Prosím o kontrolu logu, avast mi hlásí rootkity

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Anna
Level 1.5
Level 1.5
Příspěvky: 101
Registrován: březen 05
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Anna » 30 kvě 2010 17:58

OTL Extras logfile created on: 30.5.2010 17:48:17 - Run 1
OTL by OldTimer - Version 3.2.5.1 Folder = C:\Users\Jirka\Documents\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 65,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,04 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive D: | 139,28 Gb Total Space | 28,60 Gb Free Space | 20,53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIRKA-PC
Current User Name: Jirka
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\System32\shell32.dll (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)
.inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.pif [@ = piffile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- Reg Error: Value error.
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0253BBF6-64AD-4803-8A79-0A590CF17395}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{05B0586A-FA49-4B00-8236-78937880D22B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{05B3A702-ABA2-4BE4-940A-663513C9656C}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{0A49DC13-9D62-4998-BD4F-D189B5C1FA31}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{0B22F3DA-0293-4DA0-81B6-FF1F0BBA32E6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{12EF3E1D-256C-445B-B9BC-04FAAB61519D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3544042E-A7E0-46D4-A8DD-35EAF924CE9D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3658BBDD-973F-49E2-8E2F-AC4AC86B7D7B}" = rport=5357 | protocol=6 | dir=out | app=system |
"{3D083079-81DC-49F4-B65D-1CC3961549ED}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{41D96DF0-263D-41D2-81F4-5D45AD09DEFC}" = rport=139 | protocol=6 | dir=out | app=system |
"{431C8EFB-92E7-4EC2-8309-D294C83F7C80}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{48729F53-5997-4784-906B-A7C2DA784735}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4B314378-3A57-4CAF-B0CD-8805DBE913EC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{556775B5-44B6-4032-9720-7DE00F1DC75B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{5AC1DBDB-45B9-4639-9177-F44C26122A9F}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{6263BDB5-4F82-4A86-BC5D-D9FFF8EE7884}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{649D01F3-1740-47C9-A2B3-E70B93A70991}" = lport=139 | protocol=6 | dir=in | app=system |
"{66905200-966B-40FC-815F-3C6DCF0462B8}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{67AC8192-F1CF-415B-9C54-07F1FF852BBB}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{72DDCBD0-E63B-443C-A1BF-4BEA1F7DC3BE}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{75258537-B1F5-4AE7-AE6A-4DC58851AE50}" = lport=138 | protocol=17 | dir=in | app=system |
"{7D6F53E9-4F27-4E10-8ABB-558681808056}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7DBD2D90-8D2A-4E18-8C2F-D7B02DDE3D85}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{8C3B6A73-04A0-496F-ACC1-2D35A85B95E5}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{9192F5DC-34B5-4D76-83F9-FBD8977A3306}" = lport=445 | protocol=6 | dir=in | app=system |
"{9251733E-A4E1-465A-AC21-2A03B77ECFBB}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{9259E556-4E6E-4831-BE02-0B0E7ACF8591}" = rport=445 | protocol=6 | dir=out | app=system |
"{94E5DB45-47AC-46B5-B84E-27C80725F0DA}" = rport=5358 | protocol=6 | dir=out | app=system |
"{94E6880F-2423-42AD-A8F2-63C41848E88B}" = rport=137 | protocol=17 | dir=out | app=system |
"{999B0C0F-4C4E-418D-8D0E-938D63707A49}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A3740F16-F274-4698-ACD8-8A0F8B999385}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A7EAFFC6-2C97-4049-A64E-D79A5315CB72}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{C00C890C-2F6A-4E83-AED3-56FAAFBFD709}" = lport=5358 | protocol=6 | dir=in | app=system |
"{C15D2D34-C4D0-4266-A7C0-A6951D623581}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{C7663BD5-5B72-4618-B786-CBE2CE9B2D6A}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{CCB5191C-F9A0-4471-958E-14359B02B9ED}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{D0EB422E-2861-4B2B-B09D-B6302E578253}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{D1B316F4-0BA2-44AF-8F1D-E94A65D84549}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{D74036DB-45D9-4DFB-9BAC-77CF309F7B19}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E0218077-374C-4906-8418-0301C1026795}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E0754190-E77A-452B-A6F9-9BD6984DE6BD}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{E996DDB5-EB60-499D-BA85-E61666ECE7B1}" = lport=5357 | protocol=6 | dir=in | app=system |
"{ECFDE487-453B-497A-BACE-302C60BE33F5}" = rport=138 | protocol=17 | dir=out | app=system |
"{F22E4664-C8CC-4C6F-B772-9BF821073D1F}" = lport=137 | protocol=17 | dir=in | app=system |
"{F33C0175-C3A7-49C9-A844-EC094B6A34D2}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{F50E0B65-3229-4344-83CC-42E81BD57AA4}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{FA525AF6-A566-495A-8738-F4968BE90C32}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03B0B846-714E-4298-A791-C26FEF59E1B2}" = protocol=6 | dir=in | app=c:\program files\codemasters\grid demo\grid.exe |
"{109DAA23-54EC-4E90-9AAB-F5A3A92DF2CE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{11BDD925-674B-4C78-ADB4-E17A123F8A47}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{2134BE29-0EBE-45FB-9B41-256C5FCB6AF0}" = protocol=6 | dir=out | app=%systemroot%\system32\netproj.exe |
"{2580F6B5-3E00-4277-A1AA-152C4500813E}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{29A83155-4110-4AD6-B90C-ED1DFBC912BA}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{343E0C06-780B-4C86-82FA-7066E1243167}" = protocol=17 | dir=in | app=c:\program files\codemasters\grid demo\grid.exe |
"{378430A7-39AD-4C5F-A3CF-058B80FDD3D2}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{488C1DE0-13DF-455A-A042-363133B7DF83}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{57922E8A-7C12-43A9-95DA-661DD6551005}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{5B9F503B-1099-4FC4-B0BD-BEBAFE30B3C2}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{5C56A989-CB4D-4C28-9E7C-3BA50133CCB6}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{5F10FD75-57AE-49B0-A7BA-5A3C52B71736}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6F0B58AE-54BF-40D5-896E-B9BB36F1CAAF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{7AEF9FA3-2EC3-4AFD-A375-3A6460D8841D}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{7D0724FD-36AF-46BC-B0B5-3F9954E5351A}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{82614E86-2C17-4BC2-A80E-02CFCD2B397F}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{88C07B47-D654-434C-B9D1-16A3118720C8}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{8C52831A-85E3-4F1B-8637-E4DD01778BA9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{92879A6C-7D6D-47C3-ADB6-D9B390F43B91}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{96F7A489-C06E-4883-ACB1-D8E4A4685051}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{9BD2EC0C-AF40-4502-91BD-25CDEF6B3778}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{9C7A27BB-F58F-4847-9AF9-DF485DBC576D}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{A493A8F9-E8FC-4B08-93CD-DA6836FA0983}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{AD0B5049-C281-499B-AE3A-869DD005D86C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AD39F353-BE67-4161-85A6-97803B32EEDD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B3571FDC-0F8E-438C-89CD-454CA05FED7D}" = protocol=6 | dir=in | app=%systemroot%\system32\netproj.exe |
"{BAC1914E-520F-433B-979B-B0359202AA7A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C52D97B1-8F98-42C2-B534-A8C17885F88E}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{D119C6A1-1A31-4EE8-BEF7-CB4F55C1A8F8}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{DB6BE873-0CD8-4831-B95C-F4506AE86CE0}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{E005CDF4-D050-4761-8214-CE7C58F1D077}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{E0B2C81F-344D-4DAF-A097-E4E8540EA400}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{E3B010A5-808D-46C9-BDBA-4FA5ED1302C0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E6359FDF-2B1A-4F5C-A6BA-5CDB8AEDAB66}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{E86A76BE-1A90-4A1B-88CF-90B56B6F060F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F29F344D-B9B6-4523-8A1D-07F34E9CD34F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F962FFFB-FF0A-4A2F-B0A6-D2AFD28D9FA7}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{1184D8B7-9FD5-4D7F-B146-335EDBC19A01}C:\program files\wolfenstein - enemy territory\et.exe" = protocol=6 | dir=in | app=c:\program files\wolfenstein - enemy territory\et.exe |
"TCP Query User{1E915419-C505-452F-A500-7AC39F23585F}C:\program files\css\hl2.exe" = protocol=6 | dir=in | app=c:\program files\css\hl2.exe |
"TCP Query User{2CA0D4C4-2804-4176-AFB2-D1B7E9D13B40}C:\program files\css\hl2.exe" = protocol=6 | dir=in | app=c:\program files\css\hl2.exe |
"TCP Query User{2F47DD51-91BD-44C4-BE88-22B2083A2BDF}C:\users\jirka\desktop\nu2\need for speed underground 2\speed2.exe" = protocol=6 | dir=in | app=c:\users\jirka\desktop\nu2\need for speed underground 2\speed2.exe |
"TCP Query User{3548B525-3EA6-4E79-A932-07722966FF32}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{415850AD-17AF-4DCC-8448-268DEFC76B7F}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{4655591C-3D41-44BF-8AD8-B67489B2D0C0}C:\program files\opera 10 preview\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera 10 preview\opera.exe |
"TCP Query User{4766EA81-AD70-4EFC-9C90-89DC1B61DF2C}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{5156E179-4D71-4E12-9AE7-E72E1C994E0A}C:\program files\everstep\program\everstep.exe" = protocol=6 | dir=in | app=c:\program files\everstep\program\everstep.exe |
"TCP Query User{539AC87B-4FF6-44B1-A7EE-F5BFCD015B03}C:\program files\valve\hl.exe" = protocol=6 | dir=in | app=c:\program files\valve\hl.exe |
"TCP Query User{618BB319-6D7D-4006-8ED7-8959C3DB8E21}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{648395A9-473A-41A4-9256-D0DD7D48778C}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{7015CDE8-7C09-4588-8DE1-C96EF4F37780}C:\program files\call of duty\codmp.exe" = protocol=6 | dir=in | app=c:\program files\call of duty\codmp.exe |
"TCP Query User{70C20832-E968-4B56-86FD-8DA24CE7F237}C:\users\jirka\documents\mir4nda-im-0.7.17-pack-v2.2\miranda32.exe" = protocol=6 | dir=in | app=c:\users\jirka\documents\mir4nda-im-0.7.17-pack-v2.2\miranda32.exe |
"TCP Query User{73B8C5FA-E39F-4620-A412-66B705E46A97}C:\program files\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\program files\google\chrome\application\chrome.exe |
"TCP Query User{756D75B0-20D8-4E6B-AA88-21F2D2A7A265}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{771AF06F-98E9-4D52-B397-DC6C4B3C7D7E}C:\program files\qip infium jadrispack\infium.exe" = protocol=6 | dir=in | app=c:\program files\qip infium jadrispack\infium.exe |
"TCP Query User{8919BB47-8B84-4E12-A31A-B2309D997942}G:\instalačky\portable\mirandaportable\app\miranda\miranda32.exe" = protocol=6 | dir=in | app=g:\instalačky\portable\mirandaportable\app\miranda\miranda32.exe |
"TCP Query User{8AB544BF-B58C-4C17-81F9-DB6C52675FA5}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{97CC2709-A223-4328-A731-041A60F95B35}C:\program files\jabbim\jabbim.exe" = protocol=6 | dir=in | app=c:\program files\jabbim\jabbim.exe |
"TCP Query User{98901D33-5866-44E6-AE0B-13AE70314020}C:\program files\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files\miranda im\miranda32.exe |
"TCP Query User{98F73DD4-7A9C-4D55-B6EE-EBF4B946A469}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{9D6C39B2-03B1-4C97-81D5-A112F5693565}C:\program files\valve\hlds.exe" = protocol=6 | dir=in | app=c:\program files\valve\hlds.exe |
"TCP Query User{A39AC876-3A63-4A52-B3E8-34778DF99FDC}C:\program files\flatout2\flatout2.exe" = protocol=6 | dir=in | app=c:\program files\flatout2\flatout2.exe |
"TCP Query User{A9837602-27B0-4E4C-8D90-5A6A99FE6A9D}C:\program files\everstep\program\everstep.exe" = protocol=6 | dir=in | app=c:\program files\everstep\program\everstep.exe |
"TCP Query User{BCDE02AE-41D8-4C88-8BE1-66AD084BAB83}C:\program files\valve\hl.exe" = protocol=6 | dir=in | app=c:\program files\valve\hl.exe |
"TCP Query User{C216B541-DCFE-45BB-9480-A63F9EFCBAC1}C:\program files\qip infium jadrispack\infium.exe" = protocol=6 | dir=in | app=c:\program files\qip infium jadrispack\infium.exe |
"TCP Query User{C2845C17-7155-4EA7-9107-6E5098B021B2}C:\users\jirka\appdata\local\temp\rar$ex01.313\němec\miranda32.exe" = protocol=6 | dir=in | app=c:\users\jirka\appdata\local\temp\rar$ex01.313\němec\miranda32.exe |
"TCP Query User{CCCDB5A9-4AAD-4445-AFBD-9F37155A7E54}C:\program files\jabbim\jabbim.exe" = protocol=6 | dir=in | app=c:\program files\jabbim\jabbim.exe |
"TCP Query User{CF2CEC9E-F759-451A-9BC8-E84A7E49A1E6}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{E26D091E-140C-47B4-9619-22752A7F7177}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{E2FE3D90-4019-45B0-B448-D324509317A8}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe |
"TCP Query User{F23AE4D8-F02C-441C-B694-33ED05FD16B4}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{F52C8F36-72A4-4069-BC29-02E4BF2FA907}C:\program files\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"TCP Query User{F5BAF255-1ACA-4A18-A84E-6321C95B9C2A}C:\program files\ford racing 3\fr3.exe" = protocol=6 | dir=in | app=c:\program files\ford racing 3\fr3.exe |
"TCP Query User{F5CEF010-6C45-4DC3-AC58-450098276CD6}C:\program files\flatout2\flatout2.exe" = protocol=6 | dir=in | app=c:\program files\flatout2\flatout2.exe |
"TCP Query User{F61C2AD4-8930-47A6-BFA6-09C43FBC1650}C:\program files\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files\miranda im\miranda32.exe |
"TCP Query User{FD0B4731-93BC-4DC9-89A8-746DF379D138}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{0010920E-445C-4926-A4D5-10D5EEAFD714}C:\program files\jabbim\jabbim.exe" = protocol=17 | dir=in | app=c:\program files\jabbim\jabbim.exe |
"UDP Query User{03C400C8-3701-491A-9D20-1E3671DAB4E9}C:\users\jirka\desktop\nu2\need for speed underground 2\speed2.exe" = protocol=17 | dir=in | app=c:\users\jirka\desktop\nu2\need for speed underground 2\speed2.exe |
"UDP Query User{054A48A8-03CE-4A7B-A4FD-532B633D6015}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"UDP Query User{15A59827-76CA-432A-BE35-4BAA9ECC21E6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1B05CCF6-1FF8-4667-9821-0C1B242B9402}C:\program files\qip infium jadrispack\infium.exe" = protocol=17 | dir=in | app=c:\program files\qip infium jadrispack\infium.exe |
"UDP Query User{1B74173A-651C-4366-900A-CDAE4BBFEB81}C:\program files\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files\miranda im\miranda32.exe |
"UDP Query User{29259C8D-2E34-46F7-9668-3732BF1E1A5F}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{42DB6090-0C7B-404D-B12C-83A20D322E37}C:\users\jirka\documents\mir4nda-im-0.7.17-pack-v2.2\miranda32.exe" = protocol=17 | dir=in | app=c:\users\jirka\documents\mir4nda-im-0.7.17-pack-v2.2\miranda32.exe |
"UDP Query User{47309249-732B-4DE5-B6DC-0A0CD900B707}C:\program files\css\hl2.exe" = protocol=17 | dir=in | app=c:\program files\css\hl2.exe |
"UDP Query User{5C497A6F-A4C9-424B-8CEA-A45473E40865}C:\program files\jabbim\jabbim.exe" = protocol=17 | dir=in | app=c:\program files\jabbim\jabbim.exe |
"UDP Query User{6233D3DC-A2EF-4AFC-B2CF-ED8FB8956695}C:\program files\opera 10 preview\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera 10 preview\opera.exe |
"UDP Query User{63E909AE-BA4A-4073-BCAD-C931D1A30D1E}C:\program files\flatout2\flatout2.exe" = protocol=17 | dir=in | app=c:\program files\flatout2\flatout2.exe |
"UDP Query User{672B7FB1-B806-4224-8F12-ED3066220E72}C:\program files\wolfenstein - enemy territory\et.exe" = protocol=17 | dir=in | app=c:\program files\wolfenstein - enemy territory\et.exe |
"UDP Query User{6C96BC8E-5322-4E92-9FB1-B50DDF5EF349}C:\program files\flatout2\flatout2.exe" = protocol=17 | dir=in | app=c:\program files\flatout2\flatout2.exe |
"UDP Query User{6F5F4606-041F-4247-B069-F0B9E567DE4E}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{73ABC4E8-C506-4B7E-80FE-B8A6FF969651}C:\program files\qip\qip.exe" = protocol=17 | dir=in | app=c:\program files\qip\qip.exe |
"UDP Query User{7CE5BD9B-8088-446A-B990-A397E81677D5}G:\instalačky\portable\mirandaportable\app\miranda\miranda32.exe" = protocol=17 | dir=in | app=g:\instalačky\portable\mirandaportable\app\miranda\miranda32.exe |
"UDP Query User{848567A9-49B7-4CBA-B2B7-CEC547EA245D}C:\program files\css\hl2.exe" = protocol=17 | dir=in | app=c:\program files\css\hl2.exe |
"UDP Query User{853052D9-7F4C-42F7-B9ED-B9522EB53E1D}C:\program files\valve\hlds.exe" = protocol=17 | dir=in | app=c:\program files\valve\hlds.exe |
"UDP Query User{8E7235A6-2E78-4B48-9776-019F356D59CC}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{9B1396A7-C10D-4249-931B-A1F4350E4193}C:\program files\qip infium jadrispack\infium.exe" = protocol=17 | dir=in | app=c:\program files\qip infium jadrispack\infium.exe |
"UDP Query User{B175EF6B-C119-4D66-83EB-DF6C678E8E90}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{B4F51780-8E78-4A55-89E4-BFE725758AAE}C:\program files\valve\hl.exe" = protocol=17 | dir=in | app=c:\program files\valve\hl.exe |
"UDP Query User{B61EF0C5-FA40-49A6-8A5A-C15074F7E33F}C:\users\jirka\appdata\local\temp\rar$ex01.313\němec\miranda32.exe" = protocol=17 | dir=in | app=c:\users\jirka\appdata\local\temp\rar$ex01.313\němec\miranda32.exe |
"UDP Query User{B9A2E4EE-E382-4B91-B49B-A8F54D185852}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{B9ADDAC1-99ED-43E2-B807-6250A1FCD977}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{C565BB8F-2DAE-4DBD-BCB6-DBF40FD75EEF}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{CE0039BD-607B-4277-9B81-C3A6F8ABE480}C:\program files\ford racing 3\fr3.exe" = protocol=17 | dir=in | app=c:\program files\ford racing 3\fr3.exe |
"UDP Query User{D0EA1B78-39BE-4788-809A-2D703C41F723}C:\program files\valve\hl.exe" = protocol=17 | dir=in | app=c:\program files\valve\hl.exe |
"UDP Query User{D376B98E-DF13-4185-B1C0-DE48EC104BF6}C:\program files\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\program files\google\chrome\application\chrome.exe |
"UDP Query User{E95BC633-2D96-4AC2-B19E-707BE47B2F24}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{ED2554B1-84E4-4409-8467-B81874A0469A}C:\program files\call of duty\codmp.exe" = protocol=17 | dir=in | app=c:\program files\call of duty\codmp.exe |
"UDP Query User{EFC7D085-CD13-4920-B23F-0B175845E830}C:\program files\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files\miranda im\miranda32.exe |
"UDP Query User{F2009DAA-63CE-4090-BBA2-F54D547FAF84}C:\program files\everstep\program\everstep.exe" = protocol=17 | dir=in | app=c:\program files\everstep\program\everstep.exe |
"UDP Query User{F3EF4EF3-29AF-45BC-90F9-8193FF6132D4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{F3F207CD-ADDD-4F7A-8D05-1852F8B18283}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{F8E15C28-D981-49D1-A6AA-A8A22C272F96}C:\program files\everstep\program\everstep.exe" = protocol=17 | dir=in | app=c:\program files\everstep\program\everstep.exe |
"UDP Query User{FE617B3C-AF7A-4DDB-8D2A-902340C3F9F1}C:\program files\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"#1 DVD Ripper" = #1 DVD Ripper 8.1.1
"{05D67915-50EC-56C9-7148-552F8D205383}" = CCC Help German
"{068B46A0-8858-4CEB-80BC-A4AE787A05FC}" = Windows Live Sync
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Pomocník pro přihlášení ke službě Windows Live ID
"{08C69626-1E29-7EE2-E122-D475D7BAAF0B}" = Catalyst Control Center Localization Hungarian
"{09E9F3B1-2965-3D8B-F624-2F44D99B53B0}" = Catalyst Control Center Graphics Light
"{0E4E7AB0-6FFB-4C76-FD74-810DE985D518}" = Catalyst Control Center Localization Greek
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{10D3701B-1463-0C2F-748E-3E03FADEB711}" = Catalyst Control Center Localization Norwegian
"{117FBA8C-9325-4BCD-B19A-0BF21EA9A374}" = Catalyst Control Center Localization Spanish
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP520_series" = Canon MP520 series
"{122321B4-A450-0052-CAD8-B419C0EAD392}" = CCC Help Spanish
"{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}" = ATK Media
"{1606E90F-5327-EE07-9137-C518BF3DFFCE}" = Catalyst Control Center Localization Swedish
"{196BC239-53AB-615F-9B0D-FD2D61D31A58}" = Catalyst Control Center Localization Czech
"{19DC9559-9C20-4A46-A67D-7ECBA52A2788}" = Nokia PC Suite
"{1A0D2EFC-C4FC-446A-8BC3-57A54CE5EADD}" = Opera 10.53
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = LifeFrame2
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Nástroj pro odesílání služby Windows Live
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{21BBAD12-C75F-4F06-A9B0-6F8BEEAF3846}" = Moorhuhn X - XS
"{2263CDC9-37F7-433A-8907-4346BC696FEF}" = Opera 10.50
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2D06A54D-6FA7-62F1-E824-E0109C069D8E}" = CCC Help Russian
"{2EBC713F-3022-A21B-6266-376ED7C43C07}" = CCC Help French
"{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}" = ATK Hotkey
"{3969961F-4B9A-DEB9-BC69-F0348E527DEA}" = Catalyst Control Center Localization Chinese Standard
"{39EAC702-D866-AA54-97C6-13E8AAAC2219}" = CCC Help Hungarian
"{3CE73C5D-D8F0-D6D0-E5AB-39A798BF4571}" = Skins
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{46663439-F39E-BF21-673C-19A035F9C708}" = Catalyst Control Center Localization Thai
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C4A9592-2854-E201-F7A9-2AE77AB35E37}" = CCC Help Portuguese
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}" = PC Connectivity Solution
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{57B15AD4-8C9D-4164-82BB-E33D8644E757}" = ASUS InstantFun
"{5A74F5DD-CD86-FE24-C8D3-9850F43FD42D}" = CCC Help Czech
"{5BD877FE-9E11-D996-DEDB-ABAF4A251C39}" = CCC Help Chinese Standard
"{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}" = ATKOSD2
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{6153EBDC-A52B-6B24-4A3C-5CC8F85BE0DF}" = Catalyst Control Center Graphics Full New
"{6173A4FC-D42D-69A6-52CA-A30496389760}" = ccc-core-static
"{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}" = NB Probe
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{661EA4BC-FF51-FE25-7E59-D8BA41170189}" = Catalyst Control Center Localization Chinese Traditional
"{67645155-2149-7ED9-003E-92BFB7EA262A}" = Catalyst Control Center Localization Portuguese
"{68AB9F5B-85BA-1A49-F5B9-103C172A90F6}" = Catalyst Control Center Localization Korean
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{740323AF-4EFD-EB99-8632-6B5AA9D53411}" = Catalyst Control Center Localization Dutch
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7D5F5F2C-B978-2AD9-B54D-BC9006C35333}" = CCC Help Japanese
"{7D6E6E66-8B3D-42C2-DE13-E3F0C6A178D9}" = CCC Help Korean
"{7DFBD5A5-F88B-ED78-E5FD-FB994138BB25}" = ccc-utility
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F25D625-A159-49F7-B5C5-6654860EC116}" = KB-350e
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{893EFD7C-B705-892C-E6E0-49BFB6C621BC}" = Catalyst Control Center Localization Russian
"{89AF2A9F-9132-44AD-B179-66B182E56F85}" = Opera 10.00
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B8FC6A3-3467-5786-657E-6893DDA7F52D}" = CCC Help Swedish
"{8CFEBE9C-F29F-4C49-80E0-7106970F8734}" = Power4Gear eXtreme
"{8D100E0C-1A5A-43AD-93EF-76F94AE61C30}" = OviMPlatform
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0408-0000-0000000FF1CE}" = Microsoft Office Access MUI (Greek) 2007
"{90120000-0015-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0418-0000-0000000FF1CE}" = Microsoft Office Access MUI (Romanian) 2007
"{90120000-0015-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-041B-0000-0000000FF1CE}" = Microsoft Office Access MUI (Slovak) 2007
"{90120000-0015-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0408-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Greek) 2007
"{90120000-0016-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0418-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Romanian) 2007
"{90120000-0016-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0016-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0408-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Greek) 2007
"{90120000-0018-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0418-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Romanian) 2007
"{90120000-0018-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0408-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Greek) 2007
"{90120000-0019-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0418-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Romanian) 2007
"{90120000-0019-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2007
"{90120000-0019-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0408-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Greek) 2007
"{90120000-001A-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0418-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Romanian) 2007
"{90120000-001A-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}_PROHYBRIDR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0408-0000-0000000FF1CE}" = Microsoft Office Word MUI (Greek) 2007
"{90120000-001B-0408-0000-0000000FF1CE}_PROHYBRIDR_{C913F31D-FF3E-47F6-95E6-7E417D37A76E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0418-0000-0000000FF1CE}" = Microsoft Office Word MUI (Romanian) 2007
"{90120000-001B-0418-0000-0000000FF1CE}_PROHYBRIDR_{3DFBDBEE-B82A-47D9-8134-B86A98280A8E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}_PROHYBRIDR_{F69A7281-8297-47E2-B583-36EAA37C89EE}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_HOMESTUDENTR_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}_PROHYBRIDR_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0408-0000-0000000FF1CE}" = Microsoft Office Proof (Greek) 2007
"{90120000-001F-0408-0000-0000000FF1CE}_PROHYBRIDR_{3C7DCB2F-8EA1-4558-B8F5-1107C4055A0B}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-040E-0000-0000000FF1CE}_PROHYBRIDR_{573CA1BB-C8A3-46C4-993E-DB4043D9BFCD}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0418-0000-0000000FF1CE}" = Microsoft Office Proof (Romanian) 2007
"{90120000-001F-0418-0000-0000000FF1CE}_PROHYBRIDR_{6E3398C5-9A81-4054-B474-8B23A60F5048}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_HOMESTUDENTR_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}_PROHYBRIDR_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-002C-0408-0000-0000000FF1CE}" = Microsoft Office Proofing (Greek) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-002C-0418-0000-0000000FF1CE}" = Microsoft Office Proofing (Romanian) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}_PROHYBRIDR_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0408-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Greek) 2007
"{90120000-006E-0408-0000-0000000FF1CE}_PROHYBRIDR_{E3B92295-785F-4FF7-8BE1-67E86F5F8140}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0418-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Romanian) 2007
"{90120000-006E-0418-0000-0000000FF1CE}_PROHYBRIDR_{CEDDCA72-ED57-4CE5-B55D-A50EE2CD3CCF}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}_PROHYBRIDR_{8AF3A9EB-FBB9-449F-AC11-94CE39930037}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0405-0000-0000000FF1CE}" = Doplněk Microsoft Save as PDF or XPS pro aplikace sady Microsoft Office 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A70075D-6071-4704-EAF6-6DEB51CB777B}" = Catalyst Control Center Localization Finnish
"{9D513AEB-187D-C020-317A-5804F781CC95}" = CCC Help Chinese Traditional
"{9D88CAFF-7CB3-916A-0A1F-5E0DB4ECD073}" = Catalyst Control Center Localization Danish
"{9EE7095B-F74E-4DC9-FAF7-75C940A1C3E9}" = Catalyst Control Center Localization French
"{A315B77A-24C5-95D9-9325-61C98FBB7C53}" = Catalyst Control Center Localization German
"{A480B428-5A5E-8D8F-6D8E-2CCBFF6029FA}" = CCC Help Norwegian
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7AF2BC7-FCFB-03CB-DA36-5E9D44A53091}" = CCC Help Turkish
"{A8FD0C55-0D21-89F3-57E9-1E22235765B3}" = CCC Help Finnish
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.2 - Czech
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B5DCE5D7-6FDD-D5C2-C6B7-14E264E695C9}" = Catalyst Control Center Core Implementation
"{B5FE6702-0B5F-6866-7FD2-A7B28BCAB15B}" = Catalyst Control Center Localization Japanese
"{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}" = Nokia Ovi Suite
"{B89BD504-63FF-03DC-5B8B-CEBCEBF2B08D}" = CCC Help English
"{C0FC1C14-4824-4A73-87A6-9E888C9C3102}" = ASUS Splendid Video Enhancement Technology
"{C263E891-CA9F-7CE4-B31D-6A100D5D2F3C}" = CCC Help Polish
"{C4693D41-87C5-A2E0-00AB-5E0A0A205E9E}" = CCC Help Italian
"{C50EF365-2898-489A-B6C7-30DAA466E9A2}" = Nokia Connectivity Cable Driver
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C72D7008-266D-4DD8-BF3C-296B736127F6}" = Mafia
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DB891739-2EB3-45A8-9CBD-941C255CECD4}" = ASUS Touch Pad Extra
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DCC7315A-F551-0778-AFC1-C19D853E0AFA}" = Catalyst Control Center Localization Turkish
"{DCE907E3-4D72-4CD3-A08A-BEFC8C7A5869}" = Branding
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
"{DF6D07CB-BA1B-60D3-8D51-69A5775AC7D9}" = CCC Help Thai
"{E26DD81D-91CF-7348-65E2-5AC16E14612B}" = Catalyst Control Center Localization Polish
"{E33E9943-2679-C829-5E9E-4D981A1C264C}" = CCC Help Danish
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E7F0262E-84B8-9EBE-D6FD-E3865FCDB0EB}" = Catalyst Control Center Localization Italian
"{EAA02F85-3DD4-4083-9AF6-7A2C13ACF1E5}" = Moorhuhn Piraten
"{ED8C5498-6C39-92E6-B17F-414BF1722E42}" = Catalyst Control Center Graphics Previews Vista
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
Anna

Reklama
Uživatelský avatar
Anna
Level 1.5
Level 1.5
Příspěvky: 101
Registrován: březen 05
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Anna » 30 kvě 2010 17:58

"{F173C327-FAA5-D463-2CBD-A4818C7EDC8C}" = Catalyst Control Center Graphics Full Existing
"{F1C3541D-5B93-4131-B440-692FBA3DD250}" = Ovi Desktop Sync Engine
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F49109F4-EA87-B982-8A66-CCD32C6FC8AF}" = CCC Help Greek
"{F5AB638D-91F6-6517-9872-BE6996E06AF6}" = CCC Help Dutch
"{F8718F95-21A1-44B9-97EC-679C93020BAE}" = Colin McRae Rally 04
"{FC3D290D-79BE-44B7-ABF9-FDD110925930}" = PowerForPhone
"05B59228C7E1C21DFBE89260F879BD95880548D8" = Balíček ovladače systému Windows - Nokia Modem (10/05/2009 4.2)
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 4.64
"8CDCFB95BB84DD9C0F88F22266A0CA86035E55BA" = Balíček ovladače systému Windows - Nokia Modem (06/01/2009 7.01.0.4)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver
"ATI Uninstaller" = ATI Uninstaller
"avast!" = avast! Antivirus
"AviSynth" = AviSynth 2.5
"Boilsoft Video Joiner_is1" = Boilsoft Video Joiner 5.32
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A" = Balíček ovladače systému Windows - Nokia Modem (03/05/2008 3.7)
"CCleaner" = CCleaner (remove only)
"Counter-Strike Source_is1" = Counter-Strike Source v1.0.0.22
"Counter-Strike: Source Texture Pack 1.00" = Counter-Strike: Source Texture Pack 1.00
"Counter-Strike:Source čestina" = Counter-Strike:Source čestina
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab Platinum_is1" = DVDFab Platinum 3.0.7.0
"E092B2EBF2FFE83E896F8F7F829A7B5D7D1B2F9D" = Balíček ovladače systému Windows - Nokia Modem (03/13/2008 6.86.0.1)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"EAX Unified" = EAX Unified
"Efficient WMA MP3 Converter_is1" = Efficient WMA MP3 Converter v0.99
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.4
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.5.1
"LANGMaster eduExplorer" = LANGMaster eduExplorer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"Mp3tag" = Mp3tag v2.42
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Suite" = Nokia PC Suite
"OpenAL" = OpenAL
"Photodex Presenter" = Photodex Presenter
"PhotoFiltre" = PhotoFiltre
"PROHYBRIDR" = 2007 Microsoft Office system
"ProShow Gold" = ProShow Gold
"QIP Infium JadrisPack 2.4.1" = QIP Infium JadrisPack 2.4.1
"QIP Infium JadrisPack 2.4.3 (9030)" = QIP Infium JadrisPack 2.4.3 (9030)
"QIP Infium JadrisPack 2.6.1" = QIP Infium JadrisPack 2.6.1
"QIP Infium JadrisPack 3.0.3b" = QIP Infium JadrisPack 3.0.3b
"QIP Infium JadrisPack 3.1.1" = QIP Infium JadrisPack 3.1.1
"RealPlayer 12.0" = RealPlayer
"Registrace uživatele zařízení Canon MP520 series" = Registrace uživatele zařízení Canon MP520 series
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"Spyware Terminator_is1" = Spyware Terminator
"SUPER ©" = SUPER © Version 2010.bld.37 (Jan 2, 2010)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The KMPlayer" = The KMPlayer (remove only)
"Uninstall_is1" = Uninstall 1.0.0.0
"USB 2.0 1.3M UVC WebCam" = USB 2.0 1.3M UVC WebCam
"VLC media player" = VLC media player 1.0.0-rc4
"WinRAR archiver" = WinRAR

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 3.1.2010 10:22:05 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Users\Jirka\AppData\Local\Temp\ynpVUPx9.iso.part failed, 00000084.

Error - 3.1.2010 10:22:05 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Users\Jirka\Desktop\codcd2_revanovo-tk.iso.part failed, 00000084.

Error - 3.1.2010 10:24:43 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://dl.s10.uloz.to/Ps;Hs;fid=2088699 ... =19875822&
failed, 00000084.

Error - 3.1.2010 10:28:34 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://dl.s10.uloz.to/Ps;Hs;fid=2088699 ... &c=1531445
failed, 00000084.

Error - 3.1.2010 12:16:50 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://dl.s10.uloz.to/Ps;Hs;fid=2088699 ... 0&c=204832
failed, 00000084.

Error - 3.1.2010 14:25:59 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Users\Jirka\Desktop\codcd2_revanovo-tk.iso.part failed, 00000084.

Error - 3.1.2010 14:26:40 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Users\Jirka\AppData\Local\Temp\9jxkgOjC.iso.part failed, 00000084.

Error - 3.1.2010 14:26:40 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Users\Jirka\Desktop\codcd2_revanovo-tk.iso.part failed, 00000084.

Error - 3.1.2010 14:32:14 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://dl.s10.uloz.to/Ps;Hs;fid=2088699 ... =19875822&
failed, 00000084.

Error - 13.5.2010 9:48:56 | Computer Name = Jirka-PC | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\Windows\SoftwareDistribution\Download\e84b31ddce29977a6cfec05a0a6e95db\BIT9676.tmp
failed, 00000026.

[ Application Events ]
Error - 10.5.2010 9:47:20 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 11.5.2010 9:47:21 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 13.5.2010 9:42:57 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 14.5.2010 11:14:41 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 15.5.2010 12:11:37 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 16.5.2010 3:14:02 | Computer Name = Jirka-PC | Source = WinMgmt | ID = 10
Description =

Error - 16.5.2010 6:52:47 | Computer Name = Jirka-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace MCM2.EXE, verze 20.13.4.2901, časové razítko 0x63732172,
chybující modul d3drm.dll, verze 6.0.6002.18005, časové razítko 0x49e03821, kód
výjimky 0xc0000135, posun chyby 0x00009eed, ID procesu 0xda8, čas spuštění aplikace
0x01caf4e5e9250ecd.

Error - 16.5.2010 6:52:49 | Computer Name = Jirka-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace MCM2.EXE, verze 20.13.4.2901, časové razítko 0x63732172,
chybující modul d3drm.dll, verze 6.0.6002.18005, časové razítko 0x49e03821, kód
výjimky 0xc0000135, posun chyby 0x00009eed, ID procesu 0x43c, čas spuštění aplikace
0x01caf4e5ebeac134.

Error - 16.5.2010 6:55:35 | Computer Name = Jirka-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace MCM2.EXE, verze 20.13.4.2901, časové razítko 0x63732172,
chybující modul d3drm.dll, verze 6.0.6002.18005, časové razítko 0x49e03821, kód
výjimky 0xc0000135, posun chyby 0x00009eed, ID procesu 0x1310, čas spuštění aplikace
0x01caf4e64ec45f86.

Error - 16.5.2010 9:31:39 | Computer Name = Jirka-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace infium.exe, verze 9.0.3.4, časové razítko 0x2a425e19,
chybující modul InfIRC.dll, verze 1.0.0.4, časové razítko 0x2a425e19, kód výjimky
0xc0000005, posun chyby 0x0000392e, ID procesu 0x354, čas spuštění aplikace 0x01caf4c7563dcbc5.

[ OSession Events ]
Error - 2.9.2009 14:47:38 | Computer Name = Jirka-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6.9.2009 8:31:13 | Computer Name = Jirka-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 30.5.2010 10:47:43 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 30.5.2010 10:51:52 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 30.5.2010 10:53:03 | Computer Name = Jirka-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =

Error - 30.5.2010 10:58:10 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 30.5.2010 11:25:12 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 30.5.2010 11:31:05 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 30.5.2010 11:39:55 | Computer Name = Jirka-PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (17:38:54, 30.5.2010) bylo neočekávané.

Error - 30.5.2010 11:40:11 | Computer Name = Jirka-PC | Source = Print | ID = 72
Description = Systému Windows se nezdařila inicializace tiskárny Zapisovač poznámek
programu Deník, protože tiskový procesor JournalPrint nebyl nalezen. Vyžádejte
si od výrobce novou verzi ovladače (pokud je k dispozici) a nainstalujte ji nebo
vyberte alternativní ovladač, který bude s touto tiskárnou pracovat.

Error - 30.5.2010 11:41:30 | Computer Name = Jirka-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 30.5.2010 11:43:21 | Computer Name = Jirka-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =


< End of report >
Anna

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Damned » 30 kvě 2010 18:11

Proto píšu všude: Uložit na Plochu. To samé sem psal pro OTL, zas ho máš kdesi u souseda v ložnici. - Lépe se s tím pak pracuje, případně i maže.

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/Opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKCU\..\URLSearchHook: {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll File not found
O2 - BHO: (CentrumczToolbar BHO) - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll File not found
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O18 - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
@Alternate Data Stream - 184 bytes -> C:\ProgramData\Temp:4BF2F6B5
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:8CE646EE
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:CB0AACC9

:Files
C:\WINDOWS\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\system32\SET*.tmp
C:\Recycler
C:\$RECYCLE.BIN
C:\327882R2FWJFW
C:\ComboFix
C:\Qoobox
C:\Combofix.txt
C:\Windows\PEV.exe
C:\Windows\SWXCACLS.exe
C:\Windows\SWREG.exe
C:\Windows\SWSC.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\MBR.exe
C:\Windows\zip.exe
C:\Windows\NIRCMD.exe
C:\ComboFix
C:\Qoobox
C:\Windows\tasks\SA.DAT
C:\Windows\System32\CF30166.exe
C:\Users\Jirka\AppData\Roaming\ICQ Toolbar

:Reg

:Commands
[purity]
[emptytemp]
[emptyflash]
[start explorer]
[Reboot]



Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Uživatelský avatar
Anna
Level 1.5
Level 1.5
Příspěvky: 101
Registrován: březen 05
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Anna » 30 kvě 2010 18:17

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\centrumcztoolbar\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61A97628-7C82-4315-957A-C74C2CDD85DF}\ deleted successfully.
File {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll File not found not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
ADS C:\ProgramData\Temp:4BF2F6B5 deleted successfully.
ADS C:\ProgramData\Temp:8CE646EE deleted successfully.
ADS C:\ProgramData\Temp:CB0AACC9 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\*.tmp not found.
C:\WINDOWS\System32\tmp3AC9.tmp moved successfully.
C:\WINDOWS\System32\tmp3AE9.tmp moved successfully.
C:\WINDOWS\System32\tmpC497.tmp moved successfully.
C:\WINDOWS\System32\tmpC4B8.tmp moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\Recycler not found.
C:\$RECYCLE.BIN\S-1-5-21-3202407924-2347464904-772658127-1000 folder moved successfully.
C:\$RECYCLE.BIN folder moved successfully.
File\Folder C:\327882R2FWJFW not found.
C:\ComboFix folder moved successfully.
C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
C:\Qoobox\Quarantine\C\Users\Jirka\AppData\Local folder moved successfully.
C:\Qoobox\Quarantine\C\Users\Jirka\AppData folder moved successfully.
C:\Qoobox\Quarantine\C\Users\Jirka folder moved successfully.
C:\Qoobox\Quarantine\C\Users folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\ICQToolbar folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files folder moved successfully.
C:\Qoobox\Quarantine\C folder moved successfully.
C:\Qoobox\Quarantine folder moved successfully.
C:\Qoobox\BackEnv folder moved successfully.
C:\Qoobox folder moved successfully.
C:\ComboFix.txt moved successfully.
C:\Windows\PEV.exe moved successfully.
C:\Windows\SWXCACLS.exe moved successfully.
C:\Windows\SWREG.exe moved successfully.
C:\Windows\SWSC.exe moved successfully.
C:\Windows\sed.exe moved successfully.
C:\Windows\grep.exe moved successfully.
C:\Windows\MBR.exe moved successfully.
C:\Windows\zip.exe moved successfully.
C:\Windows\NIRCMD.exe moved successfully.
File\Folder C:\ComboFix not found.
File\Folder C:\Qoobox not found.
C:\Windows\tasks\SA.DAT moved successfully.
C:\Windows\System32\CF30166.exe moved successfully.
C:\Users\Jirka\AppData\Roaming\ICQ Toolbar folder moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User

User: Jirka
->Temp folder emptied: 1419675 bytes
->Temporary Internet Files folder emptied: 5310068 bytes
->Java cache emptied: 61494608 bytes
->FireFox cache emptied: 49933466 bytes
->Google Chrome cache emptied: 38848194 bytes
->Apple Safari cache emptied: 35924252 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 12281 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 31634 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 184,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Jirka
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.5.1 log created on 05302010_181409

Files\Folders moved on Reboot...
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Anna

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Damned » 30 kvě 2010 18:45

Smaž složku C:\_OTL a vysypej Koš.

Stáhni si ToolsCleaner2 (by de A.Rothstein & Dj Quiou) na Plochu a spusť ho.

Klikni na Pt. Restauration (obnova) a poté na OK.
Klikni na Corbeille (koš) a poté na OK.
Klikni na Fichiers temp (temp složky) a poté na OK.
Klikni na Recherche (hledání) a nech Cleaner pracovat. Může se během čištění zastavit , ale nech ho pokračovat.
Když program skončí , klikni na Suppression (odstranění) a odstraň nalezené.
Zavři a smaž program.

Nasplánuj test avastu po restartu. Restartuj a napiš zda něco našel.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Uživatelský avatar
Anna
Level 1.5
Level 1.5
Příspěvky: 101
Registrován: březen 05
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Anna » 30 kvě 2010 20:51

Děkuji moc za čas i za pomoc :) Avast nic nenašel krom jednoho cracku který hlásil jako trojana, ale o tom sem věděl už dříve :) ještě jednou moc děkuji :)
Anna

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, avast mi hlásí rootkity

Příspěvekod Damned » 30 kvě 2010 21:07

Tak ten crack taky smázni. Po jeho spuštění by sis mohl něco natáhnout z netu a měl by si to zpátky.

Kdyby se něco zase objevilo, tak se zastav.
Označ topic za vyřešený (zelená fajfka) a měj se. :bigups:
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 88 hostů