Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

ntb - pro vyosek

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

ntb - pro vyosek

#1 Příspěvek od schizi »

Zdravím,
ještě jednou moc děkuji za předchozí pomoc a i za tu následující ;)

Zde log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Schizi at 2012-07-09 21:20:31
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 274 GB (76%) free of 360 GB
Total RAM: 8103 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:20:35, on 9.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\Ssms.exe
c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\devenv.exe
C:\Program Files (x86)\Yaho's Miranda Pack\miranda32.exe
C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\DevServer\10.0\WebDev.WebServer40.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\DevServer\10.0\WebDev.WebServer40.exe
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
C:\Program Files\trend micro\Schizi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [KeyboardLeds.exe] "C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Unibet - {2D6012E2-B8DE-4FA0-BF98-8F3497E06F2A} - C:\Microgaming\Poker\unibetpokerMPP\MPPoker.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE
O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Web'n'walk Manager mobile equipment installation service (ameisvc) - Gemfor s.r.o. - C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HyperW7 Service (HyperW7Svc) - Lenovo Group Limited - C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15456 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0c4a6d12-6f50-4f29-b189-953e5db6d406 -SystemEventPortName:HostProcess-3b0b4456-f304-4556-91a5-d4aa5b79e263 -IoCancelEventPortName:HostProcess-46d1a1cb-4c47-49a7-b281-507b5bb031d2 -NonStateChangingEventPortName:HostProcess-34330885-156a-4aff-8121-bd34693e4b7b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:16306991-82dc-447a-bb7b-0bacbb6a2a42
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 25864256
\??\C:\Windows\system32\conhost.exe "-1141984957910544460789487048-1080097906-124017367-2328047632537615961577774818
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Windows\System32\TpShocks.exe"
"C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
C:\Windows\system32\igfxext.exe -Embedding
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\ThinkPad\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE"
"C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe"
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe"
C:\Windows\system32\CxAudMsg64.exe
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe"
WLIDSvcM.exe 4760
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\rundll32.exe "C:\PROGRAM FILES\LENOVO\HOTKEY\hotkey.dll",InstallAudioHotkeyHook
C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.MediaKey
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
"C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe" /IpNotifyInstance
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\Ssms.exe"
"c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\devenv.exe" "D:\Projekty\OtherProjects\Lilan\RealEstatePortal.sln"
"C:\Program Files (x86)\Yaho's Miranda Pack\miranda32.exe"
"C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe"
"C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files (x86)\Common Files\Microsoft Shared\DevServer\10.0\WebDev.WebServer40.exe" /port:61033 /path:"D:\Projekty\OtherProjects\Lilan\RealEstatePortal" /vpath:"/"
"C:\Program Files (x86)\Common Files\Microsoft Shared\DevServer\10.0\WebDev.WebServer40.exe" /port:61038 /path:"D:\Projekty\OtherProjects\Lilan\DataPublisher" /vpath:"/"
"C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /dde
"c:\Program Files\Microsoft Help Viewer\v1.0\HelpLibAgent.exe" ms-xhelp:///?product=VS&productVersion=100&method=f1&query=System.Windows.Controls.DataGridColumn.Width%00VS.XamlEditor&LCID=1033&TargetFrameworkMoniker=.NETFramework,Version%3Dv4.0&launchingApp=VS
"taskhost.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe36_ Global\UsGthrCtrlFltPipeMssGthrPipe36 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536
"C:\Users\Schizi\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\AutoKMSDaily.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Schizi\AppData\Roaming\Mozilla\Firefox\Profiles\a93si6j3.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/wpi,version=1.4]
"Description"=
"Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonEU\NGM\npNxGameeu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/wpi,version=1.4]
"Description"=
"Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-02-15 347424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-02-15 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-02-15 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-02-15 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2011-04-26 310912]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-07-27 1935120]
"TpShocks"=C:\Windows\SYSTEM32\TpShocks.exe [2011-03-29 380776]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2011-07-22 42344]
"AcWin7Hlpr"=C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [2011-10-20 33344]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-08-09 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-08-09 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-08-09 416024]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-12-23 2868496]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"KeyboardLeds.exe"=C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe [2011-11-11 910336]
"SUPERAntiSpyware"=C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE [2012-06-26 4787072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCKRESI.EXE]
C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [2011-09-27 386408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-11-02 59240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ForteConfig]
C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Schizi\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-08 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-12-08 421736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU]
C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [2012-03-11 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lenovo Registration]
C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LENOVO.TPKNRRES]
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2011-07-22 42344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe [2011-07-14 85832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWMTRV]
rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RotateImage]
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-31 55808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\Games\Steam\Steam.exe [2011-12-20 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe [2011-10-17 1213216]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe [2009-11-18 275072]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-12 336384]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\SYSTEM32\igfxdev.dll [2011-08-09 390144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2011-07-14 136008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
ACGina

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-07-09 21:20:31 ----D---- C:\rsit
2012-07-09 21:20:31 ----D---- C:\Program Files\trend micro
2012-07-07 13:08:43 ----D---- C:\Users\Schizi\AppData\Roaming\SUPERAntiSpyware.com
2012-07-07 13:08:29 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2012-07-07 13:08:29 ----D---- C:\Program Files\SUPERAntiSpyware
2012-07-07 11:33:12 ----A---- C:\Windows\system32\drivers\stflt.sys
2012-07-07 11:31:29 ----D---- C:\Program Files (x86)\Spyware Terminator
2012-06-28 10:48:08 ----D---- C:\Program Files (x86)\wkhtmltopdf
2012-06-22 18:56:45 ----D---- C:\Program Files (x86)\T-Mobile
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01007.dll
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\mod7700.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ewusbwwan.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ewusbmdm.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ewdcsc.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ew_jucdcecm.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ew_hwusbdev.sys
2012-06-22 16:55:34 ----A---- C:\Windows\system32\drivers\ew_hwupgrade.sys
2012-06-22 16:55:18 ----D---- C:\Program Files (x86)\Huawei
2012-06-21 09:48:54 ----A---- C:\Windows\system32\wups2.dll
2012-06-21 09:48:54 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-21 09:48:53 ----A---- C:\Windows\system32\wucltux.dll
2012-06-21 09:48:53 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-21 09:48:21 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-21 09:48:20 ----A---- C:\Windows\system32\wuapp.exe
2012-06-20 14:57:53 ----D---- C:\Crash
2012-06-20 14:55:26 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-06-20 14:55:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-06-20 14:55:26 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-06-20 14:55:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-06-20 14:55:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-06-16 17:21:14 ----D---- C:\Users\Schizi\AppData\Roaming\.mono
2012-06-16 17:21:14 ----D---- C:\ProgramData\.mono
2012-06-15 03:01:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-06-15 03:01:17 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-15 03:01:15 ----A---- C:\Windows\SYSWOW64\url.dll
2012-06-15 03:01:15 ----A---- C:\Windows\system32\url.dll
2012-06-15 03:01:14 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-06-15 03:01:14 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-06-15 03:01:14 ----A---- C:\Windows\system32\urlmon.dll
2012-06-15 03:01:14 ----A---- C:\Windows\system32\iertutil.dll
2012-06-15 03:01:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-06-15 03:01:13 ----A---- C:\Windows\system32\ieui.dll
2012-06-15 03:01:12 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-06-15 03:01:12 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-15 03:01:11 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-06-15 03:01:10 ----A---- C:\Windows\system32\wininet.dll
2012-06-15 03:01:10 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-15 03:01:09 ----A---- C:\Windows\system32\jscript9.dll
2012-06-15 03:01:08 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-06-15 03:01:08 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-06-15 03:01:07 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-06-15 03:01:07 ----A---- C:\Windows\system32\jscript.dll
2012-06-15 03:01:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-06-15 03:01:03 ----A---- C:\Windows\system32\mshtml.dll
2012-06-15 03:01:02 ----A---- C:\Windows\system32\ieframe.dll
2012-06-15 03:01:00 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-06-14 12:27:12 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-14 12:27:12 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-14 12:27:12 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-14 12:27:09 ----A---- C:\Windows\system32\profsvc.dll
2012-06-14 12:27:07 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-06-14 12:27:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-14 12:27:06 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-06-14 12:27:05 ----A---- C:\Windows\system32\win32k.sys
2012-06-14 12:27:04 ----A---- C:\Windows\system32\rdpcorets.dll
2012-06-14 12:27:03 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-14 12:27:02 ----A---- C:\Windows\SYSWOW64\msi.dll
2012-06-14 12:27:02 ----A---- C:\Windows\system32\msi.dll
2012-06-14 12:26:58 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2012-06-14 12:26:58 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2012-06-14 12:26:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2012-06-14 12:26:58 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-14 12:26:58 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-14 12:26:58 ----A---- C:\Windows\system32\crypt32.dll
2012-06-12 16:23:36 ----D---- C:\Users\Schizi\AppData\Roaming\Unity
2012-06-10 01:10:04 ----D---- C:\Program Files (x86)\No Hands SEO

======List of files/folders modified in the last 1 month======

2012-07-09 21:20:36 ----D---- C:\Windows\Temp
2012-07-09 21:20:31 ----RD---- C:\Program Files
2012-07-09 20:56:57 ----D---- C:\Program Files (x86)\The KMPlayer
2012-07-09 10:06:55 ----D---- C:\Users\Schizi\AppData\Roaming\Skype
2012-07-09 10:05:12 ----HD---- C:\ProgramData
2012-07-09 09:43:32 ----D---- C:\Windows\system32\config
2012-07-08 22:46:13 ----D---- C:\Windows\Tasks
2012-07-08 22:46:06 ----D---- C:\Windows
2012-07-08 22:46:06 ----A---- C:\Windows\KMSEmulator.exe
2012-07-08 15:39:33 ----D---- C:\Users\Schizi\AppData\Roaming\vlc
2012-07-07 22:47:06 ----A---- C:\Windows\SYSWOW64\log.txt
2012-07-07 22:46:46 ----D---- C:\Windows\system32\wdi
2012-07-07 11:33:13 ----D---- C:\Windows\system32\drivers
2012-07-07 11:33:13 ----D---- C:\Windows\Prefetch
2012-07-07 11:31:29 ----RD---- C:\Program Files (x86)
2012-07-05 19:53:02 ----SHD---- C:\System Volume Information
2012-07-05 11:14:56 ----D---- C:\Users\Schizi\AppData\Roaming\FileZilla
2012-07-03 14:32:04 ----SD---- C:\Users\Schizi\AppData\Roaming\Microsoft
2012-07-02 18:54:58 ----D---- C:\Windows\system32\Tasks
2012-06-29 13:59:20 ----D---- C:\Windows\System32
2012-06-29 13:59:20 ----D---- C:\Windows\inf
2012-06-29 13:59:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-06-29 09:44:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-06-27 00:37:45 ----D---- C:\Windows\rescache
2012-06-24 12:50:03 ----D---- C:\Windows\SysWOW64
2012-06-24 12:49:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-06-22 18:56:00 ----D---- C:\Windows\ModemLogs
2012-06-22 16:55:34 ----D---- C:\Windows\system32\catroot
2012-06-22 16:55:33 ----D---- C:\Windows\system32\DriverStore
2012-06-21 09:49:37 ----D---- C:\Windows\winsxs
2012-06-21 09:49:34 ----D---- C:\Windows\system32\en-US
2012-06-21 09:49:34 ----D---- C:\Windows\system32\cs-CZ
2012-06-21 09:49:05 ----D---- C:\Windows\system32\catroot2
2012-06-20 14:54:49 ----RSD---- C:\Windows\assembly
2012-06-20 14:53:06 ----D---- C:\Windows\Logs
2012-06-15 03:48:20 ----D---- C:\Windows\Microsoft.NET
2012-06-15 03:26:17 ----D---- C:\Windows\SYSWOW64\migration
2012-06-15 03:26:17 ----D---- C:\Windows\SYSWOW64\en-US
2012-06-15 03:26:17 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-06-15 03:26:17 ----D---- C:\Windows\system32\migration
2012-06-15 03:26:17 ----D---- C:\Program Files\Internet Explorer
2012-06-15 03:26:17 ----D---- C:\Program Files (x86)\Internet Explorer
2012-06-15 03:10:53 ----SHD---- C:\Windows\Installer
2012-06-15 03:10:53 ----SHD---- C:\Config.Msi
2012-06-15 03:10:51 ----D---- C:\ProgramData\Microsoft Help
2012-06-15 03:05:40 ----D---- C:\Windows\debug
2012-06-15 03:05:39 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2011-03-29 139888]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2011-03-29 23664]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-11-28 42328]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-11-28 591192]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-11-28 304472]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-11-28 58712]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-11-21 279616]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2011-07-09 32104]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2011-12-01 14960]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-11-28 24408]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-11-28 66904]
R2 risdxc;risdxc; C:\Windows\system32\DRIVERS\risdxc64.sys [2011-03-24 101376]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2010-11-21 146432]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2011-05-30 13128]
R3 5U877;USB Video Device; C:\Windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-05-12 9319424]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-05-11 304128]
R3 AMPPAL;Virtuבlnם adaptיr Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed; C:\Windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-03-24 1576064]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-09-09 87040]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2012-02-29 42312]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2011-08-09 12289472]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2011-08-03 8604672]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2011-12-27 40248]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-12-23 412432]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
S3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed; C:\Windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2011-10-17 437288]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-10-17 146984]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2011-10-17 164392]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-10-17 39976]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2011-10-17 21544]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 13952]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-09-09 98304]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2011-09-09 28672]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2011-09-09 218624]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-08-02 51712]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
S4 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
S4 RsFx0105;RsFx0105 Driver; C:\Windows\system32\DRIVERS\RsFx0105.sys [2011-09-22 311144]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE [2011-08-12 140672]
R2 AcPrfMgrSvc;AcPrfMgrSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe [2011-10-20 134208]
R2 AcSvc;AcSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe [2011-10-20 269376]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-05-11 203264]
R2 ameisvc;Web'n'walk Manager mobile equipment installation service; C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe [2012-06-12 124856]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-24 55144]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2011-10-17 970016]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2010-12-17 198784]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-07-27 1517328]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2012-02-29 48704]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2011-07-22 41832]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-07-22 60264]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 133992]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-09-22 58345832]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-07-27 844560]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2011-09-22 154984]
R2 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2012-03-16 34104]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-19 136176]
S2 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2011-07-09 144232]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 250056]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-19 136176]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-12-08 934760]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-27 340240]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-12-01 89152]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2011-12-01 175168]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2011-03-29 47728]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-22 431464]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2011-09-22 255336]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#3 Příspěvek od schizi »

OTL logfile created on: 10.7.2012 9:18:13 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Schizi\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

7,91 Gb Total Physical Memory | 3,55 Gb Available Physical Memory | 44,85% Memory free
15,82 Gb Paging File | 11,19 Gb Available in Paging File | 70,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 351,08 Gb Total Space | 267,84 Gb Free Space | 76,29% Space Free | Partition Type: NTFS
Drive D: | 334,67 Gb Total Space | 12,41 Gb Free Space | 3,71% Space Free | Partition Type: NTFS
Drive Q: | 11,72 Gb Total Space | 1,15 Gb Free Space | 9,85% Space Free | Partition Type: NTFS

Computer Name: SCHIZI-THINK | User Name: Schizi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.07.10 09:16:43 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Schizi\Desktop\OTL.exe
PRC - [2012.07.10 01:38:41 | 000,011,600 | ---- | M] (Microsoft Corporation) -- D:\Projekty\Dust\bldata\bin\Debug\bldata.vshost.exe
PRC - [2012.05.16 10:59:19 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe
PRC - [2011.12.01 04:05:00 | 000,064,576 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
PRC - [2011.11.28 20:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011.11.11 07:35:12 | 000,910,336 | ---- | M] (KARPOLAN) -- C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe
PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2011.10.17 16:49:14 | 000,148,768 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
PRC - [2011.07.22 13:21:32 | 000,042,344 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
PRC - [2010.10.25 21:25:32 | 000,815,200 | ---- | M] ( ) -- C:\Program Files (x86)\Yaho's Miranda Pack\miranda32.exe
PRC - [2010.04.07 08:55:00 | 003,646,208 | ---- | M] (Ghisler Software GmbH) -- C:\Program Files (x86)\totalcmd\TOTALCMD.EXE


========== Modules (No Company Name) ==========

MOD - [2012.06.24 12:49:59 | 009,459,912 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
MOD - [2012.06.15 03:47:50 | 000,253,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\44752ffa92ebb7170951a41898d8b9c6\WindowsFormsIntegration.ni.dll
MOD - [2012.06.15 03:47:48 | 004,075,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\VsDebugPresentation#\5fc4d9f2e55345903c41118cd72862ef\VsDebugPresentationPackage.ni.dll
MOD - [2012.06.15 03:47:41 | 001,226,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\6831f648f5b925f1194f691b0b491662\System.WorkflowServices.ni.dll
MOD - [2012.06.15 03:47:39 | 004,476,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Com#\a1705962a6725e5f40066496222d67e7\System.Workflow.ComponentModel.ni.dll
MOD - [2012.06.15 03:47:36 | 002,872,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\ec819e8a7e4585ffc87ae93d3b0662d8\System.Workflow.Activities.ni.dll
MOD - [2012.06.15 03:43:18 | 002,513,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SQLEditors\888757a9f09d461abe910f2fac068216\SQLEditors.ni.dll
MOD - [2012.06.15 03:43:14 | 000,225,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ObjectExplorerRepli#\e4e06b4bd726dcad1001500d549d8839\ObjectExplorerReplication.ni.dll
MOD - [2012.06.15 03:43:08 | 000,558,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\bca1ee1884a071e3ccabc828a9455520\Microsoft.SqlServer.Management.SqlStudio.Explorer.ni.dll
MOD - [2012.06.15 03:43:06 | 000,125,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\8eb34f393bf6f99f4d0118b1d338dd62\Microsoft.SqlServer.Management.SqlStudio.ni.dll
MOD - [2012.06.15 03:42:59 | 000,079,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\8650ee3907ab88e5fed68dd3263a583d\Microsoft.SqlServer.Management.Scripting.ni.dll
MOD - [2012.06.15 03:42:40 | 004,366,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\347f29a4e3a31bdcf0132d1f00a4c24e\Microsoft.SqlServer.Management.DataTools.ni.dll
MOD - [2012.06.15 03:42:25 | 000,656,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\3da7114325d5647c832547b61afaa157\Microsoft.SqlServer.Management.ConnectionUI.Dialog.ni.dll
MOD - [2012.06.15 03:41:51 | 004,154,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ObjectExplorer\c441c913b6b8137ac289163c8129a40a\ObjectExplorer.ni.dll
MOD - [2012.06.15 03:41:40 | 009,370,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\4362fb52405cbd58ef62b887585e266c\Microsoft.SqlServer.Management.Reports.ni.dll
MOD - [2012.06.15 03:41:39 | 000,384,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\e19e25bdca0577a088ad3c2e42c90d89\Microsoft.SqlServer.Management.Data.ni.dll
MOD - [2012.06.15 03:41:39 | 000,334,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\afef6d7e9feabedc8ebcf00390efe289\Microsoft.SqlServer.Management.SDK.SqlStudio.ni.dll
MOD - [2012.06.15 03:41:39 | 000,077,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.DataWareh#\0b1b9ede0e557076c1364a8cd72b836a\Microsoft.DataWarehouse.SQM.ni.dll
MOD - [2012.06.15 03:41:32 | 002,934,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.DataWareh#\72cbefbdfcf2f2037fd9978616829af1\Microsoft.DataWarehouse.ni.dll
MOD - [2012.06.15 03:41:30 | 005,334,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SqlMgmt\e4b403369505fde2e887689b8ee870e9\SqlMgmt.ni.dll
MOD - [2012.06.15 03:41:28 | 000,263,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\650f100bb6d91ece272392e4f5c402d4\Microsoft.SqlServer.Management.UserSettings.ni.dll
MOD - [2012.06.15 03:41:27 | 001,191,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\ConnectionDlg\3c0489ccb052a6c8f634f91cb33cb361\ConnectionDlg.ni.dll
MOD - [2012.06.15 03:41:27 | 000,674,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\39681826e21e039d590d9edfe25da50e\Microsoft.SqlServer.Management.Controls.ni.dll
MOD - [2012.06.15 03:41:26 | 000,628,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\b818146b0e17803b08d93e300298f943\Microsoft.SqlServer.SqlTools.VSIntegration.ni.dll
MOD - [2012.06.15 03:41:26 | 000,087,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SqlWorkbench.Interf#\751c994dd73c4e3f89ad8877fbf58a69\SqlWorkbench.Interfaces.ni.dll
MOD - [2012.06.15 03:41:25 | 001,428,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\AppIDPackage\af5999502a40a26141d9352a6cacbd47\AppIDPackage.ni.dll
MOD - [2012.06.15 03:41:19 | 000,205,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\3fafb6a18f737ad75cb03fa7fb5079e2\Microsoft.SqlServer.Management.RegisteredServers.ni.dll
MOD - [2012.06.15 03:40:47 | 000,838,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\11951db94808f70564b88fd8606c23d1\Microsoft.VisualStudio.Shell.ni.dll
MOD - [2012.06.15 03:40:38 | 000,232,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\4b5b54382263da77572c3f0a0cedc5b4\Microsoft.NetEnterpriseServers.ExceptionMessageBox.ni.dll
MOD - [2012.06.15 03:40:37 | 000,532,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\6e498d4b076ce92fc546df1bc42f5927\Microsoft.SqlServer.GridControl.ni.dll
MOD - [2012.06.15 03:34:52 | 000,208,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\912a0776c2bfd35ff76bd0b8ba977ed4\System.Drawing.Design.ni.dll
MOD - [2012.06.15 03:34:51 | 010,580,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c144f89b1f8f292d6940a1b2f8ffbec\System.Design.ni.dll
MOD - [2012.06.15 03:34:25 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012.06.15 03:34:20 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012.06.15 03:26:01 | 001,641,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\cf455da9b8fedf66767c1a7ab3eea9c9\PresentationUI.ni.dll
MOD - [2012.06.15 03:26:00 | 000,168,448 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\bb06aacde1c5cb1e729a0dad9cddcc22\PresentationFramework.VisualStudio.Design.ni.dll
MOD - [2012.06.15 03:25:57 | 003,312,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.XmlEditor\e7bbccadfae9cc64815021972163d7b8\Microsoft.XmlEditor.ni.dll
MOD - [2012.06.15 03:25:53 | 001,396,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\59c4ee1d7aa4806e8a4da2e3fb6d2513\Microsoft.Windows.Design.Platform.WPF.ni.dll
MOD - [2012.06.15 03:25:52 | 002,972,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\57432827b06282ab7683209f55cd8f55\Microsoft.Windows.Design.Platform.ni.dll
MOD - [2012.06.15 03:25:48 | 012,079,616 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\fdb5565e4c807a8cd79de9f40c0cd644\System.Web.ni.dll
MOD - [2012.06.15 03:25:42 | 001,693,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Web.Desig#\4ce033d18cd895917afdfafc25a2bb1e\Microsoft.Web.Design.Client.ni.dll
MOD - [2012.06.15 03:25:40 | 000,039,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VSDesigne#\3437df9fa6c9144bdba688d80da7124c\Microsoft.VSDesigner.Core.ni.dll
MOD - [2012.06.15 03:25:39 | 010,703,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VSDesigner\2143f7cac2869af73d604cc9857f6da1\Microsoft.VSDesigner.ni.dll
MOD - [2012.06.15 03:25:33 | 007,321,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\bffc17f9ec3c903797549d18774a64f7\Microsoft.VisualStudio.Xaml.ni.dll
MOD - [2012.06.15 03:25:28 | 000,148,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\3e06ce57a790a6a8819d13bb1565aaf2\Microsoft.VisualStudio.WizardFramework.ni.dll
MOD - [2012.06.15 03:25:26 | 000,783,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\54362d8f81fb2aa6b2a3e472555a4b3e\Microsoft.VisualStudio.Web.HTML.Implementation.ni.dll
MOD - [2012.06.15 03:25:21 | 002,848,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\58c76d4259349b9fabc2c552e171025a\Microsoft.VisualStudio.Web.ni.dll
MOD - [2012.06.15 03:25:05 | 000,201,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\6e33afb423786693c47443a644baf642\Microsoft.VisualStudio.TemplateWizard.ni.dll
MOD - [2012.06.15 03:24:51 | 001,887,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\0adf20214a5a7ff05b367e398380ba99\Microsoft.VisualStudio.Shell.UI.Internal.ni.dll
MOD - [2012.06.15 03:24:49 | 001,469,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e6d357180b20dbfcc2ae408e492e95a5\Microsoft.VisualStudio.Shell.Design.ni.dll
MOD - [2012.06.15 03:24:47 | 000,848,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\3b889d2666fa38aa86d30164c066f72a\Microsoft.VisualStudio.Shell.ni.dll
MOD - [2012.06.15 03:24:25 | 000,250,368 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e546c2d2bcac3364c192efca6b56d9e3\Microsoft.VisualStudio.Project.VS.Implementation.ni.dll
MOD - [2012.06.15 03:24:24 | 002,829,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\4ae1364ef50f5642a27db3dc9c257a73\Microsoft.VisualStudio.Project.VisualC.VCProjectEngine.ni.dll
MOD - [2012.06.15 03:24:21 | 002,359,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\8b95dff71485d551eb91edbd3d49dad0\Microsoft.VisualStudio.Platform.WindowManagement.ni.dll
MOD - [2012.06.15 03:24:21 | 000,206,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\fbc424a926b26386d7451ef58fd0fc5a\Microsoft.VisualStudio.Project.Contracts.ni.dll
MOD - [2012.06.15 03:24:19 | 005,599,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\7fed78c04743aed81ba6620f4fba628d\Microsoft.VisualStudio.Platform.VSEditor.ni.dll
MOD - [2012.06.15 03:24:14 | 001,172,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\d2af4db90c44e4183c4890d5a4a58e14\Microsoft.VisualStudio.Modeling.Sdk.Shell.10.0.ni.dll
MOD - [2012.06.15 03:24:14 | 000,051,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\8cb384c9e293d6d2918ed29980d7b284\Microsoft.VisualStudio.Platform.AppDomainManager.ni.dll
MOD - [2012.06.15 03:24:12 | 002,718,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\f4a4540b741c60a4bba5d59b65854217\Microsoft.VisualStudio.Shell.10.0.ni.dll
MOD - [2012.06.15 03:24:09 | 002,900,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\6bbe89fa3729f303d7196b77f855634a\Microsoft.VisualStudio.Modeling.Sdk.Diagrams.10.0.ni.dll
MOD - [2012.06.15 03:24:07 | 002,285,568 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\7b680be2e96fe0f496bdec2e7eec830f\Microsoft.VisualStudio.Modeling.Sdk.10.0.ni.dll
MOD - [2012.06.15 03:23:58 | 001,432,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\a3f46d3893b5f49f95722ddd09c6b78c\Microsoft.VisualStudio.ExtensionManager.Implementation.ni.dll
MOD - [2012.06.15 03:23:48 | 000,920,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\ef786a339f20be0c2b647e8f823269ef\Microsoft.VisualStudio.Shell.9.0.ni.dll
MOD - [2012.06.15 03:23:43 | 006,051,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\b2a5972f393ebd76112ef6e931e6345b\Microsoft.VisualStudio.Editors.ni.dll
MOD - [2012.06.15 03:23:39 | 002,673,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\857aba0ab25d1b90655765bfc46d7135\Microsoft.VisualStudio.Editor.Implementation.ni.dll
MOD - [2012.06.15 03:23:36 | 000,576,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\388bd5a850243fb37a40679865a866f1\Microsoft.VisualStudio.Dialogs.ni.dll
MOD - [2012.06.15 03:23:35 | 000,702,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\accb588148d6afabde54691464e2ff45\Microsoft.VisualStudio.Diagnostics.Common.ni.dll
MOD - [2012.06.15 03:23:32 | 001,844,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\a2b66235a292b39df8cc343b91b0f541\Microsoft.VisualStudio.Design.ni.dll
MOD - [2012.06.15 03:23:29 | 006,968,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\aa2d3525b7a5bf4c04be39bbb10d40e9\Microsoft.VisualStudio.CSharp.Services.Language.ni.dll
MOD - [2012.06.15 03:23:23 | 000,312,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\9a7ba52998e857cd8df4b1ffbfea417c\Microsoft.VisualStudio.ComponentModelHost.Implementation.ni.dll
MOD - [2012.06.15 03:23:22 | 001,168,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e7493bc52f74e6ee30dbdb3c43c0ad59\Microsoft.VisualStudio.CommonIDE.ni.dll
MOD - [2012.06.15 03:23:21 | 000,922,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\48c9891ab3aab787bca9990977864bb2\Microsoft.VisualStudio.AppDesigner.ni.dll
MOD - [2012.06.15 03:23:19 | 000,819,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\960442bd55d19c113e124c55905dc459\Microsoft.VisualStudio.ni.dll
MOD - [2012.06.15 03:23:15 | 001,838,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\09c2f8f606e09d85cfe6e0ad89fbe729\Microsoft.VisualBasic.ni.dll
MOD - [2012.06.15 03:22:14 | 001,880,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\e899cda47704280f54949c69b78c55cc\System.Deployment.ni.dll
MOD - [2012.06.15 03:22:13 | 002,877,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Tas#\545d26502454316492990b42b093e673\Microsoft.Build.Tasks.v4.0.ni.dll
MOD - [2012.06.15 03:22:11 | 000,445,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\FSharp.VS.FSI\e2def783e7ba4a481a963c9b0c624bad\FSharp.VS.FSI.ni.dll
MOD - [2012.06.15 03:21:45 | 001,324,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\3fb10066b2121f3b44f73adb60bac8e2\Microsoft.VisualStudio.Debugger.PdtDebug.ni.dll
MOD - [2012.06.15 03:10:36 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll
MOD - [2012.06.15 03:10:26 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll
MOD - [2012.06.15 03:10:24 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012.06.15 03:10:22 | 011,021,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Design\ecde3362b4d67a0025c3c9d5b9525f4a\System.Design.ni.dll
MOD - [2012.06.15 03:10:17 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll
MOD - [2012.06.15 03:10:17 | 000,226,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing.Desi#\0640b7fe359ea63a1799465631aa691a\System.Drawing.Design.ni.dll
MOD - [2012.06.15 03:10:16 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012.05.16 10:59:26 | 000,064,000 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2012.05.16 10:59:25 | 000,783,360 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll
MOD - [2012.05.16 10:59:25 | 000,316,928 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2012.05.16 10:59:25 | 000,276,480 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2012.05.16 10:59:25 | 000,168,448 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012.05.16 10:59:25 | 000,099,840 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012.05.16 10:59:25 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2012.05.16 10:59:25 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012.05.16 10:59:25 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2012.05.16 10:59:25 | 000,076,800 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2012.05.16 10:59:25 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2012.05.16 10:59:25 | 000,046,592 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2012.05.16 10:59:25 | 000,045,568 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gsttypefindfunctions.dll
MOD - [2012.05.11 04:04:33 | 000,142,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\VSLangProj\c831cbaf715b5bb41a9197215a1009fc\VSLangProj.ni.dll
MOD - [2012.05.11 04:04:25 | 001,971,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\b0d4852fc57aed572307b110107affa0\System.Workflow.Runtime.ni.dll
MOD - [2012.05.11 04:03:52 | 000,369,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dc86fe1c7a6e3a7ce9e9c1f13d9b1e8e\System.ServiceModel.Routing.ni.dll
MOD - [2012.05.11 04:03:41 | 001,140,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ec057796972ce41b751eaa3a8306fbcb\System.ServiceModel.Discovery.ni.dll
MOD - [2012.05.11 04:03:39 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d09c237ee72af3935f1a01388ef8e315\System.ServiceModel.Channels.ni.dll
MOD - [2012.05.11 04:03:28 | 001,393,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\5055b60e339143bbace5871f5fe4b114\System.ServiceModel.Activities.ni.dll
MOD - [2012.05.11 04:03:26 | 000,432,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f8fa8f3947b4f9b6819d121537e39050\System.ServiceModel.Activation.ni.dll
MOD - [2012.05.11 04:03:25 | 001,072,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
MOD - [2012.05.11 04:03:24 | 018,058,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
MOD - [2012.05.11 04:03:13 | 001,086,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f42c2acdb000001066c78acfc6cd8655\System.ServiceModel.Web.ni.dll
MOD - [2012.05.11 04:02:25 | 000,134,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\7803f4398a527a87d5cace8023e93e8b\System.Data.DataSetExtensions.ni.dll
MOD - [2012.05.11 04:02:18 | 004,129,280 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities\51025a1c89f6fd752a5396a059d608b2\System.Activities.ni.dll
MOD - [2012.05.11 04:02:09 | 000,196,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\0a80fd3af7e48eb9cc9099fee5814dff\UIAutomationTypes.ni.dll
MOD - [2012.05.11 04:02:09 | 000,096,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\05787d96761cf20b76b927ace10ef1d3\UIAutomationProvider.ni.dll
MOD - [2012.05.11 04:02:06 | 001,479,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationBuildTa#\96e437d1e82e54e63ed96af50e96d03d\PresentationBuildTasks.ni.dll
MOD - [2012.05.11 04:02:05 | 001,343,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\b894a1df3e6d58ada8f1aa303465ca23\System.Data.Services.Client.ni.dll
MOD - [2012.05.11 04:02:04 | 000,194,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\4330e93f9d0ef85f1a972e11c2ac5156\System.ComponentModel.DataAnnotations.ni.dll
MOD - [2012.05.11 04:01:56 | 002,607,104 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\94fa4bb3b3199ec286153f2f4b6069df\Microsoft.Windows.Design.Markup.ni.dll
MOD - [2012.05.11 04:01:54 | 000,076,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\2f4104dec48189509ae61b35ac6b3da8\Microsoft.Windows.Design.Host.ni.dll
MOD - [2012.05.11 04:01:53 | 003,008,512 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\19ad78a54ba11079a812e17b51e49483\Microsoft.Windows.Design.Developer.ni.dll
MOD - [2012.05.11 04:01:53 | 000,409,088 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\84a7aa97add340afbb361c35e26536db\Microsoft.Windows.Design.Developer.WPF.ni.dll
MOD - [2012.05.11 04:01:50 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
MOD - [2012.05.11 04:01:50 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4837a5c6204d53e7aa4f7dd94b98207c\System.Xml.Linq.ni.dll
MOD - [2012.05.11 04:01:49 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
MOD - [2012.05.11 04:01:49 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\bb97517e4ca64e02282fca24612ce8ad\SMDiagnostics.ni.dll
MOD - [2012.05.11 04:01:46 | 001,189,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.OracleC#\d62b53e7a5528b03ff512c624a1fdb83\System.Data.OracleClient.ni.dll
MOD - [2012.05.11 04:01:45 | 001,925,632 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\dbe597aa9c12df5d08fb2f3f9872b834\System.Web.Services.ni.dll
MOD - [2012.05.11 04:01:44 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\94b346f2ab12d38efb1331ded5783396\System.Runtime.Remoting.ni.dll
MOD - [2012.05.11 04:01:44 | 000,071,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\9b418f37f4594806e1f4b0ed6d083a95\System.Web.ApplicationServices.ni.dll
MOD - [2012.05.11 04:01:42 | 000,787,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.ni.dll
MOD - [2012.05.11 04:01:42 | 000,649,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\67a386434938003bceb0752e979dabb3\System.Transactions.ni.dll
MOD - [2012.05.11 04:01:42 | 000,236,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.Wrapper.dll
MOD - [2012.05.11 04:01:41 | 000,244,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\d8b4dcd719a3805ab0bce3c8cdfe8288\System.Runtime.Caching.ni.dll
MOD - [2012.05.11 04:01:34 | 000,026,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VSDesigne#\3761211251de027969b440be03b5b42c\Microsoft.VSDesigner.ExceptionAssistant.SmartTag.ni.dll
MOD - [2012.05.11 04:01:17 | 000,348,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\896efa83ae9b825caa6f242392468cfe\Microsoft.VisualStudio.Web.HTML.ni.dll
MOD - [2012.05.11 04:01:09 | 001,066,496 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\1f52f41eb2d475631f9f17001dca8353\Microsoft.VisualStudio.VisualBasic.LanguageService.ni.dll
MOD - [2012.05.11 04:00:55 | 000,323,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\7a1403e124ed6288118fbb8b1635c0d3\Microsoft.VisualStudio.TextTemplating.10.0.ni.dll
MOD - [2012.05.11 04:00:54 | 000,286,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\c6326c8b9544d6b068d6555955bec656\Microsoft.VisualStudio.Text.UI.Wpf.ni.dll
MOD - [2012.05.11 04:00:53 | 000,410,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\a3528059d8c2b7f92fed05bbe43ac535\Microsoft.VisualStudio.Text.UI.ni.dll
MOD - [2012.05.11 04:00:53 | 000,266,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\d65ee797211b2b1203060cb4c1bc23bc\Microsoft.VisualStudio.Text.Logic.ni.dll
MOD - [2012.05.11 04:00:52 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\0560c278ea6ef9ac6f72aed11fe5663a\Microsoft.VisualStudio.Text.Data.ni.dll
MOD - [2012.05.11 04:00:52 | 000,115,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\dea3cbb4057fdd4fa80184041aee8234\Microsoft.VisualStudio.Text.Internal.ni.dll
MOD - [2012.05.11 04:00:35 | 001,310,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\080714703b070f029fb6bb54a92d765b\Microsoft.VisualStudio.Shell.ViewManager.ni.dll
MOD - [2012.05.11 04:00:32 | 001,605,120 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\50165b7a9d4be8e358da29c394560f94\Microsoft.VisualStudio.Shell.StartPage.ni.dll
MOD - [2012.05.11 04:00:31 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\2ea90f4827f7af1870fe71893758c82a\Microsoft.VisualStudio.Shell.Immutable.10.0.ni.dll
MOD - [2012.05.11 03:59:58 | 000,634,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\b71c195c7e935987e18f60620729fa11\Microsoft.VisualStudio.Project.Utilities.v10.0.ni.dll
MOD - [2012.05.11 03:59:57 | 000,282,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\5c1646a9cd95400ca83e573bd838b172\Microsoft.VisualStudio.Project.Framework.Implementation.ni.dll
MOD - [2012.05.11 03:59:57 | 000,068,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\3d3cd8b14342f4a61dee6704c442d2cb\Microsoft.VisualStudio.Project.Framework.ni.dll
MOD - [2012.05.11 03:59:56 | 001,362,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\c27b3e0c5baf209a248afaab1fc842c4\Microsoft.VisualStudio.Project.Contracts.Implementation.ni.dll
MOD - [2012.05.11 03:59:42 | 001,418,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\c47526aefdbb8b27529d272adc9054c4\Microsoft.VisualStudio.Modeling.Sdk.Diagrams.GraphObject.10.0.ni.dll
MOD - [2012.05.11 03:59:35 | 000,028,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e719bd054f9dbeef2201c7cd5051c94c\Microsoft.VisualStudio.Language.StandardClassification.ni.dll
MOD - [2012.05.11 03:59:34 | 000,197,120 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\ff2a2da9c306a9335bc6d714b3665570\Microsoft.VisualStudio.Language.Intellisense.ni.dll
MOD - [2012.05.11 03:59:32 | 000,230,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\4f0071ac2829b2a8cc42f8d03314bae5\Microsoft.VisualStudio.ExtensionsExplorer.UI.ni.dll
MOD - [2012.05.11 03:59:32 | 000,130,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\c288364e373e83bc7e18596de7c5cd9d\Microsoft.VisualStudio.FileDiscovery.ni.dll
MOD - [2012.05.11 03:59:32 | 000,033,280 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\c71a6537753f036a8fa90c75f8f6cff0\Microsoft.VisualStudio.Language.CallHierarchy.ni.dll
MOD - [2012.05.11 03:59:31 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\cdc2d4307e2ddbd8ab5242e073bc4b66\Microsoft.VisualStudio.ExtensionsExplorer.ni.dll
MOD - [2012.05.11 03:59:29 | 000,792,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\40a010229b35b547479e111289b30b47\Microsoft.VisualStudio.ExtensibilityHosting.ni.dll
MOD - [2012.05.11 03:59:29 | 000,087,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\84d97f2cad28a901df1326424509f2a0\Microsoft.VisualStudio.ExtensionManager.ni.dll
MOD - [2012.05.11 03:59:10 | 000,035,840 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\4ae5a117a692c487f19550fe43529d0f\Microsoft.VisualStudio.Editor.ni.dll
MOD - [2012.05.11 03:59:06 | 000,035,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\cd9c720a731b78e6f6361a1a27485d87\Microsoft.VisualStudio.Designer.Interfaces.ni.dll
MOD - [2012.05.11 03:59:04 | 000,275,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e23d21902b1243fbcd8630720b51ac28\Microsoft.VisualStudio.CSharp.SmartTags.ni.dll
MOD - [2012.05.11 03:58:58 | 000,091,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\3574850259acb7a02ac2b5fe9b5f2007\Microsoft.VisualStudio.CoreUtility.ni.dll
MOD - [2012.05.11 03:58:51 | 001,670,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\6d5ea380fbad651d8c6bdcbf7dfcadbc\Microsoft.VisualBasic.LanguageService.ni.dll
MOD - [2012.05.11 03:58:49 | 001,385,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\7ba63e988b607ef446e1a314c958e39a\Microsoft.VisualBasic.Editor.ni.dll
MOD - [2012.05.11 03:57:18 | 000,631,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Uti#\3ad065635e1e0cd413081be61993cd38\Microsoft.Build.Utilities.v4.0.ni.dll
MOD - [2012.05.11 03:57:18 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\5a4d233916a69d48fa12a9f7f103d893\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2012.05.11 03:57:11 | 000,194,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\f11d5fea7ded12068e8cdb8b2f1bdbd9\CustomMarshalers.ni.dll
MOD - [2012.05.11 03:57:10 | 001,931,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Eng#\520f23eeaf6b5241a74a56338e8b89f8\Microsoft.Build.Engine.ni.dll
MOD - [2012.05.11 03:57:08 | 004,248,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build\5246fa832baabf6e3706fd537fe19062\Microsoft.Build.ni.dll
MOD - [2012.05.11 03:57:05 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
MOD - [2012.05.11 03:57:04 | 000,258,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Fra#\71a3a98ff5fb128d3abf6ecc3224ba6b\Microsoft.Build.Framework.ni.dll
MOD - [2012.05.11 03:57:02 | 000,027,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\9a4177f8a4c1587ca2ac8c60042f9e70\Microsoft.VisualStudio.ComponentModelHost.ni.dll
MOD - [2012.05.11 03:56:57 | 001,333,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\a2c8193e131190f1e1f21f9faed920a3\Microsoft.Windows.Design.Interaction.ni.dll
MOD - [2012.05.11 03:56:56 | 000,520,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Windows.D#\b5d879864a05dc46e040d0471eafe4cd\Microsoft.Windows.Design.Extensibility.ni.dll
MOD - [2012.05.11 03:56:38 | 002,014,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Expressio#\3d9b454d3700b66e2d57ea0d94f718f3\Microsoft.Expression.Platform.WPF.ni.dll
MOD - [2012.05.11 03:56:36 | 003,849,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Expressio#\f9161718d956e8d6b3be2ce6a54a5c1e\Microsoft.Expression.DesignModel.ni.dll
MOD - [2012.05.11 03:56:32 | 000,063,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\083b75900e64016a16940a46c668c7a5\Microsoft.VisualStudio.Diagnostics.Measurement.ni.dll
MOD - [2012.05.11 03:55:54 | 004,843,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\FSharp.Core\d12722a5b6163afd59105be64086eed2\FSharp.Core.ni.dll
MOD - [2012.05.11 03:55:48 | 000,044,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\62c1a496dff99a6e5f5e4278d31ca4c1\Accessibility.ni.dll
MOD - [2012.05.11 03:54:00 | 000,035,840 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\51d670a1c1b9a93c350ad442f84d4d7b\Microsoft.SqlServer.PolicyEnum.ni.dll
MOD - [2012.05.11 03:53:46 | 000,073,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\5181f608c3a5dbf9a9131640188d9319\Microsoft.SqlServer.BatchParserClient.ni.dll
MOD - [2012.05.11 03:50:00 | 000,059,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\edb28e055113282b94af00bea4282e4a\Microsoft.SqlServer.Management.Data.Interop.ni.dll
MOD - [2012.05.11 03:49:59 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\818060874305ba3d12e387417c83227a\Microsoft.SqlServer.Management.DataTools.Interop.ni.dll
MOD - [2012.05.11 03:48:40 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\054ff376d0135cd54d6d9c85d1322284\Microsoft.SqlServer.Instapi.ni.dll
MOD - [2012.05.11 03:48:39 | 000,450,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b1b745dccde2939b5f554fb6c58cc0cb\Microsoft.VisualStudio.Debugger.Interop.ni.dll
MOD - [2012.05.11 03:48:39 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\6d3b14d2ad8a60046d73d365f6cd4c5d\Microsoft.SqlServer.Management.ConnectionUI.ni.dll
MOD - [2012.05.11 03:48:38 | 000,118,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\fda69a3df4aea8f490d5d59d46bcb655\Microsoft.SqlServer.Sqm.ni.dll
MOD - [2012.05.11 03:46:50 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
MOD - [2012.05.11 03:46:49 | 001,282,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ec6e4a4681407bd82193397e9df9b56d\Microsoft.SqlServer.Dmf.ni.dll
MOD - [2012.05.11 03:46:48 | 001,579,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\77b4b7194b5c711ec8df3338c5172d91\Microsoft.SqlServer.SqlEnum.ni.dll
MOD - [2012.05.11 03:46:47 | 006,738,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\427380ddeacfb16f11fb404d6465922d\Microsoft.SqlServer.Smo.ni.dll
MOD - [2012.05.11 03:46:41 | 000,640,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\d9ace980a7380c6d7c67ff5bae5e4e27\Microsoft.SqlServer.BatchParser.ni.dll
MOD - [2012.05.11 03:46:39 | 000,022,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\5288ab86c56e7e057a09ecd5b94f3754\Microsoft.VisualStudio.Designer.Interfaces.ni.dll
MOD - [2012.05.11 03:46:36 | 000,577,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\81c8cd4a693fd1a23c6bbe1cb624d35b\Microsoft.VisualStudio.Shell.Interop.ni.dll
MOD - [2012.05.11 03:46:36 | 000,373,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\698d77c01aa50da51f58a6e8398258fd\Microsoft.VisualStudio.Shell.Interop.8.0.ni.dll
MOD - [2012.05.11 03:46:36 | 000,306,176 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\6444a6d4c3b92f56f6d773f8acf67e8a\Microsoft.VisualStudio.OLE.Interop.ni.dll
MOD - [2012.05.11 03:46:36 | 000,281,088 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\8dddae85999889170b4575965a102b65\Microsoft.VisualStudio.TextManager.Interop.ni.dll
MOD - [2012.05.11 03:46:21 | 001,391,104 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\262086e3e34d6e3ca6c2956cfeefb749\Microsoft.SqlServer.Management.Sdk.Sfc.ni.dll
MOD - [2012.05.11 03:46:21 | 000,272,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\038e682b0a0b762c8aae2ed9d5ead010\Microsoft.SqlServer.ConnectionInfo.ni.dll
MOD - [2012.05.11 03:46:21 | 000,026,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\9f58257b3d3eefa80050123c54b760be\Microsoft.SqlServer.SqlClrProvider.ni.dll
MOD - [2012.05.11 03:46:20 | 000,128,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\052d20cd83fa7eed005b1b79125e6f4f\Microsoft.SqlServer.RegSvrEnum.ni.dll
MOD - [2012.05.11 03:46:16 | 000,532,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\c66125712c1f26367702432574f82d35\Microsoft.SqlServer.Diagnostics.STrace.ni.dll
MOD - [2012.05.11 03:46:15 | 000,041,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\47b6fca009f90c7ee97899e49bd7c61c\Microsoft.SqlServer.SqlTDiagM.ni.dll
MOD - [2012.05.11 03:45:49 | 000,573,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\EnvDTE\5b8667c6746bd6dff357a27fe2d5aa3a\EnvDTE.ni.dll
MOD - [2012.05.11 03:31:57 | 001,116,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\68e9e465d70fdba2cb0aadbc91869ed7\System.Data.OracleClient.ni.dll
MOD - [2012.05.11 03:31:44 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
MOD - [2012.05.11 03:31:43 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
MOD - [2012.05.11 03:31:42 | 006,610,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eaeca46457a0c33b93f6f4be08990cab\System.Data.ni.dll
MOD - [2012.05.11 03:31:09 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
MOD - [2012.05.11 03:30:55 | 000,680,448 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
MOD - [2012.05.11 03:30:52 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012.05.11 03:30:48 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012.05.11 03:30:47 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012.05.11 03:30:24 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012.05.11 03:07:48 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll
MOD - [2012.05.11 03:05:55 | 002,517,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\82c0c56ff8259e1440cfd0d5727a26d8\System.Data.Linq.ni.dll
MOD - [2012.05.11 03:05:55 | 000,693,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\877ef74350e6d374ca8f80b489a8cc8e\System.ComponentModel.Composition.ni.dll
MOD - [2012.05.11 03:05:54 | 006,815,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\99d0f7ba920eea1117e45dcd9fec0eb5\System.Data.ni.dll
MOD - [2012.05.11 03:05:52 | 001,616,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\9912b6d76c1017b5af6ef24730f550ca\Microsoft.CSharp.ni.dll
MOD - [2012.05.11 03:05:52 | 000,377,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\a9b1e597aaa263dea2cf8754440bd271\System.Dynamic.ni.dll
MOD - [2012.05.11 03:05:49 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
MOD - [2012.05.11 03:05:49 | 002,550,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\fdb98c6d783fe167c1dc0022f27b7cd6\System.Data.SqlXml.ni.dll
MOD - [2012.05.11 03:05:46 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012.05.11 03:05:43 | 000,736,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\5a3beae8b211b91bfc620c029cf4c2d4\System.Security.ni.dll
MOD - [2012.05.11 03:05:42 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
MOD - [2012.05.11 03:05:40 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012.05.11 03:05:37 | 000,145,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\7b7719d46a4da2e91e8c501347e48ab9\System.Numerics.ni.dll
MOD - [2012.05.11 03:05:36 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.02.15 11:37:17 | 000,008,192 | ---- | M] () -- C:\Program Files (x86)\Java\jre6\bin\jp2native.dll
MOD - [2011.11.22 23:43:05 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Shell.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Shell.Design.dll
MOD - [2011.11.22 23:43:05 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC\VSLangProj80\8.0.0.0__b03f5f7f11d50a3a\VSLangProj80.dll
MOD - [2011.11.22 23:43:04 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Design.dll
MOD - [2011.11.22 23:43:04 | 000,294,912 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualStudio\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.dll
MOD - [2011.11.22 23:01:47 | 000,370,528 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.SqlServer.BatchParser\10.0.0.0__89845dcd8080cc91\Microsoft.SqlServer.BatchParser.dll
MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.11.21 05:24:15 | 000,486,400 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
MOD - [2010.11.21 05:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010.11.13 04:36:45 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.10.29 20:31:26 | 000,330,240 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\icq.dll
MOD - [2010.10.18 07:12:42 | 000,054,372 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\zlib.dll
MOD - [2010.10.18 07:12:06 | 000,036,973 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\dbx_mmap.dll
MOD - [2010.09.29 01:07:48 | 000,374,272 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\uinfoexw.dll
MOD - [2010.09.27 20:18:04 | 000,097,280 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\mradio.dll
MOD - [2010.09.20 19:41:34 | 000,498,688 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\fingerprint.dll
MOD - [2010.09.14 10:19:10 | 000,259,072 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\watrack.dll
MOD - [2010.08.22 14:55:20 | 000,073,840 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\advancedautoaway.dll
MOD - [2010.08.22 14:53:52 | 000,086,116 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\keepstatus.dll
MOD - [2010.08.22 14:50:26 | 000,090,218 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\startupstatus.dll
MOD - [2010.08.13 10:43:50 | 000,062,976 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\menuex.dll
MOD - [2010.08.02 18:24:00 | 000,110,592 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\folders.dll
MOD - [2010.06.16 23:48:54 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\variables.dll
MOD - [2010.02.23 13:14:28 | 001,048,064 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\libcurl.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2008.01.28 21:04:42 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\Yaho's Miranda Pack\plugins\svc_dbepp.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012.02.29 15:15:08 | 000,048,704 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:64bit: - [2011.11.28 20:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2011.10.17 16:48:24 | 000,970,016 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2011.08.12 01:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2011.08.08 08:39:18 | 001,166,848 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.07.27 22:04:48 | 001,517,328 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV:64bit: - [2011.07.27 21:48:34 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.07.27 21:44:18 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV:64bit: - [2011.07.22 13:21:34 | 000,060,264 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV:64bit: - [2011.07.22 13:21:18 | 000,041,832 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV:64bit: - [2011.07.12 17:53:58 | 000,133,992 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:64bit: - [2011.07.12 17:53:40 | 000,145,256 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV:64bit: - [2011.07.12 17:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV:64bit: - [2011.07.12 17:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV:64bit: - [2011.07.09 02:53:20 | 000,144,232 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe -- (HyperW7Svc)
SRV:64bit: - [2011.06.03 13:51:38 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R)
SRV:64bit: - [2011.05.11 23:53:46 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.03.29 20:15:36 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:64bit: - [2010.12.17 00:18:08 | 000,198,784 | ---- | M] (Conexant Systems Inc.) [Auto | Running] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg)
SRV:64bit: - [2010.09.23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.06.24 12:49:59 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.12 13:01:24 | 000,124,856 | ---- | M] (Gemfor s.r.o.) [Auto | Running] -- C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe -- (ameisvc)
SRV - [2012.04.21 03:19:00 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.03.16 17:36:10 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.12.21 16:40:56 | 000,578,264 | ---- | M] (Pandora.TV) [Auto | Running] -- C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe -- (PanService)
SRV - [2011.12.14 13:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2011.12.01 04:05:00 | 000,175,168 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc)
SRV - [2011.12.01 04:05:00 | 000,089,152 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2011.10.20 13:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
SRV - [2011.10.20 13:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2011.03.16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.02.24 09:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service) Intel(R)
SRV - [2011.02.22 05:19:12 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2011.02.22 05:19:08 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2011.01.07 05:28:42 | 000,446,592 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\SASrv.exe -- (SAService)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 04:51:42 | 001,043,072 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.29 15:14:48 | 000,042,312 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:64bit: - [2011.12.27 03:10:44 | 000,040,248 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:64bit: - [2011.12.23 13:30:56 | 000,412,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011.12.19 14:45:22 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2011.12.01 04:05:00 | 000,014,960 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:64bit: - [2011.11.28 19:54:06 | 000,591,192 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2011.11.28 19:53:58 | 000,304,472 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2011.11.28 19:52:22 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:64bit: - [2011.11.28 19:52:20 | 000,058,712 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2011.11.28 19:52:11 | 000,066,904 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2011.11.28 19:51:53 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2011.11.21 20:45:48 | 000,279,616 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.10.19 07:41:16 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.10.19 07:41:16 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.10.17 17:24:50 | 000,437,288 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011.10.17 17:24:44 | 000,164,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011.10.17 17:24:44 | 000,146,984 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011.10.17 17:24:44 | 000,039,976 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011.10.17 17:24:44 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2011.09.22 22:01:54 | 000,311,144 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0105.sys -- (RsFx0105)
DRV:64bit: - [2011.09.09 12:51:36 | 000,218,624 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm)
DRV:64bit: - [2011.09.09 12:51:02 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV:64bit: - [2011.09.09 12:51:00 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV:64bit: - [2011.09.09 12:51:00 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2011.08.09 09:32:02 | 012,289,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2011.08.08 08:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.08.08 08:32:08 | 000,299,008 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.08.03 18:28:32 | 008,604,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Ovladač adaptéru řady Intel(R)
DRV:64bit: - [2011.08.02 18:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.07.22 18:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011.07.12 23:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011.07.09 02:53:24 | 000,032,104 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Program Files\Lenovo\RapidBoot\PHCORE64.sys -- (PHCORE)
DRV:64bit: - [2011.06.10 07:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.05.30 19:21:40 | 000,013,128 | ---- | M] (Authentec Inc.) [Kernel | Auto | Running] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) SMI Helper Driver (smihlp)
DRV:64bit: - [2011.05.12 03:16:38 | 009,319,424 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.05.11 23:16:54 | 000,304,128 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.04.09 00:09:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2011.03.29 20:13:40 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:64bit: - [2011.03.29 20:11:48 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:64bit: - [2011.03.24 08:36:20 | 001,576,064 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2011.03.24 01:25:00 | 000,101,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdxc64.sys -- (risdxc)
DRV:64bit: - [2011.03.05 03:18:42 | 000,166,016 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\5U877.sys -- (5U877)
DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:24:15 | 000,146,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rmcast.sys -- (RMCAST)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.11.20 15:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010.11.20 15:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010.11.20 13:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010.11.20 13:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010.11.05 16:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.10.19 09:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.14 18:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.09.07 07:09:36 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:64bit: - [2010.07.27 10:52:16 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2010.03.20 13:06:58 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENP
IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=i ... lz=1I7LENP
IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.4: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.4: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Schizi\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Schizi\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Schizi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.12 13:16:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.01.23 09:56:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.04.25 13:50:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.12.12 13:16:13 | 000,000,000 | ---D | M]

[2012.03.27 22:40:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Schizi\AppData\Roaming\Mozilla\Extensions
[2012.05.24 09:25:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Schizi\AppData\Roaming\Mozilla\Firefox\Profiles\a93si6j3.default\extensions
[2012.04.25 13:50:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.04.21 03:19:34 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.04.21 03:18:25 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.04.21 03:18:25 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#4 Příspěvek od schizi »

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Schizi\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Schizi\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Schizi\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Schizi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: WPI Detector 1.4 (Enabled) = C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Schizi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Schizi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\Schizi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Schizi\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
CHR - Extension: Gmail = C:\Users\Schizi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Lenovo Group Limited)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [SpywareTerminatorShield] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe File not found
O4:64bit: - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000..\Run: [KeyboardLeds.exe] C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe (KARPOLAN)
O4 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9:64bit: - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 94.74.192.252 94.74.192.244
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0FA364F5-52E8-48B4-B56B-07F379BC980E}: DhcpNameServer = 94.74.192.252 94.74.192.244
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{2d7e0e58-fa15-11e0-ba93-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2d7e0e58-fa15-11e0-ba93-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009.08.10 23:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{338fd5c4-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
O33 - MountPoints2\{338fd5c4-b689-11e1-b82c-f0def19ab966}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{338fd5d2-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
O33 - MountPoints2\{338fd5d2-b689-11e1-b82c-f0def19ab966}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{338fd5de-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
O33 - MountPoints2\{338fd5de-b689-11e1-b82c-f0def19ab966}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{9e5bcdc9-740b-11e1-b893-d5cd384c8a5e}\Shell - "" = AutoRun
O33 - MountPoints2\{9e5bcdc9-740b-11e1-b893-d5cd384c8a5e}\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9e5bce53-740b-11e1-b893-d5cd384c8a5e}\Shell - "" = AutoRun
O33 - MountPoints2\{9e5bce53-740b-11e1-b893-d5cd384c8a5e}\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
O37 - HKLM\...exe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
System Restore Service not available.

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.07.10 09:16:30 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Schizi\Desktop\OTL.exe
[2012.07.09 21:20:31 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.07.09 21:20:31 | 000,000,000 | ---D | C] -- C:\rsit
[2012.07.09 13:59:22 | 000,000,000 | ---D | C] -- C:\Users\Schizi\Desktop\andyedinborough-aenetmail-50562bb
[2012.07.07 13:08:43 | 000,000,000 | ---D | C] -- C:\Users\Schizi\AppData\Roaming\SUPERAntiSpyware.com
[2012.07.07 13:08:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.07.07 13:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.07.07 13:08:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.07.07 11:33:12 | 000,051,496 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\stflt.sys
[2012.07.07 11:31:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spyware Terminator
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2012.07.10 09:22:40 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000Core.job
[2012.07.10 09:21:00 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.10 09:21:00 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.07.10 09:16:43 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Schizi\Desktop\OTL.exe
[2012.07.10 09:10:00 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000UA.job
[2012.07.10 09:09:59 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.10 09:09:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.09 22:46:12 | 000,000,202 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
[2012.07.09 22:46:06 | 000,078,848 | ---- | M] () -- C:\Windows\KMSEmulator.exe
[2012.07.09 21:21:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.09 21:20:07 | 000,935,175 | ---- | M] () -- C:\Users\Schizi\Desktop\RSITx64.exe
[2012.07.09 15:08:06 | 000,268,014 | ---- | M] () -- C:\Users\Schizi\Desktop\export.png
[2012.07.09 15:00:53 | 000,273,067 | ---- | M] () -- C:\Users\Schizi\Desktop\gmailreader.png
[2012.07.09 13:59:14 | 000,251,573 | ---- | M] () -- C:\Users\Schizi\Desktop\andyedinborough-aenetmail-50562bb.zip
[2012.07.08 21:33:54 | 000,029,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.08 21:33:54 | 000,029,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.07 22:46:16 | 000,000,202 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2012.07.07 22:40:15 | 2077,675,519 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.07 11:33:12 | 000,051,496 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\stflt.sys
[2012.07.05 11:14:08 | 000,003,983 | ---- | M] () -- C:\Users\Schizi\Desktop\freeglobes.php
[2012.07.03 15:00:07 | 000,497,990 | ---- | M] () -- C:\Users\Schizi\Desktop\navod_regtool.pdf
[2012.07.03 12:13:34 | 000,304,235 | ---- | M] () -- C:\Users\Schizi\Desktop\welcome.pdn
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.07.10 09:21:00 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.07.09 21:20:07 | 000,935,175 | ---- | C] () -- C:\Users\Schizi\Desktop\RSITx64.exe
[2012.07.09 15:08:06 | 000,268,014 | ---- | C] () -- C:\Users\Schizi\Desktop\export.png
[2012.07.09 15:00:53 | 000,273,067 | ---- | C] () -- C:\Users\Schizi\Desktop\gmailreader.png
[2012.07.09 13:59:14 | 000,251,573 | ---- | C] () -- C:\Users\Schizi\Desktop\andyedinborough-aenetmail-50562bb.zip
[2012.07.03 14:08:12 | 000,497,990 | ---- | C] () -- C:\Users\Schizi\Desktop\navod_regtool.pdf
[2012.07.03 12:13:34 | 000,304,235 | ---- | C] () -- C:\Users\Schizi\Desktop\welcome.pdn
[2012.05.28 13:56:13 | 000,847,543 | ---- | C] () -- C:\Users\Schizi\AppData\Local\debuggee.mdmp
[2012.05.11 09:20:28 | 000,078,848 | ---- | C] () -- C:\Windows\KMSEmulator.exe
[2012.03.25 19:30:09 | 000,060,304 | ---- | C] () -- C:\Users\Schizi\g2mdlhlpx.exe
[2012.02.14 02:16:06 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.02.14 02:16:05 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.02.14 02:16:02 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012.02.14 02:16:00 | 000,003,914 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.01.06 23:15:14 | 000,007,680 | ---- | C] () -- C:\Users\Schizi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.12 13:04:19 | 000,228,567 | ---- | C] () -- C:\Windows\hpoins47.dat
[2011.12.04 17:16:08 | 000,000,512 | ---- | C] () -- C:\Windows\SysWow64\Storage.dat
[2011.12.04 17:16:08 | 000,000,028 | ---- | C] () -- C:\Windows\SysWow64\Index.dat
[2011.11.22 22:20:55 | 000,007,597 | ---- | C] () -- C:\Users\Schizi\AppData\Local\resmon.resmoncfg
[2011.11.21 20:42:22 | 000,647,168 | ---- | C] () -- C:\Windows\AutoKMS.exe
[2011.11.21 20:42:22 | 000,000,184 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2011.10.19 08:07:33 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.10.19 08:04:18 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011.10.19 08:03:23 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.10.19 08:03:22 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.10.19 07:54:43 | 001,755,110 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.05.12 00:57:52 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll

========== LOP Check ==========

[2012.05.31 10:48:22 | 000,000,000 | ---D | M] -- C:\Users\regTool\AppData\Roaming\Opera
[2012.06.12 21:20:51 | 000,000,000 | ---D | M] -- C:\Users\regTool\AppData\Roaming\PwrMgr
[2012.02.13 17:16:52 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\.minecraft
[2012.06.16 17:21:14 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\.mono
[2012.04.12 19:43:53 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Awesomium
[2011.11.22 23:33:52 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\CodeRush for VS .NET
[2011.12.18 22:29:49 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\ColorCop
[2012.01.12 00:52:14 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\DAEMON Tools Lite
[2012.07.05 11:14:56 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\FileZilla
[2011.11.21 20:49:44 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\GHISLER
[2012.04.19 11:46:56 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Gomez
[2012.06.02 14:54:02 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Hi-Rez Studios
[2011.12.04 16:42:01 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\ICSharpCode
[2011.11.22 22:40:01 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\IrfanView
[2012.04.12 19:41:39 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Khrona LLC
[2011.11.21 13:14:12 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Leadertech
[2012.01.01 22:39:47 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Microgaming
[2012.01.10 23:14:53 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\MySQL
[2011.11.22 19:45:48 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Notepad++
[2011.12.29 14:38:30 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\NuGet
[2011.11.21 13:24:26 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Opera
[2011.11.21 13:53:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\PCDr
[2011.12.22 12:44:25 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\poclbm
[2011.11.21 14:33:34 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\PwrMgr
[2012.01.10 22:27:18 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Quest Software
[2012.02.25 16:53:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\redsn0w
[2011.12.22 13:53:02 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\TeamViewer
[2012.04.12 19:34:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\The Amadeus Page® Web Site
[2012.06.12 16:23:36 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Unity
[2012.03.27 21:31:19 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Vodafone
[2012.07.07 22:46:16 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2012.07.09 22:46:12 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMSDaily.job
[2009.07.14 07:08:49 | 000,017,340 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< >

< >

< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2011.10.19 07:39:30 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.10.19 07:39:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.10.19 07:39:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.10.19 07:39:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.10.19 07:39:30 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.10.19 07:39:30 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll

< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2011.09.29 19:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.03.30 12:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2011.04.25 07:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011.04.25 08:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.10.19 07:39:42 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2011.10.19 07:39:42 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
[2011.09.29 18:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< >

< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[14 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[14 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\*.tmp -> ]
[9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\*.tmp -> ]
[25 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\basicauthenticationsample\add0aece\69ae43ce\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\basicauthenticationsample\add0aece\69ae43ce\*.tmp -> ]
[9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\plaintextsample\4141b946\cd3458af\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\plaintextsample\4141b946\cd3458af\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\2821fe8b\e6097dac\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\2821fe8b\e6097dac\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\d0b932ab\fb655225\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\d0b932ab\fb655225\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\*.tmp -> ]
[6 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\11b5c4a1\628b067c\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\11b5c4a1\628b067c\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\54b9f12a\3816c6a\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\54b9f12a\3816c6a\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5bbce075\5935b9ef\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5bbce075\5935b9ef\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\*.tmp -> ]
[5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\677aa438\48209cc7\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\677aa438\48209cc7\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\*.tmp -> ]
[16 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\*.tmp -> ]
[9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a19f2af6\d2731b0c\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a19f2af6\d2731b0c\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\*.tmp -> ]
[12 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\*.tmp -> ]
[10 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\*.tmp -> ]
[5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\*.tmp -> ]
[4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\*.tmp -> ]
[3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\*.tmp -> ]
[16 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\17c49e96\46692e82\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\17c49e96\46692e82\*.tmp -> ]
[2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\*.tmp -> ]
[1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\72c99ba6\635530b5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\72c99ba6\635530b5\*.tmp -> ]
[5 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[1 C:\Windows\twain_32\*.tmp files -> C:\Windows\twain_32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.02.13 17:16:52 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\.minecraft
[2012.06.16 17:21:14 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\.mono
[2011.11.22 12:16:49 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Adobe
[2012.04.12 19:07:43 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Apple Computer
[2011.11.21 13:14:11 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\ATI
[2012.04.12 19:43:53 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Awesomium
[2011.11.22 23:33:52 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\CodeRush for VS .NET
[2011.12.18 22:29:49 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\ColorCop
[2012.01.12 00:52:14 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\DAEMON Tools Lite
[2012.07.05 11:14:56 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\FileZilla
[2011.11.21 20:49:44 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\GHISLER
[2012.04.19 11:46:56 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Gomez
[2012.06.02 14:54:02 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Hi-Rez Studios
[2011.12.12 13:20:31 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\HP
[2011.12.12 13:16:25 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\HpUpdate
[2011.12.04 16:42:01 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\ICSharpCode
[2011.11.21 13:13:45 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Identities
[2011.11.21 20:04:49 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Intel
[2011.11.22 22:40:01 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\IrfanView
[2012.04.12 19:41:39 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Khrona LLC
[2011.11.21 13:14:12 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Leadertech
[2011.11.21 16:29:22 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Macromedia
[2012.04.25 14:41:33 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Malwarebytes
[2010.11.21 09:16:41 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Media Center Programs
[2012.01.01 22:39:47 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Microgaming
[2012.07.03 14:32:04 | 000,000,000 | --SD | M] -- C:\Users\Schizi\AppData\Roaming\Microsoft
[2012.01.29 12:11:14 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Microsoft Corporation
[2012.04.25 13:50:44 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Mozilla
[2012.01.10 23:14:53 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\MySQL
[2011.11.22 19:45:48 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Notepad++
[2011.12.29 14:38:30 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\NuGet
[2011.11.21 13:24:26 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Opera
[2011.11.21 13:53:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\PCDr
[2011.12.22 12:44:25 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\poclbm
[2011.11.21 14:33:34 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\PwrMgr
[2012.01.10 22:27:18 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Quest Software
[2012.02.25 16:53:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\redsn0w
[2012.07.09 10:06:55 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Skype
[2012.07.07 13:08:43 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.22 13:53:02 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\TeamViewer
[2012.04.12 19:34:00 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\The Amadeus Page® Web Site
[2012.06.12 16:23:36 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Unity
[2012.07.08 15:39:33 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\vlc
[2012.03.27 21:31:19 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\Vodafone
[2011.11.30 15:52:15 | 000,000,000 | ---D | M] -- C:\Users\Schizi\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2012.02.14 02:17:52 | 000,010,134 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{09415C3E-4DF1-EE91-8641-DBD2E6EB9F87}\ARPPRODUCTICON.exe
[2011.11.21 13:47:53 | 000,010,134 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{24E92E7A-6848-4747-A3EA-3AAC0576BE52}\ARPPRODUCTICON.exe
[2011.11.21 13:47:55 | 000,010,134 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{39A04221-294E-4D90-A0F2-CCB1EF15CB56}\ARPPRODUCTICON.exe
[2012.05.19 19:01:07 | 000,045,126 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{882C685B-3735-452E-9B77-D562A6A6AFE3}\_6FEFF9B68218417F98F549.exe
[2012.05.19 19:01:07 | 000,045,126 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{882C685B-3735-452E-9B77-D562A6A6AFE3}\_C0EDDA7A92A80D14F7FA33.exe
[2012.02.15 10:41:45 | 000,010,134 | R--- | M] () -- C:\Users\Schizi\AppData\Roaming\Microsoft\Installer\{A02153E8-8DF8-42E6-B7BF-D88EEA33565F}\ARPPRODUCTICON.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2012.07.10 09:09:59 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.07.07 22:46:16 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2012.07.09 22:46:12 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMSDaily.job
[2012.07.09 21:21:00 | 000,000,962 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.07.10 09:21:00 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.07.10 09:22:40 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000Core.job
[2012.07.10 09:38:01 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000UA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.07.07 22:47:06 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"KeyboardLeds.exe" = "C:\Program Files (x86)\Keyboard Leds\KeyboardLeds.exe" -- [2011.11.11 07:35:12 | 000,910,336 | ---- | M] (KARPOLAN)
"SUPERAntiSpyware" = C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE -- [2012.06.26 19:33:37 | 004,787,072 | ---- | M] (SUPERAntiSpyware.com)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.04.21 03:18:58 | 000,924,600 | ---- | M] (Mozilla Corporation) MD5=4F69AABB5D82AA4EF6DFF7871212ADF6 -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.05.18 01:21:54 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >
[2012.05.16 10:59:19 | 000,949,104 | ---- | M] (Opera Software) MD5=E8F78F11945EE6F91408C99AF15143EA -- C:\Program Files (x86)\Opera\opera.exe

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.07.10 09:21:00 | 000,000,512 | ---- | M] () MD5=146539D827F8A1F8F356DE88564F96D7 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2012.03.08 11:25:37 | 000,000,319 | ---- | M] () -- \Users\Schizi\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fi.crackedcdn.com%2Ffavicon.png
[2012.03.08 11:25:37 | 000,000,134 | ---- | M] () -- \Users\Schizi\AppData\Local\Opera\Opera\icons\www.cracked.com.idx

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#5 Příspěvek od schizi »

< *keygen* /s >

< *loader* /s >
[2012.05.11 09:29:15 | 003,375,104 | ---- | M] () -- \Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader.exe
[2012.05.11 09:29:15 | 001,064,960 | ---- | M] () -- \Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
[2010.03.19 00:21:56 | 000,063,312 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.dll
[2010.03.18 01:17:14 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.tlb
[2011.06.09 03:28:44 | 000,265,552 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2011.06.09 03:28:44 | 000,018,264 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2011.11.22 23:30:17 | 000,009,452 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Controls.SL\DevExpress.Xpf.Controls.SL\UploadControl\Uploader.cs
[2011.11.22 23:30:18 | 000,007,227 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core.SL\DevExpress.Xpf.Core.SL\Editors\Controls\ImageEdit\ImageLoader.cs
[2011.11.22 23:30:21 | 000,006,769 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core.SL\DevExpress.Xpf.Core.SL\Platform\SL\StyleManager\ResourceLoader.cs
[2011.11.22 23:30:21 | 000,002,949 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core.SL\DevExpress.Xpf.Core.SL\Themes\DXThemesLoader.cs
[2011.11.22 23:30:29 | 000,005,420 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Core\Native\XamlLoaderHelper.cs
[2011.11.22 23:30:29 | 000,007,227 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Editors\Controls\ImageEdit\ImageLoader.cs
[2011.11.22 23:30:29 | 000,002,770 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Editors\DateNavigator\DateNavigatorThemesLoader.cs
[2011.11.22 23:30:29 | 000,002,949 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\DXThemesLoader.cs
[2011.11.22 23:30:29 | 000,004,102 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\ResourceLoaderHelper.cs
[2011.11.22 23:30:29 | 000,003,158 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\StandardControlsResourceLoader.cs
[2011.11.22 23:30:23 | 000,002,704 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Grid.SL\DevExpress.Xpf.Grid.SL\Grid\FrameworkElements\DXGridThemesLoader.cs
[2011.11.22 23:30:24 | 000,002,704 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Grid\DevExpress.Xpf.Grid\Grid\FrameworkElements\DXGridThemesLoader.cs
[2011.11.22 23:30:11 | 000,003,643 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Charts\DevExpress.Xpf.Charts\Platform\Wpf\XamlLoaderHelper.cs
[2011.11.22 23:30:24 | 000,002,728 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.PivotGrid\DevExpress.Xpf.PivotGrid\PivotGrid\FrameworkElements\DXThemesLoader.cs
[2011.11.22 23:30:28 | 000,003,362 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.RichEdit.SL\DevExpress.Xpf.RichEdit.SL\PlatformAbstractionLayer\Xpf\RichEditDocumentLoader.cs
[2011.11.22 23:30:28 | 000,003,362 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.RichEdit\DevExpress.Xpf.RichEdit\PlatformAbstractionLayer\Xpf\RichEditDocumentLoader.cs
[2011.11.22 23:30:28 | 000,002,794 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpf.Scheduler\DevExpress.Xpf.Scheduler\DXSchedulerThemesLoader.cs
[2011.11.22 23:30:31 | 000,046,306 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo.SL\InTransactionLoader.cs
[2011.11.22 23:30:31 | 000,050,577 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo.SL\Loader.cs
[2011.11.22 23:30:31 | 000,046,306 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo\DevExpress.Xpo.Compact\InTransactionLoader.cs
[2011.11.22 23:30:31 | 000,050,577 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo\DevExpress.Xpo.Compact\Loader.cs
[2011.11.22 23:30:31 | 000,046,306 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo\DevExpress.Xpo\InTransactionLoader.cs
[2011.11.22 23:30:31 | 000,050,577 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.Xpo\DevExpress.Xpo\Loader.cs
[2011.11.22 23:30:32 | 000,006,026 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraBars\DevExpress.XtraBars\Docking2010\Resources\Loader.cs
[2011.11.22 23:30:36 | 000,009,917 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\Resources\Images\Loader.cs
[2011.11.22 23:30:36 | 000,009,492 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\SHP\ShapeLoader.cs
[2011.11.22 23:30:36 | 000,022,183 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\XAML\ShapeLoader.cs
[2011.11.22 23:30:36 | 000,003,401 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Loader.cs
[2011.11.22 23:30:36 | 000,003,990 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Presets\Loader.cs
[2011.11.22 23:30:36 | 000,008,390 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Styles\Loader.cs
[2011.11.22 23:30:34 | 000,003,866 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraCharts\DevExpress.XtraCharts\Utils\HolidaysLoader.cs
[2011.11.22 23:30:39 | 000,011,568 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraPivotGrid\DevExpress.PivotGrid.Core\CubeLoader.cs
[2011.11.22 23:30:41 | 000,006,031 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\Native\ResLoader.cs
[2011.11.22 23:30:41 | 000,002,819 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\Native\Import\VsComponentLoader.cs
[2011.11.22 23:30:41 | 000,007,721 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\UserDesigner\Native\XRUserDesignerLoader.cs
[2011.11.22 23:31:56 | 000,081,920 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.1\IDETools\System\DXCore\BIN\DevExpress.DXCore.Loader.dll
[2012.02.23 19:22:16 | 000,015,432 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.DemoData.Win\DevExpress.DemoData.Core.Win\Loader.cs
[2012.02.23 19:22:29 | 000,005,405 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Core\Native\XamlLoaderHelper.cs
[2012.02.23 19:22:29 | 000,007,339 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Editors\Controls\ImageEdit\ImageLoader.cs
[2012.02.23 19:22:32 | 000,002,949 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\DXThemesLoader.cs
[2012.02.23 19:22:32 | 000,006,159 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\ThemeManager\AssemblyLoaderProxy.cs
[2012.02.23 19:22:34 | 000,002,831 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Core\DevExpress.Xpf.Core\Themes\ThemeManager\IAssemblyLoader.cs
[2012.02.23 19:22:17 | 000,011,840 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.DemoBase.Wpf\DevExpress.Xpf.DemoBase.Wpf\DemoBase\DemoDataLoader.cs
[2012.02.23 19:22:17 | 000,002,704 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Grid\DevExpress.Xpf.Grid\Grid\FrameworkElements\DXGridThemesLoader.cs
[2012.02.23 19:21:52 | 000,003,643 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Charts\DevExpress.Xpf.Charts\Platform\Wpf\XamlLoaderHelper.cs
[2012.02.23 19:22:21 | 000,004,545 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.PivotGrid\DevExpress.Xpf.PivotGrid\PivotGrid\FrameworkElements\DXThemesLoader.cs
[2012.02.23 19:22:27 | 000,003,362 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.RichEdit\DevExpress.Xpf.RichEdit\PlatformAbstractionLayer\Xpf\RichEditDocumentLoader.cs
[2012.02.23 19:22:25 | 000,002,794 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpf.Scheduler\DevExpress.Xpf.Scheduler\DXSchedulerThemesLoader.cs
[2012.02.23 19:22:33 | 000,047,288 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpo\DevExpress.Xpo\InTransactionLoader.cs
[2012.02.23 19:22:33 | 000,059,625 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.Xpo\DevExpress.Xpo\Loader.cs
[2012.02.23 19:22:36 | 000,006,862 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraBars\DevExpress.XtraBars\Docking2010\Resources\Loader.cs
[2012.02.23 19:22:48 | 000,010,578 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\Resources\Images\Loader.cs
[2012.02.23 19:22:48 | 000,009,492 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\SHP\ShapeLoader.cs
[2012.02.23 19:22:48 | 000,022,181 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Core\XAML\ShapeLoader.cs
[2012.02.23 19:22:48 | 000,003,401 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Loader.cs
[2012.02.23 19:22:48 | 000,003,990 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Presets\Loader.cs
[2012.02.23 19:22:48 | 000,006,756 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraGauges\DevExpress.XtraGauges.Presets\Styles\Loader.cs
[2012.02.23 19:22:41 | 000,003,866 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraCharts\DevExpress.XtraCharts\Utils\HolidaysLoader.cs
[2012.02.23 19:22:56 | 000,011,568 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraPivotGrid\DevExpress.PivotGrid.Core\CubeLoader.cs
[2012.02.23 19:22:56 | 000,014,480 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraPivotGrid\DevExpress.PivotGrid.Xmla\Xmla\Metadata\XmlaMetaLoader.cs
[2012.02.23 19:22:56 | 000,011,298 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraPivotGrid\DevExpress.PivotGrid.Xmla\Xmla\Request\MethodRequestUploader.cs
[2012.02.23 19:22:57 | 000,006,031 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\Native\ResLoader.cs
[2012.02.23 19:22:57 | 000,002,819 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\Native\Import\VsComponentLoader.cs
[2012.02.23 19:22:57 | 000,007,721 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\Components\Sources\DevExpress.XtraReports\DevExpress.XtraReports.Extensions\UserDesigner\Native\XRUserDesignerLoader.cs
[2012.02.23 19:19:36 | 000,082,944 | ---- | M] () -- \Program Files (x86)\DevExpress 2011.2\IDETools\System\DXCore\BIN\DevExpress.DXCore.Loader.dll
[2009.12.01 02:55:06 | 000,145,082 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\HelpViewer\Resources\Loader.gif
[2009.10.22 06:29:58 | 000,030,776 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\smart web printing\RsrcLoaderLib.dll
[2009.10.22 06:29:58 | 000,002,713 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\uriloader.xpt
[2009.07.22 10:17:52 | 000,019,992 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2010.03.19 00:21:56 | 000,063,312 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.dll
[2010.03.18 02:57:18 | 000,001,373 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.dll.manifest
[2010.03.18 01:17:14 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.tlb
[2009.08.31 05:51:22 | 000,001,648 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxribboninfoloader.h
[2009.08.31 05:51:22 | 000,004,525 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\VC\atlmfc\src\mfc\afxribboninfoloader.cpp
[2011.07.18 23:33:32 | 000,008,787 | ---- | M] () -- \Program Files (x86)\Notepad++\user.manual\sites\all\modules\fancy_login\images\ajax-loader.gif
[2008.02.25 08:05:22 | 000,856,064 | ---- | M] () -- \Program Files (x86)\The KMPlayer\ImLoader.dll
[2011.06.09 03:28:44 | 000,387,408 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2011.06.09 03:28:44 | 000,018,264 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2009.07.22 10:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2009.07.22 10:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SqlResourceLoader.dll
[2012.02.29 08:49:32 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.02.29 08:49:32 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.02.29 08:49:32 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.02.29 08:49:32 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2011.11.22 23:30:29 | 000,064,251 | ---- | M] () -- \Users\Public\Documents\DevExpress 2011.1 Demos\Components\Common\DevExpress.VideoRent.Win\CS\DevExpress.VideoRent.Win\ElementConstStringLoader.cs
[2011.11.22 23:30:29 | 000,002,399 | ---- | M] () -- \Users\Public\Documents\DevExpress 2011.1 Demos\Components\Common\DevExpress.VideoRent.Win\CS\DevExpress.VideoRent.Win\Tests\ElementConstStringLoaderTests.cs
[2012.02.23 19:22:33 | 000,064,251 | ---- | M] () -- \Users\Public\Documents\DevExpress 2011.2 Demos\Components\Common\DevExpress.VideoRent.Win\CS\DevExpress.VideoRent.Win\ElementConstStringLoader.cs
[2012.02.23 19:22:33 | 000,002,399 | ---- | M] () -- \Users\Public\Documents\DevExpress 2011.2 Demos\Components\Common\DevExpress.VideoRent.Win\CS\DevExpress.VideoRent.Win\Tests\ElementConstStringLoaderTests.cs
[2012.07.02 11:46:13 | 000,000,847 | ---- | M] () -- \Users\Schizi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7U3JDY3\ajax-loader[1].gif
[2012.06.07 09:38:47 | 000,010,519 | ---- | M] () -- \Users\Schizi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J879I0BU\AdLoader-aee74f28845638b42a47bb02dc06a7c6.min[1].js
[2012.06.21 11:06:06 | 000,000,847 | ---- | M] () -- \Users\Schizi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAIMEHUW\ajax-loader[1].gif
[2012.06.07 09:38:47 | 000,000,652 | ---- | M] () -- \Users\Schizi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SAHYRVCK\AdLoader[1].htm
[2012.04.02 15:07:04 | 000,000,847 | ---- | M] () -- \Users\Schizi\Desktop\lilan\IREP zaloha\App_Themes\Default\Images\ajax-loader.gif
[2012.03.11 16:51:51 | 000,446,464 | ---- | M] () -- \Windows\NEXON_EU_DownloaderUpdater.exe
[1 \Windows\*.tmp files -> \Windows\*.tmp -> ]
[2012.05.21 17:44:38 | 000,082,944 | ---- | M] () -- \Windows\assembly\GAC_MSIL\DevExpress.DXCore.Loader\11.2.5.0__35c9f04b7764aa3d\DevExpress.DXCore.Loader.dll
[2010.10.07 05:36:40 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:35:48 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.10.07 05:36:40 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.10.07 05:36:40 | 000,387,408 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:35:48 | 000,370,512 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.10.07 05:36:40 | 000,265,552 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.03.24 21:12:34 | 000,249,680 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109A20000000100000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2010.10.07 05:36:40 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.10.07 05:36:40 | 000,265,552 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8
[2010.10.07 05:36:40 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2010.10.07 05:36:40 | 000,265,552 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2008.07.30 11:06:58 | 000,072,192 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\C2B4A4AA56408FC3AB67720A728DCABA\9.0.30729\FL_coloader80_dll_128691_128691_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2008.07.29 04:43:16 | 000,004,096 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\C2B4A4AA56408FC3AB67720A728DCABA\9.0.30729\FL_coloader80_tlb_128927_128927_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2008.04.21 22:19:04 | 000,061,952 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\D1C8C80120ADC6A449DC65306F6ACF27\10.0.1600\FL_coloader80_dll_128691_____X86.3643236F_FC70_11D3_A536_0090278A1BB8
[2008.04.21 17:21:56 | 000,004,608 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\D1C8C80120ADC6A449DC65306F6ACF27\10.0.1600\FL_coloader80_tlb_128927_____X86.3643236F_FC70_11D3_A536_0090278A1BB8
[2011.07.16 06:15:45 | 000,003,584 | -H-- | M] () -- \Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\system32\dmloader.dll
[2009.04.28 09:55:06 | 000,070,936 | ---- | M] () -- \Windows\system32\PhysXLoader.dll
[2011.07.16 06:15:45 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2009.04.28 09:55:06 | 000,070,936 | ---- | M] () -- \Windows\SysWOW64\PhysXLoader.dll
[2009.07.14 03:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 03:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 07:21:03 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 07:12:44 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.10.19 07:32:19 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2011.10.19 07:32:19 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.efi.mui_35ee487d
[2011.10.19 07:32:19 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.exe.mui_3bc5b827
[2011.10.19 07:32:19 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.efi.mui_f412814e
[2011.10.19 07:32:19 | 000,030,288 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.exe.mui_ff8b5358
[2010.11.21 09:06:45 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 09:06:45 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2010.11.21 09:06:45 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2010.11.21 09:06:45 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2010.11.21 09:06:45 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2011.10.19 07:37:49 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.10.19 07:37:49 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2011.10.19 07:37:49 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2011.10.19 07:37:49 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2011.10.19 07:37:49 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009.07.14 04:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 04:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2011.10.19 07:28:51 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2010.11.21 09:05:43 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2010.11.21 05:16:35 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011.10.19 07:37:46 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.10.19 07:37:46 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 04:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:15:45 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll

< End of report >

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#6 Příspěvek od schizi »

Extras log:
OTL Extras logfile created on: 10.7.2012 9:18:13 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Schizi\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

7,91 Gb Total Physical Memory | 3,55 Gb Available Physical Memory | 44,85% Memory free
15,82 Gb Paging File | 11,19 Gb Available in Paging File | 70,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 351,08 Gb Total Space | 267,84 Gb Free Space | 76,29% Space Free | Partition Type: NTFS
Drive D: | 334,67 Gb Total Space | 12,41 Gb Free Space | 3,71% Space Free | Partition Type: NTFS
Drive Q: | 11,72 Gb Total Space | 1,15 Gb Free Space | 9,85% Space Free | Partition Type: NTFS

Computer Name: SCHIZI-THINK | User Name: Schizi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.chm [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.cmd [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.com [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.cpl [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.exe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.hlp [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.hta [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.html [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.inf [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.ini [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.url [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.js [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.jse [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.pif [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.reg [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.scr [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.txt [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.vbe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.vbs [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.wsf [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.wsh [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- Reg Error: Key error.
batfile [open] -- Reg Error: Key error.
batfile [print] -- Reg Error: Key error.
chm.file [open] -- Reg Error: Key error.
cmdfile [edit] -- Reg Error: Key error.
cmdfile [open] -- Reg Error: Key error.
cmdfile [print] -- Reg Error: Key error.
comfile [open] -- Reg Error: Key error.
cplfile [cplopen] -- Reg Error: Key error.
exefile [open] -- Reg Error: Key error.
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- Reg Error: Key error.
htafile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- Reg Error: Key error.
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- Reg Error: Key error.
inffile [open] -- Reg Error: Key error.
inffile [print] -- Reg Error: Key error.
inifile [open] -- Reg Error: Key error.
inifile [print] -- Reg Error: Key error.
InternetShortcut [open] -- Reg Error: Key error.
InternetShortcut [print] -- Reg Error: Key error.
jsfile [edit] -- Reg Error: Key error.
jsfile [open] -- Reg Error: Key error.
jsfile [print] -- Reg Error: Key error.
jsefile [edit] -- Reg Error: Key error.
jsefile [open] -- Reg Error: Key error.
jsefile [print] -- Reg Error: Key error.
piffile [open] -- Reg Error: Key error.
regfile [edit] -- Reg Error: Key error.
regfile [open] -- Reg Error: Key error.
regfile [merge] -- Reg Error: Key error.
regfile [print] -- Reg Error: Key error.
scrfile [config] -- Reg Error: Key error.
scrfile [install] -- Reg Error: Key error.
scrfile [open] -- Reg Error: Key error.
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- Reg Error: Key error.
txtfile [print] -- Reg Error: Key error.
txtfile [printto] -- Reg Error: Key error.
vbefile [edit] -- Reg Error: Key error.
vbefile [open] -- Reg Error: Key error.
vbefile [print] -- Reg Error: Key error.
vbsfile [edit] -- Reg Error: Key error.
vbsfile [open] -- Reg Error: Key error.
vbsfile [print] -- Reg Error: Key error.
wsffile [edit] -- Reg Error: Key error.
wsffile [open] -- Reg Error: Key error.
wsffile [print] -- Reg Error: Key error.
wshfile [open] -- Reg Error: Key error.
Unknown [openas] -- Reg Error: Key error.
Folder [open] -- Reg Error: Key error.
Folder [explore] -- Reg Error: Key error.
Drive [find] -- Reg Error: Key error.
Applications\iexplore.exe [open] -- Reg Error: Key error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11922A47-2B3B-4F50-A5D2-92637A606BA9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{120832C4-5CDD-4766-97E6-2C81F9E73C59}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{205E452F-842F-4377-A926-5FD4C74E6B24}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2A84A0B0-5AA4-4857-BD68-C7F9DDF19A01}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{2FA37A2F-8393-45D7-9E5A-DA5F40C004AC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{31409A84-3B0D-4AB9-A8D2-795783ECCCE4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{32050107-E47D-4C52-B272-8A9B697A6183}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{37475A45-E722-40CA-BA45-D2A3577FB803}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4F9947D8-C3F4-4E27-ACEB-CD008D983E0D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5156069F-1E5F-46ED-9CD4-B1AC321BB9F0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{58116F57-4F74-4FE3-99FC-8084C4E47620}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{58F52378-3350-43E5-A4AB-A8E50DD29C64}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5E2C5326-A9F2-4EE0-8C83-14B89B275CB3}" = rport=137 | protocol=17 | dir=out | app=system |
"{6047E08D-44A3-4F11-9454-E807703D8BC6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6747E083-393A-40CC-9CCF-043A6E688D41}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{73DABFB8-4D82-4033-BD5F-45AFB0EEC5C9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{871D126C-5DF4-4BA2-9E4B-EBE393E5A66B}" = lport=137 | protocol=17 | dir=in | app=system |
"{877B1AB2-3C0E-4546-AA9A-5BA39CDE1730}" = lport=445 | protocol=6 | dir=in | app=system |
"{8F2D59EB-E9F5-4F94-B7AB-020AE77F653B}" = lport=139 | protocol=6 | dir=in | app=system |
"{9CD3B5E0-DDE5-4559-B1EE-7FBD47039871}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A564F33B-695A-4F24-ABD4-2936EB36FCEF}" = rport=139 | protocol=6 | dir=out | app=system |
"{A9E9DC17-E812-4795-93AF-49ED671CF7F8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B12C499E-2611-40ED-BCE2-D377513A1E06}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C70955C5-7B26-4B3A-A4DC-D9BF272B3E6A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C7F4653B-DB6A-4F27-8F92-64D885182B2D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC163738-3B66-462C-9B0C-6E53B409E769}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DDA27228-9BFE-4645-94B2-FB3E5F494684}" = rport=445 | protocol=6 | dir=out | app=system |
"{DDF5B5E6-112C-40AA-BB0C-884383A6D520}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E1C73ABB-79A2-4A55-91DE-FBD52F32905D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{EA3AF11A-C6DE-40F9-98F2-B701570C8484}" = rport=138 | protocol=17 | dir=out | app=system |
"{EAF5F716-258E-4F19-8736-02417E00644F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EB79CDF4-8D30-41AA-9F46-C1A84DDC2D49}" = rport=10243 | protocol=6 | dir=out | app=system |
"{EF086334-F29A-4BAB-B440-91635E0B1565}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{F06B74D7-01EF-47C2-AC2F-94ACCC4BA31D}" = lport=138 | protocol=17 | dir=in | app=system |
"{F5DA82F6-56BC-4F4B-ABF5-109E21D57E4A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FBA47138-0CCF-4572-A43F-9C327C2CE4BF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{037B955F-333C-4203-A0BA-D0A309A71F16}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0AC5C340-2C92-42AB-8126-D33620E71936}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{0E31C876-F4C2-48D2-BF45-5C4231FFA323}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{1DA5E91C-14CD-4ADC-98A2-93592DE98200}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1F81B808-49ED-4938-B102-321C1F742D2D}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe |
"{27D1D1A0-E3E0-4051-A28A-4E0F622FA6F5}" = dir=in | app=e:\setup\hpznui40.exe |
"{2966084A-28E5-4E1A-A855-410024063FC3}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{2A714959-3C70-46BD-BEED-7ED90835A81C}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{2D10D319-ADB9-4575-BA6B-5552C78C05F2}" = protocol=6 | dir=out | app=system |
"{2E969D04-3418-4753-9565-C48516FEEA7D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{3282B58A-DACA-492C-9AAA-90A496FD7D40}" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"{33BF6FDC-AD2B-4E73-AC94-736A9D020989}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{33C5E977-FFC9-41A9-88A4-183F61EBC4CD}" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"{344386AB-B894-48DC-83EF-A8A6FB61A28E}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe |
"{36F7850C-AC54-4935-86C6-8976FF740AA7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{3A10C6A1-A967-4D12-BDDE-A101B96BBFA0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{3A593848-655F-4395-9DF4-D364DC888F47}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40632C7B-EC48-4BA2-A9F7-DB489D65FE3D}" = protocol=17 | dir=in | app=c:\program files (x86)\lenovo\system update\uncserver.exe |
"{430DCD1E-840D-4D2D-A53A-C0BA994F019A}" = protocol=17 | dir=in | app=c:\windows\kmsemulator.exe |
"{448B5ECC-1842-4AF5-8486-D1A3C544583B}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\everquest 2\launchpad.exe |
"{4A6E4B21-B608-477A-BCB5-D283BDAD83E2}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{4B88345E-55B0-4714-9730-1650603A4AF1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{4CAA8A5E-4560-4F9C-BD47-6020D57A296F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{529187E7-6CDB-45B1-A5DE-7126941FB817}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{5E32242C-F086-404E-9492-37D2142FE13F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{60CD1F33-BB15-4AC7-9FA0-8A31BAD3FA80}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{67567CF1-CB99-4EC5-A6D9-D42828C87130}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{692ECB64-5BEE-4D83-B8AC-D07A3A1D2F47}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe |
"{696EE99C-A881-48EB-9C49-2DA1E320469A}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6E221A0C-B653-4155-BD2D-157F60BD2389}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{71D86979-BFFE-4763-86FF-211067B906CC}" = protocol=6 | dir=in | app=c:\windows\kmsemulator.exe |
"{72D52E7D-F684-417D-BED0-F8BFF2300F22}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe |
"{7990FF22-3D1A-4D49-BC96-88BFD3519373}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{8015F344-301A-4D11-8CA3-8A5ED7494811}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{80DC0735-15B2-4058-B0D1-601E6C127616}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{861953BC-57D8-46BB-BD01-C921BA2E72A3}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe |
"{8B31EE47-CAAF-4DA9-9CA1-BC68C6A4F0E5}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{8C62B34A-9379-4B6F-9BD6-FE4EE83927A2}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8D797618-D525-4081-A3A2-E7D06AE48AA9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{961E8AAF-6140-4FCA-9E5C-B19309C02C03}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe |
"{9C597090-6303-412C-972A-4E0614F2611F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A424BF9C-3C62-42E9-9DDD-0B633927CB15}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{A4AD0142-ACD9-48F8-BDD9-E8C8DFA0C332}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A603FC2A-6A6C-4565-ACDC-9A6E80F28547}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe |
"{A6788375-50E4-4000-AD11-421A8612CD92}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\29infinity04\pirates, vikings, and knights ii\srcds.exe |
"{AAEACED2-3670-460A-B1BD-85C0345019CC}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe |
"{B03A4FC1-F690-4367-9170-AA266EC98F05}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\everquest 2\launchpad.exe |
"{B222E39E-1102-4383-BE2F-0DAFBADE25B1}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe |
"{B39D92E9-3DB9-4CCF-8A5C-16F4BF5B5D8A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{BDD95F47-E30F-4CC8-816A-EA485F43CDD2}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\29infinity04\pirates, vikings, and knights ii\srcds.exe |
"{BEB3BD3D-0C60-4356-AF2A-D4515F0542D1}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CBC1586E-6DA6-49B2-925A-C6237E1AC4B6}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{D06FADC4-9F7B-40A9-9EA7-F8215D73BB6B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D33AA6E5-1877-441E-9236-98C8EAD16A68}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D3777FF3-76BD-402F-B7E4-C93CB5CF9F26}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe |
"{D4B33FF5-A989-46E6-86A4-C265A03064DB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D963BD0D-2EB3-4D5B-A7B3-510B286FEE1F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DC86ACB1-65F8-42C0-AFAF-D11B0E36500B}" = protocol=6 | dir=in | app=c:\program files (x86)\lenovo\system update\uncserver.exe |
"{DDB63191-D777-40D2-88ED-7CDA67570DA3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{E0ADED02-BDE5-47EC-B235-69FF5A2F7CBA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{E8F5542D-5B1D-47CB-879E-809840873AF2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EBCF0C5E-B47E-4FA9-A9CD-942944E0EF8E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F125B4A7-7855-4D23-A3DF-41B60511862A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{F5912991-93B2-42FF-85E4-8D814EA97A1D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{FB7B87FA-8728-47E5-901E-56A81314E22D}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{FBAE5953-6F90-4F50-81EE-2FBA7388DCAA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FCD528BB-D0A1-487C-9CBA-041466F28F3B}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{FE9908B2-139D-48C5-B3B4-0F84137B9676}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{072F4F74-2209-49FA-853E-88EDBD857918}C:\program files (x86)\yaho's miranda pack\miranda32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yaho's miranda pack\miranda32.exe |
"TCP Query User{2090A41E-2C67-4BFF-BBAF-9BFF3C01E8DD}D:\games\farcry\bin\farcry.exe" = protocol=6 | dir=in | app=d:\games\farcry\bin\farcry.exe |
"TCP Query User{2F582C54-D6CE-4E24-81DF-E3067A0CB7B2}C:\program files (x86)\yaho's miranda pack\miranda32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yaho's miranda pack\miranda32.exe |
"TCP Query User{3C6E4AF2-2506-4F2D-8223-0EB93DDAEEBF}C:\redsn\redsn0w.exe" = protocol=6 | dir=in | app=c:\redsn\redsn0w.exe |
"TCP Query User{3F1ADFE6-9A33-4386-92E1-0BE32DE66D7B}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{49AAE346-636A-4A4E-93CE-A0FA38EF0CDE}D:\games\steam\steamapps\29infinity04\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\29infinity04\counter-strike source\hl2.exe |
"TCP Query User{529B5350-0736-4980-BF9E-9D7041533EED}C:\program files (x86)\spyware terminator\spywareterminatorupdate.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spyware terminator\spywareterminatorupdate.exe |
"TCP Query User{545CCC72-0201-4CE3-96C8-6714DA7DDE3A}C:\redsn\redsn0w.exe" = protocol=6 | dir=in | app=c:\redsn\redsn0w.exe |
"TCP Query User{65124E79-C716-469D-AE73-436ED033023F}D:\games\steam\steamapps\common\global agenda live\binaries\globalagenda.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"TCP Query User{A14F4895-DEEA-4061-AF23-E890FF791D7B}C:\windows\kmsemulator.exe" = protocol=6 | dir=in | app=c:\windows\kmsemulator.exe |
"TCP Query User{C5FD84E4-EA17-491E-8B56-EE87BF9239ED}D:\games\farcry\bin\farcry.exe" = protocol=6 | dir=in | app=d:\games\farcry\bin\farcry.exe |
"TCP Query User{DCC23038-7917-4E2D-B6A9-A221BF3CD254}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"TCP Query User{FBF89825-CC71-482F-92FB-C8F21A9D8306}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"UDP Query User{13B8553E-D0A4-4B9E-B1BD-657E6A730B70}C:\program files (x86)\yaho's miranda pack\miranda32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yaho's miranda pack\miranda32.exe |
"UDP Query User{2AC9797F-5125-4C31-8B4F-58F3B09BDC42}C:\redsn\redsn0w.exe" = protocol=17 | dir=in | app=c:\redsn\redsn0w.exe |
"UDP Query User{3364317D-F98C-4424-9835-F16406A95BDD}C:\redsn\redsn0w.exe" = protocol=17 | dir=in | app=c:\redsn\redsn0w.exe |
"UDP Query User{399D10AE-0ABB-49FB-B63C-792767210C43}C:\program files (x86)\spyware terminator\spywareterminatorupdate.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spyware terminator\spywareterminatorupdate.exe |
"UDP Query User{44830E64-6821-45DA-BB37-ECBDD0E624D6}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{6F97F0CE-B0E5-426F-9761-6A0AAF379E6A}D:\games\steam\steamapps\29infinity04\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\29infinity04\counter-strike source\hl2.exe |
"UDP Query User{7AD28A07-8517-434D-90F1-9FA872A44741}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"UDP Query User{9D967681-8F03-485D-863E-5F3D56E91B37}C:\program files (x86)\yaho's miranda pack\miranda32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yaho's miranda pack\miranda32.exe |
"UDP Query User{B33AEB61-360A-4C7B-9B10-BE4B07066FB9}C:\windows\kmsemulator.exe" = protocol=17 | dir=in | app=c:\windows\kmsemulator.exe |
"UDP Query User{BE216306-A445-4D12-AC29-D9B487590A4C}D:\games\farcry\bin\farcry.exe" = protocol=17 | dir=in | app=d:\games\farcry\bin\farcry.exe |
"UDP Query User{C2BBB6E7-67EF-45A8-98EA-8B1A45C87C20}D:\games\farcry\bin\farcry.exe" = protocol=17 | dir=in | app=d:\games\farcry\bin\farcry.exe |
"UDP Query User{E22CA468-068C-46D4-8DC0-7E49C5E717E4}D:\games\steam\steamapps\common\global agenda live\binaries\globalagenda.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"UDP Query User{E8B10C36-6686-48FC-9AC4-348D1068267F}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{014E482A-0C27-47E3-BA82-307E9DCA2F47}" = HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 7
"{034106B5-54B7-467F-B477-5B7DBB492624}" = Microsoft Sync Framework Services v1.0 SP1 (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0C6C4C8A-3B96-4681-90BA-0E15CDE96298}" = Microsoft SQL Server 2008 Management Studio
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{108C8C1D-DA02-4A6C-94CD-5603F6A6FC72}" = Microsoft SQL Server 2008 Management Studio
"{1AB7EDC5-D891-34C5-9FF1-BE6A85ACC44B}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
"{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)
"{1E6ED082-E32D-4B2B-8B6A-70B094815135}" = Microsoft SQL Server System CLR Types (x64)
"{25FBDA9A-E868-4B3B-B9FF-D923818511A1}" = Software Intel(R) PROSet/Wireless WiFi
"{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java(TM) 6 Update 31 (64-bit)
"{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}" = Microsoft SQL Server 2008 Native Client
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{31A767DA-2BA4-F9EF-1747-4AED98BD4212}" = ccc-utility64
"{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources
"{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources
"{39A04221-294E-4D90-A0F2-CCB1EF15CB56}" = Lenovo Patch Utility 64 bit
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5E2652DF-743F-482B-A593-C95F431A5769}" = RapidBoot
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6292D514-17A4-403F-98F9-E150F10C043D}" = Microsoft SQL Server 2008 Setup Support Files
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{81455DEB-FC7E-3EE5-85CA-2EBDD9FD61EB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8438EC02-B8A9-462D-AC72-1B521349C001}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64)
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B2C4509-2B9F-4303-BA74-E2F9BB773F03}" = Oracle VM VirtualBox 4.1.8
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{C2938C94-239C-4156-B245-C5406A4F3E93}" = ThinkVantage Fingerprint Software
"{C3600AE6-93A0-3DB7-B7AA-45BD58F133B5}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{C6C9D5F7-630C-4125-8C4E-94AF77C1896E}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{CC4878C0-4A6A-49CD-AAA7-DD3FCB06CC84}" = Microsoft Web Platform Installer 3.0
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE47BA54-78AC-409F-9151-BDF5BE15A804}" = Network64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D57519D3-2E37-3E34-94AF-4D59BFAB87E6}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E224B44B-B5EB-4af3-A80A-A255358E241A}_is1" = ThinkVantage AutoLock
"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1
"{EAEBF166-B06A-4D7F-BAF7-6615303D5C7C}" = Microsoft SQL Server 2008 R2 Management Objects (x64)
"{F5079164-1DB9-3BDA-853B-F78AF67CE071}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FBDB286E-D477-3C75-7F95-CAE737409050}" = ATI Catalyst Install Manager
"73C6BE3E3B6FC5418F2B47E6C75F6C8F9552DC12" = Windows Driver Package - Intel (iaStor) hdc (11/06/2010 10.1.0.1008)
"828B05D2B647CDAEA22493F7BFB96847265EE596" = Windows Driver Package - Realtek (RTL8167) Net (12/29/2010 7.037.1229.2010)
"ATI Uninstaller" = ATI Uninstaller
"C63C03BF3BE2B6F6204BB54541690449FFF79F4F" = Windows Driver Package - Synaptics (SynTP) Mouse (05/05/2011 15.3.6.0)
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"D01A7EE241898C810674C69EB908D655D149BE77" = Windows Driver Package - Lenovo 1.62.00.00 (01/19/2011 1.62.00.00)
"DisableAMTPopup" = Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7
"EnablePS" = Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"LENOVO.SMIIF" = Lenovo System Interface Driver
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"OnScreenDisplay" = On Screen Display
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01C5A10F-AD9B-405B-853A-6659841A1242}" = Microsoft SQL Server 2008 Policies
"{025055FC-779B-42F3-95A5-F6926B2964EF}" = Intel(R) Wireless Display
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05855322-BE43-41FE-B583-D3AE0C326D58}" = Microsoft Silverlight 4 SDK
"{05D08C4D-58A2-438B-A419-EE994E64E15D}" = B110
"{068002C1-0010-57BA-209D-D9B6E0DA62A5}" = Catalyst Control Center Graphics Previews Common
"{09415C3E-4DF1-EE91-8641-DBD2E6EB9F87}" = PX Profile Update
"{09C52940-A4D1-4409-A7CC-1AAE630CF578}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BE273CD-AAB9-361B-8C32-D955EAC929E3}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{0C7DC0B9-C6A8-9666-8A99-FEF45CD1E2CF}" = CCC Help Portuguese
"{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}" = Microsoft Sync Framework SDK v1.0 SP1
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AA5BD63-6614-44B2-88A7-605191EDB835}" = Dotfuscator Software Services - Community Edition
"{1B38D00E-A7FE-69AB-405E-A2FB92473C8D}" = CCC Help Spanish
"{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{24E92E7A-6848-4747-A3EA-3AAC0576BE52}" = Lenovo Patch Utility
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A38A248-77EE-1425-D96F-AA4DDDD042D3}" = CCC Help German
"{2DBC8055-BAA2-65E8-3942-E2843FE5B926}" = Catalyst Control Center InstallProxy
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877A7B2-CDA8-B5E9-00A4-E94A7CD6D472}" = CCC Help Finnish
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3F752762-9BB6-34C9-005A-D265B0713971}" = Catalyst Control Center Profiles Mobile
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
"{46473AAA-ECD6-340B-2A41-BBEAD7CE1239}" = CCC Help Norwegian
"{4987CBF1-634F-89D9-8D29-D703EA07E4C7}" = CCC Help Greek
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F038D88-0311-29AF-D825-D3F2D38FAF18}" = Catalyst Control Center
"{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger
"{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}" = Create Recovery Media
"{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}" = HPAppStudio
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5AB7D739-1735-3A9E-BE73-C43507CB4E6F}" = Microsoft Visual Studio 2010 Service Pack 1
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{6090C051-D5A9-7327-9494-A04316488C6C}" = CCC Help Japanese
"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages
"{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker
"{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}" = Microsoft SQL Server Compact 3.5 SP1 Query Tools English
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6E7CC067-77C3-B53A-EFFC-70A58BF90E5D}" = CCC Help Hungarian
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}" = Microsoft SQL Server 2008 R2 Management Objects
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A56D81D-6406-40E7-9184-8AC1769C4D69}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{7CC6E579-7042-F797-C812-DD14688CB3BA}" = CCC Help Dutch
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{877B76B2-F83F-4F5A-B28D-3F398641ADB6}" = Microsoft SQL Server System CLR Types
"{882C685B-3735-452E-9B77-D562A6A6AFE3}" = inSSIDer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E4B1BE8-DCF3-4B90-A726-B28107442623}" = SolutionCenter
"{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0015-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0016-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0018-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-0019-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001A-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001B-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{2304F942-79D2-46F7-A512-269A7F5B7EFC}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-001F-041B-0000-0000000FF1CE}_Office14.PROPLUSR_{A162C5E6-7778-4D5B-9F0A-38F0122DD859}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{AB90513B-B892-41B5-8F8B-1D356A449652}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-002C-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{8148DB19-71B1-4415-8B26-DF5B9E873FC3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-0044-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-006E-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{EEF3E2C0-135B-44DC-BEDD-7F01CFBEFF46}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00A1-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{90140000-00BA-0405-0000-0000000FF1CE}_Office14.PROPLUSR_{E6C0DAE8-3840-4117-AB4D-674930D0DDE9}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA0DEE4-E84B-466F-9B96-FC255F3A929F}" = Integrated Camera TWAIN
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A37A2653-CED4-4FAA-82F8-CA5B93E9EA6D}" = Awesomium SDK
"{A5630CB0-6D3C-4C93-9A51-03BEB835A982}" = NuGet
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A833C64A-8367-4683-91FB-E574143A1726}" = Catalyst Control Center - Branding
"{A879B90E-B62C-4DA4-9C3F-79A1A6CFAAF9}" = Microsoft ASP.NET Web Pages - Visual Studio 2010 Tools
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Czech
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{B2CA6F37-1602-4823-81B5-0384B6888AA6}" = Integrated Camera Driver Installer Package Ver.1.1.0.1147
"{B3131F98-FC4B-4931-9D01-723C61F1AFBD}_is1" = Yaho's Miranda Pack - Dark Edition 4.8
"{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení
"{B7B3E9B3-FB14-4927-894B-E9124509AF5A}" = Adobe Flash Player 10 ActiveX
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{B939E0E7-D4CC-01B5-A8AF-E8F16A558D3F}" = CCC Help Chinese Standard
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BBFB2E59-B0DB-42C8-8F4D-CF4E85471667}" = Toolbox
"{BC4A2B6E-DA5E-2802-F161-C5DD27C5138A}" = CCC Help Turkish
"{BC537AE0-88AF-47ED-B762-33B0D62B5188}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{BD42856F-A3A8-89E8-B307-A6AB5393EF53}" = CCC Help Polish
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel(R) Identity Protection Technology 1.1.2.0
"{C1B0A2C0-C50B-588B-392D-175E21FAA21C}" = CCC Help French
"{C2B9E4FE-F6BF-B8EA-947B-912557E9E959}" = CCC Help Thai
"{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
"{C5EB9B5A-2964-D5A3-869A-520448200FC3}" = PowerXpressHybrid
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C82D8932-EB28-4da6-9582-33D515D46F04}" = Huawei Drivers
"{C9969938-E6DA-E5AE-B662-1D886596541F}" = CCC Help Russian
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6B15AE6-B052-363E-B6BB-C4714CBA6509}" = Microsoft Visual Studio 2010 Professional - ENU
"{D6F3441B-AAF2-C216-761E-1609CFEF1793}" = CCC Help Danish
"{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}" = WCF RIA Services V1.0 SP1
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad Power Manager
"{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}" = Microsoft ASP.NET MVC 3
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1C82F2E-DFAF-444A-80B3-DE7364A0F01A}" = CCC Help Korean
"{E1E09216-785C-F097-B6F9-DE1F2614EA52}" = CCC Help Italian
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E9E25C9F-92C3-46FC-AB0B-55BE59AD271B}" = CCC Help Swedish
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Display Audio Driver
"{F1495258-1B5E-7380-3242-17942AFCEAF0}" = CCC Help Czech
"{F691F42B-5B66-656F-8161-EE8A00DE6CCD}" = PX Profile Update
"{F7BEC30A-3918-2617-00F9-4D36B9CC42B8}" = CCC Help English
"{F88E2E04-7EF5-488C-8E38-C94EB808458E}" = PS_AIO_07_B110_SW_Min
"{F9AB8BD0-282F-0DFB-14B7-21BC98C8518A}" = Catalyst Control Center Localization All
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
"{FB99AD73-DFD2-7543-3753-078BEC5EE08F}" = CCC Help Chinese Traditional
"{FC909837-27D0-4FB4-8653-00F63EB70D74}" = Microsoft ASP.NET MVC 3 - Visual Studio 2010 Tools Update
"{FE041B02-234C-4AAA-9511-80DF6482A458}" = RICOH_Media_Driver_v2.13.18.02
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"4F6D5E84-5826-4394-9F40-3A9A19165651_is1" = Pandora Service
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Free Antivirus
"Awesomium SDK 1.6.6" = Awesomium SDK
"DAEMON Tools Lite" = DAEMON Tools Lite
"DevExpress 2011.1 Components" = DevExpress 2011.1 Components
"DevExpress 2011.1 IDETools" = DevExpress 2011.1 IDETools
"DevExpress 2011.2 Components" = DevExpress 2011.2 Components
"DevExpress 2011.2 IDETools" = DevExpress 2011.2 IDETools
"FileZilla Client" = FileZilla Client 3.5.2
"IrfanView" = IrfanView (remove only)
"Keyboard Leds" = Keyboard Leds
"Microsoft Visual Studio 2010 Professional - ENU" = Microsoft Visual Studio 2010 Professional - ENU
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"No Hands SEO Trial" = No Hands SEO Trial
"Notepad++" = Notepad++
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Opera 11.64.1403" = Opera 11.64
"Plus500" = Plus500
"PokerStars.net" = PokerStars.net
"ProInst" = Intel PROSet Wireless
"Steam App 17020" = Global Agenda
"Steam App 17570" = Pirates, Vikings, & Knights II
"Steam App 201230" = EverQuest II
"Steam App 240" = Counter-Strike: Source
"TeamViewer 7" = TeamViewer 7
"The KMPlayer" = The KMPlayer (remove only)
"T-Mobile Communication Centre" = Web'n'walk Manager
"Totalcmd" = Total Commander (Remove or Repair)
"unibetpoker (Poker)" = Unibet
"VLC media player" = VLC media player 2.0.1
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.10 beta 4 (32-bit)
"wkhtmltopdf" = wkhtmltopdf

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"518496c506da956e" = RegTool2
"fc2225d322170379" = RegTool3
"fcc0be7a0151b203" = autoReg
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.1.0.880
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 7.5.2012 14:06:00 | Computer Name = Schizi-THINK | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

[ Lenovo-Message Center Plus/Admin Events ]
Error - 7.1.2012 12:42:41 | Computer Name = Schizi-THINK | Source = Lenovo-Message Center Plus/Admin | ID = 2
Description = Odkaz na objekt není nastaven na instanci objektu. -> Exception message:
Odkaz na objekt není nastaven na instanci objektu.

[ System Events ]
Error - 15.6.2012 6:11:22 | Computer Name = Schizi-THINK | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 48. Stav interní
chyby: 552

Error - 15.6.2012 6:11:22 | Computer Name = Schizi-THINK | Source = Schannel | ID = 36882
Description = Certifikát přijatý ze vzdáleného serveru byl vydán nedůvěryhodnou
certifikační autoritou. Z tohoto důvodu nelze ověřit žádná data obsažená v daném
certifikátu. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují
certifikát serveru.

Error - 15.6.2012 7:52:54 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10009
Description =

Error - 18.6.2012 8:25:46 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10009
Description =

Error - 18.6.2012 10:31:42 | Computer Name = Schizi-THINK | Source = Schannel | ID = 36888
Description = Byla vygenerována následující výstraha o závažné chybě: 48. Stav interní
chyby: 552

Error - 18.6.2012 10:31:42 | Computer Name = Schizi-THINK | Source = Schannel | ID = 36882
Description = Certifikát přijatý ze vzdáleného serveru byl vydán nedůvěryhodnou
certifikační autoritou. Z tohoto důvodu nelze ověřit žádná data obsažená v daném
certifikátu. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují
certifikát serveru.

Error - 18.6.2012 19:10:30 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10009
Description =

Error - 18.6.2012 19:10:57 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10009
Description =

Error - 18.6.2012 19:11:07 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10009
Description =

Error - 19.6.2012 3:33:00 | Computer Name = Schizi-THINK | Source = DCOM | ID = 10010
Description =


< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#7 Příspěvek od vyosek »

:arrow: Aplikujte exeHelper by Raktor :arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENP
    IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
    IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-497964454-2871790289-1274755475-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value foundO20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O33 - MountPoints2\{2d7e0e58-fa15-11e0-ba93-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{338fd5c4-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
    O33 - MountPoints2\{338fd5d2-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
    O33 - MountPoints2\{338fd5de-b689-11e1-b82c-f0def19ab966}\Shell - "" = AutoRun
    O33 - MountPoints2\{9e5bcdc9-740b-11e1-b893-d5cd384c8a5e}\Shell - "" = AutoRun
    O33 - MountPoints2\{9e5bce53-740b-11e1-b893-d5cd384c8a5e}\Shell - "" = AutoRun
    O37 - HKLM\...com [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
    O37 - HKLM\...exe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found[2012.07.09 22:46:12 | 000,000,202 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
    [2012.07.09 22:46:06 | 000,078,848 | ---- | M] () -- C:\Windows\KMSEmulator.exe
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [14 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [14 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
    [2 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\*.tmp -> ]
    [9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\*.tmp -> ]
    [25 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\basicauthenticationsample\add0aece\69ae43ce\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\basicauthenticationsample\add0aece\69ae43ce\*.tmp -> ]
    [9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\plaintextsample\4141b946\cd3458af\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\plaintextsample\4141b946\cd3458af\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\2821fe8b\e6097dac\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\2821fe8b\e6097dac\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\d0b932ab\fb655225\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\d0b932ab\fb655225\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\*.tmp -> ]
    [6 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\11b5c4a1\628b067c\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\11b5c4a1\628b067c\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\54b9f12a\3816c6a\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\54b9f12a\3816c6a\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5bbce075\5935b9ef\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5bbce075\5935b9ef\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\*.tmp -> ]
    [5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\677aa438\48209cc7\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\677aa438\48209cc7\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\*.tmp -> ]
    [16 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\*.tmp -> ]
    [9 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a19f2af6\d2731b0c\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a19f2af6\d2731b0c\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\*.tmp -> ]
    [12 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\*.tmp -> ]
    [10 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\*.tmp -> ]
    [5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\*.tmp -> ]
    [4 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\*.tmp -> ]
    [3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\*.tmp -> ]
    [16 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\17c49e96\46692e82\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\17c49e96\46692e82\*.tmp -> ]
    [2 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\*.tmp -> ]
    [1 C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\72c99ba6\635530b5\*.tmp files -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\72c99ba6\635530b5\*.tmp -> ]
    [5 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
    [1 C:\Windows\twain_32\*.tmp files -> C:\Windows\twain_32\*.tmp -> ]
    [2012.07.10 09:09:59 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
    [2012.07.07 22:46:16 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
    [2012.07.09 22:46:12 | 000,000,202 | ---- | M] () -- C:\Windows\Tasks\AutoKMSDaily.job
    [2012.07.09 21:21:00 | 000,000,962 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    [2012.07.10 09:21:00 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    [2012.07.10 09:22:40 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000Core.job
    [2012.07.10 09:38:01 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000UA.job
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SpywareTerminatorShield"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lenovo Registration]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update"=-
    ""=-
    "PWMTRV"=-
    "SunJavaUpdateSched"=-
    
    :services
    gupdate
    gupdatem
    
    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#8 Příspěvek od schizi »

Zdravím takže obojí jsem provedl ale někde nastal asi problém... Po restartu mi žádný log nevyběhl :( (restart sem musel dát po chvíli sám, protože se neprováděl, tak jestli to není tím)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#9 Příspěvek od vyosek »

Zopakujte mazani v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#10 Příspěvek od schizi »

Log:
All processes killed
========== OTL ==========
HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKU\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ not found.
Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ not found.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clonewarsadventures.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freerealms.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\soe.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-497964454-2871790289-1274755475-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sony.com\ deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value foundO20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7e0e58-fa15-11e0-ba93-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2d7e0e58-fa15-11e0-ba93-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{338fd5c4-b689-11e1-b82c-f0def19ab966}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338fd5c4-b689-11e1-b82c-f0def19ab966}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{338fd5d2-b689-11e1-b82c-f0def19ab966}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338fd5d2-b689-11e1-b82c-f0def19ab966}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{338fd5de-b689-11e1-b82c-f0def19ab966}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{338fd5de-b689-11e1-b82c-f0def19ab966}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e5bcdc9-740b-11e1-b893-d5cd384c8a5e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e5bcdc9-740b-11e1-b893-d5cd384c8a5e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e5bce53-740b-11e1-b893-d5cd384c8a5e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e5bce53-740b-11e1-b893-d5cd384c8a5e}\ not found.
HKEY_LOCAL_MACHINE\Software\Classes\.com\shell\open\command\\|"%1" %* /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Classes\.com\\|comfile /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Classes\.exe\shell\open\command\\|"%1" %* /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
C:\Windows\KMSEmulator.exe moved successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1324.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1988.tmp\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1988.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP284C.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP52D4.tmp\Microsoft.SqlServer.RegSvrEnum.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP52D4.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6877.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8600.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8B71.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA0D2.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC419.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCDFD.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD78A.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDB16.tmp\Microsoft.SqlServer.DataStorage.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDB16.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE247.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP1B0F.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP1D41.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP2C5D.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP6B8E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP96D2.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP9E7F.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPBE2F.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPCD5C.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPD1A4.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPF0E4.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPF5DF.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPFDB7.tmp folder deleted successfully.
C:\Windows\Installer\MSIA0FB.tmp deleted successfully.
C:\Windows\Installer\MSIAEC1.tmp- folder deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\0evyv1jx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\2awcahks.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\ec6eec0a\90923b32\4bp0kqe2.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\r3ydcjy4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\towsne4e.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\ajaxcascadingdropdown\fc64f2ec\2582e039\z0ewi4o2.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\5mhpbmwo.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\ainmaddx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\jcfknqsu.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\msz15zdp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\nc115dsr.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\onmyob1g.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\sc13uuav.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\uu3scu4i.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\3e128635\f618391b\vnsiwchm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\0phmv1ek.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\1dwezawn.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\24aovakg.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\354u3djg.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\4wm10asn.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\5eatkfmo.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\aia4afv4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\cm2di03d.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\cvgeisml.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\ilrqttzo.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\isdl5mjz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\k102eewy.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\k5gybqtm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\kdcm0lzl.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\l4vcd0yq.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\lbgqlqlp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\m3tcoyh0.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\mqyvy4tk.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\nlxofojp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\nnbavkup.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\osakca4k.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\rsmrbki1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\wxwibjvd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\ygedwcda.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\apptools.cz\efa338e4\be34534d\ziqsgz0u.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\ajkh00g5.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\ljoftx4a.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\asp.netwebadminfiles\988e0dc5\b210afcc\yp42yebz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\basicauthenticationsample\add0aece\69ae43ce\l4v4bx0b.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\0s4pkjny.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\15l4w5iz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\3r4pohid.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\aji4jk0a.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\lrkcjyxm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\p12lnyvw.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\povssj2t.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\utnusvzb.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\localizationdemo\cc7300d6\55f38e94\zitmwucn.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\plaintextsample\4141b946\cd3458af\4e5rnncw.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\2821fe8b\e6097dac\hflitdi1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\q308152\d0b932ab\fb655225\0j4na4ic.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\1il0231n.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\4utr4eqt.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\063d0219\7dac7045\kgo1wia3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\ha04owhp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\smqflxf4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\tju1vkql.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\z0ocyesi.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\zmoonglq.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\0c57d040\b7ff09fc\zxxix2lj.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\11b5c4a1\628b067c\dftr5ld2.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\e3a1aho2.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\gdlqa1oz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\239fbcd6\1c7115c6\rl1rfqaz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\33025k0d.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\hwqpeyse.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\26d91c49\a1656847\vyezzzjk.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\54b9f12a\3816c6a\h1fol0lk.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5bbce075\5935b9ef\klyqoccj.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\e1eltkeu.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\fqf2tmvx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\kayx3k24.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\5c813909\841643d5\pif5k4y3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\0dn2lxin.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\dyxjjooi.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\grb2ktaa.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\wardfnao.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\621204a0\41bafef2\xr00vca1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\677aa438\48209cc7\b4ttc2np.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\lwfd2zqx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\79b1c563\442cd05e\tk2yff4q.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\a3svm53e.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\czttz5cc.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\lsdb3rg0.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\7cd230f0\5e7c4cb5\rfew0zvv.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\fe5nxb1y.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\fns04km3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\frjv0hae.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\gv2mm2il.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\iuclquun.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\jvzxbtma.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\kkxoo4dm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\kvuetqg1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\mgqbljll.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\o2dnt3qq.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\ocgzhzzm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\qbrwqnog.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\s04314dm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\uptdk5au.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\vsdx0n2s.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\8df39f90\110e6c34\xn0bgevp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\k1cgwbyd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\9072ec19\eacf59f3\o5ion5fd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\3aaupqfd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\5soqijkt.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\5xxalq3u.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\bcl2lo0c.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\dnkopym4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\hb5xzuui.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\rgw0fqob.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\uxhlodeu.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\93eb29b0\c0203c0\wd2rd0yp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\a0upi4sw.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a0a72547\28115196\rghknli4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\a19f2af6\d2731b0c\fxglxr3o.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\5oat5aqv.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\ipwusuy1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\k0vlg3so.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\b4f49ebf\a1a72ea4\o51xvprh.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\0eim2mjm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\0w4h4rc3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\5vzcpmub.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\jjxijixk.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\lrjtnzez.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\rvolwwgy.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\rwphxhvc.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\ry5ytgmo.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\t4xmdfl4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\tym4rayh.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\vpqrhgnm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3352aa5\5abf3798\wmxwnnb3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\j1vw3b5c.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\pir3ecz1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c39cd64b\1a4d3858\zyhohq5a.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\1qtovmcc.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\4ethg2vs.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\543povod.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\cbmvexc2.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\d0m1gnft.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\eauhugmf.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\hpa0dk2l.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\ido3rwrl.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\iq5nzrba.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\c3fc77ec\bb081f76\qxv2vmhi.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\3wnbjvls.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\ioilalp5.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\xnmkap0x.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\xwjf1wkb.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d4f69c2e\890c66ba\yhlroo2m.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\c1r0kzxs.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\jkkz2avm.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\d55ab3f4\ba6114e7\yxfuyxda.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\0triptgr.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e303b499\c983c656\o3yed13o.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\n5lbuqdx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\o3id04zp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\p1rfstlw.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e35e4d4a\324e069\zfdwzrlt.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\dvnmf2fs.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\flg44ale.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\jmzlkmgb.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\e575f1f6\49e66632\okdll0oa.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\21y4zoa3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\5ismjsdd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\b2faqftb.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed0ec2d7\561ab6e0\dyrp1yxp.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\a3coxyx4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\euwmbimj.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\ed585ac5\47cc74a5\fszhogpd.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\03yp5hkw.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\edbeb5bd\53b3f788\1cpijcys.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\5mqgu0j0.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\cmudjinz.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\h2qcgxg4.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\hijvx1yx.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\hluu4iis.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\mssdbwd1.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\mvjbsqp5.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\mzk3dspj.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\ol3ghuwu.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\oobe5swi.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\pcia54iy.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\qikatblh.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\rpgunnql.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\rpye2luf.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\yxk2mhjk.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\fd10daf8\56e7c416\z2jzifze.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\bo3xldnv.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\simplesqlsample\f3e13be5\85d30999\c5b5pxza.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\17c49e96\46692e82\q10d0fwh.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\qpkkbml3.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\5528aafd\813e6b80\xahmjwok.tmp deleted successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\tableprovidersample\72c99ba6\635530b5\ntizscdo.tmp deleted successfully.
C:\Windows\Temp\~13FD.tmp deleted successfully.
C:\Windows\Temp\~2FA8.tmp deleted successfully.
C:\Windows\Temp\~37E2.tmp deleted successfully.
C:\Windows\Temp\~55CE.tmp deleted successfully.
C:\Windows\Temp\~8823.tmp deleted successfully.
C:\Windows\Temp\~9F4B.tmp deleted successfully.
C:\Windows\twain_32\hpqgnds2.tmp deleted successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\Tasks\AutoKMS.job moved successfully.
C:\Windows\Tasks\AutoKMSDaily.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000Core.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497964454-2871790289-1274755475-1000UA.job moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorShield not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lenovo Registration\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\PWMTRV deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named gupdate was found to stop!
Service\Driver key gupdate not found.
Error: No service named gupdatem was found to stop!
Service\Driver key gupdatem not found.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: regTool
->Temp folder emptied: 43057 bytes
->Temporary Internet Files folder emptied: 78396 bytes
->Opera cache emptied: 4502075 bytes
->Flash cache emptied: 456 bytes

User: Schizi
->Temp folder emptied: 1654144762 bytes
->Temporary Internet Files folder emptied: 617136488 bytes
->Java cache emptied: 11081444 bytes
->FireFox cache emptied: 48787975 bytes
->Google Chrome cache emptied: 42510528 bytes
->Opera cache emptied: 37121379 bytes
->Flash cache emptied: 28818 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 55636475 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50641 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2 357,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: regTool
->Flash cache emptied: 0 bytes

User: Schizi
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.53.1 log created on 07102012_233827

Files\Folders moved on Reboot...
C:\Users\Schizi\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...
File C:\Users\Schizi\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#11 Příspěvek od vyosek »

Nastala nejaka zmena v chovani ntb :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#12 Příspěvek od schizi »

Prijde mi to stejne, cekam na zacatku nekolik minut nez vse nabehne... Pak uz jede ok, ale porste ten start je divnej a zdlouhavej.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#13 Příspěvek od vyosek »

:arrow: Nemate na plose nejake velke soubory (fotky, filmy apod.)? Na plose by mely byt defakto jen zastupci

:arrow: Stahnete SytemLook http://jpshortstuff.247fixes.com/SystemLook.exe a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :dir
    %userprofile%\desktop /sub
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

schizi
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 zář 2007 13:20

Re: ntb - pro vyosek

#14 Příspěvek od schizi »

Ta plocha mne nenapadla, mel jsem tam neco kolem 600mb, takze jsem to vse presunul a natavil zastupce. Udelal restart ale stejne to nabiha hrozne dlouho, trochu se obavam ze to bude proste temi aplikacemi co ma lenovo :(

Log:
SystemLook 30.07.11 by jpshortstuff
Log created at 00:16 on 11/07/2012 by Schizi
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== dir ==========

C:\Users\Schizi\desktop - Parameters: "/sub"

---Files---
.docstates.suo ---h--- 262 bytes [13:53 03/01/2012] [13:53 03/01/2012]
002-IREP- 03 vyhledavani nabidky seznam dum.jpg --a---- 1092830 bytes [12:36 26/06/2012] [12:37 26/06/2012]
002-IREP- 04 vyhledavani nabidky seznam dum.jpg --a---- 1096080 bytes [12:54 26/06/2012] [12:54 26/06/2012]
ClubRadio.m3u --a---- 44 bytes [17:54 21/11/2011] [09:02 13/09/2010]
ColorCop.exe --a---- 97792 bytes [17:54 21/11/2011] [23:08 23/10/2007]
desktop.ini --ahs-- 282 bytes [11:13 21/11/2011] [20:06 17/02/2012]
Dust.lnk --a---- 667 bytes [11:56 26/03/2012] [11:56 26/03/2012]
exeHelper.com --a---- 294400 bytes [20:39 10/07/2012] [20:39 10/07/2012]
exehelperlog.txt --a---- 414 bytes [20:40 10/07/2012] [20:40 10/07/2012]
lilan.lnk --a---- 773 bytes [22:13 10/07/2012] [22:13 10/07/2012]
LilanWifiIp.png --a---- 12635 bytes [08:23 07/05/2012] [08:23 07/05/2012]
NorthMusic.asx --a---- 190 bytes [17:54 21/11/2011] [11:57 19/12/2010]
OTL.exe --a---- 595968 bytes [07:16 10/07/2012] [07:16 10/07/2012]
Projekt 12.02.xlsx --a---- 15317 bytes [13:30 28/06/2012] [10:02 08/07/2012]
rk_lilan_prace.xlsx --a---- 19036 bytes [13:36 03/01/2012] [08:09 09/07/2012]
RSITx64.exe --a---- 935175 bytes [19:20 09/07/2012] [19:20 09/07/2012]
SystemLook.exe --a---- 139264 bytes [22:16 10/07/2012] [22:16 10/07/2012]
SystemLook.txt --a---- 0 bytes [22:16 10/07/2012] [22:16 10/07/2012]
VPS Lilan.RDP --a---- 2094 bytes [07:57 30/03/2012] [07:57 30/03/2012]
VPS moje.RDP --a---- 2042 bytes [22:30 28/12/2011] [22:30 28/12/2011]
~$polozky RS - prodej-pronájem.xlsx --ah--- 165 bytes [09:40 03/02/2012] [09:40 03/02/2012]

No folders found.

-= EOF =-

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: ntb - pro vyosek

#15 Příspěvek od vyosek »

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Dejte novy RSIT, mrknem na ty aplikace, ale tohle by nemely delat
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět