[code] OTS logfile created on: 2012-07-12 23:24:33 - Run 3 OTS by OldTimer - Version 3.1.47.2 Folder = H:\log\log2 Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 68,00% Memory free 6,00 Gb Paging File | 6,00 Gb Available in Paging File | 95,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 144,09 Gb Total Space | 8,82 Gb Free Space | 6,12% Space Free | Partition Type: NTFS Drive D: | 144,00 Gb Total Space | 8,10 Gb Free Space | 5,62% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded Drive H: | 15,30 Gb Total Space | 14,78 Gb Free Space | 96,59% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: PIOTREK Current User Name: EuroRtvAgd Logged in as Administrator. Current Boot Mode: SafeMode Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days [Processes - Safe List] ots.exe -> H:\log\log2\OTS.exe -> [2012-07-12 08:48:46 | 000,646,656 | ---- | M] (OldTimer Tools) explorer.exe -> C:\Windows\explorer.exe -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) helppane.exe -> C:\Windows\HelpPane.exe -> [2008-01-21 04:24:02 | 000,498,176 | ---- | M] (Microsoft Corporation) [Modules - No Company Name] shellext.dll -> C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll -> [2011-06-20 22:32:10 | 000,090,592 | ---- | M] () [Win32 Services - Safe List] (SAS [Config-Lev1] Deployment Tester Server) SAS [Config-Lev1] Deployment Tester Server [Auto | Stopped] -> -> File not found (vToolbarUpdater11.2.0) vToolbarUpdater11.2.0 [Auto | Stopped] -> C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -> [2012-07-09 21:52:20 | 000,935,008 | ---- | M] () (MozillaMaintenance) Mozilla Maintenance Service [On_Demand | Stopped] -> C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -> [2012-07-07 21:00:57 | 000,113,120 | ---- | M] (Mozilla Foundation) (AVGIDSAgent) AVGIDSAgent [Auto | Stopped] -> C:\Program Files\AVG\AVG2012\avgidsagent.exe -> [2012-07-04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) (avgwd) AVG WatchDog [Auto | Stopped] -> C:\Program Files\AVG\AVG2012\avgwdsvc.exe -> [2012-02-14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) (AVG Security Toolbar Service) AVG Security Toolbar Service [On_Demand | Stopped] -> C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -> [2011-11-10 15:17:31 | 000,167,264 | ---- | M] () (Lavasoft Ad-Aware Service) Lavasoft Ad-Aware Service [On_Demand | Stopped] -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2011-06-20 22:32:05 | 001,036,104 | ---- | M] (Lavasoft) (NIHardwareService) NIHardwareService [Auto | Stopped] -> C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe -> [2011-04-07 17:33:31 | 003,857,408 | ---- | M] (Native Instruments GmbH) (SAS [Config-Lev1] Object Spawner) SAS [Config-Lev1] Object Spawner [Auto | Stopped] -> D:\SAS\SASFoundation\9.2\objspawn.exe -> [2010-03-25 07:25:04 | 000,300,312 | ---- | M] () (SAS [Config-Lev1] SASMeta - Metadata Server) SAS [Config-Lev1] SASMeta - Metadata Server [Auto | Stopped] -> D:\SAS\SASFoundation\9.2\sas.exe -> [2010-03-25 07:10:58 | 000,140,568 | ---- | M] () (SAS [Config-Lev1] SASApp - OLAP Server) SAS [Config-Lev1] SASApp - OLAP Server [Auto | Stopped] -> D:\SAS\SASFoundation\9.2\sas.exe -> [2010-03-25 07:10:58 | 000,140,568 | ---- | M] () (BcmSqlStartupSvc) Usługa startowa serwera SQL dodatku Business Contact Manager [Auto | Stopped] -> C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -> [2009-02-25 10:28:20 | 000,030,312 | ---- | M] (Microsoft Corporation) (EvtEng) Intel® PROSet/Wireless Event Log [Auto | Stopped] -> C:\Program Files\Intel\WiFi\bin\EvtEng.exe -> [2008-05-23 07:11:56 | 000,819,200 | ---- | M] (Intel(R) Corporation) (RegSrvc) Intel® PROSet/Wireless Registry Service [Auto | Stopped] -> C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -> [2008-05-23 06:43:52 | 000,466,944 | ---- | M] (Intel(R) Corporation) (Samsung Update Plus) Samsung Update Plus [Auto | Stopped] -> C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -> [2008-05-13 01:47:20 | 000,077,480 | ---- | M] () (WinDefend) Windows Defender [Auto | Stopped] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) (SAS [Config-Lev1] Analytics Platform Server) SAS [Config-Lev1] Analytics Platform Server [Auto | Stopped] -> D:\SAS\SASAnalyticsPlatform\1.5\wrapper.exe -> [2006-10-18 05:22:50 | 000,204,800 | ---- | M] () (AgereModemAudio) Agere Modem Call Progress Audio [Auto | Stopped] -> C:\Windows\System32\agrsmsvc.exe -> [2006-10-05 06:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Driver Services - Safe List] (AVGIDSHX) AVGIDSHX [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\avgidshx.sys -> [2012-04-19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) (Avgtdix) AVG TDI Driver [Kernel | System | Stopped] -> C:\Windows\System32\drivers\avgtdix.sys -> [2012-03-19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) (Avgldx86) AVG AVI Loader Driver [Kernel | System | Stopped] -> C:\Windows\System32\drivers\avgldx86.sys -> [2012-02-22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) (Avgrkx86) AVG Anti-Rootkit Driver [File_System | Boot | Running] -> C:\Windows\system32\DRIVERS\avgrkx86.sys -> [2012-01-31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) (Avgmfx86) AVG Mini-Filter Resident Anti-Virus Shield [File_System | System | Stopped] -> C:\Windows\System32\drivers\avgmfx86.sys -> [2011-12-23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) (AVGIDSShim) AVGIDSShim [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\avgidsshimx.sys -> [2011-12-23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) (AVGIDSFilter) AVGIDSFilter [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\avgidsfilterx.sys -> [2011-12-23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) (AVGIDSDriver) AVGIDSDriver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\avgidsdriverx.sys -> [2011-12-23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) (cpuz135) cpuz135 [Kernel | Auto | Stopped] -> C:\Windows\System32\drivers\cpuz135_x32.sys -> [2011-09-21 10:25:34 | 000,021,992 | ---- | M] (CPUID) (Lbd) Lbd [File_System | Boot | Running] -> C:\Windows\system32\DRIVERS\Lbd.sys -> [2009-05-04 22:36:52 | 000,064,160 | ---- | M] (Lavasoft AB) (hamachi) Hamachi Network Interface [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\hamachi.sys -> [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) (nvlddmkm) nvlddmkm [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\nvlddmkm.sys -> [2008-12-02 12:11:00 | 007,643,904 | ---- | M] (NVIDIA Corporation) (NETw5v32) Sterownik karty Intel(R) Wireless WiFi Link dla systemu Windows Vista 32 Bit [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\NETw5v32.sys -> [2008-05-20 21:36:12 | 003,663,360 | ---- | M] (Intel Corporation) (VMC302) Vimicro Camera Service VMC302 [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\vmc302.sys -> [2008-04-05 07:56:26 | 000,242,560 | ---- | M] (Vimicro Corporation) (NETw3v32) Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\NETw3v32.sys -> [2008-01-21 04:23:20 | 002,225,664 | ---- | M] (Intel Corporation) (athr) Atheros Extensible Wireless LAN device driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\athr.sys -> [2007-09-13 08:17:58 | 000,755,712 | ---- | M] (Atheros Communications, Inc.) (KMDFMEMIO) SAMSUNG Kernel Driver [Kernel | Auto | Stopped] -> C:\Windows\System32\drivers\KMDFMEMIO.sys -> [2007-05-23 10:13:10 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) (AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\AGRSM.sys -> [2006-11-28 09:11:00 | 001,161,888 | ---- | M] (Agere Systems) (bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\bcm4sbxp.sys -> [2006-11-02 09:30:53 | 000,045,056 | ---- | M] (Broadcom Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http:\\www.samsungcomputer.com -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: URLSearchHooks\\"{A3BC75A2-1F87-4686-AA43-5347D756017C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: URLSearchHooks\\"{A3BC75A2-1F87-4686-AA43-5347D756017C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: Main\\"Default_Page_URL" -> http:\\www.samsungcomputer.com -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: Main\\"Disable Script Debugger Default" -> yes -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: Main\\"DisableScriptDebuggerIE Default" -> -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: Main\\"Start Page" -> http:\\www.samsungcomputer.com -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: Main\\"StartPageCache" -> 1 -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: URLSearchHooks\\"{A3BC75A2-1F87-4686-AA43-5347D756017C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\: "ProxyEnable" -> 0 -> < FireFox Settings [Prefs.js] > -> C:\Users\EuroRtvAgd\AppData\Roaming\Mozilla\FireFox\Profiles\3sx49suo.default\prefs.js -> browser.search.defaultenginename -> "AVG Secure Search" -> browser.search.selectedEngine -> "Google" -> browser.startup.homepage -> "google.pl" -> extensions.enabledItems -> {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 -> extensions.enabledItems -> {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423 -> extensions.enabledItems -> {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}:5.0.15 -> extensions.enabledItems -> {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}:5.0.12 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31 -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\Extensions -> -> HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2] -> [2009-02-12 21:07:16 | 000,000,000 | ---D | M] HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4} -> C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4\ [C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4\] -> [2012-07-06 10:43:03 | 000,000,000 | ---D | M] HKLM\software\mozilla\Firefox\Extensions\\avg@toolbar -> C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\ [C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\] -> [2012-07-09 21:53:36 | 000,000,000 | ---D | M] HKLM\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF} -> C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK\ [C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK\] -> [2012-07-03 12:01:36 | 000,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 14.0\extensions -> -> HKLM\software\mozilla\Mozilla Firefox 14.0\extensions\\Components -> C:\Program Files\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2012-07-07 21:00:57 | 000,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS -> < FireFox Extensions [User Folders] > -> -> C:\Users\EuroRtvAgd\AppData\Roaming\mozilla\Extensions -> [2009-02-09 21:06:55 | 000,000,000 | ---D | M] -> C:\Users\EuroRtvAgd\AppData\Roaming\mozilla\Firefox\Profiles\3sx49suo.default\extensions -> [2012-07-04 15:49:42 | 000,000,000 | ---D | M] < FireFox Extensions [Program Folders] > -> -> C:\Program Files\Mozilla Firefox\extensions -> [2012-05-01 10:23:51 | 000,000,000 | ---D | M] -> C:\Program Files\Mozilla Firefox\distribution\extensions -> [2012-07-07 21:00:57 | 000,000,000 | ---D | M] AVG Do Not Track -> C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK -> [2012-07-03 12:01:36 | 000,000,000 | ---D | M] No name found -> C:\USERS\EURORTVAGD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3SX49SUO.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI -> () < HOSTS File > ([2006-09-18 23:41:30 | 000,000,761 | ---- | M] - 20 lines) -> C:\Windows\System32\drivers\etc\hosts -> Reset Hosts 127.0.0.1 localhost ::1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006-10-23 00:08:00 | 000,062,080 | ---- | M] (Adobe Systems Incorporated) {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} [HKLM] -> C:\Program Files\AVG\AVG2012\avgdtiex.dll [AVG Do Not Track] -> [2012-06-13 03:47:44 | 000,937,592 | ---- | M] (AVG Technologies CZ, s.r.o.) {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG2012\avgssie.dll [AVG Safe Search] -> [2012-06-24 04:12:06 | 001,417,336 | ---- | M] (AVG Technologies CZ, s.r.o.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2012-04-18 00:52:18 | 000,325,408 | ---- | M] (Sun Microsystems, Inc.) {95B7759C-8C7F-4BF1-B163-73684A933233} [HKLM] -> C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll [AVG Security Toolbar] -> [2012-07-09 21:52:15 | 002,074,208 | ---- | M] () {B4F3A835-0E21-4959-BA22-42B3008E02FF} [HKLM] -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [Office Document Cache Handler] -> [2010-12-21 02:05:22 | 000,561,552 | ---- | M] (Microsoft Corporation) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{95B7759C-8C7F-4BF1-B163-73684A933233}" [HKLM] -> C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll [AVG Security Toolbar] -> [2012-07-09 21:52:15 | 002,074,208 | ---- | M] () "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.] -> File not found < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AVG_TRAY" -> C:\Program Files\AVG\AVG2012\avgtray.exe ["C:\Program Files\AVG\AVG2012\avgtray.exe"] -> [2012-04-05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) "LanguageShortcut" -> C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ["C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"] -> [2007-01-08 15:17:42 | 000,052,256 | ---- | M] () "NvCplDaemon" -> C:\Windows\System32\NvCpl.dll [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2008-12-02 12:11:00 | 013,683,232 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> C:\Windows\System32\NvMcTray.dll [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2008-12-02 12:11:00 | 000,092,704 | ---- | M] (NVIDIA Corporation) "ROC_roc_dec12" -> C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ["C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12] -> [2012-01-15 14:07:13 | 000,928,096 | ---- | M] () "RtHDVCpl" -> C:\Windows\RtHDVCpl.exe [RtHDVCpl.exe] -> [2008-04-17 04:50:00 | 006,111,232 | ---- | M] (Realtek Semiconductor) "vProt" -> C:\Program Files\AVG Secure Search\vprot.exe ["C:\Program Files\AVG Secure Search\vprot.exe"] -> [2012-07-09 21:52:16 | 001,107,552 | ---- | M] () "Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008-01-21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) < RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "AutoLaunch" -> C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe [C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly] -> [2011-06-20 22:32:08 | 000,669,936 | ---- | M] () < RunOnce [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "AutoLaunch" -> C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe [C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly] -> [2011-06-20 22:32:08 | 000,669,936 | ---- | M] () < Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008-01-21 04:23:39 | 002,153,472 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008-01-21 04:23:39 | 002,153,472 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "SmiEngine" -> C:\Users\EuroRtvAgd\AppData\Local\Microsoft\Windows\2680\SmiEngine.exe [C:\Users\EuroRtvAgd\AppData\Local\Microsoft\Windows\2680\SmiEngine.exe] -> [2012-07-11 23:13:23 | 000,051,200 | ---- | M] () < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksport do programu Microsoft Excel -> C:\Program Files\MSoffice\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MSoffice\OFFICE11\EXCEL.EXE/3000] -> [2012-03-21 12:28:22 | 010,359,568 | ---- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksport do programu Microsoft Excel -> C:\Program Files\MSoffice\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MSoffice\OFFICE11\EXCEL.EXE/3000] -> [2012-03-21 12:28:22 | 010,359,568 | ---- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksport do programu Microsoft Excel -> C:\Program Files\MSoffice\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MSoffice\OFFICE11\EXCEL.EXE/3000] -> [2012-03-21 12:28:22 | 010,359,568 | ---- | M] (Microsoft Corporation) E&ksportuj do programu Microsoft Excel -> C:\Program Files\Microsoft Office\Office14\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000] -> [2012-03-15 18:07:54 | 020,774,680 | ---- | M] (Microsoft Corporation) Wyślij &do programu OneNote -> C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105] -> [2012-01-18 06:23:24 | 000,645,456 | ---- | M] (Microsoft Corporation) Wyślij obraz do urządzenia &Bluetooth... -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm [C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm] -> [2007-01-23 04:57:50 | 000,001,199 | ---- | M] () Wyślij stronę do urządzenia &Bluetooth... -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm] -> [2007-01-23 04:57:52 | 000,002,758 | ---- | M] () < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [Button: Wyślij do programu OneNote] -> [2012-01-18 06:23:24 | 000,645,456 | ---- | M] (Microsoft Corporation) {2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [Menu: Wyślij &do programu OneNote] -> [2012-01-18 06:23:24 | 000,645,456 | ---- | M] (Microsoft Corporation) {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16}:{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} [HKLM] -> C:\Program Files\AVG\AVG2012\avgdtiex.dll [Button: AVG Do Not Track] -> [2012-06-13 03:47:44 | 000,937,592 | ---- | M] (AVG Technologies CZ, s.r.o.) {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}:{FFFDC614-B694-4AE6-AB38-5D6374584B52} [HKLM] -> C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [Button: &Notatki połączone programu OneNote] -> [2010-12-21 04:08:16 | 000,497,040 | ---- | M] (Microsoft Corporation) {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}:{FFFDC614-B694-4AE6-AB38-5D6374584B52} [HKLM] -> C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [Menu: &Notatki połączone programu OneNote] -> [2010-12-21 04:08:16 | 000,497,040 | ---- | M] (Microsoft Corporation) {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\REFIEBAR.DLL [Button: Badanie] -> [2007-04-19 14:10:18 | 000,063,840 | ---- | M] (Microsoft Corporation) {CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [HKLM] -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [Button: @btrez.dll,-4015] -> [2007-01-23 04:57:52 | 000,002,758 | ---- | M] () {CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [HKLM] -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [Menu: @btrez.dll,-12650] -> [2007-01-23 04:57:52 | 000,002,758 | ---- | M] () < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> [@btrez.dll,-4015] -> File not found < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] -> {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab [Java Plug-in 1.5.0_12] -> {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab [Java Plug-in 1.5.0_15] -> {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> DhcpNameServer -> 192.168.1.254 -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {A5F4F00F-E95A-49A7-B100-E7A23C0C20D7}\\DhcpNameServer -> 192.168.1.254 (Atheros AR5007EG Wireless Network Adapter) -> {A5F4F00F-E95A-49A7-B100-E7A23C0C20D7}\\NameServer -> 194.204.152.34,192.168.1.254 (Atheros AR5007EG Wireless Network Adapter) -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> explorer.exe -> C:\Windows\explorer.exe -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit -> C:\Windows\system32\userinit.exe -> C:\Windows\System32\userinit.exe -> [2008-01-21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> Sterownik stacji dysków CD-ROM -> "ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found < Drives with AutoRun files > -> -> C:\autoexec.bat [REM Dummy file for NTVDM | ] -> C:\autoexec.bat [ NTFS ] -> [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{5cb556d1-9b42-11e1-a54f-00211930dbaf} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5cb556d1-9b42-11e1-a54f-00211930dbaf}\shell \{5cb556d1-9b42-11e1-a54f-00211930dbaf}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5cb556d1-9b42-11e1-a54f-00211930dbaf}\shell\AutoRun\command \{5cb556d1-9b42-11e1-a54f-00211930dbaf}\shell\AutoRun\command\\"" -> [G:\setup.exe] -> File not found < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> comfile [open] -> "%1" %* -> exefile [open] -> "%1" %* -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .com [@ = comfile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> [Registry - Additional Scans - Safe List] < ActiveX StubPath [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608500} [KeyFileName] -> C:\Program Files\Java\jre6\bin\regutils.dll [(default): Java (Sun); IsInstalled: 1] -> [2012-03-21 09:43:10 | 000,278,528 | ---- | M] (Sun Microsystems, Inc.) {10880D85-AAD9-4558-ABDC-2AB1552D831F} [StubPath] -> "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" [(default): LightScribe Control Panel] -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {2C7339CF-2B09-4501-B3F3-F3508C9228ED} [StubPath] -> %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [(default): Themes Setup; IsInstalled: 1] -> {3af36230-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Offline Browsing Pack; IsInstalled: 1] -> File not found {3C3901C5-3455-3E0A-A214-0B093A5070A6} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {44BBA840-CC51-11CF-AAFA-00AA00B6015C} [StubPath] -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [(default): Microsoft Windows Mail 7; IsInstalled: 1] -> {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA855-CC51-11CF-AAFA-00AA00B6015F} [HKLM] -> Reg Error: Key error. [(default): DirectDrawEx; IsInstalled: 1] -> File not found {45ea75a0-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Help; IsInstalled: 1] -> File not found {4f645220-306d-11d2-995d-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Microsoft Windows Script 5.7; IsInstalled: 1] -> File not found {5fd399c0-a70a-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Setup Tools; IsInstalled: 1] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [StubPath] -> %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI [(default): Microsoft Windows Media Player; IsInstalled: 1] -> {6fab99d0-bab8-11d1-994a-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): MSN Site Access; IsInstalled: 1] -> File not found {73FA19D0-2D75-11D2-995D-00C04F98BBC9} [StubPath] -> [(default): Foldery w sieci Web; IsInstalled: 1] -> {743F1D23-A520-44EE-BEF5-6D7474AF898E} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {7790769C-0471-11d2-AF11-00C04FA35D02} [HKLM] -> Reg Error: Key error. [(default): Address Book 7; IsInstalled: 1] -> File not found {7C028AF8-F614-47B3-82DA-BA94E41B1089} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4340} [StubPath] -> regsvr32.exe /s /n /i:U shell32.dll [(default): Windows Desktop Update; IsInstalled: 1] -> {89820200-ECBD-11cf-8B85-00AA005B4383} [StubPath] -> C:\Windows\system32\ie4uinit.exe -BaseSettings [(default): Internet Explorer; IsInstalled: 1] -> {89B4C1CD-B018-4511-B0A1-5476DBF70820} [StubPath] -> C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install [ComponentID: DOTNETFRAMEWORKS; IsInstalled: 1] -> {9381D8F2-0288-11D0-9501-00AA00B911A5} [HKLM] -> Reg Error: Key error. [(default): Dynamic HTML Data Binding; IsInstalled: 1] -> File not found {C9E9A340-D1F1-11D0-821E-444553540600} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Core Fonts; IsInstalled: 1] -> File not found {CDD7975E-60F8-41d5-8149-19E51D6F71D0} [HKLM] -> Reg Error: Key error. [ComponentID: Windows Movie Maker v2.1; IsInstalled: 1] -> File not found {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> C:\Windows\System32\Macromed\Flash\Flash10b.ocx [(default): Adobe Flash Player; IsInstalled: 01 00 00 00 [binary data]] -> [2009-02-03 04:07:18 | 003,866,528 | R--- | M] (Adobe Systems, Inc.) {de5aed00-a4bf-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): HTML Help; IsInstalled: 1] -> File not found {E92B03AB-B707-11d2-9CBD-0000F87A369E} [HKLM] -> Reg Error: Key error. [(default): Active Directory Service Interface; IsInstalled: 1] -> File not found >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} [StubPath] -> C:\Windows\system32\unregmp2.exe /ShowWMP [(default): Microsoft Windows Media Player; IsInstalled: 0] -> >{26923b43-4d38-484f-9b9e-de460746276c} [StubPath] -> C:\Windows\system32\ie4uinit.exe -UserIconConfig [(default): Internet Explorer; IsInstalled: 1] -> >{60B49E34-C7CC-11D0-8953-00A0C90347FF} [StubPath] -> RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP [(default): Browser Customizations; IsInstalled: 1] -> < ActiveX StubPath [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found < ActiveX StubPath [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found < ActiveX StubPath [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {10880D85-AAD9-4558-ABDC-2AB1552D831F} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {2C7339CF-2B09-4501-B3F3-F3508C9228ED} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA840-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {73FA19D0-2D75-11D2-995D-00C04F98BBC9} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4340} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4383} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {89B4C1CD-B018-4511-B0A1-5476DBF70820} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found >{26923b43-4d38-484f-9b9e-de460746276c} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found >{60B49E34-C7CC-11D0-8953-00A0C90347FF} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found < App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ -> AcroRd32.exe -> C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe [C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe] -> [2007-05-11 04:06:00 | 000,341,616 | ---- | M] (Adobe Systems Incorporated) AVGSE.DLL -> C:\Program Files\AVG\AVG2012\avgse.dll [C:\PROGRA~1\AVG\AVG2012\avgse.dll] -> [2012-02-14 04:53:00 | 000,158,560 | ---- | M] (AVG Technologies CZ, s.r.o.) cmmgr32.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found DVD Solution -> C:\Program Files\CyberLink\CDS\CDSVersion.exe [C:\Program Files\CyberLink\CDS\CDSVersion.exe] -> [2006-11-29 16:10:44 | 000,020,480 | ---- | M] () dvdmaker.exe -> C:\Program Files\Movie Maker\DVDMaker.exe [%ProgramFiles%\Movie Maker\dvdmaker.exe] -> [2008-01-21 04:25:24 | 001,963,008 | ---- | M] (Microsoft Corporation) EasyBatteryMgr3.exe -> [] -> File not found EasySpeedUpManager.exe -> C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager] -> [2008-04-25 14:31:34 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) excel.exe -> C:\Program Files\MSoffice\OFFICE11\EXCEL.EXE [C:\PROGRA~1\MSoffice\OFFICE11\EXCEL.EXE] -> [2012-03-21 12:28:22 | 010,359,568 | ---- | M] (Microsoft Corporation) F: -> Reg Error: Value error. [Reg Error: Value error.] -> File not found firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe] -> [2012-07-07 21:00:57 | 000,913,888 | ---- | M] (Mozilla Corporation) FL.exe -> C:\Program Files\Image-Line\FL Studio 9\FL.exe [C:\Program Files\Image-Line\FL Studio 9\FL.exe] -> [2009-07-25 18:22:36 | 000,376,320 | ---- | M] (Image-Line) fsquirt.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found gimp-2.6.exe -> C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe [C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe] -> [2009-02-15 22:52:34 | 004,603,960 | ---- | M] () HpqApKil.exe -> C:\Program Files\HP\Digital Imaging\bin\HpqApKil.exe [C:\Program Files\HP\Digital Imaging\bin\HpqApKil.exe] -> [2008-03-25 05:03:24 | 000,017,408 | ---- | M] (Hewlett-Packard) HpqPSApl.exe -> C:\Program Files\HP\Digital Imaging\bin\HpqPSApl.exe [C:\Program Files\HP\Digital Imaging\bin\HpqPSApl.exe] -> [2008-03-20 10:36:40 | 000,080,288 | ---- | M] (Hewlett-Packard) hpqpsapp.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe [C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe] -> [2008-03-20 10:36:38 | 003,782,048 | ---- | M] (Hewlett-Packard Development Co. L.P.) hpqpse.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe [C:\Program Files\HP\Digital Imaging\Bin\hpqpse.exe] -> [2008-03-13 10:34:26 | 000,087,456 | ---- | M] (Hewlett-Packard Development Co. L.P.) hpqqpawp.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqqpawp.exe [C:\Program Files\HP\Digital Imaging\Bin\hpqqpawp.exe] -> [2007-09-13 16:38:46 | 000,348,160 | ---- | M] (Hewlett-Packard Development Co. L.P.) hpqSSupply.exe -> C:\Program Files\HP\HPSSUPPLY\hpqSSupply.exe [C:\Program Files\HP\HPSSUPPLY\hpqSSupply.exe] -> [2008-03-26 00:57:00 | 000,417,792 | ---- | M] (Hewlett-Packard Development Company L.P.) Hpqsudi.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe [C:\Program Files\HP\Digital Imaging\Bin\hpqsudi.exe] -> [2008-03-20 10:36:40 | 000,135,168 | ---- | M] (Hewlett-Packard Development Co. L.P.) HpqTrMgr.exe -> C:\Program Files\HP\Digital Imaging\bin\HpqTrMgr.exe [C:\Program Files\HP\Digital Imaging\bin\HpqTrMgr.exe] -> [2007-09-13 16:38:48 | 000,163,840 | ---- | M] (Hewlett-Packard) infopath.exe -> C:\Program Files\MSoffice\OFFICE11\INFOPATH.EXE [C:\Program Files\MSoffice\OFFICE11\INFOPATH.EXE] -> [2008-08-18 17:51:58 | 007,088,648 | ---- | M] (Microsoft Corporation) inkball.exe -> C:\Program Files\Microsoft Games\inkball\inkball.exe [%ProgramFiles%\Microsoft Games\inkball\inkball.exe] -> [2008-01-21 04:25:29 | 001,254,400 | ---- | M] (Microsoft Corporation) install.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found javaws.exe -> C:\Program Files\Java\jre6\bin\javaws.exe [C:\Program Files\Java\jre6\bin\javaws.exe] -> [2012-04-18 00:52:18 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) LabelPrint.exe -> C:\Program Files\CyberLink\LabelPrint\LabelPrint.exe [C:\Program Files\CyberLink\LabelPrint\LabelPrint.exe] -> [2007-12-06 03:56:42 | 000,603,432 | ---- | M] (CyberLink Corp.) MagicDoctor.exe -> C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctor.exe [C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctor.exe] -> [2008-05-09 09:00:54 | 008,433,320 | ---- | M] (Samsung Electronics) moviemk.exe -> C:\Program Files\Movie Maker\MOVIEMK.exe [%ProgramFiles%\Movie Maker\moviemk.exe] -> [2010-06-17 17:49:15 | 000,150,016 | ---- | M] (Microsoft Corporation) MSACCESS.EXE -> C:\Program Files\MSoffice\OFFICE11\MSACCESS.EXE [C:\PROGRA~1\MSoffice\OFFICE11\MSACCESS.EXE] -> [2010-01-14 17:53:24 | 006,700,888 | ---- | M] (Microsoft Corporation) msimn.exe -> C:\Program Files\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-21 04:23:32 | 000,397,312 | ---- | M] (Microsoft Corporation) MsoHtmEd.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found MSPUB.EXE -> C:\Program Files\MSoffice\OFFICE11\MSPUB.EXE [C:\PROGRA~1\MSoffice\OFFICE11\MSPUB.EXE] -> [2011-10-26 16:18:08 | 006,644,048 | ---- | M] (Microsoft Corporation) Myth3.exe -> C:\Program Files\MumboJumbo\Myth III - The Wolf Age\Myth3.exe [C:\Program Files\MumboJumbo\Myth III - The Wolf Age\Myth3.exe] -> [2001-10-15 23:53:08 | 002,592,768 | ---- | M] (Mumbo Jumbo Games LLC) ois.exe -> C:\Program Files\MSoffice\OFFICE11\OIS.EXE [C:\PROGRA~1\MSoffice\OFFICE11\OIS.EXE] -> [2007-03-22 19:06:22 | 000,287,576 | ---- | M] (Microsoft Corporation) OneNote.exe -> C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE [C:\PROGRA~1\MICROS~2\Office14\ONENOTE.EXE] -> [2012-03-15 18:02:26 | 001,699,104 | ---- | M] (Microsoft Corporation) OUTLOOK.EXE -> C:\Program Files\MSoffice\OFFICE11\OUTLOOK.EXE [C:\PROGRA~1\MSoffice\OFFICE11\OUTLOOK.EXE] -> [2010-06-23 17:17:12 | 000,196,440 | ---- | M] (Microsoft Corporation) pbrush.exe -> C:\Windows\System32\mspaint.exe [%SystemRoot%\System32\mspaint.exe] -> [2008-01-21 04:24:56 | 000,485,376 | ---- | M] (Microsoft Corporation) Power2GO.exe -> C:\Program Files\CyberLink\Power2Go\Power2Go.exe [C:\Program Files\CyberLink\Power2Go\Power2Go.exe] -> [2008-02-25 08:41:56 | 002,200,872 | ---- | M] (Cyberlink) Power2GoExpress.exe -> C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe [C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe] -> [2008-02-25 08:34:04 | 002,512,168 | ---- | M] (Cyberlink) PowerBar -> [] -> File not found PowerDirector -> C:\Program Files\CyberLink\PowerDirector\PDR.exe [C:\Program Files\CyberLink\PowerDirector\PDR.exe] -> [2008-03-27 06:49:42 | 004,220,200 | ---- | M] (CyberLink Corp.) PowerDVD -> C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe [C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe] -> [2008-01-30 13:25:34 | 000,976,168 | ---- | M] (CyberLink Corp.) PowerDVD.exe -> C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe [C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe] -> [2008-01-30 13:25:34 | 000,976,168 | ---- | M] (CyberLink Corp.) powerpnt.exe -> C:\Program Files\MSoffice\OFFICE11\POWERPNT.EXE [C:\PROGRA~1\MSoffice\OFFICE11\POWERPNT.EXE] -> [2011-04-20 16:22:46 | 006,421,848 | ---- | M] (Microsoft Corporation) PowerProducer -> C:\Program Files\CyberLink\PowerProducer\Producer.exe [C:\Program Files\CyberLink\PowerProducer\Producer.exe] -> [2008-03-20 08:31:26 | 002,008,360 | ---- | M] (CyberLink) PowerShell.exe -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [%SystemRoot%\system32\WindowsPowerShell\v1.0\PowerShell.exe] -> [2009-10-09 23:56:28 | 000,448,000 | ---- | M] (Microsoft Corporation) PowerStarter -> C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe [C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe] -> [2007-12-03 14:47:58 | 000,255,272 | ---- | M] (CyberLink) RayV.exe -> C:\Program Files\RayV\RayV\RayV.exe [C:\Program Files\RayV\RayV\RayV.exe] -> [2009-10-26 17:18:00 | 002,544,936 | ---- | M] (RayV) RunManual.exe -> C:\Program Files\Samsung\SamsungManual\RunManual.exe [C:\Program Files\Samsung\SamsungManual\RunManual.exe] -> [2008-04-25 07:50:34 | 000,024,576 | ---- | M] (Samsung Electronics) SAS.EXE -> D:\SAS\SASFoundation\9.2\sas.exe [D:\SAS\SASFoundation\9.2\sas.exe] -> [2010-03-25 07:10:58 | 000,140,568 | ---- | M] () sbase.exe -> C:\Program Files\OpenOffice.org 3\program\sbase.exe [C:\Program Files\OpenOffice.org 3\program\sbase.exe] -> [2009-01-09 14:41:10 | 000,304,128 | ---- | M] () scalc.exe -> C:\Program Files\OpenOffice.org 3\program\scalc.exe [C:\Program Files\OpenOffice.org 3\program\scalc.exe] -> [2009-01-09 14:40:58 | 000,304,128 | ---- | M] () sdraw.exe -> C:\Program Files\OpenOffice.org 3\program\sdraw.exe [C:\Program Files\OpenOffice.org 3\program\sdraw.exe] -> [2009-01-09 14:41:02 | 000,304,128 | ---- | M] () setup.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found simpress.exe -> C:\Program Files\OpenOffice.org 3\program\simpress.exe [C:\Program Files\OpenOffice.org 3\program\simpress.exe] -> [2009-01-09 14:41:04 | 000,304,128 | ---- | M] () smath.exe -> C:\Program Files\OpenOffice.org 3\program\smath.exe [C:\Program Files\OpenOffice.org 3\program\smath.exe] -> [2009-01-09 14:41:08 | 000,304,128 | ---- | M] () SnippingTool.exe -> C:\Windows\System32\SnippingTool.exe [C:\Windows\System32\SnippingTool.exe] -> [2008-01-21 04:25:29 | 000,275,968 | ---- | M] (Microsoft Corporation) soffice.exe -> C:\Program Files\OpenOffice.org 3\program\soffice.exe [C:\Program Files\OpenOffice.org 3\program\soffice.exe] -> [2009-01-09 19:50:10 | 007,424,000 | ---- | M] (OpenOffice.org) SopCast.exe -> C:\Program Files\SopCast\SopCast.exe [C:\Program Files\SopCast\SopCast.exe] -> [2009-07-09 09:09:52 | 001,921,024 | ---- | M] (www.sopcast.com) stikynot.exe -> C:\Windows\System32\StikyNot.exe [C:\Windows\System32\stikynot.exe] -> [2006-11-02 14:35:47 | 000,289,280 | ---- | M] (Microsoft Corporation) swriter.exe -> C:\Program Files\OpenOffice.org 3\program\swriter.exe [C:\Program Files\OpenOffice.org 3\program\swriter.exe] -> [2009-01-09 14:40:56 | 000,304,128 | ---- | M] () table30.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found unopkg.exe -> C:\Program Files\OpenOffice.org 3\program\unopkg.exe [C:\Program Files\OpenOffice.org 3\program\unopkg.exe] -> [2009-01-09 14:40:50 | 000,010,752 | ---- | M] () wab.exe -> C:\Program Files\Windows Mail\wab.exe [%ProgramFiles%\Windows Mail\wab.exe] -> [2010-10-12 15:52:20 | 000,515,584 | ---- | M] (Microsoft Corporation) wabmig.exe -> C:\Program Files\Windows Mail\wabmig.exe [%ProgramFiles%\Windows Mail\wabmig.exe] -> [2010-10-12 15:52:20 | 000,066,048 | ---- | M] (Microsoft Corporation) winamp.exe -> C:\Program Files\Winamp\winamp.exe [C:\Program Files\Winamp\winamp.exe] -> [2008-08-04 01:04:00 | 001,345,376 | ---- | M] (Nullsoft) WinCal.exe -> C:\Program Files\Windows Calendar\wincal.exe ["%ProgramFiles%\Windows Calendar\wincal.exe"] -> [2008-01-21 04:23:32 | 000,967,680 | ---- | M] (Microsoft Corporation) WinMail.exe -> C:\Program Files\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-21 04:23:32 | 000,397,312 | ---- | M] (Microsoft Corporation) WinRAR.exe -> C:\Program Files\WinRAR\WinRAR.exe [C:\Program Files\WinRAR\WinRAR.exe] -> [2012-02-17 20:54:46 | 001,157,632 | ---- | M] (Alexander Roshal) Winword.exe -> C:\Program Files\MSoffice\OFFICE11\WINWORD.EXE [C:\PROGRA~1\MSoffice\OFFICE11\WINWORD.EXE] -> [2012-02-15 17:10:32 | 012,319,504 | ---- | M] (Microsoft Corporation) WORDPAD.EXE -> C:\Program Files\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2010-06-28 16:31:26 | 000,339,968 | ---- | M] (Microsoft Corporation) WRITE.EXE -> C:\Program Files\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2010-06-28 16:31:26 | 000,339,968 | ---- | M] (Microsoft Corporation) XPSViewer.exe -> C:\Windows\System32\XPSViewer\XPSViewer.exe ["C:\Windows\System32\XPSViewer\XPSViewer.exe"] -> [2008-06-20 03:14:45 | 000,301,568 | ---- | M] (Microsoft Corporation) < Approved Shell Extensions [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved -> "{00020D75-0000-0000-C000-000000000046}" [HKLM] -> C:\Program Files\MSoffice\OFFICE11\MLSHEXT.DLL [Microsoft Office Outlook Desktop Icon Handler] -> [2007-05-03 19:29:06 | 000,033,152 | ---- | M] (Microsoft Corporation) "{0006F045-0000-0000-C000-000000000046}" [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OLKFSTUB.DLL [Microsoft Office Outlook Custom Icon Handler] -> [2007-05-03 19:29:08 | 000,236,416 | ---- | M] (Microsoft Corporation) "{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoAcq.dll [PhotoAcqDropTarget] -> [2008-01-21 04:25:26 | 001,030,144 | ---- | M] (Microsoft Corporation) "{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}" [HKLM] -> C:\Program Files\Windows Photo Gallery\ImagingDevices.exe [Microsoft.ScannersAndCameras] -> [2006-11-02 14:36:17 | 000,202,752 | ---- | M] (Microsoft Corporation) "{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}" [HKLM] -> C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL [Microsoft OneNote Namespace Extension for Windows Desktop Search] -> [2010-12-27 22:31:12 | 001,177,968 | ---- | M] (Microsoft Corporation) "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" [HKLM] -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [OpenOffice.org Infotip Handler] -> [2008-12-15 13:18:46 | 000,357,888 | ---- | M] (Sun Microsystems, Inc.) "{0DF44EAA-FF21-4412-828E-260A8728E7F1}" [HKLM] -> [Taskbar and Start Menu] -> File not found "{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}" [HKLM] -> Reg Error: Key error. [Contacts folder] -> File not found "{11dbb47c-a525-400b-9e80-a54615a090c0}" [HKLM] -> C:\Windows\System32\ExplorerFrame.dll [Execute Folder] -> [2008-01-21 04:24:22 | 000,020,992 | ---- | M] (Microsoft Corporation) "{13D3C4B8-B179-4ebb-BF62-F704173E7448}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [Windows Contact Preview Handler] -> [2008-01-21 04:24:09 | 000,707,584 | ---- | M] (Microsoft Corporation) "{16C2C29D-0E5F-45f3-A445-03E03F587B7D}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [group_wab_auto_file] -> [2008-01-21 04:24:09 | 000,707,584 | ---- | M] (Microsoft Corporation) "{176d6597-26d3-11d1-b350-080036a75b03}" [HKLM] -> C:\Windows\System32\colorui.dll [ICM Scanner Management] -> [2008-01-21 04:24:36 | 000,686,592 | ---- | M] (Microsoft Corporation) "{1b24a030-9b20-49bc-97ac-1be4426f9e59}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{1FA9085F-25A2-489B-85D4-86326EEDCD87}" [HKLM] -> C:\Windows\System32\wlanpref.dll [Manage Wireless Networks] -> [2008-01-21 04:23:29 | 001,671,680 | ---- | M] (Microsoft Corporation) "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" [HKLM] -> C:\Program Files\Common Files\System\Ole DB\oledb32.dll [Microsoft Data Link] -> [2008-01-21 04:25:01 | 000,688,128 | ---- | M] (Microsoft Corporation) "{2781761E-28E0-4109-99FE-B9D127C57AFE}" [HKLM] -> C:\Program Files\Windows Defender\MpOAV.dll [Windows Defender IOfficeAntiVirus implementation] -> [2008-01-21 04:23:32 | 000,090,680 | ---- | M] (Microsoft Corporation) "{289978AC-A101-4341-A817-21EBA7FD046D}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Conflict Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{2C2577C2-63A7-40e3-9B7F-586602617ECB}" [HKLM] -> Reg Error: Key error. [Explorer Query Band] -> File not found "{2E9E59C0-B437-4981-A647-9C34B9B90891}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Setup Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{2F603045-309F-11CF-9774-0020AFD0CFF6}" [HKLM] -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll [Synaptics Control Panel] -> [2007-10-26 07:10:50 | 000,942,080 | ---- | M] (Synaptics, Inc.) "{32714800-2E5F-11d0-8B85-00AA0044F941}" [HKLM] -> C:\Program Files\Windows Mail\wabfind.dll [For &People...] -> [2010-10-12 17:48:28 | 000,033,280 | ---- | M] (Microsoft Corporation) "{34449847-FD14-4fc8-A75A-7432F5181EFB}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{3B092F0C-7696-40E3-A80F-68D74DA84210}" [HKLM] -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [OpenOffice.org Thumbnail Viewer] -> [2008-12-15 13:18:46 | 000,357,888 | ---- | M] (Sun Microsystems, Inc.) "{3e7efb4c-faf1-453d-89eb-56026875ef90}" [HKLM] -> [Get Programs Online] -> File not found "{3F30C968-480A-4C6C-862D-EFC0897BB84B}" [HKLM] -> C:\Windows\System32\PhotoMetadataHandler.dll [Photo Thumbnail Extractor] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{4026492f-2f69-46b8-b9bf-5654fc07e423}" [HKLM] -> C:\Windows\System32\FirewallControlPanel.exe [Windows Firewall] -> [2008-01-21 04:24:44 | 002,585,088 | ---- | M] (Microsoft Corporation) "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}" [HKLM] -> C:\Windows\System32\MediaMetadataHandler.dll [Video Media Properties Handler] -> [2008-01-21 04:25:18 | 000,356,864 | ---- | M] (Microsoft Corporation) "{42042206-2D85-11D3-8CFF-005004838597}" [HKLM] -> [Microsoft Office HTML Icon Handler] -> File not found "{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}" [HKLM] -> C:\Windows\System32\icsigd.dll [IGD Property Sheet Handler] -> [2006-11-02 11:46:05 | 000,195,584 | ---- | M] (Microsoft Corporation) "{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Event Properties Extension] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}" [HKLM] -> C:\Windows\System32\gameux.dll [GameUX.RichGameMediaThumbnail] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{4F58F63F-244B-4c07-B29F-210BE59BE9B4}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [.group shell extension handler] -> [2008-01-21 04:24:09 | 000,707,584 | ---- | M] (Microsoft Corporation) "{506F4668-F13E-4AA1-BB04-B43203AB3CC0}" [HKLM] -> C:\Program Files\Microsoft Office\Office14\VISSHE.DLL [{506F4668-F13E-4AA1-BB04-B43203AB3CC0}] -> [2010-03-13 01:04:04 | 000,900,464 | ---- | M] (Microsoft Corporation) "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" [HKLM] -> C:\Windows\System32\acppage.dll [Compatibility Property Page] -> [2006-11-02 11:46:02 | 000,038,912 | ---- | M] (Microsoft Corporation) "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}" [HKLM] -> C:\Windows\System32\control.exe [Control Panel command object for Start menu] -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) "{53BEDF0B-4E5B-4183-8DC9-B844344FA104}" [HKLM] -> C:\Windows\System32\mssvp.dll [Microsoft Windows MAPI Preview Handler] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Handler Properties Extension] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" [HKLM] -> C:\Windows\System32\colorui.dll [ICM Monitor Management] -> [2008-01-21 04:24:36 | 000,686,592 | ---- | M] (Microsoft Corporation) "{5ea4f148-308c-46d7-98a9-49041b1dd468}" [HKLM] -> C:\Windows\System32\mblctr.exe [Mobility Center Control Panel] -> [2008-01-21 04:25:18 | 000,939,008 | ---- | M] (Microsoft Corporation) "{63542C48-9552-494A-84F7-73AA6A7C99C1}" [HKLM] -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [OpenOffice.org Property Sheet Handler] -> [2008-12-15 13:18:46 | 000,357,888 | ---- | M] (Sun Microsystems, Inc.) "{675F097E-4C4D-11D0-B6C1-0800091AA605}" [HKLM] -> C:\Windows\System32\colorui.dll [ICM Printer Management] -> [2008-01-21 04:24:36 | 000,686,592 | ---- | M] (Microsoft Corporation) "{67718415-c450-4f3c-bf8a-b487642dc39b}" [HKLM] -> C:\Windows\System32\OptionalFeatures.exe [Windows Features] -> [2008-01-21 04:23:40 | 000,097,280 | ---- | M] (Microsoft Corporation) "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" [HKLM] -> C:\Windows\System32\shwebsvc.dll [Shell Publishing Wizard Object] -> [2008-01-21 04:23:44 | 000,425,472 | ---- | M] (Microsoft Corporation) "{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}" [HKLM] -> [Folder Options] -> File not found "{71D99464-3B6B-475C-B241-E15883207529}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Results Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{74246bfc-4c96-11d0-abef-0020af6b0b7a}" [HKLM] -> C:\Windows\System32\devmgr.dll [Device Manager] -> [2008-01-21 04:23:52 | 000,377,344 | ---- | M] (Microsoft Corporation) "{7842554E-6BED-11D2-8CDB-B05550C10000}" [HKLM] -> C:\Windows\System32\BTNCopy.dll [Monitor] -> [2008-02-12 05:36:04 | 000,184,320 | ---- | M] (Broadcom Corporation.) "{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Simple Conflict Presenter] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{7A979262-40CE-46ff-AEEE-7884AC3B6136}" [HKLM] -> C:\Windows\System32\hdwwiz.exe [Add New Hardware] -> [2006-11-02 11:45:12 | 000,080,384 | ---- | M] (Microsoft Corporation) "{7A9D77BD-5403-11d2-8785-2E0420524153}" [HKLM] -> C:\Windows\System32\Netplwiz.exe [User Accounts] -> [2008-01-21 04:23:45 | 000,025,600 | ---- | M] (Microsoft Corporation) "{8082C5E6-4C27-48ec-A809-B8E1122E8F97}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [.contact shell extension handler] -> [2008-01-21 04:24:09 | 000,707,584 | ---- | M] (Microsoft Corporation) "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}" [HKLM] -> C:\Windows\System32\MediaMetadataHandler.dll [Audio Media Properties Handler] -> [2008-01-21 04:25:18 | 000,356,864 | ---- | M] (Microsoft Corporation) "{877ca5ac-cb41-4842-9c69-9136e42d47e2}" [HKLM] -> C:\Windows\System32\sdshext.dll [File Backup Index] -> [2008-01-21 04:23:27 | 000,098,816 | ---- | M] (Microsoft Corporation) "{89D83576-6BD1-4c86-9454-BEB04E94C819}" [HKLM] -> C:\Windows\System32\mssvp.dll [MAPI Search Namespace Extension] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{8E25992B-373E-486E-80E5-BD23AE417E66}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Device Notification Sink] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{90b9bce2-b6db-4fd3-8451-35917ea1081b}" [HKLM] -> C:\Windows\System32\ExplorerFrame.dll [Search Execute Command] -> [2008-01-21 04:24:22 | 000,020,992 | ---- | M] (Microsoft Corporation) "{911051fa-c21c-4246-b470-070cd8df6dc4}" [HKLM] -> Reg Error: Key error. [.cab or .zip files] -> File not found "{91ADC906-6722-4B05-A12B-471ADDCCE132}" [HKLM] -> C:\Windows\System32\TouchX.dll [Touch Band] -> [2006-11-02 14:35:24 | 002,073,600 | ---- | M] (Microsoft Corporation) "{92337A8C-E11D-11D0-BE48-00C04FC30DF6}" [HKLM] -> C:\Windows\System32\oleprn.dll [OlePrn.PrinterURL] -> [2008-01-21 04:24:18 | 000,096,768 | ---- | M] (Microsoft Corporation) "{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" [HKLM] -> C:\Program Files\AVG\AVG2012\avgse.dll [AVG Shell Extension] -> [2012-02-14 04:53:00 | 000,158,560 | ---- | M] (AVG Technologies CZ, s.r.o.) "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" [HKLM] -> Reg Error: Key error. [AVG Find Extension] -> File not found "{a304259d-52b8-4526-8b1a-a1d6cecc8243}" [HKLM] -> C:\Windows\System32\iscsicpl.exe [iSCSI Initiator] -> [2006-11-02 11:45:17 | 000,120,320 | ---- | M] (Microsoft Corporation) "{a38b883c-1682-497e-97b0-0a3a9e801682}" [HKLM] -> C:\Windows\System32\PhotoMetadataHandler.dll [IPropertyStore Handler for Images] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{A70C977A-BF00-412C-90B7-034C51DA2439}" [HKLM] -> C:\Windows\System32\nvcpl.dll [NvCpl DesktopContext Class] -> [2008-12-02 12:11:00 | 013,683,232 | ---- | M] (NVIDIA Corporation) "{add36aa8-751a-4579-a266-d66f5202ccbb}" [HKLM] -> C:\Windows\System32\shwebsvc.dll [Print Ordering via the Web] -> [2008-01-21 04:23:44 | 000,425,472 | ---- | M] (Microsoft Corporation) "{b2c761c6-29bc-4f19-9251-e6195265baf1}" [HKLM] -> C:\Windows\System32\colorcpl.exe [Color Control Panel Applet] -> [2006-11-02 11:44:59 | 000,084,992 | ---- | M] (Microsoft Corporation) "{B32D3949-ED98-4DBB-B347-17A144969BBA}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Item Properties Extension] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{BC48B32F-5910-47F5-8570-5074A8A5636A}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Results Delegate Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{BC65FB43-1958-4349-971A-210290480130}" [HKLM] -> C:\Windows\System32\NcdProp.dll [Network Explorer Property Sheet Handler] -> [2008-01-21 04:23:45 | 000,019,968 | ---- | M] (Microsoft Corporation) "{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}" [HKLM] -> C:\Windows\System32\mssvp.dll [Client Side Cache Namespace Extension] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" [HKLM] -> C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [OpenOffice.org Column Handler] -> [2008-12-15 13:18:46 | 000,357,888 | ---- | M] (Sun Microsystems, Inc.) "{c5a40261-cd64-4ccf-84cb-c394da41d590}" [HKLM] -> C:\Windows\System32\MediaMetadataHandler.dll [Video Thumbnail Extractor] -> [2008-01-21 04:25:18 | 000,356,864 | ---- | M] (Microsoft Corporation) "{C7657C4A-9F68-40fa-A4DF-96BC08EB3551}" [HKLM] -> C:\Windows\System32\PhotoMetadataHandler.dll [Photo Thumbnail Provider] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{C8494E42-ACDD-4739-B0FB-217361E4894F}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}" [HKLM] -> C:\Windows\System32\oobefldr.dll [Welcome Center] -> [2008-01-21 04:23:39 | 002,153,472 | ---- | M] (Microsoft Corporation) "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" [HKLM] -> C:\Windows\System32\shwebsvc.dll [Web Publishing Wizard] -> [2008-01-21 04:23:44 | 000,425,472 | ---- | M] (Microsoft Corporation) "{CF67796C-F57F-45F8-92FB-AD698826C602}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [contact_wab_auto_file] -> [2008-01-21 04:24:09 | 000,707,584 | ---- | M] (Microsoft Corporation) "{d3e34b21-9d75-101a-8c3d-00aa001a1652}" [HKLM] -> C:\Windows\System32\mspaint.exe [Bitmap Image] -> [2008-01-21 04:24:56 | 000,485,376 | ---- | M] (Microsoft Corporation) "{D66DC78C-4F61-447F-942B-3FB6980118CF}" [HKLM] -> C:\Program Files\Microsoft Office\Office14\VISSHE.DLL [{D66DC78C-4F61-447F-942B-3FB6980118CF}] -> [2010-03-13 01:04:04 | 000,900,464 | ---- | M] (Microsoft Corporation) "{d8559eb9-20c0-410e-beda-7ed416aecc2a}" [HKLM] -> C:\Program Files\Windows Defender\MSASCui.exe [Windows Defender] -> [2008-01-21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) "{da67b8ad-e81b-4c70-9b91b417b5e33527}" [HKLM] -> Reg Error: Key error. [Windows Search Shell Service] -> File not found "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" [HKLM] -> C:\Windows\System32\colorui.dll [ICC Profile] -> [2008-01-21 04:24:36 | 000,686,592 | ---- | M] (Microsoft Corporation) "{E29F9716-5C08-4FCD-955A-119FDB5A522D}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{E413D040-6788-4C22-957E-175D1C513A34}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Conflict Delegate Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{E44E5D18-0652-4508-A4E2-8A090067BCB0}" [HKLM] -> C:\Windows\System32\control.exe [Default Programs command object for Start menu] -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) "{E598560B-28D5-46aa-A14A-8A3BEA34B576}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Video Verbs] -> [2008-01-21 04:25:27 | 002,314,240 | ---- | M] (Microsoft Corporation) "{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}" [HKLM] -> C:\Windows\System32\gameux.dll [RichGameMediaPropertyStore Class] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}" [HKLM] -> C:\Windows\System32\gameux.dll [Games Folder] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{F04CC277-03A2-4277-96A9-77967471BDFF}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Center Conflict Properties Extension] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}" [HKLM] -> C:\Windows\System32\SyncCenter.dll [Sync Setup Delegate Folder] -> [2008-01-21 04:23:31 | 002,204,672 | ---- | M] (Microsoft Corporation) "{fcfeecae-ee1b-4849-ae50-685dcf7717ec}" [HKLM] -> C:\Windows\System32\wercon.exe [Problem Reports and Solutions] -> [2008-01-21 04:23:53 | 001,143,296 | ---- | M] (Microsoft Corporation) "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" [HKLM] -> C:\Windows\System32\nvcpl.dll [Play on my TV helper] -> [2008-12-02 12:11:00 | 013,683,232 | ---- | M] (NVIDIA Corporation) "{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Image Verbs] -> [2008-01-21 04:25:27 | 002,314,240 | ---- | M] (Microsoft Corporation) < Approved Shell Extensions [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ -> {C6A0A7A5-0858-8F84-46B6-31977ECCB523} [HKLM] -> Reg Error: Key error. [Reg Error: Value error.] -> File not found < Desktop WallPaper > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General -> WallPaper -> C:\Windows\Web\Wallpaper\img15.jpg -> BackupWallPaper -> C:\Windows\Web\Wallpaper\img15.jpg -> < Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe -> [2008-02-12 06:19:52 | 000,723,496 | ---- | M] (Broadcom Corporation.) C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2008-03-25 21:40:42 | 000,214,360 | ---- | M] (Hewlett-Packard Co.) < Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> Adobe Reader Speed Launcher hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe -> [2008-01-11 23:16:00 | 000,039,792 | ---- | M] (Adobe Systems Incorporated) Ad-Watch hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe -> [2011-06-20 22:32:05 | 000,528,832 | ---- | M] (Lavasoft) HP Software Update hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\HP\HP Software Update\hpwuSchd2.exe -> [2008-03-25 22:27:58 | 000,049,152 | ---- | M] (Hewlett-Packard) hpqSRMon hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe -> [2008-03-13 10:34:28 | 000,081,920 | ---- | M] (Hewlett-Packard) LightScribe Control Panel hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -> [2008-03-17 10:59:40 | 002,289,664 | ---- | M] (Hewlett-Packard Company) RemoteControl hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe -> [2007-03-14 14:01:30 | 000,071,216 | ---- | M] (Cyberlink Corp.) SansaDispatch hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Users\EuroRtvAgd\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe -> [2009-02-16 18:04:39 | 000,079,872 | ---- | M] (SanDisk Corporation) SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\Common Files\Java\Java Update\jusched.exe -> [2012-01-18 14:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) Virtual Drives Manager hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> File not found WinampAgent hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files\Winamp\winampa.exe -> [2008-08-04 01:02:20 | 000,036,352 | ---- | M] () < Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state -> "startup" -> 2 -> < Drivers32 [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 -> "msacm.clmp3enc" -> C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM [C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM] -> [2005-05-13 13:00:52 | 000,217,088 | ---- | M] (CyberLink Corp.) "msacm.l3acm" -> C:\Windows\System32\l3codeca.acm [C:\Windows\System32\l3codeca.acm] -> [2010-01-21 17:59:47 | 000,062,464 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) "msacm.l3codecp" -> C:\Windows\System32\l3codecp.acm [l3codecp.acm] -> [2008-01-21 04:25:18 | 000,220,672 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) "msacm.vorbis" -> C:\Windows\System32\vorbis.acm [vorbis.acm] -> [2009-08-02 22:09:56 | 001,554,944 | ---- | M] (HMS http://hp.vector.co.jp/authors/VA012897/) "MSVideo8" -> C:\Windows\System32\vfwwdm32.dll [VfWWDM32.dll] -> [2008-01-21 04:23:54 | 000,056,832 | ---- | M] (Microsoft Corporation) "vidc.cvid" -> C:\Windows\System32\iccvid.dll [iccvid.dll] -> [2010-05-27 21:16:09 | 000,081,920 | ---- | M] (Radius Inc.) "VIDC.FFDS" -> C:\Windows\System32\ff_vfw.dll [ff_vfw.dll] -> [2011-03-18 21:42:34 | 000,080,896 | ---- | M] () "VIDC.FPS1" -> C:\Windows\System32\frapsvid.dll [frapsvid.dll] -> [2009-01-03 10:07:08 | 000,081,920 | ---- | M] (Beepa P/L) "VIDC.IV32" -> C:\Windows\System32\ir32_32.dll [ir32_32.dll] -> [2006-11-02 14:34:41 | 000,197,632 | ---- | M] (Intel(R) Corporation) "VIDC.IV41" -> C:\Windows\System32\ir41_32.ax [IR41_32.AX] -> [2006-11-02 11:44:49 | 000,839,680 | ---- | M] (Intel Corporation) < Ext (PreApproved) - [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ -> {02BCC737-B171-4746-94C9-0D8A0B2C0089} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\IEAWSDC.DLL [Microsoft Office Template and Media Control] -> [2007-04-19 14:10:30 | 000,116,576 | ---- | M] () {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {233C1507-6A77-46A4-9443-F871F945D258} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3760D689-C63B-4422-9A1D-31CA856CD5C1} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3B1E1AB9-98C2-4B7E-AE01-59C84302BBDB} [HKLM] -> C:\Program Files\RayV\RayV\plugins\nprayvplugin.dll [RayVActiveXCtrl Object] -> [2009-10-26 17:17:54 | 000,558,368 | ---- | M] (RayV) {3FD37ABB-F90A-4DE5-AA38-179629E64C2F} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSSUPP.DLL [SharePoint Spreadsheet Launcher] -> [2007-04-19 14:10:18 | 000,099,680 | ---- | M] (Microsoft Corporation) {4063BE15-3B08-470D-A0D5-B37161CFFD69} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {5852F5ED-8BF4-11D4-A245-0080C6F74284} [HKLM] -> C:\Program Files\Java\jre6\bin\wsdetect.dll [isInstalled Class] -> [2012-04-18 00:52:18 | 000,112,416 | ---- | M] (Sun Microsystems, Inc.) {62B4D041-4667-40B6-BB50-4BC0A5043A73} [HKLM] -> C:\Program Files\Microsoft Office\Office14\OWSSUPP.DLL [SharePoint Export Database Launcher] -> [2010-03-24 21:22:38 | 000,134,536 | ---- | M] (Microsoft Corporation) {65BCBEE4-7728-41A0-97BE-14E1CAE36AAE} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\STSLIST.DLL [Microsoft Office List 11.0] -> [2007-05-10 13:42:52 | 002,839,904 | ---- | M] (Microsoft Corporation) {760C4B83-E211-11D2-BF3E-00805FBE84A6} [HKLM] -> C:\Windows\System32\msnetobj.dll [Windows Media Services DRM Storage object] -> [2008-01-21 04:25:16 | 000,179,712 | ---- | M] (Microsoft Corporation) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2012-04-18 00:52:18 | 000,325,408 | ---- | M] (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_31] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {8E4062D9-FE1B-4b9e-AA16-5E8EEF68F48E} [HKLM] -> C:\Windows\System32\RegCtrl.dll [Registration Control] -> [2008-01-21 04:24:26 | 000,040,960 | ---- | M] (Microsoft Corporation) {9203C2CB-1DC1-482D-967E-597AFF270F0D} [HKLM] -> C:\Program Files\Microsoft Office\Office14\OWSSUPP.DLL [SharePoint OpenDocuments Class] -> [2010-03-24 21:22:38 | 000,134,536 | ---- | M] (Microsoft Corporation) {9F9C4924-C3F3-4459-A396-9E9E0D8B83D1} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSSUPP.DLL [SharePoint OpenDocuments Class] -> [2007-04-19 14:10:18 | 000,099,680 | ---- | M] (Microsoft Corporation) {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [HKLM] -> C:\Windows\System32\msnetobj.dll [RMGetLicense Class] -> [2008-01-21 04:25:16 | 000,179,712 | ---- | M] (Microsoft Corporation) {BDEADE98-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSCLT.DLL [OWS Post Data] -> [2007-04-19 14:10:32 | 000,648,544 | ---- | M] (Microsoft Corporation) {BDEADE9E-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSCLT.DLL [SharePoint Spreadsheet Launcher] -> [2007-04-19 14:10:32 | 000,648,544 | ---- | M] (Microsoft Corporation) {BDEADEDE-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSCLT.DLL [OSE Global Class] -> [2007-04-19 14:10:32 | 000,648,544 | ---- | M] (Microsoft Corporation) {BDEADEF2-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> Reg Error: Key error. [SharePoint OpenDocuments Class] -> File not found {BDEADEF4-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\OWSSUPP.DLL [SharePoint Stssync Handler] -> [2007-04-19 14:10:18 | 000,099,680 | ---- | M] (Microsoft Corporation) {BDEADEF5-C265-11D0-BCED-00A0C90AB50F} [HKLM] -> C:\Program Files\Microsoft Office\Office14\OWSSUPP.DLL [SharePoint Stssync Handler] -> [2010-03-24 21:22:38 | 000,134,536 | ---- | M] (Microsoft Corporation) {C514A18E-862A-45d3-8A5E-62CF54D912B6} [HKLM] -> C:\Program Files\Microsoft Office\Office14\AUTHZAX.DLL [Microsoft Office 14 Authorization Control] -> [2010-01-09 22:41:04 | 000,054,152 | ---- | M] (Microsoft Corporation) {C6FDD0C3-266A-4DC3-B459-28C697C44CDC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CA8A9780-280D-11CF-A24D-444553540000} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll [Adobe PDF Reader] -> [2007-05-10 23:26:00 | 000,632,432 | ---- | M] (Adobe Systems, Inc.) {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_12] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_12] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_12] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_15] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_15] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.5.0_15] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_31] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_31] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_31] -> [2012-04-18 00:52:18 | 000,104,224 | ---- | M] () {CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA} [HKLM] -> C:\Windows\System32\deployJava1.dll [Deployment Toolkit] -> [2012-04-18 00:52:18 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) {CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA} [HKLM] -> C:\Windows\System32\deployJava1.dll [Deployment Toolkit] -> [2012-04-18 00:52:18 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CDEC13B2-0B3C-400E-B909-E27EE89C6799} [HKLM] -> C:\Program Files\Microsoft Office\Office14\STSCOPY.DLL [STSUpld CopyCtl Class] -> [2010-03-24 21:22:38 | 000,094,080 | ---- | M] (Microsoft Corporation) {CFCDAA03-8BE4-11cf-B84B-0020AFBBCCFA} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {D27CDB6E-AE6D-11cf-96B8-444553540000} [HKLM] -> C:\Windows\System32\Macromed\Flash\Flash10b.ocx [Shockwave Flash Object] -> [2009-02-03 04:07:18 | 003,866,528 | R--- | M] (Adobe Systems, Inc.) {DFEAF541-F3E1-4c24-ACAC-99C30715084A} [HKLM] -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll [Microsoft Silverlight] -> [2012-04-11 01:15:28 | 001,210,440 | ---- | M] ( Microsoft Corporation) {E18FEC31-2EA1-49A2-A7A6-902DC0D1FF05} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\NAME.DLL [NameCtrl Class] -> [2007-04-19 14:10:26 | 000,080,216 | ---- | M] (Microsoft Corporation) {E543A17A-F212-49C0-B63D-BF09B460250E} [HKLM] -> C:\Program Files\MSoffice\OFFICE11\oisctrl.dll [OISClientLauncher Class] -> [2007-03-22 19:06:08 | 000,046,432 | ---- | M] (Microsoft Corporation) {F25AF245-4A81-40DC-92F9-E9021F207706} [HKLM] -> C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\11.2.0\ScriptHelper.exe [ScriptHelperApi Class] -> [2012-07-09 21:52:17 | 001,209,952 | ---- | M] () 3E4D4F1C-2AEE-11D1-9D3D-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 435899C9-44AB-11D1-AF00-080036234103 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 4F664F91-FF01-11D0-8AED-00C04FD7B597 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 65303443-AD66-11D1-9D65-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 92337A8C-E11D-11D0-BE48-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found C3701884-B39B-11D1-9D68-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Ext (Stats) - [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006-10-23 00:08:00 | 000,062,080 | ---- | M] (Adobe Systems Incorporated) {2670000A-7350-4F3C-8081-5663EE0C6C49} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3760D689-C63B-4422-9A1D-31CA856CD5C1} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG2012\avgssie.dll [AVG Safe Search] -> [2012-06-24 04:12:06 | 001,417,336 | ---- | M] (AVG Technologies CZ, s.r.o.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2012-04-18 00:52:18 | 000,325,408 | ---- | M] (Sun Microsystems, Inc.) {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {95B7759C-8C7F-4BF1-B163-73684A933233} [HKLM] -> C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll [AVG Security Toolbar] -> [2012-07-09 21:52:15 | 002,074,208 | ---- | M] () {A057A204-BACC-4D26-9990-79A187E2698E} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {A3BC75A2-1F87-4686-AA43-5347D756017C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {B4F3A835-0E21-4959-BA22-42B3008E02FF} [HKLM] -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [Office Document Cache Handler] -> [2010-12-21 02:05:22 | 000,561,552 | ---- | M] (Microsoft Corporation) {CCA281CA-C863-46EF-9331-5C8D4460577F} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CCC7A320-B3CA-4199-B1A6-9F516DD69829} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> C:\Windows\System32\Macromed\Flash\Flash10b.ocx [Shockwave Flash Object] -> [2009-02-03 04:07:18 | 003,866,528 | R--- | M] (Adobe Systems, Inc.) {DFEAF541-F3E1-4C24-ACAC-99C30715084A} [HKLM] -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll [Microsoft Silverlight] -> [2012-04-11 01:15:28 | 001,210,440 | ---- | M] ( Microsoft Corporation) < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> "%1" %* -> .cmd [@ = cmdfile] -> "%1" %* -> .com [@ = comfile] -> "%1" %* -> .cpl [@ = cplfile] -> C:\Windows\System32\control.exe -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) .exe [@ = exefile] -> "%1" %* -> .hlp [@ = hlpfile] -> C:\Windows\winhlp32.exe -> [2006-11-02 11:45:57 | 000,009,216 | ---- | M] (Microsoft Corporation) .url [@ = InternetShortcut] -> rundll32.exe ieframe.dll,OpenURL %l -> .pif [@ = piffile] -> "%1" %* -> .scr [@ = scrfile] -> "%1" /S -> < File Associations - Select to Repair > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Classes\\ -> .html [@ = FirefoxHTML] -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2012-07-07 21:00:57 | 000,913,888 | ---- | M] (Mozilla Corporation) < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> -> *netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs -> FastUserSwitchingCompatibility -> -> File not found Ias -> C:\Windows\System32\ias.dll -> [2008-01-21 04:24:07 | 000,018,944 | ---- | M] (Microsoft Corporation) Nla -> -> File not found Ntmssvc -> -> File not found NWCWorkstation -> -> File not found Nwsapagent -> -> File not found SRService -> -> File not found WmdmPmSp -> -> File not found LogonHours -> -> File not found PCAudit -> -> File not found helpsvc -> -> File not found uploadmgr -> -> File not found *MultiFile Done* -> -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} [HKLM] -> C:\Program Files\AVG\AVG2012\avgpp.dll[XPLPPFilter Class] -> [2012-03-27 05:19:36 | 000,122,752 | ---- | M] (AVG Technologies CZ, s.r.o.) viprotocol:{B658800C-F66E-4EF3-AB85-6C0C227862A9} [HKLM] -> C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll[ViProtocolOLE Class] -> [2012-07-09 21:52:19 | 000,165,472 | ---- | M] () < SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AppMgmt -> Service Base -> Driver Group Boot Bus Extender -> Driver Group Boot file system -> Driver Group File system -> Driver Group Filter -> Driver Group HelpSvc -> Service Lavasoft Ad-Aware Service -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2011-06-20 22:32:05 | 001,036,104 | ---- | M] (Lavasoft) NTDS -> -> File not found PCI Configuration -> Driver Group PNP Filter -> Driver Group Primary disk -> Driver Group sacsvr -> Service SCSI Class -> Driver Group System Bus Extender -> Driver Group WinDefend -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) < SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E972-E325-11CE-BFC1-08002BE10318} -> Net {4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient {4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService {4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {50DD5230-BA8A-11D1-BF5D-0000F805F530} -> Smart card readers {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AppMgmt -> Service Base -> Driver Group Boot Bus Extender -> Driver Group Boot file system -> Driver Group File system -> Driver Group Filter -> Driver Group HelpSvc -> Service Lavasoft Ad-Aware Service -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2011-06-20 22:32:05 | 001,036,104 | ---- | M] (Lavasoft) Messenger -> Service NDIS Wrapper -> Driver Group NetBIOSGroup -> Driver Group NetDDEGroup -> Driver Group Network -> Driver Group NetworkProvider -> Driver Group NTDS -> -> File not found PCI Configuration -> Driver Group PNP Filter -> Driver Group PNP_TDI -> Driver Group Primary disk -> Driver Group rdsessmgr -> Service sacsvr -> Service SCSI Class -> Driver Group Streams Drivers -> Driver Group System Bus Extender -> Driver Group TDI -> Driver Group WinDefend -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) < Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center \\"cval" -> [0] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware \Monitoring\McAfeeAntiSpyware\\"DisableMonitoring" -> [1] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc \Svc\\"AntiVirusOverride" -> [0] -> File not found \Svc\\"AntiSpywareOverride" -> [0] -> File not found \Svc\\"FirewallOverride" -> [0] -> File not found \Svc\\"VistaSp1" -> Reg Error: Unknown registry data type [Reg Error: Unknown registry data type] -> File not found < Windows DomainProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile \\"EnableFirewall" -> [1] -> File not found \\"DisableNotifications" -> [0] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging\ -> -> < Windows StandardProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile \\"EnableFirewall" -> [1] -> File not found \\"DisableNotifications" -> [0] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging\ -> -> < Session Manager Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager -> *BootExecute* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\BootExecute -> autocheck autochk * -> -> File not found lsdelete -> C:\Windows\System32\lsdelete.exe -> [2011-06-20 22:32:12 | 000,015,880 | ---- | M] () C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart -> C:\Program Files\AVG\AVG2012\avgrsx.exe -> [2012-06-13 03:48:26 | 000,758,392 | ---- | M] (AVG Technologies CZ, s.r.o.) *MultiFile Done* -> -> "ExcludeFromKnownDlls" -> [binary data] -> *ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories -> \Windows -> -> File not found \RPC Control -> -> File not found *MultiFile Done* -> -> < Session Manager Environment Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment -> "ComSpec" -> C:\Windows\System32\cmd.exe -> [2008-01-21 04:23:50 | 000,318,976 | ---- | M] (Microsoft Corporation) "TEMP" -> C:\Windows\Temp -> [2012-07-12 22:24:10 | 000,000,000 | ---D | M] "TMP" -> C:\Windows\Temp -> [2012-07-12 22:24:10 | 000,000,000 | ---D | M] "windir" -> C:\Windows -> [2012-07-12 22:25:21 | 000,000,000 | ---D | M] *Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path -> %SystemRoot%\system32 -> C:\Windows\System32 -> [2012-07-12 22:32:54 | 000,000,000 | ---D | M] %SystemRoot% -> C:\Windows -> [2012-07-12 22:25:21 | 000,000,000 | ---D | M] %SystemRoot%\System32\Wbem -> C:\Windows\System32\wbem -> [2010-06-12 09:47:28 | 000,000,000 | ---D | M] C:\Program Files\Intel\WiFi\bin\ -> C:\Program Files\Intel\WiFi\bin\ -> [2008-07-16 15:56:01 | 000,000,000 | ---D | M] C:\Program Files\Microsoft SQL Server\90\Tools\binn\ -> C:\Program Files\Microsoft SQL Server\90\Tools\binn\ -> [2011-04-07 09:47:42 | 000,000,000 | ---D | M] %SYSTEMROOT%\System32\WindowsPowerShell\v1.0\ -> C:\Windows\System32\WindowsPowerShell\v1.0\ -> [2011-03-02 10:24:28 | 000,000,000 | ---D | M] D:\SAS\SharedFiles\Formats -> D:\SAS\SharedFiles\Formats -> [2011-06-28 17:35:48 | 000,000,000 | ---D | M] C:\Program Files\Common Files\iZotope\Runtimes -> C:\Program Files\Common Files\iZotope\Runtimes -> [2012-04-15 13:59:59 | 000,000,000 | ---D | M] *MultiFile Done* -> -> *PATHEXT* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\PATHEXT -> .COM -> -> File not found .EXE -> -> File not found .BAT -> -> File not found .CMD -> -> File not found .VBS -> -> File not found .VBE -> -> File not found .JS -> -> File not found .JSE -> -> File not found .WSF -> -> File not found .WSH -> -> File not found .MSC -> -> File not found *MultiFile Done* -> -> < Session Manager FileRenameOperations Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations -> < Session Manager KnownDlls Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls -> "advapi32" -> C:\Windows\System32\advapi32.dll -> [2008-01-21 04:24:27 | 000,798,720 | ---- | M] (Microsoft Corporation) "clbcatq" -> C:\Windows\System32\clbcatq.dll -> [2008-01-21 04:24:24 | 000,523,776 | ---- | M] (Microsoft Corporation) "COMDLG32" -> C:\Windows\System32\comdlg32.dll -> [2008-01-21 04:24:38 | 000,450,048 | ---- | M] (Microsoft Corporation) "DllDirectory" -> C:\Windows\System32 -> [2012-07-12 22:32:54 | 000,000,000 | ---D | M] "gdi32" -> C:\Windows\System32\gdi32.dll -> [2008-10-21 07:25:18 | 000,296,960 | ---- | M] (Microsoft Corporation) "IERTUTIL" -> C:\Windows\System32\iertutil.dll -> [2011-04-21 16:57:48 | 000,270,848 | ---- | M] (Microsoft Corporation) "IMAGEHLP" -> C:\Windows\System32\imagehlp.dll -> [2008-01-21 04:24:06 | 000,153,088 | ---- | M] (Microsoft Corporation) "IMM32" -> C:\Windows\System32\imm32.dll -> [2008-01-21 04:24:24 | 000,114,688 | ---- | M] (Microsoft Corporation) "kernel32" -> C:\Windows\System32\kernel32.dll -> [2011-04-12 16:53:05 | 000,890,368 | ---- | M] (Microsoft Corporation) "LPK" -> C:\Windows\System32\lpk.dll -> [2008-01-21 04:24:14 | 000,023,552 | ---- | M] (Microsoft Corporation) "MSCTF" -> C:\Windows\System32\msctf.dll -> [2008-01-21 04:24:57 | 000,806,912 | ---- | M] (Microsoft Corporation) "MSVCRT" -> C:\Windows\System32\msvcrt.dll -> [2008-01-21 04:24:36 | 000,680,448 | ---- | M] (Microsoft Corporation) "NORMALIZ" -> C:\Windows\System32\normaliz.dll -> [2006-11-02 10:33:06 | 000,002,560 | ---- | M] (Microsoft Corporation) "NSI" -> C:\Windows\System32\nsi.dll -> [2008-01-21 04:24:47 | 000,008,192 | ---- | M] (Microsoft Corporation) "ole32" -> C:\Windows\System32\ole32.dll -> [2010-06-28 18:15:53 | 001,315,840 | ---- | M] (Microsoft Corporation) "OLEAUT32" -> C:\Windows\System32\oleaut32.dll -> [2010-12-20 17:39:14 | 000,563,200 | ---- | M] (Microsoft Corporation) "rpcrt4" -> C:\Windows\System32\rpcrt4.dll -> [2009-04-23 14:43:04 | 000,784,896 | ---- | M] (Microsoft Corporation) "Setupapi" -> C:\Windows\System32\setupapi.dll -> [2008-01-21 04:24:46 | 001,590,272 | ---- | M] (Microsoft Corporation) "SHELL32" -> C:\Windows\System32\shell32.dll -> [2011-01-21 17:46:32 | 011,582,464 | ---- | M] (Microsoft Corporation) "SHLWAPI" -> C:\Windows\System32\shlwapi.dll -> [2011-01-21 17:46:57 | 000,351,744 | ---- | M] (Microsoft Corporation) "URLMON" -> C:\Windows\System32\urlmon.dll -> [2011-04-21 17:00:21 | 001,174,528 | ---- | M] (Microsoft Corporation) "user32" -> C:\Windows\System32\user32.dll -> [2008-01-21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) "USP10" -> C:\Windows\System32\usp10.dll -> [2010-04-16 18:10:45 | 000,501,760 | ---- | M] (Microsoft Corporation) "WININET" -> C:\Windows\System32\wininet.dll -> [2011-04-21 17:00:34 | 000,833,024 | ---- | M] (Microsoft Corporation) "WLDAP32" -> C:\Windows\System32\Wldap32.dll -> [2008-01-21 04:24:13 | 000,289,280 | ---- | M] (Microsoft Corporation) "WS2_32" -> C:\Windows\System32\ws2_32.dll -> [2008-01-21 04:24:48 | 000,179,200 | ---- | M] (Microsoft Corporation) < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> batfile [open] -> "%1" %* -> cmdfile [open] -> "%1" %* -> comfile [open] -> "%1" %* -> cplfile [cplopen] -> %SystemRoot%\System32\control.exe "%1",%* -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) exefile [open] -> "%1" %* -> hlpfile [open] -> %SystemRoot%\winhlp32.exe %1 -> [2006-11-02 11:45:57 | 000,009,216 | ---- | M] (Microsoft Corporation) inffile [install] -> %SystemRoot%\System32\InfDefaultInstall.exe "%1" -> [2008-01-21 04:24:35 | 000,011,776 | ---- | M] (Microsoft Corporation) InternetShortcut [open] -> rundll32.exe ieframe.dll,OpenURL %l -> piffile [open] -> "%1" %* -> scrfile [config] -> "%1" -> scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> scrfile [open] -> "%1" /S -> Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 -> Directory [AddToPlaylistVLC] -> "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" -> [2011-07-14 14:21:10 | 000,108,032 | ---- | M] () Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2008-01-21 04:23:50 | 000,318,976 | ---- | M] (Microsoft Corporation) Directory [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) Directory [PlayWithVLC] -> "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" -> [2011-07-14 14:21:10 | 000,108,032 | ---- | M] () Directory [Winamp.Bookmark] -> "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" -> [2008-08-04 01:04:00 | 001,345,376 | ---- | M] (Nullsoft) Directory [Winamp.Enqueue] -> "C:\Program Files\Winamp\winamp.exe" /ADD "%1" -> [2008-08-04 01:04:00 | 001,345,376 | ---- | M] (Nullsoft) Directory [Winamp.Play] -> "C:\Program Files\Winamp\winamp.exe" "%1" -> [2008-08-04 01:04:00 | 001,345,376 | ---- | M] (Nullsoft) Folder [open] -> %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) Folder [explore] -> %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) Drive [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) < Default Protocols [HKEY_LOCAL_MACHINE\] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> ldap -> 4 = Restricted sites (Not a Default Protocol) -> news -> 4 = Restricted sites (Not a Default Protocol) -> nntp -> 4 = Restricted sites (Not a Default Protocol) -> oecmd -> 4 = Restricted sites (Not a Default Protocol) -> snews -> 4 = Restricted sites (Not a Default Protocol) -> < Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> @ivt -> @ivt protocol not assigned -> file -> file protocol not assigned -> ftp -> ftp protocol not assigned -> http -> http protocol not assigned -> https -> https protocol not assigned -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> @ivt -> @ivt protocol not assigned -> file -> file protocol not assigned -> ftp -> ftp protocol not assigned -> http -> http protocol not assigned -> https -> https protocol not assigned -> shell -> shell protocol not assigned -> < Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} -> PDFCreator {004C5DA2-2051-4D25-94BA-51CF810C91EB} -> LightScribe System Software 1.12.37.1 {00AF10C1-44BD-4862-9D7F-24E6BA3E87FD} -> imagine digital freedom - Samsung {01D57CF6-B5BC-4D03-AFF5-7960CFBD05A9} -> Native Instruments Guitar Rig 5 {02875304-0DD9-465A-986E-A3438ACDC623} -> Melodyne Runtime 4.1 (x86) {0289B35E-DC07-4c7a-9710-BBD686EA4B7D} -> Status {03D1988F-469F-4843-8E6E-E5FE9D17889D} -> WIDCOMM Bluetooth Software 6.0.1.6300 {04983D37-2202-4295-94A2-8B547C66133F} -> Atheros WLAN Client {0886900B-B2F3-452C-B580-60F1253F7F80} -> Native Instruments Controller Editor {09633A5E-3089-41A8-9FF1-382171423C5D} -> PSSWCORE {0B8565BA-BAD5-4732-B122-5FD78EFC50A9} -> Native Instruments Service Center {145DE957-0679-4A2A-BB5C-1D3E9808FAB2} -> Samsung Recovery Solution III {17283B95-21A8-4996-97DA-547A48DB266F} -> Easy Display Manager {1F1C2DFC-2D24-3E06-BCB8-725134ADF989} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} -> CyberLink DVD Suite {22F761D1-8063-4170-ADF7-2D2F47834CA9} -> VideoToolkit01 {26A24AE4-039D-4CA4-87B4-2F83216031FF} -> Java(TM) 6 Update 31 {27197499-7680-4208-8FD8-5439CDB0FDC1} -> HPProductAssistant {2A48215C-E018-4F4B-9285-3CDC88C6992A} -> Myth III - The Wolf Age {2AFEAA03-2DFE-4519-A629-EDAB6541ABE9} -> HPSSupply {2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F} -> Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) {31BFEC6C-1F27-45B5-839C-BCBAE327993A} -> OpenOffice.org 3.0 {321320E1-0E5A-36CB-9E52-F3B201B8C4D4} -> Microsoft .NET Framework 4 Client Profile PLK Language Pack {3248F0A8-6813-11D6-A77B-00B0D0150120} -> J2SE Runtime Environment 5.0 Update 12 {3248F0A8-6813-11D6-A77B-00B0D0150150} -> J2SE Runtime Environment 5.0 Update 15 {32A3A4F4-B792-11D6-A78A-00B0D0150150} -> J2SE Development Kit 5.0 Update 15 {32D6A58F-9659-446C-BBFC-E6F2B41F24DC} -> Samsung Magic Doctor {36BEAD11-8577-49AD-9250-E06A50AE87B0} -> Microsoft SOAP Toolkit 2.0 SP2 {388E4B09-3E71-4649-8921-F44A3A2954A7} -> Microsoft Visual Studio 2005 Tools for Office Runtime {3A1B5E0E-250A-4322-9D86-6E27857743C1} -> F735 {3C3901C5-3455-3E0A-A214-0B093A5070A6} -> Microsoft .NET Framework 4 Client Profile {40BF1E83-20EB-11D8-97C5-0009C5020658} -> CyberLink Power2Go {42442BC6-5A92-4BC2-9E0C-3D359D548A21}_is1 -> Pazera Free MP4 to AVI Converter 1.5 {45235788-142C-44BE-8A4D-DDE9A84492E5} -> AGEIA PhysX v7.09.13 {491DF203-7B61-4F0E-BDCB-A1218C4DAFE9} -> Native Instruments Massive {4A03706F-666A-4037-7777-5F2748764D10} -> Java Auto Updater {4ac40384-37ba-421c-b14c-2ecbe4403817} -> Business Contact Manager z dodatkiem SP2 dla programu Outlook 2007 {4E0C89A4-4040-47C7-AD0C-0E8226B6AFE2} -> AVG 2012 {4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35} -> UnloadSupport {4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185} -> Easy Network Manager 3.0 {50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1 -> AVG PC Tuneup 2011 {53F5C3EE-05ED-4830-994B-50B2F0D50FCE} -> Microsoft SQL Server Setup Support Files (English) {5552453B-BB76-45E3-973D-F95E458ED780} -> Native Instruments Kontakt 5 {593A6CAF-E114-4e31-884F-74FF349E8E36} -> SolutionCenter {6395D480-9F3B-4930-8204-B91C8882F967} -> Stata 10 {65DA2EC9-0642-47E9-AAE2-B5267AA14D75} -> Activation Assistant for the 2007 Microsoft Office suites {66E6CE0C-5A1E-430C-B40A-0C90FF1804A8} -> eSupportQFolder {6811CAA0-BF12-11D4-9EA1-0050BAE317E1} -> PowerDVD {685707A4-911C-468D-BFC4-64A50E5E3A0C} -> Samsung Update Plus {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} -> Windows Media Player Firefox Plugin {6D12EC75-E7D3-4EAD-AB10-E1F3AFF94AA6} -> AVG 2012 {6F730513-8688-4C3C-90A3-6B9792CE2EF3} -> Easy Battery Manager {710f4c1c-cc18-4c49-8cbf-51240c89a1a2} -> Microsoft Visual C++ 2005 Redistributable {71A51B09-E7D3-11DB-A386-005056C00008} -> Vimicro UVC Camera {7299052b-02a4-4627-81f2-1818da5d550d} -> Microsoft Visual C++ 2005 Redistributable {7670D32F-DAE6-4E49-8C8B-B3F08B5B1686} -> Microsoft SQL Server Native Client {79907FEF-9A0B-4CE1-928F-E3A108D79BFD} -> Economic Freedom of the World 2010 {804F1285-8CBF-408D-8CDC-D4D40003B2E4} -> PlayCamera {82DA9C71-DBFF-4ED9-8B53-B2F28AA6BFD7} -> Syntorus 1.0.0 {837b34e3-7c30-493c-8f6a-2b0f04e2912c} -> Microsoft Visual C++ 2005 Redistributable {870D7C70-1961-467a-86E4-D67D329E8172} -> HP Deskjet F735 All-In-One Driver Software 11.0 Rel .4 {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} -> Microsoft Silverlight {8FB53850-246A-3507-8ADE-0060093FFEA6} -> Visual Studio Tools for the Office system 3.0 Runtime {90110415-6000-11D3-8CFE-0150048383C9} -> Microsoft Office Professional Edition 2003 {90120000-00D1-0409-0000-0000000FF1CE} -> Microsoft Office Access database engine 2007 (English) {90140000-0015-0415-0000-0000000FF1CE} -> Microsoft Office Access MUI (Polish) 2010 {90140000-0015-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-0016-0415-0000-0000000FF1CE} -> Microsoft Office Excel MUI (Polish) 2010 {90140000-0016-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-0018-0415-0000-0000000FF1CE} -> Microsoft Office PowerPoint MUI (Polish) 2010 {90140000-0018-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-0019-0415-0000-0000000FF1CE} -> Microsoft Office Publisher MUI (Polish) 2010 {90140000-0019-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-001A-0415-0000-0000000FF1CE} -> Microsoft Office Outlook MUI (Polish) 2010 {90140000-001A-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-001B-0415-0000-0000000FF1CE} -> Microsoft Office Word MUI (Polish) 2010 {90140000-001B-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-001F-0407-0000-0000000FF1CE} -> Microsoft Office Proof (German) 2010 {90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-001F-0409-0000-0000000FF1CE} -> Microsoft Office Proof (English) 2010 {90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-001F-0415-0000-0000000FF1CE} -> Microsoft Office Proof (Polish) 2010 {90140000-001F-0415-0000-0000000FF1CE}_Office14.SingleImage_{1D751709-BA6C-49E2-844B-4F4F20F410C9} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-002C-0415-0000-0000000FF1CE} -> Microsoft Office Proofing (Polish) 2010 {90140000-002C-0415-0000-0000000FF1CE}_Office14.SingleImage_{6606F321-8216-466E-981E-B75A14C46894} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-003D-0000-0000-0000000FF1CE} -> Microsoft Office Single Image 2010 {90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-006E-0415-0000-0000000FF1CE} -> Microsoft Office Shared MUI (Polish) 2010 {90140000-006E-0415-0000-0000000FF1CE}_Office14.SingleImage_{6AF8887A-72F7-4FA0-ABE4-396172B64550} -> Microsoft Office 2010 Service Pack 1 (SP1) {90140000-00A1-0415-0000-0000000FF1CE} -> Microsoft Office OneNote MUI (Polish) 2010 {90140000-00A1-0415-0000-0000000FF1CE}_Office14.SingleImage_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4} -> Microsoft Office 2010 Service Pack 1 (SP1) {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} -> Intel® Matrix Storage Manager {90A40415-6000-11D3-8CFE-0150048383C9} -> Microsoft Office 2003 Web Components {95120000-003F-0415-0000-0000000FF1CE} -> Microsoft Office Excel Viewer {955597D8-E5E1-474D-B647-60AC44566D24} -> Play AVStation {9A25302D-30C0-39D9-BD6F-21E6EC160475} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 {9BE518E6-ECC6-35A9-88E4-87755C07200F} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 {9C2D4047-0E40-499a-AC7A-C4B9BB12FE03} -> TrayApp {9EFDFBA8-9174-3C61-8645-28376C5CA994} -> Microsoft .NET Framework 3.5 Language Pack SP1 - plk {A939D341-5A04-4E0A-BB55-3E65B386432D} -> Składniki łączności pakietu Microsoft Office Small Business {AA2E8A46-B45E-4aea-8A23-88AB57D04523} -> WebReg {AB5D51AE-EBC3-438D-872C-705C7C2084B0} -> DeviceManagementQFolder {AC76BA86-7AD7-1045-7B44-A81200000003} -> Adobe Reader 8 - Polish {B32D4B38-38D9-45DB-93EC-F5473AA452A4} -> F735_Help {B7A0CE06-068E-11D6-97FD-0050BACBF861} -> PowerProducer {BA5F3E0E-8F3E-47BD-88E4-AD3EB5225F51} -> Oprogramowanie Intel(R) PROSet/Wireless WiFi {BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA} -> User Guide {BF08AB1C-3357-4f20-A200-8EBB8EF27C59} -> BufferChm {C59C179C-668D-49A9-B6EA-0121CCFC1243} -> LabelPrint {C89B5E3A-690F-4CEE-909A-BF869E198B0A} -> Scan {CB099890-1D5F-11D5-9EA9-0050BAE317E1} -> PowerDirector {CC0E1AE3-091D-4969-B151-7AC142062C28} -> SmartWebPrinting {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} -> Microsoft .NET Framework 3.5 SP1 {D063F201-FAC4-4D5C-B10B-615058ADE5A7} -> HP Update {D16B4BE6-8B10-422f-8034-96D1CA9483B5} -> GPBaseService {D1EE8DB1-BCA3-41E7-9178-ACFDDF2ECB64} -> DJ_AIO_04_F735_ProductContext {D541804F-B0ED-4B53-9A1D-6E2A7EE5E856} -> DJ_AIO_04_F735_Software {D74CFE48-087F-46E1-80E6-E2950E1A8DCE} -> HP Photosmart Essential 2.5 {DB14F755-2F5B-4A8A-96DB-3F408C5C002E} -> DJ_AIO_04_F735_Software_Min {DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} -> Ad-Aware {E133E97F-5186-4503-BEC8-752EB9E8EBD7} -> Copy {E3E71D07-CD27-46CB-8448-16D4FB29AA13} -> Microsoft WSE 3.0 Runtime {E535C94A-B87F-4182-BEA8-1E9322078D3E} -> Cards_Calendar_OrderGift_DoMorePlugout {E7084B89-69E0-46B3-A118-8F99D06988CD} -> Microsoft SQL Server VSS Writer {E96B0085-6659-486b-A221-5042A042728D} -> Toolbox {EC015649-3B3C-4611-9C66-453F8011E944} -> Native Instruments Kontakt 4 {EF1ADA5A-0B1A-4662-8C55-7475A61D8B65} -> DeviceDiscovery {EF367AA4-070B-493C-9575-85BE59D789C9} -> Easy SpeedUp Manager {EF9E56EE-0243-4BAD-88F4-5E7508AA7D96} -> Destination Component {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} -> Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} -> Realtek High Definition Audio Driver {F333A33D-125C-32A2-8DCE-5C5D14231E27} -> Visual C++ 2008 x86 Runtime - (v9.0.30729) {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01 -> Visual C++ 2008 x86 Runtime - v9.0.30729.01 {F7B0E599-C114-4493-BC4D-D8FC7CBBABBB} -> 32 Bit HP CIO Components Installer {F9390B82-786C-43CF-A970-D39E23EF0366} -> SAS 9.2 08b33f34fcc011da91e9a2a8b9a2fdce -> SAS Analytics Platform 1.5 Activation Assistant for the 2007 Microsoft Office suites -> Activation Assistant for the 2007 Microsoft Office suites Ad-Aware -> Ad-Aware Adobe Flash Player ActiveX -> Adobe Flash Player 10 ActiveX Adobe Flash Player Plugin -> Adobe Flash Player 11 Plugin Age of Empires 2.0 -> Microsoft Age of Empires II Age of Empires II - The Conquerors - 1.0e Patch FINAL_is1 -> Age of Empires II - The Conquerors - 1.0e Patch FINAL Agere Systems Soft Modem -> Agere Systems HDA Modem Alchemy -> Alchemy Artillery2 -> Artillery2 Audacity_is1 -> Audacity 1.2.6 AVG -> AVG 2012 Business Contact Manager -> Business Contact Manager z dodatkiem SP2 dla programu Outlook 2007 Camel Audio CamelCrusher -> Camel Audio CamelCrusher Combined Community Codec Pack_is1 -> Combined Community Codec Pack 2009-09-09 Cool Record Edit Deluxe -> Cool Record Edit Deluxe CPUID HWMonitor_is1 -> CPUID HWMonitor 1.19 Dev-C++ -> Dev-C++ 5 beta 9 release (4.9.9.2) energyXT 2.5.1_is1 -> energyXT 2.5.1 febb569a337f725f5f8607711f665d3b -> SAS Versioned Jar Repository 9.2 ffdshow_is1 -> ffdshow v1.1.3814 [2011-04-11] FL Studio 9 -> FL Studio 9 Football Manager 2008 -> Football Manager 2008 GameCenter -> GameCenter HP Imaging Device Functions -> HP Imaging Device Functions 11.0 HP Photosmart Essential -> HP Photosmart Essential 3.0 HP Smart Web Printing -> HP Smart Web Printing HP Solution Center & Imaging Support Tools -> HP Solution Center 11.0 IL Download Manager -> IL Download Manager InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185} -> Easy Network Manager 3.0 InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C} -> Samsung Update Plus InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24} -> Play AVStation iZotope RX 2_is1 -> iZotope RX 2 iZotope RX_is1 -> iZotope RX iZotope Vinyl_is1 -> iZotope Vinyl LUXONIX_LFX-1310 -> LUXONIX LFX-1310 Maxima-5.25.1_is1 -> Maxima 5.25.1 Microsoft .NET Framework 3.5 Language Pack SP1 - plk -> Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK Microsoft .NET Framework 3.5 SP1 -> Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile -> Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile PLK Language Pack -> Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile Microsoft SQL Server 2005 -> Microsoft SQL Server 2005 Microsoft Visual Studio 2005 Tools for Office Runtime -> Narzędzia programu Visual Studio 2005 Second Edition do obsługi pakietu Office Mozilla Firefox 14.0 (x86 pl) -> Mozilla Firefox 14.0 (x86 pl) MozillaMaintenanceService -> Mozilla Maintenance Service NapiProjekt_is1 -> NapiProjekt 1.0.6.9 Native Instruments Controller Editor -> Native Instruments Controller Editor Native Instruments Guitar Rig 5 -> Native Instruments Guitar Rig 5 Native Instruments Kontakt 5 -> Native Instruments Kontakt 5 Native Instruments Massive -> Native Instruments Massive Native Instruments Service Center -> Native Instruments Service Center Nowe Gadu-Gadu -> Nowe Gadu-Gadu NVIDIA Drivers -> NVIDIA Drivers Office14.SingleImage -> Microsoft Office Home and Student 2010 PoiZone -> PoiZone ProInst -> Intel PROSet Wireless R for Windows 2.11.1_is1 -> R for Windows 2.11.1 RayV -> RayV ReCycle2.2_32_is1 -> ReCycle 2.2.1 Rtools_is1 -> Rtools 2.11 Sawer -> Sawer Shop for HP Supplies -> Shop for HP Supplies Softube FET Compressor VST RTAS_is1 -> Softube FET Compressor VST RTAS v1.0.3 SopCast -> SopCast 3.2.4 SubtitleWorkshop -> Subtitle Workshop 2.51 SynTPDeinstKey -> Synaptics Pointing Device Driver Toxic Biohazard -> Toxic Biohazard TransMac_is1 -> TransMac version 9.2 Trilogy_is1 -> Trilogy TruePianos: Amber Module_is1 -> TruePianos: Amber Module 1.4.0 TruePianos: Diamond Module_is1 -> TruePianos: Diamond Module 1.4.0 TruePianos: Emerald Module_is1 -> TruePianos: Emerald Module 1.4.0 TruePianos: Sapphire Module (Pedal sounds included)_is1 -> TruePianos: Sapphire Module 1.4.0 TruePianos: Sapphire Module_is1 -> TruePianos: Sapphire Module 1.4.0 TruePianos_is1 -> TruePianos 1.4.1 uTorrent -> µTorrent VideoPad -> VideoPad Video Editor Visual Studio Tools for the Office system 3.0 Runtime -> Visual Studio Tools for the Office system 3.0 Runtime VLC media player -> VLC media player 1.1.11 Winamp -> Winamp WinGimp-2.0_is1 -> GIMP 2.6.5 WinRAR archiver -> WinRAR 4.11 (32-bitowy) < Uninstall List [HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\] > -> HKEY_USERS\S-1-5-21-546161319-117832074-527936877-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> Sansa Updater -> Sansa Updater < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2012-07-12 15:42:40 Computer Name = Piotrek | Source = SAS | ID = 2400 -> Description = SAS Error Event: Failed to initialize cradle support Application [ Error ] 2012-07-12 15:43:05 Computer Name = Piotrek | Source = WinMgmt | ID = 10 -> Description = Application [ Error ] 2012-07-12 15:48:58 Computer Name = Piotrek | Source = SAS | ID = 2400 -> Description = SAS Error Event: Failed to initialize cradle support Application [ Error ] 2012-07-12 15:49:50 Computer Name = Piotrek | Source = WinMgmt | ID = 10 -> Description = Application [ Error ] 2012-07-12 16:08:12 Computer Name = Piotrek | Source = WinMgmt | ID = 10 -> Description = Application [ Error ] 2012-07-12 16:26:07 Computer Name = Piotrek | Source = EventSystem | ID = 4609 -> Description = Application [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = WinMgmt | ID = 10 -> Description = Application [ Error ] 2012-07-12 16:32:50 Computer Name = Piotrek | Source = LoadPerf | ID = 3012 -> Description = Application [ Error ] 2012-07-12 16:32:51 Computer Name = Piotrek | Source = LoadPerf | ID = 3012 -> Description = Application [ Error ] 2012-07-12 16:32:51 Computer Name = Piotrek | Source = LoadPerf | ID = 3011 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7026 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 16:27:11 Computer Name = Piotrek | Source = Service Control Manager | ID = 7001 -> Description = System [ Error ] 2012-07-12 17:18:11 Computer Name = Piotrek | Source = volsnap | ID = 393252 -> Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. [Files/Folders - Created Within 30 Days] hellomoto -> C:\Users\EuroRtvAgd\AppData\Roaming\hellomoto -> [2012-07-11 23:13:41 | 000,000,000 | ---D | C] ind-fabfilsaturn101 -> C:\Users\EuroRtvAgd\Desktop\ind-fabfilsaturn101 -> [2012-07-10 22:37:58 | 000,000,000 | ---D | C] Camel Audio -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camel Audio -> [2012-07-07 15:22:44 | 000,000,000 | ---D | C] Camel Audio -> C:\ProgramData\Camel Audio -> [2012-07-07 15:22:44 | 000,000,000 | ---D | C] Camel Audio -> C:\Program Files\Camel Audio -> [2012-07-07 15:22:44 | 000,000,000 | ---D | C] AVG -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG -> [2012-07-06 10:43:03 | 000,000,000 | ---D | C] projmal -> C:\Users\EuroRtvAgd\Desktop\projmal -> [2012-07-03 13:24:53 | 000,000,000 | ---D | C] Propellerhead -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Propellerhead -> [2012-07-01 13:20:33 | 000,000,000 | ---D | C] Lokale Einstellungen -> C:\Users\EuroRtvAgd\Lokale Einstellungen -> [2012-07-01 13:06:55 | 000,000,000 | ---D | C] energyXT 2.5.1 -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\energyXT 2.5.1 -> [2012-07-01 12:40:31 | 000,000,000 | ---D | C] energyXT -> C:\Program Files\energyXT -> [2012-07-01 12:40:30 | 000,000,000 | ---D | C] Propellerhead -> C:\Program Files\Propellerhead -> [2012-07-01 12:10:00 | 000,000,000 | ---D | C] Propellerhead Software -> C:\Users\EuroRtvAgd\AppData\Roaming\Propellerhead Software -> [2012-07-01 11:58:41 | 000,000,000 | ---D | C] Propellerhead Software -> C:\ProgramData\Propellerhead Software -> [2012-07-01 11:58:41 | 000,000,000 | ---D | C] REX Shared Library.dll -> C:\Windows\System32\REX Shared Library.dll -> [2012-07-01 11:56:25 | 000,233,472 | --S- | C] (Propellerhead Software AB) perkusja -> C:\Users\EuroRtvAgd\Desktop\perkusja -> [2012-06-27 14:35:18 | 000,000,000 | ---D | C] iZotope RX 2 Presets -> C:\Users\EuroRtvAgd\Documents\iZotope RX 2 Presets -> [2012-06-27 13:01:21 | 000,000,000 | ---D | C] {95B4F0ED-951F-4D36-B068-5EC1C4C19C14} -> C:\ProgramData\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14} -> [2012-06-26 19:09:19 | 000,000,000 | -H-D | C] {A9158F4E-7914-4019-808A-D4D4993E9958} -> C:\ProgramData\{A9158F4E-7914-4019-808A-D4D4993E9958} -> [2012-06-26 19:07:13 | 000,000,000 | -H-D | C] Sugar Bytes -> C:\Program Files\Sugar Bytes -> [2012-06-26 18:52:40 | 000,000,000 | ---D | C] Daichi -> C:\Users\EuroRtvAgd\AppData\Roaming\Daichi -> [2012-06-26 18:02:14 | 000,000,000 | ---D | C] eSellerate -> C:\ProgramData\eSellerate -> [2012-06-21 01:21:42 | 000,000,000 | ---D | C] Expert Sleepers -> C:\Users\EuroRtvAgd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Expert Sleepers -> [2012-06-21 01:20:47 | 000,000,000 | ---D | C] PiS -> C:\Users\EuroRtvAgd\Desktop\PiS -> [2012-06-18 12:58:07 | 000,000,000 | ---D | C] AVG Secure Search -> C:\Users\EuroRtvAgd\AppData\Local\AVG Secure Search -> [2012-06-13 10:19:46 | 000,000,000 | ---D | C] 1 C:\Windows\Fonts\*.tmp files -> C:\Windows\Fonts\*.tmp -> [Files/Folders - Modified Within 30 Days] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\EuroRtvAgd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2012-07-12 23:16:12 | 000,093,696 | ---- | M] () perfh015.dat -> C:\Windows\System32\perfh015.dat -> [2012-07-12 22:32:55 | 019,741,198 | ---- | M] () perfc015.dat -> C:\Windows\System32\perfc015.dat -> [2012-07-12 22:32:55 | 007,089,262 | ---- | M] () perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2012-07-12 22:32:54 | 007,650,828 | ---- | M] () perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2012-07-12 22:32:54 | 006,858,618 | ---- | M] () bootstat.dat -> C:\Windows\bootstat.dat -> [2012-07-12 22:25:36 | 000,067,584 | --S- | M] () Ikeext.etl -> C:\Windows\System32\Ikeext.etl -> [2012-07-12 22:24:11 | 000,196,608 | ---- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 22:24:10 | 000,004,784 | -H-- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 22:24:10 | 000,004,784 | -H-- | M] () bthservsdp.dat -> C:\Windows\bthservsdp.dat -> [2012-07-12 22:24:10 | 000,000,012 | ---- | M] () User_Feed_Synchronization-{1B636BC3-B688-48E3-827A-B88A3F7A5DCC}.job -> C:\Windows\tasks\User_Feed_Synchronization-{1B636BC3-B688-48E3-827A-B88A3F7A5DCC}.job -> [2012-07-12 22:20:10 | 000,000,428 | -H-- | M] () nvModes.001 -> C:\ProgramData\nvModes.001 -> [2012-07-12 22:13:26 | 000,096,112 | ---- | M] () nvModes.dat -> C:\ProgramData\nvModes.dat -> [2012-07-12 22:13:21 | 000,096,112 | ---- | M] () incavi.avm -> C:\Windows\System32\drivers\AVG\incavi.avm -> [2012-07-12 17:17:11 | 101,389,091 | ---- | M] () Ad-Aware Update (Weekly).job -> C:\Windows\tasks\Ad-Aware Update (Weekly).job -> [2012-07-10 22:32:00 | 000,000,472 | ---- | M] () iavichjg.avm -> C:\Windows\System32\drivers\AVG\iavichjg.avm -> [2012-07-10 18:56:50 | 000,443,535 | ---- | M] () Samples Alchemy.lnk -> C:\Users\EuroRtvAgd\Desktop\Samples Alchemy.lnk -> [2012-07-09 12:59:02 | 000,001,037 | ---- | M] () newnew.flp -> C:\Users\EuroRtvAgd\Desktop\newnew.flp -> [2012-07-06 20:31:19 | 075,254,487 | ---- | M] () AVG 2012.lnk -> C:\Users\Public\Desktop\AVG 2012.lnk -> [2012-07-06 10:43:03 | 000,000,872 | ---- | M] () pattern.flp -> C:\Users\EuroRtvAgd\Desktop\pattern.flp -> [2012-07-05 17:10:36 | 000,617,023 | ---- | M] () iZotope RX 2.lnk -> C:\Users\EuroRtvAgd\Desktop\iZotope RX 2.lnk -> [2012-06-27 13:10:29 | 000,000,996 | ---- | M] () BarChimes_User_Guide.pdf -> C:\Users\EuroRtvAgd\Desktop\BarChimes_User_Guide.pdf -> [2012-06-26 23:01:18 | 000,869,164 | ---- | M] () Service Center.lnk -> C:\Users\Public\Desktop\Service Center.lnk -> [2012-06-26 19:09:18 | 000,000,966 | ---- | M] () d3d9caps.dat -> C:\Users\EuroRtvAgd\AppData\Local\d3d9caps.dat -> [2012-06-18 18:59:01 | 000,000,680 | ---- | M] () gplot3.png -> C:\Users\EuroRtvAgd\gplot3.png -> [2012-06-15 20:11:24 | 000,034,075 | ---- | M] () sashtml24.htm -> C:\Users\EuroRtvAgd\sashtml24.htm -> [2012-06-15 20:11:24 | 000,028,962 | ---- | M] () gplot2.png -> C:\Users\EuroRtvAgd\gplot2.png -> [2012-06-15 20:09:10 | 000,034,745 | ---- | M] () sashtml23.htm -> C:\Users\EuroRtvAgd\sashtml23.htm -> [2012-06-15 20:09:10 | 000,028,966 | ---- | M] () gplot1.png -> C:\Users\EuroRtvAgd\gplot1.png -> [2012-06-15 20:05:06 | 000,034,477 | ---- | M] () sashtml22.htm -> C:\Users\EuroRtvAgd\sashtml22.htm -> [2012-06-15 20:05:06 | 000,028,962 | ---- | M] () sashtml21.htm -> C:\Users\EuroRtvAgd\sashtml21.htm -> [2012-06-15 20:03:18 | 000,049,563 | ---- | M] () sashtml20.htm -> C:\Users\EuroRtvAgd\sashtml20.htm -> [2012-06-15 20:01:46 | 000,049,608 | ---- | M] () sashtml19.htm -> C:\Users\EuroRtvAgd\sashtml19.htm -> [2012-06-15 19:59:36 | 000,028,961 | ---- | M] () gplot.png -> C:\Users\EuroRtvAgd\gplot.png -> [2012-06-15 19:59:35 | 000,035,043 | ---- | M] () sashtml18.htm -> C:\Users\EuroRtvAgd\sashtml18.htm -> [2012-06-15 19:58:06 | 000,043,128 | ---- | M] () sashtml17.htm -> C:\Users\EuroRtvAgd\sashtml17.htm -> [2012-06-15 19:55:53 | 000,043,098 | ---- | M] () sashtml16.htm -> C:\Users\EuroRtvAgd\sashtml16.htm -> [2012-06-15 19:54:23 | 000,043,097 | ---- | M] () sashtml15.htm -> C:\Users\EuroRtvAgd\sashtml15.htm -> [2012-06-15 19:54:02 | 000,043,127 | ---- | M] () sashtml14.htm -> C:\Users\EuroRtvAgd\sashtml14.htm -> [2012-06-15 19:53:48 | 000,043,127 | ---- | M] () sashtml13.htm -> C:\Users\EuroRtvAgd\sashtml13.htm -> [2012-06-15 19:53:32 | 000,042,272 | ---- | M] () sashtml12.htm -> C:\Users\EuroRtvAgd\sashtml12.htm -> [2012-06-15 19:53:10 | 000,043,114 | ---- | M] () sashtml11.htm -> C:\Users\EuroRtvAgd\sashtml11.htm -> [2012-06-15 19:52:56 | 000,043,114 | ---- | M] () sashtml10.htm -> C:\Users\EuroRtvAgd\sashtml10.htm -> [2012-06-15 19:52:40 | 000,043,103 | ---- | M] () sashtml9.htm -> C:\Users\EuroRtvAgd\sashtml9.htm -> [2012-06-15 19:51:47 | 000,043,097 | ---- | M] () sashtml8.htm -> C:\Users\EuroRtvAgd\sashtml8.htm -> [2012-06-15 19:51:22 | 000,055,947 | ---- | M] () sashtml7.htm -> C:\Users\EuroRtvAgd\sashtml7.htm -> [2012-06-15 19:50:30 | 000,043,078 | ---- | M] () sashtml6.htm -> C:\Users\EuroRtvAgd\sashtml6.htm -> [2012-06-15 19:50:16 | 000,047,280 | ---- | M] () sashtml5.htm -> C:\Users\EuroRtvAgd\sashtml5.htm -> [2012-06-15 19:49:33 | 000,047,280 | ---- | M] () sashtml4.htm -> C:\Users\EuroRtvAgd\sashtml4.htm -> [2012-06-15 19:48:03 | 000,047,292 | ---- | M] () sashtml3.htm -> C:\Users\EuroRtvAgd\sashtml3.htm -> [2012-06-15 19:47:37 | 000,047,296 | ---- | M] () sashtml2.htm -> C:\Users\EuroRtvAgd\sashtml2.htm -> [2012-06-15 19:47:01 | 000,047,293 | ---- | M] () sashtml1.htm -> C:\Users\EuroRtvAgd\sashtml1.htm -> [2012-06-15 19:46:02 | 000,030,472 | ---- | M] () sashtml.htm -> C:\Users\EuroRtvAgd\sashtml.htm -> [2012-06-15 19:45:23 | 000,030,471 | ---- | M] () 6 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> 6 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> [Files - No Company Name] 10.The End.mp3 -> C:\Users\EuroRtvAgd\Desktop\10.The End.mp3 -> [2012-07-10 13:58:45 | 011,259,912 | ---- | C] () Samples Alchemy.lnk -> C:\Users\EuroRtvAgd\Desktop\Samples Alchemy.lnk -> [2012-07-09 12:59:02 | 000,001,037 | ---- | C] () 12 Orquesta Sinfonica de Malaga - k) Tunc Imponent.wav -> C:\Users\EuroRtvAgd\Desktop\12 Orquesta Sinfonica de Malaga - k) Tunc Imponent.wav -> [2012-07-07 14:06:03 | 010,746,676 | ---- | C] () newnew.flp -> C:\Users\EuroRtvAgd\Desktop\newnew.flp -> [2012-07-06 20:01:38 | 075,254,487 | ---- | C] () pattern.flp -> C:\Users\EuroRtvAgd\Desktop\pattern.flp -> [2012-07-05 16:17:03 | 000,617,023 | ---- | C] () LOOP.exe -> C:\Windows\LOOP.exe -> [2012-07-01 11:55:53 | 000,331,263 | ---- | C] () iZotope RX 2.lnk -> C:\Users\EuroRtvAgd\Desktop\iZotope RX 2.lnk -> [2012-06-27 13:10:29 | 000,000,996 | ---- | C] () BarChimes_User_Guide.pdf -> C:\Users\EuroRtvAgd\Desktop\BarChimes_User_Guide.pdf -> [2012-06-26 23:01:18 | 000,869,164 | ---- | C] () Service Center.lnk -> C:\Users\Public\Desktop\Service Center.lnk -> [2012-06-26 19:09:18 | 000,000,966 | ---- | C] () gplot3.png -> C:\Users\EuroRtvAgd\gplot3.png -> [2012-06-15 20:11:24 | 000,034,075 | ---- | C] () sashtml24.htm -> C:\Users\EuroRtvAgd\sashtml24.htm -> [2012-06-15 20:11:24 | 000,028,962 | ---- | C] () gplot2.png -> C:\Users\EuroRtvAgd\gplot2.png -> [2012-06-15 20:09:10 | 000,034,745 | ---- | C] () sashtml23.htm -> C:\Users\EuroRtvAgd\sashtml23.htm -> [2012-06-15 20:09:09 | 000,028,966 | ---- | C] () gplot1.png -> C:\Users\EuroRtvAgd\gplot1.png -> [2012-06-15 20:05:06 | 000,034,477 | ---- | C] () sashtml22.htm -> C:\Users\EuroRtvAgd\sashtml22.htm -> [2012-06-15 20:05:05 | 000,028,962 | ---- | C] () sashtml21.htm -> C:\Users\EuroRtvAgd\sashtml21.htm -> [2012-06-15 20:03:18 | 000,049,563 | ---- | C] () sashtml20.htm -> C:\Users\EuroRtvAgd\sashtml20.htm -> [2012-06-15 20:01:46 | 000,049,608 | ---- | C] () gplot.png -> C:\Users\EuroRtvAgd\gplot.png -> [2012-06-15 19:59:35 | 000,035,043 | ---- | C] () sashtml19.htm -> C:\Users\EuroRtvAgd\sashtml19.htm -> [2012-06-15 19:59:35 | 000,028,961 | ---- | C] () sashtml18.htm -> C:\Users\EuroRtvAgd\sashtml18.htm -> [2012-06-15 19:58:06 | 000,043,128 | ---- | C] () sashtml17.htm -> C:\Users\EuroRtvAgd\sashtml17.htm -> [2012-06-15 19:55:53 | 000,043,098 | ---- | C] () sashtml16.htm -> C:\Users\EuroRtvAgd\sashtml16.htm -> [2012-06-15 19:54:23 | 000,043,097 | ---- | C] () sashtml15.htm -> C:\Users\EuroRtvAgd\sashtml15.htm -> [2012-06-15 19:54:02 | 000,043,127 | ---- | C] () sashtml14.htm -> C:\Users\EuroRtvAgd\sashtml14.htm -> [2012-06-15 19:53:48 | 000,043,127 | ---- | C] () sashtml13.htm -> C:\Users\EuroRtvAgd\sashtml13.htm -> [2012-06-15 19:53:32 | 000,042,272 | ---- | C] () sashtml12.htm -> C:\Users\EuroRtvAgd\sashtml12.htm -> [2012-06-15 19:53:10 | 000,043,114 | ---- | C] () sashtml11.htm -> C:\Users\EuroRtvAgd\sashtml11.htm -> [2012-06-15 19:52:56 | 000,043,114 | ---- | C] () sashtml10.htm -> C:\Users\EuroRtvAgd\sashtml10.htm -> [2012-06-15 19:52:40 | 000,043,103 | ---- | C] () sashtml9.htm -> C:\Users\EuroRtvAgd\sashtml9.htm -> [2012-06-15 19:51:47 | 000,043,097 | ---- | C] () sashtml8.htm -> C:\Users\EuroRtvAgd\sashtml8.htm -> [2012-06-15 19:51:22 | 000,055,947 | ---- | C] () sashtml7.htm -> C:\Users\EuroRtvAgd\sashtml7.htm -> [2012-06-15 19:50:30 | 000,043,078 | ---- | C] () sashtml6.htm -> C:\Users\EuroRtvAgd\sashtml6.htm -> [2012-06-15 19:50:16 | 000,047,280 | ---- | C] () sashtml5.htm -> C:\Users\EuroRtvAgd\sashtml5.htm -> [2012-06-15 19:49:33 | 000,047,280 | ---- | C] () sashtml4.htm -> C:\Users\EuroRtvAgd\sashtml4.htm -> [2012-06-15 19:48:03 | 000,047,292 | ---- | C] () sashtml3.htm -> C:\Users\EuroRtvAgd\sashtml3.htm -> [2012-06-15 19:47:37 | 000,047,296 | ---- | C] () sashtml2.htm -> C:\Users\EuroRtvAgd\sashtml2.htm -> [2012-06-15 19:47:01 | 000,047,293 | ---- | C] () sashtml1.htm -> C:\Users\EuroRtvAgd\sashtml1.htm -> [2012-06-15 19:46:02 | 000,030,472 | ---- | C] () sashtml.htm -> C:\Users\EuroRtvAgd\sashtml.htm -> [2012-06-15 19:45:22 | 000,030,471 | ---- | C] () pdfcmnnt.dll -> C:\Windows\System32\pdfcmnnt.dll -> [2011-08-29 13:12:20 | 000,116,224 | ---- | C] () ODBC.INI -> C:\Windows\ODBC.INI -> [2011-08-01 21:03:48 | 000,000,412 | ---- | C] () sasperf.dll -> C:\Windows\System32\sasperf.dll -> [2011-06-28 17:28:23 | 000,077,824 | ---- | C] () grcauth2.dll -> C:\Windows\System32\grcauth2.dll -> [2011-06-28 10:13:44 | 000,001,024 | ---- | C] () grcauth1.dll -> C:\Windows\System32\grcauth1.dll -> [2011-06-28 10:13:44 | 000,001,024 | ---- | C] () prsgrc.dll -> C:\Windows\System32\prsgrc.dll -> [2011-06-28 10:13:44 | 000,000,100 | ---- | C] () sysprs7.dll -> C:\Windows\System32\sysprs7.dll -> [2011-06-28 10:08:43 | 000,001,025 | ---- | C] () lsprst7.dll -> C:\Windows\System32\lsprst7.dll -> [2011-06-28 10:08:43 | 000,000,205 | ---- | C] () ff_vfw.dll -> C:\Windows\System32\ff_vfw.dll -> [2011-04-16 19:52:18 | 000,080,896 | ---- | C] () C -> C:\Users\EuroRtvAgd\AppData\Local\C -> [2011-01-06 13:08:47 | 000,000,000 | ---- | C] () [File - Lop Check] AVG -> C:\Users\EuroRtvAgd\AppData\Roaming\AVG -> [2010-12-19 22:24:10 | 000,000,000 | ---D | M] AVG2012 -> C:\Users\EuroRtvAgd\AppData\Roaming\AVG2012 -> [2012-06-05 10:41:30 | 000,000,000 | ---D | M] Braid -> C:\Users\EuroRtvAgd\AppData\Roaming\Braid -> [2009-09-28 17:01:14 | 000,000,000 | ---D | M] Celemony Software GmbH -> C:\Users\EuroRtvAgd\AppData\Roaming\Celemony Software GmbH -> [2012-07-10 00:23:32 | 000,000,000 | ---D | M] Cool Record Edit Deluxe -> C:\Users\EuroRtvAgd\AppData\Roaming\Cool Record Edit Deluxe -> [2011-09-16 12:54:35 | 000,000,000 | ---D | M] DAEMON Tools Lite -> C:\Users\EuroRtvAgd\AppData\Roaming\DAEMON Tools Lite -> [2009-02-10 13:51:32 | 000,000,000 | ---D | M] Daichi -> C:\Users\EuroRtvAgd\AppData\Roaming\Daichi -> [2012-06-26 18:02:14 | 000,000,000 | ---D | M] Dev-Cpp -> C:\Users\EuroRtvAgd\AppData\Roaming\Dev-Cpp -> [2009-09-28 14:08:10 | 000,000,000 | ---D | M] DriverCure -> C:\Users\EuroRtvAgd\AppData\Roaming\DriverCure -> [2009-06-29 15:15:43 | 000,000,000 | ---D | M] gtk-2.0 -> C:\Users\EuroRtvAgd\AppData\Roaming\gtk-2.0 -> [2011-09-19 16:25:24 | 000,000,000 | ---D | M] hellomoto -> C:\Users\EuroRtvAgd\AppData\Roaming\hellomoto -> [2012-07-11 23:13:49 | 000,000,000 | ---D | M] iZotope -> C:\Users\EuroRtvAgd\AppData\Roaming\iZotope -> [2012-07-02 00:10:56 | 000,000,000 | ---D | M] Nowe Gadu-Gadu -> C:\Users\EuroRtvAgd\AppData\Roaming\Nowe Gadu-Gadu -> [2011-12-11 14:23:00 | 000,000,000 | ---D | M] OpenFM -> C:\Users\EuroRtvAgd\AppData\Roaming\OpenFM -> [2009-11-23 17:43:28 | 000,000,000 | ---D | M] OpenOffice.org -> C:\Users\EuroRtvAgd\AppData\Roaming\OpenOffice.org -> [2009-03-31 21:15:16 | 000,000,000 | ---D | M] PeerNetworking -> C:\Users\EuroRtvAgd\AppData\Roaming\PeerNetworking -> [2009-04-01 22:54:29 | 000,000,000 | ---D | M] Pro Cycling Manager 2009 -> C:\Users\EuroRtvAgd\AppData\Roaming\Pro Cycling Manager 2009 -> [2009-09-15 19:07:15 | 000,000,000 | ---D | M] Propellerhead Software -> C:\Users\EuroRtvAgd\AppData\Roaming\Propellerhead Software -> [2012-07-01 12:14:23 | 000,000,000 | ---D | M] SanDisk -> C:\Users\EuroRtvAgd\AppData\Roaming\SanDisk -> [2009-02-16 18:04:10 | 000,000,000 | ---D | M] SAS -> C:\Users\EuroRtvAgd\AppData\Roaming\SAS -> [2011-10-24 19:35:16 | 000,000,000 | ---D | M] Sports Interactive -> C:\Users\EuroRtvAgd\AppData\Roaming\Sports Interactive -> [2009-02-22 00:19:33 | 000,000,000 | ---D | M] Stata10 -> C:\Users\EuroRtvAgd\AppData\Roaming\Stata10 -> [2010-12-15 10:27:34 | 000,000,000 | ---D | M] The Path -> C:\Users\EuroRtvAgd\AppData\Roaming\The Path -> [2009-09-27 11:16:06 | 000,000,000 | ---D | M] URSoft -> C:\Users\EuroRtvAgd\AppData\Roaming\URSoft -> [2009-06-16 23:07:35 | 000,000,000 | ---D | M] uTorrent -> C:\Users\EuroRtvAgd\AppData\Roaming\uTorrent -> [2012-07-09 14:44:30 | 000,000,000 | ---D | M] AVG2012 -> C:\Users\Gość\AppData\Roaming\AVG2012 -> [2012-06-05 10:41:31 | 000,000,000 | ---D | M] Nowe Gadu-Gadu -> C:\Users\Gość\AppData\Roaming\Nowe Gadu-Gadu -> [2011-01-12 19:00:43 | 000,000,000 | ---D | M] OpenOffice.org -> C:\Users\Gość\AppData\Roaming\OpenOffice.org -> [2009-08-07 15:12:23 | 000,000,000 | ---D | M] RayV -> C:\Users\Gość\AppData\Roaming\RayV -> [2012-06-07 20:19:41 | 000,000,000 | ---D | M] RayV -> C:\Users\Miki\AppData\Roaming\RayV -> [2010-01-10 20:15:20 | 000,000,000 | ---D | M] Ad-Aware Update (Weekly).job -> C:\Windows\Tasks\Ad-Aware Update (Weekly).job -> [2012-07-10 22:32:00 | 000,000,472 | ---- | M] () SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2012-07-12 22:24:10 | 000,032,544 | ---- | M] () User_Feed_Synchronization-{1B636BC3-B688-48E3-827A-B88A3F7A5DCC}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{1B636BC3-B688-48E3-827A-B88A3F7A5DCC}.job -> [2012-07-12 22:20:10 | 000,000,428 | -H-- | M] () [File - Purity Scan] [Alternate Data Streams] @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:B3D74A13 @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4 @Alternate Data Stream - 487 bytes -> C:\ProgramData\TEMP:05EE1EEF < End of report > [/code]