Kontrola logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod Michalkalensky » 12 dub 2014 11:16

========== Files - Modified Within 30 Days ==========

[2014.04.12 11:05:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Michal Kalenský\Desktop\OTL.exe
[2014.04.12 11:04:36 | 005,725,505 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Persist.Plus.v3.9.Full.apk
[2014.04.12 10:49:00 | 000,000,396 | ---- | M] () -- C:\Windows\tasks\update-S-1-5-21-1199612218-1043710064-1858448162-1000.job
[2014.04.12 10:40:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.04.12 10:33:53 | 000,000,396 | ---- | M] () -- C:\Windows\tasks\update-sys.job
[2014.04.12 10:33:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.04.10 15:28:46 | 000,670,154 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2014.04.10 15:28:46 | 000,655,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014.04.10 15:28:46 | 000,142,280 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2014.04.10 15:28:46 | 000,122,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014.04.10 15:25:33 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014.04.10 15:25:10 | 000,013,464 | ---- | M] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2014.04.10 15:23:46 | 1603,031,040 | -HS- | M] () -- C:\hiberfil.sys
[2014.04.09 19:36:05 | 000,070,705 | ---- | M] () -- C:\Users\Michal Kalenský\Documents\unnamed.jpg
[2014.04.09 19:35:54 | 000,279,456 | ---- | M] () -- C:\Users\Michal Kalenský\Documents\Android-KitKat-Wallpaper.jpg
[2014.04.09 15:43:39 | 000,138,032 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014.04.09 15:43:32 | 000,281,688 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2014.04.08 17:27:22 | 000,001,385 | ---- | M] () -- C:\Users\Michal Kalenský\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NHL® 09 Registration.lnk
[2014.04.08 17:25:29 | 000,021,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.04.08 17:25:28 | 000,021,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.04.07 20:14:41 | 000,001,930 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\CrystalDiskInfo.lnk
[2014.04.07 19:49:39 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014.04.06 20:28:35 | 000,002,259 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Spouštěč aplikací Chrome.lnk
[2014.04.06 10:18:08 | 000,002,047 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014.04.06 10:17:48 | 000,067,264 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys
[2014.04.06 10:17:47 | 000,776,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2014.04.06 10:17:47 | 000,411,552 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2014.04.06 10:17:47 | 000,271,264 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014.04.06 10:17:47 | 000,180,760 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014.04.06 10:17:47 | 000,081,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014.04.06 10:17:47 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014.04.06 10:17:47 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014.04.06 10:17:47 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.04.05 13:39:37 | 000,002,303 | ---- | M] () -- C:\Users\Public\Desktop\Need for Speed Rivals.lnk
[2014.04.01 16:46:07 | 000,095,524 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Screenshot_2014-04-01-16-37-51.jpg
[2014.03.31 18:19:18 | 001,780,772 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\avFonts-AndreaPrintUpright.zip
[2014.03.31 02:13:30 | 002,724,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.03.30 11:53:08 | 000,434,688 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014.03.28 23:22:32 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2014.03.28 21:01:04 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2014.03.25 18:25:18 | 000,000,003 | ---- | M] () -- C:\Users\Michal Kalenský\stut
[2014.03.25 15:15:17 | 000,281,688 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2014.03.23 21:07:24 | 001,037,734 | ---- | M] (Thisisu) -- C:\Users\Michal Kalenský\Desktop\JRT.exe
[2014.03.23 21:03:05 | 000,002,206 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\BitLord.lnk
[2014.03.23 20:59:56 | 000,000,335 | ---- | M] () -- C:\Users\Michal Kalenský\rgut
[2014.03.23 18:17:13 | 001,950,720 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\adwcleaner.exe
[2014.03.23 17:00:51 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\Michal Kalenský\Desktop\ATF-Cleaner.exe
[2014.03.23 15:25:26 | 000,001,663 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Far Cry 3.lnk
[2014.03.22 23:28:45 | 000,003,007 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\HiJackThis.lnk
[2014.03.22 18:08:08 | 000,002,389 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\FIFA 14.lnk
[2014.03.19 21:09:05 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2014.03.19 21:08:52 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014.03.19 21:08:52 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014.03.19 21:08:51 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014.03.19 17:32:05 | 000,002,736 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Google Keep.lnk
[2014.03.19 17:18:32 | 000,002,205 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.03.19 17:14:16 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014.03.19 17:14:16 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014.03.18 22:07:32 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.03.18 19:36:53 | 000,004,608 | ---- | M] () -- C:\Users\Michal Kalenský\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.03.17 20:49:31 | 000,000,000 | ---- | M] () -- C:\Users\Michal Kalenský\regbcm
[2014.03.13 14:43:20 | 000,016,224 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Záloha kontaktů.vcf
[2014.03.13 14:43:15 | 000,319,488 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Solo launcher - záloha plochy.bak
[2014.03.13 14:43:05 | 000,005,878 | ---- | M] () -- C:\Users\Michal Kalenský\Desktop\Solo launcher - záloha nastavení.bak
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014.04.12 11:04:23 | 005,725,505 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Persist.Plus.v3.9.Full.apk
[2014.04.09 19:36:05 | 000,070,705 | ---- | C] () -- C:\Users\Michal Kalenský\Documents\unnamed.jpg
[2014.04.09 19:35:50 | 000,279,456 | ---- | C] () -- C:\Users\Michal Kalenský\Documents\Android-KitKat-Wallpaper.jpg
[2014.04.07 20:14:41 | 000,001,930 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\CrystalDiskInfo.lnk
[2014.04.07 19:49:39 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014.04.06 20:28:35 | 000,002,259 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Spouštěč aplikací Chrome.lnk
[2014.04.06 10:18:08 | 000,002,047 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014.04.05 13:39:37 | 000,002,303 | ---- | C] () -- C:\Users\Public\Desktop\Need for Speed Rivals.lnk
[2014.04.01 16:46:07 | 000,095,524 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Screenshot_2014-04-01-16-37-51.jpg
[2014.03.31 18:19:17 | 001,780,772 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\avFonts-AndreaPrintUpright.zip
[2014.03.28 23:22:32 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2014.03.23 21:02:35 | 000,002,206 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\BitLord.lnk
[2014.03.23 21:01:25 | 000,000,003 | ---- | C] () -- C:\Users\Michal Kalenský\stut
[2014.03.23 20:59:44 | 000,000,335 | ---- | C] () -- C:\Users\Michal Kalenský\rgut
[2014.03.23 18:14:14 | 001,950,720 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\adwcleaner.exe
[2014.03.23 15:12:30 | 000,138,032 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014.03.23 15:12:25 | 000,281,688 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2014.03.23 15:12:25 | 000,281,688 | ---- | C] () -- C:\Windows\System32\PnkBstrB.ex0
[2014.03.23 15:12:23 | 000,281,688 | ---- | C] () -- C:\Windows\System32\PnkBstrB.xtr
[2014.03.23 15:12:15 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2014.03.22 23:28:45 | 000,003,007 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\HiJackThis.lnk
[2014.03.22 23:28:15 | 010,236,928 | --S- | C] () -- C:\Windows\System32\acumncyqwsr.exe
[2014.03.22 23:28:14 | 000,100,864 | --S- | C] () -- C:\Windows\System32\zlib1.dll
[2014.03.22 23:28:14 | 000,023,825 | --S- | C] () -- C:\Windows\System32\scrypt130511.cl
[2014.03.22 23:28:13 | 000,192,512 | --S- | C] () -- C:\Windows\System32\libidn-11.dll
[2014.03.22 23:28:13 | 000,133,632 | --S- | C] () -- C:\Windows\System32\librtmp.dll
[2014.03.22 23:28:13 | 000,043,810 | --S- | C] () -- C:\Windows\System32\poclbm130302.cl
[2014.03.22 23:28:13 | 000,013,062 | --S- | C] () -- C:\Windows\System32\phatk121016.cl
[2014.03.22 23:28:12 | 000,538,126 | --S- | C] () -- C:\Windows\System32\libcurl-4.dll
[2014.03.22 23:28:12 | 000,044,727 | --S- | C] () -- C:\Windows\System32\diablo130302.cl
[2014.03.22 23:28:12 | 000,030,802 | --S- | C] () -- C:\Windows\System32\diakgcn121016.cl
[2014.03.22 18:08:08 | 000,002,389 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\FIFA 14.lnk
[2014.03.20 15:55:23 | 000,001,663 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Far Cry 3.lnk
[2014.03.19 17:32:05 | 000,002,736 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Google Keep.lnk
[2014.03.19 17:18:32 | 000,002,205 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.03.19 17:14:16 | 000,000,914 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.03.18 22:07:32 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.03.18 19:36:53 | 000,004,608 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.03.17 20:49:31 | 000,000,000 | ---- | C] () -- C:\Users\Michal Kalenský\regbcm
[2014.03.13 14:43:24 | 000,016,224 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Záloha kontaktů.vcf
[2014.03.13 14:43:16 | 000,319,488 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Solo launcher - záloha plochy.bak
[2014.03.13 14:43:08 | 000,005,878 | ---- | C] () -- C:\Users\Michal Kalenský\Desktop\Solo launcher - záloha nastavení.bak
[2014.02.26 15:29:05 | 003,573,739 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin
[2014.02.22 14:45:16 | 000,242,456 | ---- | C] () -- C:\Windows\hpoins19.dat
[2014.02.22 14:45:16 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2014.02.22 00:22:03 | 000,001,057 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Roaming\vso_ts_preview.xml
[2014.02.22 00:21:47 | 000,087,608 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Roaming\inst.exe
[2014.02.22 00:21:47 | 000,007,887 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Roaming\pcouffin.cat
[2014.02.22 00:21:47 | 000,001,144 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Roaming\pcouffin.inf
[2014.02.21 23:58:06 | 000,180,760 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014.02.21 23:58:05 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014.02.21 23:56:09 | 000,000,463 | ---- | C] () -- C:\Users\Michal Kalenský\AppData\Local\UserProducts.xml
[2014.02.21 23:39:50 | 005,681,192 | ---- | C] () -- C:\Windows\System32\drivers\rtvienna.dat
[2014.02.21 23:39:45 | 000,681,905 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2014.02.21 22:25:00 | 000,013,464 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2014.02.21 22:05:48 | 000,229,376 | ---- | C] () -- C:\Windows\System32\ustor.dll
[2014.02.21 22:05:48 | 000,040,960 | ---- | C] () -- C:\Windows\System32\UMonit.exe
[2014.02.21 22:05:46 | 000,172,097 | ---- | C] () -- C:\Windows\System32\NoMSGuninstall.exe
[2014.02.21 22:05:46 | 000,000,911 | ---- | C] () -- C:\Windows\System32\ProductName.ini
[2014.02.21 22:05:39 | 000,001,519 | ---- | C] () -- C:\Windows\System32\_IconCfg0.ini
[2014.02.21 22:05:38 | 000,000,213 | ---- | C] () -- C:\Windows\System32\IconCfg0.ini
[2014.02.21 22:02:52 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014.02.21 22:02:04 | 000,000,936 | ---- | C] () -- C:\Windows\System32\drivers\SAMSfPa.dat
[2013.11.15 14:46:10 | 000,529,904 | ---- | C] () -- C:\Windows\System32\DPTopologyApp.exe
[2013.10.28 15:02:00 | 000,317,440 | ---- | C] () -- C:\Windows\System32\igdmd32.dll
[2013.10.28 15:01:40 | 000,182,272 | ---- | C] () -- C:\Windows\System32\igdde32.dll
[2013.10.28 15:01:34 | 000,142,848 | ---- | C] () -- C:\Windows\System32\igdail32.dll
[2013.10.28 15:01:24 | 000,012,288 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2013.10.28 15:01:22 | 002,585,088 | ---- | C] () -- C:\Windows\System32\GfxRes.dll
[2013.03.20 06:27:53 | 000,001,806 | ---- | C] () -- C:\Windows\System32\GfxUIEx.exe.config
[2013.03.20 06:27:53 | 000,000,264 | ---- | C] () -- C:\Windows\System32\GfxUIHotKeyMenu.exe.config
[2013.03.20 06:27:51 | 000,000,935 | ---- | C] () -- C:\Windows\System32\DPTopologyApp.exe.config
[2013.03.20 06:27:51 | 000,000,935 | ---- | C] () -- C:\Windows\System32\CustomModeApp.exe.config
[2013.03.20 06:25:42 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
[2013.02.13 13:25:14 | 000,001,536 | ---- | C] () -- C:\Windows\System32\IusEventLog.dll

========== ZeroAccess Check ==========

[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2014.02.21 23:58:45 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\AVAST Software
[2014.04.07 20:21:13 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\AVG
[2014.03.17 20:28:10 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\D394D188-BAC7-4e03-8FAF-389A4D7EC6F4
[2014.04.07 19:51:27 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\DAEMON Tools Lite
[2014.04.06 18:36:07 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\Dropbox
[2014.04.06 18:36:07 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\DropboxMaster
[2014.02.22 16:54:47 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\Leadertech
[2014.04.07 20:14:29 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\OpenCandy
[2014.04.08 17:34:49 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\PhotoScape
[2014.04.07 19:55:17 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\Seznam.cz
[2014.02.22 14:33:10 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\Telltale Games
[2014.04.07 19:51:26 | 000,000,000 | ---D | M] -- C:\Users\Michal Kalenský\AppData\Roaming\Vso

========== Purity Check ==========



< End of report >


OTL Extras logfile created on: 12.4.2014 11:08:04 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Michal Kalenský\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,99 Gb Total Physical Memory | 1,25 Gb Available Physical Memory | 62,73% Memory free
3,98 Gb Paging File | 2,64 Gb Available in Paging File | 66,31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,41 Gb Total Space | 837,49 Gb Free Space | 89,92% Space Free | Partition Type: NTFS
Drive E: | 465,74 Gb Total Space | 47,75 Gb Free Space | 10,25% Space Free | Partition Type: NTFS

Computer Name: MICHAL | User Name: Michal Kalenský | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05F82E99-7C16-4944-8C3C-955C9EA8E6C0}" = lport=80 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{09F7DAE6-412E-4868-A880-7BFE170C24EB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0D2A1FEA-943D-47A9-A861-CB4B6B8A1D0B}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0DC92724-0776-4A34-8D03-E7BBE5133288}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{109D048E-0CBF-48AB-BEFF-3EC0F99E788A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{1CB1D49F-989B-4BF4-8AFB-8151E4F5E010}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{20719D21-93C3-45F5-9B29-425FFF6E0CBD}" = rport=445 | protocol=6 | dir=out | app=system |
"{21A4BEE9-27BF-4D76-A362-2B3783B07172}" = rport=138 | protocol=17 | dir=out | app=system |
"{2DD87BFB-530E-4882-BC0A-EF950D5614D4}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{2EF0CF46-DF7F-48BD-819E-875B8E2D51C0}" = lport=137 | protocol=17 | dir=in | app=system |
"{3452C518-CC1E-43DD-B86B-67DF1820BD39}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{3548CF90-DAA8-4B39-B846-C08EF6711D2C}" = rport=137 | protocol=17 | dir=out | app=system |
"{39E29B75-5B24-4C41-ADA1-385B7AA55F87}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3B67E812-E8FB-4A87-8D76-EF461D270034}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3DEE3C3F-A608-497C-A0A6-6BCE4A5D7CE1}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{436AF6F2-44D6-4921-BE94-DB095FB025D9}" = lport=443 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{4E79E855-A9EB-43CC-877B-F392960D121C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5C6A4ECE-7858-4EA2-8BB3-F2063D8AFA05}" = lport=80 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{5D462B4C-84E1-4507-9C3E-60035BD8FFB8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5F93238D-194C-4BC5-84D3-892B25A5F2FA}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{75A6DFE3-C36C-4571-BE73-35A314A2FE2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7AA9593D-DCA0-45C3-AE7E-C5B852C8AF9B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{80CC91E0-3A48-4679-BB17-BCB23511677B}" = lport=443 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{8ACF0C07-A764-48A0-B89C-38F356ADCF92}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{8DEDBBBF-FAE2-46CB-8E96-FD94D16F353E}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{8E4D47D9-CD93-41CC-8B1C-77FE2111BA43}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{96E24A87-5467-4AAD-8792-3E9CDD6D51FA}" = lport=138 | protocol=17 | dir=in | app=system |
"{9AE08572-B41D-4C2F-883B-5D0B4EA8CC08}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{9D8C11C2-77C3-4B83-A870-CDE2DFCB9BAB}" = rport=139 | protocol=6 | dir=out | app=system |
"{A38ABE45-F498-48EE-B36E-D13C7D6910EC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AE3AA827-8890-4B54-8CAF-58CBC98BF14F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CC74EC03-64DE-49A5-9DA0-8AB5B1F67960}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DAEDEEA3-88F4-4479-9C75-C59B32118515}" = lport=139 | protocol=6 | dir=in | app=system |
"{E7638418-11FF-42D5-AF32-75A61E4E1736}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe |
"{F6E30F61-6C16-43B5-8D90-557411B40031}" = lport=445 | protocol=6 | dir=in | app=system |
"{F89C9289-5578-4875-8FAE-5B3EFAFD8942}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FB9CFB8D-5195-4A2C-80A5-23DCB16FA275}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04EF8221-9E8C-4139-9EED-C6CC320B7DBB}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{05FF75C3-ACFA-4301-9595-B61581FE9AE1}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{06284C47-6457-490F-BAA7-308104AE7258}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{06535AA8-DD1A-40D5-8A83-DE378795E968}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{13698DC3-3541-4C1A-BEDC-ACEE83B72F95}" = protocol=6 | dir=out | app=system |
"{1605EC82-5B8C-4332-A8DB-E348395EB36E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{183F1B2A-692F-4B6B-AADF-9D60766E3084}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{1A1465AD-7EE5-4863-87C5-B4434506608A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{1B0B820A-C41D-447E-B5D3-9B12C22A431F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqnrs08.exe |
"{1DC914D8-1E8D-4D08-9918-DA820816EDB6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{2159B1C9-8E88-4D31-B44E-5C822375A74A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{21C2D29B-0845-4B05-AC44-6F3E3657EA13}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{374BA022-8EFE-42FB-A47A-EC7ED7FC20C9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{3F6F36DD-FCC0-4E0D-9DBF-9791576E5409}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |
"{47FADD06-3248-4966-AD65-9AA81BE2C464}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{4E949CC3-7A62-4AEA-80C0-C283F2F7C660}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4ED43B19-A88E-4E34-A201-048E94199122}" = protocol=6 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\farcry3.exe |
"{4F62926A-9C3C-4BE6-BCEA-06AAA1D09F07}" = protocol=17 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\fc3editor.exe |
"{532ACDC7-54A1-4702-97F6-A9A7BB68816C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{55475394-54E5-40F8-AB71-4DB0A8E32EE4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5A007563-BD6C-4ECA-8A77-760459FE942E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{5AC9C306-E333-4ED5-A3E7-5792F24ACAB4}" = protocol=6 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\fc3editor.exe |
"{657CBA7B-BDF3-4AED-AD5C-859E8C28F3F1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{66975F5E-5006-4A5E-BAB8-95ECA3655133}" = protocol=17 | dir=in | app=c:\program files\electronic arts\need for speed rivals\nfs14_x86.exe |
"{66AEABCA-8CCF-4BED-BDE4-05294D894C8A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{6834FB30-E42D-4F9B-A68D-D9B7299F3FF2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{6858223A-0793-4B8F-AE38-43D44C469107}" = protocol=6 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\fc3updater.exe |
"{68A92686-8D49-413D-8C27-C12D701B5CCA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{70464396-93BA-43C1-970E-8239E6CCEE39}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{70B4CF5E-0A6E-4600-972F-CE848B9E872F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{732F6A91-C627-4C93-B280-6C67AE5DC0DD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7B230ED4-EA42-40F4-8F9B-59D16C641801}" = protocol=6 | dir=in | app=c:\program files\electronic arts\need for speed rivals\nfs14.exe |
"{827BF46B-D88E-4651-ADED-1F27A8BE74B9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{877713C5-34D7-4507-ADDE-B12CF82A091A}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{879B1DD8-F38A-4EB3-B894-0E6E952F0704}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{8BE66A11-A31B-402A-8923-1BB676FBFBE5}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{8C263F3F-B3D8-4477-BB15-816057CE14B2}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{90761B66-BFC5-499B-8218-E2C6AF9D2CF1}" = protocol=6 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\farcry3_d3d11.exe |
"{90F9A9F0-E5BA-479D-B201-39ED2A3397CA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |
"{913D51EC-75F0-487E-A2E6-C756CD95D200}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9534910D-251F-458E-8A47-F457A939334C}" = protocol=17 | dir=in | app=c:\program files\electronic arts\need for speed rivals\nfs14.exe |
"{982B2C5C-6C7D-4E61-9E5E-BD7D24C4E231}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9A9A903E-7035-47AD-B885-5F203C585325}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{9E1E086D-1220-40F2-9FBE-F61AFD8A375E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{A17E1018-F0C3-4D1B-ADC9-BC395A2F73ED}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{AC4C2B80-A493-4773-8B0A-1667B2F7E431}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B34E962F-88CA-4D01-B218-C1BC1F1924F9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{B7D49432-B27B-4852-AB29-6AEFE529B3E0}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{B912CFF9-B108-4047-82AF-AE0DB8157885}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{BBFC13AF-253C-4AB3-A04D-AE4823F74DE9}" = protocol=17 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\fc3updater.exe |
"{BFF26AAB-9CBD-4BFA-A781-F2692BBF1CDD}" = dir=in | app=c:\users\michal kalenský\appdata\local\microsoft\skydrive\skydrive.exe |
"{C6F8C9A5-70D1-42E3-9F86-3C0027E6DCEC}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{CB37E18F-2A8A-4379-8738-AFB4E7773172}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CB6FA1BD-16D2-4C16-8CB2-B2CB2B59CF6F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CF3C9548-04E3-410A-8455-1624A8551BAA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{D37B5501-75B9-4142-A77E-BBCF496621E7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D7659115-609A-4C90-ACFE-E929B1DDBA2D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E12A254A-8431-47CC-AF50-F9B91ECBEEFE}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |

Reklama
Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod Michalkalensky » 12 dub 2014 11:16

"{E2851A72-DDA5-41E4-B984-FA9F558EE691}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |
"{E38EDCAD-F6D9-4756-A1AE-B7A3202241C8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{E9BE1B91-5A9E-47C7-B092-A5319534E8E9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EB067576-B379-4DC6-B984-B63AE454FAED}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{F2257B84-B0C6-426F-BBF5-11DC77C6AD98}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{FCF10B39-7FB0-47AA-A541-9C0DB5CCFD26}" = protocol=6 | dir=in | app=c:\program files\electronic arts\need for speed rivals\nfs14_x86.exe |
"{FE8DDCF0-05F3-4D69-BB83-4890B02CA27D}" = protocol=17 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\farcry3.exe |
"{FFCB4A0F-90E3-46BB-BCC5-AAEADF1D0154}" = protocol=17 | dir=in | app=c:\program files\ubisoft\farcry 3\bin\farcry3_d3d11.exe |
"TCP Query User{2236C6F1-9046-4E71-AA2A-04F2791C08EA}C:\program files\bitlord\bitlord_win9x.exe" = protocol=6 | dir=in | app=c:\program files\bitlord\bitlord_win9x.exe |
"TCP Query User{3EF6332B-1610-4DCC-A642-D97040CA8DAB}C:\program files\win drive\nircmd.exe" = protocol=6 | dir=in | app=c:\program files\win drive\nircmd.exe |
"TCP Query User{599D2118-368A-479E-891E-CB34C48F6329}C:\program files\win drive\poclbm.exe" = protocol=6 | dir=in | app=c:\program files\win drive\poclbm.exe |
"TCP Query User{5C76A258-6C32-416A-92A8-782E91AE9731}C:\program files\bitlord\bitlord.exe" = protocol=6 | dir=in | app=c:\program files\bitlord\bitlord.exe |
"TCP Query User{6A5CD158-802B-4CE5-AAA1-BBB94C78E489}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{83067A50-D2CE-4B1F-A481-4039A49FB086}C:\windows\system32\stikynot.exe" = protocol=6 | dir=in | app=c:\windows\system32\stikynot.exe |
"TCP Query User{9BC4B3DA-DA90-4EE0-BFD5-4E670C448211}C:\program files\bloody5\bloody5\bloody5.exe" = protocol=6 | dir=in | app=c:\program files\bloody5\bloody5\bloody5.exe |
"TCP Query User{B3111FE6-D39A-434D-97C4-AB4BC0AEA4A8}C:\users\michal kalenský\appdata\local\skillbrains\lightshot\lightshot.exe" = protocol=6 | dir=in | app=c:\users\michal kalenský\appdata\local\skillbrains\lightshot\lightshot.exe |
"TCP Query User{F671DCC9-51E5-4273-B276-BD495368A672}C:\program files\win drive\nircmd.exe" = protocol=6 | dir=in | app=c:\program files\win drive\nircmd.exe |
"UDP Query User{0DDE4582-3A71-423A-9D75-F94F36799E84}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{2731D14F-43A2-4D1A-9B4A-450E9E203243}C:\windows\system32\stikynot.exe" = protocol=17 | dir=in | app=c:\windows\system32\stikynot.exe |
"UDP Query User{5D66EB93-49E3-4C5B-B08A-0AA9D6047606}C:\users\michal kalenský\appdata\local\skillbrains\lightshot\lightshot.exe" = protocol=17 | dir=in | app=c:\users\michal kalenský\appdata\local\skillbrains\lightshot\lightshot.exe |
"UDP Query User{94D93166-B559-4FF8-90FC-367AEF64B14E}C:\program files\win drive\nircmd.exe" = protocol=17 | dir=in | app=c:\program files\win drive\nircmd.exe |
"UDP Query User{B774FB44-B108-43BB-BB5A-22E6FF18E371}C:\program files\bloody5\bloody5\bloody5.exe" = protocol=17 | dir=in | app=c:\program files\bloody5\bloody5\bloody5.exe |
"UDP Query User{BD422B77-9B2E-467E-A3F2-F67931EF8FF0}C:\program files\win drive\poclbm.exe" = protocol=17 | dir=in | app=c:\program files\win drive\poclbm.exe |
"UDP Query User{DE796B50-2DFB-4099-8CCD-7E0822854198}C:\program files\win drive\nircmd.exe" = protocol=17 | dir=in | app=c:\program files\win drive\nircmd.exe |
"UDP Query User{E1D3D7D8-E982-4F33-99E2-D570AF41D33A}C:\program files\bitlord\bitlord.exe" = protocol=17 | dir=in | app=c:\program files\bitlord\bitlord.exe |
"UDP Query User{E4FED729-1B23-417F-9EA6-EE37E75388C7}C:\program files\bitlord\bitlord_win9x.exe" = protocol=17 | dir=in | app=c:\program files\bitlord\bitlord_win9x.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}" = Intel(R) Manageability Engine Firmware Recovery Agent
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{123F4E9B-80E6-3A84-BDD4-3CB3AC59ABF0}" = Microsoft .NET Framework 4.5.1 (CSY)
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{20D55630-5D12-4297-841C-D3165374ECEE}" = Intel® Trusted Connect Service Client
"{24BA1CC8-6238-4813-9680-8A7F35BB8D5F}" = The Walking Dead Season2 Episode1
"{26A24AE4-039D-4CA4-87B4-2F83217051FF}" = Java 7 Update 51
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1" = lightshot-5.1.0.15
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{4260CAAE-D108-4223-A1C5-96B67062FE86}" = Windows Live Installer
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47E808C7-0C07-4DF8-877F-7FD653DCDE7B}_is1" = The Wolf Among Us čeština verze 2.0
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4B407A54-6CF2-42B5-B419-E900B2E36972}" = 1500
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4f754127-35a3-463c-9b09-dbb8370af1de}" = Aplikace Intel® PROSet/Wireless
"{50AB145B-C607-470B-AEE8-46B683322A59}" = Intel(R) Rapid Storage Technology
"{59307833-CB98-4440-B644-0CD352F61907}" = Windows Live PIMT Platform
"{5C1D9C2A-B542-4A21-94A4-783C5A4681DF}" = Photo Common
"{5FDED311-B6BA-4FE7-83C1-7D2F10A5AAE0}" = Windows Live Essentials
"{6093CCDD-5CC8-4C0D-A349-8807B58D19EE}" = Windows Live UX Platform Language Pack
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7C6CD9B4-B230-4E76-80AA-FB465FF4DE29}" = Intel(R) PROSet/Wireless WiFi Software Driver
"{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX
"{8256F87F-8554-4457-8C3D-3F3324697D9F}" = Windows Live ID Sign-in Assistant
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C22A294-DBBA-445F-B55C-E26817CCFE69}" = Movie Maker
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8F66BFDE-B213-48E2-93EF-7151277A2916}" = Windows Live SOXE Definitions
"{90150000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{90150000-0015-0405-0000-0000000FF1CE}" = Microsoft Access MUI (Czech) 2013
"{90150000-0015-0409-0000-0000000FF1CE}" = Microsoft Access MUI (English) 2013
"{90150000-0016-0405-0000-0000000FF1CE}" = Microsoft Excel MUI (Czech) 2013
"{90150000-0016-0409-0000-0000000FF1CE}" = Microsoft Excel MUI (English) 2013
"{90150000-0017-0405-0000-0000000FF1CE}" = Microsoft SharePoint Designer MUI (Czech) 2013
"{90150000-0018-0405-0000-0000000FF1CE}" = Microsoft PowerPoint MUI (Czech) 2013
"{90150000-0018-0409-0000-0000000FF1CE}" = Microsoft PowerPoint MUI (English) 2013
"{90150000-0019-0405-0000-0000000FF1CE}" = Microsoft Publisher MUI (Czech) 2013
"{90150000-0019-0409-0000-0000000FF1CE}" = Microsoft Publisher MUI (English) 2013
"{90150000-001A-0405-0000-0000000FF1CE}" = Microsoft Outlook MUI (Czech) 2013
"{90150000-001A-0409-0000-0000000FF1CE}" = Microsoft Outlook MUI (English) 2013
"{90150000-001B-0405-0000-0000000FF1CE}" = Microsoft Word MUI (Czech) 2013
"{90150000-001B-0409-0000-0000000FF1CE}" = Microsoft Word MUI (English) 2013
"{90150000-001F-0405-0000-0000000FF1CE}" = Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština
"{90150000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch
"{90150000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-0000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office - Français
"{90150000-001F-041B-0000-0000000FF1CE}" = Nástroje korektúry balíka Microsoft Office 2013 - slovenčina
"{90150000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español
"{90150000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2013
"{90150000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2013
"{90150000-0044-0405-0000-0000000FF1CE}" = Microsoft InfoPath MUI (Czech) 2013
"{90150000-0044-0409-0000-0000000FF1CE}" = Microsoft InfoPath MUI (English) 2013
"{90150000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2013
"{90150000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2013
"{90150000-0090-0405-0000-0000000FF1CE}" = Microsoft DCF MUI (Czech) 2013
"{90150000-0090-0409-0000-0000000FF1CE}" = Microsoft DCF MUI (English) 2013
"{90150000-00A1-0405-0000-0000000FF1CE}" = Microsoft OneNote MUI (Czech) 2013
"{90150000-00A1-0409-0000-0000000FF1CE}" = Microsoft OneNote MUI (English) 2013
"{90150000-00BA-0405-0000-0000000FF1CE}" = Microsoft Groove MUI (Czech) 2013
"{90150000-00BA-0409-0000-0000000FF1CE}" = Microsoft Groove MUI (English) 2013
"{90150000-00E1-0405-0000-0000000FF1CE}" = Microsoft Office OSM MUI (Czech) 2013
"{90150000-00E1-0409-0000-0000000FF1CE}" = Microsoft Office OSM MUI (English) 2013
"{90150000-00E2-0405-0000-0000000FF1CE}" = Microsoft Office OSM UX MUI (Czech) 2013
"{90150000-00E2-0409-0000-0000000FF1CE}" = Microsoft Office OSM UX MUI (English) 2013
"{90150000-0100-0405-0000-0000000FF1CE}" = Microsoft Office O MUI (Czech) 2013
"{90150000-0101-0405-0000-0000000FF1CE}" = Microsoft X MUI (Czech) 2013
"{90150000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2013
"{90150000-0117-0409-0000-0000000FF1CE}" = Microsoft Access Setup Metadata MUI (English) 2013
"{90150000-012B-0405-0000-0000000FF1CE}" = Microsoft Lync MUI (Czech) 2013
"{90150000-012B-0409-0000-0000000FF1CE}" = Microsoft Lync MUI (English) 2013
"{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}" = Onekey Theater
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029" = Microsoft .NET Framework 4.5.1 (čeština)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{94532CD5-C66D-49E3-9131-5FB04D7647A1}" = Windows Live UX Platform
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{959B7F35-2819-40C5-A0CD-3C53B5FCC935}" = Genesys USB Mass Storage Device
"{983FA94A-A7DD-40B1-B7F9-F45D2B4FD1DE}" = Windows Live Photo Common
"{9A0C0A74-8AC8-4216-8E1F-B9AD2E14C950}" = Movie Maker
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{A2101ACC-DC36-42AA-A576-6FD6A8D466DA}" = 1500_Help
"{A407FC22-36BF-4C82-A516-59D94BC505A9}" = System Requirements Lab Detection
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4C6B32D-5088-40AF-B74D-CDABEF144F04}" = 1500Trb
"{A5457401-D56A-43F2-9524-78E54A7FC07A}" = SlimDrivers
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A94C50AA-21E8-4627-ADD0-E16A07030D7D}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
"{A9FFEC6C-9C44-4597-8E23-EDD78BF5D0B2}" = Windows Live Communications Platform
"{ABADE36E-EC37-413B-8179-B432AD3FACE7}" = Battlefield 4™
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Czech
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 334.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 334.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.2.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.13.1220
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.20
"{B4299C72-D4BF-4F29-A5A6-63294B1C0368}" = Fotogalerie
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{BB285C9F-C821-4770-8970-56C4AB52C87E}" = Skype Click to Call
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C87DF7BB-4F5C-4BBE-B041-A59FFF4A1D07}" = Windows Live SOXE
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.11.326
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DEF50764-F1A7-4DD4-B8BA-C81A4807631A}" = Intel® PROSet/Wireless WiFi Software
"{DF7DC45D-8A3C-490C-A70F-8C6A6189EDF9}" = Photo Gallery
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}" = Lenovo EasyCamera
"{E0E5B250-5C80-45ED-9AAB-829655B3E39D}_is1" = "Need for Speed Rivals"
"{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F14B8ECC-BDA0-4987-9201-D7B7DBE11029}" = Nero 7 Premium
"{F2B5A2A7-2DF9-4361-8BD5-362714528B51}" = NHL® 09
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Avast" = avast! Free Antivirus
"BitLord" = BitLord 1.1
"CCleaner" = CCleaner
"CrystalDiskInfo_is1" = CrystalDiskInfo 6.1.10
"DAEMON Tools Lite" = DAEMON Tools Lite
"Fraps" = Fraps (remove only)
"Google Chrome" = Google Chrome
"Handset WinDriver" = Handset WinDriver 1.02.03.00
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.75.0.1300
"Office15.OMUI.cs-cz" = Microsoft Office Language Pack 2013 - Czech/čeština
"Office15.PROPLUS" = Microsoft Office Professional Plus 2013
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"Shop for HP Supplies" = Shop for HP Supplies
"Steam" = Steam
"The Walking Dead Season2 Episode1 1.0.0" = The Walking Dead Season2 Episode1
"Uplay" = Uplay
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 5.01 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"OneDriveSetup.exe" = Microsoft OneDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10.4.2014 9:54:18 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\BitLord\downloads\need.for.speed.rivals.v1.3.0.0.update.and.no.origin.x86.and.x64.crack-3dm\Crack\NFS14.exe
se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 10.4.2014 9:54:19 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\BitLord\downloads\need.for.speed.rivals.v1.3.0.0.update.and.no.origin.x86.and.x64.crack-3dm\Update\NFS14.exe
se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 10.4.2014 9:55:59 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\electronic arts\need
for speed rivals\NFS14.exe se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 10.4.2014 11:53:49 | Computer Name = Michal | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10.4.2014 12:43:07 | Computer Name = Michal | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 11.4.2014 12:18:20 | Computer Name = Michal | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 11.4.2014 13:38:26 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\BitLord\downloads\need.for.speed.rivals.v1.3.0.0.update.and.no.origin.x86.and.x64.crack-3dm\Crack\NFS14.exe
se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 11.4.2014 13:38:26 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\BitLord\downloads\need.for.speed.rivals.v1.3.0.0.update.and.no.origin.x86.and.x64.crack-3dm\Update\NFS14.exe
se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 11.4.2014 13:39:25 | Computer Name = Michal | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro c:\program files\electronic arts\need
for speed rivals\NFS14.exe se nezdařilo. Závislé sestavení Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error - 12.4.2014 5:00:37 | Computer Name = Michal | Source = Customer Experience Improvement Program | ID = 1008
Description =

[ System Events ]
Error - 7.4.2014 11:47:23 | Computer Name = Michal | Source = DCOM | ID = 10001
Description =

Error - 7.4.2014 14:00:39 | Computer Name = Michal | Source = Service Control Manager | ID = 7024
Description = Služba Windows Search ukončena s chybou %%-1073473535, specifickou
pro službu.

Error - 7.4.2014 14:00:39 | Computer Name = Michal | Source = Service Control Manager | ID = 7031
Description = Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát.
Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error - 7.4.2014 14:00:48 | Computer Name = Michal | Source = DCOM | ID = 10005
Description =

Error - 7.4.2014 14:00:48 | Computer Name = Michal | Source = Service Control Manager | ID = 7009
Description = Při čekání na připojení služby Windows Search bylo dosaženo časového
limitu (30000 ms).

Error - 7.4.2014 14:00:48 | Computer Name = Michal | Source = Service Control Manager | ID = 7000
Description = Služba Windows Search neuspěla při spuštění v důsledku následující
chyby: %%1053

Error - 7.4.2014 14:48:29 | Computer Name = Michal | Source = DCOM | ID = 10001
Description =

Error - 8.4.2014 7:53:54 | Computer Name = Michal | Source = DCOM | ID = 10001
Description =

Error - 9.4.2014 9:23:38 | Computer Name = Michal | Source = DCOM | ID = 10001
Description =

Error - 11.4.2014 12:13:31 | Computer Name = Michal | Source = DCOM | ID = 10001
Description =


< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 13 dub 2014 10:11

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: %7B4e38134d-ba98-4066-b898-e296d8acc938%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7BD394D188-BAC7-4e03-8FAF-389A4D7EC6F4%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7Bea614400-e918-4741-9a97-7a972ff7c30b%7D:2.5.16
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll File not found
[2014.02.21 22:23:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Extensions
[2014.04.07 19:55:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions
[2014.03.05 17:09:41 | 000,000,000 | ---D | M] (SeArch-NewTaB) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\fcdsc8@sjeye.com
[2014.03.05 17:09:41 | 000,060,290 | ---- | M] () (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\translator@zoli.bod.xpi
[2014.03.17 20:28:10 | 000,001,781 | ---- | M] () (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{4e38134d-ba98-4066-b898-e296d8acc938}.xpi
[2014.02.26 17:12:03 | 000,957,290 | ---- | M] () (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.03.17 20:28:10 | 000,009,948 | ---- | M] () (No name found) -- C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{D394D188-BAC7-4e03-8FAF-389A4D7EC6F4}.xpi
[2014.04.07 19:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
File not found (No name found) -- C:\USERS\MICHAL KALENSKĂ˝\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FU3RMJQU.DEFAULT\EXTENSIONS\{4E38134D-BA98-4066-B898-E296D8ACC938}.XPI
File not found (No name found) -- C:\USERS\MICHAL KALENSKĂ˝\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FU3RMJQU.DEFAULT\EXTENSIONS\{D394D188-BAC7-4E03-8FAF-389A4D7EC6F4}.XPI
File not found (No name found) -- C:\USERS\MICHAL KALENSKĂ˝\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FU3RMJQU.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\USERS\MICHAL KALENSKĂ˝\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FU3RMJQU.DEFAULT\EXTENSIONS\TRANSLATOR@ZOLI.BOD.XPI
CHR - Extension: No name found = C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\
CHR - Extension: No name found = C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Users\Michal Kalenský\AppData\Roaming\AVG
C:\ProgramData\AVG
C:\Qoobox
C:\ProgramData\Sun
C:\Program Files\KMSpico
C:\Users\Michal Kalenský\AppData\Roaming\D394D188-BAC7-4e03-8FAF-389A4D7EC6F4
C:\Users\Michal Kalenský\AppData\Roaming\inst.exe

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Windows\System32\acumncyqwsr.exe
C:\Windows\System32\zlib1.dll
C:\Windows\System32\scrypt130511.cl
C:\Windows\System32\libidn-11.dll
C:\Windows\System32\librtmp.dll
C:\Windows\System32\poclbm130302.cl
C:\Windows\System32\phatk121016.cl
C:\Windows\System32\libcurl-4.dll
C:\Windows\System32\diablo130302.cl
C:\Windows\System32\diakgcn121016.cl
C:\Windows\System32\NoMSGuninstall.exe
C:\Windows\System32\_IconCfg0.ini
C:\Windows\System32\IconCfg0.ini
C:\ProgramData\DP45977C.lfl
C:\Windows\System32\DPTopologyApp.exe
C:\Windows\System32\GfxRes.dll
C:\Windows\System32\GfxUIEx.exe.config
C:\Windows\System32\GfxUIHotKeyMenu.exe.config

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod Michalkalensky » 13 dub 2014 12:29

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Prefs.js: translator%40zoli.bod:2.1.0.3 removed from extensions.enabledAddons
Prefs.js: %7B4e38134d-ba98-4066-b898-e296d8acc938%7D:1.0 removed from extensions.enabledAddons
Prefs.js: %7BD394D188-BAC7-4e03-8FAF-389A4D7EC6F4%7D:1.0 removed from extensions.enabledAddons
Prefs.js: %7Bea614400-e918-4741-9a97-7a972ff7c30b%7D:2.5.16 removed from extensions.enabledAddons
Prefs.js: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 removed from extensions.enabledAddons
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Extensions folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\fcdsc8@sjeye.com\content folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\fcdsc8@sjeye.com folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions folder moved successfully.
Folder C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\fcdsc8@sjeye.com\ not found.
File C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\translator@zoli.bod.xpi not found.
File C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{4e38134d-ba98-4066-b898-e296d8acc938}.xpi not found.
File C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi not found.
File C:\Users\Michal Kalenský\AppData\Roaming\Mozilla\Firefox\Profiles\fu3rmjqu.default\extensions\{D394D188-BAC7-4e03-8FAF-389A4D7EC6F4}.xpi not found.
C:\Program Files\Mozilla Firefox\browser\extensions folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\zh_TW folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\zh_CN folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\vi folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\uk folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\tr folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\th folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\sw folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\sv folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\sr folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\sl folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\sk folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ru folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ro folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\pt_PT folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\pt_BR folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\pl folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\no folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\nl folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ms folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\lv folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\lt folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ko folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ja folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\iw folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\it folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\id folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\hu folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\hr folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\hi folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\fr folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\fil folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\fi folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\fa folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\et folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\es_419 folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\es folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\en_GB folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\en folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\el folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\de folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\da folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\cs folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ca folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\bg folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\ar folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales\am folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\_locales folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0\i18n folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14143.1351_0 folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\zh_TW folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\zh_CN folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\ru folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\pt_PT folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\pt_BR folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\pl folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\nl folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\ko folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\ja folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\it folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\fr folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\es_419 folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\es folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\en folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales\de folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\_locales folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\assets folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\localization folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\j folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\i\ic_social\16px folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\i\ic_social folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\i\gsf folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\i folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_thin_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_thin_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_thinitalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_thinitalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_semibold_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_semibold_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_semibolditalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_semibolditalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_regular_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_regular_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_light_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_light_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_lightitalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_lightitalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_italic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_italic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_extrabold_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_extrabold_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_extrabolditalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_extrabolditalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_bold_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_bold_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_bolditalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_bolditalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_black_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_black_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_blackitalic_macroman\specimen_files folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f\proximanova_blackitalic_macroman folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c\f folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a\c folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0\a folder moved successfully.
C:\Users\Michal Kalenský\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk\0.701_0 folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
C:\WINDOWS\msdownld.tmp folder moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
c:\windows\Tasks\SlimDrivers Startup.job moved successfully.
c:\windows\Tasks\update-S-1-5-21-1199612218-1043710064-1858448162-1000.job moved successfully.
c:\windows\Tasks\update-sys.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\Users\Michal Kalenský\AppData\Roaming\AVG\AWL2014\Dashboard folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\AVG\AWL2014\Backups folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\AVG\AWL2014 folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\AVG\AWL\CrashDumps folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\AVG\AWL folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\AVG folder moved successfully.
C:\ProgramData\AVG\AWL2014 folder moved successfully.
C:\ProgramData\AVG\AWL\Program Statistics folder moved successfully.
C:\ProgramData\AVG\AWL folder moved successfully.
C:\ProgramData\AVG folder moved successfully.
Folder move failed. C:\Qoobox\BackEnv scheduled to be moved on reboot.
C:\Qoobox folder moved successfully.
C:\ProgramData\Sun\Java\Java Update folder moved successfully.
C:\ProgramData\Sun\Java folder moved successfully.
C:\ProgramData\Sun folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\D394D188-BAC7-4e03-8FAF-389A4D7EC6F4 folder moved successfully.
C:\Users\Michal Kalenský\AppData\Roaming\inst.exe moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes

User: HomeGroupUser$
->Temp folder emptied: 0 bytes

User: Michal Kalenský
->Temp folder emptied: 4513975 bytes
->Temporary Internet Files folder emptied: 1497821 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 2805085 bytes
->Google Chrome cache emptied: 449761101 bytes
->Flash cache emptied: 740 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33686355 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 1750168 bytes

Total Files Cleaned = 471,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 04132014_114941

Files\Folders moved on Reboot...
File\Folder C:\Qoobox\BackEnv not found!
C:\Users\Michal Kalenský\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


https://www.virustotal.com/cs/file/bb17 ... 397383262/
https://www.virustotal.com/cs/file/57fd ... 397383393/
https://www.virustotal.com/cs/file/9855 ... 397383509/
https://www.virustotal.com/cs/file/49e4 ... 397383625/
https://www.virustotal.com/cs/file/b3f7 ... 397383704/
https://www.virustotal.com/cs/file/96de ... 397383772/
https://www.virustotal.com/cs/file/cae9 ... 397383837/
https://www.virustotal.com/cs/file/a899 ... 397383913/
https://www.virustotal.com/cs/file/0b01 ... 397383989/
https://www.virustotal.com/cs/file/d1bc ... 397384062/
https://www.virustotal.com/cs/file/6328 ... 397384122/
https://www.virustotal.com/cs/file/a7ed ... 397384259/
https://www.virustotal.com/cs/file/cf67 ... 397384355/
https://www.virustotal.com/cs/file/e3b0 ... 397384497/
https://www.virustotal.com/cs/file/7302 ... 397384624/
https://www.virustotal.com/cs/file/abce ... 397384725/
https://www.virustotal.com/cs/file/ff9a ... 397384845/
https://www.virustotal.com/cs/file/79cc ... 397384915/

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 14 dub 2014 09:19

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

:Files
C:\Windows\System32\acumncyqwsr.exe
C:\Windows\System32\zlib1.dll
C:\Windows\System32\scrypt130511.cl
C:\Windows\System32\poclbm130302.cl
C:\Windows\System32\phatk121016.cl
C:\Windows\System32\diakgcn121016.cl

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod Michalkalensky » 14 dub 2014 19:34

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
========== FILES ==========
C:\Windows\System32\acumncyqwsr.exe moved successfully.
C:\Windows\System32\zlib1.dll moved successfully.
C:\Windows\System32\scrypt130511.cl moved successfully.
C:\Windows\System32\poclbm130302.cl moved successfully.
C:\Windows\System32\phatk121016.cl moved successfully.
C:\Windows\System32\diakgcn121016.cl moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes

User: HomeGroupUser$
->Temp folder emptied: 0 bytes

User: Michal Kalenský
->Temp folder emptied: 105639462 bytes
->Temporary Internet Files folder emptied: 2326263 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 353013319 bytes
->Flash cache emptied: 1037 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17964241 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 181309 bytes

Total Files Cleaned = 457,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 04142014_193148

Files\Folders moved on Reboot...
File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod jaro3 » 15 dub 2014 09:18

Spusť OTL a klikni na Vyčisti.

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu

Příspěvekod Michalkalensky » 26 dub 2014 11:42

Přeinstaloval jsem si Win 7 32bit na 64bit už se to nedalo mám 8gb RAM a 32bit mě hlásil 2gb a sekalo se to z toho nedostatku RAM :) Jinak díky.

Odesláno z telefonu ;)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu  Vyřešeno

Příspěvekod Orcus » 26 dub 2014 15:08

OK, potom můžeš téma označit fajfkou jako vyřešené.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 96 hostů