-CC1790E5BCA5}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034106B5-54B7-467F-B477-5B7DBB492624}" = Microsoft Sync Framework Services v1.0 SP1 (x64)
"{05198C22-FFCE-374A-B190-9F18CC99DAEA}" = Build Tools Language Resources - amd64
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{05FF8209-C4F1-4C77-BC28-791653156D20}" = Microsoft System CLR Types for SQL Server 2012 (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0B6BDD27-3097-4FE1-BDE6-1D5EC7399563}" = Visual Studio 2013 Prerequisites
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{16222DF7-8513-491E-91F0-F489AB2D3CB0}" = Visual Studio 2013 Prerequisites - ENU Language Pack
"{199C6892-5DED-409B-88B2-3BE6421552B2}" = Workflow Manager Client 1.0
"{1AB7EDC5-D891-34C5-9FF1-BE6A85ACC44B}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
"{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
"{1D2CEC61-C3F0-C27E-7280-F9D6B10378BE}" = Windows App Certification Kit Native Components
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1F4004F7-3BC0-3ABC-86F6-7A125D11F98B}" = Microsoft Office 2013 Developer Tools for Microsoft Visual Studio (x64)
"{2044FC4C-4EA3-4113-BC1E-962DF568D201}" = JavaScript Tooling
"{26A24AE4-039D-4CA4-87B4-2F06417071FF}" = Java 7 Update 71 (64-bit)
"{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}" = Microsoft SQL Server 2008 Native Client
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{325AC861-EDAF-440B-97DD-259906E216D3}" = Epic Games Launcher
"{3674F088-9B90-473A-AAC3-20A00D8D810C}" = Microsoft Web Deploy 3.5
"{393CA5BF-0362-42FD-ABC2-BA9D22EF925E}" = Microsoft SQL Server 2008 Setup Support Files
"{426582A8-202F-D13C-8BD5-F00551BAFC93}" = AMD Wireless Display v3.0
"{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}" = Microsoft SQL Server 2012 Management Objects (x64)
"{4701DEDE-1888-49E0-BAE5-857875924CA2}" = Microsoft SQL Server System CLR Types (x64)
"{49055838-1EF5-40BB-89B6-8E3456B3E817}" = Microsoft Visual Studio 2013 Performance Collection Tools - ENU
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{50813B8C-FCBB-3C61-8039-EAAA93029066}" = Microsoft .NET Framework 4.5.1 (CSY)
"{5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1}" = Windows Software Development Kit DirectX x64 Remote
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{54C5041B-0E91-4E92-8417-AAA12493C790}" = Microsoft SQL Server 2012 Transact-SQL ScriptDom
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{58FED865-4F13-408D-A5BF-996019C4B936}" = Microsoft SQL Server 2012 Command Line Utilities
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0170710}" = Java SE Development Kit 7 Update 71 (64-bit)
"{65C91666-C3E8-3A42-BDA8-87932DD34F89}" = Microsoft Team Foundation Server 2013 Object Model (x64)
"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English
"{6C026A91-640F-4A23-8B68-05D589CC6F18}" = Microsoft SQL Server 2012 Express LocalDB
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6D7131D1-87E5-4677-BD6A-08DCF2529076}" = Microsoft Visual Studio 2013 Performance Collection Tools
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{78909610-D229-459C-A936-25D92283D3FD}" = Microsoft SQL Server Compact 4.0 SP1 x64 ENU
"{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}" = IIS 8.0 Express
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{7F08A772-2816-4F46-84F1-49578502AD28}" = HP Deskjet F4500 Printer Driver Software 13.0 Rel .6
"{81455DEB-FC7E-3EE5-85CA-2EBDD9FD61EB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8438EC02-B8A9-462D-AC72-1B521349C001}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64)
"{88BAE373-00F4-3E33-828F-96E89E5E0CB9}" = Microsoft Visual Studio 2010 IntelliTrace Collection (x64)
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F2415FA-72F2-F029-0450-4EB2FAE484C5}" = AMD Accelerated Video Transcoding
"{8FF0ACBD-17A5-3637-95F4-D7C69723E2BF}" = Microsoft Visual Studio 2010 Performance Collection Tools SP1 - ENU
"{90120064-0070-0000-0000-4000000FF1CE}" = Microsoft Visual Basic for Applications 7.1 (x64)
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2010
"{90F60409-7000-11D3-8CFE-0150048383C9}" = Microsoft Visual Basic for Applications 7.1 (x64) English
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029" = Microsoft .NET Framework 4.5.1 (čeština)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95150001-1163-0409-1000-0000000FF1CE}" = SharePoint Client Components
"{95176218-0F93-3376-912E-B82DACCEA01B}" = Microsoft Visual C++ 2013 x64 Designtime - 12.0.21005
"{96F4525A-470D-F15C-796E-58D9988C3E5F}" = Windows Software Development Kit for Windows Store Apps DirectX x64 Remote
"{993F6DDC-63F8-4BCD-9B28-D941971A9CAC}" = Windows XP Targeting with C++
"{996D32B6-F629-4764-894B-CB24D9C19051}" = Microsoft Security Client
"{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb" = IIS Express Application Compatibility Database for x64
"{A6BA243E-85A3-4635-A269-32949C98AC7F}" = Microsoft SQL Server 2012 Data-Tier App Framework (x64)
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver
"{B74B199A-EDD4-B657-E055-327D454402D2}" = Windows Software Development Kit DirectX x64 Remote
"{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}" = Microsoft SQL Server 2012 Transact-SQL Compiler Service
"{C41498FE-0BF8-3B22-9785-231CE53C728E}" = Microsoft Team Foundation Server 2013 Object Model Language Pack (x64) - ENU
"{C458ABBB-B610-3195-80A2-A69E28332732}" = Microsoft Office 2013 Developer Tools for Microsoft Visual Studio (x64) - ENU Language Pack
"{C596D608-3E74-3232-8CA5-DF1DCB9F10DE}" = Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005
"{C6AB0C69-02C2-F4BA-3827-E1C9E24EF019}" = AMD Media Foundation Decoders
"{C74080EA-F5BE-C7AC-AD62-2EE612925E02}" = AMD Drag and Drop Transcoding
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}" = Microsoft SQL Server 2012 Native Client
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D57519D3-2E37-3E34-94AF-4D59BFAB87E6}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{DBAFD1B4-DDC5-DD01-D1C4-E7AEB5139097}" = AMD Fuel
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{E1F79421-EC32-437F-8525-ABE902C85AC5}" = Workflow Manager Tools 1.0 for Visual Studio
"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F17662A3-4569-4A61-ABD4-E51B632D3C4D}" = Microsoft Visual Studio 2013 VsGraphics Helper Dependencies
"{F2A7CE36-57BF-5C86-952D-90DBF3746D82}" = AMD Catalyst Install Manager
"{F5079164-1DB9-3BDA-853B-F78AF67CE071}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{F74753A3-C93C-34F5-A199-993CAF602B7D}" = Build Tools - amd64
"{F7FE0989-5F4C-3499-B78F-A63E942D100B}" = ccc-utility64
"{F99F24BF-0B90-463E-9658-3FD2EFC3C992}" = Microsoft Identity Extensions
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb" = IIS Express Application Compatibility Database for x86
"Android Studio" = Android Studio
"Blender" = Blender
"CCleaner" = CCleaner
"Factorio_is1" = Factorio version 0.11.3
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"jdownloader2" = JDownloader 2
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"pdfFactory Pro" = pdfFactory Pro
"Shop for HP Supplies" = Shop for HP Supplies
"SMPlayer" = SMPlayer 14.9.0.6558 (x64)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0099B899-7894-3B1D-9FF3-5992F84E631F}" = Microsoft LightSwitch for Visual Studio 2013 Core
"{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{0398BFBC-991B-3275-9463-D2BF91B3C80B}" = Microsoft Help Viewer 2.1
"{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}" = Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729
"{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}" = Microsoft SQL Server 2012 T-SQL Language Service
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{05855322-BE43-41FE-B583-D3AE0C326D58}" = Microsoft Silverlight 4 SDK
"{0610DFB0-CCEA-6EC0-E3C3-A0160AD7FD98}" = Windows Runtime Intellisense Content - en-us
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{06EEE072-B561-38E5-85D9-485ABCBE8342}" = Visual F# 3.1 SDK
"{070C38AC-05CE-43DF-9A20-141332F6AB2B}" = Microsoft System CLR Types for SQL Server 2012
"{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{08AEF86A-1956-4846-B906-B01350E96E30}" = Entity Framework Tools for Visual Studio 2013
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{09C52940-A4D1-4409-A7CC-1AAE630CF578}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{0B5E43C7-965D-4AF4-A33E-5FA35B6660C8}" = Behaviors SDK (XAML) for Visual Studio
"{0B698858-DAB0-4F9E-A10A-125B274EDA06}" = Microsoft Visual C++ x64 Libraries
"{0BE273CD-AAB9-361B-8C32-D955EAC929E3}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{0C03A66F-1FF0-45F9-8D67-0D806EBFFBA1}" = Blend for Visual Studio SDK for Silverlight 5
"{0CD05078-D4F3-4006-8726-B01E10A89B28}" = Movie Maker
"{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}" = Microsoft SQL Server Data Tools - enu (12.0.30919.1)
"{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}" = Microsoft Sync Framework SDK v1.0 SP1
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0FE3F13F-8A37-46BA-F973-762F81E833C3}" = CCC Help French
"{11087D24-567D-7D88-69C6-D7A08B5F4C47}" = Catalyst Control Center - Branding
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{14866AAD-1F23-39AC-A62B-7091ED1ADE64}" = Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1543E140-FADF-9E99-D388-4435C2FBC55E}" = CCC Help Chinese Standard
"{15BFD731-A10E-43E9-9D18-0F682BC0480F}" = Photo Common
"{1690CE56-2231-4E59-9006-A0876D949EA8}" = Tools for .Net 3.5
"{16A901BB-CD8E-3B48-9932-5927FB13508D}" = Microsoft SharePoint 2013 Developer Tools for Visual Studio
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{19A5926D-66E1-46FC-854D-163AA10A52D3}" = Microsoft .NET Framework 4.5.1 SDK
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1AA5BD63-6614-44B2-88A7-605191EDB835}" = Dotfuscator Software Services - Community Edition
"{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}" = Microsoft SQL Server 2012 Data-Tier App Framework
"{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}" = Minecraft
"{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1" = FTL version 1.5.10
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2386192E-D6DB-4AD2-9564-65586A0AE53E}" = Dotfuscator and Analytics Community Edition
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 67
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = The Battle for Middle-earth (tm) II
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C9A2369-162D-7AD7-D50F-5F59CEC8A046}" = CCC Help Danish
"{2D61415B-F99C-8161-F452-760B6E441428}" = CCC Help Hungarian
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F3E0052-438D-4D42-873C-94223F25FF7A}" = Windows Live UX Platform Language Pack
"{2F7DBBE6-8EBC-495C-9041-46A772F4E311}" = Microsoft SQL Server 2012 Management Objects
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{30F2491C-9410-4DB1-BE66-77B360B1F484}" = Microsoft Visual C++ x64-arm Cross Compilers
"{32136776-FE3F-453D-80DA-CDD993BDB2A3}" = Entity Framework Designer for Visual Studio 2012 - enu
"{339647D6-A277-974F-FF29-83CA6284559B}" = CCC Help German
"{34D3688E-A737-44C5-9E2A-FF73618728E1}" = AI Suite II
"{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}" = Prerequisites for SSDT
"{37464E70-B0B9-9DFF-649A-CBE169BAD657}" = Windows Software Development Kit for Windows Store Apps
"{37E53780-3944-4A6A-842F-727128E8616E}" = Blend for Visual Studio SDK for .NET 4.5
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}" = Smite
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3D2CF65C-B544-4308-B996-700D3E5F6C4C}" = Movie Maker
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{3E456233-1EA5-42ED-8556-0481BA728B41}" = Microsoft NuGet - Visual Studio 2013
"{3EA16E23-14D2-466A-8268-D7CD40DC46B6}" = Open XML SDK 2.5 for Microsoft Office
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{3FBFCF2C-392A-4632-9442-14C305B44D5E}" = AzureTools.Notifications
"{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform
"{4345E9A5-1300-4710-919D-077BA7E6B3DA}" = Windows Azure Mobile Services SDK
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45410935-B52C-468A-A836-0D1000018201}" = BulletStorm
"{46910786-E4AC-41E4-A4A0-C086EA85242D}" = WCF Data Services 5.6.0 Runtime
"{47AC83D4-C2CE-4F1F-8494-FB08066B38E3}" = Windows Live Essentials
"{492498A3-F88C-FE2F-755C-9B1B91724CA5}" = LocalESPC Dev12
"{492FCC0B-45E1-383A-A2CF-9E7F305AC200}" = Microsoft Visual Studio 2013 Team Explorer Language Pack - ENU
"{497072FE-0A75-4E5C-A5B7-EB1FA67F66F1}" = DJ_AIO_06_F4500_SW_MIN
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2
"{4AE57014-05C4-4864-A13D-86517A7E1BA4}" = Microsoft .NET Framework 4.5 SDK
"{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}" = Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729
"{4BD8FB0D-9407-429D-C412-FAE0A318A8AE}" = CCC Help Polish
"{4D594F78-0C6D-1442-61CC-94D735FEC05D}" = CCC Help English
"{4F2B8233-35EE-4197-8C3B-EACCBF712029}" = Microsoft SQL Server Data Tools - enu (11.1.20828.01)
"{504B7439-03BB-4C23-B17E-A1EC2D1D47B1}" = Sentinel System Driver Installer 7.5.2
"{5411060C-8F8C-393D-8D3B-26AF2C92FABB}" = Microsoft Visual Studio 2013 Shell (Minimum)
"{5481F163-B9E5-30A8-8441-4DBBB87D6AA2}" = Microsoft Visual C++ 2013 Microsoft Foundation Class Libraries
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{55A7B938-3D1E-4819-A87B-F83E736EF52E}" = F4500
"{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F}" = GetDataBack for NTFS
"{56AD3004-0B49-967F-F682-B05650B61A78}" = Windows Software Development Kit for Windows Store Apps DirectX x86 Remote
"{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}" = Microsoft .NET Framework 4.5 Multi-Targeting Pack
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5958C669-28BF-D667-A004-E6FBF448027D}" = CCC Help Spanish
"{5AB7D739-1735-3A9E-BE73-C43507CB4E6F}" = Microsoft Visual Studio 2010 Service Pack 1
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{5B87607E-E781-49C5-9891-80990E45BCA1}" = Fotogaléria
"{5D5CFAD6-9F93-8C63-3EB0-B6A0D3D4BD12}" = Windows Software Development Kit
"{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}" = WCF RIA Services V1.0 SP2
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{6321F2D4-366B-3AE4-877A-8E539EC3331A}" = Visual F# 3.1 VS
"{637B1239-84B7-0B0F-2549-7020CA57C831}" = CCC Help Thai
"{63CEA2E4-4FE7-4F2C-B388-C1313D24157C}" = SPORE™ Galactic Adventures
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{64297226-2B81-4588-89BD-76440BC0BCFC}" = Microsoft ASP.NET Web Pages 2 - Visual Studio 2013 - ENU
"{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer
"{6781FF9B-E87D-4A03-9373-A55A288B83FA}" = Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1)
"{678800C0-D94E-4513-89CB-478F2B781A0B}" = Microsoft Visual C++ 2013 x86-x64 Compilers
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{6A0C6700-EA93-372C-8871-DCCF13D160A4}" = Microsoft .NET Framework 4.5.1 Multi-Targeting Pack
"{6AB13C21-C3EC-46E1-8009-6FD5EBEE515B}" = Microsoft Advertising SDK for Windows 8.1 - ENU
"{6AE0A655-9BB8-460E-1956-ED37E3B221FA}" = CCC Help Greek
"{6B254D2F-6F6F-5455-DD3B-E71E5C1C0C9A}" = AMD Catalyst Control Center
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{6C06FEE9-C64E-453F-B8A5-D9E9B79ED040}" = Microsoft Visual C++ 2013 32bit Compilers - ENU Resources
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6DA2B636-698A-3294-BF4A-B5E11B238CDD}" = Microsoft Visual C++ 2008 x64 MFC Runtime 9.0.30729
"{6dff50d0-3bc3-4a92-b724-bf6d6a99de4f}" = Microsoft Visual Studio Professional 2013
"{6EE9E2DF-2CD7-4952-A649-95DEA8697BD8}" = Microsoft Exchange Web Services Managed API 2.0
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72076159-B94A-42AE-A64C-CA3855E9CB28}" = Windows Azure Tools for LightSwitch for Visual Studio 2013 - v2.1
"{721C380F-E296-4118-9ACE-589E8EF86208}" = Microsoft Visual Studio 2013 Profiling Tools
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{74602099-9B8D-4799-B349-928B8BDE6E06}" = Microsoft DirectX SDK (December 2006)
"{7481E13B-EC16-1B14-0E32-E88165CD4C57}" = Catalyst Control Center Graphics Previews Common
"{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}" = Microsoft SQL Server 2008 R2 Management Objects
"{794D38B6-C8B2-4DFC-BF1B-122233A336F3}" = Microsoft ASP.NET Web Frameworks and Tools - Visual Studio 2013 - ENU
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7A56D81D-6406-40E7-9184-8AC1769C4D69}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{7ABA4B54-3672-0548-C1CC-97405F767061}" = CCC Help Russian
"{7FE73251-50FA-E864-67EB-19C4BC7AA1C9}" = CCC Help Portuguese
"{82DAD82D-0139-3F7A-A22F-67A694F9CAA4}" = Microsoft LightSwitch for Visual Studio 2013 CoreRes - ENU
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84D88F57-4130-30FE-A0B6-1E04428FE1F6}" = Microsoft Visual C++ 2013 Core Libraries
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{877B76B2-F83F-4F5A-B28D-3F398641ADB6}" = Microsoft SQL Server System CLR Types
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{894CBED0-8225-D59B-5632-D01B14C6D520}" = CCC Help Norwegian
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8BD7C51C-0CC4-3E28-CFDC-F7D4C5583783}" = CCC Help Finnish
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}" = Microsoft Visual C++ 2008 x64 OpenMP Runtime 9.0.30729
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8ECCC07B-83E3-3877-26DF-815CD2B30749}" = CCC Help Italian
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{900FD4B9-9C27-D907-36E7-E9CCF170E2FC}" = Catalyst Control Center InstallProxy
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{9027FE9C-5488-30C3-AA42-7330D25BF92D}" = Microsoft Portable Library Multi-Targeting Pack
"{922E8525-AC7E-4294-ACAA-43712D4423C0}" = Adobe Flash Player 10 ActiveX
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{9347889B-C22A-3905-901F-C05D8F73C929}" = Build Tools Language Resources - x86
"{943F3FB1-3F9C-4FB7-A4E2-6D53617068C3}" = PreEmptive Analytics Visual Studio Components
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{96563105-F726-4865-8C32-416753ECA5F1}" = Microsoft Visual C++ x64-x86 Cross Compilers - ENU Resources
"{97592A5E-6A50-38E0-885C-7334BA7A43D8}" = Microsoft SharePoint 2013 Developer Tools for Visual Studio 2012 Nuget Package
"{976C3D92-0DEC-37A6-A870-FF4FC18CD029}" = Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps
"{979C7495-FB42-484E-92EA-7F2A59DD7718}" = Microsoft ASP.NET MVC 4 - Visual Studio 2013 - ENU
"{984022F2-9BCA-A41D-6A38-1AE658F01415}" = Windows Software Development Kit
"{985EF141-95DD-3934-8F23-7C2C4C61E5F7}" = Microsoft Visual Studio 2013 Shell (Minimum) Resources
"{988949CE-DE9A-D187-A010-22B9085FB813}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A470EA9-FF86-4C0E-992C-572BF2B9D6FF}" = Windows Live Essentials
"{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C593464-7F2F-37B3-89F8-7E894E3B09EA}" = Microsoft Visual Studio Professional 2013
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9E673C3F-423B-458E-8EA4-9AE87C49AFC8}" = Microsoft LightSwitch for Visual Studio 2013 v4.0 Tools
"{9ED1634C-4E71-4992-A1BA-7C4BE6EE39E1}" = Blend for Visual Studio 2013 ENU resources
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A1CB8286-CFB3-A985-D799-721A0F2A27F3}" = Windows Software Development Kit DirectX x86 Remote
"{A1D06677-1103-32DE-AA74-6EE44DCF7F81}" = Microsoft Visual C++ 2013 Extended Libraries
"{A223B446-EC3D-3031-828D-5188800AB782}" = Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps (ENU)
"{A2CCB3C1-3DF9-4E3E-8D3F-DDBBCDDB28B5}" = Microsoft C++ REST SDK for Visual Studio 2013
"{A2F166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A3B8D9FB-CA7D-4487-8CA2-A6A2C8AD1077}" = Microsoft Visual C++ x86 Libraries
"{A6030DAD-1600-F767-C8DD-C722ADFE8FBC}" = Windows Software Development Kit DirectX x86 Remote
"{A8229A09-E570-412B-8D18-E78985673E34}" = Microsoft Visual C++ ARM Libraries
"{A85092B2-8FB5-5A8C-B27A-69A3D78979D8}" = CCC Help Korean
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Czech
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{AE937DBA-FEFD-3BFE-9860-0591C0F91D61}" = Microsoft Visual Studio 2013 Shell (Minimum) Interop Assemblies
"{AED2C31B-91E5-481f-9E77-D3D6F68B3206}_is1" = Disciples III: Resurrection
"{B1977E93-5FC0-0BA4-2D5A-D3E69870C7D4}" = CCC Help Chinese Traditional
"{B1C38F27-D377-8C98-D98D-29B67C0B978D}" = LocalESPCui for en-us Dev12
"{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform
"{B3C98C29-A2BE-455F-9285-13B745282271}" = Microsoft Visual C++ x64-arm Cross Compilers - ENU Resources
"{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}" = Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729
"{B536762B-1047-4B51-8ECF-46D5686E5416}" = Microsoft ASP.NET Web Pages 2 Runtime
"{B6A0A174-33E0-3D42-92EA-547D318CB149}" = Microsoft Visual Studio 2013 Devenv
"{B86C786E-11A2-4CAB-BB2E-D7CD5D65D552}" = Microsoft LightSwitch v4.0 SDK
"{BB0D9EE5-F7B1-4986-AF62-DB3BED9A83BC}" = Microsoft Visual C++ x64 Native Compilers - ENU Resources
"{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}" = Adobe Flash Player 9 ActiveX
"{BBC9BF50-A35D-B0C2-9117-F3CA2F6BB64A}" = CCC Help Czech
"{BC0464FA-A0BA-3E38-85BF-DC5B3A401F48}" = Microsoft Visual Studio 2010 Ultimate - ENU
"{BC537AE0-88AF-47ED-B762-33B0D62B5188}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{BD63060C-F4C7-4E86-9C2A-4A102E7EE12C}" = Microsoft Web Developer Tools 2013 - Visual Studio 2013
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BD72C04F-892F-48EE-A236-CC10891610D6}" = Windows Azure Shared Components for Microsoft Visual Studio 2013 - v1.0
"{BF3E2194-F89B-44FB-A801-464BF787599F}" = WCF Data Services Tools for Microsoft Visual Studio 2013
"{C00453B2-27AD-4858-A20D-F44E39481C7D}" = Microsoft Report Viewer Add-On for Visual Studio 2013
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Creepy & Cute Parts Pack
"{C1D0E508-ECAF-45AA-A549-1E26B9ECE0FB}" = Microsoft Visual C++ x64-x86 Cross Compilers
"{C26C1495-8EBE-3F71-BDA1-7DE2010840D8}" = Microsoft Visual Studio 2013 Devenv Resources
"{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}" = Microsoft Visual C++ 2008 x64 ATL Runtime 9.0.30729
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C5A17590-8CBE-3581-965D-EF183BE07920}" = Microsoft Visual Studio Ultimate 2013 XAML UI Designer Core
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C9E7751E-88ED-36CF-B610-71A1D262E906}" = Team Explorer for Microsoft Visual Studio 2013
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE
"{CDECCD37-EBCE-4AF8-8D1C-5DF13194FEA1}" = Microsoft Advertising Service Extension for Visual Studio
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0FD2FF9-1BE9-E729-3878-9A603B5F1529}" = Catalyst Control Center Localization All
"{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions
"{D18F29F4-3609-4FBD-8A76-57B6AC3404F3}" = Photo Common
"{D3517C62-68A5-37CF-92F7-93C029A89681}" = Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)
"{D42681AA-BC16-3C84-949E-45F05D2AA997}" = Microsoft Visual C++ 2013 Core Libraries
"{D574CE3E-0376-4BED-B609-5C2C2AD655ED}" = Microsoft LightSwitch for Visual Studio 2013 v4.0 ToolsRes - ENU
"{D69874BF-D864-4EB2-91C3-2EDD05A64F70}" = Windows Azure Mobile Services Tools for Visual Studio 2013 Preview - v1.0
"{D94F2DE6-55B4-B211-A381-54089BC791A0}" = CCC Help Japanese
"{DB5600F1-DE83-46DE-B162-5FC4400EAF5B}" = Microsoft Visual C++ 2013 Compilers
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker
"{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}" = Microsoft ASP.NET MVC 2
"{DE0E8FAF-9758-4BFD-A16E-009DB4B8C912}" = Microsoft Visual C++ x64 Native Compilers
"{DF15CD8F-9295-3AD9-B814-7A60184AA1CD}" = Microsoft SharePoint 2013 Developer Tools for Visual Studio ENU Language Pack
"{E0363CCC-3535-4BAA-9F2C-200F548675D6}" = TuneUp Utilities Language Pack (cs-CZ)
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E100E2B5-F2EF-4955-AB7A-C3F2125A3BCD}" = Windows Live UX Platform Language Pack
"{E1FBB3D4-ADB0-4949-B101-855DA061C735}" = Microsoft Silverlight 5 SDK
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E43ED0A0-C85E-40F0-807C-6A8A9D2FAEF3}_is1" = King's Bounty. The Legend (Remove Only)
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}" = Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005
"{E6F3851E-CEEB-4ECB-A6FA-337C8F662E3D}" = Microsoft Visual C++ 2013 Compilers - ENU Resources
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{E9674444-9491-3961-873C-017D8912185E}" = Microsoft Visual Studio Professional 2013 - ENU
"{EB37C117-9C83-4696-A493-8AFBAC8F9FFC}" = JavaScript Tooling
"{EB514FFD-5FBA-3C53-94F8-3A2B96C5E7A8}" = Microsoft Visual Studio Ultimate 2013 XAML UI Designer enu Resources
"{EBC890A6-DE7C-44B4-AA03-119B6190D3E1}" = Blend for Visual Studio 2013
"{EE541DCE-3018-4A12-B0A3-7C55D62B3D01}" = Python Tools Redirection Template
"{EEFDBD75-0BD9-AC5F-8F61-903C6A19C0ED}" = CCC Help Dutch
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20914BB-FD5F-3A3A-8CDF-DF5ADEFD9451}" = Microsoft Portable Library Multi-Targeting Pack Language Pack - enu
"{F361FE04-789E-42F3-BBAB-E7B380AA5E06}" = Windows XP Targeting with C++
"{F37D360D-9308-4BB1-8515-DC6B637B9486}" = Fotogalerie
"{F395FD4F-40E5-7B56-2BCB-B3CF52B3B52C}" = Windows App Certification Kit x64
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}" = Microsoft Visual C++ 2008 x64 CRT Runtime 9.0.30729
"{F7AD7366-10AD-40C4-9846-52FFAC1784A2}" = Microsoft DirectX SDK (December 2005)
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FAE0523E-08A4-4717-8E8E-6EC6F32CBE88}" = Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20828.01)
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FB3A15FD-FC67-3A2F-892B-6890B0C56EA9}" = Build Tools - x86
"{FB415F81-DC5E-ED99-D2FE-3DC4D88BCA58}" = CCC Help Turkish
"{FD51D6A8-D687-463D-85AE-BBF1B650CD99}" = Microsoft Visual Studio 2013 Preparation
"{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}" = Microsoft Help Viewer 2.0
"{FF39514D-E2EB-40BA-A23F-C83B8E0ED110}" = Visual Studio Extensions for Windows Library for JavaScript
"Adobe AIR" = Adobe AIR
"Adobe Flash Player NPAPI" = Adobe Flash Player 17 NPAPI
"Android SDK Tools" = Android SDK Tools
"Battle.net" = Battle.net
"BioShock Infinite_is1" = BioShock Infinite
"Distance_is1" = Distance
"Endless Legend_is1" = Endless Legend version 0.6.1.S3
"Endless Space - Disharmony_is1" = Endless Space - Disharmony
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.20
"Freight Tycoon_is1" = Freight Tycoon
"GOGPACKTHEWITCHER2EE_is1" = The Witcher 2 - Assassins of Kings Enhanced Edition
"Hearthstone" = Hearthstone
"Heroes of the Storm" = Heroes of the Storm
"Cheat Engine 6.4_is1" = Cheat Engine 6.4
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"IrfanView" = IrfanView (remove only)
"Maxthon3" = Maxthon Cloud Browser
"Microsoft Help Viewer 2.0" = Microsoft Help Viewer 2.0
"Microsoft Help Viewer 2.1" = Microsoft Help Viewer 2.1
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio 2010 Ultimate - ENU" = Microsoft Visual Studio 2010 Ultimate - ENU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Need for Speed Most Wanted Black Edition_R.G. Mechanics_is1" = Need for Speed Most Wanted Black Edition
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OpenAL" = OpenAL
"Origin" = Origin
"Q3JlZXBlcldvcmxkM0FyY0V0ZXJuYWw=_is1" = Creeper World 3 Arc Eternal
"R2FtZURldlR5Y29vbnYxMzI=_is1" = Game Dev Tycoon v1.3.2 (c) Greenheart Games version 1
"RGSS-RTP Standard_is1" = RGSS-RTP Standard
"RocketDock_is1" = RocketDock 1.3.5
"Rockstar Games Social Club" = Rockstar Games Social Club
"Space Run_is1" = Space Run
"StarCraft II" = StarCraft II
"Steam" = Steam
"Steam App 200110" = Nosgoth
"Steam App 221100" = DayZ
"Steam App 301520" = Robocraft
"Steam App 570" = Dota 2
"Steam App 620" = Portal 2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Totalcmd" = Total Commander (Remove or Repair)
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"Tunngle_is1" = Tunngle
"Unity" = Unity
"Wasteland 2_R.G. Gamblers_is1" = Wasteland 2
"Winamp" = Winamp
"Winamp Essentials Pack" = Winamp Essentials Pack
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 5.11 (32-bit)
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2341083737-2633030218-564279663-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SOE-PlanetSide 2 PSG" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
"YandexBrowser" = Yandex

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 25. 4. 2015 11:24:02 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:02 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:02 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Uvolnění řetězců čítačů výkonu pro službu ASP.NET (ASP.NET) se nezdařilo.
První hodnota DWORD v datové oblasti obsahuje kód chyby.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Uvolnění řetězců čítačů výkonu pro službu ASP.NET_4.0.30319 (ASP.NET_4.0.30319)
se nezdařilo. První hodnota DWORD v datové oblasti obsahuje kód chyby.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 11:24:03 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Uvolnění řetězců čítačů výkonu pro službu ASP.NET (ASP.NET) se nezdařilo.
První hodnota DWORD v datové oblasti obsahuje kód chyby.

Error - 25. 4. 2015 14:58:20 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 14:58:20 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 25. 4. 2015 14:58:20 | Computer Name = PiccoloPC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Uvolnění řetězců čítačů výkonu pro službu WmiApRpl (WmiApRpl) se nezdařilo.
První hodnota DWORD v datové oblasti obsahuje kód chyby.

[ System Events ]
Error - 25. 4. 2015 14:13:33 | Computer Name = PiccoloPC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (20:10:57, ?25. ?4. ?2015) bylo neočekávané.

Error - 25. 4. 2015 14:13:34 | Computer Name = PICCOLOPC | Source = BugCheck | ID = 1001
Description =

Error - 25. 4. 2015 14:16:58 | Computer Name = PiccoloPC | Source = Service Control Manager | ID = 7034
Description = Služba hpqcxs08 byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error - 25. 4. 2015 14:16:58 | Computer Name = PiccoloPC | Source = Service Control Manager | ID = 7034
Description = Služba Služba HP CUE DeviceDiscovery byla neočekávaně ukončena. Tento
stav nastal již 1krát.

Error - 25. 4. 2015 14:19:31 | Computer Name = PiccoloPC | Source = Service Control Manager | ID = 7022
Description = Služba Windows Update přestala během spouštění reagovat.

Error - 25. 4. 2015 14:27:55 | Computer Name = PiccoloPC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 25. 4. 2015 14:35:50 | Computer Name = PiccoloPC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 25. 4. 2015 15:02:11 | Computer Name = PiccoloPC | Source = DCOM | ID = 10010
Description =

Error - 25. 4. 2015 17:05:17 | Computer Name = PiccoloPC | Source = Application Popup | ID = 1060
Description = Načtení \SystemRoot\SysWow64\Drivers\PQNTDrv.SYS bylo zablokováno
kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru o kompatibilní
verzi ovladače.

Error - 26. 4. 2015 2:36:03 | Computer Name = PiccoloPC | Source = Application Popup | ID = 1060
Description = Načtení \SystemRoot\SysWow64\Drivers\PQNTDrv.SYS bylo zablokováno
kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru o kompatibilní
verzi ovladače.


< End of report >

Re: Problemy s pravami

Napsal: 26 dub 2015 10:13
od Márty84
:???: Jak je to s legalitou systemu? Ultimate neni zrovna bezna domaci verze :?:

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Problemy s pravami

Napsal: 27 dub 2015 06:58
od Piccolo
tak... win mam "zlegalizovany" :)


Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 26. 4. 2015
Čas skenování: 18:36:09
Protokol: sken.txt
Správce: Ano

Verze: 2.01.6.1022
Databáze malwaru: v2015.04.26.04
Databáze rootkitů: v2015.04.21.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Piccolo

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 1451722
Uplynulý čas: 6 hod, 48 min, 56 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 44
Trojan.AutoKMS, C:\Windows\AutoKMS\AutoKMS.exe, , [46e6a8c9dbaf1a1cf4916c9308f87090],
Riskware.Tool.CK, C:\David zaloha\lenovo disk\ubuntu\Documents\tools\program+instal\SIETOVE SOFTY\Network.Protocol.Analyzer.v2.5.0.570\SoftPerfect.Network.Protocol.Analyzer.v2.5.0.570.WinAll-BRD\SoftPerfect.Network.Protocol.Analyzer.v2.5.0.570.WinAll-BRD\Patch.exe, , [8ba1c8a9602a2412c7e7a6ecf907c63a],
Trojan.WGAPatch, C:\David zaloha\lenovo disk\z pc\297044402\364876691_stistko\Crack.exe, , [68c4ef82f1997abc03eb8b2d6c96936d],
Trojan.Ancient, C:\David zaloha\lenovo disk\z pc\dokumenty\Peter\Petr.zip\pet223cz.exe, , [e943215081092e08fb198a109f63e61a],
PUP.BundleInstaller.DW, C:\David zaloha\zaloha dominika\Downloads\The_Smurfs_2011.exe, , [c26abbb6e6a448eeabb2d2646d9454ac],
PUP.Bundle.Installer.OI, C:\David zaloha\zaloha dominika\Downloads\VIO_Player_Setup.exe, , [3eeed79a1b6fdd596d0f5e6bce3222de],
Hacktool.CheatEngine, C:\Downloads\ftl1510-gir489.rar, , [cf5df77a3c4eed4965ef9aa2eb1502fe],
Joke.Winshoot, D:\Funny\GUN.EXE, , [65c7224f6d1d0b2be456574bca389a66],
Trojan.Agent.rf, D:\Funny\manzelka.exe, , [c26ac1b07d0d8fa7030f061a39c8f10f],
Trojan.Agent.rf, D:\Funny\MiniMagi.exe, , [ec406e03b7d37bbb838f64bc06fb7888],
PUP.Joke.Schmilz, D:\Funny\rozmazanie.exe, , [bd6f521fd0ba36001fd9d0cb877bdf21],
Joke.VV, D:\Funny\velka_mys.exe, , [e04c3c356921e94d58fcff14e81eea16],
Application.Badjoke, D:\Funny\windows.exe, , [0329beb36a20a393728c219d30d5c63a],
Application.Badjoke, D:\Funny\Dont open\Paranoia.exe, , [959741302d5df640926c15a9d82de61a],
Spyware.Passwords, D:\Funny\flash (upratat!)\kingofthehill.exe, , [8e9eb4bd17731e18f18ac2da07fb0ef2],
PUP.Optional.OpenCandy, D:\games\Spore\Daemon Tools Lite.exe, , [27057cf5830741f5061ad858ec1ae41c],
Hacktool.CheatEngine, D:\Mikso\Program\Hry\Save\FasterThanLight\ftl-gir489.exe, , [9a920d64b9d15fd7e173b587798703fd],
RiskWare.Tool.CK, D:\Mikso\Program\Others\QIP\Users\260402205\RcvdFiles\401358327_bayo15\fff-ea183.exe, , [55d771002a606dc9654e9a7751b514ec],
Malware.Gen, D:\Mikso\Program\Programy\new\nitro-pdf-professional-v6-0-2-6.rar, , [7ab2ea87a1e9b284dbba4443f20eb947],
RiskWare.Tool.CK, D:\Mikso\Program\Programy\new\acad 2008 cz\Crack\AutoCAD-2008-keygen.exe, , [6ebe432e38523ef8083ec5fa48bac937],
RiskWare.Tool.CK, D:\Mikso\Program\Programy\new\FlashFXP_3.8__3.7.2_Build_1270\KeyGen.exe, , [c36918593753e1556a1c089b986afc04],
RiskWare.Tool.CK, D:\Mikso\Program\Programy\new\Runtime GetDataBack for FAT NTFS 3.64\NTFS\KEYGEN\Keygen.exe, , [9795b3be2268ae8877b8bbe8fa08ae52],
Backdoor.Sdbot, D:\Mikso\Program\Programy\old\sony vegas\key\DGOHOMEVI889\keygen.exe, , [b874a9c85f2b80b6dfadebb64ab88e72],
Hacktool.Agent, D:\Mikso\Program\W7\Windows_Loader_v1.9.5.zip, , [3cf0c7aad3b7cd691764423944bd3ec2],
RiskWare.Tool.CK, D:\Mikso\USB\prog\pdf factory\keygen.exe, , [68c4fc75a7e382b460347f24ab572ed2],
RiskWare.Tool.CK, D:\Mikso\USB\prog\Runtime GetDataBack for FAT NTFS 3.64\NTFS\KEYGEN\Keygen.exe, , [81ab1d54cac0b2840b24b0f3c240a858],
RiskWare.Tool.CK, D:\Mikso\zaloha\260402205\RcvdFiles\401358327_bayo15\fff-ea183.exe, , [38f4c1b0e4a6072f644ffa1762a4a35d],
RiskWare.Tool.CK, D:\Mikso\zaloha\c\zaloha\QIP\Users\260402205\RcvdFiles\401358327_bayo15\fff-ea183.exe, , [35f7c1b071192f07159e45cc55b105fb],
RiskWare.Tool.CK, D:\Mikso\zaloha\c\zaloha\USB\Programs\autocad 2008 full cz\AutoCAD-2008-keygen.exe, , [939930413555e74f172f1da2818105fb],
RiskWare.Tool.CK, D:\Mikso\zaloha\c\zaloha\USB\Programs\Runtime GetDataBack for FAT NTFS 3.64\NTFS\KEYGEN\Keygen.exe, , [012b373a26645fd75ed17b2810f218e8],
PUP.Keygen.Intro, D:\Mikso\zaloha\c\zaloha\USB\Programs\Winamp pro 5.572.2830 Final\keygen\CORE\CORE10k.EXE, , [2b01333e840657df7a39663515f0857b],
PUP.RiskwareTool.CK, D:\Mikso\zaloha\c\zaloha\USB\Programs\Winamp pro 5.572.2830 Final\keygen\CORE\keygen.exe, , [89a3026f87032a0c53cd39f630d1d828],
RiskWare.Tool.CK, D:\Mikso\zaloha\c\zaloha\USB\Programs\Winamp pro 5.572.2830 Final\keygen\DVT\KeyMaker.exe, , [2ffdcba67d0d44f25cb8e8d7cd3554ac],
RiskWare.Tool.CK, D:\Mikso\zaloha\c\zaloha\USB\Programs\Winamp pro 5.572.2830 Final\keygen\FFF\Winamp.5.50_KEYGEN-FFF.exe, , [2705f9785e2c6acc7ff6ccd00002d62a],
Hacktool.Agent, D:\Mikso\zaloha\c\zaloha\USB\Programs\Windows Loader\Windows Loader.exe, , [3fed68093f4b979f33483b4019e89967],
RiskWare.Tool.CK, D:\Mikso\zaloha\qip2005\QIP\Users\260402205\RcvdFiles\bayo15_401358327\fff-ea183.exe, , [ff2de8890387e94d2e8547cab4524ab6],
RiskWare.Tool.CK, D:\Mikso\zaloha\USB2\programs\pdf factory\keygen.exe, , [f6366e03dcae2313b0e42a791de50000],
RiskWare.Tool.CK, D:\Mikso\zaloha\USB2\programs\Runtime GetDataBack for FAT NTFS 3.64\NTFS\KEYGEN\Keygen.exe, , [f9337af7c2c8a29432fd059eb44e639d],
PUP.Optional.InstallRex, D:\ZdielaÄ?\zaloha\Downloads\Moyea.SWF.to.Video.Converter.Pro.v.3.12.0.0.incl.patch-iOTA.zip.exe, , [3bf1076a2466c0761f8e14c3827ff010],
PUP.Optional.OpenCandy, D:\ZdielaÄ?\zaloha\Downloads\smplayer-0.8.3-ps-win32.exe, , [c567df92503aa88e32eeef41b551f20e],
PUP.Optional.Softonic.A, D:\ZdielaÄ?\zaloha\Downloads\SoftonicDownloader_for_minecraft-skinedit.exe, , [f13b94dd8efc4aec765ace83bb46c63a],
Trojan.Dropper, D:\ZdielaÄ?\zaloha\Downloads\WDL219.zip, , [4ce094dd216973c3100e618b2ed27888],
Hacktool.Agent, D:\ZdielaÄ?\zaloha\Downloads\Windows-7-Loader-v2.2.2-by-DAZ.zip, , [a28a0f62b8d230069be080fbdc259070],
Malware.Gen, D:\ZdielaÄ?\zaloha\Piccolo\Programs\a\Activation Code\keygen.exe, , [1616b8b9404a82b4eea77611ef11d32d],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Re: Problemy s pravami

Napsal: 27 dub 2015 08:54
od Márty84
Je mi lito, ale pravidla fora mi nedovoluji pokracovat. Hovori jasne http://forum.viry.cz/viewtopic.php?f=12&t=115512
Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.
:42:


23.5. :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975