[code] OTS logfile created on: 2010-09-26 13:25:55 - Run 1 OTS by OldTimer - Version 3.1.38.1 Folder = C:\Users\Maciej\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18813) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 45,00% Memory free 8,00 Gb Paging File | 5,00 Gb Available in Paging File | 65,00% Paging File free Paging file location(s): ?:\pagefile.sys %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 117,19 Gb Total Space | 46,60 Gb Free Space | 39,77% Space Free | Partition Type: NTFS Drive D: | 112,99 Gb Total Space | 80,86 Gb Free Space | 71,56% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PRODOM Current User Name: Maciej Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days [Processes - Safe List] ots.exe -> C:\Users\Maciej\Desktop\OTS.exe -> [2010-09-26 13:24:24 | 000,641,536 | ---- | M] (OldTimer Tools) easymetin2.exe -> C:\Users\Maciej\Desktop\EM2PL\EM2PL\EM2PL\Easymetin2.exe -> [2010-09-20 13:32:56 | 001,253,376 | ---- | M] (TODO: ) plugin-container.exe -> C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe -> [2010-09-16 21:51:42 | 000,014,808 | ---- | M] (Mozilla Corporation) firefox.exe -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe -> [2010-09-16 21:51:41 | 000,910,296 | ---- | M] (Mozilla Corporation) metin2client.bin -> C:\Users\Maciej\Desktop\Metin2 - Kopia\metin2client.bin -> [2010-08-11 09:18:55 | 000,952,266 | ---- | M] () gbtray.exe -> C:\Program Files (x86)\IObit\Game Booster\gbtray.exe -> [2010-08-03 10:55:18 | 000,175,960 | ---- | M] () psanhost.exe -> C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe -> [2010-04-30 13:47:28 | 000,136,448 | ---- | M] (Panda Security, S.L.) winamp.exe -> C:\Program Files (x86)\Winamp\winamp.exe -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) sdwinsec.exe -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009-01-26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) gg.exe -> C:\Program Files (x86)\Gadu-Gadu\gg.exe -> [2008-03-20 12:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) nmsaccessu.exe -> C:\Program Files (x86)\Common Files\NMSAccessU.exe -> [2007-01-25 03:52:26 | 000,065,536 | ---- | M] () [Modules - Safe List] ots.exe -> C:\Users\Maciej\Desktop\OTS.exe -> [2010-09-26 13:24:24 | 000,641,536 | ---- | M] (OldTimer Tools) msscript.ocx -> C:\Windows\SysWOW64\msscript.ocx -> [2008-01-19 09:33:00 | 000,110,592 | ---- | M] (Microsoft Corporation) comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll -> [2008-01-19 09:26:34 | 001,684,480 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] 64bit-(rpcapd) [On_Demand | Stopped] -> C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini -> File not found 64bit-(npggsvc) [On_Demand | Stopped] -> C:\Windows\SysNative\GameMon.des -> File not found 64bit-(cFosSpeedS) [Disabled | Stopped] -> C:\Program Files\cFosSpeed\spd.exe -> [2010-01-05 12:41:24 | 000,563,928 | R--- | M] (cFos Software GmbH) 64bit-(WinDefend) [Auto | Running] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-19 10:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) (Steam Client Service) Steam Client Service [On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Steam\SteamService.exe -> [2010-09-20 13:27:39 | 000,411,432 | ---- | M] (Valve Corporation) (AVP) Kaspersky Anti-Virus [Auto | Stopped] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe -> [2010-09-02 15:34:27 | 000,340,520 | ---- | M] (Kaspersky Lab) (npggsvc) nProtect GameGuard Service [On_Demand | Stopped] -> C:\Windows\SysWow64\GameMon.des -> [2010-05-06 15:12:28 | 000,000,097 | ---- | M] () (NanoServiceMain) Panda Cloud Antivirus Service [Auto | Running] -> C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe -> [2010-04-30 13:47:28 | 000,136,448 | ---- | M] (Panda Security, S.L.) (Hamachi2Svc) LogMeIn Hamachi 2.0 Tunneling Engine [Auto | Running] -> C:\Program Files (x86)\Hamachi\hamachi-2.exe -> [2010-03-30 11:16:14 | 001,823,112 | ---- | M] (LogMeIn Inc.) (aspnet_state) „Usługa stanu ASP.NET [On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe -> [2010-03-18 17:23:04 | 000,044,376 | ---- | M] (Microsoft Corporation) (WPFFontCache_v0400) Windows Presentation Foundation Font Cache 4.0.0.0 [On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -> [2010-03-18 14:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) (clr_optimization_v4.0.30319_64) Microsoft .NET Framework NGEN v4.0.30319_X64 [Auto | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -> [2010-03-18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) (clr_optimization_v4.0.30319_32) Microsoft .NET Framework NGEN v4.0.30319_X86 [Auto | Stopped] -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -> [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) (SBSDWSCService) SBSD Security Center Service [Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009-01-26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) (FLEXnet Licensing Service) FLEXnet Licensing Service [On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008-04-28 20:17:00 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) (NMSAccessU) NMSAccessU [Auto | Running] -> C:\Program Files (x86)\Common Files\NMSAccessU.exe -> [2007-01-25 03:52:26 | 000,065,536 | ---- | M] () [Driver Services - Safe List] 64bit-(NwlnkFwd) IPX Traffic Forwarder Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -> File not found 64bit-(NwlnkFlt) IPX Traffic Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -> File not found 64bit-(NPPTNT2) NPPTNT2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\npptNT2.sys -> File not found 64bit-(IpInIp) IP in IP Tunnel Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\ipinip.sys -> File not found 64bit-(KLIF) Kaspersky Lab Driver [File_System | System | Running] -> C:\Windows\SysNative\DRIVERS\klif.sys -> [2010-07-19 14:46:23 | 000,353,296 | ---- | M] () 64bit-(cpuz134) cpuz134 [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\cpuz134_x64.sys -> [2010-07-09 13:19:02 | 000,021,480 | ---- | M] () 64bit-(PSINAflt) PSINAflt [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSINAflt.sys -> [2010-05-27 18:39:36 | 000,158,280 | ---- | M] () 64bit-(PSINProt) PSINProt [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSINProt.sys -> [2010-05-12 10:58:00 | 000,126,024 | ---- | M] () 64bit-(PSINKNC) PSINKNC [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\psinknc.sys -> [2010-05-04 08:36:40 | 000,149,512 | ---- | M] () 64bit-(PSINProc) PSINProc [File_System | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSINProc.sys -> [2010-04-30 13:46:39 | 000,121,864 | ---- | M] () 64bit-(PSINFile) PSINFile [File_System | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSINFile.sys -> [2010-04-30 13:46:37 | 000,114,696 | ---- | M] () 64bit-(cFosSpeed) cFosSpeed Miniport [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\cfosspeed.sys -> [2010-01-05 12:41:26 | 001,224,408 | ---- | M] () 64bit-(KLBG) Kaspersky Lab Boot Guard Driver [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\klbg.sys -> [2009-10-14 20:18:38 | 000,040,464 | ---- | M] () 64bit-(klmouflt) Kaspersky Lab KLMOUFLT [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\klmouflt.sys -> [2009-10-02 18:39:32 | 000,021,008 | ---- | M] () 64bit-(hamachi) Hamachi Network Interface [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\hamachi.sys -> [2009-09-23 10:42:58 | 000,033,856 | -H-- | M] () 64bit-(KLIM6) Kaspersky Anti-Virus NDIS 6 Filter [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\klim6.sys -> [2009-09-14 13:46:42 | 000,027,152 | ---- | M] () 64bit-(kl1) kl1 [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\kl1.sys -> [2009-09-01 14:29:56 | 000,157,712 | ---- | M] () 64bit-(sptd) sptd [Kernel | Boot | Running] -> C:\Windows\SysNative\Drivers\sptd.sys -> [2009-04-18 10:22:59 | 000,868,848 | ---- | M] () 64bit-(atksgt) atksgt [Kernel | Auto | Stopped] -> C:\Windows\SysNative\DRIVERS\atksgt.sys -> [2008-05-17 09:27:26 | 000,303,616 | ---- | M] () 64bit-(lirsgt) lirsgt [Kernel | Auto | Stopped] -> C:\Windows\SysNative\DRIVERS\lirsgt.sys -> [2008-05-17 09:27:26 | 000,035,328 | ---- | M] () 64bit-(WpdUsb) WpdUsb [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\wpdusb.sys -> [2008-01-19 08:47:12 | 000,046,080 | ---- | M] () 64bit-(NPF) NetGroup Packet Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\npf.sys -> [2007-11-06 22:23:14 | 000,040,464 | ---- | M] () 64bit-(AmdLLD64) AMD Low Level Device Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\AmdLLD64.sys -> [2007-06-29 14:48:06 | 000,039,424 | ---- | M] () 64bit-(NVENETFD) Sterownik kontrolera sieci NVIDIA nForce [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nvm60x64.sys -> [2006-10-10 04:09:03 | 000,742,696 | ---- | M] () 64bit-(Ntfs) Ntfs [File_System | On_Demand | Running] -> C:\Windows\SysNative\WBEM\ntfs.mof -> [2006-09-18 23:36:24 | 000,000,308 | ---- | M] () 64bit-(MTsensor) ATK0110 ACPI UTILITY [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\ASACPI.sys -> [2005-03-29 01:30:38 | 000,008,192 | ---- | M] () (speedfan) speedfan [Kernel | Boot | Running] -> C:\Windows\SysWOW64\speedfan.sys -> [2007-02-07 20:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) (NPPTNT2) NPPTNT2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysWOW64\npptNT2.sys -> [2005-01-03 08:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Registry - Safe List] < 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> about:blank -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\: "ProxyEnable" -> 0 -> < FireFox Settings [Prefs.js] > -> C:\Users\Maciej\AppData\Roaming\Mozilla\FireFox\Profiles\lqh26mbd.default\prefs.js -> browser.search.defaultenginename -> "Winamp Search" -> browser.search.defaulturl -> "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" -> browser.search.selectedEngine -> "Google" -> browser.search.useDBForOrder -> true -> browser.startup.homepage -> "http://pl4.grepolis.com/game/index" -> extensions.enabledItems -> {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 -> extensions.enabledItems -> linkfilter@kaspersky.ru:9.0.0.736 -> extensions.enabledItems -> {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 -> keyword.URL -> "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" -> < FireFox Settings [User.js] > -> C:\Users\Maciej\AppData\Roaming\Mozilla\FireFox\Profiles\lqh26mbd.default\user.js -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\Extensions -> -> HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions -> -> HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2010-09-16 21:51:44 | 000,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2010-09-16 21:51:44 | 000,000,000 | ---D | M] < FireFox Extensions [User Folders] > -> -> C:\Users\Maciej\AppData\Roaming\mozilla\Extensions -> [2008-07-03 21:41:00 | 000,000,000 | ---D | M] -> C:\Users\Maciej\AppData\Roaming\mozilla\Firefox\Profiles\lqh26mbd.default\extensions -> [2010-09-25 21:15:30 | 000,000,000 | ---D | M] Winamp Toolbar -> C:\Users\Maciej\AppData\Roaming\mozilla\Firefox\Profiles\lqh26mbd.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} -> [2010-05-03 18:05:09 | 000,000,000 | ---D | M] Microsoft .NET Framework Assistant -> C:\Users\Maciej\AppData\Roaming\mozilla\Firefox\Profiles\lqh26mbd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2010-05-03 18:05:09 | 000,000,000 | ---D | M] Greasemonkey -> C:\Users\Maciej\AppData\Roaming\mozilla\Firefox\Profiles\lqh26mbd.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} -> [2010-06-28 11:26:14 | 000,000,000 | ---D | M] < FireFox SearchPlugins [User Folders] > -> daemon-search.xml -> C:\Users\Maciej\AppData\Roaming\Mozilla\FireFox\Profiles\lqh26mbd.default\searchplugins\daemon-search.xml -> [2009-04-18 10:30:04 | 000,000,523 | ---- | M] () winamp-search.xml -> C:\Users\Maciej\AppData\Roaming\Mozilla\FireFox\Profiles\lqh26mbd.default\searchplugins\winamp-search.xml -> [2009-05-25 19:43:39 | 000,001,196 | ---- | M] () < FireFox Extensions [Program Folders] > -> -> C:\Program Files (x86)\mozilla firefox\extensions -> [2010-09-10 15:51:26 | 000,000,000 | ---D | M] Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} -> [2010-07-17 22:25:05 | 000,000,000 | ---D | M] -> C:\Program Files (x86)\mozilla firefox\extensions\linkfilter@kaspersky.ru -> [2010-05-03 17:49:23 | 000,000,000 | ---D | M] < HOSTS File > ([2010-08-11 13:51:51 | 000,000,930 | ---- | M] - 23 lines) -> C:\Windows\SysNative\Drivers\etc\hosts -> Reset Hosts 127.0.0.1 localhost ::1 localhost < 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:39:12 | 000,061,456 | ---- | M] (Kaspersky Lab) {E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\PROGRA~2\SPYBOT~1\SDHelper.dll [Spybot-S&D IE Protection] -> [2008-09-15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:34:50 | 000,068,112 | ---- | M] (Kaspersky Lab) {E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {F156768E-81EF-470C-9057-481BA8380DBA} [HKLM] -> C:\Program Files (x86)\FlashGet\getflash.dll [FlashGet GetFlash Class] -> [2007-05-18 18:13:10 | 000,163,840 | ---- | M] (www.flashget.com) < 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [DAEMON Tools Toolbar] -> File not found < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [DAEMON Tools Toolbar] -> File not found WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{CB789373-04D5-4EF4-9C16-871463FD0830}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "cFosSpeed" -> C:\Program Files\cFosSpeed\cfosspeed.exe [C:\Program Files\cFosSpeed\cFosSpeed.exe] -> [2010-01-05 12:41:20 | 001,349,848 | R--- | M] (cFos Software GmbH) "RtHDVCpl" -> C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s] -> [2009-12-08 12:34:24 | 009,642,528 | ---- | M] (Realtek Semiconductor) < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AVP" -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe ["C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"] -> [2010-09-02 15:34:27 | 000,340,520 | ---- | M] (Kaspersky Lab) "TkBellExe" -> C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot] -> [2010-08-28 02:28:17 | 000,202,256 | ---- | M] (RealNetworks, Inc.) < Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008-01-19 09:33:30 | 001,233,920 | ---- | M] (Microsoft Corporation) "WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008-01-19 09:36:02 | 002,153,472 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2008-01-19 09:33:30 | 001,233,920 | ---- | M] (Microsoft Corporation) "WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008-01-19 09:36:02 | 002,153,472 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Gadu-Gadu" -> C:\Program Files (x86)\Gadu-Gadu\gg.exe ["C:\Program Files (x86)\Gadu-Gadu\gg.exe" /tray] -> [2008-03-20 12:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) "SmartRAM" -> C:\Users\Maciej\Desktop\Programy\iobit_toolbox\Tools\Suo10_SmartRAM.exe ["C:\Users\Maciej\Desktop\Programy\iobit_toolbox\Tools\Suo10_SmartRAM.exe" /m] -> [2010-08-11 13:09:23 | 000,866,136 | ---- | M] (IObit) < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoActiveDesktop" -> [1] -> File not found \\"NoActiveDesktopChanges" -> [1] -> File not found \\"NoDriveTypeAutoRun" -> [60] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"LogonHoursAction" -> [2] -> File not found \\"DontDisplayLogonHoursWarnings" -> [1] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> Crawler Search -> [tbr:iemenu] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> Crawler Search -> [tbr:iemenu] -> File not found < 64bit-Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\Software\Microsoft\Internet Explorer\MenuExt\ -> &Ściągnij przy pomocy FlashGet'a -> C:\Program Files (x86)\FlashGet\jc_link.htm [C:\Program Files (x86)\FlashGet\jc_link.htm] -> [2007-05-18 18:13:10 | 000,001,898 | ---- | M] () &Ściągnij wszystko przy pomocy FlashGet'a -> C:\Program Files (x86)\FlashGet\jc_all.htm [C:\Program Files (x86)\FlashGet\jc_all.htm] -> [2007-05-18 18:13:10 | 000,001,049 | ---- | M] () < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\Software\Microsoft\Internet Explorer\MenuExt\ -> &Ściągnij przy pomocy FlashGet'a -> C:\Program Files (x86)\FlashGet\jc_link.htm [C:\Program Files (x86)\FlashGet\jc_link.htm] -> [2007-05-18 18:13:10 | 000,001,898 | ---- | M] () &Ściągnij wszystko przy pomocy FlashGet'a -> C:\Program Files (x86)\FlashGet\jc_all.htm [C:\Program Files (x86)\FlashGet\jc_all.htm] -> [2007-05-18 18:13:10 | 000,001,049 | ---- | M] () < 64bit-Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {4248FE82-7FCB-46AC-B270-339F08212110}:{4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [Button: &Wirtualna klawiatura] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {CCF151D8-D089-449F-A5A4-D9909053F20F}:{CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [Button: &Sprawdzanie adresów] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {4248FE82-7FCB-46AC-B270-339F08212110}:{4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [Button: &Wirtualna klawiatura] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {CCF151D8-D089-449F-A5A4-D9909053F20F}:{CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [Button: &Sprawdzanie adresów] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files (x86)\FlashGet\FlashGet.exe [Button: FlashGet] -> [2007-09-25 10:10:50 | 002,007,088 | ---- | M] (FlashGet.com) {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files (x86)\FlashGet\FlashGet.exe [Menu: FlashGet] -> [2007-09-25 10:10:50 | 002,007,088 | ---- | M] (FlashGet.com) {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\PROGRA~2\SPYBOT~1\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008-09-15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) < 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7004 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6252 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6252 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4810 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [Reg Error: Value error.] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab [Java Plug-in 1.6.0_21] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Value error.] -> {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab [Java Plug-in 1.6.0_04] -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab [Java Plug-in 1.6.0_21] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab [Java Plug-in 1.6.0_21] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> DhcpNameServer -> 217.30.129.149 192.168.0.1 -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {684D0890-6A67-48F9-A840-3065D3653EB7}\\DhcpNameServer -> 217.30.129.149 192.168.0.1 (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> {AE2B20E4-B547-4000-BF31-686774AC5674}\\DhcpNameServer -> 217.30.129.149 192.168.0.1 (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles "MaxScriptStatements" -> Reg Error: Invalid data type. "Use My Stylesheet" -> Reg Error: Invalid data type. < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll -> C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll -> [2010-07-19 14:46:25 | 000,109,072 | ---- | M] (Kaspersky Lab) *MultiFile Done* -> -> < 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> C:\Windows\explorer.exe -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < 64bit-Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> klogon -> C:\Windows\SysNative\klogon.dll -> [2009-10-20 19:39:14 | 000,224,272 | ---- | M] () < Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> {074F1D70-9447-46BC-883B-A4C337139034} -> lport=1900 | profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | {08DDE8EF-052F-493F-BE8E-F4BBBA48A5ED} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie usługami (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {0BABAF5E-9CC9-45DD-8D60-C7E11ABE05EE} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie zaporą systemu windows (rpc) | app=c:\windows\system32\svchost.exe | svc=policyagent | {0D3884BA-CBE1-4DB5-8581-67A490C15E86} -> lport=2178 | profile=private | protocol=6 | dir=in | action=allow | name=buforowanie równorzędne bits (zawartość — ruch przychodzący) | app=system | {0E5F7FF1-E5D3-4DB2-A836-748746CBA80C} -> lport=1701 | profile=private | protocol=17 | dir=in | action=allow | name=routing i dostęp zdalny (ruch przychodzący l2tp) | app=system | {13C3CC05-30D3-4604-BA49-17C3DE8E8B5F} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie woluminami (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {1405B7D1-BD75-4D7B-9495-7DFFD0EDA9C2} -> lport=2869 | profile=domain | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system | {152C0038-8CE6-4FCA-8409-7F3D4EA09AAE} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie dziennikiem zdarzeń (nazwane potoki — ruch przychodzący) | app=system | {1DCB0C13-8887-4FAE-921E-F046AF104C47} -> lport=3702 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-32785 | app=%systemroot%\system32\svchost.exe | svc=fdphost | {1E1DE04F-5812-4B88-BC7E-BBA4AC469297} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=bezprzewodowe urządzenia przenośne (ruch wychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {20C5ED8B-A11F-40AE-BABA-CFE22148D88F} -> lport=443 | profile=private | protocol=6 | dir=in | action=allow | name=protokół sstp (ruch przychodzący sstp) | app=system | {294A29FE-9B40-4657-A007-D4AD33BA6FB4} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący qwave tcp) | app=c:\windows\system32\svchost.exe | svc=qwave | {2EAF4B9E-5BB1-4EA0-9FE1-1636BCEE74B8} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave | {30F9963D-1CBC-40B1-85A1-B54E81D67BC9} -> lport=1900 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-32753 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | {31347806-056E-4ECF-8B80-C94E14C8F1F3} -> rport=2178 | profile=private | protocol=6 | dir=out | action=allow | name=buforowanie równorzędne bits (zawartość — ruch wychodzący) | app=system | {3599B852-CCEC-4563-8AA8-52A72D87971F} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system | {38322ED6-D8F3-4794-8FBF-8A93BE481DE1} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący qwave rtsp) | app=c:\windows\system32\svchost.exe | svc=qwave | {41B697A5-1318-42FC-B68E-D25D8A5829DC} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system | {42298666-A99C-4B97-8B1A-40777515857D} -> lport=3587 | profile=private | protocol=6 | dir=in | action=allow | name=obszar spotkań w systemie windows (ruch przychodzący p2p) | app=c:\windows\system32\svchost.exe | svc=p2psvc | {43ECC63F-5D9B-4B2C-A3EF-CC0E8DCB62C4} -> rport=3540 | profile=private | protocol=17 | dir=out | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch wychodzący pnrp) | app=c:\windows\system32\svchost.exe | svc=pnrpsvc | {46EE2469-6FA6-4A0C-A172-56FE24167DCD} -> rport=3702 | profile=private | protocol=17 | dir=out | action=allow | name=buforowanie równorzędne bits (ruch wychodzący wsd) | app=c:\windows\system32\svchost.exe | svc=bits | {4792BCBE-BF05-437C-9C49-7D2FD1CD91B2} -> rport=3587 | profile=private | protocol=6 | dir=out | action=allow | name=obszar spotkań w systemie windows (ruch wychodzący p2p) | app=c:\windows\system32\svchost.exe | svc=p2psvc | {4DCE73CA-E51D-435A-9658-E9E4606F6295} -> lport=2869 | profile=private | protocol=6 | dir=in | action=allow | name=bezprzewodowe urządzenia przenośne (ruch przychodzący upnp) | app=system | {56E47140-5155-4AE8-A826-D230063D69DB} -> rport=3702 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-32789 | app=%systemroot%\system32\svchost.exe | svc=fdphost | {59F0CDA3-0C22-4581-A19B-993AAA733846} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=administracja zdalna (rpc) | app=c:\windows\system32\svchost.exe | svc=* | {5AEB3F2A-712B-48A4-8111-2EB2A02DDBD4} -> rport=5355 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-32805 | app=%systemroot%\system32\svchost.exe | svc=dnscache | {5ECE33DC-7D16-4706-9A47-84EBD7F8D78B} -> rport=1701 | profile=private | protocol=17 | dir=out | action=allow | name=routing i dostęp zdalny (ruch wychodzący l2tp) | app=system | {5F23449B-1484-4C7C-95D7-840AF2A9C984} -> rport=5357 | profile=private | protocol=6 | dir=out | action=allow | name=połącz z projektorem sieciowym (ruch wychodzący zdarzeń wsd) | app=system | {60308DE4-AE88-4EB2-9627-228851E5E3D7} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {62D9B045-B70F-4C29-A8BB-49C108C201E4} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=usługa rejestracji nazw komputerów w funkcji współpraca w systemie windows (ruch przychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {69EC2683-207D-4BC6-A5CF-D2EE7111E75F} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=buforowanie równorzędne bits (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {6AC49E5F-7853-4691-A41B-63903AE3CFE0} -> lport=5355 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-32801 | app=%systemroot%\system32\svchost.exe | svc=dnscache | {732EC899-3A89-446B-B35B-F854D8EBF8A8} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=bezprzewodowe urządzenia przenośne (ruch przychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {74903D79-5105-4208-8CE5-5CC6F3E6E308} -> lport=10244 | profile=private | protocol=6 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący przesyłania strumieniowego http) | app=system | {74CB0934-B134-46ED-8211-9588CCBBC370} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie usługami (rpc) | app=c:\windows\system32\services.exe | {7651885C-5D6C-497C-A469-417D525C8D0B} -> lport=808 | protocol=6 | dir=in | action=allow | name=@c:\windows\microsoft.net\framework64\v4.0.30319\\servicemodelevents.dll,-2000 | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | svc=nettcpactivator | {796AE456-01E8-4B78-BF60-8941E1D690CA} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=usługa rejestracji nazw komputerów w funkcji współpraca w systemie windows (ruch wychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {7FB5B55D-4ED5-4E41-A53B-3B631F3BE4A7} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch wychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {8168407E-9A96-45E7-8A87-2C854660CB5F} -> rport=3702 | profile=private | protocol=17 | dir=out | action=allow | name=połącz z projektorem sieciowym (ruch wychodzący wsd) | app=c:\windows\system32\netproj.exe | {81A7D10D-A791-43D0-BD04-DD292EB22FE2} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=administracja zdalna (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {83FCD77D-08C4-42DE-8D53-EAE4DF59465C} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie woluminami — moduł ładujący usługi dysków wirtualnych (rpc) | app=c:\windows\system32\vdsldr.exe | {862D0287-AD09-446B-9D85-9EE87DE37A64} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch przychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {87391C16-737E-4A80-BFF4-B3169E56B40E} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=buforowanie równorzędne bits (rpc) | app=c:\windows\system32\svchost.exe | svc=bits | {88F46B6F-7F39-407B-891F-06E1FCC04F9B} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave | {8A521540-29BA-4ECD-BD1D-68E707B0639A} -> lport=3702 | profile=private | protocol=17 | dir=in | action=allow | name=buforowanie równorzędne bits (ruch przychodzący wsd) | app=c:\windows\system32\svchost.exe | svc=bits | {931AC50B-3A77-4ED1-82F2-EFD5254BFB38} -> lport=5722 | profile=private | protocol=6 | dir=in | action=allow | name=obszar spotkań w systemie windows (ruch przychodzący dfsr) | app=c:\windows\system32\dfsr.exe | svc=dfsr | {9895ADD2-9514-4DFF-9E18-60D8DFD5F159} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave | {997CCE48-F944-4F74-BE5D-4DE23A526512} -> rport=5722 | profile=private | protocol=6 | dir=out | action=allow | name=obszar spotkań w systemie windows (ruch wychodzący dfsr) | app=c:\windows\system32\dfsr.exe | svc=dfsr | {9B9F5B1B-A9FD-4C7B-8E9A-02FBBBB83A6B} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie dziennikiem zdarzeń (rpc) | app=c:\windows\system32\svchost.exe | svc=eventlog | {9E17A6F1-B73A-40B3-9A7A-3E863A2D3F74} -> lport=135 | profile=private | protocol=6 | dir=in | action=allow | name=dzienniki wydajności i alerty (ruch przychodzący dcom) | app=c:\windows\system32\svchost.exe | svc=rpcss | {9F03450D-C366-4EB9-BB0E-409EF76DBA3A} -> lport=162 | profile=private | protocol=17 | dir=in | action=allow | name=usługa snmp trap (ruch przychodzący udp) | app=c:\windows\system32\snmptrap.exe | svc=snmptrap | {A0562276-A5E8-4E14-9907-580ECBB3ED73} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący qwave udp) | app=c:\windows\system32\svchost.exe | svc=qwave | {A2758070-F0B4-4E13-A60F-6933F5E809A7} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave | {A6F040C0-9C5F-41A1-BA85-CFA1A43DA942} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie dziennikiem zdarzeń (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {AAF5D3F3-B882-4B41-A21D-D8A46953BA33} -> rport=5358 | profile=private | protocol=6 | dir=out | action=allow | name=połącz z projektorem sieciowym (ruch wychodzący bezpiecznych zdarzeń wsd) | app=system | {AB5B59A5-ABDE-4A04-8431-5B17A153F38D} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący qwave tcp) | app=c:\windows\system32\svchost.exe | svc=qwave | {AE3781B2-8DB1-431B-AE4D-E67C61835350} -> lport=3702 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-32809 | app=%systemroot%\system32\svchost.exe | svc=fdrespub | {B01A883C-37FB-4C5D-A8E6-93BB3499139F} -> lport=3702 | profile=private | protocol=17 | dir=in | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch przychodzący wsd) | app=c:\windows\system32\p2phost.exe | {B1B18BBA-3066-4086-B163-576BD5C73B22} -> lport=7777 | profile=private | protocol=17 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący wmdrm-nd/rtp/rtcp) | app=c:\windows\ehome\ehshell.exe | {B74ECCBF-B449-439C-A538-689123F065EB} -> lport=80 | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie systemem windows (ruch przychodzący http) | app=system | {B9E057AE-2888-41C9-A983-BB9547D04B87} -> rport=10244 | profile=private | protocol=6 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący przesyłania strumieniowego http) | app=system | {BC73EDCF-2667-464E-9990-EC922A492A9E} -> lport=1723 | profile=private | protocol=6 | dir=in | action=allow | name=routing i dostęp zdalny (ruch przychodzący pptp) | app=system | {BCC6E54A-C235-42BB-86BF-D186E5B5A682} -> lport=3702 | profile=private | protocol=17 | dir=in | action=allow | name=połącz z projektorem sieciowym (ruch przychodzący wsd) | app=c:\windows\system32\netproj.exe | {BD8B0401-1C5A-4368-8BDB-2C07BC8578F5} -> lport=3390 | profile=private | protocol=6 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący rdp) | app=system | {BE0C3780-DE7F-4BDE-979C-BAE4893BE15B} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie usługami (nazwane potoki — ruch przychodzący) | app=system | {C4789B48-6A2B-43C8-8925-0DFB29D63304} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie woluminami — usługa dysków wirtualnych (rpc) | app=c:\windows\system32\vds.exe | svc=vds | {C66E8B3F-EC7A-42A6-89D9-EC33BF8085FE} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie zaplanowanymi zadaniami (rpc) | app=c:\windows\system32\svchost.exe | svc=schedule | {C6CE27D7-DB86-4A63-859B-7EBF301393E2} -> lport=3540 | profile=private | protocol=17 | dir=in | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch przychodzący pnrp) | app=c:\windows\system32\svchost.exe | svc=pnrpsvc | {CAD469CF-4B22-47A3-ABD7-433E71693651} -> rport=1900 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-32757 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | {CAFD261B-57E7-4822-9468-11E24CA79837} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=koordynator transakcji rozproszonych (rpc) | app=c:\windows\system32\svchost.exe | svc=ktmrm | {CC24AEE9-A5D2-444D-88B0-23858236F508} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie zaplanowanymi zadaniami (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {CC3EB9AE-3EF6-4D7E-B804-55B1B2F12A37} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący ssdp) | app=c:\windows\system32\svchost.exe | svc=ssdpsrv | {D342A5F8-2A26-4788-9F13-A6948EAFBDD0} -> lport=5357 | profile=private | protocol=6 | dir=in | action=allow | name=połącz z projektorem sieciowym (ruch przychodzący zdarzeń wsd) | app=system | {DD352CE5-42B5-45CD-A447-511E2FAC08A4} -> rport=3702 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-32811 | app=%systemroot%\system32\svchost.exe | svc=fdrespub | {DD860298-71B4-44A6-A18F-02212CEC2599} -> rport=3702 | profile=private | protocol=17 | dir=out | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch wychodzący wsd) | app=c:\windows\system32\p2phost.exe | {DEC2744C-BF83-4A43-922C-D4AB0A580CD2} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=koordynator transakcji rozproszonych (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {DFD75ECE-56B7-492E-A0F4-AE8764328349} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=zdalne zarządzanie zaporą systemu windows (rpc-epmap) | app=c:\windows\system32\svchost.exe | svc=rpcss | {E0285FDE-7ECC-4E4C-AF4A-46D38FA7B6B9} -> rport=1900 | profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | {ED94F169-FE76-44B7-B4DC-26C3FCFB7C0C} -> rport=1723 | profile=private | protocol=6 | dir=out | action=allow | name=routing i dostęp zdalny (ruch wychodzący pptp) | app=system | {EF78EABB-7BF7-45F2-8E58-B82CD915F6B0} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=administracja zdalna (nazwane potoki — ruch przychodzący) | app=system | {F089686D-5C34-45BD-B14A-8E20BED5C166} -> lport=5358 | profile=private | protocol=6 | dir=in | action=allow | name=połącz z projektorem sieciowym (ruch przychodzący bezpiecznych zdarzeń wsd) | app=system | {F2FD77C9-D2E5-40E5-B424-33921C97DDA1} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=usługa netlogon (nazwane potoki — ruch przychodzący) | app=system | {F4842CDC-A620-4969-A5D9-441A1F6DA8A9} -> rport=3540 | profile=private | protocol=17 | dir=out | action=allow | name=usługa rejestracji nazw komputerów w funkcji współpraca w systemie windows (ruch wychodzący pnrp) | app=c:\windows\system32\svchost.exe | svc=pnrpsvc | {F4B54F95-4C96-48EB-8086-3090A02D1F17} -> lport=135 | profile=private | protocol=6 | dir=in | action=allow | name=instrumentacja zarządzania windows (ruch przychodzący dcom) | app=c:\windows\system32\svchost.exe | svc=rpcss | {F74A3DC0-2A6D-4F79-B62D-317E4300E048} -> lport=3540 | profile=private | protocol=17 | dir=in | action=allow | name=usługa rejestracji nazw komputerów w funkcji współpraca w systemie windows (ruch przychodzący pnrp) | app=c:\windows\system32\svchost.exe | svc=pnrpsvc | {FCE20841-B288-40AB-BC73-73F86D9D7176} -> lport=554 | profile=private | protocol=6 | dir=in | action=allow | name=urządzenia media center extender (ruch przychodzący rtsp) | app=c:\windows\ehome\ehshell.exe | < Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> {00B51FD6-471F-4CAC-B789-F8EF27992DBB} -> profile=private | protocol=17 | dir=out | action=allow | name=obszar spotkań w systemie windows (ruch wychodzący udp) | app=c:\program files\windows collaboration\wincollab.exe | {043C52C8-F984-422E-93B9-D03FDFFDB3AE} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost | {057A76F7-A5EF-4B83-AA60-FA7304A6B9CC} -> profile=private | protocol=17 | dir=in | action=allow | name=ubisoft game launcher | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | {0A8CA071-708C-4928-82BB-4C86D69BEC3E} -> profile=private | protocol=6 | dir=in | action=allow | name=usługa iscsi (ruch przychodzący tcp) | app=c:\windows\system32\svchost.exe | svc=msiscsi | {0D3D3999-5763-46B6-91D2-65E473D0E675} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe | {0D47C83E-41EA-4B94-AEA1-3B5614D46796} -> profile=private | protocol=6 | dir=out | action=allow | name=obszar spotkań w systemie windows (ruch wychodzący tcp) | app=c:\program files\windows collaboration\wincollab.exe | {0F233154-4AFD-46E6-BDD8-BF469EC37B36} -> profile=private | protocol=17 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe | {12ACACDD-DEFC-4BC9-B9BB-A238A8B61C72} -> profile=private | protocol=6 | dir=out | action=allow | name=usługa iscsi (ruch wychodzący tcp) | app=c:\windows\system32\svchost.exe | svc=msiscsi | {1320E8C4-62AB-411D-B3F7-E6DF2BA77143} -> profile=private | protocol=6 | dir=out | action=allow | name=windows media player (ruch wychodzący tcp) | app=c:\program files\windows media player\wmplayer.exe | {1873D3B5-3A9F-4D6F-A656-409B250C96A2} -> profile=private | protocol=17 | dir=in | action=allow | name=empire earth iii | app=c:\program files\empire earth iii\ee3.exe | {1AF0EC49-2457-48E2-8E8E-4643866AC37E} -> profile=private | protocol=17 | dir=in | action=allow | name=windows media player (ruch przychodzący udp) | app=c:\program files\windows media player\wmplayer.exe | {1E46E439-8096-4129-BEBE-B869D1E9E250} -> profile=private | protocol=17 | dir=in | action=allow | name=counter-strike | app=c:\program files (x86)\steam\steamapps\50535820\counter-strike\hl.exe | {20DB4B2C-67C4-4900-8613-5BC180EA1156} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31323 | app=%programfiles(x86)%\windows media player\wmplayer.exe | {2330C2A2-431C-4731-BA91-4B2800CE89D6} -> profile=domain | protocol=17 | dir=out | action=allow | name=windows media player (ruch wychodzący udp) | app=c:\program files\windows media player\wmplayer.exe | {23347714-A1BB-4546-8F72-46273353FB81} -> profile=private | protocol=6 | dir=in | action=allow | name=dzienniki wydajności i alerty (ruch przychodzący tcp) | app=c:\windows\system32\plasrv.exe | {295EEBA1-34AD-4B6A-89F4-BC25FA2DD9F8} -> profile=private | protocol=17 | dir=in | action=allow | name=grid | app=c:\program files (x86)\codemasters\grid\grid.exe | {300F34B3-706F-4E0C-85D0-192D9F28EDFA} -> profile=private | protocol=17 | dir=in | action=allow | name=ef | app=c:\enemy flag\ef.exe | {30673F39-4E99-4132-A06E-62A614780343} -> profile=private | protocol=6 | dir=in | action=allow | name=koordynator transakcji rozproszonych (ruch przychodzący tcp) | app=c:\windows\system32\msdtc.exe | {322375A4-935A-4F3C-97AC-87387E048353} -> profile=private | protocol=6 | dir=out | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch wychodzący tcp) | app=c:\windows\system32\p2phost.exe | {323B7F7E-DF50-4008-A3C2-DF2143FD0740} -> profile=domain | protocol=17 | dir=out | action=allow | name=windows media player x86 (ruch wychodzący udp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {328A8CB8-5682-46C1-9CA9-3BA77437F307} -> profile=private | protocol=6 | dir=out | action=allow | name=windows media player x86 (ruch przychodzący tcp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {32B51C0D-014F-43DA-8698-E4702C03877E} -> profile=private | protocol=17 | dir=out | action=allow | name=urządzenia media center extender (ruch przychodzący wmdrm-nd/rtp/rtcp) | app=c:\windows\ehome\ehshell.exe | {3479E9B8-99E9-43BD-A4C6-3F6E6667DE9F} -> profile=public | protocol=6 | dir=in | action=allow | name=counter-strike | app=c:\program files (x86)\steam\steamapps\50535820\counter-strike\hl.exe | {3BC32750-59D3-4112-BD79-9A2192836422} -> profile=private | protocol=6 | dir=in | action=allow | name=instrumentacja zarządzania windows (ruch przychodzący wmi) | app=c:\windows\system32\svchost.exe | svc=winmgmt | {3F90D403-6DF8-443C-8C6A-7AF9F8DAE32B} -> profile=private | protocol=6 | dir=out | action=allow | name=bezprzewodowe urządzenia przenośne (ruch wychodzący tcp) | app=c:\windows\system32\wudfhost.exe | {494AD69C-BF9C-4D30-9C5F-69FA09A4AC43} -> profile=private | protocol=6 | dir=in | action=allow | name=ef | app=c:\enemy flag\ef.exe | {49F31778-9E4D-4156-AF11-830589C7B229} -> profile=private | protocol=6 | dir=out | action=allow | name=bezprzewodowe urządzenia przenośne (ruch wychodzący upnp) | app=system | {4F8B1DB4-14CE-4E51-8198-823FC1019CDD} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe | {521F8365-481B-49E0-8342-E1F113EE6E39} -> profile=private | protocol=6 | dir=in | action=allow | name=ubisoft game launcher | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | {58E7AD51-D8D5-4238-9721-1BCE12B99E7F} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31324 | app=%programfiles(x86)%\windows media player\wmplayer.exe | {591CFDBC-AA23-479E-A716-5A292EC1479A} -> profile=private | protocol=17 | dir=out | action=allow | name=windows media player (ruch wychodzący udp) | app=c:\program files\windows media player\wmplayer.exe | {59ED49E9-EFE0-4F0D-967C-D2F566240D21} -> profile=private | protocol=6 | dir=in | action=allow | name=grid | app=c:\program files (x86)\codemasters\grid\grid.exe | {5CEAD67E-E5D9-4FE9-9C86-0FCDA362EBDA} -> profile=private | protocol=6 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe | {6074E8F1-0FE5-425E-BB29-8F40C2C8C0B9} -> profile=domain | protocol=17 | dir=in | action=allow | name=windows media player x86 (ruch przychodzący udp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {609D001A-F317-4D83-9B0B-1792F9ADFCF5} -> profile=private | protocol=17 | dir=in | action=allow | name=umi | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | {668F50F3-C8EF-4992-BB97-E70E3072E33D} -> profile=domain | protocol=6 | dir=out | action=allow | name=windows media player (ruch wychodzący tcp) | app=c:\program files\windows media player\wmplayer.exe | {6703AECA-2318-4231-B798-CB4143E4DC16} -> profile=private | protocol=6 | dir=out | action=allow | name=instrumentacja zarządzania windows (ruch wychodzący wmi) | app=c:\windows\system32\svchost.exe | svc=winmgmt | {6F9A89A5-E2B3-4901-9431-1EDA956A7C43} -> profile=private | protocol=6 | dir=in | action=allow | name=empire earth iii | app=c:\program files\empire earth iii\ee3.exe | {7EC50E2C-9877-47E5-9F2E-69C8E15293ED} -> profile=private | protocol=6 | dir=out | action=allow | name=koordynator transakcji rozproszonych (ruch wychodzący tcp) | app=c:\windows\system32\msdtc.exe | {7F5274C6-3DA5-4DB0-9690-8D615BF6ADE2} -> profile=private | protocol=17 | dir=in | action=allow | name=pinnacle videospin | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | {7F6871E9-BB3C-479B-9324-00CDCBD9680C} -> profile=private | protocol=17 | dir=out | action=allow | name=windows media player x86 (ruch wychodzący udp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {806D3E2E-2EE0-456B-9AE8-5D0C3E32907A} -> profile=private | protocol=6 | dir=in | action=allow | name=połącz z projektorem sieciowym (ruch przychodzący tcp) | app=c:\windows\system32\netproj.exe | {809AABF6-030F-49D5-9EC3-F7CB3ED27DDF} -> dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe | {81CC193A-95E8-428C-8986-ED9A303944D8} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe | {9088B643-5D0D-411D-B2CD-AA7E96B749C8} -> profile=private | protocol=6 | dir=in | action=allow | name=funkcja podstawa współpracy w sieci równorzędnej systemu windows (ruch przychodzący tcp) | app=c:\windows\system32\p2phost.exe | {94B3C529-2766-4523-84F0-23EBB50ED748} -> profile=private | protocol=6 | dir=in | action=allow | name=counter-strike | app=c:\program files (x86)\steam\steamapps\50535820\counter-strike\hl.exe | {9948DB1B-8A34-42E2-B27F-AE77372F8128} -> profile=private | protocol=17 | dir=in | action=allow | name=obszar spotkań w systemie windows (ruch przychodzący udp) | app=c:\program files\windows collaboration\wincollab.exe | {9BD662A3-730F-4E52-BBAE-D80DAC10C23F} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system | {A665274A-D001-4D0A-A16F-297CC1D86133} -> profile=private | protocol=17 | dir=in | action=allow | name=render manager | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | {A923B064-318D-467E-AD94-0BC0D2CF0D7B} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe | {AB09DF67-BBC4-4331-ACD9-CCD5284A9944} -> profile=public | protocol=17 | dir=in | action=allow | name=counter-strike | app=c:\program files (x86)\steam\steamapps\50535820\counter-strike\hl.exe | {AB69667F-EA05-4D25-BEA6-048E1C0C8C9D} -> profile=private | protocol=6 | dir=out | action=allow | name=połącz z projektorem sieciowym (ruch wychodzący tcp) | app=c:\windows\system32\netproj.exe | {ACE08842-754B-4A0D-8C8E-5AE05ADA2220} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31325 | app=%programfiles(x86)%\windows media player\wmplayer.exe | {BA82A0B6-69ED-47FE-8904-866D5C4A5818} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe | {BB298E34-2C03-4709-AEB5-8D8B8A01C212} -> profile=private | protocol=6 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący rtsp) | app=c:\windows\ehome\ehshell.exe | {C17819C9-D53D-47E1-921A-CB2FDCCDE2BB} -> profile=private | protocol=6 | dir=in | action=allow | name=instrumentacja zarządzania windows (ruch przychodzący async) | app=c:\windows\system32\wbem\unsecapp.exe | {C30BC296-03E0-4231-A0BB-0D2CC5502634} -> profile=private | protocol=6 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący biblioteki świadczenia usług) | app=c:\windows\ehome\mcx2prov.exe | {CF343EFE-CD0D-4F55-B06A-45D4667A3D05} -> profile=private | protocol=6 | dir=in | action=allow | name=obszar spotkań w systemie windows (ruch przychodzący tcp) | app=c:\program files\windows collaboration\wincollab.exe | {D424E19D-7DDD-4375-B38B-FF218ABBF53C} -> profile=public | protocol=6 | dir=in | action=allow | name=opera internet browser | app=c:\opera\opera.exe | {D5F88881-9DE1-446E-9192-C8E73606DAD0} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe | {D68B0033-811E-4B9F-9618-4C1AFDE14929} -> profile=public | protocol=17 | dir=in | action=allow | name=opera internet browser | app=c:\opera\opera.exe | {D745AF2D-B2C2-46AF-B77C-822B5C2A8E63} -> profile=private | protocol=6 | dir=in | action=allow | name=render manager | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | {E10E2CF6-F089-4605-85BF-50A16A302BF3} -> profile=private | protocol=6 | dir=in | action=allow | name=pinnacle videospin | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | {EA4B4CBD-6FAC-4986-8E43-35F0274207C9} -> profile=domain | protocol=6 | dir=out | action=allow | name=windows media player x86 (ruch przychodzący tcp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {EC4E2897-E504-422D-84AD-71E1A3372E6F} -> profile=public | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-32821 | app=%systemroot%\system32\svchost.exe | svc=upnphost | {F0B0D105-3D98-4FC7-B460-D5E107070642} -> profile=private | protocol=6 | dir=in | action=allow | name=umi | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | {F0E7FA67-0D0F-43D3-84AF-8F5F502A642A} -> profile=private | protocol=6 | dir=out | action=allow | name=bezprzewodowe urządzenia przenośne (ruch wychodzący upnphost) | app=c:\windows\system32\svchost.exe | svc=upnphost | {F52451C6-7D67-4474-90E6-D3ECA919D009} -> profile=domain | protocol=17 | dir=in | action=allow | name=windows media player (ruch przychodzący udp) | app=c:\program files\windows media player\wmplayer.exe | {F62429BF-5F95-4D96-9844-27129E9BE9EE} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe | {F8122573-4B9F-43B6-A6D8-2DD60F3246E6} -> profile=private | protocol=17 | dir=in | action=allow | name=windows media player x86 (ruch przychodzący udp) | app=c:\program files (x86)\windows media player\wmplayer.exe | {F939A209-8FF6-441A-9A7C-E1B0DD14F1EB} -> profile=private | protocol=6 | dir=out | action=allow | name=urządzenia media center extender (ruch wychodzący usług) | app=c:\windows\system32\svchost.exe | svc=mcx2svc | TCP Query User{0010441B-4246-48B4-AB4C-B6E1EF068209}C:\users\maciej\desktop\nowy folder\counter-strikeeee\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder\counter-strikeeee\hl.exe | TCP Query User{0046CFAD-5F91-4C01-9DB1-7A0333639B41}C:\users\maciej\desktop\nowy folder\s-metin2.exe -> profile=private | protocol=6 | dir=in | action=block | name=s-metin2.exe | app=c:\users\maciej\desktop\nowy folder\s-metin2.exe | TCP Query User{0344191E-BBC7-4B1A-86F4-F937757854E4}C:\users\maciej\program files (x86)\dna\btdna.exe -> profile=private | protocol=6 | dir=in | action=allow | name=btdna.exe | app=c:\users\maciej\program files (x86)\dna\btdna.exe | TCP Query User{037B324A-DD3B-48EE-ACF4-D840855D120C}C:\users\maciej\desktop\programy\cs\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\programy\cs\hl.exe | TCP Query User{0512B13C-A813-4F1C-80E8-27C7317652F3}C:\users\maciej\desktop\metin22\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin22\metin2client.bin | TCP Query User{058B623C-E24F-4A00-8BE4-B2AF6E3660AB}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia\hl.exe | TCP Query User{05E93E78-A46A-429C-9F20-A908DF94D646}C:\users\maciej\desktop\nowy folder\mcmetinpro.exe -> profile=private | protocol=6 | dir=in | action=block | name=mcmetinpro.exe | app=c:\users\maciej\desktop\nowy folder\mcmetinpro.exe | TCP Query User{079F7D99-3B91-435A-BD67-B9F95829DC47}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{084E6C8C-992A-474A-B594-29B76E8628AA}C:\users\maciej\desktop\nowy folder\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder\counter-strike\hl.exe | TCP Query User{0871582F-15C7-4E09-B5B8-67392785B287}C:\enemy flag\efserver.exe -> profile=private | protocol=6 | dir=in | action=allow | name=efserver | app=c:\enemy flag\efserver.exe | TCP Query User{08E22EFA-C394-4EDC-A090-27ED76FCFDC0}C:\users\maciej\desktop\programy\metin2\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\programy\metin2\metin2client.bin | TCP Query User{0C83204B-C9D4-43DD-8D74-F2156FE57441}C:\program files (x86)\gadu-gadu\gg.exe -> profile=private | protocol=6 | dir=in | action=allow | name=gadu-gadu - program główny | app=c:\program files (x86)\gadu-gadu\gg.exe | TCP Query User{0F2C5BB6-C16F-449D-8F7B-A6A5F5B4F396}C:\users\wioletta\desktop\counter-strike\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\wioletta\desktop\counter-strike\hl.exe | TCP Query User{0FD42F46-2042-4AFD-96E0-031D80E465A7}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{107A8669-147B-4F6E-A9FD-323DBE7B1814}C:\users\maciej\desktop\ahrimania - kopia\ahrimania\ahrimania.exe -> profile=private | protocol=6 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania - kopia\ahrimania\ahrimania.exe | TCP Query User{10BB34B1-A488-4737-BA34-55E9F02E2FC5}C:\metin 2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\metin 2\metin2.bin | TCP Query User{10BDCDB4-87A3-4964-B90C-73DC5344B375}C:\users\maciej\desktop\cs\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\cs\hl.exe | TCP Query User{110FBFF0-F29D-4B7F-AED7-26A8CB92E76C}D:\metin2\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=d:\metin2\metin2client.bin | TCP Query User{124FAE76-86D9-4FF2-8771-2014528324DD}C:\users\maciej\desktop\counter-strikes - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia\hl.exe | TCP Query User{188899CE-1FA5-4600-BBAC-0AC0739350B6}D:\program files (x86)\cheat engine\cheat engine server.exe -> profile=private | protocol=6 | dir=in | action=allow | name=cheat engine server | app=d:\program files (x86)\cheat engine\cheat engine server.exe | TCP Query User{19736C4B-8600-40A8-9352-713F6A10360F}C:\wapster\aqq\aqq.exe -> profile=private | protocol=6 | dir=in | action=allow | name=aqq | app=c:\wapster\aqq\aqq.exe | TCP Query User{1B8DF941-FF64-4470-8CC4-07831B72B241}C:\users\maciej\desktop\metin2 priv\avalonmt2.exe -> profile=private | protocol=6 | dir=in | action=block | name=avalonmt2.exe | app=c:\users\maciej\desktop\metin2 priv\avalonmt2.exe | TCP Query User{1BD85DC7-7A26-4B9E-A8B6-46E7C240FE83}C:\users\maciej\desktop\assassins.creed.2.pl-crack\offlineserver-v0.32\server.exe -> profile=private | protocol=6 | dir=in | action=allow | name=server.exe | app=c:\users\maciej\desktop\assassins.creed.2.pl-crack\offlineserver-v0.32\server.exe | TCP Query User{1C122EB6-CE64-49FF-AE22-4E02EE06EA03}C:\program files (x86)\ares\ares.exe -> profile=public | protocol=6 | dir=in | action=block | name=ares p2p for windows | app=c:\program files (x86)\ares\ares.exe | TCP Query User{1F612C4A-15EF-4704-919D-463F0396602B}C:\users\michał\desktop\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\michał\desktop\counter-strike\hl.exe | TCP Query User{1FA15D89-A053-48FB-B091-4D237EDBC097}C:\users\maciej\appdata\local\temp\usmt\migwiz.exe -> profile=public | protocol=6 | dir=in | action=allow | name=migwiz.exe | app=c:\users\maciej\appdata\local\temp\usmt\migwiz.exe | TCP Query User{21F719F0-D7DC-4D8C-AE8D-679F50306AB2}C:\users\maciej\desktop\counter-strik - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strik - kopia\hl.exe | TCP Query User{24C8FC61-61A2-4C08-9C0F-B5F8969BB6D7}C:\users\maciej\desktop\ahrimania\ahrimania\ahrimania.exe -> profile=private | protocol=6 | dir=in | action=allow | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania\ahrimania\ahrimania.exe | TCP Query User{252643BF-B334-43BD-8D79-149909FDC57F}C:\users\maciej\desktop\cs2d_0103\counterstrike2d.exe -> profile=private | protocol=6 | dir=in | action=block | name=counterstrike2d.exe | app=c:\users\maciej\desktop\cs2d_0103\counterstrike2d.exe | TCP Query User{2673E278-53A8-48DC-9938-56F7E976E7FF}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{27FFB260-1927-4034-8B09-06C62D9211AA}C:\program files (x86)\spellforce\spellforce.exe -> profile=public | protocol=6 | dir=in | action=allow | name=spellforce | app=c:\program files (x86)\spellforce\spellforce.exe | TCP Query User{28EA663E-264D-4E35-8B34-FB29F03A2123}C:\users\maciej\desktop\new metin2 client\client completo per cheatforge\mc.exe -> profile=private | protocol=6 | dir=in | action=block | name=mc.exe | app=c:\users\maciej\desktop\new metin2 client\client completo per cheatforge\mc.exe | TCP Query User{2975E6F1-EDC1-4159-AF18-4DE3D0CDB7EB}C:\users\maciej\desktop\counter-strikes\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes\hl.exe | TCP Query User{2AB1EB8C-9BA6-4435-A8BC-E7C0C7929F63}C:\program files (x86)\astral\launcher.exe -> profile=private | protocol=6 | dir=in | action=allow | name=launcher | app=c:\program files (x86)\astral\launcher.exe | TCP Query User{2E937E76-7BBE-4D8F-B179-7B0EE8813240}C:\users\maciej\desktop\metin2 priv\thenextland.exe -> profile=private | protocol=6 | dir=in | action=block | name=thenextland.exe | app=c:\users\maciej\desktop\metin2 priv\thenextland.exe | TCP Query User{2ECD6C63-0CE9-462E-B0B9-CB2A6FCE9B67}C:\users\maciej\desktop\metin2\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2\metin2client.bin | TCP Query User{2F6AED90-9B6B-404E-B8D6-3F967FC5729F}C:\program files (x86)\counter-strike\hlds.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\counter-strike\hlds.exe | TCP Query User{30F16773-BE17-49D7-83BD-545EFAC46EE9}C:\program files (x86)\opera\opera.exe -> profile=private | protocol=6 | dir=in | action=allow | name=opera internet browser | app=c:\program files (x86)\opera\opera.exe | TCP Query User{312AB59F-0F83-4284-9C99-C4A054E6733F}C:\users\maciej\desktop\metin2\metin2.bin -> profile=public | protocol=6 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\metin2\metin2.bin | TCP Query User{3138D9F2-C126-4C29-A708-11EB3AA8C4B9}C:\program files (x86)\flashget\flashget.exe -> profile=private | protocol=6 | dir=in | action=allow | name=flashget | app=c:\program files (x86)\flashget\flashget.exe | TCP Query User{3209AD2A-C61D-470A-A133-CFB834CBA9AF}D:\metin2\metin2client.bin -> profile=public | protocol=6 | dir=in | action=block | name=metin2client.bin | app=d:\metin2\metin2client.bin | TCP Query User{32A05C84-A1B0-4C65-95AD-828465E74DB2}C:\users\maciej\desktop\333 - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\333 - kopia\metin2.bin | TCP Query User{339F3504-D8BB-4BA7-8937-482799A8FC1E}C:\users\maciej\desktop\444\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\444\metin2client.bin | TCP Query User{3450627F-608B-4A57-BC5C-AC76F02E28D2}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{35F7EFB9-7E68-4CD5-8C39-3EC905B1D19E}C:\program files (x86)\java\jre6\bin\java.exe -> profile=private | protocol=6 | dir=in | action=allow | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\java.exe | TCP Query User{36264CA2-D427-4EA1-B3A3-3A28EA0938BD}C:\users\maciej\desktop\metin2 thenextland\tnlmt2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=tnlmt2.bin | app=c:\users\maciej\desktop\metin2 thenextland\tnlmt2.bin | TCP Query User{3A2CC163-EFE3-447E-804E-71A246AE3023}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{3BB52856-2378-4A0E-BDCF-5B2761EEEBDF}C:\users\maciej\desktop\222\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\222\metin2client.bin | TCP Query User{3C7901D5-3AAB-496F-BFEB-B095C32AAD85}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{3C9500E1-4BBB-4650-B1C6-C61C6BB7F5EB}C:\users\maciej\desktop\metin 2 - kopia - kopia - kopia - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia - kopia - kopia - kopia\metin2.bin | TCP Query User{3DF639A3-7F69-4994-8B62-86078E5A1E03}C:\users\maciej\desktop\ahrimania dmg\ahrimania\ahrimania.exe -> profile=private | protocol=6 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania dmg\ahrimania\ahrimania.exe | TCP Query User{3E966231-AF8D-4D72-94CE-7AAFD3FE8B53}C:\users\maciej\desktop\444\metin2client1.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client1.bin | app=c:\users\maciej\desktop\444\metin2client1.bin | TCP Query User{42AA9CB5-8785-47A9-8C50-CB785D510CC0}C:\users\maciej\desktop\counter-strike 1.6\counter-strike 1.6\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6\counter-strike 1.6\hl.exe | TCP Query User{42D59043-7704-4177-AB63-90FC4E70EB89}C:\users\maciej\temp\teamviewer\version4\teamviewer.exe -> profile=private | protocol=6 | dir=in | action=block | name=teamviewer.exe | app=c:\users\maciej\temp\teamviewer\version4\teamviewer.exe | TCP Query User{43DC020E-7320-4CCC-AE14-294228829EC7}C:\users\maciej\desktop\programy\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\programy\counter-strike\hl.exe | TCP Query User{43FAAE79-F31C-4AD2-AAA5-C8BFA153CC97}C:\users\maciej\desktop\metin 2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2\metin2.bin | TCP Query User{4531908C-131A-4D6F-8401-04503506E6DC}C:\users\maciej\desktop\metin2 - kopia (2)\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia (2)\metin2.bin | TCP Query User{4708C2BC-C595-4BE4-86AC-524BE7A8B2FE}C:\users\maciej\desktop\metin2 priv\belenus.exe -> profile=private | protocol=6 | dir=in | action=block | name=belenus.exe | app=c:\users\maciej\desktop\metin2 priv\belenus.exe | TCP Query User{49C6F8E2-267D-4502-9D2A-7B951EB336B9}C:\program files (x86)\metin2\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2\metin2client.bin | TCP Query User{4A36CD66-2A82-42D6-839F-F13F7437DE5F}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia (2)\hl.exe | TCP Query User{4AD877D7-4C69-4618-9797-CE5428DC1D8C}C:\users\maciej\desktop\counter-strikes\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes\hl.exe | TCP Query User{4BFE7823-8054-4816-A42F-A6346FD7AC65}C:\users\maciej\desktop\counter-strikes - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia\hl.exe | TCP Query User{4C274C9E-06BA-4F5B-A370-27AB32720888}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{4DFF6549-F266-4E99-A513-CAD46EB325C3}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{4E605D9D-C8AD-424A-8B90-7F46F9094D62}C:\users\maciej\desktop\metin2 - kopia - kopia\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia - kopia\metin2client.bin | TCP Query User{4F1B018D-34EF-47AA-99BB-4D015C026AC5}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{4F78A78F-58BA-47F7-B9B5-438102815234}C:\program files (x86)\emule\emule.exe -> profile=private | protocol=6 | dir=in | action=allow | name=emule | app=c:\program files (x86)\emule\emule.exe | TCP Query User{502188FF-C325-438D-8EDB-D576081C7741}C:\users\maciej\desktop\programy\metin2\metin2client.bin -> profile=public | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\programy\metin2\metin2client.bin | TCP Query User{5045D189-1830-4D9B-B8D5-42AA7082050C}D:\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=d:\counter-strike\hl.exe | TCP Query User{514EF65A-BE97-4036-A468-1D117EC8F907}C:\users\maciej\desktop\nowy folder\xlast.exe -> profile=private | protocol=6 | dir=in | action=block | name=xlast.exe | app=c:\users\maciej\desktop\nowy folder\xlast.exe | TCP Query User{5152E777-C7E2-4A11-B829-22B143618E80}C:\empire earth ii\ee2.exe -> profile=private | protocol=6 | dir=in | action=allow | name=empire earth ii | app=c:\empire earth ii\ee2.exe | TCP Query User{5267C417-4EF9-4F94-A608-19357EAB935F}C:\program files (x86)\valve\hltv.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hltv launcher | app=c:\program files (x86)\valve\hltv.exe | TCP Query User{54A7260B-224B-424B-9D5F-6FDDF2954A36}C:\program files (x86)\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=c:\program files (x86)\counter-strike\hl.exe | TCP Query User{555A1EC4-188E-45D7-A601-BC75507282A5}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{55D1D6E9-C612-4782-B8FF-B3D864C232A1}C:\users\maciej\desktop\tnl_www.przeklej.pl\tnl\tnlmt2.bin -> profile=private | protocol=6 | dir=in | action=block | name=tnlmt2.bin | app=c:\users\maciej\desktop\tnl_www.przeklej.pl\tnl\tnlmt2.bin | TCP Query User{58D47EBD-7E28-4C09-91DE-DA4C0F10E0EB}C:\users\maciej\desktop\counter-strike - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia\hl.exe | TCP Query User{597F4951-0FAF-4C89-9841-29BA71312807}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia\hl.exe | TCP Query User{5A9FCE48-2DAF-447E-91E7-97232AF4384C}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{5AF194AA-ED8B-4819-A894-EC47239D549A}C:\users\maciej\desktop\nowy folder\x-world.exe -> profile=private | protocol=6 | dir=in | action=block | name=x-world.exe | app=c:\users\maciej\desktop\nowy folder\x-world.exe | TCP Query User{5BFEB27F-0F16-445D-8AE9-84DE498BD3B1}C:\program files (x86)\mirc\mirc.exe -> profile=private | protocol=6 | dir=in | action=allow | name=mirc | app=c:\program files (x86)\mirc\mirc.exe | TCP Query User{5C327FC0-0FF9-4413-AA33-495613279ADE}C:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\metin2mod.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\metin2mod.bin | TCP Query User{5E90AD03-26C7-40A0-BC97-B799F5446BC5}C:\users\maciej\desktop\metin2 - kopia (3)\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia (3)\metin2client.bin | TCP Query User{5ED12778-9F53-4B85-B15F-9B449E90981A}C:\program files (x86)\wesnoth 1.4\wesnothd.exe -> profile=private | protocol=6 | dir=in | action=allow | name=wesnothd | app=c:\program files (x86)\wesnoth 1.4\wesnothd.exe | TCP Query User{5F1C2A9C-1FB0-4252-9FA5-C9BCEF8C9139}C:\users\maciej\desktop\metin2 - kopia\metin2client.bin -> profile=public | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2client.bin | TCP Query User{602031B7-88EE-42A6-9C4B-F6B6A57025C6}C:\users\wioletta\desktop\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\wioletta\desktop\counter-strike\hl.exe | TCP Query User{60EBA4CC-7AD9-4F2B-9609-72B321679F0E}C:\users\maciej\desktop\ahrimania killer\ahrimania\ahrimania.exe -> profile=private | protocol=6 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania killer\ahrimania\ahrimania.exe | TCP Query User{62031F96-F622-4B3F-BC38-7912A3598EE2}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia\hl.exe | TCP Query User{6382D0FF-E6E6-414E-BD40-F8BC208C72D6}D:\rakionis\bin\rakion.bin -> profile=private | protocol=6 | dir=in | action=allow | name=rakion.bin | app=d:\rakionis\bin\rakion.bin | TCP Query User{6540AD02-5932-4B35-92AA-8EFD01C58048}C:\users\maciej\desktop\programy\cs\hlds.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\programy\cs\hlds.exe | TCP Query User{669118A9-24A6-42E6-9CA7-4EB70A9B9C97}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{6810E942-D3AA-4F52-AA55-B72A7B5D26D4}C:\users\maciej\desktop\333 - kopia\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\333 - kopia\metin2client.bin | TCP Query User{68CBC00A-EB8B-4444-BBB5-6E088C7F5F26}C:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\ahrimania.exe -> profile=private | protocol=6 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\ahrimania.exe | TCP Query User{6B10F6A0-43EF-4D38-ACB0-9C9151F284A9}C:\program files (x86)\metin2.ae\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2.ae\metin2.bin | TCP Query User{6CD7A7AB-6348-4FD5-B518-E5BD06E4874F}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia\hl.exe | TCP Query User{6D3B46C6-447E-4191-AFE3-B5FE8285FCA3}C:\users\maciej\desktop\programy\metin2\metin.exe -> profile=private | protocol=6 | dir=in | action=allow | name=metin.exe | app=c:\users\maciej\desktop\programy\metin2\metin.exe | TCP Query User{6D656199-E11C-49A7-8FB6-4D90F473B6CC}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{6F1F0B3A-BB54-4A08-9702-2BEA8AC24748}C:\users\maciej\desktop\metin2 dmg + mh\metin2client1.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client1.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client1.bin | TCP Query User{6F626094-9AED-4584-8B9A-A75041621FD1}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{6FEF5ED6-78D1-4682-8EB6-4DF57FF29A5B}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{71245A98-29D4-40D5-8B8B-DB047EDFD9CD}C:\users\maciej\desktop\metin2 - kopia - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia - kopia\metin2.bin | TCP Query User{7163071B-58CD-4E5F-999C-7A27E1E0781E}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{72BD6BE3-3B5E-4D86-BEC9-AE569125FD21}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{73A4288C-E8FC-4EAB-826D-CD35DEC5016E}C:\users\maciej\desktop\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\hl.exe | TCP Query User{73B17183-6E25-4CD1-83F9-CE2376AAF44C}C:\program files (x86)\empire earth ii\ee2.exe -> profile=private | protocol=6 | dir=in | action=allow | name=empire earth ii | app=c:\program files (x86)\empire earth ii\ee2.exe | TCP Query User{73CEDCFE-8E72-49B6-93E8-7CF1C1BD70DD}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia (2)\hl.exe | TCP Query User{7428CA36-7187-4B28-9AB3-E2F7C91959BC}C:\users\maciej\desktop\counter-strikeeee - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee - kopia - kopia\hl.exe | TCP Query User{77013A61-7E80-4E4B-A46E-0B11D28B0C0F}D:\rakionis\bin\rakion.exe -> profile=private | protocol=6 | dir=in | action=allow | name=rakion | app=d:\rakionis\bin\rakion.exe | TCP Query User{7E13DB54-D68C-4DBD-8897-C4ADECFC26F7}C:\users\maciej\desktop\launcher.exe -> profile=private | protocol=6 | dir=in | action=allow | name=launcher.exe | app=c:\users\maciej\desktop\launcher.exe | TCP Query User{7E87C8EC-CB42-4A72-9C5F-C21792B4A30F}C:\users\maciej\desktop\metin 2 - kopia - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia - kopia\metin2.bin | TCP Query User{7EF5F184-B8FA-421B-A819-76125BECD0EC}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{7F2ACA95-545F-4593-911F-CE41DF4CED93}C:\program files (x86)\reality pump\polanie ii\polanieii.ex2 -> profile=private | protocol=6 | dir=in | action=allow | name=knightshift | app=c:\program files (x86)\reality pump\polanie ii\polanieii.ex2 | TCP Query User{7F2FBB6D-20DB-4B71-AC1C-ED7F099268B1}C:\counter strike 1.6 v32\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=c:\counter strike 1.6 v32\hl.exe | TCP Query User{7FBE7982-D960-49B7-9C5E-D4462CE4F974}C:\users\maciej\desktop\metin2 - kopia\metin2modpl.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2modpl.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2modpl.bin | TCP Query User{80BD6FD4-88AB-455A-BB78-4030BAB8E13A}C:\program files (x86)\internet explorer\iexplore.exe -> profile=private | protocol=6 | dir=in | action=allow | name=internet explorer | app=c:\program files (x86)\internet explorer\iexplore.exe | TCP Query User{83CAFC37-AFA2-44C5-99ED-1795347E5456}C:\users\maciej\desktop\programy\metin2\metin2bot.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2bot.bin | app=c:\users\maciej\desktop\programy\metin2\metin2bot.bin | TCP Query User{842B7D1D-356F-4FC7-889F-191D3D440FCA}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (3)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (3)\hl.exe | TCP Query User{84CF0C34-5AD2-4853-BD18-9DCEB0FEA4B7}C:\users\maciej\desktop\nowy folder - kopia (2)\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\nowy folder - kopia (2)\metin2client.bin | TCP Query User{85F202AB-B23C-4C58-8893-4A09FBB55852}C:\users\maciej\desktop\counter-strike 1.6 - kopia\counter-strike 1.6\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia\counter-strike 1.6\hl.exe | TCP Query User{8764A37B-0A2F-4757-8326-353EC841B7B1}C:\program files (x86)\metin2_pl\metin2.bin -> profile=public | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2_pl\metin2.bin | TCP Query User{882DC492-8B9E-4FA2-BCE0-9ACF917096E5}C:\users\maciej\desktop\444\thenextland.exe -> profile=private | protocol=6 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\444\thenextland.exe | TCP Query User{888D8D1B-0681-474E-AB26-7AE8A5309803}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (2)\hl.exe | TCP Query User{89A39CC3-D745-40B3-80F9-1D367E14E5A0}C:\program files\metin 2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\program files\metin 2\metin2.bin | TCP Query User{89A70BB4-5327-4E05-982F-50BDACBC7AB8}C:\program files (x86)\rise of nations - rise of legends\legends.exe -> profile=private | protocol=6 | dir=in | action=allow | name=rise of legends | app=c:\program files (x86)\rise of nations - rise of legends\legends.exe | TCP Query User{8E11745F-9509-4E0C-ACA0-9BFDDB7EEBA0}C:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe | TCP Query User{8E925AC0-5DCE-4ADE-B107-2AB86B3B05CF}C:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe -> profile=public | protocol=6 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe | TCP Query User{8F1D753C-7DFF-4E47-8FA9-256D9819DF2E}C:\users\maciej\desktop\programy\totalcmd\totalcmd\totalcmd.exe -> profile=private | protocol=6 | dir=in | action=allow | name=totalcmd.exe | app=c:\users\maciej\desktop\programy\totalcmd\totalcmd\totalcmd.exe | TCP Query User{8F70679D-D539-4FFA-AF5F-37F7A3B6F747}C:\users\maciej\desktop\metin2\metin2client.bin -> profile=public | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2\metin2client.bin | TCP Query User{916D918C-F221-4FC3-8FB3-D2FBD626AB77}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{936F3172-0B10-4245-9D30-855806F0D53E}C:\users\maciej\desktop\metin2 priv\metin2mod.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\metin2 priv\metin2mod.bin | TCP Query User{93D9950B-9435-4CB4-B9E6-6DA547EC1DDE}C:\users\maciej\desktop\programy\metin2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\programy\metin2\metin2.bin | TCP Query User{9458EF1F-5642-4782-8258-9D714EA7ED7B}C:\users\maciej\desktop\counter-strikee\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikee\hl.exe | TCP Query User{94B5BD92-1DBE-46C0-8CF0-73213BA82CF4}C:\users\maciej\desktop\nowy folder - kopia\thenextland.exe -> profile=private | protocol=6 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\nowy folder - kopia\thenextland.exe | TCP Query User{99C0331C-EC2D-4965-96C6-C243A858034F}C:\opera\opera.exe -> profile=private | protocol=6 | dir=in | action=allow | name=opera internet browser | app=c:\opera\opera.exe | TCP Query User{9A00908A-4DAA-4A74-AC28-C4A9A1DE3403}C:\users\maciej\desktop\metin 2 - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia\metin2.bin | TCP Query User{9A1704C7-B7D5-4611-AA13-65057B31C437}C:\wapster\aqq\aqq.exe -> profile=public | protocol=6 | dir=in | action=block | name=aqq | app=c:\wapster\aqq\aqq.exe | TCP Query User{9A428530-967D-473B-94BD-5ED51EED931A}C:\users\maciej\desktop\metin2 dmg + mh\metin2client4.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client4.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client4.bin | TCP Query User{9B9DFA80-7789-45E6-996F-E8C5D1D79ACC}C:\program files (x86)\flashget\flashget.exe -> profile=public | protocol=6 | dir=in | action=allow | name=flashget | app=c:\program files (x86)\flashget\flashget.exe | TCP Query User{9CAE5BE6-7597-4A05-BDF9-E849EDF5A587}C:\program files (x86)\metin2.ae\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2.ae\metin2client.bin | TCP Query User{9F3E4823-2795-4076-A720-B08CF3EFBC21}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia\hl.exe | TCP Query User{A094B0A5-79C8-47F9-928F-0521BAD52D35}C:\downloads\counter-strike 1.6\counter-strike 1.6\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=c:\downloads\counter-strike 1.6\counter-strike 1.6\hl.exe | TCP Query User{A231A0EE-4A0A-43C3-923A-6BE925DFB4FD}C:\users\maciej\desktop\metin2bot\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2bot\metin2client.bin | TCP Query User{A2489C43-60F9-4528-A09D-F355D1CFB9C0}C:\users\maciej\desktop\counter-strikeeee - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee - kopia\hl.exe | TCP Query User{A32C6323-CB4A-4DDD-9901-A2229F224272}C:\users\maciej\desktop\444\metin2client3.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client3.bin | app=c:\users\maciej\desktop\444\metin2client3.bin | TCP Query User{A409B30E-08EA-4669-893C-E3FC5B24B9AE}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{A4E70122-A109-4461-BC96-A29E1455647E}D:\metin2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=d:\metin2\metin2.bin | TCP Query User{A5F8A5E7-79E1-4BD1-9ACC-C686A1C117F0}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{A62C66F5-8D19-4757-8ED5-CD0B15D4D49D}C:\users\maciej\desktop\counter-strike 1.6\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6\hl.exe | TCP Query User{A6C5F58C-4A39-424A-8548-11B76F3A5380}C:\astral masters\masters.exe -> profile=private | protocol=6 | dir=in | action=block | name=masters | app=c:\astral masters\masters.exe | TCP Query User{A795DF72-8D20-42A2-9667-47BC929DBB5E}C:\windows\syswow64\dpnsvr.exe -> profile=private | protocol=6 | dir=in | action=allow | name=microsoft directplay8 server | app=c:\windows\syswow64\dpnsvr.exe | TCP Query User{AC01073A-0C37-4C40-9703-62AF03A07C55}C:\program files (x86)\ares\ares.exe -> profile=private | protocol=6 | dir=in | action=allow | name=ares p2p for windows | app=c:\program files (x86)\ares\ares.exe | TCP Query User{AD848A4D-2AC6-4719-8BE3-F0E1A23AE865}C:\users\maciej\desktop\metin2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2\metin2.bin | TCP Query User{ADCDED78-9BD4-45D9-95BE-04026F5B7DED}C:\program files (x86)\nowe gadu-gadu\gg.exe -> profile=public | protocol=6 | dir=in | action=allow | name=nowe gadu-gadu | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | TCP Query User{ADFF073E-003A-41AA-BB5D-8707DD6235FC}C:\users\maciej\desktop\nowy folder (2)\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder (2)\counter-strike\hl.exe | TCP Query User{AEE20244-3613-4E3B-B97A-A0224C7A8418}C:\program files (x86)\metin2\metin2client.bin -> profile=public | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2\metin2client.bin | TCP Query User{B030F9B0-0836-4E30-9206-AD50DFAC13CD}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{B090366E-B898-47BD-952D-D35C3A48162A}C:\users\maciej\desktop\counter-strike - kopia - kopia (2)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2)\hl.exe | TCP Query User{B16DD97F-C470-4D28-8970-D1B26A47A42B}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hltv.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hltv.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hltv.exe | TCP Query User{B3AB6084-C5F4-46E6-8965-898D293902EE}C:\program files (x86)\steam\steamapps\aimbot15\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=c:\program files (x86)\steam\steamapps\aimbot15\counter-strike\hl.exe | TCP Query User{B3EB4079-DC34-433E-8F28-6E708A683ECF}C:\users\maciej\desktop\333\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\333\metin2.bin | TCP Query User{B3EE928C-E7EE-4006-913E-C8D3D33B0CA6}C:\users\maciej\desktop\counter-strike - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia\hl.exe | TCP Query User{B43E5D99-492C-43B5-A582-D812D852B2D9}C:\users\maciej\program files (x86)\dna\btdna.exe -> profile=public | protocol=6 | dir=in | action=block | name=btdna.exe | app=c:\users\maciej\program files (x86)\dna\btdna.exe | TCP Query User{B44DF9B4-5776-4E2D-A6BF-F7213D3CCFDA}C:\users\maciej\desktop\nowy folder - kopia (2)\metin2.exe -> profile=private | protocol=6 | dir=in | action=block | name=metin2.exe | app=c:\users\maciej\desktop\nowy folder - kopia (2)\metin2.exe | TCP Query User{B511F04B-3AAC-44AE-AAC7-F4CA62999BD3}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{B52CD7AB-8617-47D2-BF2B-630B5789304B}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{B657DC1F-3BA2-48D6-B277-B81F3241290C}C:\users\maciej\desktop\nowy folder\diwang2 by tetleyu.exe -> profile=private | protocol=6 | dir=in | action=block | name=diwang2 by tetleyu.exe | app=c:\users\maciej\desktop\nowy folder\diwang2 by tetleyu.exe | TCP Query User{B99A2F48-4423-414C-91A2-8CD07FD82907}C:\users\maciej\desktop\programy\counter-strike\hlds.exe -> profile=public | protocol=6 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\programy\counter-strike\hlds.exe | TCP Query User{BA6BEA51-9113-40FE-9EB5-6CDEF123320E}C:\users\maciej\desktop\metin2 dmg + mh\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client.bin | TCP Query User{BA9B33AD-B943-471C-BFF3-CE84E5D32FE8}C:\users\maciej\desktop\nowy folder\thenextland.exe -> profile=private | protocol=6 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\nowy folder\thenextland.exe | TCP Query User{BB6026AE-320A-408A-9856-BF19B5517CDC}C:\users\maciej\desktop\metin2 tornado\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 tornado\metin2client.bin | TCP Query User{BB64F6A5-B4F6-4DE2-9104-6BC2BB92E53E}C:\program files (x86)\metin2_pl\zoom.nebel.exe -> profile=private | protocol=6 | dir=in | action=allow | name=zoom.nebel | app=c:\program files (x86)\metin2_pl\zoom.nebel.exe | TCP Query User{BC41A459-A647-446C-958C-FEE4104A61D9}C:\users\maciej\desktop\metin2 dmg + mh - kopia\metin2mod.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\metin2 dmg + mh - kopia\metin2mod.bin | TCP Query User{BD90078B-C3E5-4762-96E5-4F13CEC175D6}C:\users\maciej\desktop\astral.exe -> profile=private | protocol=6 | dir=in | action=allow | name=astral.exe | app=c:\users\maciej\desktop\astral.exe | TCP Query User{BF8329D4-FAAF-4F1B-8148-91912D9963FB}C:\users\maciej\desktop\programy\metin2\zoom.nebel.exe -> profile=private | protocol=6 | dir=in | action=allow | name=zoom.nebel.exe | app=c:\users\maciej\desktop\programy\metin2\zoom.nebel.exe | TCP Query User{C2926FCF-87D2-4695-B7E8-6BF7BDC7307E}M:\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=half-life launcher | app=m:\counter-strike\hl.exe | TCP Query User{C353C301-757D-400B-90E1-B621CA031E3C}C:\users\maciej\desktop\444 - kopia\metin2mod.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2mod.bin | app=c:\users\maciej\desktop\444 - kopia\metin2mod.bin | TCP Query User{C5698162-C628-4467-82F3-72C700F926B6}C:\users\maciej\desktop\counter-strikeee\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeee\hl.exe | TCP Query User{C66F2689-AA14-4241-9D2A-302AE90E1C07}C:\users\maciej\desktop\metin2 dmg + mh\metin2client3.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client3.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client3.bin | TCP Query User{C789AEE9-9755-4B50-B140-1208FF463DA3}C:\program files (x86)\empire earth ii\ee2.exe -> profile=public | protocol=6 | dir=in | action=block | name=empire earth ii | app=c:\program files (x86)\empire earth ii\ee2.exe | TCP Query User{CA9EFECA-B832-44C2-9DCA-C030209F45FF}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{CBB34C4C-388C-41ED-B0AF-3D20006D7511}C:\program files (x86)\gadu-gadu\gg.exe -> profile=public | protocol=6 | dir=in | action=block | name=gadu-gadu - program główny | app=c:\program files (x86)\gadu-gadu\gg.exe | TCP Query User{CDE1246D-89FE-4127-85BF-5BD76595F35F}C:\users\maciej\desktop\metin2 - kopia\metin2client.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2client.bin | TCP Query User{D14E325E-AC5A-425C-BFBD-0706486C44F6}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{D2848A4D-895E-4E10-A397-8E75C3717822}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{D455549F-F3D6-496C-8B07-31984FBFCBBE}C:\users\maciej\desktop\counter-strike\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\hl.exe | TCP Query User{D4B751F0-0DDB-4D06-81B8-918500ED5A0F}C:\users\maciej\appdata\local\temp\pyl4c0e.tmp\pyrun.exe -> profile=public | protocol=6 | dir=in | action=allow | name=pyrun.exe | app=c:\users\maciej\appdata\local\temp\pyl4c0e.tmp\pyrun.exe | TCP Query User{D6E5EB7A-8A2E-4F33-8274-F1008D09F903}C:\users\maciej\desktop\counter-strikeeee\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee\hl.exe | TCP Query User{D7A90778-E00C-4703-86D3-4CE914AC444D}C:\users\maciej\desktop\metin2 - kopia (2)\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia (2)\metin2client.bin | TCP Query User{D9122A34-E8F6-416A-8498-AEB69C7D51B4}C:\users\maciej\desktop\ahrimania killer\ahrimania\metin2mod.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\ahrimania killer\ahrimania\metin2mod.bin | TCP Query User{D974737E-6D36-4161-AF88-D16AC67FBDC2}C:\users\maciej\desktop\nowy folder\tnlmt2.bin -> profile=private | protocol=6 | dir=in | action=block | name=tnlmt2.bin | app=c:\users\maciej\desktop\nowy folder\tnlmt2.bin | TCP Query User{DB2E6F6A-DD45-4343-A70E-7195E7F6DE63}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{DF2CA7CC-F55E-4E12-B46E-5720D0900844}C:\program files (x86)\metin2\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2\metin2.bin | TCP Query User{E0807E50-0875-4C36-A6ED-71372CCF7A6C}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{E09245F1-D9EE-44EF-BD06-3D6FE097DBE8}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{E19AB5CF-1B28-48E5-8721-B3BC3A2241BB}C:\users\maciej\desktop\444\metin2client4.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client4.bin | app=c:\users\maciej\desktop\444\metin2client4.bin | TCP Query User{E2062E53-04E6-447D-805D-6073E3EC7BC3}C:\users\maciej\desktop\programy\metin2\metin2.bin -> profile=public | protocol=6 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\programy\metin2\metin2.bin | TCP Query User{E39A3654-8D03-446E-8871-1E77C6190765}C:\users\maciej\desktop\metin2 - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2.bin | TCP Query User{E464F8FA-3283-4D7D-A6C3-B5251B6F038B}C:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hlds.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hlds.exe | TCP Query User{E64BA66D-1704-455C-8591-CD6E184E0398}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{E7128963-69A0-4105-B104-55763FCE0637}C:\users\maciej\desktop\nowy folder\dergal.exe -> profile=private | protocol=6 | dir=in | action=block | name=dergal.exe | app=c:\users\maciej\desktop\nowy folder\dergal.exe | TCP Query User{E795D019-E8C2-40FE-8D47-A9D8BB8555DC}C:\users\maciej\desktop\333\metin2bot.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2bot.bin | app=c:\users\maciej\desktop\333\metin2bot.bin | TCP Query User{E88AC38C-74C7-4EBC-8EC6-5A39EB3A0D59}C:\users\maciej\desktop\333\metin2client.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\333\metin2client.bin | TCP Query User{EA85B7CB-2EC5-49FC-A8F3-21BDBAED2FF2}C:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hl.exe | TCP Query User{EB702E84-3EE8-43BA-A8DA-B7812765E8A4}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{EB8A00AC-551F-490E-92F5-4D65A2DB0BB2}C:\users\maciej\desktop\cs\hl.exe -> profile=public | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\cs\hl.exe | TCP Query User{ECC18F74-62F4-45B7-9E5E-783FDD4E6B92}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2)\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2)\hl.exe | TCP Query User{ECCBC190-B612-40E1-99EF-B8D5AE16B932}C:\users\maciej\desktop\programy\counter-strike\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\programy\counter-strike\hl.exe | TCP Query User{EE59354F-F3B0-4272-91E6-F5D5ED97E244}C:\program files (x86)\counter-strike\hltv.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hltv launcher | app=c:\program files (x86)\counter-strike\hltv.exe | TCP Query User{EFE1F885-60C7-4957-B287-25F8BF1B07BC}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{F181D173-754E-4AE0-9E09-EF47657CCEF6}C:\program files (x86)\nowe gadu-gadu\gg.exe -> profile=private | protocol=6 | dir=in | action=allow | name=nowe gadu-gadu | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | TCP Query User{F2CDCAFB-914A-490A-94DF-244A1638A53A}C:\users\maciej\desktop\counter-strike\counter-strike\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\counter-strike\hl.exe | TCP Query User{F410E9CA-FB5A-493D-8C5F-2EE6A47F5929}C:\users\maciej\desktop\metin2 thenextland\thenextland.exe -> profile=private | protocol=6 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\metin2 thenextland\thenextland.exe | TCP Query User{F61C6F0C-EA29-4B09-81D4-FA1AB01AB687}C:\program files (x86)\astral\astral.exe -> profile=private | protocol=6 | dir=in | action=allow | name=astral | app=c:\program files (x86)\astral\astral.exe | TCP Query User{F8CDCF39-9F4D-4FE1-A25B-C01A25C2A1BB}C:\users\maciej\appdata\local\virtualstore\program files\metin 2 - kopia\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\appdata\local\virtualstore\program files\metin 2 - kopia\metin2.bin | TCP Query User{F8E695CC-C3DA-4114-A606-7E3DD0F4CDA3}C:\program files (x86)\metin2_pl\metin2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2_pl\metin2.bin | TCP Query User{F9355DC1-6DFA-4901-A936-CC16CB3FF609}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{F97F292D-CDCA-4B46-B124-AD5B76D931A5}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{F9B6882D-B067-4772-80CD-193706009D33}C:\users\maciej\desktop\counter-strik\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strik\hl.exe | TCP Query User{FA4810E3-E341-41CE-BFC4-2CFD8EAA197A}C:\enemy flag\efserver.exe -> profile=public | protocol=6 | dir=in | action=allow | name=efserver | app=c:\enemy flag\efserver.exe | TCP Query User{FAC30619-9610-4C88-A6E1-6C7C697BC566}C:\program files (x86)\wesnoth 1.4\wesnothd.exe -> profile=public | protocol=6 | dir=in | action=block | name=wesnothd | app=c:\program files (x86)\wesnoth 1.4\wesnothd.exe | TCP Query User{FB134597-538F-40C6-88DF-008BCE30D6BB}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=6 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | TCP Query User{FB80F38B-1BF8-44EA-9C5C-E59339B51D48}C:\users\maciej\desktop\metin2 dmg + mh\metin2client2.bin -> profile=private | protocol=6 | dir=in | action=allow | name=metin2client2.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client2.bin | TCP Query User{FBB213FC-1F07-475A-ABEE-F79888F5BAEF}C:\users\maciej\desktop\444\metin2.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\444\metin2.bin | TCP Query User{FE0ADFD2-BBD6-4A81-8E8B-6E2873B25308}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia\hl.exe | TCP Query User{FE531052-F8D6-4954-900F-166ACDEB2118}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia\hl.exe -> profile=private | protocol=6 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia\hl.exe | TCP Query User{FF70F3CB-EF20-47D2-9C88-F0AB6435F28D}C:\users\maciej\desktop\444\metin2client2.bin -> profile=private | protocol=6 | dir=in | action=block | name=metin2client2.bin | app=c:\users\maciej\desktop\444\metin2client2.bin | UDP Query User{00BC5CFD-14D6-4C63-B476-DC81FCB3CBAA}C:\users\maciej\desktop\programy\totalcmd\totalcmd\totalcmd.exe -> profile=private | protocol=17 | dir=in | action=allow | name=totalcmd.exe | app=c:\users\maciej\desktop\programy\totalcmd\totalcmd\totalcmd.exe | UDP Query User{04CA0103-BD30-4C71-B787-E12EAF31AC01}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{05553CE7-74E3-42D9-8BC7-95F7B80D3B0B}C:\users\maciej\desktop\programy\metin2\metin2client.bin -> profile=public | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\programy\metin2\metin2client.bin | UDP Query User{0634DE02-24ED-4289-989D-56A34176750D}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{0674AC7B-1696-4437-8B34-EC9BBB2BCA15}C:\program files (x86)\counter-strike\hltv.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hltv launcher | app=c:\program files (x86)\counter-strike\hltv.exe | UDP Query User{06D2A28F-5724-48CC-98DC-853C4011415E}C:\users\maciej\desktop\nowy folder (2)\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder (2)\counter-strike\hl.exe | UDP Query User{0753896E-F73C-48A9-A86F-E5AB6C05B8EA}C:\program files (x86)\reality pump\polanie ii\polanieii.ex2 -> profile=private | protocol=17 | dir=in | action=allow | name=knightshift | app=c:\program files (x86)\reality pump\polanie ii\polanieii.ex2 | UDP Query User{08424999-4172-4A8B-9E9B-5664A628AA56}C:\users\maciej\desktop\metin2\metin2client.bin -> profile=public | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2\metin2client.bin | UDP Query User{08A5663B-D1A7-4D45-86AF-FA11EA9AEAAE}C:\users\maciej\desktop\metin2 - kopia\metin2client.bin -> profile=public | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2client.bin | UDP Query User{0A204344-8096-4649-879A-C7B151D16307}C:\program files (x86)\gadu-gadu\gg.exe -> profile=public | protocol=17 | dir=in | action=block | name=gadu-gadu - program główny | app=c:\program files (x86)\gadu-gadu\gg.exe | UDP Query User{0A3BCA63-6F80-4314-9630-75027381F6C5}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{0A527BF1-8273-4775-95AB-5D6DDCA2F63F}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{0A8A83AD-2823-4F95-BAE7-8CB82AE02268}C:\program files (x86)\metin2.ae\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2.ae\metin2.bin | UDP Query User{0B075F10-3B8A-421D-A037-68354D516677}C:\program files (x86)\metin2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2\metin2.bin | UDP Query User{0B6F9899-2416-44B3-B76C-C6A7DDD1EAAE}C:\counter strike 1.6 v32\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=c:\counter strike 1.6 v32\hl.exe | UDP Query User{0D5A67F0-B114-441A-B48C-E2C27A0EB2DE}C:\users\maciej\desktop\metin2 - kopia\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2client.bin | UDP Query User{0E54D77D-D7FE-4AAE-B299-B00F97B5E403}C:\users\maciej\desktop\launcher.exe -> profile=private | protocol=17 | dir=in | action=allow | name=launcher.exe | app=c:\users\maciej\desktop\launcher.exe | UDP Query User{0EFD7F48-6E39-4C45-AA76-386A66D30212}D:\rakionis\bin\rakion.exe -> profile=private | protocol=17 | dir=in | action=allow | name=rakion | app=d:\rakionis\bin\rakion.exe | UDP Query User{0FCD9737-C36C-425C-B2BB-280CA9452BD4}C:\users\maciej\desktop\nowy folder - kopia\thenextland.exe -> profile=private | protocol=17 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\nowy folder - kopia\thenextland.exe | UDP Query User{1073AA5C-D7DC-4144-A9ED-FA05155AF898}C:\users\maciej\desktop\ahrimania dmg\ahrimania\ahrimania.exe -> profile=private | protocol=17 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania dmg\ahrimania\ahrimania.exe | UDP Query User{108C9FB4-EF6B-4D4F-965C-98F6A1143AED}C:\users\maciej\desktop\nowy folder\thenextland.exe -> profile=private | protocol=17 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\nowy folder\thenextland.exe | UDP Query User{11DCF127-5425-4558-A766-C091F2C9DBEE}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{12E53940-CDFD-4269-80B6-C3EF22725CA1}C:\users\maciej\desktop\counter-strikeeee\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee\hl.exe | UDP Query User{148F74D7-0C41-4C2E-AECA-0CBD81F08489}C:\users\maciej\desktop\counter-strike - kopia - kopia (2)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2)\hl.exe | UDP Query User{157B35DB-0F23-4507-9A6E-DB4BF982065D}C:\windows\syswow64\dpnsvr.exe -> profile=private | protocol=17 | dir=in | action=allow | name=microsoft directplay8 server | app=c:\windows\syswow64\dpnsvr.exe | UDP Query User{16FD69A1-C16A-40AA-B5B5-76E20BFD7F0B}C:\users\maciej\desktop\metin 2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2\metin2.bin | UDP Query User{176E0714-B393-4817-90DA-A0D22319E6D8}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia (2)\hl.exe | UDP Query User{177ED22F-B014-410A-88A2-3D27642ACF1D}C:\users\maciej\desktop\programy\counter-strike\hlds.exe -> profile=public | protocol=17 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\programy\counter-strike\hlds.exe | UDP Query User{1A13825F-C3CA-4062-AC2B-7ED46E127774}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hltv.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hltv.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hltv.exe | UDP Query User{1E46284E-A451-4108-9359-4F27A3F4ACA6}C:\users\michał\desktop\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\michał\desktop\counter-strike\hl.exe | UDP Query User{1E51BB4B-14C2-47E3-8B8D-1A70709E8F72}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (2)\hl.exe | UDP Query User{1FD24E67-DF13-440E-9820-FCB88E0F88B2}C:\users\maciej\desktop\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\hl.exe | UDP Query User{209BCB1A-693C-424E-B613-1633482B43AE}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{2270BE6B-1F4A-473E-B698-E38C4BC37FC9}C:\users\maciej\desktop\counter-strike - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia\hl.exe | UDP Query User{236B28B6-25CF-4A1D-9A85-0FFA349FF649}C:\users\maciej\desktop\metin2 dmg + mh - kopia\metin2mod.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\metin2 dmg + mh - kopia\metin2mod.bin | UDP Query User{242470AA-D976-4D88-9375-0198809F5705}C:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe -> profile=public | protocol=17 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe | UDP Query User{265BD474-ED7E-4D37-AB5A-2861DD544CB7}C:\users\wioletta\desktop\counter-strike\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\wioletta\desktop\counter-strike\hl.exe | UDP Query User{273669BD-7D88-4F35-83F2-81BEAE8E707B}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{289176A8-2D92-4EA0-ACFD-045E70D6BB33}C:\program files (x86)\java\jre6\bin\java.exe -> profile=private | protocol=17 | dir=in | action=allow | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\java.exe | UDP Query User{28E4BEA4-132F-4C75-9040-B073A454C0E6}C:\users\maciej\desktop\metin2 priv\thenextland.exe -> profile=private | protocol=17 | dir=in | action=block | name=thenextland.exe | app=c:\users\maciej\desktop\metin2 priv\thenextland.exe | UDP Query User{2905238C-EFCB-45CE-83E9-CDEEAC1761B6}C:\opera\opera.exe -> profile=private | protocol=17 | dir=in | action=allow | name=opera internet browser | app=c:\opera\opera.exe | UDP Query User{291A56E7-64E4-4994-9554-5022168E0C6A}C:\users\maciej\desktop\metin2 priv\belenus.exe -> profile=private | protocol=17 | dir=in | action=block | name=belenus.exe | app=c:\users\maciej\desktop\metin2 priv\belenus.exe | UDP Query User{29E8C09C-1E49-4CF3-BB2B-7DC26C7A8298}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{2B994641-786E-4C09-B7B8-0F060475E901}D:\metin2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=d:\metin2\metin2.bin | UDP Query User{2D905824-D058-4BCD-9D41-4A4B0D21F419}C:\users\maciej\desktop\counter-strikeee\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeee\hl.exe | UDP Query User{2ECCE17C-A227-49D7-875C-49A6BFCE8E0A}D:\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=d:\counter-strike\hl.exe | UDP Query User{2F02836B-AF7C-4039-8F71-D84AC5D734BF}C:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\ahrimania.exe -> profile=private | protocol=17 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\ahrimania.exe | UDP Query User{2F2BC679-7AFF-4235-9D61-867AC82780EB}C:\program files (x86)\mirc\mirc.exe -> profile=private | protocol=17 | dir=in | action=allow | name=mirc | app=c:\program files (x86)\mirc\mirc.exe | UDP Query User{301B5F1A-6901-4611-83CA-D4FE0A229133}C:\users\maciej\desktop\metin2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2\metin2.bin | UDP Query User{3066EDB6-30E5-42FB-9289-B9DEB0E7BD1A}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{3148A908-7575-4C5A-B55E-08F4EB370435}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{3286D275-C059-4659-9DA4-D8E1A52BA8DF}C:\program files (x86)\metin2_pl\zoom.nebel.exe -> profile=private | protocol=17 | dir=in | action=allow | name=zoom.nebel | app=c:\program files (x86)\metin2_pl\zoom.nebel.exe | UDP Query User{32FF6D65-092F-4717-8F37-5578F4E4E25C}C:\enemy flag\efserver.exe -> profile=private | protocol=17 | dir=in | action=allow | name=efserver | app=c:\enemy flag\efserver.exe | UDP Query User{35265C0F-DA8D-4790-AC92-655F2EE430F6}C:\users\maciej\desktop\metin2 - kopia (2)\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia (2)\metin2.bin | UDP Query User{35A2F3AA-1A58-4508-8E82-724585745E3F}C:\users\maciej\program files (x86)\dna\btdna.exe -> profile=private | protocol=17 | dir=in | action=allow | name=btdna.exe | app=c:\users\maciej\program files (x86)\dna\btdna.exe | UDP Query User{36E1C91F-4E0B-4146-B3F2-B1A089E36895}C:\users\maciej\desktop\counter-strik - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strik - kopia\hl.exe | UDP Query User{3769036D-9112-47DB-B049-6CCCAC4A01B5}C:\users\maciej\desktop\nowy folder\xlast.exe -> profile=private | protocol=17 | dir=in | action=block | name=xlast.exe | app=c:\users\maciej\desktop\nowy folder\xlast.exe | UDP Query User{3A629CF2-70DE-4959-B983-111723BEE5B4}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia\hl.exe | UDP Query User{3B0B52E3-A98C-48A4-8B90-8D1BD6010EDC}C:\users\maciej\desktop\333 - kopia\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\333 - kopia\metin2client.bin | UDP Query User{3CDA5AED-F403-49E9-83FD-EDE40558B82B}C:\astral masters\masters.exe -> profile=private | protocol=17 | dir=in | action=block | name=masters | app=c:\astral masters\masters.exe | UDP Query User{3D1062F0-2C15-4ACA-97E0-68FA4448A396}C:\users\maciej\desktop\counter-strike 1.6\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6\hl.exe | UDP Query User{3D38AA46-BA66-4210-BE63-65473AE1E523}C:\users\maciej\desktop\metin2 - kopia (3)\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia (3)\metin2client.bin | UDP Query User{3EDE9457-61F5-4F52-9C7E-01C986F3B021}C:\users\maciej\desktop\counter-strikes - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia\hl.exe | UDP Query User{3F3B8DB5-9A03-4E83-9DB4-76622FB67797}C:\users\maciej\desktop\nowy folder\dergal.exe -> profile=private | protocol=17 | dir=in | action=block | name=dergal.exe | app=c:\users\maciej\desktop\nowy folder\dergal.exe | UDP Query User{42C62918-6357-4A14-AB53-29ED2D440D6A}C:\users\maciej\desktop\333\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\333\metin2.bin | UDP Query User{447D40AD-3E13-488D-89DC-480993AE14BA}C:\users\maciej\desktop\444\metin2.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\444\metin2.bin | UDP Query User{4480C805-73EC-45D1-8FDC-4430810E23FD}C:\users\maciej\desktop\nowy folder\counter-strikeeee\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder\counter-strikeeee\hl.exe | UDP Query User{46E66AF3-743B-47C2-A60C-D027F4B7361E}C:\users\maciej\desktop\metin2 dmg + mh\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client.bin | UDP Query User{47499E6E-84A8-493A-B235-C50ABC9E8522}C:\users\maciej\desktop\programy\metin2\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\programy\metin2\metin2client.bin | UDP Query User{47778C4B-4B3A-4A00-8F52-CFA42A57992E}C:\users\maciej\desktop\programy\cs\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\programy\cs\hl.exe | UDP Query User{4915E0DD-CE2E-4A32-A605-8E2F4ED7EFED}C:\users\maciej\desktop\metin2 priv\metin2mod.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\metin2 priv\metin2mod.bin | UDP Query User{4966C319-26E3-415A-B9C7-9498741F484A}C:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\metin2mod.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\ahrimania killer - kamer mod\ahrimania\metin2mod.bin | UDP Query User{49C969E7-8F59-4CCC-9C35-6D63CEA9A5BD}C:\empire earth ii\ee2.exe -> profile=private | protocol=17 | dir=in | action=allow | name=empire earth ii | app=c:\empire earth ii\ee2.exe | UDP Query User{4BC5047C-1823-4A35-9016-13948AD2EB59}D:\metin2\metin2client.bin -> profile=public | protocol=17 | dir=in | action=block | name=metin2client.bin | app=d:\metin2\metin2client.bin | UDP Query User{4BFB3405-2090-42D0-A690-185E1169C159}M:\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=m:\counter-strike\hl.exe | UDP Query User{4C321B09-C0EC-456B-A825-7509E7FE24C4}C:\metin 2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\metin 2\metin2.bin | UDP Query User{4C4739B9-EA1F-4612-9C07-39716C0D81FA}C:\program files (x86)\emule\emule.exe -> profile=private | protocol=17 | dir=in | action=allow | name=emule | app=c:\program files (x86)\emule\emule.exe | UDP Query User{4E6ABF9E-F126-454E-AD6B-6032EE07C942}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{4FA2C6DF-C981-4E58-936D-768B13E73FB7}C:\users\maciej\desktop\333 - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\333 - kopia\metin2.bin | UDP Query User{4FAC82E2-445C-4526-89D2-69159CE6E84D}C:\program files (x86)\flashget\flashget.exe -> profile=public | protocol=17 | dir=in | action=allow | name=flashget | app=c:\program files (x86)\flashget\flashget.exe | UDP Query User{4FFDE798-96F9-4137-AE3C-73B5B4B6A555}C:\users\maciej\desktop\programy\metin2\zoom.nebel.exe -> profile=private | protocol=17 | dir=in | action=allow | name=zoom.nebel.exe | app=c:\users\maciej\desktop\programy\metin2\zoom.nebel.exe | UDP Query User{5150776E-35F0-41BF-BC27-14408D02F0B5}C:\users\maciej\desktop\metin2 - kopia - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia - kopia\metin2.bin | UDP Query User{51F6C644-0C6A-46A5-AECA-4456DBD218FD}C:\users\maciej\desktop\counter-strike - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia\hl.exe | UDP Query User{527A7E30-5EF1-4694-92FD-1B7A155A9A0D}C:\program files (x86)\metin2\metin2client.bin -> profile=public | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2\metin2client.bin | UDP Query User{5330FD45-71FC-4A6E-AEB9-1F20F0944528}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{53BBEEB5-7DCC-4502-AEEF-1E94FDDDF75B}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{574F3BFE-B23F-4586-8008-4E71EEED6279}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia\hl.exe | UDP Query User{5851A4D8-A053-43EE-B010-1B3B1A877A71}C:\users\maciej\desktop\metin 2 - kopia - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia - kopia\metin2.bin | UDP Query User{59373009-9328-496D-AA5B-D71BD1FC89EC}C:\users\maciej\desktop\444\metin2client2.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client2.bin | app=c:\users\maciej\desktop\444\metin2client2.bin | UDP Query User{5A0AF0C6-3E05-4110-83AC-96CDDF3D4910}C:\wapster\aqq\aqq.exe -> profile=private | protocol=17 | dir=in | action=allow | name=aqq | app=c:\wapster\aqq\aqq.exe | UDP Query User{5C286B31-4910-498B-9F90-BDE194FEEE48}C:\users\maciej\desktop\counter-strikee\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikee\hl.exe | UDP Query User{5C7BEF46-9489-4511-9F64-BF2CD01158CF}C:\users\maciej\desktop\programy\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\programy\counter-strike\hl.exe | UDP Query User{5DEA46D1-C635-44EB-91E8-5FB781300EEE}C:\users\maciej\desktop\nowy folder\s-metin2.exe -> profile=private | protocol=17 | dir=in | action=block | name=s-metin2.exe | app=c:\users\maciej\desktop\nowy folder\s-metin2.exe | UDP Query User{5E15D2F8-CBD3-4124-8472-1FFEF88212C9}C:\users\maciej\desktop\metin2\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2\metin2client.bin | UDP Query User{5E4344EB-9CB6-4F17-AA8D-43A7DB14AF2F}C:\users\maciej\desktop\programy\cs\hlds.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\programy\cs\hlds.exe | UDP Query User{61A234D2-CE6F-45F8-A3A2-8534393606C7}C:\users\maciej\desktop\counter-strike 1.6 - kopia\counter-strike 1.6\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia\counter-strike 1.6\hl.exe | UDP Query User{62128DE3-5E83-4A5F-A806-A728E5F27B0C}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{62681911-EFA4-43A2-A8F3-9F44BE071FB5}C:\program files (x86)\steam\steamapps\aimbot15\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=c:\program files (x86)\steam\steamapps\aimbot15\counter-strike\hl.exe | UDP Query User{64CF706B-6AEA-4AF4-8488-7BD0E1CF381C}C:\users\wioletta\desktop\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\wioletta\desktop\counter-strike\hl.exe | UDP Query User{65CBB4FB-F0F4-4F55-972D-CE0BC8B2C802}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{68E0B4A4-1B1D-47D3-BD0E-39E507CFB8FF}C:\users\maciej\desktop\metin 2 - kopia - kopia - kopia - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia - kopia - kopia - kopia\metin2.bin | UDP Query User{691FF9CF-BEBA-4A0D-8C49-F1BAD48C4EB0}C:\users\maciej\desktop\333\metin2bot.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2bot.bin | app=c:\users\maciej\desktop\333\metin2bot.bin | UDP Query User{692C9E74-FCD5-45DA-82AA-D68034FE0833}C:\program files (x86)\opera\opera.exe -> profile=private | protocol=17 | dir=in | action=allow | name=opera internet browser | app=c:\program files (x86)\opera\opera.exe | UDP Query User{695E6A1F-FD9D-45C5-95C9-BA71DDF88B8E}C:\program files (x86)\wesnoth 1.4\wesnothd.exe -> profile=public | protocol=17 | dir=in | action=block | name=wesnothd | app=c:\program files (x86)\wesnoth 1.4\wesnothd.exe | UDP Query User{69EF3AF0-99AF-4C6B-B4FA-1D11508E9AAC}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{6C6E0C6B-29FD-40DC-AB0F-80777BFD1566}C:\users\maciej\desktop\metin2 - kopia (2)\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia (2)\metin2client.bin | UDP Query User{6CE9D00A-A45D-4FD5-B225-6F6EB092D723}C:\users\maciej\desktop\metin2 priv\avalonmt2.exe -> profile=private | protocol=17 | dir=in | action=block | name=avalonmt2.exe | app=c:\users\maciej\desktop\metin2 priv\avalonmt2.exe | UDP Query User{6D7D1276-C9B2-475D-83E2-F37F0EDECFE1}C:\program files (x86)\ares\ares.exe -> profile=public | protocol=17 | dir=in | action=block | name=ares p2p for windows | app=c:\program files (x86)\ares\ares.exe | UDP Query User{720BC63F-07F2-4D5D-8FF4-D7A02CD6381D}C:\enemy flag\efserver.exe -> profile=public | protocol=17 | dir=in | action=allow | name=efserver | app=c:\enemy flag\efserver.exe | UDP Query User{7254231B-F87C-4031-BD81-40FAE8428C0F}C:\downloads\counter-strike 1.6\counter-strike 1.6\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=c:\downloads\counter-strike 1.6\counter-strike 1.6\hl.exe | UDP Query User{73CF61A1-0A70-46CE-AEB1-7703910FF667}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia\hl.exe | UDP Query User{75205871-17C4-4C64-A5A2-4077940A00B7}C:\users\maciej\desktop\444\metin2client4.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client4.bin | app=c:\users\maciej\desktop\444\metin2client4.bin | UDP Query User{77C530F6-4B36-4729-B4AF-D0D0662323ED}C:\users\maciej\desktop\metin2\metin2.bin -> profile=public | protocol=17 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\metin2\metin2.bin | UDP Query User{7AA50517-3D9C-475F-B755-8BD86C6A819E}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2)\hl.exe | UDP Query User{7BB854CA-9EA3-41CA-9A6E-7D890DFAE879}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{7C4A409F-96BB-4B89-8788-FBA469634814}C:\program files (x86)\wesnoth 1.4\wesnothd.exe -> profile=private | protocol=17 | dir=in | action=allow | name=wesnothd | app=c:\program files (x86)\wesnoth 1.4\wesnothd.exe | UDP Query User{7EC36DB5-26C2-4041-B9A2-7C3AA67F022D}D:\rakionis\bin\rakion.bin -> profile=private | protocol=17 | dir=in | action=allow | name=rakion.bin | app=d:\rakionis\bin\rakion.bin | UDP Query User{7ECBACB2-8294-4489-A9FC-474905705EB6}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{814BD330-3DE4-4C10-A106-F08F6CDEF92F}C:\users\maciej\desktop\nowy folder - kopia (2)\metin2.exe -> profile=private | protocol=17 | dir=in | action=block | name=metin2.exe | app=c:\users\maciej\desktop\nowy folder - kopia (2)\metin2.exe | UDP Query User{841B3686-5714-4092-9E43-837A21454240}C:\users\maciej\desktop\nowy folder\x-world.exe -> profile=private | protocol=17 | dir=in | action=block | name=x-world.exe | app=c:\users\maciej\desktop\nowy folder\x-world.exe | UDP Query User{84D2F4A2-3DB1-44E0-A381-A71C74C0D293}C:\users\maciej\desktop\counter-strik\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strik\hl.exe | UDP Query User{86DB6527-CA99-4FB2-B2FB-78A24DFC1095}C:\users\maciej\desktop\programy\metin2\metin2.bin -> profile=public | protocol=17 | dir=in | action=block | name=metin2.bin | app=c:\users\maciej\desktop\programy\metin2\metin2.bin | UDP Query User{87D23114-8D54-45E7-AD11-CBD1521D47B2}C:\users\maciej\desktop\metin2 tornado\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 tornado\metin2client.bin | UDP Query User{89F75094-2F40-4F49-BDB4-B7EB859AE5D0}C:\program files (x86)\metin2.ae\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2.ae\metin2client.bin | UDP Query User{8BDE4FDF-33FD-45AF-BACB-F1B2DFA3A948}C:\users\maciej\desktop\metin22\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin22\metin2client.bin | UDP Query User{8EECC8C0-501F-412E-AB71-082B649D9B06}C:\users\maciej\desktop\astral.exe -> profile=private | protocol=17 | dir=in | action=allow | name=astral.exe | app=c:\users\maciej\desktop\astral.exe | UDP Query User{8F1B6EDC-AAE9-4D0B-956B-9604A8AB0591}C:\program files (x86)\internet explorer\iexplore.exe -> profile=private | protocol=17 | dir=in | action=allow | name=internet explorer | app=c:\program files (x86)\internet explorer\iexplore.exe | UDP Query User{8F532C3F-CC9A-4A0D-B831-6A37A08200CA}C:\program files\metin 2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\program files\metin 2\metin2.bin | UDP Query User{8FE7ECA9-4F28-4FCA-A5FA-F13028759AE5}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{91292CED-CD8E-4E59-BA47-36428949FE7D}C:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hl.exe | UDP Query User{91A681EA-22BA-48CC-977C-67671B155D24}C:\users\maciej\desktop\counter-strikeeee - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee - kopia - kopia\hl.exe | UDP Query User{92F7B4CC-288E-4A3C-B7A5-3CC1DE10C3CC}C:\users\maciej\desktop\counter-strikes\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes\hl.exe | UDP Query User{9338ACF5-3047-43DD-8479-3EBAB4A262AB}C:\program files (x86)\flashget\flashget.exe -> profile=private | protocol=17 | dir=in | action=allow | name=flashget | app=c:\program files (x86)\flashget\flashget.exe | UDP Query User{9490049A-3D65-440D-8578-9A934FCA0E60}C:\program files (x86)\gadu-gadu\gg.exe -> profile=private | protocol=17 | dir=in | action=allow | name=gadu-gadu - program główny | app=c:\program files (x86)\gadu-gadu\gg.exe | UDP Query User{96342995-576E-4CDA-A373-FFD5B68E120D}C:\users\maciej\desktop\assassins.creed.2.pl-crack\offlineserver-v0.32\server.exe -> profile=private | protocol=17 | dir=in | action=allow | name=server.exe | app=c:\users\maciej\desktop\assassins.creed.2.pl-crack\offlineserver-v0.32\server.exe | UDP Query User{963B8B8A-540F-4AB8-AB45-DB071138E8FF}C:\users\maciej\desktop\metin2 - kopia\metin2modpl.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2modpl.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2modpl.bin | UDP Query User{96DB07D4-E381-422E-B0EB-DBC0DDFBF1AC}C:\users\maciej\desktop\programy\metin2\metin.exe -> profile=private | protocol=17 | dir=in | action=allow | name=metin.exe | app=c:\users\maciej\desktop\programy\metin2\metin.exe | UDP Query User{96EB3DC9-50CD-48CE-8361-6CA936A8DAD9}C:\users\maciej\temp\teamviewer\version4\teamviewer.exe -> profile=private | protocol=17 | dir=in | action=block | name=teamviewer.exe | app=c:\users\maciej\temp\teamviewer\version4\teamviewer.exe | UDP Query User{9B3A243B-ECFE-467F-BAD4-9E17A2C552DC}C:\users\maciej\desktop\new metin2 client\client completo per cheatforge\mc.exe -> profile=private | protocol=17 | dir=in | action=block | name=mc.exe | app=c:\users\maciej\desktop\new metin2 client\client completo per cheatforge\mc.exe | UDP Query User{9B4C22CF-4725-4ED4-9604-D723F0E1FE73}C:\users\maciej\desktop\metin2 dmg + mh\metin2client2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client2.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client2.bin | UDP Query User{9FC992A5-051E-41C4-8B77-902B58BB06C9}C:\program files (x86)\counter-strike\hlds.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\counter-strike\hlds.exe | UDP Query User{A05ABF7A-A55B-432C-A473-2AA0DA56E842}C:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hlds launcher | app=c:\program files (x86)\steam\steamapps\50535820\dedicated server\hlds.exe | UDP Query User{A190DF0E-5AFE-4562-AC4B-AA03ED2A4B0B}C:\users\maciej\desktop\metin2 dmg + mh\metin2client3.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client3.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client3.bin | UDP Query User{A2150302-C2F9-4774-A165-1A5C856EE546}C:\program files (x86)\valve\hltv.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hltv launcher | app=c:\program files (x86)\valve\hltv.exe | UDP Query User{A59ABF39-0208-4580-9ACB-701B66D8C300}C:\program files (x86)\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=half-life launcher | app=c:\program files (x86)\counter-strike\hl.exe | UDP Query User{A5C16128-CD0C-40D8-B252-50C11579360B}C:\users\maciej\desktop\programy\metin2\metin2bot.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2bot.bin | app=c:\users\maciej\desktop\programy\metin2\metin2bot.bin | UDP Query User{A604CCB2-5B49-4693-A295-5AE5ED7EFCC7}C:\users\maciej\desktop\counter-strike 1.6\counter-strike 1.6\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike 1.6\counter-strike 1.6\hl.exe | UDP Query User{A70CE45E-FF2F-4F80-99FE-B57EE4945D71}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{A769055E-EE53-4BF4-9BC6-B298C814069A}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{A9B64C42-AE62-42F6-A86C-5CFB523E7516}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{AB4BD34A-7A86-45D6-9213-FDCED414C1AC}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia\hl.exe | UDP Query User{ABB8A3E9-75AC-4B55-A8E9-B940C9C582FE}C:\users\maciej\desktop\metin2 dmg + mh\metin2client4.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client4.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client4.bin | UDP Query User{ACF8D0FB-045A-4FC6-A087-C4D187BBC66E}C:\program files (x86)\astral\launcher.exe -> profile=private | protocol=17 | dir=in | action=allow | name=launcher | app=c:\program files (x86)\astral\launcher.exe | UDP Query User{AD0BEEE3-B85D-4101-B6DD-2C9FFFBBA6A8}C:\users\maciej\desktop\metin2 thenextland\tnlmt2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=tnlmt2.bin | app=c:\users\maciej\desktop\metin2 thenextland\tnlmt2.bin | UDP Query User{ADBF1D77-0075-4508-A98C-BB4B40F7F7D1}C:\users\maciej\desktop\ahrimania - kopia\ahrimania\ahrimania.exe -> profile=private | protocol=17 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania - kopia\ahrimania\ahrimania.exe | UDP Query User{AEA9D75C-CE14-495C-B129-4D3FE552EDC0}C:\users\maciej\desktop\cs\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\cs\hl.exe | UDP Query User{B1193FAA-4F7E-49AB-A144-DC6062A9B2E6}C:\users\maciej\desktop\444\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\444\metin2client.bin | UDP Query User{B1CE17E1-7669-4056-B438-BE7A71EED41B}C:\users\maciej\desktop\444 - kopia\metin2mod.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2mod.bin | app=c:\users\maciej\desktop\444 - kopia\metin2mod.bin | UDP Query User{B26DF2D3-78B4-4E4E-8C5B-F9882800A2D9}D:\program files (x86)\cheat engine\cheat engine server.exe -> profile=private | protocol=17 | dir=in | action=allow | name=cheat engine server | app=d:\program files (x86)\cheat engine\cheat engine server.exe | UDP Query User{B3AD9F02-4111-48B8-A804-48253F92EA3E}C:\users\maciej\desktop\counter-strike\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\counter-strike\hl.exe | UDP Query User{B45F5105-C291-4AB4-A36A-26EE8B310A88}C:\users\maciej\desktop\ahrimania killer\ahrimania\metin2mod.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2mod.bin | app=c:\users\maciej\desktop\ahrimania killer\ahrimania\metin2mod.bin | UDP Query User{B63A3B90-D0DF-4665-BE90-10DEFE43BC4A}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{B7ED2883-8AA6-4CBE-A32B-E6AFBA8667A5}C:\program files (x86)\nowe gadu-gadu\gg.exe -> profile=public | protocol=17 | dir=in | action=allow | name=nowe gadu-gadu | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | UDP Query User{B8F94410-B22D-47CC-AF06-D3EE6C018B0D}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{B9CC10B4-030E-4E8C-B3C3-225B1BE6B906}C:\users\maciej\desktop\counter-strike\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike\hl.exe | UDP Query User{B9F36B22-A26E-4A40-A4AB-456952E97719}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{BA5B5A90-B8BD-4D1D-82A9-C59C84D571A2}D:\metin2\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=d:\metin2\metin2client.bin | UDP Query User{BC53E681-7A8D-4A84-B8DC-9CB8DEC556A3}C:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hlds.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hlds.exe | app=c:\users\maciej\desktop\counter-strike 1.6 - kopia - kopia\counter-strike 1.6\hlds.exe | UDP Query User{BD592158-7482-4956-BB39-A70960D210DE}C:\users\maciej\desktop\metin2 dmg + mh\metin2client1.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client1.bin | app=c:\users\maciej\desktop\metin2 dmg + mh\metin2client1.bin | UDP Query User{BE37D421-4FBF-4860-BF49-FE25193EF3B8}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{C0BA3A8B-4C76-4C00-BE7D-8AB36DAAE6A8}C:\users\maciej\desktop\nowy folder\diwang2 by tetleyu.exe -> profile=private | protocol=17 | dir=in | action=block | name=diwang2 by tetleyu.exe | app=c:\users\maciej\desktop\nowy folder\diwang2 by tetleyu.exe | UDP Query User{C10FD0C5-F39F-4972-9FB3-C68257ED12C3}C:\users\maciej\program files (x86)\dna\btdna.exe -> profile=public | protocol=17 | dir=in | action=block | name=btdna.exe | app=c:\users\maciej\program files (x86)\dna\btdna.exe | UDP Query User{C24131C1-9DFC-421D-B201-E90293AD4742}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{C2B9AED4-76B2-49FA-9A0D-08DD667AF75E}C:\wapster\aqq\aqq.exe -> profile=public | protocol=17 | dir=in | action=block | name=aqq | app=c:\wapster\aqq\aqq.exe | UDP Query User{C2FF6171-79C6-4990-8DD9-8A79483E05A5}C:\users\maciej\desktop\cs2d_0103\counterstrike2d.exe -> profile=private | protocol=17 | dir=in | action=block | name=counterstrike2d.exe | app=c:\users\maciej\desktop\cs2d_0103\counterstrike2d.exe | UDP Query User{C3511A34-12FF-487A-91EB-2F731FD9EF1D}C:\users\maciej\desktop\333\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\333\metin2client.bin | UDP Query User{C4813459-A588-484D-AC58-2F23EF38F513}C:\program files (x86)\nowe gadu-gadu\gg.exe -> profile=private | protocol=17 | dir=in | action=allow | name=nowe gadu-gadu | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | UDP Query User{C7114573-6273-4357-83EC-84DFA3D65F64}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{C86D6B1D-BA4B-4F9E-9C4D-1D50DF218C84}C:\users\maciej\desktop\nowy folder\mcmetinpro.exe -> profile=private | protocol=17 | dir=in | action=block | name=mcmetinpro.exe | app=c:\users\maciej\desktop\nowy folder\mcmetinpro.exe | UDP Query User{CA5265CE-2D3B-4FBB-96EA-C52DB45F36FB}C:\users\maciej\desktop\metin 2 - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin 2 - kopia\metin2.bin | UDP Query User{CB561D45-0F3F-4EF6-A675-A531DD253A62}C:\users\maciej\desktop\metin2 - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\metin2 - kopia\metin2.bin | UDP Query User{D10BBF71-E8B4-4C22-9484-31E8C0DA8B43}C:\program files (x86)\metin2_pl\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2_pl\metin2.bin | UDP Query User{D1473955-A88C-4740-9DBE-F99B26D17B17}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{D50F15B7-2938-403F-9E07-273136605781}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia\hl.exe | UDP Query User{D51B67BA-9A26-4467-9A76-11A3C66EB44E}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{D52F871B-6AE1-4915-B354-98DEB8E0CE0E}C:\program files (x86)\empire earth ii\ee2.exe -> profile=public | protocol=17 | dir=in | action=block | name=empire earth ii | app=c:\program files (x86)\empire earth ii\ee2.exe | UDP Query User{D5D685B9-E895-4B67-BD88-A7857EFB0216}C:\users\maciej\desktop\ahrimania\ahrimania\ahrimania.exe -> profile=private | protocol=17 | dir=in | action=allow | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania\ahrimania\ahrimania.exe | UDP Query User{D769E59C-89A7-4648-A48F-933C19345155}C:\users\maciej\appdata\local\temp\pyl4c0e.tmp\pyrun.exe -> profile=public | protocol=17 | dir=in | action=allow | name=pyrun.exe | app=c:\users\maciej\appdata\local\temp\pyl4c0e.tmp\pyrun.exe | UDP Query User{D79BC95E-2988-4EB5-AE13-0F0A226AC8A6}C:\program files (x86)\empire earth ii\ee2.exe -> profile=private | protocol=17 | dir=in | action=allow | name=empire earth ii | app=c:\program files (x86)\empire earth ii\ee2.exe | UDP Query User{D9F4FFF6-524B-47BE-9EB6-05012D1F2C72}C:\users\maciej\desktop\222\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\222\metin2client.bin | UDP Query User{DB17F06A-2AA2-454A-8B51-52F4B3E724AD}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{DC5C16C1-EDED-4008-8C5E-C101B319C5C5}C:\users\maciej\desktop\counter-strikeeee - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikeeee - kopia\hl.exe | UDP Query User{DE8418E1-8568-4938-86D9-32B79BB11400}C:\users\maciej\desktop\metin2 - kopia - kopia\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\users\maciej\desktop\metin2 - kopia - kopia\metin2client.bin | UDP Query User{DEC12C6B-2B3C-4D94-94D1-4D2D388FB0C0}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia\hl.exe | UDP Query User{E0B2A291-7CE0-43CB-BC25-9B4CD1AAC332}C:\users\maciej\desktop\counter-strikes - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia\hl.exe | UDP Query User{E0E15C1D-E110-4F34-8814-AA2F03BA16F2}C:\users\maciej\desktop\metin2 thenextland\thenextland.exe -> profile=private | protocol=17 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\metin2 thenextland\thenextland.exe | UDP Query User{E25C0CF2-9E55-4996-936D-006AB45DD135}C:\program files (x86)\metin2_pl\metin2.bin -> profile=public | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\program files (x86)\metin2_pl\metin2.bin | UDP Query User{E27ED9E9-C734-420E-B51F-B339C1A32399}C:\users\maciej\desktop\444\metin2client1.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client1.bin | app=c:\users\maciej\desktop\444\metin2client1.bin | UDP Query User{E40A3244-2D69-4AF0-A499-B9FD5A9F7CB2}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia (2)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia (2)\hl.exe | UDP Query User{E40DAA52-24C6-4CFF-8771-E5454D1E7CBE}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{E5CFDA02-D310-4623-BE56-B190423E28FE}C:\users\maciej\desktop\programy\counter-strike\hl.exe -> profile=public | protocol=17 | dir=in | action=block | name=hl.exe | app=c:\users\maciej\desktop\programy\counter-strike\hl.exe | UDP Query User{E5F22CD0-1E62-4093-B915-77F9DB48AB35}C:\users\maciej\desktop\cs\hl.exe -> profile=public | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\cs\hl.exe | UDP Query User{E6B8F10F-65A7-465D-8E8F-A5A881FE096C}C:\program files (x86)\metin2\metin2client.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2client.bin | app=c:\program files (x86)\metin2\metin2client.bin | UDP Query User{E7D5B368-3CD5-4E85-94AC-CDF02B586194}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{E84B1B1F-7ADA-4D78-BC1A-8DA012FF20E2}C:\program files (x86)\spellforce\spellforce.exe -> profile=public | protocol=17 | dir=in | action=allow | name=spellforce | app=c:\program files (x86)\spellforce\spellforce.exe | UDP Query User{E9441063-6580-4CF5-A34A-DE9CA505DA0E}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{E982BA5A-9AB3-4652-ACE9-CAE0CB0B266D}C:\users\maciej\desktop\444\metin2client3.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client3.bin | app=c:\users\maciej\desktop\444\metin2client3.bin | UDP Query User{EA909D8D-264E-48EC-924E-223A36D979C5}C:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (3)\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia (3)\hl.exe | UDP Query User{EACA39CB-1E28-426E-BDC2-F527022A394B}C:\users\maciej\desktop\ahrimania killer\ahrimania\ahrimania.exe -> profile=private | protocol=17 | dir=in | action=block | name=ahrimania.exe | app=c:\users\maciej\desktop\ahrimania killer\ahrimania\ahrimania.exe | UDP Query User{EEE041D1-D2F3-4D3C-813C-76BC82D2A480}C:\program files (x86)\ares\ares.exe -> profile=private | protocol=17 | dir=in | action=allow | name=ares p2p for windows | app=c:\program files (x86)\ares\ares.exe | UDP Query User{F2A27896-6ABF-475D-B95F-9FDDF5C2E6CB}C:\users\maciej\desktop\counter-strikes\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes\hl.exe | UDP Query User{F3649B39-6749-4C81-837B-58FA4F242882}C:\users\maciej\appdata\local\temp\usmt\migwiz.exe -> profile=public | protocol=17 | dir=in | action=allow | name=migwiz.exe | app=c:\users\maciej\appdata\local\temp\usmt\migwiz.exe | UDP Query User{F40BE898-251C-42A6-8428-6D741DD744A7}C:\users\maciej\desktop\444\thenextland.exe -> profile=private | protocol=17 | dir=in | action=allow | name=thenextland.exe | app=c:\users\maciej\desktop\444\thenextland.exe | UDP Query User{F40F8CB7-720C-4668-9AF5-666CB2D1EE24}C:\users\maciej\desktop\tnl_www.przeklej.pl\tnl\tnlmt2.bin -> profile=private | protocol=17 | dir=in | action=block | name=tnlmt2.bin | app=c:\users\maciej\desktop\tnl_www.przeklej.pl\tnl\tnlmt2.bin | UDP Query User{F4B3BB50-8425-4E22-9AF7-D7C8F32344CD}C:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (3) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{F4D1E0B2-0D29-4C58-98E5-31A7375ED748}C:\program files (x86)\rise of nations - rise of legends\legends.exe -> profile=private | protocol=17 | dir=in | action=allow | name=rise of legends | app=c:\program files (x86)\rise of nations - rise of legends\legends.exe | UDP Query User{F61C321C-BE76-4804-AE4C-760C88101052}C:\users\maciej\appdata\local\virtualstore\program files\metin 2 - kopia\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\appdata\local\virtualstore\program files\metin 2 - kopia\metin2.bin | UDP Query User{F735E236-D276-4DF6-89CD-6343139EBCEA}C:\program files (x86)\astral\astral.exe -> profile=private | protocol=17 | dir=in | action=allow | name=astral | app=c:\program files (x86)\astral\astral.exe | UDP Query User{F861CE7E-3DAB-4AAE-A436-B3D45898C8C8}C:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strikes - kopia - kopia (2) - kopia - kopia\hl.exe | UDP Query User{FB5B8DFA-2534-4E9A-985A-9D9E8E5C90B7}C:\users\maciej\desktop\programy\metin2\metin2.bin -> profile=private | protocol=17 | dir=in | action=allow | name=metin2.bin | app=c:\users\maciej\desktop\programy\metin2\metin2.bin | UDP Query User{FBC03CE2-8804-496B-86B0-DF301B048F48}C:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\counter-strike - kopia - kopia (2) - kopia - kopia - kopia - kopia - kopia - kopia - kopia - kopia\hl.exe | UDP Query User{FC245A68-31FB-484B-AB30-C3C0BAEC8D8A}C:\users\maciej\desktop\nowy folder\tnlmt2.bin -> profile=private | protocol=17 | dir=in | action=block | name=tnlmt2.bin | app=c:\users\maciej\desktop\nowy folder\tnlmt2.bin | UDP Query User{FEBDCFDC-C219-450A-8825-56077024E6FF}C:\users\maciej\desktop\nowy folder - kopia (2)\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\nowy folder - kopia (2)\metin2client.bin | UDP Query User{FF1E5DFB-A9D6-40A4-8841-9B9C63496B08}C:\users\maciej\desktop\nowy folder\counter-strike\hl.exe -> profile=private | protocol=17 | dir=in | action=allow | name=hl.exe | app=c:\users\maciej\desktop\nowy folder\counter-strike\hl.exe | UDP Query User{FF3FD36B-8781-4F6C-B2A4-7EE3CB724289}C:\users\maciej\desktop\metin2bot\metin2client.bin -> profile=private | protocol=17 | dir=in | action=block | name=metin2client.bin | app=c:\users\maciej\desktop\metin2bot\metin2client.bin | < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 0 -> "DisplayName" -> Sterownik stacji dysków CD-ROM -> "ImagePath" -> C:\Windows\SysNative\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008-01-19 08:29:04 | 000,079,872 | ---- | M] () < Drives with AutoRun files > -> -> D:\Auto Clicker Typer [] -> D:\Auto Clicker Typer [ NTFS ] -> [2010-05-20 17:39:06 | 000,000,000 | ---D | M] < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{28f9592d-c0ac-11de-91bb-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{28f9592d-c0ac-11de-91bb-000fea624528}\shell\AutoRun\command \{28f9592d-c0ac-11de-91bb-000fea624528}\shell\AutoRun\command\\"" -> G:\Menu.exe [G:\Menu.exe] -> File not found \{8bd776fc-1876-11dd-978c-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8bd776fc-1876-11dd-978c-000fea624528}\shell \{8bd776fc-1876-11dd-978c-000fea624528}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8bd776fc-1876-11dd-978c-000fea624528}\shell\AutoRun\command \{8bd776fc-1876-11dd-978c-000fea624528}\shell\AutoRun\command\\"" -> J:\AutoRun.exe [J:\AutoRun.exe] -> File not found \{9d30ceae-32ec-11dd-ac51-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d30ceae-32ec-11dd-ac51-000fea624528}\shell \{9d30ceae-32ec-11dd-ac51-000fea624528}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d30ceae-32ec-11dd-ac51-000fea624528}\shell\AutoRun\command \{9d30ceae-32ec-11dd-ac51-000fea624528}\shell\AutoRun\command\\"" -> L:\setup_homm5.exe [L:\setup_homm5.exe] -> File not found \{a9654381-0b4a-11df-bc7c-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a9654381-0b4a-11df-bc7c-000fea624528}\shell \{a9654381-0b4a-11df-bc7c-000fea624528}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a9654381-0b4a-11df-bc7c-000fea624528}\shell\AutoRun\command \{a9654381-0b4a-11df-bc7c-000fea624528}\shell\AutoRun\command\\"" -> M:\LaunchU3.exe [M:\LaunchU3.exe -a] -> File not found \{e21921ed-19db-11dd-b94d-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e21921ed-19db-11dd-b94d-000fea624528}\shell \{e21921ed-19db-11dd-b94d-000fea624528}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e21921ed-19db-11dd-b94d-000fea624528}\shell\AutoRun\command \{e21921ed-19db-11dd-b94d-000fea624528}\shell\AutoRun\command\\"" -> K:\silent.exe [K:\silent.exe] -> File not found \{e2938b6b-2bf2-11de-88cb-000fea624528} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e2938b6b-2bf2-11de-88cb-000fea624528}\shell \{e2938b6b-2bf2-11de-88cb-000fea624528}\shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e2938b6b-2bf2-11de-88cb-000fea624528}\shell\AutoRun\command \{e2938b6b-2bf2-11de-88cb-000fea624528}\shell\AutoRun\command\\"" -> F:\autorun1.exe [F:\autorun1.exe] -> File not found < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> 64bit-comfile [open] -> "%1" %* -> File not found 64bit-exefile [open] -> "%1" %* -> File not found comfile [open] -> "%1" %* -> exefile [open] -> "%1" %* -> < 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .com [@ = comfile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .com [@ = comfile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> [Registry - Additional Scans - Safe List] < 64bit-ActiveX StubPath [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {22d6f312-b0f6-11d0-94ab-0080c74c7e95} [HKLM] -> C:\Windows\SysNative\wmpdxm.dll [(default): Microsoft Windows Media Player 11.0; IsInstalled: 1] -> [2009-07-14 15:21:42 | 000,368,128 | ---- | M] () {2C7339CF-2B09-4501-B3F3-F3508C9228ED} [StubPath] -> %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [(default): Themes Setup; IsInstalled: 1] -> {3af36230-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Offline Browsing Pack; IsInstalled: 1] -> File not found {44BBA840-CC51-11CF-AAFA-00AA00B6015C} [StubPath] -> "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [(default): Microsoft Windows Mail 7; IsInstalled: 1] -> {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA855-CC51-11CF-AAFA-00AA00B6015F} [HKLM] -> Reg Error: Key error. [(default): DirectDrawEx; IsInstalled: 1] -> File not found {45ea75a0-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Help; IsInstalled: 1] -> File not found {4f645220-306d-11d2-995d-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Microsoft Windows Script 5.6; IsInstalled: 1] -> File not found {5fd399c0-a70a-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Setup Tools; IsInstalled: 1] -> File not found {630b1da0-b465-11d1-9948-00c04f98bbc9} [KeyFileName] -> Reg Error: Value error. [(default): Browsing Enhancements; IsInstalled: 1] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [StubPath] -> %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI [(default): Microsoft Windows Media Player; IsInstalled: 1] -> {6fab99d0-bab8-11d1-994a-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): MSN Site Access; IsInstalled: 1] -> File not found {7790769C-0471-11d2-AF11-00C04FA35D02} [HKLM] -> Reg Error: Key error. [(default): Address Book 7; IsInstalled: 1] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4340} [StubPath] -> regsvr32.exe /s /n /i:U shell32.dll [(default): Windows Desktop Update; IsInstalled: 1] -> {89820200-ECBD-11cf-8B85-00AA005B4383} [StubPath] -> C:\Windows\system32\ie4uinit.exe -BaseSettings [(default): Internet Explorer; IsInstalled: 1] -> {9381D8F2-0288-11D0-9501-00AA00B911A5} [HKLM] -> Reg Error: Key error. [(default): Dynamic HTML Data Binding; IsInstalled: 1] -> File not found {C9E9A340-D1F1-11D0-821E-444553540600} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Core Fonts; IsInstalled: 1] -> File not found {CDD7975E-60F8-41d5-8149-19E51D6F71D0} [HKLM] -> Reg Error: Key error. [ComponentID: Windows Movie Maker v2.1; IsInstalled: 1] -> File not found {de5aed00-a4bf-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): HTML Help; IsInstalled: 1] -> File not found {E92B03AB-B707-11d2-9CBD-0000F87A369E} [HKLM] -> Reg Error: Key error. [(default): Active Directory Service Interface; IsInstalled: 1] -> File not found {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {FEBEF00C-046D-438D-8A88-BF94A6C9E703} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} [StubPath] -> C:\Windows\system32\unregmp2.exe /ShowWMP [(default): Microsoft Windows Media Player; IsInstalled: 0] -> >{26923b43-4d38-484f-9b9e-de460746276c} [StubPath] -> C:\Windows\system32\ie4uinit.exe -UserIconConfig [(default): Internet Explorer; IsInstalled: 1] -> >{60B49E34-C7CC-11D0-8953-00A0C90347FF} [StubPath] -> "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [(default): Browser Customizations; IsInstalled: 1] -> < ActiveX StubPath [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608500} [KeyFileName] -> C:\Program Files (x86)\Java\jre6\bin\regutils.dll [(default): Java (Sun); IsInstalled: 1] -> [2010-06-22 05:57:02 | 000,278,528 | ---- | M] (Oracle) {22d6f312-b0f6-11d0-94ab-0080c74c7e95} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [(default): Microsoft Windows Media Player; IsInstalled: 1] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {233C1507-6A77-46A4-9443-F871F945D258} [HKLM] -> C:\Windows\SysWOW64\Adobe\Director\SwDir.dll [(default): Adobe Shockwave Director 11.0; IsInstalled: 01 00 00 00 [binary data]] -> [2010-08-18 08:22:14 | 000,213,272 | ---- | M] (Adobe Systems, Inc.) {2A202491-F00D-11cf-87CC-0020AFEECF20} [HKLM] -> Reg Error: Key error. [(default): Adobe Shockwave Director 11.0; IsInstalled: 01 00 00 00 [binary data]] -> File not found {2C7339CF-2B09-4501-B3F3-F3508C9228ED} [StubPath] -> %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [(default): Themes Setup; IsInstalled: 1] -> {3af36230-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Offline Browsing Pack; IsInstalled: 1] -> File not found {44BBA840-CC51-11CF-AAFA-00AA00B6015C} [StubPath] -> "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [(default): Microsoft Windows Mail 7; IsInstalled: 1] -> {44BBA855-CC51-11CF-AAFA-00AA00B6015F} [HKLM] -> Reg Error: Key error. [(default): DirectDrawEx; IsInstalled: 1] -> File not found {45ea75a0-a269-11d1-b5bf-0000f8051515} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Help; IsInstalled: 1] -> File not found {4f645220-306d-11d2-995d-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Microsoft Windows Script 5.8; IsInstalled: 1] -> File not found {5fd399c0-a70a-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Setup Tools; IsInstalled: 1] -> File not found {630b1da0-b465-11d1-9948-00c04f98bbc9} [KeyFileName] -> C:\Windows\SysWOW64\msieftp.dll [(default): Browsing Enhancements; IsInstalled: 1] -> [2008-01-19 09:35:10 | 000,296,960 | ---- | M] (Microsoft Corporation) {6BF52A52-394A-11d3-B153-00C04F79FAA6} [StubPath] -> %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI [(default): Microsoft Windows Media Player; IsInstalled: 1] -> {6fab99d0-bab8-11d1-994a-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): MSN Site Access; IsInstalled: 1] -> File not found {743F1D23-A520-44EE-BEF5-6D7474AF898E} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {7790769C-0471-11d2-AF11-00C04FA35D02} [HKLM] -> Reg Error: Key error. [(default): Address Book 7; IsInstalled: 1] -> File not found {7C028AF8-F614-47B3-82DA-BA94E41B1089} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4340} [StubPath] -> regsvr32.exe /s /n /i:U shell32.dll [(default): Windows Desktop Update; IsInstalled: 1] -> {89820200-ECBD-11cf-8B85-00AA005B4383} [StubPath] -> C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings [(default): Internet Explorer; IsInstalled: 1] -> {89B4C1CD-B018-4511-B0A1-5476DBF70820} [StubPath] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install [ComponentID: DOTNETFRAMEWORKS; IsInstalled: 1] -> {9381D8F2-0288-11D0-9501-00AA00B911A5} [HKLM] -> Reg Error: Key error. [(default): Dynamic HTML Data Binding; IsInstalled: 1] -> File not found {C9E9A340-D1F1-11D0-821E-444553540600} [HKLM] -> Reg Error: Key error. [(default): Internet Explorer Core Fonts; IsInstalled: 1] -> File not found {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> C:\Windows\SysWOW64\Macromed\Flash\Flash10h.ocx [(default): Adobe Flash Player; IsInstalled: 01 00 00 00 [binary data]] -> [2010-07-27 07:38:16 | 005,712,336 | R--- | M] (Adobe Systems, Inc.) {de5aed00-a4bf-11d1-9948-00c04f98bbc9} [HKLM] -> Reg Error: Key error. [(default): HTML Help; IsInstalled: 1] -> File not found {E92B03AB-B707-11d2-9CBD-0000F87A369E} [HKLM] -> Reg Error: Key error. [(default): Active Directory Service Interface; IsInstalled: 1] -> File not found {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} [HKLM] -> Reg Error: Key error. [(default): .NET Framework] -> File not found >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} [StubPath] -> %SystemRoot%\system32\unregmp2.exe /ShowWMP [(default): Microsoft Windows Media Player; IsInstalled: 0] -> >{26923b43-4d38-484f-9b9e-de460746276c} [StubPath] -> C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig [(default): Internet Explorer; IsInstalled: 1] -> >{60B49E34-C7CC-11D0-8953-00A0C90347FF} [StubPath] -> "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP [(default): Browser Customizations; IsInstalled: 1] -> < ActiveX StubPath [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Microsoft NetShow Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {22d6f312-b0f6-11d0-94ab-0080c74c7e95} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [HKLM] -> C:\Windows\SysWOW64\wmp.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:16 | 010,624,000 | ---- | M] (Microsoft Corporation) < ActiveX StubPath [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Microsoft NetShow Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {22d6f312-b0f6-11d0-94ab-0080c74c7e95} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [HKLM] -> C:\Windows\SysWOW64\wmp.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:16 | 010,624,000 | ---- | M] (Microsoft Corporation) < ActiveX StubPath [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Active Setup\Installed Components\ -> {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Microsoft NetShow Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {22d6f312-b0f6-11d0-94ab-0080c74c7e95} [HKLM] -> C:\Windows\SysWOW64\wmpdxm.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:17 | 000,313,344 | ---- | M] (Microsoft Corporation) {2C7339CF-2B09-4501-B3F3-F3508C9228ED} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA840-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {44BBA848-CC51-11CF-AAFA-00AA00B6015C} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [HKLM] -> C:\Windows\SysWOW64\wmp.dll [HKLM: Windows Media Player] -> [2009-07-14 15:00:16 | 010,624,000 | ---- | M] (Microsoft Corporation) {89820200-ECBD-11cf-8B85-00AA005B4340} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found {89820200-ECBD-11cf-8B85-00AA005B4383} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found >{26923b43-4d38-484f-9b9e-de460746276c} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found >{60B49E34-C7CC-11D0-8953-00A0C90347FF} [HKLM] -> Reg Error: Key error. [(no name)] -> File not found < 64bit-App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ -> cmmgr32.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found defraggler.exe -> C:\Program Files\Defraggler\Defraggler64.exe [C:\Program Files\Defraggler\Defraggler64.exe] -> [2010-07-30 21:18:08 | 003,149,624 | ---- | M] (Piriform Ltd) dvdmaker.exe -> C:\Program Files\Movie Maker\DVDMaker.exe [%ProgramFiles%\Movie Maker\dvdmaker.exe] -> [2008-01-19 10:00:14 | 002,259,456 | ---- | M] (Microsoft Corporation) inkball.exe -> C:\Program Files\Microsoft Games\inkball\inkball.exe [%ProgramFiles%\Microsoft Games\inkball\inkball.exe] -> File not found install.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found Journal.exe -> C:\Program Files\Windows Journal\Journal.exe [%ProgramFiles%\Windows Journal\Journal.exe] -> [2008-01-19 10:00:19 | 002,295,296 | ---- | M] (Microsoft Corporation) migwiz.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found moviemk.exe -> C:\Program Files\Movie Maker\MOVIEMK.exe [%ProgramFiles%\Movie Maker\moviemk.exe] -> [2006-11-02 17:04:44 | 000,150,528 | ---- | M] (Microsoft Corporation) mplayer2.exe -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe [%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe] -> [2009-07-14 12:59:24 | 000,168,960 | ---- | M] (Microsoft Corporation) msimn.exe -> C:\Program Files\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-19 10:00:45 | 000,400,896 | ---- | M] (Microsoft Corporation) pbrush.exe -> C:\Windows\SysNative\mspaint.exe [%SystemRoot%\System32\mspaint.exe] -> [2008-01-19 10:00:24 | 000,593,408 | ---- | M] () setup.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found SnippingTool.exe -> C:\Windows\SysNative\SnippingTool.exe [C:\Windows\System32\SnippingTool.exe] -> [2008-01-19 10:00:39 | 000,310,272 | ---- | M] () stikynot.exe -> C:\Windows\SysNative\stikynot.exe [C:\Windows\System32\stikynot.exe] -> [2006-11-02 17:04:10 | 000,318,976 | ---- | M] () table30.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found TabTip.exe -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe [%CommonProgramFiles%\microsoft shared\ink\TabTip.exe] -> [2008-01-19 10:00:29 | 000,353,792 | ---- | M] (Microsoft Corporation) wab.exe -> C:\Program Files\Windows Mail\wab.exe [%ProgramFiles%\Windows Mail\wab.exe] -> [2006-11-02 13:16:17 | 000,516,096 | ---- | M] (Microsoft Corporation) wabmig.exe -> C:\Program Files\Windows Mail\wabmig.exe [%ProgramFiles%\Windows Mail\wabmig.exe] -> [2006-11-02 13:16:17 | 000,068,096 | ---- | M] (Microsoft Corporation) WinCal.exe -> C:\Program Files\Windows Calendar\wincal.exe ["%ProgramFiles%\Windows Calendar\wincal.exe"] -> [2008-01-19 10:00:45 | 001,264,128 | ---- | M] (Microsoft Corporation) WinMail.exe -> C:\Program Files\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-19 10:00:45 | 000,400,896 | ---- | M] (Microsoft Corporation) wmplayer.exe -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe [%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe] -> [2009-07-14 12:59:24 | 000,168,960 | ---- | M] (Microsoft Corporation) WORDPAD.EXE -> C:\Program Files\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008-01-19 10:00:47 | 000,404,992 | ---- | M] (Microsoft Corporation) WRITE.EXE -> C:\Program Files\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008-01-19 10:00:47 | 000,404,992 | ---- | M] (Microsoft Corporation) XPSViewer.exe -> C:\Windows\SysWOW64\XPSViewer\XPSViewer.exe ["C:\Windows\SysWOW64\XPSViewer\XPSViewer.exe"] -> [2008-11-26 01:25:01 | 000,299,336 | ---- | M] (Microsoft Corporation) < App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ -> AcroRd32.exe -> D:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe [D:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe] -> [2010-06-20 04:06:46 | 000,349,616 | ---- | M] (Adobe Systems Incorporated) Ahk2Exe.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found AU3_Spy.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found AutoHotkey.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found AutoScriptWriter.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found bridge.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found ccleaner.exe -> D:\Program Files (x86)\CCleaner\CCleaner.exe [D:\Program Files (x86)\CCleaner\ccleaner.exe] -> [2010-06-23 23:07:14 | 001,699,128 | ---- | M] (Piriform Ltd) CDGrab.exe -> C:\Program Files (x86)\dBpoweramp\CDGrab.exe [C:\Program Files (x86)\dBpoweramp\CDGrab.exe] -> [2010-08-24 17:34:15 | 002,240,512 | ---- | M] (Illustrate) cmmgr32.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found cnq.exe -> C:\Program Files (x86)\ASUS\Cool & Quiet\cnq.exe [C:\Program Files (x86)\ASUS\Cool & Quiet\cnq.exe] -> [2010-03-31 11:33:54 | 001,112,704 | ---- | M] (ASUSTeK Computer Inc.) CoreConverter.exe -> C:\Program Files (x86)\dBpoweramp\CoreConverter.exe [C:\Program Files (x86)\dBpoweramp\CoreConverter.exe] -> [2010-08-24 17:34:14 | 000,237,568 | ---- | M] (Illustrate) dBConfig.exe -> C:\Program Files (x86)\dBpoweramp\dBConfig.exe [C:\Program Files (x86)\dBpoweramp\dBConfig.exe] -> [2010-08-24 17:34:13 | 000,433,896 | ---- | M] (Illustrate) DMCFileSelector.exe -> C:\Program Files (x86)\dBpoweramp\DMCFileSelector.exe [C:\Program Files (x86)\dBpoweramp\DMCFileSelector.exe] -> [2010-08-24 17:34:16 | 000,495,616 | ---- | M] (Illustrate) firefox.exe -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe [C:\Program Files (x86)\Mozilla Firefox\firefox.exe] -> [2010-09-16 21:51:41 | 000,910,296 | ---- | M] (Mozilla Corporation) GetPopupInfo.exe -> C:\Program Files (x86)\dBpoweramp\GetPopupInfo.exe [C:\Program Files (x86)\dBpoweramp\GetPopupInfo.exe] -> [2010-08-24 17:34:14 | 000,159,744 | ---- | M] (Illustrate) hdcd.exe -> C:\Program Files (x86)\dBpoweramp\hdcd.exe [C:\Program Files (x86)\dBpoweramp\hdcd.exe] -> [2010-08-24 17:34:20 | 000,064,382 | ---- | M] () install.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found Installer.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found ipla.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found javaws.exe -> C:\Program Files (x86)\Java\jre6\bin\javaws.exe [C:\Program Files (x86)\Java\jre6\bin\javaws.exe] -> [2010-06-22 04:36:38 | 000,153,376 | ---- | M] (Oracle) lame.exe -> C:\Program Files (x86)\dBpoweramp\encoder\mp3 (Lame)\lame.exe [C:\Program Files (x86)\dBpoweramp\encoder\mp3 (Lame)\lame.exe] -> [2010-08-24 17:34:20 | 000,581,120 | ---- | M] () mplayer2.exe -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe [%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe] -> [2009-07-14 12:59:24 | 000,168,960 | ---- | M] (Microsoft Corporation) mplayerc.exe -> C:\Program Files (x86)\Real Alternative\Media Player Classic\mplayerc.exe ["C:\Program Files (x86)\Real Alternative\Media Player Classic\mplayerc.exe"] -> [2009-10-09 20:00:00 | 004,411,392 | ---- | M] (Gabest) msimn.exe -> C:\Program Files (x86)\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-19 09:33:37 | 000,397,312 | ---- | M] (Microsoft Corporation) MusicConverter.exe -> C:\Program Files (x86)\dBpoweramp\MusicConverter.exe [C:\Program Files (x86)\dBpoweramp\MusicConverter.exe] -> [2010-08-24 17:34:14 | 000,671,744 | ---- | M] (Illustrate) OUTLOOK.EXE -> Reg Error: Value error. [Reg Error: Value error.] -> File not found pbrush.exe -> C:\Windows\SysWOW64\mspaint.exe [%SystemRoot%\System32\mspaint.exe] -> [2008-01-19 09:33:17 | 000,485,376 | ---- | M] (Microsoft Corporation) Photoshop.exe -> C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\Photoshop.exe [C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\Photoshop.exe] -> [2008-10-24 21:56:55 | 044,814,336 | ---- | M] (Adobe Systems, Incorporated) RealConverter.exe -> c:\program files (x86)\real\realplayer\converter\RealConverter.exe [c:\program files (x86)\real\realplayer\converter\RealConverter.exe] -> [2010-08-28 02:28:49 | 000,378,376 | ---- | M] (RealNetworks, Inc.) RealPlay.exe -> C:\Program Files (x86)\Real\RealPlayer\realplay.exe [C:\Program Files (x86)\Real\RealPlayer\realplay.exe] -> [2010-08-28 02:28:22 | 000,488,968 | ---- | M] (RealNetworks, Inc.) RealUpgrade.exe -> C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] -> [2010-06-03 03:02:42 | 000,173,576 | ---- | M] (RealNetworks, Inc.) rnxproc.exe -> C:\Program Files (x86)\Common Files\Real\Update_OB\rnxproc.exe [C:\Program Files (x86)\Common Files\Real\Update_OB\rnxproc.exe] -> [2010-08-28 02:28:18 | 000,058,920 | ---- | M] (RealNetworks, Inc.) setup.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found sidebar.exe -> C:\Program Files (x86)\Windows Sidebar\sidebar.exe ["%ProgramFiles%\Windows Sidebar\sidebar.exe"] -> [2008-01-19 09:33:30 | 001,233,920 | ---- | M] (Microsoft Corporation) table30.exe -> Reg Error: Value error. [Reg Error: Value error.] -> File not found TabTip.exe -> C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip.exe [%CommonProgramFiles%\microsoft shared\ink\TabTip.exe] -> File not found VegasMovieStudioPE90.exe -> C:\Program Files (x86)\Sony\Vegas Movie Studio Platinum 9.0\VegasMovieStudioPE90.exe [C:\Program Files (x86)\Sony\Vegas Movie Studio Platinum 9.0\VegasMovieStudioPE90.exe] -> [2010-05-27 20:08:25 | 013,311,744 | ---- | M] (Sony Creative Software Inc.) wab.exe -> C:\Program Files (x86)\Windows Mail\wab.exe [%ProgramFiles(x86)%\Windows Mail\wab.exe] -> [2006-11-02 11:45:51 | 000,516,096 | ---- | M] (Microsoft Corporation) wabmig.exe -> C:\Program Files (x86)\Windows Mail\wabmig.exe [%ProgramFiles(x86)%\Windows Mail\wabmig.exe] -> [2006-11-02 11:45:51 | 000,066,048 | ---- | M] (Microsoft Corporation) winamp.exe -> C:\Program Files (x86)\Winamp\winamp.exe [C:\Program Files (x86)\Winamp\winamp.exe] -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) WinCal.exe -> C:\Program Files (x86)\Windows Calendar\wincal.exe ["%ProgramFiles%\Windows Calendar\wincal.exe"] -> [2008-01-19 09:33:37 | 000,967,680 | ---- | M] (Microsoft Corporation) WinMail.exe -> C:\Program Files (x86)\Windows Mail\WinMail.exe [%ProgramFiles%\Windows Mail\WinMail.exe] -> [2008-01-19 09:33:37 | 000,397,312 | ---- | M] (Microsoft Corporation) wmenc.exe -> C:\Program Files (x86)\Windows Media Components\Encoder\WMEnc.exe [C:\Program Files (x86)\Windows Media Components\Encoder\WMEnc.exe] -> [2001-05-09 17:04:52 | 000,364,544 | ---- | M] (Microsoft Corporation) wmplayer.exe -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe [%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe] -> [2009-07-14 12:59:24 | 000,168,960 | ---- | M] (Microsoft Corporation) WORDPAD.EXE -> C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008-01-19 09:33:40 | 000,337,408 | ---- | M] (Microsoft Corporation) WRITE.EXE -> C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008-01-19 09:33:40 | 000,337,408 | ---- | M] (Microsoft Corporation) XPSViewer.exe -> C:\Windows\SysWOW64\XPSViewer\XPSViewer.exe ["C:\Windows\SysWOW64\XPSViewer\XPSViewer.exe"] -> [2008-11-26 01:25:01 | 000,299,336 | ---- | M] (Microsoft Corporation) < 64bit-Approved Shell Extensions [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved -> "{00020d75-0000-0000-c000-000000000046}" [HKLM] -> Reg Error: Key error. [lnkfile] -> File not found "{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoAcq.dll [PhotoAcqDropTarget] -> [2008-01-19 10:03:35 | 001,208,320 | ---- | M] (Microsoft Corporation) "{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}" [HKLM] -> C:\Program Files\Windows Photo Gallery\ImagingDevices.exe [Microsoft.ScannersAndCameras] -> [2006-11-02 17:04:55 | 000,203,264 | ---- | M] (Microsoft Corporation) "{025A5937-A6BE-4686-A844-36FE4BEC8B6D}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Microsoft Power Options] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{031EE060-67BC-460d-8847-E4A7C5E45A27}" [HKLM] -> C:\Program Files\Windows Media Player\wmprph.exe [Windows Media Player Rich Preview Handler] -> [2008-01-19 10:00:47 | 000,070,656 | ---- | M] (Microsoft Corporation) "{03B6C51D-9552-4416-B111-45AE011448DC}" [HKLM] -> C:\Program Files (x86)\Panda Security\Panda Antivirus 2008\ShellTit64.dll [Panda Antivirus] -> File not found "{0a4286ea-e355-44fb-8086-af3df7645bd9}" [HKLM] -> C:\Program Files\Windows Media Player\wmpband.dll [Windows Media Player] -> [2008-01-19 10:04:43 | 000,273,408 | ---- | M] (Microsoft Corporation) "{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [New Shortcut Wizard Modal] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" [HKLM] -> C:\Windows\SysNative\cabview.dll [.CAB file viewer] -> [2008-01-19 10:00:59 | 000,102,912 | ---- | M] () "{0D45D530-764B-11d0-A1CA-00AA00C16E65}" [HKLM] -> C:\Windows\SysNative\dsuiext.dll [Directory Property UI] -> [2008-01-19 10:01:17 | 000,632,832 | ---- | M] () "{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}" [HKLM] -> Reg Error: Key error. [Contacts folder] -> File not found "{11dbb47c-a525-400b-9e80-a54615a090c0}" [HKLM] -> C:\Windows\SysNative\ExplorerFrame.dll [Execute Folder] -> [2008-01-19 10:01:34 | 000,039,936 | ---- | M] () "{13D3C4B8-B179-4ebb-BF62-F704173E7448}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [Windows Contact Preview Handler] -> [2008-01-19 10:04:25 | 000,893,952 | ---- | M] (Microsoft Corporation) "{143A62C8-C33B-11D1-84FE-00C04FA34A14}" [HKLM] -> C:\Windows\MSAgent64\AgentPsh.dll [Microsoft Agent Character Property Sheet Handler] -> [2006-11-02 13:16:28 | 000,031,232 | ---- | M] (Microsoft Corporation) "{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}" [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\ink\TipBand.dll [Tablet PC Input Panel] -> [2006-11-02 17:04:00 | 000,120,832 | ---- | M] (Microsoft Corporation) "{15eae92e-f17a-4431-9f28-805e482dafd4}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [Install New Programs] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" [HKLM] -> C:\Windows\SysNative\dsquery.dll [Directory Object Find] -> [2008-01-19 10:01:17 | 000,428,032 | ---- | M] () "{16C2C29D-0E5F-45f3-A445-03E03F587B7D}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [group_wab_auto_file] -> [2008-01-19 10:04:25 | 000,893,952 | ---- | M] (Microsoft Corporation) "{176d6597-26d3-11d1-b350-080036a75b03}" [HKLM] -> C:\Windows\SysNative\colorui.dll [ICM Scanner Management] -> [2008-01-19 10:01:07 | 000,701,952 | ---- | M] () "{17cd9488-1228-4b2f-88ce-4298e93e0966}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{1a184871-359e-4f67-aad9-5b9905d62232}" [HKLM] -> C:\Windows\SysNative\fontext.dll [Microsoft Windows Font File Context Menu Handler] -> [2008-01-19 10:01:35 | 000,163,328 | ---- | M] () "{1b24a030-9b20-49bc-97ac-1be4426f9e59}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{1CDB2949-8F65-4355-8456-263E7C208A5D}" [HKLM] -> C:\Program Files\NVIDIA Corporation\nView\nvShell.dll [Desktop Explorer] -> [2010-01-21 02:41:26 | 000,403,048 | ---- | M] () "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" [HKLM] -> C:\Program Files\NVIDIA Corporation\nView\nvShell.dll [Desktop Explorer Menu] -> [2010-01-21 02:41:26 | 000,403,048 | ---- | M] () "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" [HKLM] -> C:\Program Files\NVIDIA Corporation\nView\nvShell.dll [nView Desktop Context Menu] -> [2010-01-21 02:41:26 | 000,403,048 | ---- | M] () "{1F2E5C40-9550-11CE-99D2-00AA006E086C}" [HKLM] -> C:\Windows\SysNative\rshx32.dll [NTFS Security Page] -> [2008-01-19 10:03:54 | 000,053,760 | ---- | M] () "{1FA9085F-25A2-489B-85D4-86326EEDCD87}" [HKLM] -> C:\Windows\SysNative\wlanpref.dll [Manage Wireless Networks] -> [2008-01-19 10:04:36 | 001,792,512 | ---- | M] () "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" [HKLM] -> C:\Program Files\Common Files\System\Ole DB\oledb32.dll [Microsoft Data Link] -> [2008-01-19 10:03:26 | 000,790,528 | ---- | M] (Microsoft Corporation) "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Search] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Help and Support] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Help and Support] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Run...] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Internet] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [E-mail] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Start Menu OEM Command] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Set Program Access and Defaults] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{2781761E-28E0-4109-99FE-B9D127C57AFE}" [HKLM] -> C:\Program Files\Windows Defender\MpOAV.dll [Windows Defender IOfficeAntiVirus implementation] -> [2008-01-19 10:06:37 | 000,114,232 | ---- | M] (Microsoft Corporation) "{289978AC-A101-4341-A817-21EBA7FD046D}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Conflict Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}" [HKLM] -> C:\Windows\SysNative\fontext.dll [Microsoft Windows Font File Icon Handler] -> [2008-01-19 10:01:35 | 000,163,328 | ---- | M] () "{2C2577C2-63A7-40e3-9B7F-586602617ECB}" [HKLM] -> Reg Error: Key error. [Explorer Query Band] -> File not found "{2E9E59C0-B437-4981-A647-9C34B9B90891}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Setup Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{3080F90D-D7AD-11D9-BD98-0000947B0257}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Show Desktop] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{3080F90E-D7AD-11D9-BD98-0000947B0257}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Window Switcher] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{32714800-2E5F-11d0-8B85-00AA0044F941}" [HKLM] -> C:\Program Files\Windows Mail\wabfind.dll [For &People...] -> [2006-11-02 13:19:10 | 000,035,328 | ---- | M] (Microsoft Corporation) "{335a31dd-f04b-4d76-a925-d6b47cf360df}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{34449847-FD14-4fc8-A75A-7432F5181EFB}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{35786D3C-B075-49b9-88DD-029876E11C01}" [HKLM] -> C:\Windows\SysNative\wpdshext.dll [Portable Devices] -> [2008-01-19 10:04:48 | 002,727,936 | ---- | M] () "{36eef7db-88ad-4e81-ad49-0e313f0c35f8}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Windows Update] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}" [HKLM] -> C:\Windows\SysNative\van.DLL [View Available Networks] -> [2008-01-19 10:04:23 | 000,303,616 | ---- | M] () "{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}" [HKLM] -> C:\Windows\SysNative\nvshext.dll [NVIDIA Play On My TV Context Menu Extension] -> [2009-07-14 14:08:54 | 000,238,080 | ---- | M] () "{3e7efb4c-faf1-453d-89eb-56026875ef90}" [HKLM] -> [Get Programs Online] -> File not found "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" [HKLM] -> C:\Windows\SysNative\docprop.dll [OLE Docfile Property Page] -> [2006-11-02 13:16:57 | 000,043,008 | ---- | M] () "{3F30C968-480A-4C6C-862D-EFC0897BB84B}" [HKLM] -> C:\Windows\SysNative\PhotoMetadataHandler.dll [Photo Thumbnail Extractor] -> [2008-08-28 06:02:28 | 000,470,016 | ---- | M] () "{4026492f-2f69-46b8-b9bf-5654fc07e423}" [HKLM] -> C:\Windows\SysNative\FirewallControlPanel.exe [Windows Firewall] -> [2008-01-19 10:00:16 | 002,626,048 | ---- | M] () "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}" [HKLM] -> C:\Windows\SysNative\mediametadatahandler.dll [Video Media Properties Handler] -> [2008-01-19 10:02:05 | 000,403,456 | ---- | M] () "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" [HKLM] -> C:\Windows\SysNative\ntshrui.dll [Shell extensions for sharing] -> [2008-01-19 10:03:24 | 000,355,328 | ---- | M] () "{41E300E0-78B6-11ce-849B-444553540000}" [HKLM] -> C:\Windows\SysNative\themeui.dll [PlusPack CPL Extension] -> [2008-01-19 10:04:16 | 000,688,128 | ---- | M] () "{42071712-76d4-11d1-8b24-00a0c9068ff3}" [HKLM] -> C:\Windows\SysNative\deskadp.dll [Display Adapter CPL Extension] -> [2006-11-02 13:16:55 | 000,049,664 | ---- | M] () "{42071713-76d4-11d1-8b24-00a0c9068ff3}" [HKLM] -> C:\Windows\SysNative\deskmon.dll [Display Monitor CPL Extension] -> [2006-11-02 13:16:55 | 000,046,592 | ---- | M] () "{4336a54d-038b-4685-ab02-99bb52d3fb8b}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Public Folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{44121072-A222-48f2-A58A-6D9AD51EBBE9}" [HKLM] -> C:\Windows\SysNative\XPSSHHDR.DLL [Microsoft XPS Thumbnail] -> [2008-01-19 10:04:52 | 000,942,592 | ---- | M] () "{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}" [HKLM] -> C:\Windows\SysNative\mydocs.dll [MyDocuments menu and properties] -> [2008-01-19 10:02:59 | 000,143,360 | ---- | M] () "{45670FA8-ED97-4F44-BC93-305082590BFB}" [HKLM] -> C:\Windows\SysNative\XPSSHHDR.DLL [Microsoft XPS Properties] -> [2008-01-19 10:04:52 | 000,942,592 | ---- | M] () "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" [HKLM] -> Reg Error: Key error. [Shell Extension for Malware scanning] -> File not found "{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}" [HKLM] -> C:\Windows\SysNative\icsigd.dll [IGD Property Sheet Handler] -> [2006-11-02 13:17:34 | 000,197,632 | ---- | M] () "{4a7ded0a-ad25-11d0-98a8-0800361b1103}" [HKLM] -> C:\Windows\SysNative\mydocs.dll [MyFolder Properties] -> [2008-01-19 10:02:59 | 000,143,360 | ---- | M] () "{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Event Properties Extension] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{4E40F770-369C-11d0-8922-00A024AB2DBB}" [HKLM] -> C:\Windows\SysNative\dssec.dll [DS Security Page] -> [2008-01-19 10:01:17 | 000,055,296 | ---- | M] () "{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}" [HKLM] -> C:\Windows\SysNative\gameux.dll [GameUX.RichGameMediaThumbnail] -> [2008-03-08 06:42:22 | 001,926,656 | ---- | M] () "{4F58F63F-244B-4c07-B29F-210BE59BE9B4}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [.group shell extension handler] -> [2008-01-19 10:04:25 | 000,893,952 | ---- | M] (Microsoft Corporation) "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" [HKLM] -> C:\Windows\SysNative\acppage.dll [Compatibility Property Page] -> [2006-11-02 13:16:25 | 000,046,080 | ---- | M] () "{53BEDF0B-4E5B-4183-8DC9-B844344FA104}" [HKLM] -> C:\Windows\SysNative\mssvp.dll [Microsoft Windows MAPI Preview Handler] -> [2008-05-27 07:21:25 | 000,796,672 | ---- | M] () "{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Handler Properties Extension] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{58E3C745-D971-4081-9034-86E34B30836A}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{59099400-57FF-11CE-BD94-0020AF85B590}" [HKLM] -> C:\Windows\SysNative\diskcopy.dll [Disk Copy Extension] -> [2006-11-02 13:16:56 | 001,502,208 | ---- | M] () "{59be4990-f85c-11ce-aff7-00aa003ca9f6}" [HKLM] -> C:\Windows\SysNative\ntlanui2.dll [Shell extensions for Microsoft Windows Network objects] -> [2006-11-02 13:19:07 | 000,017,920 | ---- | M] () "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" [HKLM] -> C:\Windows\SysNative\colorui.dll [ICM Monitor Management] -> [2008-01-19 10:01:07 | 000,701,952 | ---- | M] () "{5ea4f148-308c-46d7-98a9-49041b1dd468}" [HKLM] -> C:\Windows\SysNative\mblctr.exe [Mobility Center Control Panel] -> [2008-01-19 10:00:28 | 000,958,464 | ---- | M] () "{60254CA5-953B-11CF-8C96-00AA00B8708C}" [HKLM] -> C:\Windows\SysNative\wshext.dll [Shell extensions for Windows Script Host] -> [2008-05-08 08:06:54 | 000,101,888 | ---- | M] () "{60632754-c523-4b62-b45c-4172da012619}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{60fd46de-f830-4894-a628-6fa81bc0190d}" [HKLM] -> C:\Windows\SysNative\photowiz.dll [DropTarget Object for Photo Printing Wizard] -> [2008-01-19 10:03:38 | 000,399,872 | ---- | M] () "{62AE1F9A-126A-11D0-A14B-0800361B1103}" [HKLM] -> C:\Windows\SysNative\dsuiext.dll [Directory Context Menu Verbs] -> [2008-01-19 10:01:17 | 000,632,832 | ---- | M] () "{63da6ec0-2e98-11cf-8d82-444553540000}" [HKLM] -> C:\Windows\SysNative\msieftp.dll [FTP Folders Webview] -> [2008-01-19 10:02:34 | 000,330,240 | ---- | M] () "{675F097E-4C4D-11D0-B6C1-0800091AA605}" [HKLM] -> C:\Windows\SysNative\colorui.dll [ICM Printer Management] -> [2008-01-19 10:01:07 | 000,701,952 | ---- | M] () "{67718415-c450-4f3c-bf8a-b487642dc39b}" [HKLM] -> C:\Windows\SysNative\optionalfeatures.exe [Windows Features] -> [2008-01-19 10:00:25 | 000,097,792 | ---- | M] () "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" [HKLM] -> C:\Windows\SysNative\shwebsvc.dll [Shell Publishing Wizard Object] -> [2008-01-19 10:04:05 | 000,447,488 | ---- | M] () "{6b9228da-9c15-419e-856c-19e768a13bdc}" [HKLM] -> C:\Program Files\Windows Sidebar\sbdrop.dll [Windows gadget DropTarget] -> [2006-11-02 17:03:14 | 000,067,584 | ---- | M] (Microsoft Corporation) "{7007ACC7-3202-11D1-AAD2-00805FC1270E}" [HKLM] -> C:\Windows\SysNative\netshell.dll [Network Connections] -> [2008-01-19 10:03:03 | 003,341,312 | ---- | M] () "{71D99464-3B6B-475C-B241-E15883207529}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Results Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{74246bfc-4c96-11d0-abef-0020af6b0b7a}" [HKLM] -> C:\Windows\SysNative\devmgr.dll [Device Manager] -> [2008-01-19 10:01:14 | 000,496,128 | ---- | M] () "{7444C717-39BF-11D1-8CD9-00C04FC29D45}" [HKLM] -> C:\Windows\SysNative\cryptext.dll [Crypto PKO Extension] -> [2008-01-19 10:01:10 | 000,065,536 | ---- | M] () "{7444C719-39BF-11D1-8CD9-00C04FC29D45}" [HKLM] -> C:\Windows\SysNative\cryptext.dll [Crypto Sign Extension] -> [2008-01-19 10:01:10 | 000,065,536 | ---- | M] () "{77597368-7b15-11d0-a0c2-080036af3f03}" [HKLM] -> C:\Windows\SysNative\printui.dll [Web Printer Shell Extension] -> [2008-01-19 10:03:41 | 000,980,480 | ---- | M] () "{78F3955E-3B90-4184-BD14-5397C15F1EFC}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{7988B573-EC89-11cf-9C00-00AA00A14F56}" [HKLM] -> C:\Windows\SysNative\dskquoui.dll [Disk Quota UI] -> [2008-01-19 10:01:17 | 000,237,056 | ---- | M] () "{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Simple Conflict Presenter] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" [HKLM] -> C:\Windows\SysNative\mmcshext.dll [MMC Icon Handler] -> [2008-01-19 10:02:10 | 000,127,488 | ---- | M] () "{7A979262-40CE-46ff-AEEE-7884AC3B6136}" [HKLM] -> C:\Windows\SysNative\hdwwiz.exe [Add New Hardware] -> [2006-11-02 13:15:53 | 000,080,384 | ---- | M] () "{7A9D77BD-5403-11d2-8785-2E0420524153}" [HKLM] -> C:\Windows\SysNative\Netplwiz.exe [User Accounts] -> [2008-01-19 10:00:24 | 000,026,624 | ---- | M] () "{7b81be6a-ce2b-4676-a29e-eb907a5126c5}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [Programs and Features] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{7D4734E6-047E-41e2-AEAA-E763B4739DC4}" [HKLM] -> C:\Windows\SysNative\wmpshell.dll [Windows Media Player Play as Playlist Context Menu Handler] -> [2008-01-19 10:04:43 | 000,124,416 | ---- | M] () "{8082C5E6-4C27-48ec-A809-B8E1122E8F97}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [.contact shell extension handler] -> [2008-01-19 10:04:25 | 000,893,952 | ---- | M] (Microsoft Corporation) "{80AEF606-7FFA-4EF6-86C4-0B86FEF4E0CD}" [HKLM] -> C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNShell.DLL [SimpleShlExt extension] -> [2010-05-14 15:04:49 | 000,473,920 | ---- | M] (Panda Security, S.L.) "{85BBD920-42A0-1069-A2E4-08002B30309D}" [HKLM] -> C:\Windows\SysNative\syncui.dll [Briefcase] -> [2008-01-19 10:04:14 | 000,211,968 | ---- | M] () "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}" [HKLM] -> C:\Windows\SysNative\mediametadatahandler.dll [Audio Media Properties Handler] -> [2008-01-19 10:02:05 | 000,403,456 | ---- | M] () "{877ca5ac-cb41-4842-9c69-9136e42d47e2}" [HKLM] -> C:\Windows\SysNative\sdshext.dll [File Backup Index] -> [2008-01-19 10:03:56 | 000,120,320 | ---- | M] () "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}" [HKLM] -> C:\Windows\SysNative\zipfldr.dll [Compressed (zipped) Folder SendTo Target] -> [2008-01-19 10:04:55 | 000,386,560 | ---- | M] () "{88C6C381-2E85-11D0-94DE-444553540000}" [HKLM] -> C:\Windows\SysNative\occache.dll [ActiveX Cache Folder] -> [2009-07-22 00:09:54 | 000,243,712 | ---- | M] () "{89D83576-6BD1-4c86-9454-BEB04E94C819}" [HKLM] -> C:\Windows\SysNative\mssvp.dll [MAPI Search Namespace Extension] -> [2008-05-27 07:21:25 | 000,796,672 | ---- | M] () "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" [HKLM] -> C:\Windows\SysNative\dsquery.dll [Directory Query UI] -> [2008-01-19 10:01:17 | 000,428,032 | ---- | M] () "{8A734961-C4AA-4741-AC1E-791ACEBF5B39}" [HKLM] -> C:\Windows\SysNative\wmpshell.dll [Windows Media Player Shop Music Context Menu Handler] -> [2008-01-19 10:04:43 | 000,124,416 | ---- | M] () "{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}" [HKLM] -> C:\Windows\SysNative\fontext.dll [Microsoft Windows Font Previewer] -> [2008-01-19 10:01:35 | 000,163,328 | ---- | M] () "{8DD448E6-C188-4aed-AF92-44956194EB1F}" [HKLM] -> C:\Windows\SysNative\wmpshell.dll [Windows Media Player Burn Audio CD Context Menu Handler] -> [2008-01-19 10:04:43 | 000,124,416 | ---- | M] () "{8E25992B-373E-486E-80E5-BD23AE417E66}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Device Notification Sink] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{8E908FC9-BECC-40f6-915B-F4CA0E70D03D}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{90b9bce2-b6db-4fd3-8451-35917ea1081b}" [HKLM] -> C:\Windows\SysNative\ExplorerFrame.dll [Search Execute Command] -> [2008-01-19 10:01:34 | 000,039,936 | ---- | M] () "{90f8c90b-04e0-4e92-a186-e6e9c125d664}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Property Labels] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{911051fa-c21c-4246-b470-070cd8df6dc4}" [HKLM] -> Reg Error: Key error. [.cab or .zip files] -> File not found "{91ADC906-6722-4B05-A12B-471ADDCCE132}" [HKLM] -> C:\Windows\SysNative\TouchX.dll [Touch Band] -> [2008-01-19 10:04:18 | 002,084,352 | ---- | M] () "{92337A8C-E11D-11D0-BE48-00C04FC30DF6}" [HKLM] -> C:\Windows\SysNative\oleprn.dll [OlePrn.PrinterURL] -> [2008-01-19 10:03:26 | 000,115,712 | ---- | M] () "{96AE8D84-A250-4520-95A5-A47A7E3C548B}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{97e467b4-98c6-4f19-9588-161b7773d6f6}" [HKLM] -> C:\Windows\SysNative\propsys.dll [Office Document Property Handler] -> [2008-05-27 07:19:55 | 000,921,088 | ---- | M] () "{992CFFA0-F557-101A-88EC-00DD010CCC48}" [HKLM] -> C:\Windows\SysNative\netshell.dll [Network Connections] -> [2008-01-19 10:03:03 | 003,341,312 | ---- | M] () "{9C60DE1E-E5FC-40f4-A487-460851A8D915}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{9D687A4C-1404-41ef-A089-883B6FBECDE6}" [HKLM] -> [Windows Photo Gallery Viewer Autoplay Handler] -> File not found "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" [HKLM] -> C:\Windows\SysNative\dsquery.dll [Shell properties for a DS object] -> [2008-01-19 10:01:17 | 000,428,032 | ---- | M] () "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" [HKLM] -> C:\Windows\SysNative\sendmail.dll [Mail Service] -> [2008-01-19 10:03:58 | 000,076,288 | ---- | M] () "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" [HKLM] -> C:\Windows\SysNative\sendmail.dll [Desktop Shortcut] -> [2008-01-19 10:03:58 | 000,076,288 | ---- | M] () "{a304259d-52b8-4526-8b1a-a1d6cecc8243}" [HKLM] -> C:\Windows\SysNative\iscsicpl.exe [iSCSI Initiator] -> [2006-11-02 13:15:55 | 000,120,832 | ---- | M] () "{a38b883c-1682-497e-97b0-0a3a9e801682}" [HKLM] -> C:\Windows\SysNative\PhotoMetadataHandler.dll [IPropertyStore Handler for Images] -> [2008-08-28 06:02:28 | 000,470,016 | ---- | M] () "{A70C977A-BF00-412C-90B7-034C51DA2439}" [HKLM] -> C:\Program Files\NVIDIA Corporation\Display\nvui.dll [NvCpl DesktopContext Class] -> [2010-09-11 00:55:02 | 001,862,248 | ---- | M] (NVIDIA Corporation) "{add36aa8-751a-4579-a266-d66f5202ccbb}" [HKLM] -> C:\Windows\SysNative\shwebsvc.dll [Print Ordering via the Web] -> [2008-01-19 10:04:05 | 000,447,488 | ---- | M] () "{b155bdf8-02f0-451e-9a26-ae317cfd7779}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [nethood delegate folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{b2c761c6-29bc-4f19-9251-e6195265baf1}" [HKLM] -> C:\Windows\SysNative\colorcpl.exe [Color Control Panel Applet] -> [2006-11-02 13:15:47 | 000,085,504 | ---- | M] () "{B32D3949-ED98-4DBB-B347-17A144969BBA}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Item Properties Extension] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}" [HKLM] -> C:\Windows\SysNative\zipfldr.dll [Compressed (zipped) Folder Context Menu] -> [2008-01-19 10:04:55 | 000,386,560 | ---- | M] () "{BB06C0E4-D293-4f75-8A90-CB05B6477EEE}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{BC48B32F-5910-47F5-8570-5074A8A5636A}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Results Delegate Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{BC65FB43-1958-4349-971A-210290480130}" [HKLM] -> C:\Windows\SysNative\NcdProp.dll [Network Explorer Property Sheet Handler] -> [2006-11-02 13:18:45 | 000,024,064 | ---- | M] () "{BD472F60-27FA-11cf-B8B4-444553540000}" [HKLM] -> C:\Windows\SysNative\zipfldr.dll [Compressed (zipped) Folder Right Drag Handler] -> [2008-01-19 10:04:55 | 000,386,560 | ---- | M] () "{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}" [HKLM] -> C:\Windows\SysNative\mssvp.dll [Client Side Cache Namespace Extension] -> [2008-05-27 07:21:25 | 000,796,672 | ---- | M] () "{BD84B380-8CA2-1069-AB1D-08000948F534}" [HKLM] -> C:\Windows\SysNative\fontext.dll [Microsoft Windows Font Folder] -> [2008-01-19 10:01:35 | 000,163,328 | ---- | M] () "{BE122A0E-4503-11DA-8BDE-F66BAD1E3F3A}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{C080DC3F-9095-4E4B-95E6-D67D077130E8}" [HKLM] -> C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNShell.DLL [Nano icon extension] -> [2010-05-14 15:04:49 | 000,473,920 | ---- | M] (Panda Security, S.L.) "{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}" [HKLM] -> C:\Windows\SysNative\comdlg32.dll [File Save Dialog] -> [2008-01-19 10:01:07 | 000,549,376 | ---- | M] () "{c5a40261-cd64-4ccf-84cb-c394da41d590}" [HKLM] -> C:\Windows\SysNative\mediametadatahandler.dll [Video Thumbnail Extractor] -> [2008-01-19 10:02:05 | 000,403,456 | ---- | M] () "{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Search Folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{C7657C4A-9F68-40fa-A4DF-96BC08EB3551}" [HKLM] -> C:\Windows\SysNative\PhotoMetadataHandler.dll [Photo Thumbnail Provider] -> [2008-08-28 06:02:28 | 000,470,016 | ---- | M] () "{C8494E42-ACDD-4739-B0FB-217361E4894F}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}" [HKLM] -> C:\Windows\SysNative\oobefldr.dll [Welcome Center] -> [2008-01-19 10:03:33 | 002,438,656 | ---- | M] () "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" [HKLM] -> C:\Windows\SysNative\shwebsvc.dll [Web Publishing Wizard] -> [2008-01-19 10:04:05 | 000,447,488 | ---- | M] () "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}" [HKLM] -> C:\Windows\SysNative\wmpshell.dll [Windows Media Player Play as Playlist Context Menu Handler] -> [2008-01-19 10:04:43 | 000,124,416 | ---- | M] () "{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [New Shortcut Wizard] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{CF67796C-F57F-45F8-92FB-AD698826C602}" [HKLM] -> C:\Program Files\Common Files\System\wab32.dll [contact_wab_auto_file] -> [2008-01-19 10:04:25 | 000,893,952 | ---- | M] (Microsoft Corporation) "{CF74B903-3389-469c-B3B6-0204D204FCBD}" [HKLM] -> C:\SnagIt 9\DLLx64\SnagItShellExt64.dll [SnagIt Shell Extension] -> File not found "{CFCCC7A0-A282-11D1-9082-006008059382}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [Darwin App Publisher] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{D20EA4E1-3957-11d2-A40B-0C5020524152}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Fonts] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{D20EA4E1-3957-11d2-A40B-0C5020524153}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Administrative Tools] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [Common Places Folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{d3e34b21-9d75-101a-8c3d-00aa001a1652}" [HKLM] -> C:\Windows\SysNative\mspaint.exe [Bitmap Image] -> [2008-01-19 10:00:24 | 000,593,408 | ---- | M] () "{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}" [HKLM] -> C:\Windows\SysNative\appwiz.cpl [Installed Updates] -> [2008-01-19 09:59:48 | 001,321,472 | ---- | M] () "{D555645E-D4F8-4c29-A827-D93C859C4F2A}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}" [HKLM] -> C:\Windows\SysNative\wpdshext.dll [Portable Devices Menu] -> [2008-01-19 10:04:48 | 002,727,936 | ---- | M] () "{d8559eb9-20c0-410e-beda-7ed416aecc2a}" [HKLM] -> C:\Program Files\Windows Defender\MSASCui.exe [Windows Defender] -> [2008-01-19 10:07:02 | 001,584,184 | ---- | M] (Microsoft Corporation) "{da67b8ad-e81b-4c70-9b91b417b5e33527}" [HKLM] -> Reg Error: Key error. [Windows Search Shell Service] -> File not found "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" [HKLM] -> C:\Windows\SysNative\colorui.dll [ICC Profile] -> [2008-01-19 10:01:07 | 000,701,952 | ---- | M] () "{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}" [HKLM] -> C:\Windows\SysNative\comdlg32.dll [File Open Dialog] -> [2008-01-19 10:01:07 | 000,549,376 | ---- | M] () "{DFFACDC5-679F-4156-8947-C5C76BC0B67F}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [users files delegate folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{E29F9716-5C08-4FCD-955A-119FDB5A522D}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" [HKLM] -> C:\Windows\SysNative\dfshim.dll [Shell Icon Handler for Application References] -> [2008-07-27 20:01:52 | 000,112,120 | ---- | M] () "{E413D040-6788-4C22-957E-175D1C513A34}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Conflict Delegate Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{E598560B-28D5-46aa-A14A-8A3BEA34B576}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Video Verbs] -> [2008-01-19 10:03:37 | 002,908,160 | ---- | M] (Microsoft Corporation) "{E7DE9B1A-7533-4556-9484-B26FB486475E}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{e82a2d71-5b2f-43a0-97b8-81be15854de8}" [HKLM] -> C:\Windows\SysNative\dfshim.dll [ShellLink for Application References] -> [2008-07-27 20:01:52 | 000,112,120 | ---- | M] () "{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}" [HKLM] -> C:\Windows\SysNative\zipfldr.dll [Compressed (zipped) Folder] -> [2008-01-19 10:04:55 | 000,386,560 | ---- | M] () "{E95A4861-D57A-4be1-AD0F-35267E261739}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{eb124705-128b-40d4-8dd8-d93ed12589a4}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [WPL property store] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}" [HKLM] -> C:\Windows\SysNative\DfsShlEx.dll [DfsShell.DfsShell Property Sheet] -> [2008-01-19 10:01:14 | 000,067,584 | ---- | M] () "{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}" [HKLM] -> C:\Windows\SysNative\gameux.dll [RichGameMediaPropertyStore Class] -> [2008-03-08 06:42:22 | 001,926,656 | ---- | M] () "{ECF03A32-103D-11d2-854D-006008059367}" [HKLM] -> C:\Windows\SysNative\mydocs.dll [MyDocs Drop Target] -> [2008-01-19 10:02:59 | 000,143,360 | ---- | M] () "{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}" [HKLM] -> C:\Windows\SysNative\gameux.dll [Games Folder] -> [2008-03-08 06:42:22 | 001,926,656 | ---- | M] () "{ed50fc29-b964-48a9-afb3-15ebb9b97f36}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [printhood delegate folder] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}" [HKLM] -> C:\Windows\SysNative\shdocvw.dll [] -> [2008-01-19 10:04:03 | 001,195,008 | ---- | M] () "{ed9d80b9-d157-457b-9192-0e7280313bf0}" [HKLM] -> C:\Windows\SysNative\zipfldr.dll [Compressed (zipped) Folder Drop Handler] -> [2008-01-19 10:04:55 | 000,386,560 | ---- | M] () "{F0152790-D56E-4445-850E-4F3117DB740C}" [HKLM] -> C:\Windows\SysNative\remotepg.dll [Remote Sessions CPL Extension] -> [2008-01-19 10:03:53 | 000,065,024 | ---- | M] () "{F020E586-5264-11d1-A532-0000F8757D7E}" [HKLM] -> C:\Windows\SysNative\dsquery.dll [Directory Start/Search Find] -> [2008-01-19 10:01:17 | 000,428,032 | ---- | M] () "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}" [HKLM] -> C:\Windows\SysNative\NetworkExplorer.dll [Computers and Devices] -> [2008-01-19 10:03:03 | 002,247,168 | ---- | M] () "{F04CC277-03A2-4277-96A9-77967471BDFF}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Center Conflict Properties Extension] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}" [HKLM] -> C:\Windows\SysNative\SyncCenter.dll [Sync Setup Delegate Folder] -> [2008-01-19 10:04:14 | 002,575,360 | ---- | M] () "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}" [HKLM] -> C:\Windows\SysNative\wmpshell.dll [Windows Media Player Add to Playlist Context Menu Handler] -> [2008-01-19 10:04:43 | 000,124,416 | ---- | M] () "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" [HKLM] -> C:\Windows\SysNative\rshx32.dll [Printers Security Page] -> [2008-01-19 10:03:54 | 000,053,760 | ---- | M] () "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" [HKLM] -> C:\Windows\SysNative\ntshrui.dll [Shell extensions for sharing] -> [2008-01-19 10:03:24 | 000,355,328 | ---- | M] () "{f92e8c40-3d33-11d2-b1aa-080036a75b03}" [HKLM] -> C:\Windows\SysNative\deskperf.dll [Display TroubleShoot CPL Extension] -> [2006-11-02 13:16:55 | 000,040,960 | ---- | M] () "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" [HKLM] -> Reg Error: Key error. [IE User Assist] -> File not found "{fcfeecae-ee1b-4849-ae50-685dcf7717ec}" [HKLM] -> C:\Windows\SysNative\wercon.exe [Problem Reports and Solutions] -> [2008-01-19 10:00:44 | 001,394,176 | ---- | M] () "{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}" [HKLM] -> C:\Program Files\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Image Verbs] -> [2008-01-19 10:03:37 | 002,908,160 | ---- | M] (Microsoft Corporation) "SimpleShlExt extension" [HKLM] -> Reg Error: Key error. [{80AEF606-7FFA-4EF6-86C4-0B86FEF4E0CD}] -> File not found < Approved Shell Extensions [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved -> "{00020d75-0000-0000-c000-000000000046}" [HKLM] -> Reg Error: Key error. [lnkfile] -> File not found "{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}" [HKLM] -> C:\Program Files (x86)\Windows Photo Gallery\PhotoAcq.dll [PhotoAcqDropTarget] -> [2008-01-19 09:36:03 | 001,030,144 | ---- | M] (Microsoft Corporation) "{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}" [HKLM] -> C:\Program Files (x86)\Windows Photo Gallery\ImagingDevices.exe [Microsoft.ScannersAndCameras] -> [2006-11-02 17:04:58 | 000,202,752 | ---- | M] (Microsoft Corporation) "{031EE060-67BC-460d-8847-E4A7C5E45A27}" [HKLM] -> C:\Program Files (x86)\Windows Media Player\wmprph.exe [Windows Media Player Rich Preview Handler] -> [2008-01-19 09:33:40 | 000,059,392 | ---- | M] (Microsoft Corporation) "{0a4286ea-e355-44fb-8086-af3df7645bd9}" [HKLM] -> C:\Program Files (x86)\Windows Media Player\wmpband.dll [Windows Media Player] -> [2008-01-19 09:37:03 | 000,099,328 | ---- | M] (Microsoft Corporation) "{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [New Shortcut Wizard Modal] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" [HKLM] -> C:\Windows\SysWow64\cabview.dll [.CAB file viewer] -> [2008-01-19 09:33:49 | 000,097,280 | ---- | M] (Microsoft Corporation) "{0D45D530-764B-11d0-A1CA-00AA00C16E65}" [HKLM] -> C:\Windows\SysWOW64\dsuiext.dll [Directory Property UI] -> [2008-01-19 09:34:07 | 000,616,448 | ---- | M] (Microsoft Corporation) "{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}" [HKLM] -> Reg Error: Key error. [Contacts folder] -> File not found "{11dbb47c-a525-400b-9e80-a54615a090c0}" [HKLM] -> C:\Windows\SysWow64\ExplorerFrame.dll [Execute Folder] -> [2008-01-19 09:34:20 | 000,020,992 | ---- | M] (Microsoft Corporation) "{13D3C4B8-B179-4ebb-BF62-F704173E7448}" [HKLM] -> C:\Program Files (x86)\Common Files\System\wab32.dll [Windows Contact Preview Handler] -> [2008-01-19 09:36:48 | 000,707,584 | ---- | M] (Microsoft Corporation) "{143A62C8-C33B-11D1-84FE-00C04FA34A14}" [HKLM] -> C:\Windows\MSAgent\AgentPsh.dll [Microsoft Agent Character Property Sheet Handler] -> [2008-01-19 09:33:43 | 000,030,720 | ---- | M] (Microsoft Corporation) "{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}" [HKLM] -> C:\Program Files (x86)\Common Files\microsoft shared\ink\TipBand.dll [Tablet PC Input Panel] -> File not found "{15eae92e-f17a-4431-9f28-805e482dafd4}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [Install New Programs] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" [HKLM] -> C:\Windows\SysWOW64\dsquery.dll [Directory Object Find] -> [2008-01-19 09:34:07 | 000,394,240 | ---- | M] (Microsoft Corporation) "{16C2C29D-0E5F-45f3-A445-03E03F587B7D}" [HKLM] -> C:\Program Files (x86)\Common Files\System\wab32.dll [group_wab_auto_file] -> [2008-01-19 09:36:48 | 000,707,584 | ---- | M] (Microsoft Corporation) "{176d6597-26d3-11d1-b350-080036a75b03}" [HKLM] -> C:\Windows\SysWOW64\colorui.dll [ICM Scanner Management] -> [2008-01-19 09:33:58 | 000,686,592 | ---- | M] (Microsoft Corporation) "{1a184871-359e-4f67-aad9-5b9905d62232}" [HKLM] -> C:\Windows\SysWow64\fontext.dll [Microsoft Windows Font File Context Menu Handler] -> [2008-01-19 09:34:21 | 000,142,336 | ---- | M] (Microsoft Corporation) "{1b24a030-9b20-49bc-97ac-1be4426f9e59}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{1F2E5C40-9550-11CE-99D2-00AA006E086C}" [HKLM] -> C:\Windows\SysWow64\rshx32.dll [NTFS Security Page] -> [2008-01-19 09:36:17 | 000,043,520 | ---- | M] (Microsoft Corporation) "{1FA9085F-25A2-489B-85D4-86326EEDCD87}" [HKLM] -> C:\Windows\SysWOW64\wlanpref.dll [Manage Wireless Networks] -> [2008-01-19 09:36:57 | 001,671,680 | ---- | M] (Microsoft Corporation) "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" [HKLM] -> C:\Program Files (x86)\Common Files\System\Ole DB\oledb32.dll [Microsoft Data Link] -> [2008-01-19 09:36:01 | 000,688,128 | ---- | M] (Microsoft Corporation) "{2781761E-28E0-4109-99FE-B9D127C57AFE}" [HKLM] -> C:\Program Files (x86)\Windows Defender\MpOav.dll [Windows Defender IOfficeAntiVirus implementation] -> [2008-01-19 09:38:14 | 000,090,680 | ---- | M] (Microsoft Corporation) "{289978AC-A101-4341-A817-21EBA7FD046D}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Conflict Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}" [HKLM] -> C:\Windows\SysWow64\fontext.dll [Microsoft Windows Font File Icon Handler] -> [2008-01-19 09:34:21 | 000,142,336 | ---- | M] (Microsoft Corporation) "{2C2577C2-63A7-40e3-9B7F-586602617ECB}" [HKLM] -> Reg Error: Key error. [Explorer Query Band] -> File not found "{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}" [HKLM] -> Reg Error: Key error. [dBpoweramp Music Converter] -> File not found "{2E9E59C0-B437-4981-A647-9C34B9B90891}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Setup Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{32714800-2E5F-11d0-8B85-00AA0044F941}" [HKLM] -> C:\Program Files (x86)\Windows Mail\wabfind.dll [For &People...] -> [2006-11-02 11:46:13 | 000,033,280 | ---- | M] (Microsoft Corporation) "{34449847-FD14-4fc8-A75A-7432F5181EFB}" [HKLM] -> Reg Error: Key error. [ActiveDirectory Folder] -> File not found "{35786D3C-B075-49b9-88DD-029876E11C01}" [HKLM] -> C:\Windows\SysWOW64\wpdshext.dll [Portable Devices] -> [2008-01-19 09:37:09 | 002,537,472 | ---- | M] (Microsoft Corporation) "{37efd44d-ef8d-41b1-940d-96973a50e9e0}" [HKLM] -> C:\Program Files (x86)\Windows Sidebar\sidebar.exe [Windows Sidebar Properties] -> [2008-01-19 09:33:30 | 001,233,920 | ---- | M] (Microsoft Corporation) "{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}" [HKLM] -> C:\Windows\SysWow64\van.DLL [View Available Networks] -> [2008-01-19 09:36:47 | 000,257,024 | ---- | M] (Microsoft Corporation) "{3e7efb4c-faf1-453d-89eb-56026875ef90}" [HKLM] -> [Get Programs Online] -> File not found "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" [HKLM] -> C:\Windows\SysWow64\docprop.dll [OLE Docfile Property Page] -> [2006-11-02 11:46:04 | 000,036,864 | ---- | M] (Microsoft Corporation) "{3F30C968-480A-4C6C-862D-EFC0897BB84B}" [HKLM] -> C:\Windows\SysWOW64\PhotoMetadataHandler.dll [Photo Thumbnail Extractor] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{4026492f-2f69-46b8-b9bf-5654fc07e423}" [HKLM] -> C:\Windows\SysWOW64\FirewallControlPanel.exe [Windows Firewall] -> [2008-01-19 09:33:10 | 002,585,088 | ---- | M] (Microsoft Corporation) "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}" [HKLM] -> C:\Windows\SysWOW64\MediaMetadataHandler.dll [Video Media Properties Handler] -> [2008-01-19 09:34:44 | 000,356,864 | ---- | M] (Microsoft Corporation) "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" [HKLM] -> C:\Windows\SysWow64\ntshrui.dll [Shell extensions for sharing] -> [2008-01-19 09:35:59 | 000,296,960 | ---- | M] (Microsoft Corporation) "{41E300E0-78B6-11ce-849B-444553540000}" [HKLM] -> C:\Windows\SysWOW64\themeui.dll [PlusPack CPL Extension] -> [2008-01-19 09:36:40 | 000,615,424 | ---- | M] (Microsoft Corporation) "{42071712-76d4-11d1-8b24-00a0c9068ff3}" [HKLM] -> C:\Windows\SysWow64\deskadp.dll [Display Adapter CPL Extension] -> [2006-11-02 11:46:03 | 000,047,616 | ---- | M] (Microsoft Corporation) "{42071713-76d4-11d1-8b24-00a0c9068ff3}" [HKLM] -> C:\Windows\SysWow64\deskmon.dll [Display Monitor CPL Extension] -> [2006-11-02 11:46:03 | 000,044,544 | ---- | M] (Microsoft Corporation) "{44121072-A222-48f2-A58A-6D9AD51EBBE9}" [HKLM] -> C:\Windows\SysWOW64\XPSSHHDR.dll [Microsoft XPS Thumbnail] -> [2008-01-19 09:37:13 | 000,574,976 | ---- | M] (Microsoft Corporation) "{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}" [HKLM] -> C:\Windows\SysWOW64\mydocs.dll [MyDocuments menu and properties] -> [2008-01-19 09:35:34 | 000,135,680 | ---- | M] (Microsoft Corporation) "{45670FA8-ED97-4F44-BC93-305082590BFB}" [HKLM] -> C:\Windows\SysWOW64\XPSSHHDR.dll [Microsoft XPS Properties] -> [2008-01-19 09:37:13 | 000,574,976 | ---- | M] (Microsoft Corporation) "{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}" [HKLM] -> C:\Windows\SysWOW64\icsigd.dll [IGD Property Sheet Handler] -> [2006-11-02 11:46:05 | 000,195,584 | ---- | M] (Microsoft Corporation) "{4a7ded0a-ad25-11d0-98a8-0800361b1103}" [HKLM] -> C:\Windows\SysWOW64\mydocs.dll [MyFolder Properties] -> [2008-01-19 09:35:34 | 000,135,680 | ---- | M] (Microsoft Corporation) "{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Event Properties Extension] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{4E40F770-369C-11d0-8922-00A024AB2DBB}" [HKLM] -> C:\Windows\SysWow64\dssec.dll [DS Security Page] -> [2008-01-19 09:34:07 | 000,044,032 | ---- | M] (Microsoft Corporation) "{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}" [HKLM] -> C:\Windows\SysWOW64\gameux.dll [GameUX.RichGameMediaThumbnail] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{4F58F63F-244B-4c07-B29F-210BE59BE9B4}" [HKLM] -> C:\Program Files (x86)\Common Files\System\wab32.dll [.group shell extension handler] -> [2008-01-19 09:36:48 | 000,707,584 | ---- | M] (Microsoft Corporation) "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" [HKLM] -> C:\Windows\SysWOW64\acppage.dll [Compatibility Property Page] -> [2006-11-02 11:46:02 | 000,038,912 | ---- | M] (Microsoft Corporation) "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}" [HKLM] -> C:\Windows\SysWOW64\control.exe [Control Panel command object for Start menu] -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) "{53BEDF0B-4E5B-4183-8DC9-B844344FA104}" [HKLM] -> C:\Windows\SysWOW64\mssvp.dll [Microsoft Windows MAPI Preview Handler] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Handler Properties Extension] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{59099400-57FF-11CE-BD94-0020AF85B590}" [HKLM] -> C:\Windows\SysWow64\diskcopy.dll [Disk Copy Extension] -> [2006-11-02 11:46:03 | 001,502,720 | ---- | M] (Microsoft Corporation) "{59be4990-f85c-11ce-aff7-00aa003ca9f6}" [HKLM] -> C:\Windows\SysWow64\ntlanui2.dll [Shell extensions for Microsoft Windows Network objects] -> [2006-11-02 11:46:12 | 000,015,872 | ---- | M] (Microsoft Corporation) "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" [HKLM] -> C:\Windows\SysWOW64\colorui.dll [ICM Monitor Management] -> [2008-01-19 09:33:58 | 000,686,592 | ---- | M] (Microsoft Corporation) "{60254CA5-953B-11CF-8C96-00AA00B8708C}" [HKLM] -> C:\Windows\SysWOW64\wshext.dll [Shell extensions for Windows Script Host] -> [2008-05-08 23:59:35 | 000,090,112 | ---- | M] (Microsoft Corporation) "{60fd46de-f830-4894-a628-6fa81bc0190d}" [HKLM] -> C:\Windows\SysWOW64\photowiz.dll [DropTarget Object for Photo Printing Wizard] -> [2008-01-19 09:36:05 | 000,291,328 | ---- | M] (Microsoft Corporation) "{62AE1F9A-126A-11D0-A14B-0800361B1103}" [HKLM] -> C:\Windows\SysWOW64\dsuiext.dll [Directory Context Menu Verbs] -> [2008-01-19 09:34:07 | 000,616,448 | ---- | M] (Microsoft Corporation) "{63da6ec0-2e98-11cf-8d82-444553540000}" [HKLM] -> C:\Windows\SysWOW64\msieftp.dll [FTP Folders Webview] -> [2008-01-19 09:35:10 | 000,296,960 | ---- | M] (Microsoft Corporation) "{640167b4-59b0-47a6-b335-a6b3c0695aea}" [HKLM] -> C:\Windows\SysWOW64\audiodev.dll [Portable Media Devices] -> [2008-01-19 09:33:45 | 000,244,224 | ---- | M] (Microsoft Corporation) "{675F097E-4C4D-11D0-B6C1-0800091AA605}" [HKLM] -> C:\Windows\SysWOW64\colorui.dll [ICM Printer Management] -> [2008-01-19 09:33:58 | 000,686,592 | ---- | M] (Microsoft Corporation) "{67718415-c450-4f3c-bf8a-b487642dc39b}" [HKLM] -> C:\Windows\SysWOW64\OptionalFeatures.exe [Windows Features] -> [2008-01-19 09:33:19 | 000,097,280 | ---- | M] (Microsoft Corporation) "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" [HKLM] -> C:\Windows\SysWOW64\shwebsvc.dll [Shell Publishing Wizard Object] -> [2008-01-19 09:36:30 | 000,425,472 | ---- | M] (Microsoft Corporation) "{6b9228da-9c15-419e-856c-19e768a13bdc}" [HKLM] -> C:\Program Files (x86)\Windows Sidebar\sbdrop.dll [Windows gadget DropTarget] -> [2006-11-02 17:03:27 | 000,066,048 | ---- | M] (Microsoft Corporation) "{7007ACC7-3202-11D1-AAD2-00805FC1270E}" [HKLM] -> C:\Windows\SysWOW64\netshell.dll [Network Connections] -> [2008-01-19 09:35:37 | 003,173,376 | ---- | M] (Microsoft Corporation) "{71D99464-3B6B-475C-B241-E15883207529}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Results Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{74246bfc-4c96-11d0-abef-0020af6b0b7a}" [HKLM] -> C:\Windows\SysWOW64\devmgr.dll [Device Manager] -> [2008-01-19 09:34:03 | 000,377,344 | ---- | M] (Microsoft Corporation) "{7444C717-39BF-11D1-8CD9-00C04FC29D45}" [HKLM] -> C:\Windows\SysWOW64\cryptext.dll [Rozszerzenie Crypto PKO] -> [2006-11-02 11:46:03 | 000,054,784 | ---- | M] (Microsoft Corporation) "{7444C719-39BF-11D1-8CD9-00C04FC29D45}" [HKLM] -> C:\Windows\SysWOW64\cryptext.dll [Rozszerzenie Crypto Sign] -> [2006-11-02 11:46:03 | 000,054,784 | ---- | M] (Microsoft Corporation) "{77597368-7b15-11d0-a0c2-080036af3f03}" [HKLM] -> C:\Windows\SysWOW64\printui.dll [Web Printer Shell Extension] -> [2008-01-19 09:36:08 | 000,869,888 | ---- | M] (Microsoft Corporation) "{7988B573-EC89-11cf-9C00-00AA00A14F56}" [HKLM] -> C:\Windows\SysWow64\dskquoui.dll [Disk Quota UI] -> [2008-01-19 09:34:07 | 000,190,976 | ---- | M] (Microsoft Corporation) "{79BC0345-1015-11D2-A299-006008312725}" [HKLM] -> Reg Error: Key error. [blue.shell] -> File not found "{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Simple Conflict Presenter] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" [HKLM] -> C:\Windows\SysWOW64\mmcshext.dll [MMC Icon Handler] -> [2008-01-19 09:34:49 | 000,127,488 | ---- | M] (Microsoft Corporation) "{7A979262-40CE-46ff-AEEE-7884AC3B6136}" [HKLM] -> C:\Windows\SysWOW64\hdwwiz.exe [Add New Hardware] -> [2006-11-02 11:45:12 | 000,080,384 | ---- | M] (Microsoft Corporation) "{7A9D77BD-5403-11d2-8785-2E0420524153}" [HKLM] -> C:\Windows\SysWow64\Netplwiz.exe [User Accounts] -> [2008-01-19 09:33:18 | 000,025,600 | ---- | M] (Microsoft Corporation) "{7b81be6a-ce2b-4676-a29e-eb907a5126c5}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [Programs and Features] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{7D4734E6-047E-41e2-AEAA-E763B4739DC4}" [HKLM] -> C:\Windows\SysWOW64\wmpshell.dll [Windows Media Player Play as Playlist Context Menu Handler] -> [2008-01-19 09:37:05 | 000,101,376 | ---- | M] (Microsoft Corporation) "{8082C5E6-4C27-48ec-A809-B8E1122E8F97}" [HKLM] -> C:\Program Files (x86)\Common Files\System\wab32.dll [.contact shell extension handler] -> [2008-01-19 09:36:48 | 000,707,584 | ---- | M] (Microsoft Corporation) "{85BBD920-42A0-1069-A2E4-08002B30309D}" [HKLM] -> C:\Windows\SysWow64\syncui.dll [Briefcase] -> [2008-01-19 09:36:38 | 000,175,616 | ---- | M] (Microsoft Corporation) "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}" [HKLM] -> C:\Windows\SysWOW64\MediaMetadataHandler.dll [Audio Media Properties Handler] -> [2008-01-19 09:34:44 | 000,356,864 | ---- | M] (Microsoft Corporation) "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}" [HKLM] -> C:\Windows\SysWOW64\zipfldr.dll [Compressed (zipped) Folder SendTo Target] -> [2008-01-19 09:37:13 | 000,342,016 | ---- | M] (Microsoft Corporation) "{88C6C381-2E85-11D0-94DE-444553540000}" [HKLM] -> C:\Windows\SysWOW64\occache.dll [ActiveX Cache Folder] -> [2009-07-21 23:50:46 | 000,206,848 | ---- | M] (Microsoft Corporation) "{8903F6C9-25E3-40AC-A98F-E6D35CD0469C}" [HKLM] -> Reg Error: Value error. [PSPad] -> File not found "{89D83576-6BD1-4c86-9454-BEB04E94C819}" [HKLM] -> C:\Windows\SysWOW64\mssvp.dll [MAPI Search Namespace Extension] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" [HKLM] -> C:\Windows\SysWOW64\dsquery.dll [Directory Query UI] -> [2008-01-19 09:34:07 | 000,394,240 | ---- | M] (Microsoft Corporation) "{8A734961-C4AA-4741-AC1E-791ACEBF5B39}" [HKLM] -> C:\Windows\SysWOW64\wmpshell.dll [Windows Media Player Shop Music Context Menu Handler] -> [2008-01-19 09:37:05 | 000,101,376 | ---- | M] (Microsoft Corporation) "{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}" [HKLM] -> C:\Windows\SysWow64\fontext.dll [Microsoft Windows Font Previewer] -> [2008-01-19 09:34:21 | 000,142,336 | ---- | M] (Microsoft Corporation) "{8DD448E6-C188-4aed-AF92-44956194EB1F}" [HKLM] -> C:\Windows\SysWOW64\wmpshell.dll [Windows Media Player Burn Audio CD Context Menu Handler] -> [2008-01-19 09:37:05 | 000,101,376 | ---- | M] (Microsoft Corporation) "{8E25992B-373E-486E-80E5-BD23AE417E66}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Device Notification Sink] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{90b9bce2-b6db-4fd3-8451-35917ea1081b}" [HKLM] -> C:\Windows\SysWow64\ExplorerFrame.dll [Search Execute Command] -> [2008-01-19 09:34:20 | 000,020,992 | ---- | M] (Microsoft Corporation) "{911051fa-c21c-4246-b470-070cd8df6dc4}" [HKLM] -> Reg Error: Key error. [.cab or .zip files] -> File not found "{92337A8C-E11D-11D0-BE48-00C04FC30DF6}" [HKLM] -> C:\Windows\SysWOW64\oleprn.dll [OlePrn.PrinterURL] -> [2008-01-19 09:36:01 | 000,096,768 | ---- | M] (Microsoft Corporation) "{992CFFA0-F557-101A-88EC-00DD010CCC48}" [HKLM] -> C:\Windows\SysWOW64\netshell.dll [Network Connections] -> [2008-01-19 09:35:37 | 003,173,376 | ---- | M] (Microsoft Corporation) "{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{9D687A4C-1404-41ef-A089-883B6FBECDE6}" [HKLM] -> [Windows Photo Gallery Viewer Autoplay Handler] -> File not found "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" [HKLM] -> C:\Windows\SysWOW64\dsquery.dll [Shell properties for a DS object] -> [2008-01-19 09:34:07 | 000,394,240 | ---- | M] (Microsoft Corporation) "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" [HKLM] -> C:\Windows\SysWOW64\sendmail.dll [Mail Service] -> [2008-01-19 09:36:21 | 000,069,632 | ---- | M] (Microsoft Corporation) "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" [HKLM] -> C:\Windows\SysWOW64\sendmail.dll [Desktop Shortcut] -> [2008-01-19 09:36:21 | 000,069,632 | ---- | M] (Microsoft Corporation) "{a304259d-52b8-4526-8b1a-a1d6cecc8243}" [HKLM] -> C:\Windows\SysWOW64\iscsicpl.exe [iSCSI Initiator] -> [2006-11-02 11:45:17 | 000,120,320 | ---- | M] (Microsoft Corporation) "{a38b883c-1682-497e-97b0-0a3a9e801682}" [HKLM] -> C:\Windows\SysWOW64\PhotoMetadataHandler.dll [IPropertyStore Handler for Images] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{add36aa8-751a-4579-a266-d66f5202ccbb}" [HKLM] -> C:\Windows\SysWOW64\shwebsvc.dll [Print Ordering via the Web] -> [2008-01-19 09:36:30 | 000,425,472 | ---- | M] (Microsoft Corporation) "{b2c761c6-29bc-4f19-9251-e6195265baf1}" [HKLM] -> C:\Windows\SysWOW64\colorcpl.exe [Color Control Panel Applet] -> [2006-11-02 11:44:59 | 000,084,992 | ---- | M] (Microsoft Corporation) "{B32D3949-ED98-4DBB-B347-17A144969BBA}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Item Properties Extension] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}" [HKLM] -> C:\Windows\SysWOW64\zipfldr.dll [Compressed (zipped) Folder Context Menu] -> [2008-01-19 09:37:13 | 000,342,016 | ---- | M] (Microsoft Corporation) "{BC48B32F-5910-47F5-8570-5074A8A5636A}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Results Delegate Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{BC65FB43-1958-4349-971A-210290480130}" [HKLM] -> C:\Windows\SysWOW64\NcdProp.dll [Network Explorer Property Sheet Handler] -> [2008-01-19 09:35:35 | 000,019,968 | ---- | M] (Microsoft Corporation) "{BD472F60-27FA-11cf-B8B4-444553540000}" [HKLM] -> C:\Windows\SysWOW64\zipfldr.dll [Compressed (zipped) Folder Right Drag Handler] -> [2008-01-19 09:37:13 | 000,342,016 | ---- | M] (Microsoft Corporation) "{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}" [HKLM] -> C:\Windows\SysWOW64\mssvp.dll [Client Side Cache Namespace Extension] -> [2008-05-27 07:18:56 | 000,670,208 | ---- | M] (Microsoft Corporation) "{BD84B380-8CA2-1069-AB1D-08000948F534}" [HKLM] -> C:\Windows\SysWOW64\fontext.dll [Microsoft Windows Font Folder] -> [2008-01-19 09:34:21 | 000,142,336 | ---- | M] (Microsoft Corporation) "{BD88A479-9623-4897-8546-BC62B9628F44}" [HKLM] -> Reg Error: Key error. [SPTHandler] -> File not found "{c5a40261-cd64-4ccf-84cb-c394da41d590}" [HKLM] -> C:\Windows\SysWOW64\MediaMetadataHandler.dll [Video Thumbnail Extractor] -> [2008-01-19 09:34:44 | 000,356,864 | ---- | M] (Microsoft Corporation) "{C7657C4A-9F68-40fa-A4DF-96BC08EB3551}" [HKLM] -> C:\Windows\SysWOW64\PhotoMetadataHandler.dll [Photo Thumbnail Provider] -> [2008-08-28 05:40:09 | 000,425,472 | ---- | M] (Microsoft Corporation) "{C8494E42-ACDD-4739-B0FB-217361E4894F}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}" [HKLM] -> C:\Windows\SysWow64\oobefldr.dll [Welcome Center] -> [2008-01-19 09:36:02 | 002,153,472 | ---- | M] (Microsoft Corporation) "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" [HKLM] -> C:\Windows\SysWOW64\shwebsvc.dll [Web Publishing Wizard] -> [2008-01-19 09:36:30 | 000,425,472 | ---- | M] (Microsoft Corporation) "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}" [HKLM] -> C:\Windows\SysWOW64\wmpshell.dll [Windows Media Player Play as Playlist Context Menu Handler] -> [2008-01-19 09:37:05 | 000,101,376 | ---- | M] (Microsoft Corporation) "{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [New Shortcut Wizard] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{CF67796C-F57F-45F8-92FB-AD698826C602}" [HKLM] -> C:\Program Files (x86)\Common Files\System\wab32.dll [contact_wab_auto_file] -> [2008-01-19 09:36:48 | 000,707,584 | ---- | M] (Microsoft Corporation) "{CFCCC7A0-A282-11D1-9082-006008059382}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [Darwin App Publisher] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{d3e34b21-9d75-101a-8c3d-00aa001a1652}" [HKLM] -> C:\Windows\SysWOW64\mspaint.exe [Bitmap Image] -> [2008-01-19 09:33:17 | 000,485,376 | ---- | M] (Microsoft Corporation) "{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}" [HKLM] -> C:\Windows\SysWOW64\appwiz.cpl [Installed Updates] -> [2008-01-19 09:32:56 | 001,122,304 | ---- | M] (Microsoft Corporation) "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}" [HKLM] -> C:\Windows\SysWOW64\wpdshext.dll [Portable Devices Menu] -> [2008-01-19 09:37:09 | 002,537,472 | ---- | M] (Microsoft Corporation) "{d8559eb9-20c0-410e-beda-7ed416aecc2a}" [HKLM] -> Reg Error: Key error. [Windows Defender] -> File not found "{da67b8ad-e81b-4c70-9b91b417b5e33527}" [HKLM] -> Reg Error: Key error. [Windows Search Shell Service] -> File not found "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" [HKLM] -> C:\Windows\SysWOW64\colorui.dll [ICC Profile] -> [2008-01-19 09:33:58 | 000,686,592 | ---- | M] (Microsoft Corporation) "{E29F9716-5C08-4FCD-955A-119FDB5A522D}" [HKLM] -> Reg Error: Key error. [Sam Account Folder] -> File not found "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" [HKLM] -> C:\Windows\SysWOW64\dfshim.dll [Shell Icon Handler for Application References] -> [2008-07-27 20:03:16 | 000,096,760 | ---- | M] (Microsoft Corporation) "{E413D040-6788-4C22-957E-175D1C513A34}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Conflict Delegate Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{E44E5D18-0652-4508-A4E2-8A090067BCB0}" [HKLM] -> C:\Windows\SysWow64\control.exe [Default Programs command object for Start menu] -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) "{E598560B-28D5-46aa-A14A-8A3BEA34B576}" [HKLM] -> C:\Program Files (x86)\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Video Verbs] -> [2008-01-19 09:36:04 | 002,314,240 | ---- | M] (Microsoft Corporation) "{e82a2d71-5b2f-43a0-97b8-81be15854de8}" [HKLM] -> C:\Windows\SysWOW64\dfshim.dll [ShellLink for Application References] -> [2008-07-27 20:03:16 | 000,096,760 | ---- | M] (Microsoft Corporation) "{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}" [HKLM] -> C:\Windows\SysWOW64\zipfldr.dll [Compressed (zipped) Folder] -> [2008-01-19 09:37:13 | 000,342,016 | ---- | M] (Microsoft Corporation) "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}" [HKLM] -> C:\Windows\SysWow64\DfsShlEx.dll [DfsShell.DfsShell Property Sheet] -> [2008-01-19 09:34:03 | 000,053,760 | ---- | M] (Microsoft Corporation) "{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}" [HKLM] -> C:\Windows\SysWOW64\gameux.dll [RichGameMediaPropertyStore Class] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{ECF03A32-103D-11d2-854D-006008059367}" [HKLM] -> C:\Windows\SysWOW64\mydocs.dll [MyDocs Drop Target] -> [2008-01-19 09:35:34 | 000,135,680 | ---- | M] (Microsoft Corporation) "{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}" [HKLM] -> C:\Windows\SysWOW64\gameux.dll [Games Folder] -> [2008-03-08 06:21:55 | 001,695,744 | ---- | M] (Microsoft Corporation) "{ed9d80b9-d157-457b-9192-0e7280313bf0}" [HKLM] -> C:\Windows\SysWOW64\zipfldr.dll [Compressed (zipped) Folder Drop Handler] -> [2008-01-19 09:37:13 | 000,342,016 | ---- | M] (Microsoft Corporation) "{F0152790-D56E-4445-850E-4F3117DB740C}" [HKLM] -> C:\Windows\SysWOW64\remotepg.dll [Remote Sessions CPL Extension] -> [2008-01-19 09:36:16 | 000,058,368 | ---- | M] (Microsoft Corporation) "{F020E586-5264-11d1-A532-0000F8757D7E}" [HKLM] -> C:\Windows\SysWOW64\dsquery.dll [Directory Start/Search Find] -> [2008-01-19 09:34:07 | 000,394,240 | ---- | M] (Microsoft Corporation) "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}" [HKLM] -> C:\Windows\SysWOW64\networkexplorer.dll [Computers and Devices] -> [2008-01-19 09:35:37 | 002,226,688 | ---- | M] (Microsoft Corporation) "{F04CC277-03A2-4277-96A9-77967471BDFF}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Center Conflict Properties Extension] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" [HKLM] -> C:\Program Files (x86)\Real\RealPlayer\rpshell.dll [Shell Extensions for RealOne Player] -> [2010-08-28 02:29:09 | 000,063,016 | ---- | M] (RealNetworks, Inc.) "{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}" [HKLM] -> C:\Windows\SysWOW64\SyncCenter.dll [Sync Setup Delegate Folder] -> [2008-01-19 09:36:38 | 002,204,672 | ---- | M] (Microsoft Corporation) "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}" [HKLM] -> C:\Windows\SysWOW64\wmpshell.dll [Windows Media Player Add to Playlist Context Menu Handler] -> [2008-01-19 09:37:05 | 000,101,376 | ---- | M] (Microsoft Corporation) "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" [HKLM] -> C:\Windows\SysWow64\rshx32.dll [Printers Security Page] -> [2008-01-19 09:36:17 | 000,043,520 | ---- | M] (Microsoft Corporation) "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" [HKLM] -> C:\Windows\SysWow64\ntshrui.dll [Shell extensions for sharing] -> [2008-01-19 09:35:59 | 000,296,960 | ---- | M] (Microsoft Corporation) "{f92e8c40-3d33-11d2-b1aa-080036a75b03}" [HKLM] -> C:\Windows\SysWow64\deskperf.dll [Display TroubleShoot CPL Extension] -> [2006-11-02 11:46:03 | 000,039,424 | ---- | M] (Microsoft Corporation) "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" [HKLM] -> Reg Error: Key error. [IE User Assist] -> File not found "{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}" [HKLM] -> C:\Program Files (x86)\Windows Photo Gallery\PhotoViewer.dll [Windows Photo Gallery Viewer Image Verbs] -> [2008-01-19 09:36:04 | 002,314,240 | ---- | M] (Microsoft Corporation) < Desktop WallPaper > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General -> WallPaper -> C:\Users\Maciej\Pictures\Bez tytułu.jpg -> BackupWallPaper -> C:\Users\Maciej\Pictures\Bez tytułu.jpg -> < 64bit-Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> Adobe ARM hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe -> [2010-06-09 10:06:33 | 000,976,832 | ---- | M] (Adobe Systems Incorporated) Adobe Reader Speed Launcher hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> D:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe -> [2010-06-20 04:04:47 | 000,035,760 | ---- | M] (Adobe Systems Incorporated) avast5 hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe -> File not found LogMeIn Hamachi Ui hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Hamachi\hamachi-2-ui.exe -> [2010-03-30 11:16:16 | 001,820,040 | ---- | M] (LogMeIn Inc.) PSUNMain hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe -> [2010-05-14 15:06:28 | 000,406,848 | ---- | M] (Panda Security, S.L.) SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe -> [2010-05-14 11:44:46 | 000,248,552 | ---- | M] (Sun Microsystems, Inc.) WPCUMI hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Windows\SysNative\WpcUmi.exe -> [2006-11-02 17:03:48 | 000,182,784 | ---- | M] () < 64bit-Drivers32 [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 -> "msacm.l3acm" -> C:\Windows\SysNative\l3codeca.acm [C:\Windows\System32\l3codeca.acm] -> [2008-01-19 10:00:00 | 000,072,192 | ---- | M] () "VIDC.FPS1" -> C:\Windows\SysNative\frapsv64.dll [frapsv64.dll] -> [2010-03-31 08:00:44 | 000,084,992 | ---- | M] () < Drivers32 [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 -> "msacm.ac3acm" -> C:\Windows\SysWow64\ac3acm.acm [ac3acm.acm] -> [2007-09-21 02:52:46 | 000,118,784 | ---- | M] (fccHandler) "msacm.divxa32" -> C:\Windows\SysWow64\divxa32.acm [divxa32.acm] -> [2001-02-25 03:19:46 | 000,287,744 | ---- | M] (Kristal StudioDFileDescription) "msacm.l3acm" -> C:\Windows\SysWOW64\l3codeca.acm [C:\Windows\SysWOW64\l3codeca.acm] -> [2008-01-19 09:33:00 | 000,062,464 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) "msacm.l3fhg" -> C:\Windows\SysWow64\mp3fhg.acm [mp3fhg.acm] -> [2006-10-18 20:05:16 | 000,232,448 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) "msacm.lameacm" -> [lameACM.acm] -> File not found "msacm.lhacm" -> C:\Windows\SysWow64\lhacm.acm [lhacm.acm] -> [2010-02-09 14:48:22 | 000,034,064 | ---- | M] (Microsoft Corporation) "msacm.vorbis" -> C:\Windows\SysWow64\vorbis.acm [vorbis.acm] -> [2002-07-08 00:14:24 | 001,294,336 | ---- | M] (HMS http://hp.vector.co.jp/authors/VA012897/) "msacm.voxacm160" -> C:\Windows\SysWow64\vct3216.acm [vct3216.acm] -> [2001-03-02 19:46:18 | 000,082,944 | ---- | M] (Voxware, Inc.) "vidc.cvid" -> C:\Windows\SysWow64\iccvid.dll [iccvid.dll] -> [2006-11-02 17:02:31 | 000,081,920 | ---- | M] (Radius Inc.) "VIDC.DIVX" -> C:\Windows\SysWow64\divx.dll [divx.dll] -> [2008-03-31 23:25:46 | 000,682,496 | ---- | M] (DivX, Inc.) "VIDC.FFDS" -> C:\Windows\SysWow64\ff_vfw.dll [ff_vfw.dll] -> [2008-03-28 19:41:32 | 000,007,680 | ---- | M] () "VIDC.FPS1" -> C:\Windows\SysWow64\frapsvid.dll [frapsvid.dll] -> [2010-03-31 08:00:46 | 000,086,016 | ---- | M] (Beepa P/L) "VIDC.HFYU" -> C:\Windows\SysWow64\huffyuv.dll [huffyuv.dll] -> [2004-05-18 20:16:42 | 000,039,936 | ---- | M] (Disappearing Inc.) "vidc.i263" -> C:\Windows\SysWow64\I263_32.drv [i263_32.drv] -> [1997-04-07 19:19:00 | 000,391,680 | ---- | M] (Intel Corporation) "vidc.iv41" -> C:\Windows\SysWow64\ir41_32.ax [Ir41_32.ax] -> [2006-11-02 11:44:49 | 000,839,680 | ---- | M] (Intel Corporation) "vidc.iv50" -> C:\Windows\SysWow64\ir50_32.dll [ir50_32.dll] -> [2006-11-02 11:46:05 | 000,746,496 | ---- | M] (Intel Corporation) "vidc.tscc" -> C:\Windows\SysWow64\tsccvid.dll [tsccvid.dll] -> [2009-08-19 06:18:36 | 000,107,864 | ---- | M] (TechSmith Corporation) "VIDC.VP60" -> C:\Windows\SysWow64\vp6vfw.dll [vp6vfw.dll] -> [2004-12-10 10:03:02 | 000,438,272 | ---- | M] (On2.com) "VIDC.VP61" -> C:\Windows\SysWow64\vp6vfw.dll [vp6vfw.dll] -> [2004-12-10 10:03:02 | 000,438,272 | ---- | M] (On2.com) "VIDC.VP62" -> C:\Windows\SysWow64\vp6vfw.dll [vp6vfw.dll] -> [2004-12-10 10:03:02 | 000,438,272 | ---- | M] (On2.com) "VIDC.VP70" -> C:\Windows\SysWow64\vp7vfw.dll [vp7vfw.dll] -> [2006-04-02 14:47:06 | 000,630,784 | ---- | M] (On2.com) "VIDC.X264" -> C:\Windows\SysWow64\x264vfw.dll [x264vfw.dll] -> [2008-04-02 00:28:48 | 002,102,272 | ---- | M] () "vidc.XVID" -> C:\Windows\SysWow64\xvidvfw.dll [xvidvfw.dll] -> [2008-01-10 14:16:20 | 000,159,839 | ---- | M] () "VIDC.YV12" -> C:\Windows\SysWow64\yv12vfw.dll [yv12vfw.dll] -> [2004-01-25 18:18:44 | 000,217,088 | ---- | M] (www.helixcommunity.org) < 64bit-Ext (PreApproved) - [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ -> {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {19916E01-B44E-4E31-94A4-4696DF46157B} [HKLM] -> C:\Windows\SysNative\icardie.dll [InformationCardSigninHelper Class] -> [2009-03-08 13:38:13 | 000,085,504 | ---- | M] () {233C1507-6A77-46A4-9443-F871F945D258} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3050F819-98B5-11CF-BB82-00AA00BDCE0B} [HKLM] -> C:\Windows\SysNative\mshtmled.dll [HtmlDlgSafeHelper Class] -> [2009-03-08 13:37:42 | 000,096,768 | ---- | M] () {333C7BC4-460F-11D0-BC04-0080C7055A83} [HKLM] -> C:\Windows\SysNative\tdc.ocx [Tabular Data Control] -> [2009-03-08 13:37:10 | 000,077,824 | ---- | M] () {4063BE15-3B08-470D-A0D5-B37161CFFD69} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [HKLM] -> C:\Windows\SysNative\wmp.dll [Windows Media Player] -> [2009-07-14 15:21:42 | 013,426,176 | ---- | M] () {760C4B83-E211-11D2-BF3E-00805FBE84A6} [HKLM] -> C:\Windows\SysNative\msnetobj.dll [Windows Media Services DRM Storage object] -> [2008-01-19 10:02:34 | 000,221,696 | ---- | M] () {88d969c0-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c1-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c2-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c3-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c4-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c5-f192-11d4-a65f-0040963251e5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8E4062D9-FE1B-4b9e-AA16-5E8EEF68F48E} [HKLM] -> C:\Windows\SysNative\RegCtrl.dll [Registration Control] -> [2008-01-19 10:03:53 | 000,048,640 | ---- | M] () {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [HKLM] -> C:\Windows\SysNative\msnetobj.dll [RMGetLicense Class] -> [2008-01-19 10:02:34 | 000,221,696 | ---- | M] () {CA8A9780-280D-11CF-A24D-444553540000} [HKLM] -> Reg Error: Key error. [Adobe PDF Reader] -> File not found {CFCDAA03-8BE4-11cf-B84B-0020AFBBCCFA} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {D27CDB6E-AE6D-11cf-96B8-444553540000} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {EE09B103-97E0-11CF-978F-00A02463E06F} [HKLM] -> C:\Windows\SysNative\scrrun.dll [Scripting.Dictionary] -> [2008-05-08 08:06:49 | 000,197,632 | ---- | M] () 3E4D4F1C-2AEE-11D1-9D3D-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 435899C9-44AB-11D1-AF00-080036234103 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 4F664F91-FF01-11D0-8AED-00C04FD7B597 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 65303443-AD66-11D1-9D65-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 92337A8C-E11D-11D0-BE48-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found C3701884-B39B-11D1-9D68-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Ext (PreApproved) - [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar Helper] -> File not found {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> C:\Windows\SysWOW64\Adobe\Director\SwDir.dll [Shockwave ActiveX Control] -> [2010-08-18 08:22:14 | 000,213,272 | ---- | M] (Adobe Systems, Inc.) {19916E01-B44E-4E31-94A4-4696DF46157B} [HKLM] -> C:\Windows\SysWOW64\icardie.dll [InformationCardSigninHelper Class] -> [2009-03-08 13:31:51 | 000,059,904 | ---- | M] (Microsoft Corporation) {233C1507-6A77-46A4-9443-F871F945D258} [HKLM] -> C:\Windows\SysWOW64\Adobe\Director\SwDir.dll [Shockwave ActiveX Control] -> [2010-08-18 08:22:14 | 000,213,272 | ---- | M] (Adobe Systems, Inc.) {3050F819-98B5-11CF-BB82-00AA00BDCE0B} [HKLM] -> C:\Windows\SysWOW64\mshtmled.dll [HtmlDlgSafeHelper Class] -> [2009-03-08 13:31:24 | 000,066,560 | ---- | M] (Microsoft Corporation) {333C7BC4-460F-11D0-BC04-0080C7055A83} [HKLM] -> C:\Windows\SysWOW64\tdc.ocx [Tabular Data Control] -> [2009-03-08 13:30:54 | 000,066,560 | ---- | M] (Microsoft Corporation) {3760D689-C63B-4422-9A1D-31CA856CD5C1} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {5852F5ED-8BF4-11D4-A245-0080C6F74284} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\wsdetect.dll [isInstalled Class] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] (Oracle) {64AA7031-C150-4118-8D31-FD273A2BB22C} [HKLM] -> Reg Error: Value error. [PSFactoryBuffer] -> File not found {6BF52A52-394A-11d3-B153-00C04F79FAA6} [HKLM] -> C:\Windows\SysWOW64\wmp.dll [Windows Media Player] -> [2009-07-14 15:00:16 | 010,624,000 | ---- | M] (Microsoft Corporation) {760C4B83-E211-11D2-BF3E-00805FBE84A6} [HKLM] -> C:\Windows\SysWOW64\msnetobj.dll [Windows Media Services DRM Storage object] -> [2008-01-19 09:35:11 | 000,179,712 | ---- | M] (Microsoft Corporation) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {88d969c0-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [XML DOM Document 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {88d969c1-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [Free Threaded XML DOM Document 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {88d969c2-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [XML Schema Cache 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {88d969c3-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [XSL Template 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {88d969c4-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [XML Data Source Object 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {88d969c5-f192-11d4-a65f-0040963251e5} [HKLM] -> C:\Windows\SysWOW64\msxml4.dll [XML HTTP 4.0] -> [2008-09-30 17:43:34 | 001,286,152 | ---- | M] (Microsoft Corporation) {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_21] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {8E4062D9-FE1B-4b9e-AA16-5E8EEF68F48E} [HKLM] -> C:\Windows\SysWOW64\RegCtrl.dll [Registration Control] -> [2008-01-19 09:36:16 | 000,040,960 | ---- | M] (Microsoft Corporation) {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [HKLM] -> C:\Windows\SysWOW64\msnetobj.dll [RMGetLicense Class] -> [2008-01-19 09:35:11 | 000,179,712 | ---- | M] (Microsoft Corporation) {B345F37E-6763-433b-BC53-9B526A9B7B8B} [HKLM] -> Reg Error: Value error. [GetInfo2 Class] -> File not found {CA8A9780-280D-11CF-A24D-444553540000} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll [Adobe PDF Reader] -> [2010-06-19 21:28:28 | 000,660,912 | ---- | M] (Adobe Systems, Inc.) {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_04] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_04] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_04] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_07] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_07] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_07] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_21] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_21] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll [Java Plug-in 1.6.0_21] -> [2010-06-22 04:36:33 | 000,108,320 | ---- | M] () {CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA} [HKLM] -> C:\Windows\SysWOW64\deployJava1.dll [Deployment Toolkit] -> [2010-06-22 04:36:29 | 000,423,656 | ---- | M] (Oracle) {CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA} [HKLM] -> C:\Windows\SysWOW64\deployJava1.dll [Deployment Toolkit] -> [2010-06-22 04:36:29 | 000,423,656 | ---- | M] (Oracle) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CFCDAA03-8BE4-11cf-B84B-0020AFBBCCFA} [HKLM] -> C:\Windows\SysWOW64\rmoc3260.dll [RealPlayer G2 Control] -> [2010-08-28 02:29:17 | 000,185,920 | ---- | M] (RealNetworks, Inc.) {D27CDB6E-AE6D-11cf-96B8-444553540000} [HKLM] -> C:\Windows\SysWOW64\Macromed\Flash\Flash10h.ocx [Shockwave Flash Object] -> [2010-07-27 07:38:16 | 005,712,336 | R--- | M] (Adobe Systems, Inc.) {D5184A39-CBDF-4A4F-AC1A-7A45A852C883} [HKLM] -> Reg Error: Value error. [GetInfo Class] -> File not found {DFEAF541-F3E1-4c24-ACAC-99C30715084A} [HKLM] -> Reg Error: Value error. [Microsoft Silverlight] -> File not found {EE09B103-97E0-11CF-978F-00A02463E06F} [HKLM] -> C:\Windows\SysWOW64\scrrun.dll [Scripting.Dictionary] -> [2008-05-08 23:59:32 | 000,172,032 | ---- | M] (Microsoft Corporation) {EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar] -> File not found 3E4D4F1C-2AEE-11D1-9D3D-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 435899C9-44AB-11D1-AF00-080036234103 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 4F664F91-FF01-11D0-8AED-00C04FD7B597 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 65303443-AD66-11D1-9D65-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 92337A8C-E11D-11D0-BE48-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found C3701884-B39B-11D1-9D68-00C04FC30DF6 [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Ext (Settings) - [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\ -> {00C6482D-C502-44C8-8409-FCE54AD9C208} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar Helper] -> File not found {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2010-06-19 21:29:40 | 000,061,888 | ---- | M] (Adobe Systems Incorporated) {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {22BF413B-C6D2-4D91-82A9-A0F997BA588C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {2333EB16-E7A7-4DA8-A5B8-5F2F82A3D9A3} [HKLM] -> Reg Error: Value error. [Iplamk Control] -> File not found {25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) 64bit-{32099AAC-C132-4136-9E9A-4E364A424E17} [HKLM] -> C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [DAEMON Tools Toolbar] -> File not found {32099AAC-C132-4136-9E9A-4E364A424E17} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [VirtualKeyboardButtonHandler Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [VirtualKeyboardButtonHandler Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {4B3803EA-5230-4DC3-A7FC-33638F3D3542} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {4D0C4820-53F7-4D79-A2E1-5252683CF69C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\PROGRA~2\SPYBOT~1\SDHelper.dll [Spybot-S&D IE Protection] -> [2008-09-15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) {57BCA5FA-5DBB-45A2-B558-1755C3F6253B} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:39:12 | 000,061,456 | ---- | M] (Kaspersky Lab) {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:34:50 | 000,068,112 | ---- | M] (Kaspersky Lab) {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {6D53EC84-6AAE-4787-AEEE-F4628F01010C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8170D7DC-BDD6-461E-88EB-F047257898C9} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {AA58ED58-01DD-4D91-8333-CF10577473F7} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {ACBCF095-E8C0-420F-8769-2845D9B92E8C} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CB789373-04D5-4EF4-9C16-871463FD0830} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [FilterButtonHandler Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [FilterButtonHandler Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> C:\Windows\SysWOW64\Macromed\Flash\Flash10h.ocx [Shockwave Flash Object] -> [2010-07-27 07:38:16 | 005,712,336 | R--- | M] (Adobe Systems, Inc.) {D6E814A0-E0C5-11D4-8D29-0050BA6940E3} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar] -> File not found {F156768E-81EF-470C-9057-481BA8380DBA} [HKLM] -> C:\Program Files (x86)\FlashGet\getflash.dll [FlashGet GetFlash Class] -> [2007-05-18 18:13:10 | 000,163,840 | ---- | M] (www.flashget.com) {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {F90D830D-C175-4bbe-82C7-FF94669A4C42} [HKLM] -> C:\Program Files (x86)\FlashGet\fgupdate.dll [FGAutoLive] -> [2007-05-18 18:13:08 | 000,176,208 | ---- | M] (www.flashget.com) < Ext (Stats) - [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\ -> {00C6482D-C502-44C8-8409-FCE54AD9C208} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar Helper] -> File not found {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2010-06-19 21:29:40 | 000,061,888 | ---- | M] (Adobe Systems Incorporated) {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {22BF413B-C6D2-4D91-82A9-A0F997BA588C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) 64bit-{32099AAC-C132-4136-9E9A-4E364A424E17} [HKLM] -> C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [DAEMON Tools Toolbar] -> File not found {32099AAC-C132-4136-9E9A-4E364A424E17} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {3760D689-C63B-4422-9A1D-31CA856CD5C1} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [VirtualKeyboardButtonHandler Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {4248FE82-7FCB-46AC-B270-339F08212110} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [VirtualKeyboardButtonHandler Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {4B3803EA-5230-4DC3-A7FC-33638F3D3542} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {4D0C4820-53F7-4D79-A2E1-5252683CF69C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\PROGRA~2\SPYBOT~1\SDHelper.dll [Spybot-S&D IE Protection] -> [2008-09-15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) {57BCA5FA-5DBB-45A2-B558-1755C3F6253B} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:39:12 | 000,061,456 | ---- | M] (Kaspersky Lab) {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll [IEVkbdBHO Class] -> [2009-10-20 19:34:50 | 000,068,112 | ---- | M] (Kaspersky Lab) {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {6D53EC84-6AAE-4787-AEEE-F4628F01010C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8170D7DC-BDD6-461E-88EB-F047257898C9} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {AA58ED58-01DD-4D91-8333-CF10577473F7} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {ACBCF095-E8C0-420F-8769-2845D9B92E8C} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {CB789373-04D5-4EF4-9C16-871463FD0830} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [FilterButtonHandler Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {CCF151D8-D089-449F-A5A4-D9909053F20F} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [FilterButtonHandler Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> C:\Windows\SysWOW64\Macromed\Flash\Flash10h.ocx [Shockwave Flash Object] -> [2010-07-27 07:38:16 | 005,712,336 | R--- | M] (Adobe Systems, Inc.) {D6E814A0-E0C5-11D4-8D29-0050BA6940E3} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found 64bit-{E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:39:14 | 000,345,104 | ---- | M] (Kaspersky Lab) {E33CF602-D945-461A-83F0-819F76A199F8} [HKLM] -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [FilterBHO Class] -> [2009-10-20 19:34:56 | 000,268,816 | ---- | M] (Kaspersky Lab) {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> Reg Error: Key error. [Yahoo! Toolbar] -> File not found {F156768E-81EF-470C-9057-481BA8380DBA} [HKLM] -> C:\Program Files (x86)\FlashGet\getflash.dll [FlashGet GetFlash Class] -> [2007-05-18 18:13:10 | 000,163,840 | ---- | M] (www.flashget.com) {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {F90D830D-C175-4bbe-82C7-FF94669A4C42} [HKLM] -> C:\Program Files (x86)\FlashGet\fgupdate.dll [FGAutoLive] -> [2007-05-18 18:13:08 | 000,176,208 | ---- | M] (www.flashget.com) {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} [HKLM] -> C:\Program Files (x86)\FlashGet\jccatch.dll [FGCatchUrl] -> [2007-08-06 11:11:58 | 000,094,308 | ---- | M] (www.flashget.com) < 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> "%1" %* -> .cmd [@ = cmdfile] -> "%1" %* -> .com [@ = comfile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> .pif [@ = piffile] -> "%1" %* -> .scr [@ = scrfile] -> "%1" /S -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> "%1" %* -> .cmd [@ = cmdfile] -> "%1" %* -> .com [@ = comfile] -> "%1" %* -> .cpl [@ = cplfile] -> C:\Windows\SysWow64\control.exe -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) .exe [@ = exefile] -> "%1" %* -> .pif [@ = piffile] -> "%1" %* -> .scr [@ = scrfile] -> "%1" /S -> < File Associations - Select to Repair > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Classes\\ -> .chm [@ = chm.file] -> Reg Error: Key error. -> File not found .html [@ = FirefoxHTML] -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe -> [2010-09-16 21:51:41 | 000,910,296 | ---- | M] (Mozilla Corporation) < 64bit-Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> gopher:{79eac9e4-baf9-11ce-8c82-00aa004ba90b} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.] -> File not found skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.] -> File not found < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} [HKLM] -> C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL[IEProtocolHandler Class] -> [2010-05-13 16:12:42 | 002,135,336 | R--- | M] (Skype Technologies) < 64bit-SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AppMgmt -> 32bit -> File not found Base -> Driver Group Boot Bus Extender -> Driver Group Boot file system -> Driver Group File system -> Driver Group Filter -> Driver Group HelpSvc -> Service NTDS -> 32bit -> File not found PCI Configuration -> Driver Group PNP Filter -> Driver Group Primary disk -> Driver Group sacsvr -> Service SCSI Class -> Driver Group System Bus Extender -> Driver Group TrustedInstaller -> Service WinDefend -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-19 10:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) < SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AppInfo -> 64bit -> File not found AppMgmt -> 64bit -> File not found Base -> Driver Group Boot Bus Extender -> Driver Group Boot file system -> Driver Group DcomLaunch -> 64bit -> File not found EventLog -> 64bit -> File not found File system -> Driver Group Filter -> Driver Group HelpSvc -> Service KeyIso -> 64bit -> File not found Netlogon -> 64bit -> File not found NTDS -> 64bit -> File not found PCI Configuration -> Driver Group PlugPlay -> 64bit -> File not found PNP Filter -> Driver Group Primary disk -> Driver Group ProfSvc -> 64bit -> File not found RpcSs -> 64bit -> File not found sacsvr -> Service SCSI Class -> Driver Group sermouse.sys -> 64bit -> File not found SWPRV -> 64bit -> File not found System Bus Extender -> Driver Group TabletInputService -> 64bit -> File not found TBS -> 64bit -> File not found TrustedInstaller -> Service VDS -> 64bit -> File not found vga.sys -> 64bit -> File not found vgasave.sys -> 64bit -> File not found volmgr.sys -> 64bit -> File not found volmgrx.sys -> 64bit -> File not found WinDefend -> 64bit -> File not found WinMgmt -> 64bit -> File not found < 64bit-SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E972-E325-11CE-BFC1-08002BE10318} -> Net {4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient {4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService {4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {50DD5230-BA8A-11D1-BF5D-0000F805F530} -> Smart card readers {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AppMgmt -> 32bit -> File not found Base -> Driver Group Boot Bus Extender -> Driver Group Boot file system -> Driver Group File system -> Driver Group Filter -> Driver Group Hamachi2Svc -> 32bit -> File not found HelpSvc -> Service Messenger -> Service NDIS Wrapper -> Driver Group NetBIOSGroup -> Driver Group NetDDEGroup -> Driver Group Network -> Driver Group NetworkProvider -> Driver Group NTDS -> 32bit -> File not found PCI Configuration -> Driver Group PNP Filter -> Driver Group PNP_TDI -> Driver Group Primary disk -> Driver Group rdsessmgr -> Service sacsvr -> Service SCSI Class -> Driver Group Streams Drivers -> Driver Group System Bus Extender -> Driver Group TDI -> Driver Group TrustedInstaller -> Service WinDefend -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008-01-19 10:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) < SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ -> {36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers {4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive {4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive {4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller {4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc {4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard {4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse {4D36E972-E325-11CE-BFC1-08002BE10318} -> Net {4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient {4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService {4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans {4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters {4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter {4D36E97D-E325-11CE-BFC1-08002BE10318} -> System {4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive {50DD5230-BA8A-11D1-BF5D-0000F805F530} -> Smart card readers {533C5B84-EC70-11D2-9505-00C04F79DEAF} -> Volume shadow copy {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} -> IEEE 1394 Bus host controllers {71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices {D48179BE-EC20-11D1-B6B8-00C04FA372A7} -> SBP2 IEEE 1394 Devices {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} -> SecurityDevices AFD -> 64bit -> File not found AppInfo -> 64bit -> File not found AppMgmt -> 64bit -> File not found Base -> Driver Group BFE -> 64bit -> File not found Boot Bus Extender -> Driver Group Boot file system -> Driver Group bowser -> 64bit -> File not found Browser -> 64bit -> File not found DcomLaunch -> 64bit -> File not found dfsc -> 64bit -> File not found DnsCache -> 64bit -> File not found Dot3Svc -> 64bit -> File not found Eaphost -> 64bit -> File not found EventLog -> 64bit -> File not found File system -> Driver Group Filter -> Driver Group Hamachi2Svc -> C:\Program Files (x86)\Hamachi\hamachi-2.exe -> [2010-03-30 11:16:14 | 001,823,112 | ---- | M] (LogMeIn Inc.) HelpSvc -> Service IKEEXT -> 64bit -> File not found ipnat.sys -> 64bit -> File not found KeyIso -> 64bit -> File not found LanmanServer -> 64bit -> File not found LanmanWorkstation -> 64bit -> File not found LmHosts -> 64bit -> File not found Messenger -> Service MPSDrv -> 64bit -> File not found MPSSvc -> 64bit -> File not found mrxsmb -> 64bit -> File not found mrxsmb10 -> 64bit -> File not found mrxsmb20 -> 64bit -> File not found NativeWifiP -> 64bit -> File not found NDIS -> 64bit -> File not found NDIS Wrapper -> Driver Group Ndisuio -> 64bit -> File not found NetBIOS -> 64bit -> File not found NetBIOSGroup -> Driver Group NetBT -> 64bit -> File not found NetDDEGroup -> Driver Group Netlogon -> 64bit -> File not found NetMan -> 64bit -> File not found Network -> Driver Group NetworkProvider -> Driver Group NlaSvc -> 64bit -> File not found Nsi -> 64bit -> File not found nsiproxy.sys -> 64bit -> File not found NTDS -> 64bit -> File not found PCI Configuration -> Driver Group PlugPlay -> 64bit -> File not found PNP Filter -> Driver Group PNP_TDI -> Driver Group PolicyAgent -> 64bit -> File not found Primary disk -> Driver Group ProfSvc -> 64bit -> File not found rdbss -> 64bit -> File not found rdpencdd.sys -> 64bit -> File not found rdsessmgr -> Service RpcSs -> 64bit -> File not found sacsvr -> Service SCSI Class -> Driver Group sermouse.sys -> 64bit -> File not found SharedAccess -> 64bit -> File not found Streams Drivers -> Driver Group SWPRV -> 64bit -> File not found System Bus Extender -> Driver Group TabletInputService -> 64bit -> File not found TBS -> 64bit -> File not found Tcpip -> 64bit -> File not found TDI -> Driver Group TrustedInstaller -> Service VDS -> 64bit -> File not found vga.sys -> 64bit -> File not found vgasave.sys -> 64bit -> File not found volmgr.sys -> 64bit -> File not found volmgrx.sys -> 64bit -> File not found WinDefend -> 64bit -> File not found WinMgmt -> 64bit -> File not found Wlansvc -> 64bit -> File not found < 64bit-Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center -> 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center \\"cval" -> [1] -> File not found 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\ -> -> 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc \Svc\\"AntiVirusOverride" -> [0] -> File not found \Svc\\"AntiSpywareOverride" -> [0] -> File not found \Svc\\"FirewallOverride" -> [0] -> File not found \Svc\\"VistaSp1" -> [7B 2F 5E 2D 95 C4 C8 01 [binary data]] -> File not found 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol\ -> -> < 64bit-System Restore Group Policy Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore -> < Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus \Monitoring\KasperskyAntiVirus\\"DisableMonitoring" -> [1] -> File not found \Monitoring\KasperskyAntiVirus\\"" -> [] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc \Svc\\"oobe_av" -> [1] -> File not found < System Restore Group Policy Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore -> < Windows DomainProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile \\"DisableNotifications" -> [0] -> File not found \\"EnableFirewall" -> [1] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging\ -> -> < Windows StandardProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile \\"DisableNotifications" -> [0] -> File not found \\"EnableFirewall" -> [1] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging\ -> -> < Session Manager Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager -> *BootExecute* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\BootExecute -> autocheck autochk * -> -> File not found *MultiFile Done* -> -> "ExcludeFromKnownDlls" -> [binary data] -> 64bit-*ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories -> \Windows -> \Windows -> [2010-09-26 10:30:01 | 000,000,000 | ---D | M] \RPC Control -> -> File not found *MultiFile Done* -> -> *ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories -> \Windows -> \Windows -> [2010-09-26 10:30:01 | 000,000,000 | ---D | M] \RPC Control -> -> File not found *MultiFile Done* -> -> 64bit-*PendingFileRenameOperations* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\PendingFileRenameOperations -> \??\C:\ProgramData\IObit\Advanced SystemCare\temp.ini [\??\C:\ProgramData\IObit\Advanced SystemCare\temp.ini] -> C:\ProgramData\IObit\Advanced SystemCare\temp.ini [C:\ProgramData\IObit\Advanced SystemCare\temp.ini] -> [2010-09-26 10:34:08 | 000,000,114 | ---- | M] () *MultiFile Done* -> -> *PendingFileRenameOperations* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\PendingFileRenameOperations -> \??\C:\ProgramData\IObit\Advanced SystemCare\temp.ini [\??\C:\ProgramData\IObit\Advanced SystemCare\temp.ini] -> C:\ProgramData\IObit\Advanced SystemCare\temp.ini [C:\ProgramData\IObit\Advanced SystemCare\temp.ini] -> [2010-09-26 10:34:08 | 000,000,114 | ---- | M] () *MultiFile Done* -> -> < Session Manager Environment Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment -> 64bit-"ComSpec" -> C:\Windows\SysNative\cmd.exe -> [2008-01-19 10:00:10 | 000,363,008 | ---- | M] () "ComSpec" -> C:\Windows\SysWOW64\cmd.exe -> [2008-01-19 09:33:04 | 000,318,976 | ---- | M] (Microsoft Corporation) "TEMP" -> C:\Windows\Temp -> [2010-09-26 13:35:45 | 000,000,000 | ---D | M] "TMP" -> C:\Windows\Temp -> [2010-09-26 13:35:45 | 000,000,000 | ---D | M] "windir" -> C:\Windows -> [2010-09-26 10:30:01 | 000,000,000 | ---D | M] 64bit-*Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path -> %SYSTEMROOT%\SYSTEM32 -> C:\Windows\SysNative -> File not found %SYSTEMROOT% -> C:\Windows -> [2010-09-26 10:30:01 | 000,000,000 | ---D | M] %SYSTEMROOT%\SYSTEM32\WBEM -> C:\Windows\SysNative\WBEM -> [2010-02-19 22:38:20 | 000,000,000 | ---D | M] *MultiFile Done* -> -> *Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path -> %SYSTEMROOT%\SYSTEM32 -> C:\Windows\SysWOW64 -> [2010-09-20 13:01:19 | 000,000,000 | ---D | M] %SYSTEMROOT% -> C:\Windows -> [2010-09-26 10:30:01 | 000,000,000 | ---D | M] %SYSTEMROOT%\SYSTEM32\WBEM -> C:\Windows\SysWOW64\wbem -> [2010-08-11 13:51:44 | 000,000,000 | ---D | M] *MultiFile Done* -> -> *PATHEXT* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\PATHEXT -> .COM -> -> File not found .EXE -> -> File not found .BAT -> -> File not found .CMD -> -> File not found .VBS -> -> File not found .VBE -> -> File not found .JS -> -> File not found .JSE -> -> File not found .WSF -> -> File not found .WSH -> -> File not found .MSC -> -> File not found *MultiFile Done* -> -> < Session Manager FileRenameOperations Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations -> < Session Manager KnownDlls Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls -> 64bit-"advapi32" -> C:\Windows\SysNative\advapi32.dll -> [2008-01-19 10:00:50 | 001,062,400 | ---- | M] () 64bit-"clbcatq" -> C:\Windows\SysNative\clbcatq.dll -> [2008-01-19 10:01:02 | 000,611,328 | ---- | M] () 64bit-"COMDLG32" -> C:\Windows\SysNative\comdlg32.dll -> [2008-01-19 10:01:07 | 000,549,376 | ---- | M] () 64bit-"DllDirectory" -> C:\Windows\SysNative -> File not found 64bit-"DllDirectory32" -> C:\Windows\SysWOW64 -> [2010-09-20 13:01:19 | 000,000,000 | ---D | M] 64bit-"gdi32" -> C:\Windows\SysNative\gdi32.dll -> [2008-10-21 07:49:02 | 000,388,608 | ---- | M] () 64bit-"IERTUTIL" -> C:\Windows\SysNative\iertutil.dll -> [2009-07-22 00:06:31 | 002,334,208 | ---- | M] () 64bit-"IMAGEHLP" -> C:\Windows\SysNative\imagehlp.dll -> [2008-01-19 10:01:50 | 000,074,240 | ---- | M] () 64bit-"IMM32" -> C:\Windows\SysNative\imm32.dll -> [2008-01-19 10:01:50 | 000,163,840 | ---- | M] () 64bit-"kernel32" -> C:\Windows\SysNative\kernel32.dll -> [2009-02-13 10:57:39 | 001,208,832 | ---- | M] () 64bit-"LPK" -> C:\Windows\SysNative\lpk.dll -> [2008-01-19 10:02:01 | 000,032,768 | ---- | M] () 64bit-"MSCTF" -> C:\Windows\SysNative\msctf.dll -> [2008-01-19 10:02:20 | 001,040,384 | ---- | M] () 64bit-"MSVCRT" -> C:\Windows\SysNative\msvcrt.dll -> [2008-01-19 10:02:37 | 000,621,056 | ---- | M] () 64bit-"NORMALIZ" -> C:\Windows\SysNative\normaliz.dll -> [2006-11-02 11:05:22 | 000,003,072 | ---- | M] () 64bit-"NSI" -> C:\Windows\SysNative\nsi.dll -> [2008-01-19 10:03:22 | 000,011,264 | ---- | M] () 64bit-"ole32" -> C:\Windows\SysNative\ole32.dll -> [2008-01-19 10:03:26 | 001,923,072 | ---- | M] () 64bit-"OLEAUT32" -> C:\Windows\SysNative\oleaut32.dll -> [2008-01-19 10:03:26 | 000,847,872 | ---- | M] () 64bit-"rpcrt4" -> C:\Windows\SysNative\rpcrt4.dll -> [2009-04-23 15:18:11 | 001,280,512 | ---- | M] () 64bit-"Setupapi" -> C:\Windows\SysNative\setupapi.dll -> [2008-01-19 10:04:02 | 001,921,536 | ---- | M] () 64bit-"SHELL32" -> C:\Windows\SysNative\shell32.dll -> [2008-11-06 15:32:58 | 012,897,792 | ---- | M] () 64bit-"SHLWAPI" -> C:\Windows\SysNative\shlwapi.dll -> [2008-01-19 10:04:04 | 000,454,144 | ---- | M] () 64bit-"URLMON" -> C:\Windows\SysNative\urlmon.dll -> [2009-07-22 00:11:04 | 001,484,288 | ---- | M] () 64bit-"user32" -> C:\Windows\SysNative\user32.dll -> [2008-01-19 10:04:23 | 000,820,224 | ---- | M] () 64bit-"USP10" -> C:\Windows\SysNative\usp10.dll -> [2008-01-19 10:04:23 | 000,622,080 | ---- | M] () 64bit-"WININET" -> C:\Windows\SysNative\wininet.dll -> [2009-07-22 00:11:15 | 001,146,880 | ---- | M] () 64bit-"WLDAP32" -> C:\Windows\SysNative\Wldap32.dll -> [2008-01-19 10:04:36 | 000,328,704 | ---- | M] () 64bit-"WS2_32" -> C:\Windows\SysNative\ws2_32.dll -> [2008-01-19 10:04:48 | 000,265,216 | ---- | M] () "advapi32" -> C:\Windows\SysWow64\advapi32.dll -> [2008-01-19 09:33:43 | 000,798,720 | ---- | M] (Microsoft Corporation) "clbcatq" -> C:\Windows\SysWow64\clbcatq.dll -> [2008-01-19 09:33:52 | 000,523,776 | ---- | M] (Microsoft Corporation) "COMDLG32" -> C:\Windows\SysWow64\comdlg32.dll -> [2008-01-19 09:33:58 | 000,450,048 | ---- | M] (Microsoft Corporation) "DllDirectory" -> C:\Windows\SysWOW64 -> [2010-09-20 13:01:19 | 000,000,000 | ---D | M] "DllDirectory32" -> C:\Windows\SysWOW64 -> [2010-09-20 13:01:19 | 000,000,000 | ---D | M] "gdi32" -> C:\Windows\SysWow64\gdi32.dll -> [2008-10-21 07:23:58 | 000,303,104 | ---- | M] (Microsoft Corporation) "IERTUTIL" -> C:\Windows\SysWow64\iertutil.dll -> [2009-07-21 23:47:27 | 001,985,536 | ---- | M] (Microsoft Corporation) "IMAGEHLP" -> C:\Windows\SysWow64\imagehlp.dll -> [2008-01-19 09:34:32 | 000,153,088 | ---- | M] (Microsoft Corporation) "IMM32" -> C:\Windows\SysWow64\imm32.dll -> [2008-01-19 09:32:17 | 000,116,224 | ---- | M] (Microsoft Corporation) "kernel32" -> C:\Windows\SysWow64\kernel32.dll -> [2009-02-13 10:47:47 | 000,855,552 | ---- | M] (Microsoft Corporation) "LPK" -> C:\Windows\SysWow64\lpk.dll -> [2008-01-19 09:32:19 | 000,023,552 | ---- | M] (Microsoft Corporation) "MSCTF" -> C:\Windows\SysWow64\msctf.dll -> [2008-01-19 09:34:55 | 000,806,912 | ---- | M] (Microsoft Corporation) "MSVCRT" -> C:\Windows\SysWow64\msvcrt.dll -> [2008-01-19 09:35:15 | 000,680,448 | ---- | M] (Microsoft Corporation) "NORMALIZ" -> C:\Windows\SysWow64\normaliz.dll -> [2006-11-02 10:33:06 | 000,002,560 | ---- | M] (Microsoft Corporation) "NSI" -> C:\Windows\SysWow64\nsi.dll -> [2008-01-19 09:35:57 | 000,008,192 | ---- | M] (Microsoft Corporation) "ole32" -> C:\Windows\SysWow64\ole32.dll -> [2008-01-19 09:36:01 | 001,315,328 | ---- | M] (Microsoft Corporation) "OLEAUT32" -> C:\Windows\SysWow64\oleaut32.dll -> [2008-01-19 09:36:01 | 000,563,200 | ---- | M] (Microsoft Corporation) "rpcrt4" -> C:\Windows\SysWow64\rpcrt4.dll -> [2009-04-23 14:44:38 | 000,677,376 | ---- | M] (Microsoft Corporation) "Setupapi" -> C:\Windows\SysWow64\setupapi.dll -> [2008-01-19 09:36:24 | 001,590,272 | ---- | M] (Microsoft Corporation) "SHELL32" -> C:\Windows\SysWow64\shell32.dll -> [2008-11-06 15:14:25 | 011,580,928 | ---- | M] (Microsoft Corporation) "SHLWAPI" -> C:\Windows\SysWow64\shlwapi.dll -> [2008-01-19 09:36:29 | 000,351,744 | ---- | M] (Microsoft Corporation) "URLMON" -> C:\Windows\SysWow64\urlmon.dll -> [2009-07-21 23:52:13 | 001,208,832 | ---- | M] (Microsoft Corporation) "user32" -> C:\Windows\SysWow64\user32.dll -> [2008-01-19 09:32:19 | 000,648,192 | ---- | M] (Microsoft Corporation) "USP10" -> C:\Windows\SysWow64\usp10.dll -> [2008-01-19 09:36:47 | 000,501,760 | ---- | M] (Microsoft Corporation) "WININET" -> C:\Windows\SysWow64\wininet.dll -> [2009-07-21 23:52:28 | 000,915,456 | ---- | M] (Microsoft Corporation) "WLDAP32" -> C:\Windows\SysWow64\Wldap32.dll -> [2008-01-19 09:36:57 | 000,289,280 | ---- | M] (Microsoft Corporation) "WS2_32" -> C:\Windows\SysWow64\ws2_32.dll -> [2008-01-19 09:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> 64bit-batfile [open] -> "%1" %* -> File not found 64bit-cmdfile [open] -> "%1" %* -> File not found 64bit-comfile [open] -> "%1" %* -> File not found 64bit-exefile [open] -> "%1" %* -> File not found 64bit-htmlfile [print] -> rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" -> File not found 64bit-inffile [install] -> %SystemRoot%\System32\InfDefaultInstall.exe "%1" -> [2006-11-02 13:15:54 | 000,011,264 | ---- | M] () 64bit-InternetShortcut [print] -> "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" -> [2009-07-21 23:48:31 | 005,937,152 | ---- | M] (Microsoft Corporation) 64bit-piffile [open] -> "%1" %* -> File not found 64bit-scrfile [config] -> "%1" -> File not found 64bit-scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008-01-19 09:59:48 | 000,371,200 | ---- | M] () 64bit-scrfile [open] -> "%1" /S -> File not found 64bit-Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 -> File not found 64bit-Directory [[ Odkurz tutaj ]] -> "C:\Program Files (x86)\Odkurzacz\odkurzacz.exe" "%1" -> [2010-09-25 15:03:59 | 001,232,896 | ---- | M] (Franmo Software) 64bit-Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2008-01-19 10:00:10 | 000,363,008 | ---- | M] () 64bit-Directory [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) 64bit-Directory [Winamp.Bookmark] -> "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) 64bit-Directory [Winamp.Enqueue] -> "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) 64bit-Directory [Winamp.Play] -> "C:\Program Files (x86)\Winamp\winamp.exe" "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) 64bit-Folder [open] -> %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) 64bit-Folder [explore] -> %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) 64bit-Drive [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) batfile [open] -> "%1" %* -> cmdfile [open] -> "%1" %* -> comfile [open] -> "%1" %* -> cplfile [cplopen] -> %SystemRoot%\System32\control.exe "%1",%* -> [2006-11-02 11:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation) exefile [open] -> "%1" %* -> htmlfile [print] -> rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" -> inffile [install] -> %SystemRoot%\System32\InfDefaultInstall.exe "%1" -> [2008-01-19 09:33:12 | 000,011,776 | ---- | M] (Microsoft Corporation) piffile [open] -> "%1" %* -> scrfile [config] -> "%1" -> scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008-01-19 09:32:56 | 000,368,640 | ---- | M] (Microsoft Corporation) scrfile [open] -> "%1" /S -> Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 -> Directory [[ Odkurz tutaj ]] -> "C:\Program Files (x86)\Odkurzacz\odkurzacz.exe" "%1" -> [2010-09-25 15:03:59 | 001,232,896 | ---- | M] (Franmo Software) Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2008-01-19 09:33:04 | 000,318,976 | ---- | M] (Microsoft Corporation) Directory [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) Directory [Winamp.Bookmark] -> "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) Directory [Winamp.Enqueue] -> "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) Directory [Winamp.Play] -> "C:\Program Files (x86)\Winamp\winamp.exe" "%1" -> [2009-03-09 17:50:48 | 001,433,952 | ---- | M] (Nullsoft) Folder [open] -> %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) Folder [explore] -> %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) Drive [find] -> %SystemRoot%\Explorer.exe -> [2008-10-29 08:49:22 | 003,080,704 | ---- | M] (Microsoft Corporation) < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 64bit-NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -> C:\Program Files (x86)\Bonjour\mdnsNSP.dll -> [2006-02-28 12:42:30 | 000,094,208 | ---- | M] (Apple Computer, Inc.) 64bit-Protocol_Catalog9\Catalog_Entries\000000000001 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000002 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000003 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000004 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000005 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000006 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000007 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000008 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () 64bit-Protocol_Catalog9\Catalog_Entries\000000000019 -> C:\Windows\SysNative\wpclsp.dll -> [2006-11-02 17:03:49 | 000,102,912 | ---- | M] () NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -> C:\Program Files (x86)\Bonjour\mdnsNSP.dll -> [2006-02-28 12:42:30 | 000,094,208 | ---- | M] (Apple Computer, Inc.) Protocol_Catalog9\Catalog_Entries\000000000001 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000002 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000003 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000004 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000005 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000006 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000007 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000008 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) Protocol_Catalog9\Catalog_Entries\000000000019 -> C:\Windows\SysWow64\wpclsp.dll -> [2008-01-19 09:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) < Default Protocols [HKEY_LOCAL_MACHINE\] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> ldap -> 4 = Restricted sites (Not a Default Protocol) -> news -> 4 = Restricted sites (Not a Default Protocol) -> nntp -> 4 = Restricted sites (Not a Default Protocol) -> oecmd -> 4 = Restricted sites (Not a Default Protocol) -> snews -> 4 = Restricted sites (Not a Default Protocol) -> < Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> @ivt -> @ivt protocol not assigned -> file -> file protocol not assigned -> ftp -> ftp protocol not assigned -> http -> http protocol not assigned -> https -> https protocol not assigned -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> @ivt -> @ivt protocol not assigned -> file -> file protocol not assigned -> ftp -> ftp protocol not assigned -> http -> http protocol not assigned -> https -> https protocol not assigned -> shell -> shell protocol not assigned -> < 64bit-Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {071c9b48-7c32-4621-a0ac-3f809523288f} -> Microsoft Visual C++ 2005 Redistributable (x64) {3D3E663D-4E7E-4577-A560-7ECDDD45548A} -> PVSonyDll {50431EE1-C1CC-4AE7-BDE3-B60536E7BA92} -> Panda Cloud Antivirus {8E34682C-8118-31F1-BC4C-98CD9675E1C2} -> Microsoft .NET Framework 4 Extended {8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7} -> Microsoft .NET Framework 4 Extended PLK Language Pack {A49402DD-2781-3782-B0CF-52BDA349E3F3} -> Microsoft .NET Framework 4 Client Profile PLK Language Pack {B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel -> Panel sterowania NVIDIA 260.63 {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver -> NVIDIA Sterownik graficzny 260.63 {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer -> NVIDIA Install Application {B6E3757B-5E77-3915-866A-CCFC4B8D194C} -> Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} -> Microsoft .NET Framework 4 Client Profile cFosSpeed -> cFosSpeed v5.00 CPUID CPU-Z_is1 -> CPUID CPU-Z 1.55 Defraggler -> Defraggler Microsoft .NET Framework 4 Client Profile -> Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile PLK Language Pack -> Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended -> Microsoft .NET Framework 4 Extended Microsoft .NET Framework 4 Extended PLK Language Pack -> Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended NVIDIA Drivers -> NVIDIA Drivers NVIDIA nView Desktop Manager -> NVIDIA nView Desktop Manager < Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {048298C9-A4D3-490B-9FF9-AB023A9238F3} -> Steam {04AF207D-9A77-465A-8B76-991F6AB66245} -> Adobe Help Viewer CS3 {08B32819-6EEF-4057-AEDA-5AB681A36A23} -> Adobe Bridge Start Meeting {184CE391-7E0E-4C63-9935-D7A10EDFD3C6} -> Adobe WinSoft Linguistics Plugin {18E65799-76BD-46EF-9E53-972FE5A40736} -> Opera 10.62 {1ADE1AA0-7F82-4BB1-B1BD-727DE438057B} -> Cool & Quiet {24D7346D-D4B4-45E8-98EA-75EC14B42DD8} -> Adobe ExtendScript Toolkit 2 {26A24AE4-039D-4CA4-87B4-2F83216016FF} -> Java(TM) 6 Update 21 {293D5729-7C01-4FA4-A4DE-BB6A1587BBB9} -> PDF Settings {29E5EA97-5F74-4A57-B8B2-D4F169117183} -> Adobe Stock Photos CS3 {2D57FB4E-6277-4A6D-8739-304C38051B89} -> Jitbit Macro Recorder {3248F0A8-6813-11D6-A77B-00B0D0160040} -> Java(TM) 6 Update 4 {3248F0A8-6813-11D6-A77B-00B0D0160070} -> Java(TM) 6 Update 7 {4A03706F-666A-4037-7777-5F2748764D10} -> Java Auto Updater {54793AA1-5001-42F4-ABB6-C364617C6078} -> Adobe Linguistics CS3 {6179A7D2-A668-4F1D-BC9A-DCC6A10C7871} -> Adobe Color NA Extra Settings {64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1} -> Adobe Setup {6ABE0BEE-D572-4FE8-B434-9E72A289431B} -> Adobe Fonts All {6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2} -> Adobe Asset Services CS3 {6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF} -> Adobe Color Common Settings {716E0306-8318-4364-8B8F-0CC4E9376BAC} -> MSXML 4.0 SP2 Parser and SDK {770657D0-A123-3C07-8E44-1C83EC895118} -> Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 {789289CA-F73A-4A16-A331-54D498CE069F} -> Ventrilo {78EFD06D-7583-42F1-9E77-671D8782EB70} -> Adobe Photoshop CS3 {802771A9-A856-4A41-ACF7-1450E523C923} -> Adobe XMP Panels CS3 {85DAE0C8-B3BB-11D8-88E4-0004769F25D1} -> Spellforce {85EBB283-65AF-4C53-9EBE-7C0A232762F7} -> AGEIA PhysX v7.03.21 {888F1505-C2B3-4FDE-835D-36353EBD4754} -> Ubisoft Game Launcher {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} -> Microsoft Silverlight {8A74DEFD-A224-49CC-AB80-4E88BC730125} -> LogMeIn Hamachi {8B452EA5-844D-44BD-A25B-89C77DEC498A}_is1 -> EasyMetin2 ExpBot dla Metin2 PL {8D2BA474-F406-4710-9AE4-D4F22D21F0DD} -> Adobe Device Central CS3 {8E6808E2-613D-4FCD-81A2-6C8FA8E03312} -> Adobe Type Support {90176341-0A8B-4CCC-A78D-F862228A6B95} -> Adobe Anchor Service CS3 {94056AE8-EF0F-45E4-A1B4-D754115F8A28} -> Numedia CD-DVD writing as non-admin user {943B6738-4801-4982-90EC-0442EF7AEB16} -> Kaspersky Anti-Virus 2010 {97E038E1-41AD-4C93-BCDC-6A2394AEE352} -> Vegas Movie Studio Platinum 9.0 {9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9} -> Counter-Strike 1.6 {9C9824D9-9000-4373-A6A5-D0E5D4831394} -> Adobe Bridge CS3 {9FD6F1A8-5550-46AF-8509-271DF0E768B5} -> Dual-Core Optimizer {A2B242BD-FF8D-4840-9DAA-9170EABEC59C} -> Adobe CMaps {A2D81E70-2A98-4A08-A628-94388B063C5E} -> Adobe Color - Photoshop Specific {A589DA26-51BD-475D-8C32-E19E34145842} -> Camtasia Studio 6 {AC76BA86-7AD7-1045-7B44-A93000000001} -> Adobe Reader 9.3.3 - Polish {AC76BA86-7AD7-5464-3428-900000000004} -> Spelling Dictionaries Support For Adobe Reader 9 {B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C} -> Adobe Camera Raw 4.0 {B3C02EC1-A7B0-4987-9A43-8789426AAA7D} -> Adobe Setup {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 -> Spybot - Search & Destroy {B9B35331-B7E4-4E5C-BF4C-7BC87856124D} -> Adobe Default Language CS3 {BD087F50-46B2-43E4-BD73-5DB3DC20B47C} -> Adobe Color EU Recommended Settings {CBF4DADD-974D-49C8-BC83-C6F31554001E} -> Adobe Setup {D0DFF92A-492E-4C40-B862-A74A173C25C5} -> Adobe Version Cue CS3 Client {D103C4BA-F905-437A-8049-DB24763BBE36} -> Skype™ 4.2 {D2559B88-CC9D-4B48-81BB-F492BAA9C48C} -> Adobe PDF Library Files {D5CF78E4-02D5-413C-A68D-4604560D3CB5}_is1 -> Patch 3.5 dla Metin2 {D81A311F-D26B-4BDA-8A44-0B608DF49BEF} -> Podłączanie pulpitu zdalnego {D92B72E2-C854-4738-8ED6-4C3661CC17AE} -> Adobe Color JA Extra Settings {DF315348-721C-40B8-BAE2-58C6C7D935A2} -> Empire Earth II {E528951A-4CD9-471A-BD53-F6B7C27723D2}_is1 -> EasyMetin2 ExpBot dla Metin2 PL {E69AE897-9E0B-485C-8552-7841F48D42D8} -> Adobe Update Manager CS3 {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} -> Realtek High Definition Audio Driver {F4F4F84E-804F-4E9A-84D7-C34283F0088F} -> RealUpgrade 1.0 Adobe Flash Player ActiveX -> Adobe Flash Player 10 ActiveX Adobe Flash Player Plugin -> Adobe Flash Player 10 Plugin Adobe Shockwave Player -> Adobe Shockwave Player 11.5 Adobe_3e054d2218e7aa282c2369d939e58ff -> Adobe ExtendScript Toolkit 2 Adobe_678cd98c8365a5647f9a2e539d120a8 -> Adobe Photoshop CS3 Adobe_6c8e2cb4fd241c55406016127a6ab2e -> Adobe Color Common Settings Advanced SystemCare 3_is1 -> Advanced SystemCare 3 Alien Shooter_is1 -> Alien Shooter ALLPlayer V3.2_is1 -> ALLPlayer V3.X ALLPlayer V3.5.6.3_is1 -> ALLPlayer V3.X AMX Mod X Installer -> AMX Mod X Installer 1.8.1 Audacity_is1 -> Audacity 1.2.6 AutoHotkey -> AutoHotkey 1.0.48.05 CCleaner -> CCleaner Cheat Engine 5.3_is1 -> Cheat Engine 5.3 Cheat Engine 5.6.1_is1 -> Cheat Engine 5.6.1 CWK -> CWK (Czasowy Wyłącznik Komputera) dBpoweramp Music Converter -> dBpoweramp Music Converter ezHTML_doklejki_is1 -> Edytor Znaczników HTML 2.0PR1 Alef FlashGet -> FlashGet 1.9.6.1073 Fraps -> Fraps (remove only) Freez FLV to AVI/MPEG/WMV Converter v1.6_is1 -> Freez FLV to AVI/MPEG/WMV Converter Gadu-Gadu -> Gadu-Gadu 7.7 Gadu-Gadu 10 -> Gadu-Gadu 10 Game Booster_is1 -> Game Booster GoldWave v5.11 -> GoldWave v5.11 HD Tune_is1 -> HD Tune 2.55 InstallWIX_{943B6738-4801-4982-90EC-0442EF7AEB16} -> Kaspersky Anti-Virus 2010 ipla -> ipla 2.1.2 KLiteCodecPack_is1 -> K-Lite Codec Pack 3.9.0 Full LHTTSENG -> L&H TTS3000 British English LogMeIn Hamachi -> LogMeIn Hamachi Metin2_is1 -> Metin2 Mozilla Firefox (3.6.8) -> Mozilla Firefox (3.6.8) MSTTS -> Microsoft Text-to-Speech Engine 4.0 (English) NSS -> Norton Security Scan Odkurzacz 11.2 Pro_is1 -> Odkurzacz 11.2 Pro Odkurzacz 12.4_is1 -> Odkurzacz 12.4 OpenAL -> OpenAL Panda Cloud Antivirus -> Panda Cloud Antivirus Pogoda_is1 -> Pogoda 1.61 PSPad editor_is1 -> PSPad editor RealAlt_is1 -> Real Alternative 2.0.1 RealPlayer 12.0 -> RealPlayer Smart Defrag_is1 -> Smart Defrag SpeedFan -> SpeedFan (remove only) Steam App 10 -> Counter-Strike SystemRequirementsLab -> System Requirements Lab Tasker_is1 -> Tasker v4.110 Teamspeak 2 RC2_is1 -> TeamSpeak 2 RC2 vTask Studio_is1 -> vTask Studio v7.422 Winamp -> Winamp WinPcapInst -> WinPcap 4.0.2 WorldUnlock Codes Calculator -> WorldUnlock Codes Calculator Wubi -> Ubuntu Xvid_is1 -> Xvid 1.1.2 final uninstall < Uninstall List [HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\] > -> HKEY_USERS\S-1-5-21-2134886519-3978328712-2873364562-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> Mp3R -> Mp3 Recorder (remove only) < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2010-09-25 12:14:22 Computer Name = PRODOM | Source = ESENT | ID = 490 -> Description = Windows (2244) Windows: Próba otwarcia pliku "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk" w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8). Application [ Error ] 2010-09-25 12:14:22 Computer Name = PRODOM | Source = ESENT | ID = 439 -> Description = Windows (2244) Windows: Nie można dokonać zapisu lustrzanego nagłówka pliku C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk. Błąd -1032. Application [ Error ] 2010-09-25 12:14:35 Computer Name = PRODOM | Source = Windows Search Service | ID = 7040 -> Description = Application [ Error ] 2010-09-25 12:14:35 Computer Name = PRODOM | Source = Windows Search Service | ID = 7040 -> Description = Application [ Error ] 2010-09-25 12:14:46 Computer Name = PRODOM | Source = ESENT | ID = 490 -> Description = Windows (2244) Windows: Próba otwarcia pliku "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk" w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8). Application [ Error ] 2010-09-25 12:14:46 Computer Name = PRODOM | Source = ESENT | ID = 439 -> Description = Windows (2244) Windows: Nie można dokonać zapisu lustrzanego nagłówka pliku C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk. Błąd -1032. Application [ Error ] 2010-09-25 12:14:57 Computer Name = PRODOM | Source = ESENT | ID = 490 -> Description = Windows (2244) Windows: Próba otwarcia pliku "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk" w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8). Application [ Error ] 2010-09-25 12:14:57 Computer Name = PRODOM | Source = ESENT | ID = 439 -> Description = Windows (2244) Windows: Nie można dokonać zapisu lustrzanego nagłówka pliku C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk. Błąd -1032. Application [ Error ] 2010-09-26 06:39:33 Computer Name = PRODOM | Source = Microsoft-Windows-CAPI2 | ID = 131083 -> Description = Application [ Error ] 2010-09-26 06:39:33 Computer Name = PRODOM | Source = Microsoft-Windows-CAPI2 | ID = 131083 -> Description = System [ Error ] 2010-09-26 04:30:31 Computer Name = PRODOM | Source = HTTP | ID = 15016 -> Description = System [ Error ] 2010-09-26 04:31:10 Computer Name = PRODOM | Source = Service Control Manager | ID = 7000 -> Description = System [ Error ] 2010-09-26 04:31:10 Computer Name = PRODOM | Source = Service Control Manager | ID = 7000 -> Description = System [ Error ] 2010-09-26 04:32:20 Computer Name = PRODOM | Source = Service Control Manager | ID = 7026 -> Description = System [ Error ] 2010-09-26 04:34:09 Computer Name = PRODOM | Source = DCOM | ID = 10005 -> Description = System [ Error ] 2010-09-26 04:34:09 Computer Name = PRODOM | Source = Service Control Manager | ID = 7009 -> Description = System [ Error ] 2010-09-26 04:34:09 Computer Name = PRODOM | Source = Service Control Manager | ID = 7000 -> Description = System [ Error ] 2010-09-26 04:35:05 Computer Name = PRODOM | Source = Service Control Manager | ID = 7009 -> Description = System [ Error ] 2010-09-26 04:35:35 Computer Name = PRODOM | Source = Service Control Manager | ID = 7009 -> Description = System [ Error ] 2010-09-26 04:35:35 Computer Name = PRODOM | Source = Service Control Manager | ID = 7024 -> Description = [Files/Folders - Created Within 30 Days] OTS.exe -> C:\Users\Maciej\Desktop\OTS.exe -> [2010-09-26 13:24:22 | 000,641,536 | ---- | C] (OldTimer Tools) ManToWoman by XTheX -> C:\Users\Maciej\Desktop\ManToWoman by XTheX -> [2010-09-25 18:01:51 | 000,000,000 | ---D | C] EM2PL -> C:\Users\Maciej\Desktop\EM2PL -> [2010-09-25 17:25:57 | 000,000,000 | ---D | C] Metin2 - Kopia -> C:\Users\Maciej\Desktop\Metin2 - Kopia -> [2010-09-25 17:14:57 | 000,000,000 | ---D | C] Metin2 -> C:\Users\Maciej\Desktop\Metin2 -> [2010-09-25 16:45:58 | 000,000,000 | ---D | C] nvoglv32.dll -> C:\Windows\SysWow64\nvoglv32.dll -> [2010-09-19 15:30:09 | 014,899,816 | ---- | C] (NVIDIA Corporation) nvcuvid.dll -> C:\Windows\SysWow64\nvcuvid.dll -> [2010-09-19 15:30:09 | 002,912,360 | ---- | C] (NVIDIA Corporation) OpenCL.dll -> C:\Windows\SysWow64\OpenCL.dll -> [2010-09-19 15:30:09 | 000,057,960 | ---- | C] (Khronos Group) nvcompiler.dll -> C:\Windows\SysWow64\nvcompiler.dll -> [2010-09-19 15:30:08 | 013,019,752 | ---- | C] (NVIDIA Corporation) nvcuda.dll -> C:\Windows\SysWow64\nvcuda.dll -> [2010-09-19 15:30:08 | 004,836,456 | ---- | C] (NVIDIA Corporation) nvcuvenc.dll -> C:\Windows\SysWow64\nvcuvenc.dll -> [2010-09-19 15:30:08 | 002,666,600 | ---- | C] (NVIDIA Corporation) VSW0 -> C:\Users\Maciej\AppData\Local\VSW0 -> [2010-09-13 21:02:58 | 000,000,000 | ---D | C] models -> C:\Users\Maciej\Desktop\models -> [2010-09-13 16:24:04 | 000,000,000 | ---D | C] Counter-Strike -> C:\Users\Maciej\Desktop\Counter-Strike -> [2010-09-12 14:07:57 | 000,000,000 | ---D | C] Ventrilo -> C:\Program Files (x86)\Ventrilo -> [2010-09-10 20:19:44 | 000,000,000 | ---D | C] NSSx64 -> C:\Windows\SysNative\drivers\NSSx64 -> [2010-09-10 18:53:27 | 000,000,000 | ---D | C] Norton Security Scan -> C:\Program Files (x86)\Norton Security Scan -> [2010-09-10 18:53:27 | 000,000,000 | ---D | C] Norton -> C:\ProgramData\Norton -> [2010-09-10 18:53:27 | 000,000,000 | ---D | C] 0207030.022 -> C:\Windows\SysNative\drivers\NSSx64\0207030.022 -> [2010-09-10 18:53:27 | 000,000,000 | ---D | C] NortonInstaller -> C:\ProgramData\NortonInstaller -> [2010-09-10 18:53:24 | 000,000,000 | ---D | C] NortonInstaller -> C:\Program Files (x86)\NortonInstaller -> [2010-09-10 18:53:24 | 000,000,000 | ---D | C] Puzzle Quest -> C:\Users\Maciej\Documents\Puzzle Quest -> [2010-09-04 18:33:26 | 000,000,000 | ---D | C] AMX Mod X -> C:\Program Files (x86)\AMX Mod X -> [2010-09-02 17:54:12 | 000,000,000 | ---D | C] pokerth -> C:\Users\Maciej\AppData\Roaming\pokerth -> [2010-09-01 21:56:01 | 000,000,000 | ---D | C] xing shared -> C:\Program Files (x86)\Common Files\xing shared -> [2010-08-28 02:28:52 | 000,000,000 | ---D | C] Real -> C:\Program Files (x86)\Common Files\Real -> [2010-08-28 02:28:15 | 000,000,000 | ---D | C] Real -> C:\Program Files (x86)\Real -> [2010-08-28 02:28:14 | 000,000,000 | ---D | C] Real -> C:\ProgramData\Real -> [2010-08-28 02:28:13 | 000,000,000 | ---D | C] Real -> C:\Users\Maciej\AppData\Roaming\Real -> [2010-08-28 02:28:08 | 000,000,000 | ---D | C] SpellForce -> C:\Users\Maciej\Documents\SpellForce -> [2010-08-27 16:58:15 | 000,000,000 | ---D | C] Spellforce -> C:\Program Files (x86)\Spellforce -> [2010-08-27 16:35:47 | 000,000,000 | ---D | C] 2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> 2 C:\Users\Maciej\AppData\Local\*.tmp files -> C:\Users\Maciej\AppData\Local\*.tmp -> [Files/Folders - Modified Within 30 Days] User_Feed_Synchronization-{6FF84F90-F920-473A-95DB-326239736A7C}.job -> C:\Windows\tasks\User_Feed_Synchronization-{6FF84F90-F920-473A-95DB-326239736A7C}.job -> [2010-09-26 14:00:00 | 000,000,432 | -H-- | M] () User_Feed_Synchronization-{11560955-498D-41DD-895A-E9AFC0B2D703}.job -> C:\Windows\tasks\User_Feed_Synchronization-{11560955-498D-41DD-895A-E9AFC0B2D703}.job -> [2010-09-26 14:00:00 | 000,000,422 | -H-- | M] () ntuser.dat -> C:\Users\Maciej\ntuser.dat -> [2010-09-26 13:59:47 | 010,223,616 | -HS- | M] () User_Feed_Synchronization-{F72F8CD5-9ABE-44CE-B9BD-5B90E2A51BB3}.job -> C:\Windows\tasks\User_Feed_Synchronization-{F72F8CD5-9ABE-44CE-B9BD-5B90E2A51BB3}.job -> [2010-09-26 13:59:00 | 000,000,480 | -H-- | M] () User_Feed_Synchronization-{616D024A-B47C-4BE3-8C0B-3824B79BAB95}.job -> C:\Windows\tasks\User_Feed_Synchronization-{616D024A-B47C-4BE3-8C0B-3824B79BAB95}.job -> [2010-09-26 13:59:00 | 000,000,434 | -H-- | M] () Windows6.0-KB948465-X64.exe.part -> C:\Users\Maciej\Desktop\Windows6.0-KB948465-X64.exe.part -> [2010-09-26 13:47:42 | 352,561,348 | ---- | M] () Windows6.0-KB948465-X64.exe -> C:\Users\Maciej\Desktop\Windows6.0-KB948465-X64.exe -> [2010-09-26 13:47:42 | 000,000,000 | ---- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010-09-26 13:30:49 | 000,005,264 | -H-- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010-09-26 13:30:49 | 000,005,264 | -H-- | M] () SecurityCheck.exe -> C:\Users\Maciej\Desktop\SecurityCheck.exe -> [2010-09-26 13:28:40 | 000,869,051 | ---- | M] () OTS.exe -> C:\Users\Maciej\Desktop\OTS.exe -> [2010-09-26 13:24:24 | 000,641,536 | ---- | M] (OldTimer Tools) AWC Startup.job -> C:\Windows\tasks\AWC Startup.job -> [2010-09-26 10:37:51 | 000,000,396 | ---- | M] () Ikeext.etl -> C:\Windows\SysNative\Ikeext.etl -> [2010-09-26 10:34:04 | 000,196,608 | ---- | M] () User_Feed_Synchronization-{06198E6D-F743-4611-AB99-F908EE02762C}.job -> C:\Windows\tasks\User_Feed_Synchronization-{06198E6D-F743-4611-AB99-F908EE02762C}.job -> [2010-09-26 10:33:17 | 000,000,434 | -H-- | M] () SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010-09-26 10:30:31 | 000,000,006 | -H-- | M] () bootstat.dat -> C:\Windows\bootstat.dat -> [2010-09-26 10:30:12 | 000,067,584 | --S- | M] () ntuser.dat{93c7fc36-1d95-11df-8d63-000fea624528}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Maciej\ntuser.dat{93c7fc36-1d95-11df-8d63-000fea624528}.TMContainer00000000000000000001.regtrans-ms -> [2010-09-26 00:09:54 | 000,524,288 | -HS- | M] () ntuser.dat{93c7fc36-1d95-11df-8d63-000fea624528}.TM.blf -> C:\Users\Maciej\ntuser.dat{93c7fc36-1d95-11df-8d63-000fea624528}.TM.blf -> [2010-09-26 00:09:54 | 000,065,536 | -HS- | M] () IconCache.db -> C:\Users\Maciej\AppData\Local\IconCache.db -> [2010-09-26 00:09:47 | 002,960,724 | -H-- | M] () Norton Security Scan for Maciej.job -> C:\Windows\tasks\Norton Security Scan for Maciej.job -> [2010-09-25 18:10:25 | 000,000,500 | -H-- | M] () GoogleUpdateTaskUserS-1-5-21-2134886519-3978328712-2873364562-1000.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2134886519-3978328712-2873364562-1000.job -> [2010-09-24 14:50:22 | 000,001,134 | ---- | M] () Dowiązanie do Desktop -> C:\Users\Maciej\Dowiązanie do Desktop -> [2010-09-21 17:46:55 | 000,000,096 | --S- | M] () wubildr -> C:\wubildr -> [2010-09-21 16:00:38 | 000,088,242 | ---- | M] () wubildr.mbr -> C:\wubildr.mbr -> [2010-09-21 16:00:38 | 000,008,192 | ---- | M] () nvModes.dat -> C:\ProgramData\nvModes.dat -> [2010-09-19 13:22:16 | 000,037,013 | ---- | M] () nvModes.001 -> C:\ProgramData\nvModes.001 -> [2010-09-19 13:22:14 | 000,037,013 | ---- | M] () nvoglv64.dll -> C:\Windows\SysNative\nvoglv64.dll -> [2010-09-11 08:46:00 | 020,280,936 | ---- | M] () nvcompiler.dll -> C:\Windows\SysNative\nvcompiler.dll -> [2010-09-11 08:46:00 | 018,597,480 | ---- | M] () nvoglv32.dll -> C:\Windows\SysWow64\nvoglv32.dll -> [2010-09-11 08:46:00 | 014,899,816 | ---- | M] (NVIDIA Corporation) nvcompiler.dll -> C:\Windows\SysWow64\nvcompiler.dll -> [2010-09-11 08:46:00 | 013,019,752 | ---- | M] (NVIDIA Corporation) nvd3dumx.dll -> C:\Windows\SysNative\nvd3dumx.dll -> [2010-09-11 08:46:00 | 012,787,304 | ---- | M] () nvd3dum.dll -> C:\Windows\SysWow64\nvd3dum.dll -> [2010-09-11 08:46:00 | 010,022,504 | ---- | M] (NVIDIA Corporation) nvcuda.dll -> C:\Windows\SysNative\nvcuda.dll -> [2010-09-11 08:46:00 | 006,470,760 | ---- | M] () nvcuda.dll -> C:\Windows\SysWow64\nvcuda.dll -> [2010-09-11 08:46:00 | 004,836,456 | ---- | M] (NVIDIA Corporation) nvcuvid.dll -> C:\Windows\SysNative\nvcuvid.dll -> [2010-09-11 08:46:00 | 003,112,552 | ---- | M] () nvcuvenc.dll -> C:\Windows\SysNative\nvcuvenc.dll -> [2010-09-11 08:46:00 | 002,934,888 | ---- | M] () nvcuvid.dll -> C:\Windows\SysWow64\nvcuvid.dll -> [2010-09-11 08:46:00 | 002,912,360 | ---- | M] (NVIDIA Corporation) nvcuvenc.dll -> C:\Windows\SysWow64\nvcuvenc.dll -> [2010-09-11 08:46:00 | 002,666,600 | ---- | M] (NVIDIA Corporation) nvapi64.dll -> C:\Windows\SysNative\nvapi64.dll -> [2010-09-11 08:46:00 | 002,159,720 | ---- | M] () nvapi.dll -> C:\Windows\SysWow64\nvapi.dll -> [2010-09-11 08:46:00 | 001,718,376 | ---- | M] (NVIDIA Corporation) nvdispco642050.dll -> C:\Windows\SysNative\nvdispco642050.dll -> [2010-09-11 08:46:00 | 001,499,240 | ---- | M] () nvgenco642030.dll -> C:\Windows\SysNative\nvgenco642030.dll -> [2010-09-11 08:46:00 | 001,308,776 | ---- | M] () OpenCL.dll -> C:\Windows\SysNative\OpenCL.dll -> [2010-09-11 08:46:00 | 000,067,176 | ---- | M] () OpenCL.dll -> C:\Windows\SysWow64\OpenCL.dll -> [2010-09-11 08:46:00 | 000,057,960 | ---- | M] (Khronos Group) nvBridge.kmd -> C:\Windows\SysNative\drivers\nvBridge.kmd -> [2010-09-11 08:46:00 | 000,011,240 | ---- | M] () nvinfo.pb -> C:\Windows\SysNative\nvinfo.pb -> [2010-09-11 08:46:00 | 000,007,877 | ---- | M] () nvcpl.dll -> C:\Windows\SysNative\nvcpl.dll -> [2010-09-11 00:55:12 | 005,792,360 | ---- | M] () nvsvc64.dll -> C:\Windows\SysNative\nvsvc64.dll -> [2010-09-11 00:55:00 | 002,570,344 | ---- | M] () nvsvcr.dll -> C:\Windows\SysNative\nvsvcr.dll -> [2010-09-11 00:55:00 | 001,881,704 | ---- | M] () nvmctray.dll -> C:\Windows\SysNative\nvmctray.dll -> [2010-09-11 00:55:00 | 000,116,328 | ---- | M] () isolate.ini -> C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini -> [2010-09-10 18:53:27 | 000,000,172 | ---- | M] () PerfStringBackup.INI -> C:\Windows\SysWow64\PerfStringBackup.INI -> [2010-09-03 20:57:45 | 001,587,842 | ---- | M] () perfh015.dat -> C:\Windows\SysNative\perfh015.dat -> [2010-09-03 20:57:45 | 000,712,594 | ---- | M] () perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2010-09-03 20:57:45 | 000,632,594 | ---- | M] () perfc015.dat -> C:\Windows\SysNative\perfc015.dat -> [2010-09-03 20:57:45 | 000,150,530 | ---- | M] () perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2010-09-03 20:57:45 | 000,119,116 | ---- | M] () PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2010-09-03 20:57:17 | 001,587,842 | ---- | M] () RootExtract.xml -> C:\Users\Maciej\RootExtract.xml -> [2010-09-03 18:13:22 | 000,000,591 | ---- | M] () FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2010-08-31 11:48:41 | 002,182,864 | ---- | M] () GDIPFONTCACHEV1.DAT -> C:\Users\Maciej\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010-08-30 22:47:44 | 000,056,256 | ---- | M] () rmoc3260.dll -> C:\Windows\SysWow64\rmoc3260.dll -> [2010-08-28 02:29:17 | 000,185,920 | ---- | M] (RealNetworks, Inc.) pndx5016.dll -> C:\Windows\SysWow64\pndx5016.dll -> [2010-08-28 02:29:07 | 000,006,656 | ---- | M] (RealNetworks, Inc.) pndx5032.dll -> C:\Windows\SysWow64\pndx5032.dll -> [2010-08-28 02:29:07 | 000,005,632 | ---- | M] (RealNetworks, Inc.) pncrt.dll -> C:\Windows\SysWow64\pncrt.dll -> [2010-08-28 02:28:20 | 000,278,528 | ---- | M] (Real Networks, Inc) 2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> 2 C:\Users\Maciej\AppData\Local\*.tmp files -> C:\Users\Maciej\AppData\Local\*.tmp -> [Files - No Company Name] Windows6.0-KB948465-X64.exe -> C:\Users\Maciej\Desktop\Windows6.0-KB948465-X64.exe -> [2010-09-26 13:47:42 | 000,000,000 | ---- | C] () Windows6.0-KB948465-X64.exe.part -> C:\Users\Maciej\Desktop\Windows6.0-KB948465-X64.exe.part -> [2010-09-26 13:47:39 | 141,043,908 | ---- | C] () SecurityCheck.exe -> C:\Users\Maciej\Desktop\SecurityCheck.exe -> [2010-09-26 13:28:39 | 000,869,051 | ---- | C] () FASTWiz.log -> C:\Users\Maciej\AppData\Local\FASTWiz.log -> [2010-09-22 18:55:11 | 000,036,811 | ---- | C] () Dowiązanie do Desktop -> C:\Users\Maciej\Dowiązanie do Desktop -> [2010-09-21 17:46:55 | 000,000,096 | --S- | C] () wubildr -> C:\wubildr -> [2010-09-21 16:00:38 | 000,088,242 | ---- | C] () wubildr.mbr -> C:\wubildr.mbr -> [2010-09-21 16:00:38 | 000,008,192 | ---- | C] () nvoglv64.dll -> C:\Windows\SysNative\nvoglv64.dll -> [2010-09-19 15:30:09 | 020,280,936 | ---- | C] () nvd3dumx.dll -> C:\Windows\SysNative\nvd3dumx.dll -> [2010-09-19 15:30:09 | 012,787,304 | ---- | C] () nvcuvid.dll -> C:\Windows\SysNative\nvcuvid.dll -> [2010-09-19 15:30:09 | 003,112,552 | ---- | C] () nvdispco642050.dll -> C:\Windows\SysNative\nvdispco642050.dll -> [2010-09-19 15:30:09 | 001,499,240 | ---- | C] () nvgenco642030.dll -> C:\Windows\SysNative\nvgenco642030.dll -> [2010-09-19 15:30:09 | 001,308,776 | ---- | C] () OpenCL.dll -> C:\Windows\SysNative\OpenCL.dll -> [2010-09-19 15:30:09 | 000,067,176 | ---- | C] () nvcompiler.dll -> C:\Windows\SysNative\nvcompiler.dll -> [2010-09-19 15:30:08 | 018,597,480 | ---- | C] () nvcuda.dll -> C:\Windows\SysNative\nvcuda.dll -> [2010-09-19 15:30:08 | 006,470,760 | ---- | C] () nvcuvenc.dll -> C:\Windows\SysNative\nvcuvenc.dll -> [2010-09-19 15:30:08 | 002,934,888 | ---- | C] () nvBridge.kmd -> C:\Windows\SysNative\drivers\nvBridge.kmd -> [2010-09-19 15:30:08 | 000,011,240 | ---- | C] () dd_NET_Framework35_x64_MSI5194.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI5194.txt -> [2010-09-13 21:02:40 | 001,054,352 | ---- | C] () dd_NET_Framework35_x64_MSI5092.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI5092.txt -> [2010-09-13 21:01:21 | 001,047,008 | ---- | C] () nvcpl.dll -> C:\Windows\SysNative\nvcpl.dll -> [2010-09-11 00:55:12 | 005,792,360 | ---- | C] () nvsvc64.dll -> C:\Windows\SysNative\nvsvc64.dll -> [2010-09-11 00:55:00 | 002,570,344 | ---- | C] () nvsvcr.dll -> C:\Windows\SysNative\nvsvcr.dll -> [2010-09-11 00:55:00 | 001,881,704 | ---- | C] () nvmctray.dll -> C:\Windows\SysNative\nvmctray.dll -> [2010-09-11 00:55:00 | 000,116,328 | ---- | C] () Norton Security Scan for Maciej.job -> C:\Windows\tasks\Norton Security Scan for Maciej.job -> [2010-09-10 18:53:35 | 000,000,500 | -H-- | C] () isolate.ini -> C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini -> [2010-09-10 18:53:27 | 000,000,172 | ---- | C] () dd_NET_Framework35_x64_MSI4824.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI4824.txt -> [2010-09-03 21:07:45 | 001,042,910 | ---- | C] () dd_NET_Framework35_x64_MSI472B.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI472B.txt -> [2010-09-03 21:06:29 | 001,038,642 | ---- | C] () dd_NET_Framework35_x64_MSI4620.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI4620.txt -> [2010-09-03 21:05:07 | 001,034,402 | ---- | C] () dd_NET_Framework35_x64_MSI451E.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI451E.txt -> [2010-09-03 21:03:48 | 001,030,216 | ---- | C] () IconCache.db -> C:\Users\Maciej\AppData\Local\IconCache.db -> [2010-08-28 03:31:20 | 002,960,724 | -H-- | C] () AsIO.dll -> C:\Windows\SysWow64\AsIO.dll -> [2010-08-15 15:12:30 | 000,024,576 | ---- | C] () AsIO.sys -> C:\Windows\SysWow64\drivers\AsIO.sys -> [2010-08-15 15:12:30 | 000,013,440 | ---- | C] () AsInsHelp64.sys -> C:\Windows\SysWow64\drivers\AsInsHelp64.sys -> [2010-08-15 15:12:18 | 000,011,832 | ---- | C] () AsInsHelp32.sys -> C:\Windows\SysWow64\drivers\AsInsHelp32.sys -> [2010-08-15 15:12:18 | 000,010,216 | ---- | C] () desktop.ini -> C:\Program Files (x86)\desktop.ini -> [2010-08-11 13:48:33 | 000,000,174 | -HS- | C] () ezsidmv.dat -> C:\ProgramData\ezsidmv.dat -> [2010-08-06 23:52:45 | 000,000,056 | -H-- | C] () nvModes.001 -> C:\ProgramData\nvModes.001 -> [2010-08-06 09:45:18 | 000,037,013 | ---- | C] () nvModes.dat -> C:\ProgramData\nvModes.dat -> [2010-08-06 09:44:59 | 000,037,013 | ---- | C] () uxeventlog.txt -> C:\Users\Maciej\AppData\Local\uxeventlog.txt -> [2010-07-20 14:14:53 | 000,031,594 | ---- | C] () dd_NET_Framework35_x64_MSI2D5B.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI2D5B.txt -> [2010-07-19 23:33:13 | 001,025,798 | ---- | C] () dd_NET_Framework35_x64_MSI2C2C.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI2C2C.txt -> [2010-07-19 23:31:40 | 001,021,530 | ---- | C] () dd_NET_Framework35_x64_MSI2AF2.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI2AF2.txt -> [2010-07-19 23:30:04 | 001,017,288 | ---- | C] () dd_NET_Framework35_x64_MSI29B9.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI29B9.txt -> [2010-07-19 23:28:29 | 001,015,802 | ---- | C] () dd_NET_Framework35_x64_MSI4F84.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI4F84.txt -> [2010-07-17 19:20:18 | 002,409,948 | ---- | C] () setup.log -> C:\Users\Maciej\AppData\Local\setup.log -> [2010-07-17 19:19:57 | 000,008,798 | ---- | C] () dd_NET_Framework35_LangPack_MSI4EC0.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_LangPack_MSI4EC0.txt -> [2010-07-17 19:19:18 | 000,681,546 | ---- | C] () dd_vcredistMSI4EFF.txt -> C:\Users\Maciej\AppData\Local\dd_vcredistMSI4EFF.txt -> [2010-07-16 18:14:28 | 000,561,082 | ---- | C] () dd_vcredistUI4EFF.txt -> C:\Users\Maciej\AppData\Local\dd_vcredistUI4EFF.txt -> [2010-07-16 18:14:28 | 000,014,658 | ---- | C] () dd_vcredistMSI20C6.txt -> C:\Users\Maciej\AppData\Local\dd_vcredistMSI20C6.txt -> [2010-07-02 18:45:22 | 000,560,548 | ---- | C] () dd_vcredistUI20C6.txt -> C:\Users\Maciej\AppData\Local\dd_vcredistUI20C6.txt -> [2010-07-02 18:45:21 | 000,013,462 | ---- | C] () NCMedia2.dll -> C:\Windows\SysWow64\NCMedia2.dll -> [2010-05-29 19:25:47 | 008,676,883 | ---- | C] () dd_NET_Framework35_LangPack_MSI2074.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_LangPack_MSI2074.txt -> [2009-12-06 18:39:16 | 000,772,962 | ---- | C] () dd_NET_Framework35_x64_MSI200C.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_x64_MSI200C.txt -> [2009-12-06 18:38:44 | 001,868,456 | ---- | C] () dd_depcheckdotnetfx30.txt -> C:\Users\Maciej\AppData\Local\dd_depcheckdotnetfx30.txt -> [2009-12-06 18:23:32 | 000,166,569 | ---- | C] () dd_dotnetfx3install.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx3install.txt -> [2009-12-06 18:23:22 | 000,159,412 | ---- | C] () dd_dotnetfx3error.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx3error.txt -> [2009-12-06 18:23:22 | 000,001,876 | ---- | C] () dd_dotnetfx35install.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx35install.txt -> [2009-12-06 11:37:07 | 002,029,196 | ---- | C] () dd_dotnetfx35error.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx35error.txt -> [2009-12-06 11:37:07 | 000,001,580 | ---- | C] () Relax.ini -> C:\Windows\Relax.ini -> [2009-07-28 00:23:01 | 000,000,052 | ---- | C] () 2pic.ini -> C:\Windows\2pic.ini -> [2009-07-28 00:12:07 | 000,000,043 | ---- | C] () fusioncache.dat -> C:\Users\Maciej\AppData\Local\fusioncache.dat -> [2009-07-13 11:52:18 | 000,000,094 | ---- | C] () PerfStringBackup.INI -> C:\Windows\SysWow64\PerfStringBackup.INI -> [2009-07-13 11:51:28 | 001,587,842 | ---- | C] () BASSMOD.dll -> C:\Windows\SysWow64\BASSMOD.dll -> [2009-06-23 14:16:52 | 000,013,312 | ---- | C] () d3d8caps.dat -> C:\Users\Maciej\AppData\Local\d3d8caps.dat -> [2009-06-11 11:32:35 | 000,001,100 | ---- | C] () libeay32.dll -> C:\Windows\SysWow64\libeay32.dll -> [2009-05-29 20:42:16 | 000,688,128 | ---- | C] () ssleay32.dll -> C:\Windows\SysWow64\ssleay32.dll -> [2009-05-29 20:42:16 | 000,155,648 | ---- | C] () dd_NET_Framework35_LangPack_MSI54E7.txt -> C:\Users\Maciej\AppData\Local\dd_NET_Framework35_LangPack_MSI54E7.txt -> [2009-05-09 10:52:11 | 000,794,414 | ---- | C] () dd_depcheck_NETFX_EXP_35.txt -> C:\Users\Maciej\AppData\Local\dd_depcheck_NETFX_EXP_35.txt -> [2009-05-09 10:52:09 | 001,647,873 | ---- | C] () dd_dotnetfx35install_lp.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx35install_lp.txt -> [2009-05-09 10:52:07 | 000,244,238 | ---- | C] () dd_dotnetfx35error_lp.txt -> C:\Users\Maciej\AppData\Local\dd_dotnetfx35error_lp.txt -> [2009-05-09 10:52:07 | 000,000,002 | ---- | C] () d3d9caps.dat -> C:\Users\Maciej\AppData\Local\d3d9caps.dat -> [2009-03-28 13:15:31 | 000,000,680 | ---- | C] () DownloadStudio.INI -> C:\Windows\DownloadStudio.INI -> [2008-08-08 21:53:41 | 000,000,023 | ---- | C] () d3dx9.dll -> C:\Windows\SysWow64\d3dx9.dll -> [2008-07-07 22:52:51 | 001,970,176 | ---- | C] () d3d9caps64.dat -> C:\Users\Maciej\AppData\Local\d3d9caps64.dat -> [2008-05-21 16:36:29 | 000,000,732 | ---- | C] () msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2008-05-19 23:15:06 | 000,368,640 | ---- | C] () tcpmon.ini -> C:\Windows\SysWow64\tcpmon.ini -> [2008-05-19 23:14:45 | 000,060,124 | ---- | C] () pthread.dll -> C:\Windows\SysWow64\pthread.dll -> [2008-05-10 15:25:41 | 000,029,696 | ---- | C] () UserTile.png -> C:\Users\Maciej\AppData\Roaming\UserTile.png -> [2008-05-09 18:18:31 | 000,031,079 | ---- | C] () unrar.dll -> C:\Windows\SysWow64\unrar.dll -> [2008-05-09 16:51:34 | 000,164,352 | ---- | C] () x264vfw.dll -> C:\Windows\SysWow64\x264vfw.dll -> [2008-05-09 16:51:32 | 002,102,272 | ---- | C] () qt-dx331.dll -> C:\Windows\SysWow64\qt-dx331.dll -> [2008-05-09 16:51:31 | 003,596,288 | ---- | C] () ff_vfw.dll -> C:\Windows\SysWow64\ff_vfw.dll -> [2008-05-09 16:51:31 | 000,007,680 | ---- | C] () ff_vfw.dll.manifest -> C:\Windows\SysWow64\ff_vfw.dll.manifest -> [2008-05-09 16:51:31 | 000,000,547 | ---- | C] () xvidcore.dll -> C:\Windows\SysWow64\xvidcore.dll -> [2008-04-22 21:25:13 | 000,755,027 | ---- | C] () xvidvfw.dll -> C:\Windows\SysWow64\xvidvfw.dll -> [2008-04-22 21:25:12 | 000,159,839 | ---- | C] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\Maciej\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008-04-22 15:24:25 | 000,052,736 | ---- | C] () GDIPFONTCACHEV1.DAT -> C:\Users\Maciej\AppData\Local\GDIPFONTCACHEV1.DAT -> [2008-04-20 12:04:27 | 000,056,256 | ---- | C] () pthreadVC.dll -> C:\Windows\SysWow64\pthreadVC.dll -> [2007-11-06 22:19:28 | 000,053,299 | ---- | C] () PhysXLoader.dll -> C:\Windows\SysWow64\PhysXLoader.dll -> [2007-03-26 10:45:18 | 000,071,208 | ---- | C] () AgCPanelJapanese.dll -> C:\Windows\SysWow64\AgCPanelJapanese.dll -> [2007-02-20 14:59:08 | 000,053,248 | ---- | C] () AgCPanelTraditionalChinese.dll -> C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelSwedish.dll -> C:\Windows\SysWow64\AgCPanelSwedish.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelSimplifiedChinese.dll -> C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelPortugese.dll -> C:\Windows\SysWow64\AgCPanelPortugese.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelKorean.dll -> C:\Windows\SysWow64\AgCPanelKorean.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelGerman.dll -> C:\Windows\SysWow64\AgCPanelGerman.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelFrench.dll -> C:\Windows\SysWow64\AgCPanelFrench.dll -> [2007-02-20 14:59:06 | 000,053,248 | ---- | C] () AgCPanelSpanish.dll -> C:\Windows\SysWow64\AgCPanelSpanish.dll -> [2007-02-20 14:59:04 | 000,053,248 | ---- | C] () NMSAccessU.exe -> C:\Program Files (x86)\Common Files\NMSAccessU.exe -> [2007-01-25 03:52:26 | 000,065,536 | ---- | C] () desktop.ini -> C:\Program Files\desktop.ini -> [2006-11-02 17:25:49 | 000,000,174 | -HS- | C] () GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2006-11-02 17:07:25 | 000,030,808 | ---- | C] () GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2006-11-02 17:07:25 | 000,029,779 | ---- | C] () GlobalSansSerif.CompositeFont -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont -> [2006-11-02 17:07:25 | 000,026,489 | ---- | C] () GlobalMonospace.CompositeFont -> C:\Windows\Fonts\GlobalMonospace.CompositeFont -> [2006-11-02 17:07:25 | 000,026,040 | ---- | C] () JPeg32.dll -> C:\Windows\SysWow64\JPeg32.dll -> [2004-06-09 22:38:01 | 000,184,320 | ---- | C] () [File - Lop Check] AgerWebEdytor -> C:\Users\Maciej\AppData\Roaming\AgerWebEdytor -> [2009-11-17 16:20:36 | 000,000,000 | ---D | M] AutoText -> C:\Users\Maciej\AppData\Roaming\AutoText -> [2010-05-04 21:42:47 | 000,000,000 | ---D | M] Conceiva -> C:\Users\Maciej\AppData\Roaming\Conceiva -> [2008-07-21 10:08:18 | 000,000,000 | ---D | M] DAEMON Tools -> C:\Users\Maciej\AppData\Roaming\DAEMON Tools -> [2009-04-18 10:31:37 | 000,000,000 | ---D | M] DAEMON Tools Lite -> C:\Users\Maciej\AppData\Roaming\DAEMON Tools Lite -> [2009-04-18 10:31:37 | 000,000,000 | ---D | M] DAEMON Tools Pro -> C:\Users\Maciej\AppData\Roaming\DAEMON Tools Pro -> [2009-06-08 15:06:02 | 000,000,000 | ---D | M] dBpoweramp -> C:\Users\Maciej\AppData\Roaming\dBpoweramp -> [2010-06-27 18:10:39 | 000,000,000 | ---D | M] FlashGet -> C:\Users\Maciej\AppData\Roaming\FlashGet -> [2008-04-20 12:04:26 | 000,000,000 | ---D | M] Gadu-Gadu -> C:\Users\Maciej\AppData\Roaming\Gadu-Gadu -> [2008-04-29 19:41:19 | 000,000,000 | ---D | M] Gadu-Gadu 10 -> C:\Users\Maciej\AppData\Roaming\Gadu-Gadu 10 -> [2010-02-24 22:38:30 | 000,000,000 | ---D | M] GHISLER -> C:\Users\Maciej\AppData\Roaming\GHISLER -> [2009-10-22 15:36:43 | 000,000,000 | ---D | M] IObit -> C:\Users\Maciej\AppData\Roaming\IObit -> [2010-08-14 17:31:22 | 000,000,000 | ---D | M] ipla -> C:\Users\Maciej\AppData\Roaming\ipla -> [2010-06-28 11:26:14 | 000,000,000 | ---D | M] Macro Recorder -> C:\Users\Maciej\AppData\Roaming\Macro Recorder -> [2010-05-04 21:45:04 | 000,000,000 | ---D | M] NCsoft -> C:\Users\Maciej\AppData\Roaming\NCsoft -> [2010-02-21 00:23:03 | 000,000,000 | ---D | M] Nowe Gadu-Gadu -> C:\Users\Maciej\AppData\Roaming\Nowe Gadu-Gadu -> [2009-06-16 14:52:52 | 000,000,000 | ---D | M] OpenFM -> C:\Users\Maciej\AppData\Roaming\OpenFM -> [2009-06-20 09:57:42 | 000,000,000 | ---D | M] OpenOffice.org -> C:\Users\Maciej\AppData\Roaming\OpenOffice.org -> [2009-07-06 21:26:56 | 000,000,000 | ---D | M] Opera -> C:\Users\Maciej\AppData\Roaming\Opera -> [2009-11-28 00:03:33 | 000,000,000 | ---D | M] Oxin's Style! -> C:\Users\Maciej\AppData\Roaming\Oxin's Style! -> [2008-05-15 17:47:37 | 000,000,000 | ---D | M] Panda Security -> C:\Users\Maciej\AppData\Roaming\Panda Security -> [2010-05-07 14:02:59 | 000,000,000 | ---D | M] PeerNetworking -> C:\Users\Maciej\AppData\Roaming\PeerNetworking -> [2008-05-09 18:18:31 | 000,000,000 | ---D | M] pokerth -> C:\Users\Maciej\AppData\Roaming\pokerth -> [2010-09-01 21:56:01 | 000,000,000 | ---D | M] Publish Providers -> C:\Users\Maciej\AppData\Roaming\Publish Providers -> [2010-05-27 20:11:28 | 000,000,000 | ---D | M] Sierra -> C:\Users\Maciej\AppData\Roaming\Sierra -> [2010-08-10 16:37:48 | 000,000,000 | ---D | M] Sony -> C:\Users\Maciej\AppData\Roaming\Sony -> [2010-05-27 20:33:17 | 000,000,000 | ---D | M] Spyware Terminator -> C:\Users\Maciej\AppData\Roaming\Spyware Terminator -> [2008-06-03 13:47:15 | 000,000,000 | ---D | M] streamripper -> C:\Users\Maciej\AppData\Roaming\streamripper -> [2010-02-09 13:49:35 | 000,000,000 | ---D | M] TeamViewer -> C:\Users\Maciej\AppData\Roaming\TeamViewer -> [2010-08-11 13:24:44 | 000,000,000 | ---D | M] thriXXX -> C:\Users\Maciej\AppData\Roaming\thriXXX -> [2008-05-15 17:58:35 | 000,000,000 | ---D | M] Ubisoft -> C:\Users\Maciej\AppData\Roaming\Ubisoft -> [2010-06-19 16:07:01 | 000,000,000 | ---D | M] IObit -> C:\Users\Zbigniew.PRODOM\AppData\Roaming\IObit -> [2010-07-29 20:38:36 | 000,000,000 | ---D | M] Panda Security -> C:\Users\Zbigniew.PRODOM\AppData\Roaming\Panda Security -> [2010-05-06 14:47:40 | 000,000,000 | ---D | M] AWC Startup.job -> C:\Windows\Tasks\AWC Startup.job -> [2010-09-26 10:37:51 | 000,000,396 | ---- | M] () SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2010-09-26 00:10:00 | 000,032,578 | ---- | M] () User_Feed_Synchronization-{06198E6D-F743-4611-AB99-F908EE02762C}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{06198E6D-F743-4611-AB99-F908EE02762C}.job -> [2010-09-26 10:33:17 | 000,000,434 | -H-- | M] () User_Feed_Synchronization-{11560955-498D-41DD-895A-E9AFC0B2D703}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{11560955-498D-41DD-895A-E9AFC0B2D703}.job -> [2010-09-26 14:00:00 | 000,000,422 | -H-- | M] () User_Feed_Synchronization-{616D024A-B47C-4BE3-8C0B-3824B79BAB95}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{616D024A-B47C-4BE3-8C0B-3824B79BAB95}.job -> [2010-09-26 13:59:00 | 000,000,434 | -H-- | M] () User_Feed_Synchronization-{6FF84F90-F920-473A-95DB-326239736A7C}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{6FF84F90-F920-473A-95DB-326239736A7C}.job -> [2010-09-26 14:00:00 | 000,000,432 | -H-- | M] () User_Feed_Synchronization-{F72F8CD5-9ABE-44CE-B9BD-5B90E2A51BB3}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{F72F8CD5-9ABE-44CE-B9BD-5B90E2A51BB3}.job -> [2010-09-26 13:59:00 | 000,000,480 | -H-- | M] () [File - Purity Scan] < End of report > [/code]