Prosím o kontrolu. Se strojem se dlouho nic nedělo, je potřeba jej pročistit...
Zatím jsem provedl: čištění+registry CCleanerem, proskenování MBAM, čištění přes ATF + log HijackThis.
Děkuji předem:-)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:03:49, on 3.9.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16563)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast5\avastui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\mobsync.exe
J:\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: (no name) - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - (no file)
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2229433316-4178244195-4092863301-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O4 - Startup: Obsah aplikace OneNote.onetoc2
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate1c9a326fd1c5f6) (gupdate1c9a326fd1c5f6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
--
End of file - 8583 bytes
Prosím o kontrolu - celkové pročištění Vyřešeno
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - celkové pročištění
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
===================================================
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
===================================================
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: Prosím o kontrolu - celkové pročištění
Poznatky z chování PC:
- po startu je dlouho řerná obrazovka s kurzorem než naběhne plocha:-(
# AdwCleaner v3.309 - Report created 04/09/2014 at 16:37:39
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Eva - EVA-PC
# Running from : C:\Users\Eva\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icqplugin.xml
File Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\mywebsearch.xml
File Found : C:\Users\Adéla\daemonprocess.txt
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Askcom.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Conduit.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-3.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-4.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\mywebsearch.xml
File Found : C:\Users\Eva\daemonprocess.txt
File Found : C:\Users\Kaku\daemonprocess.txt
Folder Found : C:\Program Files\AVG Secure Search
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\Crawler
Folder Found : C:\Program Files\ICQ6Toolbar
Folder Found : C:\Program Files\Mobogenie
Folder Found : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Found : C:\Program Files\MyPC Backup
Folder Found : C:\Program Files\VideoDownloadConverter_4z
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\FileCure
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Found : C:\Users\Adéla\AppData\Local\VideoDownloadConverter_4z
Folder Found : C:\Users\Adéla\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Adéla\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Adéla\AppData\LocalLow\FunWebProducts
Folder Found : C:\Users\Adéla\AppData\LocalLow\Inbox Toolbar
Folder Found : C:\Users\Adéla\AppData\LocalLow\Internet Saving Optimizer
Folder Found : C:\Users\Adéla\AppData\LocalLow\Media Access Startup
Folder Found : C:\Users\Adéla\AppData\LocalLow\MyWebSearch
Folder Found : C:\Users\Adéla\AppData\LocalLow\VideoDownloadConverter_4z
Folder Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com
Folder Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\ICQToolbarData
Folder Found : C:\Users\Adéla\AppData\Roaming\pdfforge
Folder Found : C:\Users\Eva\AppData\Local\genienext
Folder Found : C:\Users\Eva\AppData\Local\Mobogenie
Folder Found : C:\Users\Eva\AppData\Local\OpenCandy
Folder Found : C:\Users\Eva\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Eva\AppData\LocalLow\Conduit
Folder Found : C:\Users\Eva\AppData\LocalLow\Internet Saving Optimizer
Folder Found : C:\Users\Eva\AppData\LocalLow\Media Access Startup
Folder Found : C:\Users\Eva\AppData\LocalLow\MyWebSearch
Folder Found : C:\Users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
Folder Found : C:\Users\Eva\AppData\Roaming\Babylon
Folder Found : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Found : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\ICQToolbarData
Folder Found : C:\Users\Eva\AppData\Roaming\newnext.me
Folder Found : C:\Users\Eva\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Eva\AppData\Roaming\pdfforge
Folder Found : C:\Users\Eva\Documents\Mobogenie
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Found : C:\Users\Kaku\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Kaku\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Public\Documents\AlawarWrapper
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\DoubleD
Key Found : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Found : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Found : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Found : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Found : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Found : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\BI
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mobogenie
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\MyWebSearch
Key Found : HKCU\Software\ParetoLogic
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\AVG Secure Search
Key Found : HKLM\SOFTWARE\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Fun Web Products
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Found : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Found : HKLM\SOFTWARE\MyWebSearch
Key Found : HKLM\SOFTWARE\Tarma Installer
Key Found : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{48586425-6BB7-4F51-8DC6-38C88E3EBB58}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4zffxtbr@VideoDownloadConverter_4z.com]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js ]
Line Found : user_pref("browser.search.defaultengine", "Ask.com");
Line Found : user_pref("browser.search.order.1", "Ask.com");
Line Found : user_pref("browser.search.selectedEngine", "Ask.com");
Line Found : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Found : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir[...]
Line Found : user_pref("extensions.enabledItems", "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{4B3803EA-5230-4DC3-A7FC-336[...]
Line Found : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCman000&ptb=f4QqUC5BF15QlOyD0zmmQw");
Line Found : user_pref("extensions.mywebsearch.prevDefaultEngine", "AVG Secure Search");
Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Found : user_pref("extensions.mywebsearch.prevSelectedEngine", "AVG Secure Search");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2012111713");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "HJxdm073YYcz");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "pconverter");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "31D2536B-8AC9-4AEF-9501-27BC0AC7D40A");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1403109881881");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.searchHistory", "facebook.com");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "videodownloadconverter@mindspark.com");
Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Found : user_pref("icqtoolbar.allowSendURL", false);
Line Found : user_pref("icqtoolbar.engineVerified", false);
Line Found : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Found : user_pref("icqtoolbar.history", "seznam");
Line Found : user_pref("icqtoolbar.numberOfSearches", 0);
Line Found : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Found : user_pref("icqtoolbar.skip_default_search", "no");
Line Found : user_pref("icqtoolbar.suggestions", false);
Line Found : user_pref("icqtoolbar.uniqueID", "128706460512870646041287064608024");
Line Found : user_pref("icqtoolbar.usageStatstTimestamp", 1350818370);
Line Found : user_pref("icqtoolbar.version", "1.1.5");
Line Found : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Found : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Found : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ind=2012111713&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconver[...]
[ File : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js ]
Line Found : user_pref("CT2247187.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Found : user_pref("CT2247187.CTID", "CT2247187");
Line Found : user_pref("CT2247187.Chat.Meebo.ServerLastCheckTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Found : user_pref("CT2247187.Chat.Meebo.ServerLastResponseTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.2030of7a78203f", 2);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.30plus683ec0a3", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.entertainment3d98c8ee", 1);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.healthed7eb5ea", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.marioforevercommunitychatdf56fc21", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.musicpca565a36", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.newstu0548025d", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.recreation2b6006ec", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.spirituality9440382e", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.sports84029aeb", 6);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.technology9fc01102", 1);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.travel0e02ee8e", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.videogames58dc7b74", 0);
Line Found : user_pref("CT2247187.Chat.ServerLastCheckTime", "Fri Dec 16 2011 17:04:56 GMT+0100");
Line Found : user_pref("CT2247187.CommunitiesChangesLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Found : user_pref("CT2247187.CommunityChanged", true);
Line Found : user_pref("CT2247187.DialogsAlignMode", "LTR");
Line Found : user_pref("CT2247187.DownloadDomainsCheckInterval", "168");
Line Found : user_pref("CT2247187.DownloadDomainsListLastCheckTime", "Thu Dec 15 2011 19:49:27 GMT+0100");
Line Found : user_pref("CT2247187.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Found : user_pref("CT2247187.EMailNotifierPollDate", "Fri Dec 16 2011 18:04:57 GMT+0100");
Line Found : user_pref("CT2247187.FirstTime", true);
Line Found : user_pref("CT2247187.FirstTimeFF3", true);
Line Found : user_pref("CT2247187.FixPageNotFoundErrors", true);
Line Found : user_pref("CT2247187.GroupingServerCheckInterval", 1440);
Line Found : user_pref("CT2247187.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Found : user_pref("CT2247187.Initialize", true);
Line Found : user_pref("CT2247187.InitializeCommonPrefs", true);
Line Found : user_pref("CT2247187.InstalledDate", "Fri Sep 23 2011 13:08:33 GMT+0200");
Line Found : user_pref("CT2247187.InvalidateCache", false);
Line Found : user_pref("CT2247187.IsGrouping", false);
Line Found : user_pref("CT2247187.IsMulticommunity", true);
Line Found : user_pref("CT2247187.IsOpenThankYouPage", true);
Line Found : user_pref("CT2247187.IsOpenUninstallPage", true);
Line Found : user_pref("CT2247187.LanguagePackLastCheckTime", "Thu Dec 15 2011 19:49:34 GMT+0100");
Line Found : user_pref("CT2247187.LanguagePackReloadIntervalMM", 1440);
Line Found : user_pref("CT2247187.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Found : user_pref("CT2247187.LastLogin_2.1.0.15", "Fri Dec 16 2011 17:04:55 GMT+0100");
Line Found : user_pref("CT2247187.LatestVersion", "3.8.1.0");
Line Found : user_pref("CT2247187.Locale", "en");
Line Found : user_pref("CT2247187.LoginCache", 4);
Line Found : user_pref("CT2247187.MCDetectTooltipHeight", "83");
Line Found : user_pref("CT2247187.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Found : user_pref("CT2247187.MCDetectTooltipWidth", "295");
Line Found : user_pref("CT2247187.RadioIsPodcast", false);
Line Found : user_pref("CT2247187.RadioLastCheckTime", "Thu Dec 15 2011 19:49:33 GMT+0100");
Line Found : user_pref("CT2247187.RadioLastUpdateIPServer", "3");
Line Found : user_pref("CT2247187.RadioLastUpdateServer", "128929877726170000");
Line Found : user_pref("CT2247187.RadioMediaID", "10957728");
Line Found : user_pref("CT2247187.RadioMediaType", "Media Player");
Line Found : user_pref("CT2247187.RadioMenuSelectedID", "EBRadioMenu_CT224718710957728");
Line Found : user_pref("CT2247187.RadioShrinked", "shrinked");
Line Found : user_pref("CT2247187.RadioStationName", "Rap%20(Uncensored)");
Line Found : user_pref("CT2247187.RadioStationURL", "hxxp://www.1club.fm/go/tunein.aspx?station=raw");
Line Found : user_pref("CT2247187.RadioVolume", "100");
Line Found : user_pref("CT2247187.SHRINK_TOOLBAR", 1);
Line Found : user_pref("CT2247187.SearchFromAddressBarIsInit", true);
Line Found : user_pref("CT2247187.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2247187&SearchSource=2&q=");
Line Found : user_pref("CT2247187.SettingsCheckIntervalMin", 120);
Line Found : user_pref("CT2247187.SettingsLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Found : user_pref("CT2247187.SettingsLastUpdate", "1320749725");
Line Found : user_pref("CT2247187.ThirdPartyComponentsInterval", 504);
Line Found : user_pref("CT2247187.ThirdPartyComponentsLastCheck", "Thu Dec 15 2011 19:49:26 GMT+0100");
Line Found : user_pref("CT2247187.ThirdPartyComponentsLastUpdate", "1312887586");
Line Found : user_pref("CT2247187.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Found : user_pref("CT2247187.UserID", "UN24827853259944055");
Line Found : user_pref("CT2247187.WeatherNetwork", "");
Line Found : user_pref("CT2247187.WeatherPollDate", "Fri Dec 16 2011 17:34:58 GMT+0100");
Line Found : user_pref("CT2247187.WeatherUnit", "C");
Line Found : user_pref("CT2247187.clientLogIsEnabled", true);
Line Found : user_pref("CT2247187.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Found : user_pref("CT2247187.myStuffEnabled", true);
Line Found : user_pref("CT2247187.myStuffPublihserMinWidth", 400);
Line Found : user_pref("CT2247187.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Found : user_pref("CT2247187.myStuffServiceIntervalMM", 1440);
Line Found : user_pref("CT2247187.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Found : user_pref("CT2247187.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Found : user_pref("CommunityToolbar.ToolbarsList", "CT2247187");
Line Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2247187");
Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Found : user_pref("dom.ipc.plugins.enabled.npmywebs.dll", false);
Line Found : user_pref("extensions.BabylonToolbar.admin", false);
Line Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Found : user_pref("extensions.BabylonToolbar.babExt", "");
Line Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=108758");
Line Found : user_pref("extensions.BabylonToolbar.bbDpng", 28);
Line Found : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Found : user_pref("extensions.BabylonToolbar.dfltSrch", true);
Line Found : user_pref("extensions.BabylonToolbar.hmpg", true);
Line Found : user_pref("extensions.BabylonToolbar.id", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar.instlDay", "15380");
Line Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Found : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=108758&babsrc=adbartrp&mntrId=c275a845000000000000001fd034c547&q=");
Line Found : user_pref("extensions.BabylonToolbar.lastDP", 28);
Line Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "29.0");
Line Found : user_pref("extensions.BabylonToolbar.newTab", true);
Line Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Found : user_pref("extensions.BabylonToolbar.propectorlck", 139863026);
Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Found : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Line Found : user_pref("extensions.BabylonToolbar.smplGrp", "azb");
Line Found : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Line Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108758");
Line Found : user_pref("extensions.BabylonToolbar_i.hardId", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar_i.id", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15380");
Line Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Found : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Found : user_pref("extensions.enabledItems", "wrc@avast.com:7.0.1426,ffxtlbr@babylon.com:1.2.0,{4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3,inboxcomtoolbar@inbox.com:1.2.0.0,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCB[...]
Line Found : user_pref("extensions.foxcub.prev.KWD", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&[...]
Line Found : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCxdm490YYCZ&ptb=WXjHv1pOK5nVe5O0ePPuhw&ind=2011040811&ptnrS=ZCxdm490YYCZ&si=&n=77de0c2[...]
Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Found : user_pref("icqtoolbar.allowSendURL", false);
Line Found : user_pref("icqtoolbar.engineVerified", true);
Line Found : user_pref("icqtoolbar.geolastmodified", 1346001456);
Line Found : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Found : user_pref("icqtoolbar.history", "fhs%20utb||Love||zlin.priluky.kk||facebook%20chat||facebook||PYRENEJSK%C3%9D%20OV%C4%8C%C3%81K%2C%20S%20HLADKOU%20SRST%C3%8D%20V%20OBLI%C4%8CEJI||PYRENEJSK%C3%9D%20OV%[...]
Line Found : user_pref("icqtoolbar.icqgeo", 42);
Line Found : user_pref("icqtoolbar.installTime", "1346491879");
Line Found : user_pref("icqtoolbar.installsource", "1");
Line Found : user_pref("icqtoolbar.newtab_state", "1");
Line Found : user_pref("icqtoolbar.numberOfSearches", 0);
Line Found : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Found : user_pref("icqtoolbar.skip_default_search", "no");
Line Found : user_pref("icqtoolbar.suggestions", false);
Line Found : user_pref("icqtoolbar.uniqueID", "125976343412597634341261413213301");
Line Found : user_pref("icqtoolbar.usageStatstTimestamp", 1346491883);
Line Found : user_pref("icqtoolbar.version", "1.4.7");
Line Found : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Found : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Found : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Found : user_pref("icqtoolbar.voucherWasShown", 0);
Line Found : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Found : user_pref("icqtoolbar.xmlLanguage", "cs");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://ask.com/web?q={searchTerms}&search=&qsrc=364&o=0&l=dir
Found [Search Provider] : hxxp://ww2.tiketportal.cz/?epl=asxJWeLu ... ADw&query={searchTerms}&afdToken=CooDChMI3bHO9u7juQIVQnveCh0magBZEAIYAyAAODBA76S5vpDe_YbrAVDk2sQJUO-qqA5QiPfiDlD7-ZgPUNT_mA9Q87TOD1DE5M4PUMy63A9QlLvcD1DQu9wPUM-s9g9Q_f-gEFDTv70QUKi3mxFQqbebEVCZvbURUJ69tRFQpr21EVCrvbURULS9tRFQooDxEVCh7f8TUKnu_xNQ_-q3FVCv67cVUL7l6RVQ4cLdF1C6g8UYUNauuR1Qo4L9IFDTqpEhUInCkSFQqeGRIVCq4ZEhUKHskSFQhNjtJlCF2O0mUOycrSlQhp2tKVDUsa0pUNaxrSlQtMO1KVC-w7UpUJjVyzBQmtXLMFCAh6ZRUOrxt1FQiJCTjwFQ8ej7kwFQ-buUlQFQtPvtlwFQgd2IogFQ3MjkqwFQqcrkqwFQj7WLsgFQuOrUuQFQhPzJvwFQjJfzwAFQoIvJnQNQ7orMnQNxTJhBPhasH_eCARMIgNvT9u7juQIVApfeCh25PACKkQG9ZUTgBkYR5hIZAJyFAkrmawK4Y0Rtgfuf7Pggy4YUuhwx_Q&search=1
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.0.5.292&pid=avg&sg=0&sap=hp|hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.1.0.443&pid=avg&sg=0&sap=hp
Found [Homepage] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Found [Extension] : dhjbpmkagjlnhcmdpmbagjldaknbgnff
[ File : C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Found [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[ File : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://isearch.avg.com/search?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
*************************
AdwCleaner[R0].txt - [42438 octets] - [04/09/2014 16:37:39]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [42499 octets] ##########
- po startu je dlouho řerná obrazovka s kurzorem než naběhne plocha:-(
# AdwCleaner v3.309 - Report created 04/09/2014 at 16:37:39
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Eva - EVA-PC
# Running from : C:\Users\Eva\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icqplugin.xml
File Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\mywebsearch.xml
File Found : C:\Users\Adéla\daemonprocess.txt
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Askcom.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Conduit.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-3.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-4.xml
File Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\mywebsearch.xml
File Found : C:\Users\Eva\daemonprocess.txt
File Found : C:\Users\Kaku\daemonprocess.txt
Folder Found : C:\Program Files\AVG Secure Search
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\Crawler
Folder Found : C:\Program Files\ICQ6Toolbar
Folder Found : C:\Program Files\Mobogenie
Folder Found : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Found : C:\Program Files\MyPC Backup
Folder Found : C:\Program Files\VideoDownloadConverter_4z
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\FileCure
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Found : C:\Users\Adéla\AppData\Local\VideoDownloadConverter_4z
Folder Found : C:\Users\Adéla\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Adéla\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Adéla\AppData\LocalLow\FunWebProducts
Folder Found : C:\Users\Adéla\AppData\LocalLow\Inbox Toolbar
Folder Found : C:\Users\Adéla\AppData\LocalLow\Internet Saving Optimizer
Folder Found : C:\Users\Adéla\AppData\LocalLow\Media Access Startup
Folder Found : C:\Users\Adéla\AppData\LocalLow\MyWebSearch
Folder Found : C:\Users\Adéla\AppData\LocalLow\VideoDownloadConverter_4z
Folder Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com
Folder Found : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\ICQToolbarData
Folder Found : C:\Users\Adéla\AppData\Roaming\pdfforge
Folder Found : C:\Users\Eva\AppData\Local\genienext
Folder Found : C:\Users\Eva\AppData\Local\Mobogenie
Folder Found : C:\Users\Eva\AppData\Local\OpenCandy
Folder Found : C:\Users\Eva\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Eva\AppData\LocalLow\Conduit
Folder Found : C:\Users\Eva\AppData\LocalLow\Internet Saving Optimizer
Folder Found : C:\Users\Eva\AppData\LocalLow\Media Access Startup
Folder Found : C:\Users\Eva\AppData\LocalLow\MyWebSearch
Folder Found : C:\Users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
Folder Found : C:\Users\Eva\AppData\Roaming\Babylon
Folder Found : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Found : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Found : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\ICQToolbarData
Folder Found : C:\Users\Eva\AppData\Roaming\newnext.me
Folder Found : C:\Users\Eva\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Eva\AppData\Roaming\pdfforge
Folder Found : C:\Users\Eva\Documents\Mobogenie
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Found : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Found : C:\Users\Kaku\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Kaku\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Public\Documents\AlawarWrapper
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\DoubleD
Key Found : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Found : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Found : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Found : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Found : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Found : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\BI
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mobogenie
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\MyWebSearch
Key Found : HKCU\Software\ParetoLogic
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\AVG Secure Search
Key Found : HKLM\SOFTWARE\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Found : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Fun Web Products
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Found : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Found : HKLM\SOFTWARE\MyWebSearch
Key Found : HKLM\SOFTWARE\Tarma Installer
Key Found : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{48586425-6BB7-4F51-8DC6-38C88E3EBB58}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4zffxtbr@VideoDownloadConverter_4z.com]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] - hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js ]
Line Found : user_pref("browser.search.defaultengine", "Ask.com");
Line Found : user_pref("browser.search.order.1", "Ask.com");
Line Found : user_pref("browser.search.selectedEngine", "Ask.com");
Line Found : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Found : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir[...]
Line Found : user_pref("extensions.enabledItems", "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{4B3803EA-5230-4DC3-A7FC-336[...]
Line Found : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCman000&ptb=f4QqUC5BF15QlOyD0zmmQw");
Line Found : user_pref("extensions.mywebsearch.prevDefaultEngine", "AVG Secure Search");
Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Found : user_pref("extensions.mywebsearch.prevSelectedEngine", "AVG Secure Search");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2012111713");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "HJxdm073YYcz");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "pconverter");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "31D2536B-8AC9-4AEF-9501-27BC0AC7D40A");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1403109881881");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.searchHistory", "facebook.com");
Line Found : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "videodownloadconverter@mindspark.com");
Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Found : user_pref("icqtoolbar.allowSendURL", false);
Line Found : user_pref("icqtoolbar.engineVerified", false);
Line Found : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Found : user_pref("icqtoolbar.history", "seznam");
Line Found : user_pref("icqtoolbar.numberOfSearches", 0);
Line Found : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Found : user_pref("icqtoolbar.skip_default_search", "no");
Line Found : user_pref("icqtoolbar.suggestions", false);
Line Found : user_pref("icqtoolbar.uniqueID", "128706460512870646041287064608024");
Line Found : user_pref("icqtoolbar.usageStatstTimestamp", 1350818370);
Line Found : user_pref("icqtoolbar.version", "1.1.5");
Line Found : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Found : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Found : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ind=2012111713&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconver[...]
[ File : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js ]
Line Found : user_pref("CT2247187.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Found : user_pref("CT2247187.CTID", "CT2247187");
Line Found : user_pref("CT2247187.Chat.Meebo.ServerLastCheckTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Found : user_pref("CT2247187.Chat.Meebo.ServerLastResponseTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.2030of7a78203f", 2);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.30plus683ec0a3", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.entertainment3d98c8ee", 1);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.healthed7eb5ea", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.marioforevercommunitychatdf56fc21", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.musicpca565a36", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.newstu0548025d", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.recreation2b6006ec", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.spirituality9440382e", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.sports84029aeb", 6);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.technology9fc01102", 1);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.travel0e02ee8e", 0);
Line Found : user_pref("CT2247187.Chat.Meebo.rooms.videogames58dc7b74", 0);
Line Found : user_pref("CT2247187.Chat.ServerLastCheckTime", "Fri Dec 16 2011 17:04:56 GMT+0100");
Line Found : user_pref("CT2247187.CommunitiesChangesLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Found : user_pref("CT2247187.CommunityChanged", true);
Line Found : user_pref("CT2247187.DialogsAlignMode", "LTR");
Line Found : user_pref("CT2247187.DownloadDomainsCheckInterval", "168");
Line Found : user_pref("CT2247187.DownloadDomainsListLastCheckTime", "Thu Dec 15 2011 19:49:27 GMT+0100");
Line Found : user_pref("CT2247187.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Found : user_pref("CT2247187.EMailNotifierPollDate", "Fri Dec 16 2011 18:04:57 GMT+0100");
Line Found : user_pref("CT2247187.FirstTime", true);
Line Found : user_pref("CT2247187.FirstTimeFF3", true);
Line Found : user_pref("CT2247187.FixPageNotFoundErrors", true);
Line Found : user_pref("CT2247187.GroupingServerCheckInterval", 1440);
Line Found : user_pref("CT2247187.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Found : user_pref("CT2247187.Initialize", true);
Line Found : user_pref("CT2247187.InitializeCommonPrefs", true);
Line Found : user_pref("CT2247187.InstalledDate", "Fri Sep 23 2011 13:08:33 GMT+0200");
Line Found : user_pref("CT2247187.InvalidateCache", false);
Line Found : user_pref("CT2247187.IsGrouping", false);
Line Found : user_pref("CT2247187.IsMulticommunity", true);
Line Found : user_pref("CT2247187.IsOpenThankYouPage", true);
Line Found : user_pref("CT2247187.IsOpenUninstallPage", true);
Line Found : user_pref("CT2247187.LanguagePackLastCheckTime", "Thu Dec 15 2011 19:49:34 GMT+0100");
Line Found : user_pref("CT2247187.LanguagePackReloadIntervalMM", 1440);
Line Found : user_pref("CT2247187.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Found : user_pref("CT2247187.LastLogin_2.1.0.15", "Fri Dec 16 2011 17:04:55 GMT+0100");
Line Found : user_pref("CT2247187.LatestVersion", "3.8.1.0");
Line Found : user_pref("CT2247187.Locale", "en");
Line Found : user_pref("CT2247187.LoginCache", 4);
Line Found : user_pref("CT2247187.MCDetectTooltipHeight", "83");
Line Found : user_pref("CT2247187.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Found : user_pref("CT2247187.MCDetectTooltipWidth", "295");
Line Found : user_pref("CT2247187.RadioIsPodcast", false);
Line Found : user_pref("CT2247187.RadioLastCheckTime", "Thu Dec 15 2011 19:49:33 GMT+0100");
Line Found : user_pref("CT2247187.RadioLastUpdateIPServer", "3");
Line Found : user_pref("CT2247187.RadioLastUpdateServer", "128929877726170000");
Line Found : user_pref("CT2247187.RadioMediaID", "10957728");
Line Found : user_pref("CT2247187.RadioMediaType", "Media Player");
Line Found : user_pref("CT2247187.RadioMenuSelectedID", "EBRadioMenu_CT224718710957728");
Line Found : user_pref("CT2247187.RadioShrinked", "shrinked");
Line Found : user_pref("CT2247187.RadioStationName", "Rap%20(Uncensored)");
Line Found : user_pref("CT2247187.RadioStationURL", "hxxp://www.1club.fm/go/tunein.aspx?station=raw");
Line Found : user_pref("CT2247187.RadioVolume", "100");
Line Found : user_pref("CT2247187.SHRINK_TOOLBAR", 1);
Line Found : user_pref("CT2247187.SearchFromAddressBarIsInit", true);
Line Found : user_pref("CT2247187.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2247187&SearchSource=2&q=");
Line Found : user_pref("CT2247187.SettingsCheckIntervalMin", 120);
Line Found : user_pref("CT2247187.SettingsLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Found : user_pref("CT2247187.SettingsLastUpdate", "1320749725");
Line Found : user_pref("CT2247187.ThirdPartyComponentsInterval", 504);
Line Found : user_pref("CT2247187.ThirdPartyComponentsLastCheck", "Thu Dec 15 2011 19:49:26 GMT+0100");
Line Found : user_pref("CT2247187.ThirdPartyComponentsLastUpdate", "1312887586");
Line Found : user_pref("CT2247187.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Found : user_pref("CT2247187.UserID", "UN24827853259944055");
Line Found : user_pref("CT2247187.WeatherNetwork", "");
Line Found : user_pref("CT2247187.WeatherPollDate", "Fri Dec 16 2011 17:34:58 GMT+0100");
Line Found : user_pref("CT2247187.WeatherUnit", "C");
Line Found : user_pref("CT2247187.clientLogIsEnabled", true);
Line Found : user_pref("CT2247187.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Found : user_pref("CT2247187.myStuffEnabled", true);
Line Found : user_pref("CT2247187.myStuffPublihserMinWidth", 400);
Line Found : user_pref("CT2247187.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Found : user_pref("CT2247187.myStuffServiceIntervalMM", 1440);
Line Found : user_pref("CT2247187.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Found : user_pref("CT2247187.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Found : user_pref("CommunityToolbar.ToolbarsList", "CT2247187");
Line Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2247187");
Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Found : user_pref("dom.ipc.plugins.enabled.npmywebs.dll", false);
Line Found : user_pref("extensions.BabylonToolbar.admin", false);
Line Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Found : user_pref("extensions.BabylonToolbar.babExt", "");
Line Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=108758");
Line Found : user_pref("extensions.BabylonToolbar.bbDpng", 28);
Line Found : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Found : user_pref("extensions.BabylonToolbar.dfltSrch", true);
Line Found : user_pref("extensions.BabylonToolbar.hmpg", true);
Line Found : user_pref("extensions.BabylonToolbar.id", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar.instlDay", "15380");
Line Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Found : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=108758&babsrc=adbartrp&mntrId=c275a845000000000000001fd034c547&q=");
Line Found : user_pref("extensions.BabylonToolbar.lastDP", 28);
Line Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "29.0");
Line Found : user_pref("extensions.BabylonToolbar.newTab", true);
Line Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Found : user_pref("extensions.BabylonToolbar.propectorlck", 139863026);
Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Found : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Line Found : user_pref("extensions.BabylonToolbar.smplGrp", "azb");
Line Found : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Line Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108758");
Line Found : user_pref("extensions.BabylonToolbar_i.hardId", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar_i.id", "c275a845000000000000001fd034c547");
Line Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15380");
Line Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Found : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:28:34");
Line Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Found : user_pref("extensions.enabledItems", "wrc@avast.com:7.0.1426,ffxtlbr@babylon.com:1.2.0,{4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3,inboxcomtoolbar@inbox.com:1.2.0.0,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCB[...]
Line Found : user_pref("extensions.foxcub.prev.KWD", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&[...]
Line Found : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCxdm490YYCZ&ptb=WXjHv1pOK5nVe5O0ePPuhw&ind=2011040811&ptnrS=ZCxdm490YYCZ&si=&n=77de0c2[...]
Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Found : user_pref("icqtoolbar.allowSendURL", false);
Line Found : user_pref("icqtoolbar.engineVerified", true);
Line Found : user_pref("icqtoolbar.geolastmodified", 1346001456);
Line Found : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Found : user_pref("icqtoolbar.history", "fhs%20utb||Love||zlin.priluky.kk||facebook%20chat||facebook||PYRENEJSK%C3%9D%20OV%C4%8C%C3%81K%2C%20S%20HLADKOU%20SRST%C3%8D%20V%20OBLI%C4%8CEJI||PYRENEJSK%C3%9D%20OV%[...]
Line Found : user_pref("icqtoolbar.icqgeo", 42);
Line Found : user_pref("icqtoolbar.installTime", "1346491879");
Line Found : user_pref("icqtoolbar.installsource", "1");
Line Found : user_pref("icqtoolbar.newtab_state", "1");
Line Found : user_pref("icqtoolbar.numberOfSearches", 0);
Line Found : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Found : user_pref("icqtoolbar.skip_default_search", "no");
Line Found : user_pref("icqtoolbar.suggestions", false);
Line Found : user_pref("icqtoolbar.uniqueID", "125976343412597634341261413213301");
Line Found : user_pref("icqtoolbar.usageStatstTimestamp", 1346491883);
Line Found : user_pref("icqtoolbar.version", "1.4.7");
Line Found : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Found : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Found : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Found : user_pref("icqtoolbar.voucherWasShown", 0);
Line Found : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Found : user_pref("icqtoolbar.xmlLanguage", "cs");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://ask.com/web?q={searchTerms}&search=&qsrc=364&o=0&l=dir
Found [Search Provider] : hxxp://ww2.tiketportal.cz/?epl=asxJWeLu ... ADw&query={searchTerms}&afdToken=CooDChMI3bHO9u7juQIVQnveCh0magBZEAIYAyAAODBA76S5vpDe_YbrAVDk2sQJUO-qqA5QiPfiDlD7-ZgPUNT_mA9Q87TOD1DE5M4PUMy63A9QlLvcD1DQu9wPUM-s9g9Q_f-gEFDTv70QUKi3mxFQqbebEVCZvbURUJ69tRFQpr21EVCrvbURULS9tRFQooDxEVCh7f8TUKnu_xNQ_-q3FVCv67cVUL7l6RVQ4cLdF1C6g8UYUNauuR1Qo4L9IFDTqpEhUInCkSFQqeGRIVCq4ZEhUKHskSFQhNjtJlCF2O0mUOycrSlQhp2tKVDUsa0pUNaxrSlQtMO1KVC-w7UpUJjVyzBQmtXLMFCAh6ZRUOrxt1FQiJCTjwFQ8ej7kwFQ-buUlQFQtPvtlwFQgd2IogFQ3MjkqwFQqcrkqwFQj7WLsgFQuOrUuQFQhPzJvwFQjJfzwAFQoIvJnQNQ7orMnQNxTJhBPhasH_eCARMIgNvT9u7juQIVApfeCh25PACKkQG9ZUTgBkYR5hIZAJyFAkrmawK4Y0Rtgfuf7Pggy4YUuhwx_Q&search=1
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.0.5.292&pid=avg&sg=0&sap=hp|hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Found [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.1.0.443&pid=avg&sg=0&sap=hp
Found [Homepage] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Found [Extension] : dhjbpmkagjlnhcmdpmbagjldaknbgnff
[ File : C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Found [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[ File : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://isearch.avg.com/search?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
*************************
AdwCleaner[R0].txt - [42438 octets] - [04/09/2014 16:37:39]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [42499 octets] ##########
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - celkové pročištění
Avast5 stará verze , zaktualizuj progra,
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu - celkové pročištění
Ale Avast mi normálně hlýsá, že je aktuální... Kontroloval jsem to...
Log z ADWcleaner:
================
# AdwCleaner v3.309 - Report created 04/09/2014 at 21:18:01
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Eva - EVA-PC
# Running from : C:\Users\Eva\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\FileCure
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Crawler
Folder Deleted : C:\Program Files\ICQ6Toolbar
Folder Deleted : C:\Program Files\Mobogenie
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\VideoDownloadConverter_4z
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Adéla\AppData\Local\VideoDownloadConverter_4z
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Inbox Toolbar
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Media Access Startup
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\VideoDownloadConverter_4z
Folder Deleted : C:\Users\Adéla\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Eva\AppData\Local\genienext
Folder Deleted : C:\Users\Eva\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Eva\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Eva\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Media Access Startup
Folder Deleted : C:\Users\Eva\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
Folder Deleted : C:\Users\Eva\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Eva\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Eva\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Eva\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Deleted : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Eva\Documents\Mobogenie
Folder Deleted : C:\Users\Kaku\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Kaku\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\ICQToolbarData
Folder Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\ICQToolbarData
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Deleted : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
[!] Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
File Deleted : C:\Users\Adéla\daemonprocess.txt
File Deleted : C:\Users\Eva\daemonprocess.txt
File Deleted : C:\Users\Kaku\daemonprocess.txt
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\mywebsearch.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\mywebsearch.xml
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4zffxtbr@VideoDownloadConverter_4z.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{48586425-6BB7-4F51-8DC6-38C88E3EBB58}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\MyWebSearch
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\DoubleD
Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Deleted : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Fun Web Products
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\MyWebSearch
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mobogenie
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir[...]
Line Deleted : user_pref("extensions.enabledItems", "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{4B3803EA-5230-4DC3-A7FC-336[...]
Line Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCman000&ptb=f4QqUC5BF15QlOyD0zmmQw");
Line Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2012111713");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "HJxdm073YYcz");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "pconverter");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "31D2536B-8AC9-4AEF-9501-27BC0AC7D40A");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1403109881881");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.searchHistory", "facebook.com");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "videodownloadconverter@mindspark.com");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", false);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "seznam");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "128706460512870646041287064608024");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1350818370);
Line Deleted : user_pref("icqtoolbar.version", "1.1.5");
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Deleted : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ind=2012111713&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconver[...]
[ File : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js ]
Line Deleted : user_pref("CT2247187.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2247187.CTID", "CT2247187");
Line Deleted : user_pref("CT2247187.Chat.Meebo.ServerLastCheckTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.Chat.Meebo.ServerLastResponseTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.2030of7a78203f", 2);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.30plus683ec0a3", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.entertainment3d98c8ee", 1);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.healthed7eb5ea", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.marioforevercommunitychatdf56fc21", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.musicpca565a36", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.newstu0548025d", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.recreation2b6006ec", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.spirituality9440382e", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.sports84029aeb", 6);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.technology9fc01102", 1);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.travel0e02ee8e", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.videogames58dc7b74", 0);
Line Deleted : user_pref("CT2247187.Chat.ServerLastCheckTime", "Fri Dec 16 2011 17:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.CommunitiesChangesLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Deleted : user_pref("CT2247187.CommunityChanged", true);
Line Deleted : user_pref("CT2247187.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2247187.DownloadDomainsCheckInterval", "168");
Line Deleted : user_pref("CT2247187.DownloadDomainsListLastCheckTime", "Thu Dec 15 2011 19:49:27 GMT+0100");
Line Deleted : user_pref("CT2247187.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Deleted : user_pref("CT2247187.EMailNotifierPollDate", "Fri Dec 16 2011 18:04:57 GMT+0100");
Line Deleted : user_pref("CT2247187.FirstTime", true);
Line Deleted : user_pref("CT2247187.FirstTimeFF3", true);
Line Deleted : user_pref("CT2247187.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2247187.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2247187.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2247187.Initialize", true);
Line Deleted : user_pref("CT2247187.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2247187.InstalledDate", "Fri Sep 23 2011 13:08:33 GMT+0200");
Line Deleted : user_pref("CT2247187.InvalidateCache", false);
Line Deleted : user_pref("CT2247187.IsGrouping", false);
Line Deleted : user_pref("CT2247187.IsMulticommunity", true);
Line Deleted : user_pref("CT2247187.IsOpenThankYouPage", true);
Line Deleted : user_pref("CT2247187.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2247187.LanguagePackLastCheckTime", "Thu Dec 15 2011 19:49:34 GMT+0100");
Line Deleted : user_pref("CT2247187.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2247187.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2247187.LastLogin_2.1.0.15", "Fri Dec 16 2011 17:04:55 GMT+0100");
Line Deleted : user_pref("CT2247187.LatestVersion", "3.8.1.0");
Line Deleted : user_pref("CT2247187.Locale", "en");
Line Deleted : user_pref("CT2247187.LoginCache", 4);
Line Deleted : user_pref("CT2247187.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2247187.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2247187.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2247187.RadioIsPodcast", false);
Line Deleted : user_pref("CT2247187.RadioLastCheckTime", "Thu Dec 15 2011 19:49:33 GMT+0100");
Line Deleted : user_pref("CT2247187.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2247187.RadioLastUpdateServer", "128929877726170000");
Line Deleted : user_pref("CT2247187.RadioMediaID", "10957728");
Line Deleted : user_pref("CT2247187.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2247187.RadioMenuSelectedID", "EBRadioMenu_CT224718710957728");
Line Deleted : user_pref("CT2247187.RadioShrinked", "shrinked");
Line Deleted : user_pref("CT2247187.RadioStationName", "Rap%20(Uncensored)");
Line Deleted : user_pref("CT2247187.RadioStationURL", "hxxp://www.1club.fm/go/tunein.aspx?station=raw");
Line Deleted : user_pref("CT2247187.RadioVolume", "100");
Line Deleted : user_pref("CT2247187.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2247187.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2247187.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2247187&SearchSource=2&q=");
Line Deleted : user_pref("CT2247187.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2247187.SettingsLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Deleted : user_pref("CT2247187.SettingsLastUpdate", "1320749725");
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsLastCheck", "Thu Dec 15 2011 19:49:26 GMT+0100");
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsLastUpdate", "1312887586");
Line Deleted : user_pref("CT2247187.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2247187.UserID", "UN24827853259944055");
Line Deleted : user_pref("CT2247187.WeatherNetwork", "");
Line Deleted : user_pref("CT2247187.WeatherPollDate", "Fri Dec 16 2011 17:34:58 GMT+0100");
Line Deleted : user_pref("CT2247187.WeatherUnit", "C");
Line Deleted : user_pref("CT2247187.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2247187.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2247187.myStuffEnabled", true);
Line Deleted : user_pref("CT2247187.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2247187.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2247187.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2247187.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2247187.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2247187");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2247187");
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("dom.ipc.plugins.enabled.npmywebs.dll", false);
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=108758");
Line Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 28);
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", true);
Line Deleted : user_pref("extensions.BabylonToolbar.hmpg", true);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15380");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=108758&babsrc=adbartrp&mntrId=c275a845000000000000001fd034c547&q=");
Line Deleted : user_pref("extensions.BabylonToolbar.lastDP", 28);
Line Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "29.0");
Line Deleted : user_pref("extensions.BabylonToolbar.newTab", true);
Line Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 139863026);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Line Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "azb");
Line Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108758");
Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15380");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.enabledItems", "wrc@avast.com:7.0.1426,ffxtlbr@babylon.com:1.2.0,{4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3,inboxcomtoolbar@inbox.com:1.2.0.0,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCB[...]
Line Deleted : user_pref("extensions.foxcub.prev.KWD", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&[...]
Line Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCxdm490YYCZ&ptb=WXjHv1pOK5nVe5O0ePPuhw&ind=2011040811&ptnrS=ZCxdm490YYCZ&si=&n=77de0c2[...]
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1346001456);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "fhs%20utb||Love||zlin.priluky.kk||facebook%20chat||facebook||PYRENEJSK%C3%9D%20OV%C4%8C%C3%81K%2C%20S%20HLADKOU%20SRST%C3%8D%20V%20OBLI%C4%8CEJI||PYRENEJSK%C3%9D%20OV%[...]
Line Deleted : user_pref("icqtoolbar.icqgeo", 42);
Line Deleted : user_pref("icqtoolbar.installTime", "1346491879");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "125976343412597634341261413213301");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1346491883);
Line Deleted : user_pref("icqtoolbar.version", "1.4.7");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://ask.com/web?q={searchTerms}&search=&qsrc=364&o=0&l=dir
Deleted [Search Provider] : hxxp://ww2.tiketportal.cz/?epl=asxJWeLu ... ADw&query={searchTerms}&afdToken=CooDChMI3bHO9u7juQIVQnveCh0magBZEAIYAyAAODBA76S5vpDe_YbrAVDk2sQJUO-qqA5QiPfiDlD7-ZgPUNT_mA9Q87TOD1DE5M4PUMy63A9QlLvcD1DQu9wPUM-s9g9Q_f-gEFDTv70QUKi3mxFQqbebEVCZvbURUJ69tRFQpr21EVCrvbURULS9tRFQooDxEVCh7f8TUKnu_xNQ_-q3FVCv67cVUL7l6RVQ4cLdF1C6g8UYUNauuR1Qo4L9IFDTqpEhUInCkSFQqeGRIVCq4ZEhUKHskSFQhNjtJlCF2O0mUOycrSlQhp2tKVDUsa0pUNaxrSlQtMO1KVC-w7UpUJjVyzBQmtXLMFCAh6ZRUOrxt1FQiJCTjwFQ8ej7kwFQ-buUlQFQtPvtlwFQgd2IogFQ3MjkqwFQqcrkqwFQj7WLsgFQuOrUuQFQhPzJvwFQjJfzwAFQoIvJnQNQ7orMnQNxTJhBPhasH_eCARMIgNvT9u7juQIVApfeCh25PACKkQG9ZUTgBkYR5hIZAJyFAkrmawK4Y0Rtgfuf7Pggy4YUuhwx_Q&search=1
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.0.5.292&pid=avg&sg=0&sap=hp|hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.1.0.443&pid=avg&sg=0&sap=hp
Deleted [Homepage] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Deleted [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Deleted [Extension] : dhjbpmkagjlnhcmdpmbagjldaknbgnff
[ File : C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[ File : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://isearch.avg.com/search?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
*************************
AdwCleaner[R0].txt - [42580 octets] - [04/09/2014 16:37:39]
AdwCleaner[R1].txt - [42641 octets] - [04/09/2014 21:12:46]
AdwCleaner[S0].txt - [43338 octets] - [04/09/2014 21:18:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [43399 octets] ##########
Log z JRT:
=================
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Eva on źt 04.09.2014 at 21:29:53,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{780EE620-1C79-42D8-87C7-5F63D0A0874C}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files\video download converter"
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{3E1EAA2A-1078-488F-98DC-4CBD2B9D0246}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{76ABA36B-424B-4B07-942D-B320AC96F17E}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{A73581F0-C58B-4DE9-97BA-BC10FEE6A048}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{C024BDB9-9174-4324-92F8-262EEC7BC07A}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{C54E6A89-2179-4524-A3C7-C49A908E6080}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted the following from C:\Users\Eva\AppData\Roaming\mozilla\firefox\profiles\mgx5xa5t.default\prefs.js
user_pref("extensions.inboxcomtoolbar@inbox.com.update.url", "hxxp://toolbar.inbox.com/toolbar/firefox/update.aspx?version=%ITEM_VERSION%&status=%ITEM_STATUS%&appVersion=%APP_
Emptied folder: C:\Users\Eva\AppData\Roaming\mozilla\firefox\profiles\mgx5xa5t.default\minidumps [21 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 04.09.2014 at 21:42:50,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log z MBAM:
=================
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 4.9.2014
Čas skenování: 21:49:38
Protokol: mabm.txt
Správce: Ano
Verze: 2.00.2.1012
Databáze malwaru: v2014.03.04.09
Databáze rootkitů: v2014.02.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto
OS: Windows Vista Service Pack 2
CPU: x86
Souborový systém: NTFS
Uživatel: Eva
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 311374
Uplynulý čas: 35 min, 32 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(No malicious items detected)
Moduly: 0
(No malicious items detected)
Klíče registru: 0
(No malicious items detected)
Hodnoty registru: 0
(No malicious items detected)
Data registru: 0
(No malicious items detected)
Složky: 0
(No malicious items detected)
Soubory: 0
(No malicious items detected)
Fyzické sektory: 0
(No malicious items detected)
(end)
Log z RogueKiller:
=================
RogueKiller V9.2.9.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : https://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Eva [Práva správce]
Mód : Kontrola -- Datum : 09/04/2014 22:53:00
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 17 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NALEZENO
[PUM.HomePage] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> NALEZENO
¤¤¤ naplánované úlohy : 4 ¤¤¤
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_HP_rmv.job -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_TB_rmv.job -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_HP_rmv -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_TB_rmv -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> NALEZENO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
[C:\Windows\System32\drivers\etc\hosts] ::1 localhost
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] mgx5xa5t.default : user_pref("browser.startup.homepage", "www.seznam.cz"); -> NALEZENO
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD322HJ SCSI Disk Device +++++
--- User ---
[MBR] 104ba06c77ed2d7cbe799ab42f332a5b
[BSP] ebbaba802650105ad6b444168769693d : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
Log z ADWcleaner:
================
# AdwCleaner v3.309 - Report created 04/09/2014 at 21:18:01
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Eva - EVA-PC
# Running from : C:\Users\Eva\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\FileCure
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Crawler
Folder Deleted : C:\Program Files\ICQ6Toolbar
Folder Deleted : C:\Program Files\Mobogenie
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\VideoDownloadConverter_4z
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Adéla\AppData\Local\VideoDownloadConverter_4z
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Inbox Toolbar
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\Media Access Startup
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Adéla\AppData\LocalLow\VideoDownloadConverter_4z
Folder Deleted : C:\Users\Adéla\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Eva\AppData\Local\genienext
Folder Deleted : C:\Users\Eva\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Eva\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Eva\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Eva\AppData\LocalLow\Media Access Startup
Folder Deleted : C:\Users\Eva\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
Folder Deleted : C:\Users\Eva\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Eva\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Eva\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Eva\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Deleted : C:\Users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Eva\Documents\Mobogenie
Folder Deleted : C:\Users\Kaku\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Kaku\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\ICQToolbarData
Folder Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\ICQToolbarData
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
Folder Deleted : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjbpmkagjlnhcmdpmbagjldaknbgnff
Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
[!] Folder Deleted : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl
File Deleted : C:\Users\Adéla\daemonprocess.txt
File Deleted : C:\Users\Eva\daemonprocess.txt
File Deleted : C:\Users\Kaku\daemonprocess.txt
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\mywebsearch.xml
File Deleted : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\searchplugins\mywebsearch.xml
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [4zffxtbr@VideoDownloadConverter_4z.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\angobeimajilfhlcpeiccndaifchnppl
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DB507187-9746-458C-97DA-C458131EEDE7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{48586425-6BB7-4F51-8DC6-38C88E3EBB58}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\MyWebSearch
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\DoubleD
Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Deleted : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Fun Web Products
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\MyWebSearch
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mobogenie
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir[...]
Line Deleted : user_pref("extensions.enabledItems", "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{4B3803EA-5230-4DC3-A7FC-336[...]
Line Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCman000&ptb=f4QqUC5BF15QlOyD0zmmQw");
Line Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ptnrS=HJxdm073YYcz&si=pconverter");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2012111713");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "HJxdm073YYcz");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "pconverter");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "31D2536B-8AC9-4AEF-9501-27BC0AC7D40A");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1403109881881");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.searchHistory", "facebook.com");
Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "videodownloadconverter@mindspark.com");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", false);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "seznam");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "128706460512870646041287064608024");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1350818370);
Line Deleted : user_pref("icqtoolbar.version", "1.1.5");
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Deleted : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=31D2536B-8AC9-4AEF-9501-27BC0AC7D40A&n=77ee6361&ind=2012111713&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconver[...]
[ File : C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js ]
Line Deleted : user_pref("CT2247187.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2247187.CTID", "CT2247187");
Line Deleted : user_pref("CT2247187.Chat.Meebo.ServerLastCheckTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.Chat.Meebo.ServerLastResponseTime", "Fri Dec 16 2011 18:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.2030of7a78203f", 2);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.30plus683ec0a3", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.entertainment3d98c8ee", 1);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.healthed7eb5ea", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.marioforevercommunitychatdf56fc21", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.musicpca565a36", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.newstu0548025d", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.recreation2b6006ec", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.spirituality9440382e", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.sports84029aeb", 6);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.technology9fc01102", 1);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.travel0e02ee8e", 0);
Line Deleted : user_pref("CT2247187.Chat.Meebo.rooms.videogames58dc7b74", 0);
Line Deleted : user_pref("CT2247187.Chat.ServerLastCheckTime", "Fri Dec 16 2011 17:04:56 GMT+0100");
Line Deleted : user_pref("CT2247187.CommunitiesChangesLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Deleted : user_pref("CT2247187.CommunityChanged", true);
Line Deleted : user_pref("CT2247187.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2247187.DownloadDomainsCheckInterval", "168");
Line Deleted : user_pref("CT2247187.DownloadDomainsListLastCheckTime", "Thu Dec 15 2011 19:49:27 GMT+0100");
Line Deleted : user_pref("CT2247187.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Deleted : user_pref("CT2247187.EMailNotifierPollDate", "Fri Dec 16 2011 18:04:57 GMT+0100");
Line Deleted : user_pref("CT2247187.FirstTime", true);
Line Deleted : user_pref("CT2247187.FirstTimeFF3", true);
Line Deleted : user_pref("CT2247187.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2247187.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2247187.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2247187.Initialize", true);
Line Deleted : user_pref("CT2247187.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2247187.InstalledDate", "Fri Sep 23 2011 13:08:33 GMT+0200");
Line Deleted : user_pref("CT2247187.InvalidateCache", false);
Line Deleted : user_pref("CT2247187.IsGrouping", false);
Line Deleted : user_pref("CT2247187.IsMulticommunity", true);
Line Deleted : user_pref("CT2247187.IsOpenThankYouPage", true);
Line Deleted : user_pref("CT2247187.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2247187.LanguagePackLastCheckTime", "Thu Dec 15 2011 19:49:34 GMT+0100");
Line Deleted : user_pref("CT2247187.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2247187.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2247187.LastLogin_2.1.0.15", "Fri Dec 16 2011 17:04:55 GMT+0100");
Line Deleted : user_pref("CT2247187.LatestVersion", "3.8.1.0");
Line Deleted : user_pref("CT2247187.Locale", "en");
Line Deleted : user_pref("CT2247187.LoginCache", 4);
Line Deleted : user_pref("CT2247187.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2247187.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2247187.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2247187.RadioIsPodcast", false);
Line Deleted : user_pref("CT2247187.RadioLastCheckTime", "Thu Dec 15 2011 19:49:33 GMT+0100");
Line Deleted : user_pref("CT2247187.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2247187.RadioLastUpdateServer", "128929877726170000");
Line Deleted : user_pref("CT2247187.RadioMediaID", "10957728");
Line Deleted : user_pref("CT2247187.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2247187.RadioMenuSelectedID", "EBRadioMenu_CT224718710957728");
Line Deleted : user_pref("CT2247187.RadioShrinked", "shrinked");
Line Deleted : user_pref("CT2247187.RadioStationName", "Rap%20(Uncensored)");
Line Deleted : user_pref("CT2247187.RadioStationURL", "hxxp://www.1club.fm/go/tunein.aspx?station=raw");
Line Deleted : user_pref("CT2247187.RadioVolume", "100");
Line Deleted : user_pref("CT2247187.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2247187.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2247187.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2247187&SearchSource=2&q=");
Line Deleted : user_pref("CT2247187.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2247187.SettingsLastCheckTime", "Fri Dec 16 2011 17:04:53 GMT+0100");
Line Deleted : user_pref("CT2247187.SettingsLastUpdate", "1320749725");
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsLastCheck", "Thu Dec 15 2011 19:49:26 GMT+0100");
Line Deleted : user_pref("CT2247187.ThirdPartyComponentsLastUpdate", "1312887586");
Line Deleted : user_pref("CT2247187.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2247187.UserID", "UN24827853259944055");
Line Deleted : user_pref("CT2247187.WeatherNetwork", "");
Line Deleted : user_pref("CT2247187.WeatherPollDate", "Fri Dec 16 2011 17:34:58 GMT+0100");
Line Deleted : user_pref("CT2247187.WeatherUnit", "C");
Line Deleted : user_pref("CT2247187.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2247187.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2247187.myStuffEnabled", true);
Line Deleted : user_pref("CT2247187.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2247187.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2247187.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2247187.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2247187.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2247187");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2247187");
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("dom.ipc.plugins.enabled.npmywebs.dll", false);
Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=108758");
Line Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 28);
Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Line Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", true);
Line Deleted : user_pref("extensions.BabylonToolbar.hmpg", true);
Line Deleted : user_pref("extensions.BabylonToolbar.id", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15380");
Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=108758&babsrc=adbartrp&mntrId=c275a845000000000000001fd034c547&q=");
Line Deleted : user_pref("extensions.BabylonToolbar.lastDP", 28);
Line Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "29.0");
Line Deleted : user_pref("extensions.BabylonToolbar.newTab", true);
Line Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Line Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 139863026);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 1);
Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Line Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "azb");
Line Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108758");
Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "c275a845000000000000001fd034c547");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15380");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:28:34");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.enabledItems", "wrc@avast.com:7.0.1426,ffxtlbr@babylon.com:1.2.0,{4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3,inboxcomtoolbar@inbox.com:1.2.0.0,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCB[...]
Line Deleted : user_pref("extensions.foxcub.prev.KWD", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCman000&fl=0&ptb=f4QqUC5BF15QlOyD0zmmQw&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&[...]
Line Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCxdm490YYCZ&ptb=WXjHv1pOK5nVe5O0ePPuhw&ind=2011040811&ptnrS=ZCxdm490YYCZ&si=&n=77de0c2[...]
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "chrome://browser-region/locale/region.properties");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1346001456);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "fhs%20utb||Love||zlin.priluky.kk||facebook%20chat||facebook||PYRENEJSK%C3%9D%20OV%C4%8C%C3%81K%2C%20S%20HLADKOU%20SRST%C3%8D%20V%20OBLI%C4%8CEJI||PYRENEJSK%C3%9D%20OV%[...]
Line Deleted : user_pref("icqtoolbar.icqgeo", 42);
Line Deleted : user_pref("icqtoolbar.installTime", "1346491879");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.5");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "125976343412597634341261413213301");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1346491883);
Line Deleted : user_pref("icqtoolbar.version", "1.4.7");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\Adéla\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://ask.com/web?q={searchTerms}&search=&qsrc=364&o=0&l=dir
Deleted [Search Provider] : hxxp://ww2.tiketportal.cz/?epl=asxJWeLu ... ADw&query={searchTerms}&afdToken=CooDChMI3bHO9u7juQIVQnveCh0magBZEAIYAyAAODBA76S5vpDe_YbrAVDk2sQJUO-qqA5QiPfiDlD7-ZgPUNT_mA9Q87TOD1DE5M4PUMy63A9QlLvcD1DQu9wPUM-s9g9Q_f-gEFDTv70QUKi3mxFQqbebEVCZvbURUJ69tRFQpr21EVCrvbURULS9tRFQooDxEVCh7f8TUKnu_xNQ_-q3FVCv67cVUL7l6RVQ4cLdF1C6g8UYUNauuR1Qo4L9IFDTqpEhUInCkSFQqeGRIVCq4ZEhUKHskSFQhNjtJlCF2O0mUOycrSlQhp2tKVDUsa0pUNaxrSlQtMO1KVC-w7UpUJjVyzBQmtXLMFCAh6ZRUOrxt1FQiJCTjwFQ8ej7kwFQ-buUlQFQtPvtlwFQgd2IogFQ3MjkqwFQqcrkqwFQj7WLsgFQuOrUuQFQhPzJvwFQjJfzwAFQoIvJnQNQ7orMnQNxTJhBPhasH_eCARMIgNvT9u7juQIVApfeCh25PACKkQG9ZUTgBkYR5hIZAJyFAkrmawK4Y0Rtgfuf7Pggy4YUuhwx_Q&search=1
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.0.5.292&pid=avg&sg=0&sap=hp|hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.3.0.11&pid=avg&sg=0&sap=hp
Deleted [Startup_urls] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=18.1.0.443&pid=avg&sg=0&sap=hp
Deleted [Homepage] : hxxp://isearch.avg.com/?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=14.2.0.1&pid=avg&sg=&sap=hp
Deleted [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Deleted [Extension] : dhjbpmkagjlnhcmdpmbagjldaknbgnff
[ File : C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[ File : C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://isearch.avg.com/search?cid={B02EEC65-5199-4595-AF7E-C5CEE844C3AF}&mid=cc50d5b0171447d0a281d15696d02cb4-77980187689e01f368d258b7c1e86db5d79e224a&lang=cs&ds=pd011&pr=sa&d=2012-10-28 15:42:30&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
*************************
AdwCleaner[R0].txt - [42580 octets] - [04/09/2014 16:37:39]
AdwCleaner[R1].txt - [42641 octets] - [04/09/2014 21:12:46]
AdwCleaner[S0].txt - [43338 octets] - [04/09/2014 21:18:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [43399 octets] ##########
Log z JRT:
=================
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Eva on źt 04.09.2014 at 21:29:53,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{780EE620-1C79-42D8-87C7-5F63D0A0874C}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files\video download converter"
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{3E1EAA2A-1078-488F-98DC-4CBD2B9D0246}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{76ABA36B-424B-4B07-942D-B320AC96F17E}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{A73581F0-C58B-4DE9-97BA-BC10FEE6A048}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{C024BDB9-9174-4324-92F8-262EEC7BC07A}
Successfully deleted: [Empty Folder] C:\Users\Eva\appdata\local\{C54E6A89-2179-4524-A3C7-C49A908E6080}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted the following from C:\Users\Eva\AppData\Roaming\mozilla\firefox\profiles\mgx5xa5t.default\prefs.js
user_pref("extensions.inboxcomtoolbar@inbox.com.update.url", "hxxp://toolbar.inbox.com/toolbar/firefox/update.aspx?version=%ITEM_VERSION%&status=%ITEM_STATUS%&appVersion=%APP_
Emptied folder: C:\Users\Eva\AppData\Roaming\mozilla\firefox\profiles\mgx5xa5t.default\minidumps [21 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 04.09.2014 at 21:42:50,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log z MBAM:
=================
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 4.9.2014
Čas skenování: 21:49:38
Protokol: mabm.txt
Správce: Ano
Verze: 2.00.2.1012
Databáze malwaru: v2014.03.04.09
Databáze rootkitů: v2014.02.20.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto
OS: Windows Vista Service Pack 2
CPU: x86
Souborový systém: NTFS
Uživatel: Eva
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 311374
Uplynulý čas: 35 min, 32 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(No malicious items detected)
Moduly: 0
(No malicious items detected)
Klíče registru: 0
(No malicious items detected)
Hodnoty registru: 0
(No malicious items detected)
Data registru: 0
(No malicious items detected)
Složky: 0
(No malicious items detected)
Soubory: 0
(No malicious items detected)
Fyzické sektory: 0
(No malicious items detected)
(end)
Log z RogueKiller:
=================
RogueKiller V9.2.9.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : https://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Eva [Práva správce]
Mód : Kontrola -- Datum : 09/04/2014 22:53:00
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 17 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NALEZENO
[PUM.HomePage] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> NALEZENO
¤¤¤ naplánované úlohy : 4 ¤¤¤
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_HP_rmv.job -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_TB_rmv.job -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_HP_rmv -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> NALEZENO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_TB_rmv -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> NALEZENO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
[C:\Windows\System32\drivers\etc\hosts] ::1 localhost
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] mgx5xa5t.default : user_pref("browser.startup.homepage", "www.seznam.cz"); -> NALEZENO
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD322HJ SCSI Disk Device +++++
--- User ---
[MBR] 104ba06c77ed2d7cbe799ab42f332a5b
[BSP] ebbaba802650105ad6b444168769693d : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - celkové pročištění
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu - celkové pročištění
"Log z RogueKiller"
RogueKiller V9.2.9.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : https://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Eva [Práva správce]
Mód : Odebrat -- Datum : 09/06/2014 08:23:10
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 17 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> VYMAZÁNO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> VYMAZÁNO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.HomePage] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> NAHRAZENO (http://go.microsoft.com/fwlink/p/?LinkId=255141)
¤¤¤ naplánované úlohy : 4 ¤¤¤
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_HP_rmv.job -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_TB_rmv.job -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_HP_rmv -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_TB_rmv -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> VYMAZÁNO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] ::1 localhost -> VYMAZÁNO
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 11 ¤¤¤
[FIREFX:Addon] mgx5xa5t.default : Seznam lištička [{ea614400-e918-4741-9a97-7a972ff7c30b}] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : avast! Online Security [wrc@avast.com] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Microsoft .NET Framework Assistant [{20a82645-c095-46ed-80e3-08825760534b}] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Default Manager [DefaultManager@Microsoft] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Skype Click to Call [{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}] -> VYMAZÁNO
[PUM.HomePage][FIREFX:Config] mgx5xa5t.default : user_pref("browser.startup.homepage", "www.seznam.cz"); -> NAHRAZENO (about:home)
[CHROME:Addon] Default : YouTube [blpcfgokakmgnkcojhhkbfbldkacnbeo] -> VYMAZÁNO
[CHROME:Addon] Default : Google Search [coobgpohoikkiipiblmjeljniedjpjpf] -> ERROR [2]
[CHROME:Addon] Default : Skype Click to Call [lifbcibllhkdhoafpjfnlhfpfgnpldfl] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
[CHROME:Addon] Default : Gmail [pjkljhegncpnkpknbcohdijeoejaedia] -> ERROR [2]
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD322HJ SCSI Disk Device +++++
--- User ---
[MBR] 104ba06c77ed2d7cbe799ab42f332a5b
[BSP] ebbaba802650105ad6b444168769693d : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
+++++ PhysicalDrive1: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive2: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
============================================
RKreport_SCN_09042014_225300.log - RKreport_SCN_09062014_082021.log
"Log z Zoek"
Zoek.exe v5.0.0.0 Updated 06-August-2014
Tool run by Eva on so 06.09.2014 at 8:33:36,44.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Eva\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
6.9.2014 8:41:33 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js:
user_pref("browser.search.defaultenginename", "ICQ Search");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);
user_pref("browser.search.defaulturl", "https://www.google.com/search");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "https://www.google.com/search");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default
user.js not found
---- Lines ffxtbr modified from prefs.js ----
user_pref("extensions.enabledAddons", "4zffxtbr%40VideoDownloadConverter_4z.com:2.73.1.31511,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1");
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\
---- FireFox user.js and prefs.js backups ----
prefs_06.09.2014_0926_.backup
ProfilePath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_06.09.2014_0926_.backup
==== Deleting Files \ Folders ======================
C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com not found
C:\Windows\system32\appdata deleted
C:\PROGRA~2\100 deleted
C:\Users\Eva\.android deleted
C:\Program Files\Alawar deleted
C:\Program Files\Alawarhry.cz deleted
C:\found.000 deleted
C:\Users\Eva\AppData\Roaming\Karaoke-Sing-n-Burn.INI deleted
C:\Users\Eva\AppData\Roaming\AlawarEntertainment deleted
C:\Windows\system32\config\systemprofile\AppData\Roaming\24x7 Help deleted
C:\PROGRA~2\ICQ deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\Eva\Searches deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Users\wangzhisong deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icq-search.xml deleted
C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\CT2247187 deleted
"C:\Users\Eva\AppData\Roaming\Zoner" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [10.07.2014 18:58]
==== Firefox Extensions ======================
ProfilePath: C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default
- Undetermined - C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default
9EE20E6E2E3F94714D44F739B9A228F4 - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll - Shockwave Flash
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Eva\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.1.0.20926.0.dll - Silverlight Plug-In
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
F71C9E5E3B1CBE60269D873E8313EDA3 - C:\Users\Eva\AppData\Roaming\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll - Cryptoplus KB – podepisovací modul
AE84791D996D1F05A2446B0C447D937A - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat
AE84791D996D1F05A2446B0C447D937A - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer
025F127536724D29F5426F624BFB224D - C:\Users\Eva\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
6CA6D643F830CBCD23DC67E07D84505E - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 6.0.2
98C32FE5BD575B13BDD6C347FCBB28A4 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 6.0.2
C6E707E8E9198C33CE3ABF5001622986 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 6.0.2
8AF702F62DA01D1B37F1A38035760049 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 6.0.2
359522AF09FC088F5D8F68381F70F6B5 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 6.0.2
414C3EEDE19AB68F10AE6B98CB7FA523 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 6.0.2
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[10.07.2014 18:57]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[14.05.2013 13:27]
Skype Click to Call - Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Skype Click to Call - ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
==== Chromium Startpages ======================
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com/"
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences
{"backup":{"session":{"urls_to_restore_on_startup":["http://www.google.com"]}},"browser":{"window_placement":{"bottom":758,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":768,"work_area_left":0,"work_area_right":1366,"work_area_top":0}},"countryid_at_install":17242,"default_apps_install_state":3,"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"show_welcome_page":true,"skip_first_run_ui":false,"system_level":true,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["http://www.24x7help.org/",["http://fonts.googleapis.com/",2.27338020,"http://www.24x7help.org/",3.594660999999999]]],"startup_list":[1,"http://fonts.googleapis.com/","http://www.24x7help.org/"]},"download":{"directory_upgrade":true},"extensions":{"autoupdate":{"next_check":"13008535254151980"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"last_chrome_version":"25.0.1364.172","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["appNotifications","management","webstorePrivate"]},"app_launcher_ordinal":"n","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682264980","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Chrome Web Store","permissions":["appNotifications","webstorePrivate","management"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"exclude_from_sideload_wipeout":true},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"exclude_from_sideload_wipeout":true},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682262980","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":["app.currentWindowInternal","app.runtime","app.window"],"explicit_host":["chrome://settings-frame/*"]},"app_launcher_ordinal":"t","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682266980","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\settings_app","was_installed_by_default":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682263980","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint","https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\cloud_print","was_installed_by_default":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"exclude_from_sideload_wipeout":true}}},"homepage":"http://www.google.com","homepage_is_newtabpage":false,"ntp":{"promo_resource_cache_update":"1364043087.49698"},"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"name":"PrvnĂ uĹľivatel"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":null,"urls_to_restore_on_startup":["http://www.google.com"]}}
{"backup":{"session":{"urls_to_restore_on_startup":["http://www.google.com"]}},"browser":{"window_placement":{"bottom":758,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":768,"work_area_left":0,"work_area_right":1366,"work_area_top":0}},"countryid_at_install":17242,"default_apps_install_state":3,"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"show_welcome_page":true,"skip_first_run_ui":false,"system_level":true,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["http://www.24x7help.org/",["http://fonts.googleapis.com/",2.27338020,"http://www.24x7help.org/",3.594660999999999]]],"startup_list":[1,"http://fonts.googleapis.com/","http://www.24x7help.org/"]},"download":{"directory_upgrade":true},"extensions":{"autoupdate":{"next_check":"13008535254151980"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"last_chrome_version":"25.0.1364.172","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["appNotifications","management","webstorePrivate"]},"app_launcher_ordinal":"n","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682264980","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Chrome Web Store","permissions":["appNotifications","webstorePrivate","management"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"exclude_from_sideload_wipeout":true},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"exclude_from_sideload_wipeout":true},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682262980","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":["app.currentWindowInternal","app.runtime","app.window"],"explicit_host":["chrome://settings-frame/*"]},"app_launcher_ordinal":"t","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682266980","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\settings_app","was_installed_by_default":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682263980","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint","https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\cloud_print","was_installed_by_default":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"exclude_from_sideload_wipeout":true}}},"homepage":"http://www.google.com","homepage_is_newtabpage":false,"ntp":{"promo_resource_cache_update":"1364043087.49698"},"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"name":"PrvnĂ uĹľivatel"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":null,"urls_to_restore_on_startup":["http://www.google.com"]}}
==== Chrome Fix ======================
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage deleted successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz="
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{313D37BD-0CA7-F37E-8AF9-6C196438D264} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ACBEF528-6F04-D4A7-1E6B-74843632E85A} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InboxToolbar deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uninstall_CToolbar deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoDownloadConverter Search Scope Monitor deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoDownloadConverter_4z Browser Plugin Loader deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate deleted successfully
==== Empty IE Cache ======================
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Kaku\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Eva\AppData\Local\Mozilla\Firefox\Profiles\mgx5xa5t.default\Cache emptied successfully
C:\Users\ADLA~1\AppData\Local\Mozilla\Firefox\Profiles\cvwrnd3t.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=97 folders=38 4928745 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Eva\AppData\Local\Temp will be emptied at reboot
C:\Users\Kaku\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Eva\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun-42-421CFC91-A93E-42AB-A35C-F06F127FCC44.lock" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
==== EOF on so 06.09.2014 at 9:41:44,92 ======================
RogueKiller V9.2.9.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : https://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Eva [Práva správce]
Mód : Odebrat -- Datum : 09/06/2014 08:23:10
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 17 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | NameServer : 194.228.2.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5FCAAB53-3391-4E95-AB5D-753F2DF24E75} | DhcpNameServer : 10.0.0.138 -> NAHRAZENO ()
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> VYMAZÁNO
[PUM.Policies] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> VYMAZÁNO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.HomePage] HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.seznam.cz/ -> NAHRAZENO (http://go.microsoft.com/fwlink/p/?LinkId=255141)
¤¤¤ naplánované úlohy : 4 ¤¤¤
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_HP_rmv.job -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] AVG-Secure-Search-Update_JUNE2013_TB_rmv.job -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_HP_rmv -- C:\Windows\TEMP\{3353AF86-9182-4E68-969D-418548B831AE}.exe (--uninstall=1) -> VYMAZÁNO
[Suspicious.Path] \\AVG-Secure-Search-Update_JUNE2013_TB_rmv -- C:\Windows\TEMP\{50C9F61C-EE7B-4906-B968-D3B789B3B442}.exe (--uninstall=1) -> VYMAZÁNO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] ::1 localhost -> VYMAZÁNO
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 11 ¤¤¤
[FIREFX:Addon] mgx5xa5t.default : Seznam lištička [{ea614400-e918-4741-9a97-7a972ff7c30b}] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : avast! Online Security [wrc@avast.com] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Microsoft .NET Framework Assistant [{20a82645-c095-46ed-80e3-08825760534b}] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Default Manager [DefaultManager@Microsoft] -> VYMAZÁNO
[FIREFX:Addon] mgx5xa5t.default : Skype Click to Call [{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}] -> VYMAZÁNO
[PUM.HomePage][FIREFX:Config] mgx5xa5t.default : user_pref("browser.startup.homepage", "www.seznam.cz"); -> NAHRAZENO (about:home)
[CHROME:Addon] Default : YouTube [blpcfgokakmgnkcojhhkbfbldkacnbeo] -> VYMAZÁNO
[CHROME:Addon] Default : Google Search [coobgpohoikkiipiblmjeljniedjpjpf] -> ERROR [2]
[CHROME:Addon] Default : Skype Click to Call [lifbcibllhkdhoafpjfnlhfpfgnpldfl] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
[CHROME:Addon] Default : Gmail [pjkljhegncpnkpknbcohdijeoejaedia] -> ERROR [2]
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD322HJ SCSI Disk Device +++++
--- User ---
[MBR] 104ba06c77ed2d7cbe799ab42f332a5b
[BSP] ebbaba802650105ad6b444168769693d : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
+++++ PhysicalDrive1: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive2: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
============================================
RKreport_SCN_09042014_225300.log - RKreport_SCN_09062014_082021.log
"Log z Zoek"
Zoek.exe v5.0.0.0 Updated 06-August-2014
Tool run by Eva on so 06.09.2014 at 8:33:36,44.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Eva\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
6.9.2014 8:41:33 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js:
user_pref("browser.search.defaultenginename", "ICQ Search");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);
user_pref("browser.search.defaulturl", "https://www.google.com/search");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "https://www.google.com/search");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default
user.js not found
---- Lines ffxtbr modified from prefs.js ----
user_pref("extensions.enabledAddons", "4zffxtbr%40VideoDownloadConverter_4z.com:2.73.1.31511,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1");
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\
---- FireFox user.js and prefs.js backups ----
prefs_06.09.2014_0926_.backup
ProfilePath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_06.09.2014_0926_.backup
==== Deleting Files \ Folders ======================
C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com not found
C:\Windows\system32\appdata deleted
C:\PROGRA~2\100 deleted
C:\Users\Eva\.android deleted
C:\Program Files\Alawar deleted
C:\Program Files\Alawarhry.cz deleted
C:\found.000 deleted
C:\Users\Eva\AppData\Roaming\Karaoke-Sing-n-Burn.INI deleted
C:\Users\Eva\AppData\Roaming\AlawarEntertainment deleted
C:\Windows\system32\config\systemprofile\AppData\Roaming\24x7 Help deleted
C:\PROGRA~2\ICQ deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\Eva\Searches deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Users\wangzhisong deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\searchplugins\icq-search.xml deleted
C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\CT2247187 deleted
"C:\Users\Eva\AppData\Roaming\Zoner" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [10.07.2014 18:58]
==== Firefox Extensions ======================
ProfilePath: C:\Users\ADLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default
- Undetermined - C:\Users\Adéla\AppData\Roaming\Mozilla\Firefox\Profiles\cvwrnd3t.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default
9EE20E6E2E3F94714D44F739B9A228F4 - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll - Shockwave Flash
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Eva\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.1.0.20926.0.dll - Silverlight Plug-In
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
F71C9E5E3B1CBE60269D873E8313EDA3 - C:\Users\Eva\AppData\Roaming\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll - Cryptoplus KB – podepisovací modul
AE84791D996D1F05A2446B0C447D937A - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat
AE84791D996D1F05A2446B0C447D937A - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer
025F127536724D29F5426F624BFB224D - C:\Users\Eva\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
6CA6D643F830CBCD23DC67E07D84505E - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 6.0.2
98C32FE5BD575B13BDD6C347FCBB28A4 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 6.0.2
C6E707E8E9198C33CE3ABF5001622986 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 6.0.2
8AF702F62DA01D1B37F1A38035760049 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 6.0.2
359522AF09FC088F5D8F68381F70F6B5 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 6.0.2
414C3EEDE19AB68F10AE6B98CB7FA523 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 6.0.2
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[10.07.2014 18:57]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[14.05.2013 13:27]
Skype Click to Call - Kaku\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Skype Click to Call - ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
==== Chromium Startpages ======================
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com/"
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences
{"backup":{"session":{"urls_to_restore_on_startup":["http://www.google.com"]}},"browser":{"window_placement":{"bottom":758,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":768,"work_area_left":0,"work_area_right":1366,"work_area_top":0}},"countryid_at_install":17242,"default_apps_install_state":3,"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"show_welcome_page":true,"skip_first_run_ui":false,"system_level":true,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["http://www.24x7help.org/",["http://fonts.googleapis.com/",2.27338020,"http://www.24x7help.org/",3.594660999999999]]],"startup_list":[1,"http://fonts.googleapis.com/","http://www.24x7help.org/"]},"download":{"directory_upgrade":true},"extensions":{"autoupdate":{"next_check":"13008535254151980"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"last_chrome_version":"25.0.1364.172","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["appNotifications","management","webstorePrivate"]},"app_launcher_ordinal":"n","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682264980","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Chrome Web Store","permissions":["appNotifications","webstorePrivate","management"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"exclude_from_sideload_wipeout":true},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"exclude_from_sideload_wipeout":true},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682262980","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":["app.currentWindowInternal","app.runtime","app.window"],"explicit_host":["chrome://settings-frame/*"]},"app_launcher_ordinal":"t","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682266980","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\settings_app","was_installed_by_default":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682263980","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint","https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\cloud_print","was_installed_by_default":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"exclude_from_sideload_wipeout":true}}},"homepage":"http://www.google.com","homepage_is_newtabpage":false,"ntp":{"promo_resource_cache_update":"1364043087.49698"},"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"name":"PrvnĂ uĹľivatel"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":null,"urls_to_restore_on_startup":["http://www.google.com"]}}
{"backup":{"session":{"urls_to_restore_on_startup":["http://www.google.com"]}},"browser":{"window_placement":{"bottom":758,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":768,"work_area_left":0,"work_area_right":1366,"work_area_top":0}},"countryid_at_install":17242,"default_apps_install_state":3,"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"show_welcome_page":true,"skip_first_run_ui":false,"system_level":true,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["http://www.24x7help.org/",["http://fonts.googleapis.com/",2.27338020,"http://www.24x7help.org/",3.594660999999999]]],"startup_list":[1,"http://fonts.googleapis.com/","http://www.24x7help.org/"]},"download":{"directory_upgrade":true},"extensions":{"autoupdate":{"next_check":"13008535254151980"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"last_chrome_version":"25.0.1364.172","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["appNotifications","management","webstorePrivate"]},"app_launcher_ordinal":"n","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682264980","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Chrome Web Store","permissions":["appNotifications","webstorePrivate","management"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"exclude_from_sideload_wipeout":true},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"exclude_from_sideload_wipeout":true},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"exclude_from_sideload_wipeout":true},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682262980","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":["app.currentWindowInternal","app.runtime","app.window"],"explicit_host":["chrome://settings-frame/*"]},"app_launcher_ordinal":"t","creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682266980","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\settings_app","was_installed_by_default":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"]},"creation_flags":1,"from_bookmark":false,"from_webstore":false,"install_time":"13008516682263980","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint","https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.172\\resources\\cloud_print","was_installed_by_default":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"exclude_from_sideload_wipeout":true}}},"homepage":"http://www.google.com","homepage_is_newtabpage":false,"ntp":{"promo_resource_cache_update":"1364043087.49698"},"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"name":"PrvnĂ uĹľivatel"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":null,"urls_to_restore_on_startup":["http://www.google.com"]}}
==== Chrome Fix ======================
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage deleted successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Search Page"="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz="
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{313D37BD-0CA7-F37E-8AF9-6C196438D264} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ACBEF528-6F04-D4A7-1E6B-74843632E85A} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InboxToolbar deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uninstall_CToolbar deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoDownloadConverter Search Scope Monitor deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoDownloadConverter_4z Browser Plugin Loader deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate deleted successfully
==== Empty IE Cache ======================
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Kaku\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Eva\AppData\Local\Mozilla\Firefox\Profiles\mgx5xa5t.default\Cache emptied successfully
C:\Users\ADLA~1\AppData\Local\Mozilla\Firefox\Profiles\cvwrnd3t.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Kaku\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\ADLA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=97 folders=38 4928745 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Eva\AppData\Local\Temp will be emptied at reboot
C:\Users\Kaku\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Users\ADLA~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Eva\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun-42-421CFC91-A93E-42AB-A35C-F06F127FCC44.lock" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
==== EOF on so 06.09.2014 at 9:41:44,92 ======================
Re: Prosím o kontrolu - celkové pročištění
08:30:18.0037 0x0c44 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
08:30:21.0141 0x0c44 ============================================================
08:30:21.0141 0x0c44 Current date / time: 2014/09/06 08:30:21.0141
08:30:21.0141 0x0c44 SystemInfo:
08:30:21.0141 0x0c44
08:30:21.0141 0x0c44 OS Version: 6.0.6002 ServicePack: 2.0
08:30:21.0141 0x0c44 Product type: Workstation
08:30:21.0141 0x0c44 ComputerName: EVA-PC
08:30:21.0141 0x0c44 UserName: Eva
08:30:21.0141 0x0c44 Windows directory: C:\Windows
08:30:21.0141 0x0c44 System windows directory: C:\Windows
08:30:21.0141 0x0c44 Processor architecture: Intel x86
08:30:21.0141 0x0c44 Number of processors: 1
08:30:21.0141 0x0c44 Page size: 0x1000
08:30:21.0141 0x0c44 Boot type: Normal boot
08:30:21.0141 0x0c44 ============================================================
08:30:21.0406 0x0c44 KLMD registered as C:\Windows\system32\drivers\43645563.sys
08:30:21.0609 0x0c44 System UUID: {30C31705-CFE4-7715-FC44-A018ADFB6E49}
08:30:22.0514 0x0c44 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
08:30:22.0545 0x0c44 ============================================================
08:30:22.0545 0x0c44 \Device\Harddisk0\DR0:
08:30:22.0561 0x0c44 MBR partitions:
08:30:22.0561 0x0c44 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2542D800
08:30:22.0561 0x0c44 ============================================================
08:30:22.0654 0x0c44 C: <-> \Device\Harddisk0\DR0\Partition1
08:30:22.0654 0x0c44 ============================================================
08:30:22.0654 0x0c44 Initialize success
08:30:22.0654 0x0c44 ============================================================
08:30:24.0807 0x0c5c ============================================================
08:30:24.0807 0x0c5c Scan started
08:30:24.0807 0x0c5c Mode: Manual;
08:30:24.0807 0x0c5c ============================================================
08:30:24.0823 0x0c5c KSN ping started
08:30:24.0838 0x0c5c KSN ping finished: false
08:30:25.0525 0x0c5c ================ Scan system memory ========================
08:30:25.0525 0x0c5c System memory - ok
08:30:25.0525 0x0c5c ================ Scan services =============================
08:30:25.0993 0x0c5c [ D9AF0082D3F09F5007E5727798786CD8, 3CFE9A1919433811F6C7A0B9F1D905A4D5F3F90B8C11B3C480E1A41A8CBB3A59 ] 3xHybrid C:\Windows\system32\DRIVERS\3xHybrid.sys
08:30:26.0040 0x0c5c 3xHybrid - ok
08:30:26.0164 0x0c5c [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI C:\Windows\system32\drivers\acpi.sys
08:30:26.0180 0x0c5c ACPI - ok
08:30:26.0289 0x0c5c [ F4BF3ADDDDC1AD372604F13C2B0C1F65, FA37ED5014336A72F778C485226B61BEFECEB861AB754862738795C167F0BAB7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
08:30:26.0305 0x0c5c AdobeFlashPlayerUpdateSvc - ok
08:30:26.0398 0x0c5c [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
08:30:26.0445 0x0c5c adp94xx - ok
08:30:26.0554 0x0c5c [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci C:\Windows\system32\drivers\adpahci.sys
08:30:26.0570 0x0c5c adpahci - ok
08:30:26.0617 0x0c5c [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
08:30:26.0632 0x0c5c adpu160m - ok
08:30:26.0710 0x0c5c [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
08:30:26.0726 0x0c5c adpu320 - ok
08:30:26.0788 0x0c5c [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
08:30:26.0804 0x0c5c AeLookupSvc - ok
08:30:26.0944 0x0c5c [ F5272A105F59A7B3B345D9D6D87DA7AD, 9E84776994D04240BF2537330DBB555EDE16DFCFC59DEDCBA05A44ED7F70BEFA ] AFD C:\Windows\system32\drivers\afd.sys
08:30:26.0991 0x0c5c AFD - ok
08:30:27.0038 0x0c5c [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440 C:\Windows\system32\drivers\agp440.sys
08:30:27.0038 0x0c5c agp440 - ok
08:30:27.0085 0x0c5c [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
08:30:27.0085 0x0c5c aic78xx - ok
08:30:27.0116 0x0c5c [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG C:\Windows\System32\alg.exe
08:30:27.0132 0x0c5c ALG - ok
08:30:27.0163 0x0c5c [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide C:\Windows\system32\drivers\aliide.sys
08:30:27.0178 0x0c5c aliide - ok
08:30:27.0225 0x0c5c [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp C:\Windows\system32\drivers\amdagp.sys
08:30:27.0241 0x0c5c amdagp - ok
08:30:27.0256 0x0c5c [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide C:\Windows\system32\drivers\amdide.sys
08:30:27.0272 0x0c5c amdide - ok
08:30:27.0334 0x0c5c [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
08:30:27.0334 0x0c5c AmdK7 - ok
08:30:27.0381 0x0c5c [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
08:30:27.0381 0x0c5c AmdK8 - ok
08:30:27.0490 0x0c5c [ 8F7D200717A58E9800D391F4C2101577, F07CF0F5636F46D8F3D5133284943E991E8739E5A644BCA5F18BB896B374620D ] Appinfo C:\Windows\System32\appinfo.dll
08:30:27.0522 0x0c5c Appinfo - ok
08:30:27.0553 0x0c5c [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc C:\Windows\system32\drivers\arc.sys
08:30:27.0568 0x0c5c arc - ok
08:30:27.0600 0x0c5c [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas C:\Windows\system32\drivers\arcsas.sys
08:30:27.0600 0x0c5c arcsas - ok
08:30:27.0787 0x0c5c [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
08:30:27.0818 0x0c5c aspnet_state - ok
08:30:27.0896 0x0c5c [ 3BFBB5DAE801CB893B8B46345FED6437, 2C2B71C1294585265D4871E74F17541500CA20DE34AC516F2A906DD81964C833 ] aswHwid C:\Windows\system32\drivers\aswHwid.sys
08:30:27.0896 0x0c5c aswHwid - ok
08:30:28.0052 0x0c5c [ C3014C735F450FE822C97FFBB0627113, 1CCFE845AED1757B8C1F52D310933076FF1EC197D82E499DB4592B09D66137B0 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
08:30:28.0052 0x0c5c aswMonFlt - ok
08:30:28.0192 0x0c5c [ D6C9024F5D14843D33ADA8A6A10A1BE1, D40022D0A360FD4010D3D5D452BBC4CE9EE68224DEAB9584626E6F435E128857 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
08:30:28.0208 0x0c5c aswRdr - ok
08:30:28.0270 0x0c5c [ B7750AF7EDFD95674EB7CA92BCDD3358, A097577004F3CF71E2F9465F02B073D39926D7DEE2E2A9516D888158A5CB19E9 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
08:30:28.0286 0x0c5c aswRvrt - ok
08:30:28.0395 0x0c5c [ 51FDE588D860857A97E4C4B560E40C9B, 8A3AC3E55249DAE6CCD95593989F8B100D5C4712A16681A36E5D0F2F08BD57AA ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
08:30:28.0442 0x0c5c aswSnx - ok
08:30:28.0536 0x0c5c [ 1AEB8CDB797666AF709A291B47AE81E0, 12AC4DBC6338BA5E5C04B449FF8362E7EC8EBFCA675C4F21BE847DFDCAE8F7C9 ] aswSP C:\Windows\system32\drivers\aswSP.sys
08:30:28.0551 0x0c5c aswSP - ok
08:30:28.0598 0x0c5c [ 26C51C289E39E8EE0F12B8B06B71E436, 81382FC3E836698432EE832A166F09251CC9164B17584E90F73037A1FA54E4F7 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
08:30:28.0614 0x0c5c aswTdi - ok
08:30:28.0660 0x0c5c [ 90BEE0170D70D6744CEF2355EEAF8086, 8F9FF53F529B854934020E2F8163605DC794FF48464D3D4439BAAF70ECE8E963 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
08:30:28.0676 0x0c5c aswVmm - ok
08:30:28.0770 0x0c5c [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
08:30:28.0770 0x0c5c AsyncMac - ok
08:30:28.0848 0x0c5c [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi C:\Windows\system32\drivers\atapi.sys
08:30:28.0848 0x0c5c atapi - ok
08:30:28.0957 0x0c5c [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
08:30:28.0972 0x0c5c AudioEndpointBuilder - ok
08:30:29.0019 0x0c5c [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv C:\Windows\System32\Audiosrv.dll
08:30:29.0035 0x0c5c Audiosrv - ok
08:30:29.0160 0x0c5c [ 73F5C13B431915BAE35254B4E95DFB71, 393A045859382C44133C004598B1512048046BCC129FED2247A77FDBFCDB6DFF ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
08:30:29.0160 0x0c5c avast! Antivirus - ok
08:30:29.0269 0x0c5c [ E03A1466A8A7B869EBC90B179D777EA4, 5F4EBE04C9ACE28DE7AD34603998C282132B66BB9620017AF677A94BA2FE872E ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
08:30:29.0284 0x0c5c avgtp - ok
08:30:29.0347 0x0c5c [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep C:\Windows\system32\drivers\Beep.sys
08:30:29.0362 0x0c5c Beep - ok
08:30:29.0456 0x0c5c [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE C:\Windows\System32\bfe.dll
08:30:29.0518 0x0c5c BFE - ok
08:30:29.0721 0x0c5c [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS C:\Windows\System32\qmgr.dll
08:30:29.0799 0x0c5c BITS - ok
08:30:29.0830 0x0c5c [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
08:30:29.0846 0x0c5c blbdrive - ok
08:30:29.0893 0x0c5c [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
08:30:29.0893 0x0c5c bowser - ok
08:30:29.0955 0x0c5c [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
08:30:29.0955 0x0c5c BrFiltLo - ok
08:30:29.0986 0x0c5c [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
08:30:29.0986 0x0c5c BrFiltUp - ok
08:30:30.0033 0x0c5c [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser C:\Windows\System32\browser.dll
08:30:30.0033 0x0c5c Browser - ok
08:30:30.0080 0x0c5c [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid C:\Windows\system32\drivers\brserid.sys
08:30:30.0080 0x0c5c Brserid - ok
08:30:30.0111 0x0c5c [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
08:30:30.0127 0x0c5c BrSerWdm - ok
08:30:30.0158 0x0c5c [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
08:30:30.0158 0x0c5c BrUsbMdm - ok
08:30:30.0189 0x0c5c [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
08:30:30.0205 0x0c5c BrUsbSer - ok
08:30:30.0252 0x0c5c [ AD07C1EC6665B8B35741AB91200C6B68, DCE1305A30D6713222A01C1F1D03ED0ADABE23C742CE1E82BB142531B82A3FF7 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
08:30:30.0252 0x0c5c BTHMODEM - ok
08:30:30.0298 0x0c5c [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
08:30:30.0314 0x0c5c cdfs - ok
08:30:30.0345 0x0c5c [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
08:30:30.0361 0x0c5c cdrom - ok
08:30:30.0408 0x0c5c [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc C:\Windows\System32\certprop.dll
08:30:30.0423 0x0c5c CertPropSvc - ok
08:30:30.0454 0x0c5c [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass C:\Windows\system32\drivers\circlass.sys
08:30:30.0454 0x0c5c circlass - ok
08:30:30.0532 0x0c5c [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS C:\Windows\system32\CLFS.sys
08:30:30.0548 0x0c5c CLFS - ok
08:30:30.0657 0x0c5c [ 6B6943A0CA56B47D6FB2EE476890854F, 6DA779879487F4A187DF54B0362642643D7871AA8F7E30992D781F558C50F052 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:30:30.0657 0x0c5c clr_optimization_v2.0.50727_32 - ok
08:30:30.0782 0x0c5c [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:30:30.0829 0x0c5c clr_optimization_v4.0.30319_32 - ok
08:30:30.0876 0x0c5c [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide C:\Windows\system32\drivers\cmdide.sys
08:30:30.0876 0x0c5c cmdide - ok
08:30:30.0907 0x0c5c [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
08:30:30.0907 0x0c5c Compbatt - ok
08:30:30.0938 0x0c5c COMSysApp - ok
08:30:30.0985 0x0c5c [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
08:30:30.0985 0x0c5c crcdisk - ok
08:30:31.0063 0x0c5c [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe C:\Windows\system32\drivers\crusoe.sys
08:30:31.0078 0x0c5c Crusoe - ok
08:30:31.0172 0x0c5c [ 684C130BBC6DB681BAD4920A4C944AA5, DDE434B206984808351C98500824A33E6740B4326C455066027F8D549D4C3B92 ] CryptSvc C:\Windows\system32\cryptsvc.dll
08:30:31.0188 0x0c5c CryptSvc - ok
08:30:31.0312 0x0c5c [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch C:\Windows\system32\rpcss.dll
08:30:31.0375 0x0c5c DcomLaunch - ok
08:30:31.0437 0x0c5c [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
08:30:31.0437 0x0c5c DfsC - ok
08:30:31.0640 0x0c5c [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR C:\Windows\system32\DFSR.exe
08:30:31.0858 0x0c5c DFSR - ok
08:30:32.0202 0x0c5c [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
08:30:32.0217 0x0c5c Dhcp - ok
08:30:32.0311 0x0c5c [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk C:\Windows\system32\drivers\disk.sys
08:30:32.0311 0x0c5c disk - ok
08:30:32.0404 0x0c5c [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache C:\Windows\System32\dnsrslvr.dll
08:30:32.0404 0x0c5c Dnscache - ok
08:30:32.0514 0x0c5c [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc C:\Windows\System32\dot3svc.dll
08:30:32.0529 0x0c5c dot3svc - ok
08:30:32.0592 0x0c5c [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS C:\Windows\system32\dps.dll
08:30:32.0592 0x0c5c DPS - ok
08:30:32.0670 0x0c5c [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
08:30:32.0670 0x0c5c drmkaud - ok
08:30:32.0779 0x0c5c [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
08:30:32.0794 0x0c5c dtsoftbus01 - ok
08:30:32.0872 0x0c5c [ 5C2C209CDEFBC51D83D66E8A53B2BE89, 7AE68672A6BEEF601017BE28AA0BF3673318EFE97AA08E70F58A9391C54DF71F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
08:30:32.0919 0x0c5c DXGKrnl - ok
08:30:32.0982 0x0c5c [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
08:30:32.0982 0x0c5c E1G60 - ok
08:30:33.0044 0x0c5c [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost C:\Windows\System32\eapsvc.dll
08:30:33.0075 0x0c5c EapHost - ok
08:30:33.0153 0x0c5c [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache C:\Windows\system32\drivers\ecache.sys
08:30:33.0169 0x0c5c Ecache - ok
08:30:33.0247 0x0c5c [ 9BE3744D295A7701EB425332014F0797, 1A139EE9232581E466591C5EBEF41E4BF1F82D99C1959F1C68C879B240E9F46D ] ehRecvr C:\Windows\ehome\ehRecvr.exe
08:30:33.0294 0x0c5c ehRecvr - ok
08:30:33.0356 0x0c5c [ AD1870C8E5D6DD340C829E6074BF3C3F, 064D07106A1BBE80294F1913354832F2B67D22274BB4D36C81D2D83C96FE0B88 ] ehSched C:\Windows\ehome\ehsched.exe
08:30:33.0372 0x0c5c ehSched - ok
08:30:33.0403 0x0c5c [ C27C4EE8926E74AA72EFCAB24C5242C3, F1EBF78CCE9BA76AFD0478BC66B67CA44DEAF3C380369BFCE91BD8F678C8608A ] ehstart C:\Windows\ehome\ehstart.dll
08:30:33.0403 0x0c5c ehstart - ok
08:30:33.0496 0x0c5c [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor C:\Windows\system32\drivers\elxstor.sys
08:30:33.0543 0x0c5c elxstor - ok
08:30:33.0621 0x0c5c [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
08:30:33.0668 0x0c5c EMDMgmt - ok
08:30:33.0699 0x0c5c [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev C:\Windows\system32\drivers\errdev.sys
08:30:33.0699 0x0c5c ErrDev - ok
08:30:33.0824 0x0c5c [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem C:\Windows\system32\es.dll
08:30:33.0855 0x0c5c EventSystem - ok
08:30:33.0933 0x0c5c [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat C:\Windows\system32\drivers\exfat.sys
08:30:33.0949 0x0c5c exfat - ok
08:30:34.0027 0x0c5c [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat C:\Windows\system32\drivers\fastfat.sys
08:30:34.0042 0x0c5c fastfat - ok
08:30:34.0105 0x0c5c [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc C:\Windows\system32\DRIVERS\fdc.sys
08:30:34.0105 0x0c5c fdc - ok
08:30:34.0152 0x0c5c [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost C:\Windows\system32\fdPHost.dll
08:30:34.0167 0x0c5c fdPHost - ok
08:30:34.0198 0x0c5c [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub C:\Windows\system32\fdrespub.dll
08:30:34.0198 0x0c5c FDResPub - ok
08:30:34.0245 0x0c5c [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
08:30:34.0245 0x0c5c FileInfo - ok
08:30:34.0292 0x0c5c [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
08:30:34.0292 0x0c5c Filetrace - ok
08:30:34.0323 0x0c5c [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
08:30:34.0339 0x0c5c flpydisk - ok
08:30:34.0417 0x0c5c [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
08:30:34.0432 0x0c5c FltMgr - ok
08:30:34.0573 0x0c5c [ 2AFA3A46986AE935DAECEBC7E66314CF, 747FAF9B7F8291B83EE44B91E5708395E749DC87BD42CC3BF2CD41209C298F4D ] FontCache C:\Windows\system32\FntCache.dll
08:30:34.0635 0x0c5c FontCache - ok
08:30:34.0729 0x0c5c [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
08:30:34.0729 0x0c5c FontCache3.0.0.0 - ok
08:30:34.0854 0x0c5c [ B0082808A6856A252F7CDD939892CE50, 3A069239629C4F54049A2CFC6642AC5102ECEAA74470BAA9DDB1AB108D1060EE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
08:30:34.0869 0x0c5c fssfltr - ok
08:30:35.0134 0x0c5c [ 28DDEEEC44E988657B732CF404D504CB, 47F83018E5449CDCED3DD447991788EBAAC92C418D4513FBA9408C45E9AB8E7E ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
08:30:35.0244 0x0c5c fsssvc - ok
08:30:35.0306 0x0c5c [ B972A66758577E0BFD1DE0F91AAA27B5, E934034F3F740A83D4E7ABCD2C581845AC2945B0BCCAACF65CC3F99A1DBDE455 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
08:30:35.0306 0x0c5c Fs_Rec - ok
08:30:35.0353 0x0c5c [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
08:30:35.0368 0x0c5c gagp30kx - ok
08:30:35.0462 0x0c5c [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc C:\Windows\System32\gpsvc.dll
08:30:35.0493 0x0c5c gpsvc - ok
08:30:35.0618 0x0c5c [ 626A24ED1228580B9518C01930936DF9, CBD94AB1E5477D7288799D17528CC43D572E711DA0F2B0C784A0B9FE105BF0F4 ] gupdate1c9a326fd1c5f6 C:\Program Files\Google\Update\GoogleUpdate.exe
08:30:35.0634 0x0c5c gupdate1c9a326fd1c5f6 - ok
08:30:35.0665 0x0c5c [ 626A24ED1228580B9518C01930936DF9, CBD94AB1E5477D7288799D17528CC43D572E711DA0F2B0C784A0B9FE105BF0F4 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
08:30:35.0680 0x0c5c gupdatem - ok
08:30:35.0774 0x0c5c [ CB04C744BE0A61B1D648FAED182C3B59, 61DC0FF94325DAFCCB7B3980A48727EFBF1283FCF753EC16EF04C730525994C0 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
08:30:35.0805 0x0c5c HdAudAddService - ok
08:30:35.0914 0x0c5c [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
08:30:35.0946 0x0c5c HDAudBus - ok
08:30:35.0992 0x0c5c [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth C:\Windows\system32\drivers\hidbth.sys
08:30:35.0992 0x0c5c HidBth - ok
08:30:36.0039 0x0c5c [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr C:\Windows\system32\drivers\hidir.sys
08:30:36.0055 0x0c5c HidIr - ok
08:30:36.0102 0x0c5c [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv C:\Windows\system32\hidserv.dll
08:30:36.0102 0x0c5c hidserv - ok
08:30:36.0148 0x0c5c [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
08:30:36.0148 0x0c5c HidUsb - ok
08:30:36.0211 0x0c5c [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc C:\Windows\system32\kmsvc.dll
08:30:36.0226 0x0c5c hkmsvc - ok
08:30:36.0258 0x0c5c [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
08:30:36.0258 0x0c5c HpCISSs - ok
08:30:36.0336 0x0c5c [ F870AA3E254628EBEAFE754108D664DE, B0444E7D246AA1982094030ACB991690F6A7DD3FB07B1BB6A1BC0F3AA9718A70 ] HTTP C:\Windows\system32\drivers\HTTP.sys
08:30:36.0367 0x0c5c HTTP - ok
08:30:36.0398 0x0c5c [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
08:30:36.0414 0x0c5c i2omp - ok
08:30:36.0492 0x0c5c [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
08:30:36.0492 0x0c5c i8042prt - ok
08:30:36.0538 0x0c5c [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
08:30:36.0570 0x0c5c iaStorV - ok
08:30:36.0757 0x0c5c [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
08:30:36.0757 0x0c5c IDriverT - ok
08:30:36.0928 0x0c5c [ DD386C45D2B5863740166783448A2E7A, 10B912BA70306644BE73A53AF4DCDFF63880C4C5860FF6DBA92B0914EB566718 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
08:30:36.0991 0x0c5c idsvc - ok
08:30:37.0038 0x0c5c [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp C:\Windows\system32\drivers\iirsp.sys
08:30:37.0053 0x0c5c iirsp - ok
08:30:37.0194 0x0c5c [ 755519F49906B73C1FE9CBBF75E347EA, 20FF0D235478C693AB0708DF040EDA2ED8D4856EFCACD0A0ABD25E49330810FC ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
08:30:37.0194 0x0c5c IJPLMSVC - ok
08:30:37.0350 0x0c5c [ 4687EE0C0DD2CE5F7AAA9C2E33C1DC78, FA8EBED2778D9F7560ADC1B563954EEF98AAE651C0553F2803372B37B122AEB3 ] IKEEXT C:\Windows\System32\ikeext.dll
08:30:37.0365 0x0c5c IKEEXT - ok
08:30:37.0802 0x0c5c [ 126C1E93D4D3EA3E0AAA0557873AE646, 08C3CBE7FD629CAD38E2CF33CC4644FBBCD90872EA082EF81A87B4E84BF3324A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
08:30:37.0911 0x0c5c IntcAzAudAddService - ok
08:30:37.0974 0x0c5c [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide C:\Windows\system32\drivers\intelide.sys
08:30:37.0974 0x0c5c intelide - ok
08:30:38.0020 0x0c5c [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
08:30:38.0020 0x0c5c intelppm - ok
08:30:38.0098 0x0c5c [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
08:30:38.0114 0x0c5c IPBusEnum - ok
08:30:38.0145 0x0c5c [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:30:38.0145 0x0c5c IpFilterDriver - ok
08:30:38.0239 0x0c5c [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
08:30:38.0254 0x0c5c iphlpsvc - ok
08:30:38.0286 0x0c5c IpInIp - ok
08:30:38.0317 0x0c5c [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
08:30:38.0332 0x0c5c IPMIDRV - ok
08:30:38.0379 0x0c5c [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
08:30:38.0379 0x0c5c IPNAT - ok
08:30:38.0426 0x0c5c [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM C:\Windows\system32\drivers\irenum.sys
08:30:38.0426 0x0c5c IRENUM - ok
08:30:38.0457 0x0c5c [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp C:\Windows\system32\drivers\isapnp.sys
08:30:38.0473 0x0c5c isapnp - ok
08:30:38.0535 0x0c5c [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
08:30:38.0535 0x0c5c iScsiPrt - ok
08:30:38.0582 0x0c5c [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
08:30:38.0598 0x0c5c iteatapi - ok
08:30:38.0629 0x0c5c [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid C:\Windows\system32\drivers\iteraid.sys
08:30:38.0629 0x0c5c iteraid - ok
08:30:38.0676 0x0c5c [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
08:30:38.0676 0x0c5c kbdclass - ok
08:30:38.0738 0x0c5c [ EDE59EC70E25C24581ADD1FBEC7325F7, 41B37778E9A12675FC0DF74606AAF18C652EB88513B3C4889C5C512E14587CEE ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
08:30:38.0738 0x0c5c kbdhid - ok
08:30:38.0800 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso C:\Windows\system32\lsass.exe
08:30:38.0800 0x0c5c KeyIso - ok
08:30:38.0925 0x0c5c [ 4A1445EFA932A3BAF5BDB02D7131EE20, 9DD262ED72DF268FE024063788F54124E320D0775D8DC0C5CAD099CD5F655DA2 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
08:30:38.0956 0x0c5c KSecDD - ok
08:30:39.0066 0x0c5c [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm C:\Windows\system32\msdtckrm.dll
08:30:39.0097 0x0c5c KtmRm - ok
08:30:39.0159 0x0c5c [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer C:\Windows\system32\srvsvc.dll
08:30:39.0175 0x0c5c LanmanServer - ok
08:30:39.0222 0x0c5c [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
08:30:39.0253 0x0c5c LanmanWorkstation - ok
08:30:39.0300 0x0c5c [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
08:30:39.0315 0x0c5c lltdio - ok
08:30:39.0378 0x0c5c [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc C:\Windows\System32\lltdsvc.dll
08:30:39.0393 0x0c5c lltdsvc - ok
08:30:39.0424 0x0c5c [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts C:\Windows\System32\lmhsvc.dll
08:30:39.0440 0x0c5c lmhosts - ok
08:30:39.0502 0x0c5c [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
08:30:39.0502 0x0c5c LSI_FC - ok
08:30:39.0549 0x0c5c [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
08:30:39.0549 0x0c5c LSI_SAS - ok
08:30:39.0627 0x0c5c [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
08:30:39.0627 0x0c5c LSI_SCSI - ok
08:30:39.0658 0x0c5c [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv C:\Windows\system32\drivers\luafv.sys
08:30:39.0674 0x0c5c luafv - ok
08:30:39.0721 0x0c5c [ AEF9BABB8A506BC4CE0451A64AADED46, D5608A703EA7E97F11ED4D029B4B820440B0C9317DB7D7DC0152253CD723DC07 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
08:30:39.0736 0x0c5c Mcx2Svc - ok
08:30:39.0783 0x0c5c [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas C:\Windows\system32\drivers\megasas.sys
08:30:39.0783 0x0c5c megasas - ok
08:30:39.0924 0x0c5c [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR C:\Windows\system32\drivers\megasr.sys
08:30:39.0955 0x0c5c MegaSR - ok
08:30:40.0080 0x0c5c [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
08:30:40.0095 0x0c5c Microsoft Office Groove Audit Service - ok
08:30:40.0142 0x0c5c [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS C:\Windows\system32\mmcss.dll
08:30:40.0158 0x0c5c MMCSS - ok
08:30:40.0189 0x0c5c [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem C:\Windows\system32\drivers\modem.sys
08:30:40.0204 0x0c5c Modem - ok
08:30:40.0236 0x0c5c [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
08:30:40.0236 0x0c5c monitor - ok
08:30:40.0282 0x0c5c [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
08:30:40.0282 0x0c5c mouclass - ok
08:30:40.0314 0x0c5c [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
08:30:40.0329 0x0c5c mouhid - ok
08:30:40.0345 0x0c5c [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
08:30:40.0360 0x0c5c MountMgr - ok
08:30:40.0485 0x0c5c [ 4E9D8041D352A33332FD6F59A3A78B03, D4E6229B07EF9866993EEE4F6223DC7F1FF1108273FE14A3DC74E65C181DE56A ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
08:30:40.0485 0x0c5c MozillaMaintenance - ok
08:30:40.0579 0x0c5c [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio C:\Windows\system32\drivers\mpio.sys
08:30:40.0594 0x0c5c mpio - ok
08:30:40.0641 0x0c5c [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
08:30:40.0657 0x0c5c mpsdrv - ok
08:30:40.0735 0x0c5c [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc C:\Windows\system32\mpssvc.dll
08:30:40.0782 0x0c5c MpsSvc - ok
08:30:40.0828 0x0c5c [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
08:30:40.0828 0x0c5c Mraid35x - ok
08:30:40.0906 0x0c5c [ 82CEA0395524AACFEB58BA1448E8325C, 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
08:30:40.0922 0x0c5c MRxDAV - ok
08:30:40.0984 0x0c5c [ 1E94971C4B446AB2290DEB71D01CF0C2, 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
08:30:40.0984 0x0c5c mrxsmb - ok
08:30:41.0078 0x0c5c [ 4FCCB34D793B116423209C0F8B7A3B03, 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:30:41.0094 0x0c5c mrxsmb10 - ok
08:30:41.0125 0x0c5c [ C3CB1B40AD4A0124D617A1199B0B9D7C, B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:30:41.0140 0x0c5c mrxsmb20 - ok
08:30:41.0172 0x0c5c [ 28023E86F17001F7CD9B15A5BC9AE07D, FC7EAA592C5F796E3BCD7F7EF261709CD899B33FC8486E594A480F143D0D6320 ] msahci C:\Windows\system32\drivers\msahci.sys
08:30:41.0172 0x0c5c msahci - ok
08:30:41.0218 0x0c5c [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm C:\Windows\system32\drivers\msdsm.sys
08:30:41.0234 0x0c5c msdsm - ok
08:30:41.0281 0x0c5c [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC C:\Windows\System32\msdtc.exe
08:30:41.0296 0x0c5c MSDTC - ok
08:30:41.0359 0x0c5c [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs C:\Windows\system32\drivers\Msfs.sys
08:30:41.0374 0x0c5c Msfs - ok
08:30:41.0452 0x0c5c [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
08:30:41.0468 0x0c5c msisadrv - ok
08:30:41.0515 0x0c5c [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
08:30:41.0546 0x0c5c MSiSCSI - ok
08:30:41.0562 0x0c5c msiserver - ok
08:30:41.0608 0x0c5c [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
08:30:41.0608 0x0c5c MSKSSRV - ok
08:30:41.0671 0x0c5c [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
08:30:41.0671 0x0c5c MSPCLOCK - ok
08:30:41.0733 0x0c5c [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
08:30:41.0749 0x0c5c MSPQM - ok
08:30:41.0811 0x0c5c [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
08:30:41.0827 0x0c5c MsRPC - ok
08:30:41.0920 0x0c5c [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
08:30:41.0920 0x0c5c mssmbios - ok
08:30:41.0983 0x0c5c [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
08:30:41.0983 0x0c5c MSTEE - ok
08:30:42.0076 0x0c5c [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup C:\Windows\system32\Drivers\mup.sys
08:30:42.0076 0x0c5c Mup - ok
08:30:42.0154 0x0c5c [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent C:\Windows\system32\qagentRT.dll
08:30:42.0186 0x0c5c napagent - ok
08:30:42.0279 0x0c5c [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
08:30:42.0295 0x0c5c NativeWifiP - ok
08:30:42.0388 0x0c5c [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS C:\Windows\system32\drivers\ndis.sys
08:30:42.0435 0x0c5c NDIS - ok
08:30:42.0466 0x0c5c [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
08:30:42.0482 0x0c5c NdisTapi - ok
08:30:42.0513 0x0c5c [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
08:30:42.0513 0x0c5c Ndisuio - ok
08:30:42.0560 0x0c5c [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
08:30:42.0560 0x0c5c NdisWan - ok
08:30:42.0607 0x0c5c [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
08:30:42.0607 0x0c5c NDProxy - ok
08:30:43.0012 0x0c5c [ A0101E836D2A39682E134C47B1565256, 5EE54165FE35B4319B935349612230AB771A46DFA229BDB002E9D28906CE0131 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
08:30:43.0059 0x0c5c Nero BackItUp Scheduler 3 - ok
08:30:43.0106 0x0c5c [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
08:30:43.0106 0x0c5c NetBIOS - ok
08:30:43.0200 0x0c5c [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt C:\Windows\system32\DRIVERS\netbt.sys
08:30:43.0215 0x0c5c netbt - ok
08:30:43.0278 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon C:\Windows\system32\lsass.exe
08:30:43.0293 0x0c5c Netlogon - ok
08:30:43.0402 0x0c5c [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman C:\Windows\System32\netman.dll
08:30:43.0434 0x0c5c Netman - ok
08:30:43.0527 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0543 0x0c5c NetMsmqActivator - ok
08:30:43.0621 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0636 0x0c5c NetPipeActivator - ok
08:30:43.0714 0x0c5c [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm C:\Windows\System32\netprofm.dll
08:30:43.0730 0x0c5c netprofm - ok
08:30:43.0808 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0824 0x0c5c NetTcpActivator - ok
08:30:43.0855 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0886 0x0c5c NetTcpPortSharing - ok
08:30:43.0964 0x0c5c [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
08:30:43.0964 0x0c5c nfrd960 - ok
08:30:44.0011 0x0c5c [ 2997B15415F9BBE05B5A4C1C85E0C6A2, 5455536515FE740E18E090329FDCC40288724372AD18ACDB2CB4BB9D85CF681E ] NlaSvc C:\Windows\System32\nlasvc.dll
08:30:44.0042 0x0c5c NlaSvc - ok
08:30:44.0307 0x0c5c [ 6EF0506CE1F553E9BD085645933C8686, D498F90F1CDA4FBB409110A72585CA0D33EE227E0EA20677A71F29CCE6AEB3BE ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
08:30:44.0338 0x0c5c NMIndexingService - ok
08:30:44.0448 0x0c5c [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs C:\Windows\system32\drivers\Npfs.sys
08:30:44.0463 0x0c5c Npfs - ok
08:30:44.0510 0x0c5c [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi C:\Windows\system32\nsisvc.dll
08:30:44.0526 0x0c5c nsi - ok
08:30:44.0650 0x0c5c [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
08:30:44.0650 0x0c5c nsiproxy - ok
08:30:45.0040 0x0c5c [ 2C1121F2B87E9A6B12485DF53CD848C7, E580428F3BA7B201C6C7CFADF1F44A6ECA4F589EDB034DA14260136236195936 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
08:30:45.0103 0x0c5c Ntfs - ok
08:30:45.0150 0x0c5c [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
08:30:45.0150 0x0c5c ntrigdigi - ok
08:30:45.0181 0x0c5c [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null C:\Windows\system32\drivers\Null.sys
08:30:45.0196 0x0c5c Null - ok
08:30:45.0259 0x0c5c [ 91601B20EFE9E8FECB435329A9E19D58, 6CD4C41AD9DB47344CF3FD730BD58A2BA0049EBE29FF37D868A86F0DA85D48D9 ] nvamacpi C:\Windows\system32\DRIVERS\NVAMACPI.sys
08:30:45.0259 0x0c5c nvamacpi - ok
08:30:45.0493 0x0c5c [ D958A2B5F6AD5C3B8CCDC4D7DA62466C, 574DC2C4C1C46E3B6F53E0A14E0595493E73EEE03EA1FF9DD1D3266B414B9941 ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
08:30:45.0555 0x0c5c NVENETFD - ok
08:30:46.0569 0x0c5c [ 9A77B1C13BCCEDDF78DFD7AFC25B4F5E, 88FA632754A20025F03FE0970C93F572055919F53C8A50E5DB6CF1EF7B00B7FD ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
08:30:47.0224 0x0c5c nvlddmkm - ok
08:30:47.0349 0x0c5c [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid C:\Windows\system32\drivers\nvraid.sys
08:30:47.0349 0x0c5c nvraid - ok
08:30:47.0412 0x0c5c [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor C:\Windows\system32\drivers\nvstor.sys
08:30:47.0427 0x0c5c nvstor - ok
08:30:47.0474 0x0c5c [ 8EE374B6FB3CB2BB8D70395218B464A5, AE409EDE8F89CD349BDB765C991470AAFB1FE0F39F25AAF9871B5E7EC3C7393D ] nvstor32 C:\Windows\system32\DRIVERS\nvstor32.sys
08:30:47.0490 0x0c5c nvstor32 - ok
08:30:47.0630 0x0c5c [ 31B8835B003CAA6D31BEAD83DDBF98E5, FB7C7BD1E95BEFB9A8FFEB3FB1B6D9BCD923E48498CB23169EDAA025C84CDD33 ] nvsvc C:\Windows\system32\nvvsvc.exe
08:30:47.0677 0x0c5c nvsvc - ok
08:30:47.0973 0x0c5c [ 0629259E3AF6BB0534FCECA208973404, E5DDA62D5D21D5D11A711BBFC5B839B59E336997C0C9A32A0B04AC9FBB6472D4 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
08:30:48.0145 0x0c5c nvUpdatusService - ok
08:30:48.0192 0x0c5c [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
08:30:48.0192 0x0c5c nv_agp - ok
08:30:48.0301 0x0c5c NwlnkFlt - ok
08:30:48.0316 0x0c5c NwlnkFwd - ok
08:30:48.0582 0x0c5c [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:30:48.0613 0x0c5c odserv - ok
08:30:48.0660 0x0c5c [ 790E27C3DB53410B40FF9EF2FD10A1D9, FD06F2702B8F7E04ECF1B6E88602F14301E7AE7FC44AD114282E580FAD530A9C ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
08:30:48.0675 0x0c5c ohci1394 - ok
08:30:48.0753 0x0c5c [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:30:48.0769 0x0c5c ose - ok
08:30:48.0940 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc C:\Windows\system32\p2psvc.dll
08:30:49.0018 0x0c5c p2pimsvc - ok
08:30:49.0081 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc C:\Windows\system32\p2psvc.dll
08:30:49.0128 0x0c5c p2psvc - ok
08:30:49.0284 0x0c5c [ 8A79FDF04A73428597E2CAF9D0D67850, DB438FDE5510AB2F350ED1AC4CF0E99D3CC665FE46533A438A8FDA4DAF950F93 ] Parport C:\Windows\system32\DRIVERS\parport.sys
08:30:49.0284 0x0c5c Parport - ok
08:30:49.0377 0x0c5c [ B9C2B89F08670E159F7181891E449CD9, BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A ] partmgr C:\Windows\system32\drivers\partmgr.sys
08:30:49.0377 0x0c5c partmgr - ok
08:30:49.0408 0x0c5c [ 6C580025C81CAF3AE9E3617C22CAD00E, 64F9061196462085E5DCD3ACB97A0D8FC67CA9A96DDD6E2103AFFF1593AE236A ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
08:30:49.0440 0x0c5c Parvdm - ok
08:30:49.0502 0x0c5c [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc C:\Windows\System32\pcasvc.dll
08:30:49.0533 0x0c5c PcaSvc - ok
08:30:49.0596 0x0c5c [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci C:\Windows\system32\drivers\pci.sys
08:30:49.0611 0x0c5c pci - ok
08:30:49.0658 0x0c5c [ 1636D43F10416AEB483BC6001097B26C, 36E61A993693A46538FE0F726D67BB28886F61D53384AD600D1282296A27662E ] pciide C:\Windows\system32\drivers\pciide.sys
08:30:49.0658 0x0c5c pciide - ok
08:30:49.0720 0x0c5c [ E6F3FB1B86AA519E7698AD05E58B04E5, 2C4B45DDD3B980C9DAA6F039CAEFCD6E84A4D5BB43AFBA73C0C42B5556C1303C ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
08:30:49.0736 0x0c5c pcmcia - ok
08:30:49.0845 0x0c5c [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
08:30:49.0908 0x0c5c PEAUTH - ok
08:30:50.0157 0x0c5c [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla C:\Windows\system32\pla.dll
08:30:50.0266 0x0c5c pla - ok
08:30:50.0360 0x0c5c [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
08:30:50.0391 0x0c5c PlugPlay - ok
08:30:50.0563 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
08:30:50.0610 0x0c5c PNRPAutoReg - ok
08:30:50.0672 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc C:\Windows\system32\p2psvc.dll
08:30:50.0719 0x0c5c PNRPsvc - ok
08:30:50.0812 0x0c5c [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
08:30:50.0844 0x0c5c PolicyAgent - ok
08:30:50.0890 0x0c5c [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
08:30:21.0141 0x0c44 ============================================================
08:30:21.0141 0x0c44 Current date / time: 2014/09/06 08:30:21.0141
08:30:21.0141 0x0c44 SystemInfo:
08:30:21.0141 0x0c44
08:30:21.0141 0x0c44 OS Version: 6.0.6002 ServicePack: 2.0
08:30:21.0141 0x0c44 Product type: Workstation
08:30:21.0141 0x0c44 ComputerName: EVA-PC
08:30:21.0141 0x0c44 UserName: Eva
08:30:21.0141 0x0c44 Windows directory: C:\Windows
08:30:21.0141 0x0c44 System windows directory: C:\Windows
08:30:21.0141 0x0c44 Processor architecture: Intel x86
08:30:21.0141 0x0c44 Number of processors: 1
08:30:21.0141 0x0c44 Page size: 0x1000
08:30:21.0141 0x0c44 Boot type: Normal boot
08:30:21.0141 0x0c44 ============================================================
08:30:21.0406 0x0c44 KLMD registered as C:\Windows\system32\drivers\43645563.sys
08:30:21.0609 0x0c44 System UUID: {30C31705-CFE4-7715-FC44-A018ADFB6E49}
08:30:22.0514 0x0c44 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
08:30:22.0545 0x0c44 ============================================================
08:30:22.0545 0x0c44 \Device\Harddisk0\DR0:
08:30:22.0561 0x0c44 MBR partitions:
08:30:22.0561 0x0c44 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2542D800
08:30:22.0561 0x0c44 ============================================================
08:30:22.0654 0x0c44 C: <-> \Device\Harddisk0\DR0\Partition1
08:30:22.0654 0x0c44 ============================================================
08:30:22.0654 0x0c44 Initialize success
08:30:22.0654 0x0c44 ============================================================
08:30:24.0807 0x0c5c ============================================================
08:30:24.0807 0x0c5c Scan started
08:30:24.0807 0x0c5c Mode: Manual;
08:30:24.0807 0x0c5c ============================================================
08:30:24.0823 0x0c5c KSN ping started
08:30:24.0838 0x0c5c KSN ping finished: false
08:30:25.0525 0x0c5c ================ Scan system memory ========================
08:30:25.0525 0x0c5c System memory - ok
08:30:25.0525 0x0c5c ================ Scan services =============================
08:30:25.0993 0x0c5c [ D9AF0082D3F09F5007E5727798786CD8, 3CFE9A1919433811F6C7A0B9F1D905A4D5F3F90B8C11B3C480E1A41A8CBB3A59 ] 3xHybrid C:\Windows\system32\DRIVERS\3xHybrid.sys
08:30:26.0040 0x0c5c 3xHybrid - ok
08:30:26.0164 0x0c5c [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI C:\Windows\system32\drivers\acpi.sys
08:30:26.0180 0x0c5c ACPI - ok
08:30:26.0289 0x0c5c [ F4BF3ADDDDC1AD372604F13C2B0C1F65, FA37ED5014336A72F778C485226B61BEFECEB861AB754862738795C167F0BAB7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
08:30:26.0305 0x0c5c AdobeFlashPlayerUpdateSvc - ok
08:30:26.0398 0x0c5c [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
08:30:26.0445 0x0c5c adp94xx - ok
08:30:26.0554 0x0c5c [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci C:\Windows\system32\drivers\adpahci.sys
08:30:26.0570 0x0c5c adpahci - ok
08:30:26.0617 0x0c5c [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
08:30:26.0632 0x0c5c adpu160m - ok
08:30:26.0710 0x0c5c [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
08:30:26.0726 0x0c5c adpu320 - ok
08:30:26.0788 0x0c5c [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
08:30:26.0804 0x0c5c AeLookupSvc - ok
08:30:26.0944 0x0c5c [ F5272A105F59A7B3B345D9D6D87DA7AD, 9E84776994D04240BF2537330DBB555EDE16DFCFC59DEDCBA05A44ED7F70BEFA ] AFD C:\Windows\system32\drivers\afd.sys
08:30:26.0991 0x0c5c AFD - ok
08:30:27.0038 0x0c5c [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440 C:\Windows\system32\drivers\agp440.sys
08:30:27.0038 0x0c5c agp440 - ok
08:30:27.0085 0x0c5c [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
08:30:27.0085 0x0c5c aic78xx - ok
08:30:27.0116 0x0c5c [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG C:\Windows\System32\alg.exe
08:30:27.0132 0x0c5c ALG - ok
08:30:27.0163 0x0c5c [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide C:\Windows\system32\drivers\aliide.sys
08:30:27.0178 0x0c5c aliide - ok
08:30:27.0225 0x0c5c [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp C:\Windows\system32\drivers\amdagp.sys
08:30:27.0241 0x0c5c amdagp - ok
08:30:27.0256 0x0c5c [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide C:\Windows\system32\drivers\amdide.sys
08:30:27.0272 0x0c5c amdide - ok
08:30:27.0334 0x0c5c [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
08:30:27.0334 0x0c5c AmdK7 - ok
08:30:27.0381 0x0c5c [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
08:30:27.0381 0x0c5c AmdK8 - ok
08:30:27.0490 0x0c5c [ 8F7D200717A58E9800D391F4C2101577, F07CF0F5636F46D8F3D5133284943E991E8739E5A644BCA5F18BB896B374620D ] Appinfo C:\Windows\System32\appinfo.dll
08:30:27.0522 0x0c5c Appinfo - ok
08:30:27.0553 0x0c5c [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc C:\Windows\system32\drivers\arc.sys
08:30:27.0568 0x0c5c arc - ok
08:30:27.0600 0x0c5c [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas C:\Windows\system32\drivers\arcsas.sys
08:30:27.0600 0x0c5c arcsas - ok
08:30:27.0787 0x0c5c [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
08:30:27.0818 0x0c5c aspnet_state - ok
08:30:27.0896 0x0c5c [ 3BFBB5DAE801CB893B8B46345FED6437, 2C2B71C1294585265D4871E74F17541500CA20DE34AC516F2A906DD81964C833 ] aswHwid C:\Windows\system32\drivers\aswHwid.sys
08:30:27.0896 0x0c5c aswHwid - ok
08:30:28.0052 0x0c5c [ C3014C735F450FE822C97FFBB0627113, 1CCFE845AED1757B8C1F52D310933076FF1EC197D82E499DB4592B09D66137B0 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
08:30:28.0052 0x0c5c aswMonFlt - ok
08:30:28.0192 0x0c5c [ D6C9024F5D14843D33ADA8A6A10A1BE1, D40022D0A360FD4010D3D5D452BBC4CE9EE68224DEAB9584626E6F435E128857 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
08:30:28.0208 0x0c5c aswRdr - ok
08:30:28.0270 0x0c5c [ B7750AF7EDFD95674EB7CA92BCDD3358, A097577004F3CF71E2F9465F02B073D39926D7DEE2E2A9516D888158A5CB19E9 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
08:30:28.0286 0x0c5c aswRvrt - ok
08:30:28.0395 0x0c5c [ 51FDE588D860857A97E4C4B560E40C9B, 8A3AC3E55249DAE6CCD95593989F8B100D5C4712A16681A36E5D0F2F08BD57AA ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
08:30:28.0442 0x0c5c aswSnx - ok
08:30:28.0536 0x0c5c [ 1AEB8CDB797666AF709A291B47AE81E0, 12AC4DBC6338BA5E5C04B449FF8362E7EC8EBFCA675C4F21BE847DFDCAE8F7C9 ] aswSP C:\Windows\system32\drivers\aswSP.sys
08:30:28.0551 0x0c5c aswSP - ok
08:30:28.0598 0x0c5c [ 26C51C289E39E8EE0F12B8B06B71E436, 81382FC3E836698432EE832A166F09251CC9164B17584E90F73037A1FA54E4F7 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
08:30:28.0614 0x0c5c aswTdi - ok
08:30:28.0660 0x0c5c [ 90BEE0170D70D6744CEF2355EEAF8086, 8F9FF53F529B854934020E2F8163605DC794FF48464D3D4439BAAF70ECE8E963 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
08:30:28.0676 0x0c5c aswVmm - ok
08:30:28.0770 0x0c5c [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
08:30:28.0770 0x0c5c AsyncMac - ok
08:30:28.0848 0x0c5c [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi C:\Windows\system32\drivers\atapi.sys
08:30:28.0848 0x0c5c atapi - ok
08:30:28.0957 0x0c5c [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
08:30:28.0972 0x0c5c AudioEndpointBuilder - ok
08:30:29.0019 0x0c5c [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv C:\Windows\System32\Audiosrv.dll
08:30:29.0035 0x0c5c Audiosrv - ok
08:30:29.0160 0x0c5c [ 73F5C13B431915BAE35254B4E95DFB71, 393A045859382C44133C004598B1512048046BCC129FED2247A77FDBFCDB6DFF ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
08:30:29.0160 0x0c5c avast! Antivirus - ok
08:30:29.0269 0x0c5c [ E03A1466A8A7B869EBC90B179D777EA4, 5F4EBE04C9ACE28DE7AD34603998C282132B66BB9620017AF677A94BA2FE872E ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
08:30:29.0284 0x0c5c avgtp - ok
08:30:29.0347 0x0c5c [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep C:\Windows\system32\drivers\Beep.sys
08:30:29.0362 0x0c5c Beep - ok
08:30:29.0456 0x0c5c [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE C:\Windows\System32\bfe.dll
08:30:29.0518 0x0c5c BFE - ok
08:30:29.0721 0x0c5c [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS C:\Windows\System32\qmgr.dll
08:30:29.0799 0x0c5c BITS - ok
08:30:29.0830 0x0c5c [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
08:30:29.0846 0x0c5c blbdrive - ok
08:30:29.0893 0x0c5c [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
08:30:29.0893 0x0c5c bowser - ok
08:30:29.0955 0x0c5c [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
08:30:29.0955 0x0c5c BrFiltLo - ok
08:30:29.0986 0x0c5c [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
08:30:29.0986 0x0c5c BrFiltUp - ok
08:30:30.0033 0x0c5c [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser C:\Windows\System32\browser.dll
08:30:30.0033 0x0c5c Browser - ok
08:30:30.0080 0x0c5c [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid C:\Windows\system32\drivers\brserid.sys
08:30:30.0080 0x0c5c Brserid - ok
08:30:30.0111 0x0c5c [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
08:30:30.0127 0x0c5c BrSerWdm - ok
08:30:30.0158 0x0c5c [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
08:30:30.0158 0x0c5c BrUsbMdm - ok
08:30:30.0189 0x0c5c [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
08:30:30.0205 0x0c5c BrUsbSer - ok
08:30:30.0252 0x0c5c [ AD07C1EC6665B8B35741AB91200C6B68, DCE1305A30D6713222A01C1F1D03ED0ADABE23C742CE1E82BB142531B82A3FF7 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
08:30:30.0252 0x0c5c BTHMODEM - ok
08:30:30.0298 0x0c5c [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
08:30:30.0314 0x0c5c cdfs - ok
08:30:30.0345 0x0c5c [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
08:30:30.0361 0x0c5c cdrom - ok
08:30:30.0408 0x0c5c [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc C:\Windows\System32\certprop.dll
08:30:30.0423 0x0c5c CertPropSvc - ok
08:30:30.0454 0x0c5c [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass C:\Windows\system32\drivers\circlass.sys
08:30:30.0454 0x0c5c circlass - ok
08:30:30.0532 0x0c5c [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS C:\Windows\system32\CLFS.sys
08:30:30.0548 0x0c5c CLFS - ok
08:30:30.0657 0x0c5c [ 6B6943A0CA56B47D6FB2EE476890854F, 6DA779879487F4A187DF54B0362642643D7871AA8F7E30992D781F558C50F052 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:30:30.0657 0x0c5c clr_optimization_v2.0.50727_32 - ok
08:30:30.0782 0x0c5c [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:30:30.0829 0x0c5c clr_optimization_v4.0.30319_32 - ok
08:30:30.0876 0x0c5c [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide C:\Windows\system32\drivers\cmdide.sys
08:30:30.0876 0x0c5c cmdide - ok
08:30:30.0907 0x0c5c [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
08:30:30.0907 0x0c5c Compbatt - ok
08:30:30.0938 0x0c5c COMSysApp - ok
08:30:30.0985 0x0c5c [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
08:30:30.0985 0x0c5c crcdisk - ok
08:30:31.0063 0x0c5c [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe C:\Windows\system32\drivers\crusoe.sys
08:30:31.0078 0x0c5c Crusoe - ok
08:30:31.0172 0x0c5c [ 684C130BBC6DB681BAD4920A4C944AA5, DDE434B206984808351C98500824A33E6740B4326C455066027F8D549D4C3B92 ] CryptSvc C:\Windows\system32\cryptsvc.dll
08:30:31.0188 0x0c5c CryptSvc - ok
08:30:31.0312 0x0c5c [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch C:\Windows\system32\rpcss.dll
08:30:31.0375 0x0c5c DcomLaunch - ok
08:30:31.0437 0x0c5c [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
08:30:31.0437 0x0c5c DfsC - ok
08:30:31.0640 0x0c5c [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR C:\Windows\system32\DFSR.exe
08:30:31.0858 0x0c5c DFSR - ok
08:30:32.0202 0x0c5c [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
08:30:32.0217 0x0c5c Dhcp - ok
08:30:32.0311 0x0c5c [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk C:\Windows\system32\drivers\disk.sys
08:30:32.0311 0x0c5c disk - ok
08:30:32.0404 0x0c5c [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache C:\Windows\System32\dnsrslvr.dll
08:30:32.0404 0x0c5c Dnscache - ok
08:30:32.0514 0x0c5c [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc C:\Windows\System32\dot3svc.dll
08:30:32.0529 0x0c5c dot3svc - ok
08:30:32.0592 0x0c5c [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS C:\Windows\system32\dps.dll
08:30:32.0592 0x0c5c DPS - ok
08:30:32.0670 0x0c5c [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
08:30:32.0670 0x0c5c drmkaud - ok
08:30:32.0779 0x0c5c [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
08:30:32.0794 0x0c5c dtsoftbus01 - ok
08:30:32.0872 0x0c5c [ 5C2C209CDEFBC51D83D66E8A53B2BE89, 7AE68672A6BEEF601017BE28AA0BF3673318EFE97AA08E70F58A9391C54DF71F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
08:30:32.0919 0x0c5c DXGKrnl - ok
08:30:32.0982 0x0c5c [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
08:30:32.0982 0x0c5c E1G60 - ok
08:30:33.0044 0x0c5c [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost C:\Windows\System32\eapsvc.dll
08:30:33.0075 0x0c5c EapHost - ok
08:30:33.0153 0x0c5c [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache C:\Windows\system32\drivers\ecache.sys
08:30:33.0169 0x0c5c Ecache - ok
08:30:33.0247 0x0c5c [ 9BE3744D295A7701EB425332014F0797, 1A139EE9232581E466591C5EBEF41E4BF1F82D99C1959F1C68C879B240E9F46D ] ehRecvr C:\Windows\ehome\ehRecvr.exe
08:30:33.0294 0x0c5c ehRecvr - ok
08:30:33.0356 0x0c5c [ AD1870C8E5D6DD340C829E6074BF3C3F, 064D07106A1BBE80294F1913354832F2B67D22274BB4D36C81D2D83C96FE0B88 ] ehSched C:\Windows\ehome\ehsched.exe
08:30:33.0372 0x0c5c ehSched - ok
08:30:33.0403 0x0c5c [ C27C4EE8926E74AA72EFCAB24C5242C3, F1EBF78CCE9BA76AFD0478BC66B67CA44DEAF3C380369BFCE91BD8F678C8608A ] ehstart C:\Windows\ehome\ehstart.dll
08:30:33.0403 0x0c5c ehstart - ok
08:30:33.0496 0x0c5c [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor C:\Windows\system32\drivers\elxstor.sys
08:30:33.0543 0x0c5c elxstor - ok
08:30:33.0621 0x0c5c [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
08:30:33.0668 0x0c5c EMDMgmt - ok
08:30:33.0699 0x0c5c [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev C:\Windows\system32\drivers\errdev.sys
08:30:33.0699 0x0c5c ErrDev - ok
08:30:33.0824 0x0c5c [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem C:\Windows\system32\es.dll
08:30:33.0855 0x0c5c EventSystem - ok
08:30:33.0933 0x0c5c [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat C:\Windows\system32\drivers\exfat.sys
08:30:33.0949 0x0c5c exfat - ok
08:30:34.0027 0x0c5c [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat C:\Windows\system32\drivers\fastfat.sys
08:30:34.0042 0x0c5c fastfat - ok
08:30:34.0105 0x0c5c [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc C:\Windows\system32\DRIVERS\fdc.sys
08:30:34.0105 0x0c5c fdc - ok
08:30:34.0152 0x0c5c [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost C:\Windows\system32\fdPHost.dll
08:30:34.0167 0x0c5c fdPHost - ok
08:30:34.0198 0x0c5c [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub C:\Windows\system32\fdrespub.dll
08:30:34.0198 0x0c5c FDResPub - ok
08:30:34.0245 0x0c5c [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
08:30:34.0245 0x0c5c FileInfo - ok
08:30:34.0292 0x0c5c [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
08:30:34.0292 0x0c5c Filetrace - ok
08:30:34.0323 0x0c5c [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
08:30:34.0339 0x0c5c flpydisk - ok
08:30:34.0417 0x0c5c [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
08:30:34.0432 0x0c5c FltMgr - ok
08:30:34.0573 0x0c5c [ 2AFA3A46986AE935DAECEBC7E66314CF, 747FAF9B7F8291B83EE44B91E5708395E749DC87BD42CC3BF2CD41209C298F4D ] FontCache C:\Windows\system32\FntCache.dll
08:30:34.0635 0x0c5c FontCache - ok
08:30:34.0729 0x0c5c [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
08:30:34.0729 0x0c5c FontCache3.0.0.0 - ok
08:30:34.0854 0x0c5c [ B0082808A6856A252F7CDD939892CE50, 3A069239629C4F54049A2CFC6642AC5102ECEAA74470BAA9DDB1AB108D1060EE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
08:30:34.0869 0x0c5c fssfltr - ok
08:30:35.0134 0x0c5c [ 28DDEEEC44E988657B732CF404D504CB, 47F83018E5449CDCED3DD447991788EBAAC92C418D4513FBA9408C45E9AB8E7E ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
08:30:35.0244 0x0c5c fsssvc - ok
08:30:35.0306 0x0c5c [ B972A66758577E0BFD1DE0F91AAA27B5, E934034F3F740A83D4E7ABCD2C581845AC2945B0BCCAACF65CC3F99A1DBDE455 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
08:30:35.0306 0x0c5c Fs_Rec - ok
08:30:35.0353 0x0c5c [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
08:30:35.0368 0x0c5c gagp30kx - ok
08:30:35.0462 0x0c5c [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc C:\Windows\System32\gpsvc.dll
08:30:35.0493 0x0c5c gpsvc - ok
08:30:35.0618 0x0c5c [ 626A24ED1228580B9518C01930936DF9, CBD94AB1E5477D7288799D17528CC43D572E711DA0F2B0C784A0B9FE105BF0F4 ] gupdate1c9a326fd1c5f6 C:\Program Files\Google\Update\GoogleUpdate.exe
08:30:35.0634 0x0c5c gupdate1c9a326fd1c5f6 - ok
08:30:35.0665 0x0c5c [ 626A24ED1228580B9518C01930936DF9, CBD94AB1E5477D7288799D17528CC43D572E711DA0F2B0C784A0B9FE105BF0F4 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
08:30:35.0680 0x0c5c gupdatem - ok
08:30:35.0774 0x0c5c [ CB04C744BE0A61B1D648FAED182C3B59, 61DC0FF94325DAFCCB7B3980A48727EFBF1283FCF753EC16EF04C730525994C0 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
08:30:35.0805 0x0c5c HdAudAddService - ok
08:30:35.0914 0x0c5c [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
08:30:35.0946 0x0c5c HDAudBus - ok
08:30:35.0992 0x0c5c [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth C:\Windows\system32\drivers\hidbth.sys
08:30:35.0992 0x0c5c HidBth - ok
08:30:36.0039 0x0c5c [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr C:\Windows\system32\drivers\hidir.sys
08:30:36.0055 0x0c5c HidIr - ok
08:30:36.0102 0x0c5c [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv C:\Windows\system32\hidserv.dll
08:30:36.0102 0x0c5c hidserv - ok
08:30:36.0148 0x0c5c [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
08:30:36.0148 0x0c5c HidUsb - ok
08:30:36.0211 0x0c5c [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc C:\Windows\system32\kmsvc.dll
08:30:36.0226 0x0c5c hkmsvc - ok
08:30:36.0258 0x0c5c [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
08:30:36.0258 0x0c5c HpCISSs - ok
08:30:36.0336 0x0c5c [ F870AA3E254628EBEAFE754108D664DE, B0444E7D246AA1982094030ACB991690F6A7DD3FB07B1BB6A1BC0F3AA9718A70 ] HTTP C:\Windows\system32\drivers\HTTP.sys
08:30:36.0367 0x0c5c HTTP - ok
08:30:36.0398 0x0c5c [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
08:30:36.0414 0x0c5c i2omp - ok
08:30:36.0492 0x0c5c [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
08:30:36.0492 0x0c5c i8042prt - ok
08:30:36.0538 0x0c5c [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
08:30:36.0570 0x0c5c iaStorV - ok
08:30:36.0757 0x0c5c [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
08:30:36.0757 0x0c5c IDriverT - ok
08:30:36.0928 0x0c5c [ DD386C45D2B5863740166783448A2E7A, 10B912BA70306644BE73A53AF4DCDFF63880C4C5860FF6DBA92B0914EB566718 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
08:30:36.0991 0x0c5c idsvc - ok
08:30:37.0038 0x0c5c [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp C:\Windows\system32\drivers\iirsp.sys
08:30:37.0053 0x0c5c iirsp - ok
08:30:37.0194 0x0c5c [ 755519F49906B73C1FE9CBBF75E347EA, 20FF0D235478C693AB0708DF040EDA2ED8D4856EFCACD0A0ABD25E49330810FC ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
08:30:37.0194 0x0c5c IJPLMSVC - ok
08:30:37.0350 0x0c5c [ 4687EE0C0DD2CE5F7AAA9C2E33C1DC78, FA8EBED2778D9F7560ADC1B563954EEF98AAE651C0553F2803372B37B122AEB3 ] IKEEXT C:\Windows\System32\ikeext.dll
08:30:37.0365 0x0c5c IKEEXT - ok
08:30:37.0802 0x0c5c [ 126C1E93D4D3EA3E0AAA0557873AE646, 08C3CBE7FD629CAD38E2CF33CC4644FBBCD90872EA082EF81A87B4E84BF3324A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
08:30:37.0911 0x0c5c IntcAzAudAddService - ok
08:30:37.0974 0x0c5c [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide C:\Windows\system32\drivers\intelide.sys
08:30:37.0974 0x0c5c intelide - ok
08:30:38.0020 0x0c5c [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
08:30:38.0020 0x0c5c intelppm - ok
08:30:38.0098 0x0c5c [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
08:30:38.0114 0x0c5c IPBusEnum - ok
08:30:38.0145 0x0c5c [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:30:38.0145 0x0c5c IpFilterDriver - ok
08:30:38.0239 0x0c5c [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
08:30:38.0254 0x0c5c iphlpsvc - ok
08:30:38.0286 0x0c5c IpInIp - ok
08:30:38.0317 0x0c5c [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
08:30:38.0332 0x0c5c IPMIDRV - ok
08:30:38.0379 0x0c5c [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
08:30:38.0379 0x0c5c IPNAT - ok
08:30:38.0426 0x0c5c [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM C:\Windows\system32\drivers\irenum.sys
08:30:38.0426 0x0c5c IRENUM - ok
08:30:38.0457 0x0c5c [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp C:\Windows\system32\drivers\isapnp.sys
08:30:38.0473 0x0c5c isapnp - ok
08:30:38.0535 0x0c5c [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
08:30:38.0535 0x0c5c iScsiPrt - ok
08:30:38.0582 0x0c5c [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
08:30:38.0598 0x0c5c iteatapi - ok
08:30:38.0629 0x0c5c [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid C:\Windows\system32\drivers\iteraid.sys
08:30:38.0629 0x0c5c iteraid - ok
08:30:38.0676 0x0c5c [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
08:30:38.0676 0x0c5c kbdclass - ok
08:30:38.0738 0x0c5c [ EDE59EC70E25C24581ADD1FBEC7325F7, 41B37778E9A12675FC0DF74606AAF18C652EB88513B3C4889C5C512E14587CEE ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
08:30:38.0738 0x0c5c kbdhid - ok
08:30:38.0800 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso C:\Windows\system32\lsass.exe
08:30:38.0800 0x0c5c KeyIso - ok
08:30:38.0925 0x0c5c [ 4A1445EFA932A3BAF5BDB02D7131EE20, 9DD262ED72DF268FE024063788F54124E320D0775D8DC0C5CAD099CD5F655DA2 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
08:30:38.0956 0x0c5c KSecDD - ok
08:30:39.0066 0x0c5c [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm C:\Windows\system32\msdtckrm.dll
08:30:39.0097 0x0c5c KtmRm - ok
08:30:39.0159 0x0c5c [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer C:\Windows\system32\srvsvc.dll
08:30:39.0175 0x0c5c LanmanServer - ok
08:30:39.0222 0x0c5c [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
08:30:39.0253 0x0c5c LanmanWorkstation - ok
08:30:39.0300 0x0c5c [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
08:30:39.0315 0x0c5c lltdio - ok
08:30:39.0378 0x0c5c [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc C:\Windows\System32\lltdsvc.dll
08:30:39.0393 0x0c5c lltdsvc - ok
08:30:39.0424 0x0c5c [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts C:\Windows\System32\lmhsvc.dll
08:30:39.0440 0x0c5c lmhosts - ok
08:30:39.0502 0x0c5c [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
08:30:39.0502 0x0c5c LSI_FC - ok
08:30:39.0549 0x0c5c [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
08:30:39.0549 0x0c5c LSI_SAS - ok
08:30:39.0627 0x0c5c [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
08:30:39.0627 0x0c5c LSI_SCSI - ok
08:30:39.0658 0x0c5c [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv C:\Windows\system32\drivers\luafv.sys
08:30:39.0674 0x0c5c luafv - ok
08:30:39.0721 0x0c5c [ AEF9BABB8A506BC4CE0451A64AADED46, D5608A703EA7E97F11ED4D029B4B820440B0C9317DB7D7DC0152253CD723DC07 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
08:30:39.0736 0x0c5c Mcx2Svc - ok
08:30:39.0783 0x0c5c [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas C:\Windows\system32\drivers\megasas.sys
08:30:39.0783 0x0c5c megasas - ok
08:30:39.0924 0x0c5c [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR C:\Windows\system32\drivers\megasr.sys
08:30:39.0955 0x0c5c MegaSR - ok
08:30:40.0080 0x0c5c [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
08:30:40.0095 0x0c5c Microsoft Office Groove Audit Service - ok
08:30:40.0142 0x0c5c [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS C:\Windows\system32\mmcss.dll
08:30:40.0158 0x0c5c MMCSS - ok
08:30:40.0189 0x0c5c [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem C:\Windows\system32\drivers\modem.sys
08:30:40.0204 0x0c5c Modem - ok
08:30:40.0236 0x0c5c [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
08:30:40.0236 0x0c5c monitor - ok
08:30:40.0282 0x0c5c [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
08:30:40.0282 0x0c5c mouclass - ok
08:30:40.0314 0x0c5c [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
08:30:40.0329 0x0c5c mouhid - ok
08:30:40.0345 0x0c5c [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
08:30:40.0360 0x0c5c MountMgr - ok
08:30:40.0485 0x0c5c [ 4E9D8041D352A33332FD6F59A3A78B03, D4E6229B07EF9866993EEE4F6223DC7F1FF1108273FE14A3DC74E65C181DE56A ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
08:30:40.0485 0x0c5c MozillaMaintenance - ok
08:30:40.0579 0x0c5c [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio C:\Windows\system32\drivers\mpio.sys
08:30:40.0594 0x0c5c mpio - ok
08:30:40.0641 0x0c5c [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
08:30:40.0657 0x0c5c mpsdrv - ok
08:30:40.0735 0x0c5c [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc C:\Windows\system32\mpssvc.dll
08:30:40.0782 0x0c5c MpsSvc - ok
08:30:40.0828 0x0c5c [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
08:30:40.0828 0x0c5c Mraid35x - ok
08:30:40.0906 0x0c5c [ 82CEA0395524AACFEB58BA1448E8325C, 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
08:30:40.0922 0x0c5c MRxDAV - ok
08:30:40.0984 0x0c5c [ 1E94971C4B446AB2290DEB71D01CF0C2, 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
08:30:40.0984 0x0c5c mrxsmb - ok
08:30:41.0078 0x0c5c [ 4FCCB34D793B116423209C0F8B7A3B03, 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:30:41.0094 0x0c5c mrxsmb10 - ok
08:30:41.0125 0x0c5c [ C3CB1B40AD4A0124D617A1199B0B9D7C, B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:30:41.0140 0x0c5c mrxsmb20 - ok
08:30:41.0172 0x0c5c [ 28023E86F17001F7CD9B15A5BC9AE07D, FC7EAA592C5F796E3BCD7F7EF261709CD899B33FC8486E594A480F143D0D6320 ] msahci C:\Windows\system32\drivers\msahci.sys
08:30:41.0172 0x0c5c msahci - ok
08:30:41.0218 0x0c5c [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm C:\Windows\system32\drivers\msdsm.sys
08:30:41.0234 0x0c5c msdsm - ok
08:30:41.0281 0x0c5c [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC C:\Windows\System32\msdtc.exe
08:30:41.0296 0x0c5c MSDTC - ok
08:30:41.0359 0x0c5c [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs C:\Windows\system32\drivers\Msfs.sys
08:30:41.0374 0x0c5c Msfs - ok
08:30:41.0452 0x0c5c [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
08:30:41.0468 0x0c5c msisadrv - ok
08:30:41.0515 0x0c5c [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
08:30:41.0546 0x0c5c MSiSCSI - ok
08:30:41.0562 0x0c5c msiserver - ok
08:30:41.0608 0x0c5c [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
08:30:41.0608 0x0c5c MSKSSRV - ok
08:30:41.0671 0x0c5c [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
08:30:41.0671 0x0c5c MSPCLOCK - ok
08:30:41.0733 0x0c5c [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
08:30:41.0749 0x0c5c MSPQM - ok
08:30:41.0811 0x0c5c [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
08:30:41.0827 0x0c5c MsRPC - ok
08:30:41.0920 0x0c5c [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
08:30:41.0920 0x0c5c mssmbios - ok
08:30:41.0983 0x0c5c [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
08:30:41.0983 0x0c5c MSTEE - ok
08:30:42.0076 0x0c5c [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup C:\Windows\system32\Drivers\mup.sys
08:30:42.0076 0x0c5c Mup - ok
08:30:42.0154 0x0c5c [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent C:\Windows\system32\qagentRT.dll
08:30:42.0186 0x0c5c napagent - ok
08:30:42.0279 0x0c5c [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
08:30:42.0295 0x0c5c NativeWifiP - ok
08:30:42.0388 0x0c5c [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS C:\Windows\system32\drivers\ndis.sys
08:30:42.0435 0x0c5c NDIS - ok
08:30:42.0466 0x0c5c [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
08:30:42.0482 0x0c5c NdisTapi - ok
08:30:42.0513 0x0c5c [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
08:30:42.0513 0x0c5c Ndisuio - ok
08:30:42.0560 0x0c5c [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
08:30:42.0560 0x0c5c NdisWan - ok
08:30:42.0607 0x0c5c [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
08:30:42.0607 0x0c5c NDProxy - ok
08:30:43.0012 0x0c5c [ A0101E836D2A39682E134C47B1565256, 5EE54165FE35B4319B935349612230AB771A46DFA229BDB002E9D28906CE0131 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
08:30:43.0059 0x0c5c Nero BackItUp Scheduler 3 - ok
08:30:43.0106 0x0c5c [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
08:30:43.0106 0x0c5c NetBIOS - ok
08:30:43.0200 0x0c5c [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt C:\Windows\system32\DRIVERS\netbt.sys
08:30:43.0215 0x0c5c netbt - ok
08:30:43.0278 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon C:\Windows\system32\lsass.exe
08:30:43.0293 0x0c5c Netlogon - ok
08:30:43.0402 0x0c5c [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman C:\Windows\System32\netman.dll
08:30:43.0434 0x0c5c Netman - ok
08:30:43.0527 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0543 0x0c5c NetMsmqActivator - ok
08:30:43.0621 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0636 0x0c5c NetPipeActivator - ok
08:30:43.0714 0x0c5c [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm C:\Windows\System32\netprofm.dll
08:30:43.0730 0x0c5c netprofm - ok
08:30:43.0808 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0824 0x0c5c NetTcpActivator - ok
08:30:43.0855 0x0c5c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
08:30:43.0886 0x0c5c NetTcpPortSharing - ok
08:30:43.0964 0x0c5c [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
08:30:43.0964 0x0c5c nfrd960 - ok
08:30:44.0011 0x0c5c [ 2997B15415F9BBE05B5A4C1C85E0C6A2, 5455536515FE740E18E090329FDCC40288724372AD18ACDB2CB4BB9D85CF681E ] NlaSvc C:\Windows\System32\nlasvc.dll
08:30:44.0042 0x0c5c NlaSvc - ok
08:30:44.0307 0x0c5c [ 6EF0506CE1F553E9BD085645933C8686, D498F90F1CDA4FBB409110A72585CA0D33EE227E0EA20677A71F29CCE6AEB3BE ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
08:30:44.0338 0x0c5c NMIndexingService - ok
08:30:44.0448 0x0c5c [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs C:\Windows\system32\drivers\Npfs.sys
08:30:44.0463 0x0c5c Npfs - ok
08:30:44.0510 0x0c5c [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi C:\Windows\system32\nsisvc.dll
08:30:44.0526 0x0c5c nsi - ok
08:30:44.0650 0x0c5c [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
08:30:44.0650 0x0c5c nsiproxy - ok
08:30:45.0040 0x0c5c [ 2C1121F2B87E9A6B12485DF53CD848C7, E580428F3BA7B201C6C7CFADF1F44A6ECA4F589EDB034DA14260136236195936 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
08:30:45.0103 0x0c5c Ntfs - ok
08:30:45.0150 0x0c5c [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
08:30:45.0150 0x0c5c ntrigdigi - ok
08:30:45.0181 0x0c5c [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null C:\Windows\system32\drivers\Null.sys
08:30:45.0196 0x0c5c Null - ok
08:30:45.0259 0x0c5c [ 91601B20EFE9E8FECB435329A9E19D58, 6CD4C41AD9DB47344CF3FD730BD58A2BA0049EBE29FF37D868A86F0DA85D48D9 ] nvamacpi C:\Windows\system32\DRIVERS\NVAMACPI.sys
08:30:45.0259 0x0c5c nvamacpi - ok
08:30:45.0493 0x0c5c [ D958A2B5F6AD5C3B8CCDC4D7DA62466C, 574DC2C4C1C46E3B6F53E0A14E0595493E73EEE03EA1FF9DD1D3266B414B9941 ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
08:30:45.0555 0x0c5c NVENETFD - ok
08:30:46.0569 0x0c5c [ 9A77B1C13BCCEDDF78DFD7AFC25B4F5E, 88FA632754A20025F03FE0970C93F572055919F53C8A50E5DB6CF1EF7B00B7FD ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
08:30:47.0224 0x0c5c nvlddmkm - ok
08:30:47.0349 0x0c5c [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid C:\Windows\system32\drivers\nvraid.sys
08:30:47.0349 0x0c5c nvraid - ok
08:30:47.0412 0x0c5c [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor C:\Windows\system32\drivers\nvstor.sys
08:30:47.0427 0x0c5c nvstor - ok
08:30:47.0474 0x0c5c [ 8EE374B6FB3CB2BB8D70395218B464A5, AE409EDE8F89CD349BDB765C991470AAFB1FE0F39F25AAF9871B5E7EC3C7393D ] nvstor32 C:\Windows\system32\DRIVERS\nvstor32.sys
08:30:47.0490 0x0c5c nvstor32 - ok
08:30:47.0630 0x0c5c [ 31B8835B003CAA6D31BEAD83DDBF98E5, FB7C7BD1E95BEFB9A8FFEB3FB1B6D9BCD923E48498CB23169EDAA025C84CDD33 ] nvsvc C:\Windows\system32\nvvsvc.exe
08:30:47.0677 0x0c5c nvsvc - ok
08:30:47.0973 0x0c5c [ 0629259E3AF6BB0534FCECA208973404, E5DDA62D5D21D5D11A711BBFC5B839B59E336997C0C9A32A0B04AC9FBB6472D4 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
08:30:48.0145 0x0c5c nvUpdatusService - ok
08:30:48.0192 0x0c5c [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
08:30:48.0192 0x0c5c nv_agp - ok
08:30:48.0301 0x0c5c NwlnkFlt - ok
08:30:48.0316 0x0c5c NwlnkFwd - ok
08:30:48.0582 0x0c5c [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:30:48.0613 0x0c5c odserv - ok
08:30:48.0660 0x0c5c [ 790E27C3DB53410B40FF9EF2FD10A1D9, FD06F2702B8F7E04ECF1B6E88602F14301E7AE7FC44AD114282E580FAD530A9C ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
08:30:48.0675 0x0c5c ohci1394 - ok
08:30:48.0753 0x0c5c [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:30:48.0769 0x0c5c ose - ok
08:30:48.0940 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc C:\Windows\system32\p2psvc.dll
08:30:49.0018 0x0c5c p2pimsvc - ok
08:30:49.0081 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc C:\Windows\system32\p2psvc.dll
08:30:49.0128 0x0c5c p2psvc - ok
08:30:49.0284 0x0c5c [ 8A79FDF04A73428597E2CAF9D0D67850, DB438FDE5510AB2F350ED1AC4CF0E99D3CC665FE46533A438A8FDA4DAF950F93 ] Parport C:\Windows\system32\DRIVERS\parport.sys
08:30:49.0284 0x0c5c Parport - ok
08:30:49.0377 0x0c5c [ B9C2B89F08670E159F7181891E449CD9, BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A ] partmgr C:\Windows\system32\drivers\partmgr.sys
08:30:49.0377 0x0c5c partmgr - ok
08:30:49.0408 0x0c5c [ 6C580025C81CAF3AE9E3617C22CAD00E, 64F9061196462085E5DCD3ACB97A0D8FC67CA9A96DDD6E2103AFFF1593AE236A ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
08:30:49.0440 0x0c5c Parvdm - ok
08:30:49.0502 0x0c5c [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc C:\Windows\System32\pcasvc.dll
08:30:49.0533 0x0c5c PcaSvc - ok
08:30:49.0596 0x0c5c [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci C:\Windows\system32\drivers\pci.sys
08:30:49.0611 0x0c5c pci - ok
08:30:49.0658 0x0c5c [ 1636D43F10416AEB483BC6001097B26C, 36E61A993693A46538FE0F726D67BB28886F61D53384AD600D1282296A27662E ] pciide C:\Windows\system32\drivers\pciide.sys
08:30:49.0658 0x0c5c pciide - ok
08:30:49.0720 0x0c5c [ E6F3FB1B86AA519E7698AD05E58B04E5, 2C4B45DDD3B980C9DAA6F039CAEFCD6E84A4D5BB43AFBA73C0C42B5556C1303C ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
08:30:49.0736 0x0c5c pcmcia - ok
08:30:49.0845 0x0c5c [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
08:30:49.0908 0x0c5c PEAUTH - ok
08:30:50.0157 0x0c5c [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla C:\Windows\system32\pla.dll
08:30:50.0266 0x0c5c pla - ok
08:30:50.0360 0x0c5c [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
08:30:50.0391 0x0c5c PlugPlay - ok
08:30:50.0563 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
08:30:50.0610 0x0c5c PNRPAutoReg - ok
08:30:50.0672 0x0c5c [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc C:\Windows\system32\p2psvc.dll
08:30:50.0719 0x0c5c PNRPsvc - ok
08:30:50.0812 0x0c5c [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
08:30:50.0844 0x0c5c PolicyAgent - ok
08:30:50.0890 0x0c5c [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
Re: Prosím o kontrolu - celkové pročištění
08:30:50.0890 0x0c5c PptpMiniport - ok
08:30:50.0937 0x0c5c [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor C:\Windows\system32\DRIVERS\processr.sys
08:30:50.0953 0x0c5c Processor - ok
08:30:51.0031 0x0c5c [ 0508FAA222D28835310B7BFCA7A77346, 3AE2340C6E365F137CC00D9560069501DD2724756EA9EBF7A6CDFFC91B43709C ] ProfSvc C:\Windows\system32\profsvc.dll
08:30:51.0046 0x0c5c ProfSvc - ok
08:30:51.0093 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe
08:30:51.0093 0x0c5c ProtectedStorage - ok
08:30:51.0140 0x0c5c [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
08:30:51.0156 0x0c5c PSched - ok
08:30:51.0218 0x0c5c [ 153D02480A0A2F45785522E814C634B6, 02B7590F2F4A8FA0B031CDA7A28BD55E7C04A080C1EA810BF3AC3212A62153A6 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
08:30:51.0234 0x0c5c PxHelp20 - ok
08:30:51.0421 0x0c5c [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300 C:\Windows\system32\drivers\ql2300.sys
08:30:51.0499 0x0c5c ql2300 - ok
08:30:51.0561 0x0c5c [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
08:30:51.0561 0x0c5c ql40xx - ok
08:30:51.0624 0x0c5c [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE C:\Windows\system32\qwave.dll
08:30:51.0655 0x0c5c QWAVE - ok
08:30:51.0686 0x0c5c [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
08:30:51.0702 0x0c5c QWAVEdrv - ok
08:30:51.0733 0x0c5c [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
08:30:51.0748 0x0c5c RasAcd - ok
08:30:51.0795 0x0c5c [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto C:\Windows\System32\rasauto.dll
08:30:51.0811 0x0c5c RasAuto - ok
08:30:51.0858 0x0c5c [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
08:30:51.0873 0x0c5c Rasl2tp - ok
08:30:51.0951 0x0c5c [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan C:\Windows\System32\rasmans.dll
08:30:51.0967 0x0c5c RasMan - ok
08:30:52.0029 0x0c5c [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
08:30:52.0029 0x0c5c RasPppoe - ok
08:30:52.0076 0x0c5c [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
08:30:52.0092 0x0c5c RasSstp - ok
08:30:52.0170 0x0c5c [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
08:30:52.0185 0x0c5c rdbss - ok
08:30:52.0232 0x0c5c [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
08:30:52.0232 0x0c5c RDPCDD - ok
08:30:52.0294 0x0c5c [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
08:30:52.0310 0x0c5c rdpdr - ok
08:30:52.0341 0x0c5c [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
08:30:52.0341 0x0c5c RDPENCDD - ok
08:30:52.0450 0x0c5c [ C127EBD5AFAB31524662C48DFCEB773A, 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
08:30:52.0466 0x0c5c RDPWD - ok
08:30:52.0560 0x0c5c [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess C:\Windows\System32\mprdim.dll
08:30:52.0575 0x0c5c RemoteAccess - ok
08:30:52.0638 0x0c5c [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry C:\Windows\system32\regsvc.dll
08:30:52.0669 0x0c5c RemoteRegistry - ok
08:30:52.0747 0x0c5c [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator C:\Windows\system32\locator.exe
08:30:52.0747 0x0c5c RpcLocator - ok
08:30:52.0840 0x0c5c [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs C:\Windows\system32\rpcss.dll
08:30:52.0887 0x0c5c RpcSs - ok
08:30:52.0934 0x0c5c [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
08:30:52.0950 0x0c5c rspndr - ok
08:30:53.0028 0x0c5c [ 2CC77C65216A8BB4677E637120D5731D, AFE240686B87D6DC04D26A92E983884C4A3DAF73E58C2E19FDD3CD6187906B32 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
08:30:53.0043 0x0c5c RTL8169 - ok
08:30:53.0074 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs C:\Windows\system32\lsass.exe
08:30:53.0090 0x0c5c SamSs - ok
08:30:53.0152 0x0c5c [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
08:30:53.0168 0x0c5c sbp2port - ok
08:30:53.0215 0x0c5c [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr C:\Windows\System32\SCardSvr.dll
08:30:53.0230 0x0c5c SCardSvr - ok
08:30:53.0355 0x0c5c [ 1A58069DB21D05EB2AB58EE5753EBE8D, EED8111EB613F4C93D1638C74FDB0A6DC6694E1B108DCD0D794B5B5F9B8C6EE4 ] Schedule C:\Windows\system32\schedsvc.dll
08:30:53.0402 0x0c5c Schedule - ok
08:30:53.0449 0x0c5c [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc C:\Windows\System32\certprop.dll
08:30:53.0464 0x0c5c SCPolicySvc - ok
08:30:53.0605 0x0c5c [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC C:\Windows\System32\SDRSVC.dll
08:30:53.0636 0x0c5c SDRSVC - ok
08:30:53.0761 0x0c5c [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
08:30:53.0761 0x0c5c secdrv - ok
08:30:53.0854 0x0c5c [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon C:\Windows\system32\seclogon.dll
08:30:53.0870 0x0c5c seclogon - ok
08:30:53.0948 0x0c5c [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS C:\Windows\System32\sens.dll
08:30:53.0948 0x0c5c SENS - ok
08:30:54.0026 0x0c5c [ CE9EC966638EF0B10B864DDEDF62A099, 2DEC5A8C947D87C12B342F15B8A552A0D49B979A2AC32D2C97FC7A3A76C34524 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
08:30:54.0042 0x0c5c Serenum - ok
08:30:54.0088 0x0c5c [ 6D663022DB3E7058907784AE14B69898, 54263888C64A7F010D3B5E399369B0F3FF3AF0A0DE8ADB502B98277533E4D45F ] Serial C:\Windows\system32\DRIVERS\serial.sys
08:30:54.0104 0x0c5c Serial - ok
08:30:54.0135 0x0c5c [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse C:\Windows\system32\drivers\sermouse.sys
08:30:54.0151 0x0c5c sermouse - ok
08:30:54.0244 0x0c5c [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv C:\Windows\system32\sessenv.dll
08:30:54.0260 0x0c5c SessionEnv - ok
08:30:54.0369 0x0c5c [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
08:30:54.0369 0x0c5c sffdisk - ok
08:30:54.0416 0x0c5c [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
08:30:54.0416 0x0c5c sffp_mmc - ok
08:30:54.0447 0x0c5c [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
08:30:54.0447 0x0c5c sffp_sd - ok
08:30:54.0556 0x0c5c [ 15BE2B5E4DC5B8623CF167720682ABC9, FAECDC0DCB6EACE8130B278E2FB84B9523AB10329A00B24043B9C76867B917F0 ] sfhlp02 C:\Windows\system32\drivers\sfhlp02.sys
08:30:54.0556 0x0c5c sfhlp02 - ok
08:30:54.0603 0x0c5c [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
08:30:54.0619 0x0c5c sfloppy - ok
08:30:54.0666 0x0c5c [ 6120E41228A3718D8376437FE135DD4D, 91506C006BAB2E50F24A0BA158B5E361DCDD54A3F724D9BBB9FE3295FEDC8008 ] sfsync02 C:\Windows\system32\drivers\sfsync02.sys
08:30:54.0666 0x0c5c sfsync02 - ok
08:30:54.0806 0x0c5c [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess C:\Windows\System32\ipnathlp.dll
08:30:54.0837 0x0c5c SharedAccess - ok
08:30:54.0884 0x0c5c [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
08:30:54.0946 0x0c5c ShellHWDetection - ok
08:30:54.0978 0x0c5c [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp C:\Windows\system32\drivers\sisagp.sys
08:30:54.0993 0x0c5c sisagp - ok
08:30:55.0040 0x0c5c [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
08:30:55.0056 0x0c5c SiSRaid2 - ok
08:30:55.0102 0x0c5c [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
08:30:55.0134 0x0c5c SiSRaid4 - ok
08:30:55.0196 0x0c5c [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
08:30:55.0212 0x0c5c SkypeUpdate - ok
08:30:55.0633 0x0c5c [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc C:\Windows\system32\SLsvc.exe
08:30:55.0836 0x0c5c slsvc - ok
08:30:55.0914 0x0c5c [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify C:\Windows\system32\SLUINotify.dll
08:30:55.0929 0x0c5c SLUINotify - ok
08:30:55.0976 0x0c5c [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb C:\Windows\system32\DRIVERS\smb.sys
08:30:55.0976 0x0c5c Smb - ok
08:30:56.0054 0x0c5c [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
08:30:56.0070 0x0c5c SNMPTRAP - ok
08:30:56.0132 0x0c5c [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr C:\Windows\system32\drivers\spldr.sys
08:30:56.0132 0x0c5c spldr - ok
08:30:56.0210 0x0c5c [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler C:\Windows\System32\spoolsv.exe
08:30:56.0226 0x0c5c Spooler - ok
08:30:56.0366 0x0c5c [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv C:\Windows\system32\DRIVERS\srv.sys
08:30:56.0382 0x0c5c srv - ok
08:30:56.0506 0x0c5c [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
08:30:56.0522 0x0c5c srv2 - ok
08:30:56.0569 0x0c5c [ 7605C0E1D01A08F3ECD743F38B834A44, 83A77E31004BCF83443F30EFC290E04BB1A2F332E8DFD614AB6E25B527C92299 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
08:30:56.0584 0x0c5c srvnet - ok
08:30:56.0631 0x0c5c [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
08:30:56.0647 0x0c5c SSDPSRV - ok
08:30:56.0772 0x0c5c [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc C:\Windows\system32\sstpsvc.dll
08:30:56.0787 0x0c5c SstpSvc - ok
08:30:56.0850 0x0c5c [ EF70B3D22B4BFFDA6EA851ECB063EFAA, 1666572F8F988805C3A2E949FA6B060B35B72DBB115B86F4CFC710FB6A86C3E3 ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
08:30:56.0865 0x0c5c StillCam - ok
08:30:56.0943 0x0c5c [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc C:\Windows\System32\wiaservc.dll
08:30:56.0990 0x0c5c stisvc - ok
08:30:57.0037 0x0c5c [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum C:\Windows\system32\DRIVERS\swenum.sys
08:30:57.0037 0x0c5c swenum - ok
08:30:57.0240 0x0c5c [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
08:30:57.0286 0x0c5c SwitchBoard - ok
08:30:57.0427 0x0c5c [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv C:\Windows\System32\swprv.dll
08:30:57.0458 0x0c5c swprv - ok
08:30:57.0520 0x0c5c [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
08:30:57.0520 0x0c5c Symc8xx - ok
08:30:57.0583 0x0c5c [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
08:30:57.0583 0x0c5c Sym_hi - ok
08:30:57.0630 0x0c5c [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
08:30:57.0645 0x0c5c Sym_u3 - ok
08:30:57.0723 0x0c5c [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain C:\Windows\system32\sysmain.dll
08:30:57.0786 0x0c5c SysMain - ok
08:30:57.0910 0x0c5c [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
08:30:57.0926 0x0c5c TabletInputService - ok
08:30:58.0051 0x0c5c [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv C:\Windows\System32\tapisrv.dll
08:30:58.0082 0x0c5c TapiSrv - ok
08:30:58.0113 0x0c5c [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS C:\Windows\System32\tbssvc.dll
08:30:58.0144 0x0c5c TBS - ok
08:30:58.0300 0x0c5c [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
08:30:58.0363 0x0c5c Tcpip - ok
08:30:58.0519 0x0c5c [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
08:30:58.0597 0x0c5c Tcpip6 - ok
08:30:58.0644 0x0c5c [ 608C345A255D82A6289C2D468EB41FD7, 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
08:30:58.0659 0x0c5c tcpipreg - ok
08:30:58.0753 0x0c5c [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
08:30:58.0768 0x0c5c TDPIPE - ok
08:30:58.0831 0x0c5c [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
08:30:58.0831 0x0c5c TDTCP - ok
08:30:58.0971 0x0c5c [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
08:30:58.0971 0x0c5c tdx - ok
08:30:59.0845 0x0c5c [ CC907C2FB839D3F92690A25FF8E463BE, 3CEE9BEA1ACB1086389AA4817D996431716EFEB4432EC4D59EEF1BA710C15B8C ] TeamViewer9 C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
08:31:00.0157 0x0c5c TeamViewer9 - ok
08:31:00.0250 0x0c5c [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
08:31:00.0250 0x0c5c TermDD - ok
08:31:00.0328 0x0c5c [ BB95DA09BEF6E7A131BFF3BA5032090D, BAF6997F8D944F85F0553957677866C7F22E72AA434BA45FFFB6CC41041070DC ] TermService C:\Windows\System32\termsrv.dll
08:31:00.0375 0x0c5c TermService - ok
08:31:00.0438 0x0c5c [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes C:\Windows\system32\shsvcs.dll
08:31:00.0469 0x0c5c Themes - ok
08:31:00.0547 0x0c5c [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER C:\Windows\system32\mmcss.dll
08:31:00.0562 0x0c5c THREADORDER - ok
08:31:00.0656 0x0c5c [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks C:\Windows\System32\trkwks.dll
08:31:00.0672 0x0c5c TrkWks - ok
08:31:00.0874 0x0c5c [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
08:31:00.0890 0x0c5c TrustedInstaller - ok
08:31:00.0968 0x0c5c [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3, 1CBB5106A32362ABDEE73BF170E205FE64DDBF826C5F6DFFCCD229F220B9C85E ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
08:31:00.0968 0x0c5c tssecsrv - ok
08:31:01.0015 0x0c5c [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
08:31:01.0015 0x0c5c tunmp - ok
08:31:01.0077 0x0c5c [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
08:31:01.0077 0x0c5c tunnel - ok
08:31:01.0155 0x0c5c [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
08:31:01.0171 0x0c5c uagp35 - ok
08:31:01.0249 0x0c5c [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs C:\Windows\system32\DRIVERS\udfs.sys
08:31:01.0264 0x0c5c udfs - ok
08:31:01.0342 0x0c5c [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
08:31:01.0374 0x0c5c UI0Detect - ok
08:31:01.0436 0x0c5c [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
08:31:01.0436 0x0c5c uliagpkx - ok
08:31:01.0576 0x0c5c [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci C:\Windows\system32\drivers\uliahci.sys
08:31:01.0608 0x0c5c uliahci - ok
08:31:01.0654 0x0c5c [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata C:\Windows\system32\drivers\ulsata.sys
08:31:01.0670 0x0c5c UlSata - ok
08:31:01.0732 0x0c5c [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
08:31:01.0732 0x0c5c ulsata2 - ok
08:31:01.0779 0x0c5c [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
08:31:01.0779 0x0c5c umbus - ok
08:31:01.0826 0x0c5c [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost C:\Windows\System32\upnphost.dll
08:31:01.0873 0x0c5c upnphost - ok
08:31:01.0951 0x0c5c [ 1114579556DB85E9FAF9590DBC64CD62, 10479A3C12BBBB9B5759082358FE11AC20BAEFA6B4977C8AE6E60AA17BE6C7FA ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
08:31:01.0966 0x0c5c usbaudio - ok
08:31:02.0013 0x0c5c [ AAB0B5F72D2D726FBFDC895A2902DE1D, 7824AF6E2ADEA23F208526F3A62AD1BACDBBDB23E58EB5806890B0761529C50F ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
08:31:02.0029 0x0c5c usbccgp - ok
08:31:02.0091 0x0c5c [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir C:\Windows\system32\drivers\usbcir.sys
08:31:02.0091 0x0c5c usbcir - ok
08:31:02.0169 0x0c5c [ 153E8515CB86F8BB5D1A8B478EBF4BB2, 0F1F79BA7C32ACAAE69184A56E67D6E18E2E2F07E0BE23F266401431169DAE14 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
08:31:02.0169 0x0c5c usbehci - ok
08:31:02.0263 0x0c5c [ 2AE6BCEBD85D31317E433733DAF25888, 7B2C0E8703D0275A620160E479166EB7AA31B0F146507603535CEBF0BA4684A4 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
08:31:02.0278 0x0c5c usbhub - ok
08:31:02.0325 0x0c5c [ D457EBD0C3A8B3A3A144355B5EE91CBC, 6AD52BDBB1607A48F0B02E663B97C3A00E3345B1B12C259608A5AE728C1C06B2 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
08:31:02.0325 0x0c5c usbohci - ok
08:31:02.0388 0x0c5c [ E75C4B5269091D15A2E7DC0B6D35F2F5, B0A4141B69B66276890836DE98EB8BC790D35CE59FA503060593E8CC12AA106B ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
08:31:02.0388 0x0c5c usbprint - ok
08:31:02.0434 0x0c5c [ 1D714B8497CD68307806D5D3F60A5169, 1914D92ECE39995168E3C8F5A7694B7A94954DB299410A2781D1321C8E60C3D9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
08:31:02.0434 0x0c5c usbscan - ok
08:31:02.0497 0x0c5c [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:31:02.0497 0x0c5c USBSTOR - ok
08:31:02.0559 0x0c5c [ 814D653EFC4D48BE3B04A307ECEFF56F, D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
08:31:02.0559 0x0c5c usbuhci - ok
08:31:02.0637 0x0c5c [ 73FF24E21B690625A58109637DDA0DF7, 62B1F9CD82678E2110D4BB5CC86EE8A7AB0757681443916620B6AAA1EF0DECEB ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
08:31:02.0653 0x0c5c usbvideo - ok
08:31:02.0715 0x0c5c [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms C:\Windows\System32\uxsms.dll
08:31:02.0731 0x0c5c UxSms - ok
08:31:02.0918 0x0c5c [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds C:\Windows\System32\vds.exe
08:31:02.0949 0x0c5c vds - ok
08:31:03.0043 0x0c5c [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
08:31:03.0074 0x0c5c vga - ok
08:31:03.0168 0x0c5c [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave C:\Windows\System32\drivers\vga.sys
08:31:03.0168 0x0c5c VgaSave - ok
08:31:03.0214 0x0c5c [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp C:\Windows\system32\drivers\viaagp.sys
08:31:03.0214 0x0c5c viaagp - ok
08:31:03.0261 0x0c5c [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
08:31:03.0261 0x0c5c ViaC7 - ok
08:31:03.0308 0x0c5c [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide C:\Windows\system32\drivers\viaide.sys
08:31:03.0308 0x0c5c viaide - ok
08:31:03.0402 0x0c5c [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr C:\Windows\system32\drivers\volmgr.sys
08:31:03.0417 0x0c5c volmgr - ok
08:31:03.0495 0x0c5c [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
08:31:03.0511 0x0c5c volmgrx - ok
08:31:03.0636 0x0c5c [ 786DB5771F05EF300390399F626BF30A, 4A07BE5AEDBA4C15C2F9A91250F0488A0B0305C67BB7A037508D5CBF86D4E1B7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
08:31:03.0651 0x0c5c volsnap - ok
08:31:03.0729 0x0c5c [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
08:31:03.0745 0x0c5c vsmraid - ok
08:31:04.0369 0x0c5c [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS C:\Windows\system32\vssvc.exe
08:31:04.0462 0x0c5c VSS - ok
08:31:04.0665 0x0c5c [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time C:\Windows\system32\w32time.dll
08:31:04.0696 0x0c5c W32Time - ok
08:31:04.0774 0x0c5c [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
08:31:04.0774 0x0c5c WacomPen - ok
08:31:04.0837 0x0c5c [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
08:31:04.0837 0x0c5c Wanarp - ok
08:31:04.0884 0x0c5c [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
08:31:04.0884 0x0c5c Wanarpv6 - ok
08:31:05.0133 0x0c5c [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc C:\Windows\System32\wcncsvc.dll
08:31:05.0196 0x0c5c wcncsvc - ok
08:31:05.0242 0x0c5c [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
08:31:05.0258 0x0c5c WcsPlugInService - ok
08:31:05.0305 0x0c5c [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd C:\Windows\system32\drivers\wd.sys
08:31:05.0320 0x0c5c Wd - ok
08:31:05.0430 0x0c5c [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
08:31:05.0476 0x0c5c Wdf01000 - ok
08:31:05.0523 0x0c5c [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost C:\Windows\system32\wdi.dll
08:31:05.0539 0x0c5c WdiServiceHost - ok
08:31:05.0570 0x0c5c [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost C:\Windows\system32\wdi.dll
08:31:05.0601 0x0c5c WdiSystemHost - ok
08:31:05.0742 0x0c5c [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient C:\Windows\System32\webclnt.dll
08:31:05.0757 0x0c5c WebClient - ok
08:31:05.0851 0x0c5c [ AE3736E7E8892241C23E4EBBB7453B60, 0F998116CC07CD719CB237EAE53BB16B2EDD6973828B9C1055EB981AEA0453D1 ] Wecsvc C:\Windows\system32\wecsvc.dll
08:31:05.0882 0x0c5c Wecsvc - ok
08:31:05.0929 0x0c5c [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport C:\Windows\System32\wercplsupport.dll
08:31:05.0960 0x0c5c wercplsupport - ok
08:31:06.0022 0x0c5c [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc C:\Windows\System32\WerSvc.dll
08:31:06.0038 0x0c5c WerSvc - ok
08:31:06.0178 0x0c5c [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
08:31:06.0194 0x0c5c WinDefend - ok
08:31:06.0256 0x0c5c WinHttpAutoProxySvc - ok
08:31:06.0397 0x0c5c [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
08:31:06.0412 0x0c5c Winmgmt - ok
08:31:06.0927 0x0c5c [ 7CFE68BDC065E55AA5E8421607037511, C2CE76D52AD4E31FC4216E94457DC16ABF65A5F3E883F0BD97AD387FB7574533 ] WinRM C:\Windows\system32\WsmSvc.dll
08:31:07.0036 0x0c5c WinRM - ok
08:31:07.0161 0x0c5c [ 676F4B665BDD8053EAA53AC1695B8074, 98521FCB6B6B33DD8BF38A703745053481681C7981DFE5A59116D6BDE187D6F6 ] winusb C:\Windows\system32\DRIVERS\WinUSB.SYS
08:31:07.0161 0x0c5c winusb - ok
08:31:07.0255 0x0c5c [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc C:\Windows\System32\wlansvc.dll
08:31:07.0317 0x0c5c Wlansvc - ok
08:31:07.0598 0x0c5c [ 6067ACEF367E79914AF628FA1E9B5330, 491A705267B48C103E00B26BBD21FA8829DB03A88343CBC27264CEE5DE8C8DEF ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
08:31:07.0645 0x0c5c wlcrasvc - ok
08:31:08.0206 0x0c5c [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:31:08.0300 0x0c5c wlidsvc - ok
08:31:08.0394 0x0c5c [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
08:31:08.0394 0x0c5c WmiAcpi - ok
08:31:08.0550 0x0c5c [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
08:31:08.0565 0x0c5c wmiApSrv - ok
08:31:08.0971 0x0c5c [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
08:31:09.0018 0x0c5c WMPNetworkSvc - ok
08:31:09.0142 0x0c5c [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc C:\Windows\System32\wpcsvc.dll
08:31:09.0158 0x0c5c WPCSvc - ok
08:31:09.0283 0x0c5c [ 801FBDB89D472B3C467EB112A0FC9246, C24053FA12732089384D3AF06C676FF201D282FC5AD56A42B6EE8BAED4379CB2 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
08:31:09.0298 0x0c5c WPDBusEnum - ok
08:31:09.0548 0x0c5c [ DE9D36F91A4DF3D911626643DEBF11EA, 8029ECE76E29276BFB6ED3387AC560A9A779AAF683A4416E96334FAF7BDBADA0 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
08:31:09.0548 0x0c5c WpdUsb - ok
08:31:09.0844 0x0c5c [ F8D3544ACBCE9110362119F7C10D848E, 31C49201A931751A36286874AC0B929D886F490D7CE48CCC9283850A56AD9FD9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
08:31:09.0891 0x0c5c WPFFontCache_v0400 - ok
08:31:09.0985 0x0c5c [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
08:31:09.0985 0x0c5c ws2ifsl - ok
08:31:10.0110 0x0c5c [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc C:\Windows\System32\wscsvc.dll
08:31:10.0125 0x0c5c wscsvc - ok
08:31:10.0219 0x0c5c WSearch - ok
08:31:10.0531 0x0c5c [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
08:31:10.0656 0x0c5c wuauserv - ok
08:31:10.0749 0x0c5c [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
08:31:10.0765 0x0c5c WudfPf - ok
08:31:10.0890 0x0c5c [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
08:31:10.0905 0x0c5c WUDFRd - ok
08:31:11.0014 0x0c5c [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
08:31:11.0030 0x0c5c wudfsvc - ok
08:31:11.0155 0x0c5c ================ Scan global ===============================
08:31:11.0186 0x0c5c [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll
08:31:11.0264 0x0c5c [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
08:31:11.0420 0x0c5c [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
08:31:11.0560 0x0c5c [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe
08:31:11.0592 0x0c5c [ Global ] - ok
08:31:11.0623 0x0c5c ================ Scan MBR ==================================
08:31:11.0638 0x0c5c [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
08:31:12.0106 0x0c5c \Device\Harddisk0\DR0 - ok
08:31:12.0122 0x0c5c ================ Scan VBR ==================================
08:31:12.0122 0x0c5c [ FAD0CBFEF0D6F91A26D1E55FF6930AC3 ] \Device\Harddisk0\DR0\Partition1
08:31:12.0153 0x0c5c \Device\Harddisk0\DR0\Partition1 - ok
08:31:12.0231 0x0c5c ================ Scan generic autorun ======================
08:31:12.0949 0x0c5c [ D8D82420048EC795DE3481DA1DDA758E, 6533BFC7B22B6A68D503C26773DD32BA555CBF785FA63437F99DE34811F4A445 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
08:31:13.0308 0x0c5c RtHDVCpl - ok
08:31:13.0510 0x0c5c [ A192F366A80D34961823D0FA6FD3EC66, D9BA08A8E430FA881AF720C4DBCB82C0EBA158BF4AB2790802030C422C157736 ] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
08:31:13.0620 0x0c5c Skytel - ok
08:31:14.0680 0x0c5c [ 26B558B2D31C7425B455B00E562EAD93, B64D128A2F1FC42BA4376F8EB08D70F4B705745CB983D0631DB45851BF34BBDF ] C:\Program Files\Alwil Software\Avast5\AvastUI.exe
08:31:14.0946 0x0c5c AvastUI.exe - ok
08:31:15.0289 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:15.0382 0x0c5c Sidebar - ok
08:31:15.0460 0x0c5c WindowsWelcomeCenter - ok
08:31:15.0632 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:15.0694 0x0c5c Sidebar - ok
08:31:15.0804 0x0c5c WindowsWelcomeCenter - ok
08:31:15.0913 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:15.0975 0x0c5c Sidebar - ok
08:31:16.0100 0x0c5c [ BF08674925F151BD4537B89A493E3E0C, 6A97562E998A2B90649FF7986313AD33823053FF98BBE163AD39AAA5E01FC545 ] C:\Windows\ehome\ehTray.exe
08:31:16.0116 0x0c5c ehTray.exe - ok
08:31:16.0178 0x0c5c [ 35937EAD711207544E219C2A19A78A7D, EE6E5EAE00F577D7C3FFB8C0D8EE484552A337CEAA27FCB107174A9879FE7362 ] C:\Program Files\Windows Media Player\WMPNSCFG.exe
08:31:16.0194 0x0c5c WMPNSCFG - ok
08:31:16.0630 0x0c5c [ 0C30D008B853CD7D8C2D604FD9790C59, F9A3D55B787DB3EE056922772D60622B6E4E3AA31235368BC2F2C7F8F5B02C07 ] C:\Program Files\DAEMON Tools Lite\DTLite.exe
08:31:16.0927 0x0c5c DAEMON Tools Lite - ok
08:31:17.0098 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:17.0192 0x0c5c Sidebar - ok
08:31:17.0270 0x0c5c WindowsWelcomeCenter - ok
08:31:17.0457 0x0c5c [ 5B2185DA1CDCDC40565B3F1ECDB11E75, 7AB5AE9C70E6DED079CA0F0459B5A06BD02F185692F9FBBDF369278A73DB28B3 ] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
08:31:17.0473 0x0c5c BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - ok
08:31:17.0535 0x0c5c [ BF08674925F151BD4537B89A493E3E0C, 6A97562E998A2B90649FF7986313AD33823053FF98BBE163AD39AAA5E01FC545 ] C:\Windows\ehome\ehTray.exe
08:31:17.0551 0x0c5c ehTray.exe - ok
08:31:17.0629 0x0c5c swg - ok
08:31:18.0222 0x0c5c [ 2A3FB4C98F139038E23330D2439DB8A4, DE9253AD362B03FA5D3D4912662398E5C4AC76F7274B83E51C251A6921A5B838 ] C:\Users\Adéla\AppData\Local\Facebook\Update\FacebookUpdate.exe
08:31:18.0253 0x0c5c Facebook Update - ok
08:31:18.0331 0x0c5c Zoner Photo Studio Autoupdate - ok
08:31:18.0393 0x0c5c [ 35937EAD711207544E219C2A19A78A7D, EE6E5EAE00F577D7C3FFB8C0D8EE484552A337CEAA27FCB107174A9879FE7362 ] C:\Program Files\Windows Media Player\WMPNSCFG.exe
08:31:18.0409 0x0c5c WMPNSCFG - ok
08:31:18.0471 0x0c5c [ 0B729DBAE22BCEACB1FA39B19748EBDC, 267CB064201C3F284B9602CFC5526B6313D8AC326588D710C5BAB0BFD2A36454 ] C:\Windows\system32\p2phost.exe
08:31:18.0487 0x0c5c CollaborationHost - ok
08:31:18.0768 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:18.0830 0x0c5c Sidebar - ok
08:31:18.0846 0x0c5c WindowsWelcomeCenter - ok
08:31:18.0970 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:19.0033 0x0c5c Sidebar - ok
08:31:19.0048 0x0c5c WindowsWelcomeCenter - ok
08:31:19.0064 0x0c5c AVG-Secure-Search-Update_JUNE2013_TB - ok
08:31:19.0064 0x0c5c AVG-Secure-Search-Update_JUNE2013_HP - ok
08:31:19.0158 0x0c5c AV detected via SS2: avast! Antivirus, C:\Program Files\Alwil Software\Avast5\VisthAux.exe ( 9.0.2021.515 ), 0x40000 ( disabled : updated )
08:31:19.0173 0x0c5c FW detected via SS2: avast! Antivirus, C:\Program Files\Alwil Software\Avast5\VisthAux.exe ( 9.0.2021.515 ), 0x40010 ( disabled )
08:31:19.0189 0x0c5c Win FW state via NFP2: disabled
08:31:19.0189 0x0c5c ============================================================
08:31:19.0189 0x0c5c Scan finished
08:31:19.0189 0x0c5c ============================================================
08:31:19.0220 0x0c10 Detected object count: 0
08:31:19.0220 0x0c10 Actual detected object count: 0
08:33:14.0971 0x04bc Deinitialize success
08:30:50.0937 0x0c5c [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor C:\Windows\system32\DRIVERS\processr.sys
08:30:50.0953 0x0c5c Processor - ok
08:30:51.0031 0x0c5c [ 0508FAA222D28835310B7BFCA7A77346, 3AE2340C6E365F137CC00D9560069501DD2724756EA9EBF7A6CDFFC91B43709C ] ProfSvc C:\Windows\system32\profsvc.dll
08:30:51.0046 0x0c5c ProfSvc - ok
08:30:51.0093 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe
08:30:51.0093 0x0c5c ProtectedStorage - ok
08:30:51.0140 0x0c5c [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
08:30:51.0156 0x0c5c PSched - ok
08:30:51.0218 0x0c5c [ 153D02480A0A2F45785522E814C634B6, 02B7590F2F4A8FA0B031CDA7A28BD55E7C04A080C1EA810BF3AC3212A62153A6 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
08:30:51.0234 0x0c5c PxHelp20 - ok
08:30:51.0421 0x0c5c [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300 C:\Windows\system32\drivers\ql2300.sys
08:30:51.0499 0x0c5c ql2300 - ok
08:30:51.0561 0x0c5c [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
08:30:51.0561 0x0c5c ql40xx - ok
08:30:51.0624 0x0c5c [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE C:\Windows\system32\qwave.dll
08:30:51.0655 0x0c5c QWAVE - ok
08:30:51.0686 0x0c5c [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
08:30:51.0702 0x0c5c QWAVEdrv - ok
08:30:51.0733 0x0c5c [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
08:30:51.0748 0x0c5c RasAcd - ok
08:30:51.0795 0x0c5c [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto C:\Windows\System32\rasauto.dll
08:30:51.0811 0x0c5c RasAuto - ok
08:30:51.0858 0x0c5c [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
08:30:51.0873 0x0c5c Rasl2tp - ok
08:30:51.0951 0x0c5c [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan C:\Windows\System32\rasmans.dll
08:30:51.0967 0x0c5c RasMan - ok
08:30:52.0029 0x0c5c [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
08:30:52.0029 0x0c5c RasPppoe - ok
08:30:52.0076 0x0c5c [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
08:30:52.0092 0x0c5c RasSstp - ok
08:30:52.0170 0x0c5c [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
08:30:52.0185 0x0c5c rdbss - ok
08:30:52.0232 0x0c5c [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
08:30:52.0232 0x0c5c RDPCDD - ok
08:30:52.0294 0x0c5c [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
08:30:52.0310 0x0c5c rdpdr - ok
08:30:52.0341 0x0c5c [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
08:30:52.0341 0x0c5c RDPENCDD - ok
08:30:52.0450 0x0c5c [ C127EBD5AFAB31524662C48DFCEB773A, 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
08:30:52.0466 0x0c5c RDPWD - ok
08:30:52.0560 0x0c5c [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess C:\Windows\System32\mprdim.dll
08:30:52.0575 0x0c5c RemoteAccess - ok
08:30:52.0638 0x0c5c [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry C:\Windows\system32\regsvc.dll
08:30:52.0669 0x0c5c RemoteRegistry - ok
08:30:52.0747 0x0c5c [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator C:\Windows\system32\locator.exe
08:30:52.0747 0x0c5c RpcLocator - ok
08:30:52.0840 0x0c5c [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs C:\Windows\system32\rpcss.dll
08:30:52.0887 0x0c5c RpcSs - ok
08:30:52.0934 0x0c5c [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
08:30:52.0950 0x0c5c rspndr - ok
08:30:53.0028 0x0c5c [ 2CC77C65216A8BB4677E637120D5731D, AFE240686B87D6DC04D26A92E983884C4A3DAF73E58C2E19FDD3CD6187906B32 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
08:30:53.0043 0x0c5c RTL8169 - ok
08:30:53.0074 0x0c5c [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs C:\Windows\system32\lsass.exe
08:30:53.0090 0x0c5c SamSs - ok
08:30:53.0152 0x0c5c [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
08:30:53.0168 0x0c5c sbp2port - ok
08:30:53.0215 0x0c5c [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr C:\Windows\System32\SCardSvr.dll
08:30:53.0230 0x0c5c SCardSvr - ok
08:30:53.0355 0x0c5c [ 1A58069DB21D05EB2AB58EE5753EBE8D, EED8111EB613F4C93D1638C74FDB0A6DC6694E1B108DCD0D794B5B5F9B8C6EE4 ] Schedule C:\Windows\system32\schedsvc.dll
08:30:53.0402 0x0c5c Schedule - ok
08:30:53.0449 0x0c5c [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc C:\Windows\System32\certprop.dll
08:30:53.0464 0x0c5c SCPolicySvc - ok
08:30:53.0605 0x0c5c [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC C:\Windows\System32\SDRSVC.dll
08:30:53.0636 0x0c5c SDRSVC - ok
08:30:53.0761 0x0c5c [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
08:30:53.0761 0x0c5c secdrv - ok
08:30:53.0854 0x0c5c [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon C:\Windows\system32\seclogon.dll
08:30:53.0870 0x0c5c seclogon - ok
08:30:53.0948 0x0c5c [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS C:\Windows\System32\sens.dll
08:30:53.0948 0x0c5c SENS - ok
08:30:54.0026 0x0c5c [ CE9EC966638EF0B10B864DDEDF62A099, 2DEC5A8C947D87C12B342F15B8A552A0D49B979A2AC32D2C97FC7A3A76C34524 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
08:30:54.0042 0x0c5c Serenum - ok
08:30:54.0088 0x0c5c [ 6D663022DB3E7058907784AE14B69898, 54263888C64A7F010D3B5E399369B0F3FF3AF0A0DE8ADB502B98277533E4D45F ] Serial C:\Windows\system32\DRIVERS\serial.sys
08:30:54.0104 0x0c5c Serial - ok
08:30:54.0135 0x0c5c [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse C:\Windows\system32\drivers\sermouse.sys
08:30:54.0151 0x0c5c sermouse - ok
08:30:54.0244 0x0c5c [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv C:\Windows\system32\sessenv.dll
08:30:54.0260 0x0c5c SessionEnv - ok
08:30:54.0369 0x0c5c [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
08:30:54.0369 0x0c5c sffdisk - ok
08:30:54.0416 0x0c5c [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
08:30:54.0416 0x0c5c sffp_mmc - ok
08:30:54.0447 0x0c5c [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
08:30:54.0447 0x0c5c sffp_sd - ok
08:30:54.0556 0x0c5c [ 15BE2B5E4DC5B8623CF167720682ABC9, FAECDC0DCB6EACE8130B278E2FB84B9523AB10329A00B24043B9C76867B917F0 ] sfhlp02 C:\Windows\system32\drivers\sfhlp02.sys
08:30:54.0556 0x0c5c sfhlp02 - ok
08:30:54.0603 0x0c5c [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
08:30:54.0619 0x0c5c sfloppy - ok
08:30:54.0666 0x0c5c [ 6120E41228A3718D8376437FE135DD4D, 91506C006BAB2E50F24A0BA158B5E361DCDD54A3F724D9BBB9FE3295FEDC8008 ] sfsync02 C:\Windows\system32\drivers\sfsync02.sys
08:30:54.0666 0x0c5c sfsync02 - ok
08:30:54.0806 0x0c5c [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess C:\Windows\System32\ipnathlp.dll
08:30:54.0837 0x0c5c SharedAccess - ok
08:30:54.0884 0x0c5c [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
08:30:54.0946 0x0c5c ShellHWDetection - ok
08:30:54.0978 0x0c5c [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp C:\Windows\system32\drivers\sisagp.sys
08:30:54.0993 0x0c5c sisagp - ok
08:30:55.0040 0x0c5c [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
08:30:55.0056 0x0c5c SiSRaid2 - ok
08:30:55.0102 0x0c5c [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
08:30:55.0134 0x0c5c SiSRaid4 - ok
08:30:55.0196 0x0c5c [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
08:30:55.0212 0x0c5c SkypeUpdate - ok
08:30:55.0633 0x0c5c [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc C:\Windows\system32\SLsvc.exe
08:30:55.0836 0x0c5c slsvc - ok
08:30:55.0914 0x0c5c [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify C:\Windows\system32\SLUINotify.dll
08:30:55.0929 0x0c5c SLUINotify - ok
08:30:55.0976 0x0c5c [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb C:\Windows\system32\DRIVERS\smb.sys
08:30:55.0976 0x0c5c Smb - ok
08:30:56.0054 0x0c5c [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
08:30:56.0070 0x0c5c SNMPTRAP - ok
08:30:56.0132 0x0c5c [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr C:\Windows\system32\drivers\spldr.sys
08:30:56.0132 0x0c5c spldr - ok
08:30:56.0210 0x0c5c [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler C:\Windows\System32\spoolsv.exe
08:30:56.0226 0x0c5c Spooler - ok
08:30:56.0366 0x0c5c [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv C:\Windows\system32\DRIVERS\srv.sys
08:30:56.0382 0x0c5c srv - ok
08:30:56.0506 0x0c5c [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
08:30:56.0522 0x0c5c srv2 - ok
08:30:56.0569 0x0c5c [ 7605C0E1D01A08F3ECD743F38B834A44, 83A77E31004BCF83443F30EFC290E04BB1A2F332E8DFD614AB6E25B527C92299 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
08:30:56.0584 0x0c5c srvnet - ok
08:30:56.0631 0x0c5c [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
08:30:56.0647 0x0c5c SSDPSRV - ok
08:30:56.0772 0x0c5c [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc C:\Windows\system32\sstpsvc.dll
08:30:56.0787 0x0c5c SstpSvc - ok
08:30:56.0850 0x0c5c [ EF70B3D22B4BFFDA6EA851ECB063EFAA, 1666572F8F988805C3A2E949FA6B060B35B72DBB115B86F4CFC710FB6A86C3E3 ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
08:30:56.0865 0x0c5c StillCam - ok
08:30:56.0943 0x0c5c [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc C:\Windows\System32\wiaservc.dll
08:30:56.0990 0x0c5c stisvc - ok
08:30:57.0037 0x0c5c [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum C:\Windows\system32\DRIVERS\swenum.sys
08:30:57.0037 0x0c5c swenum - ok
08:30:57.0240 0x0c5c [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
08:30:57.0286 0x0c5c SwitchBoard - ok
08:30:57.0427 0x0c5c [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv C:\Windows\System32\swprv.dll
08:30:57.0458 0x0c5c swprv - ok
08:30:57.0520 0x0c5c [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
08:30:57.0520 0x0c5c Symc8xx - ok
08:30:57.0583 0x0c5c [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
08:30:57.0583 0x0c5c Sym_hi - ok
08:30:57.0630 0x0c5c [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
08:30:57.0645 0x0c5c Sym_u3 - ok
08:30:57.0723 0x0c5c [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain C:\Windows\system32\sysmain.dll
08:30:57.0786 0x0c5c SysMain - ok
08:30:57.0910 0x0c5c [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
08:30:57.0926 0x0c5c TabletInputService - ok
08:30:58.0051 0x0c5c [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv C:\Windows\System32\tapisrv.dll
08:30:58.0082 0x0c5c TapiSrv - ok
08:30:58.0113 0x0c5c [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS C:\Windows\System32\tbssvc.dll
08:30:58.0144 0x0c5c TBS - ok
08:30:58.0300 0x0c5c [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
08:30:58.0363 0x0c5c Tcpip - ok
08:30:58.0519 0x0c5c [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
08:30:58.0597 0x0c5c Tcpip6 - ok
08:30:58.0644 0x0c5c [ 608C345A255D82A6289C2D468EB41FD7, 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
08:30:58.0659 0x0c5c tcpipreg - ok
08:30:58.0753 0x0c5c [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
08:30:58.0768 0x0c5c TDPIPE - ok
08:30:58.0831 0x0c5c [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
08:30:58.0831 0x0c5c TDTCP - ok
08:30:58.0971 0x0c5c [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
08:30:58.0971 0x0c5c tdx - ok
08:30:59.0845 0x0c5c [ CC907C2FB839D3F92690A25FF8E463BE, 3CEE9BEA1ACB1086389AA4817D996431716EFEB4432EC4D59EEF1BA710C15B8C ] TeamViewer9 C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
08:31:00.0157 0x0c5c TeamViewer9 - ok
08:31:00.0250 0x0c5c [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
08:31:00.0250 0x0c5c TermDD - ok
08:31:00.0328 0x0c5c [ BB95DA09BEF6E7A131BFF3BA5032090D, BAF6997F8D944F85F0553957677866C7F22E72AA434BA45FFFB6CC41041070DC ] TermService C:\Windows\System32\termsrv.dll
08:31:00.0375 0x0c5c TermService - ok
08:31:00.0438 0x0c5c [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes C:\Windows\system32\shsvcs.dll
08:31:00.0469 0x0c5c Themes - ok
08:31:00.0547 0x0c5c [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER C:\Windows\system32\mmcss.dll
08:31:00.0562 0x0c5c THREADORDER - ok
08:31:00.0656 0x0c5c [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks C:\Windows\System32\trkwks.dll
08:31:00.0672 0x0c5c TrkWks - ok
08:31:00.0874 0x0c5c [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
08:31:00.0890 0x0c5c TrustedInstaller - ok
08:31:00.0968 0x0c5c [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3, 1CBB5106A32362ABDEE73BF170E205FE64DDBF826C5F6DFFCCD229F220B9C85E ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
08:31:00.0968 0x0c5c tssecsrv - ok
08:31:01.0015 0x0c5c [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
08:31:01.0015 0x0c5c tunmp - ok
08:31:01.0077 0x0c5c [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
08:31:01.0077 0x0c5c tunnel - ok
08:31:01.0155 0x0c5c [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
08:31:01.0171 0x0c5c uagp35 - ok
08:31:01.0249 0x0c5c [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs C:\Windows\system32\DRIVERS\udfs.sys
08:31:01.0264 0x0c5c udfs - ok
08:31:01.0342 0x0c5c [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
08:31:01.0374 0x0c5c UI0Detect - ok
08:31:01.0436 0x0c5c [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
08:31:01.0436 0x0c5c uliagpkx - ok
08:31:01.0576 0x0c5c [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci C:\Windows\system32\drivers\uliahci.sys
08:31:01.0608 0x0c5c uliahci - ok
08:31:01.0654 0x0c5c [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata C:\Windows\system32\drivers\ulsata.sys
08:31:01.0670 0x0c5c UlSata - ok
08:31:01.0732 0x0c5c [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
08:31:01.0732 0x0c5c ulsata2 - ok
08:31:01.0779 0x0c5c [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
08:31:01.0779 0x0c5c umbus - ok
08:31:01.0826 0x0c5c [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost C:\Windows\System32\upnphost.dll
08:31:01.0873 0x0c5c upnphost - ok
08:31:01.0951 0x0c5c [ 1114579556DB85E9FAF9590DBC64CD62, 10479A3C12BBBB9B5759082358FE11AC20BAEFA6B4977C8AE6E60AA17BE6C7FA ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
08:31:01.0966 0x0c5c usbaudio - ok
08:31:02.0013 0x0c5c [ AAB0B5F72D2D726FBFDC895A2902DE1D, 7824AF6E2ADEA23F208526F3A62AD1BACDBBDB23E58EB5806890B0761529C50F ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
08:31:02.0029 0x0c5c usbccgp - ok
08:31:02.0091 0x0c5c [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir C:\Windows\system32\drivers\usbcir.sys
08:31:02.0091 0x0c5c usbcir - ok
08:31:02.0169 0x0c5c [ 153E8515CB86F8BB5D1A8B478EBF4BB2, 0F1F79BA7C32ACAAE69184A56E67D6E18E2E2F07E0BE23F266401431169DAE14 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
08:31:02.0169 0x0c5c usbehci - ok
08:31:02.0263 0x0c5c [ 2AE6BCEBD85D31317E433733DAF25888, 7B2C0E8703D0275A620160E479166EB7AA31B0F146507603535CEBF0BA4684A4 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
08:31:02.0278 0x0c5c usbhub - ok
08:31:02.0325 0x0c5c [ D457EBD0C3A8B3A3A144355B5EE91CBC, 6AD52BDBB1607A48F0B02E663B97C3A00E3345B1B12C259608A5AE728C1C06B2 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
08:31:02.0325 0x0c5c usbohci - ok
08:31:02.0388 0x0c5c [ E75C4B5269091D15A2E7DC0B6D35F2F5, B0A4141B69B66276890836DE98EB8BC790D35CE59FA503060593E8CC12AA106B ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
08:31:02.0388 0x0c5c usbprint - ok
08:31:02.0434 0x0c5c [ 1D714B8497CD68307806D5D3F60A5169, 1914D92ECE39995168E3C8F5A7694B7A94954DB299410A2781D1321C8E60C3D9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
08:31:02.0434 0x0c5c usbscan - ok
08:31:02.0497 0x0c5c [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:31:02.0497 0x0c5c USBSTOR - ok
08:31:02.0559 0x0c5c [ 814D653EFC4D48BE3B04A307ECEFF56F, D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
08:31:02.0559 0x0c5c usbuhci - ok
08:31:02.0637 0x0c5c [ 73FF24E21B690625A58109637DDA0DF7, 62B1F9CD82678E2110D4BB5CC86EE8A7AB0757681443916620B6AAA1EF0DECEB ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
08:31:02.0653 0x0c5c usbvideo - ok
08:31:02.0715 0x0c5c [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms C:\Windows\System32\uxsms.dll
08:31:02.0731 0x0c5c UxSms - ok
08:31:02.0918 0x0c5c [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds C:\Windows\System32\vds.exe
08:31:02.0949 0x0c5c vds - ok
08:31:03.0043 0x0c5c [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
08:31:03.0074 0x0c5c vga - ok
08:31:03.0168 0x0c5c [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave C:\Windows\System32\drivers\vga.sys
08:31:03.0168 0x0c5c VgaSave - ok
08:31:03.0214 0x0c5c [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp C:\Windows\system32\drivers\viaagp.sys
08:31:03.0214 0x0c5c viaagp - ok
08:31:03.0261 0x0c5c [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
08:31:03.0261 0x0c5c ViaC7 - ok
08:31:03.0308 0x0c5c [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide C:\Windows\system32\drivers\viaide.sys
08:31:03.0308 0x0c5c viaide - ok
08:31:03.0402 0x0c5c [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr C:\Windows\system32\drivers\volmgr.sys
08:31:03.0417 0x0c5c volmgr - ok
08:31:03.0495 0x0c5c [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
08:31:03.0511 0x0c5c volmgrx - ok
08:31:03.0636 0x0c5c [ 786DB5771F05EF300390399F626BF30A, 4A07BE5AEDBA4C15C2F9A91250F0488A0B0305C67BB7A037508D5CBF86D4E1B7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
08:31:03.0651 0x0c5c volsnap - ok
08:31:03.0729 0x0c5c [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
08:31:03.0745 0x0c5c vsmraid - ok
08:31:04.0369 0x0c5c [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS C:\Windows\system32\vssvc.exe
08:31:04.0462 0x0c5c VSS - ok
08:31:04.0665 0x0c5c [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time C:\Windows\system32\w32time.dll
08:31:04.0696 0x0c5c W32Time - ok
08:31:04.0774 0x0c5c [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
08:31:04.0774 0x0c5c WacomPen - ok
08:31:04.0837 0x0c5c [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
08:31:04.0837 0x0c5c Wanarp - ok
08:31:04.0884 0x0c5c [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
08:31:04.0884 0x0c5c Wanarpv6 - ok
08:31:05.0133 0x0c5c [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc C:\Windows\System32\wcncsvc.dll
08:31:05.0196 0x0c5c wcncsvc - ok
08:31:05.0242 0x0c5c [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
08:31:05.0258 0x0c5c WcsPlugInService - ok
08:31:05.0305 0x0c5c [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd C:\Windows\system32\drivers\wd.sys
08:31:05.0320 0x0c5c Wd - ok
08:31:05.0430 0x0c5c [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
08:31:05.0476 0x0c5c Wdf01000 - ok
08:31:05.0523 0x0c5c [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost C:\Windows\system32\wdi.dll
08:31:05.0539 0x0c5c WdiServiceHost - ok
08:31:05.0570 0x0c5c [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost C:\Windows\system32\wdi.dll
08:31:05.0601 0x0c5c WdiSystemHost - ok
08:31:05.0742 0x0c5c [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient C:\Windows\System32\webclnt.dll
08:31:05.0757 0x0c5c WebClient - ok
08:31:05.0851 0x0c5c [ AE3736E7E8892241C23E4EBBB7453B60, 0F998116CC07CD719CB237EAE53BB16B2EDD6973828B9C1055EB981AEA0453D1 ] Wecsvc C:\Windows\system32\wecsvc.dll
08:31:05.0882 0x0c5c Wecsvc - ok
08:31:05.0929 0x0c5c [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport C:\Windows\System32\wercplsupport.dll
08:31:05.0960 0x0c5c wercplsupport - ok
08:31:06.0022 0x0c5c [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc C:\Windows\System32\WerSvc.dll
08:31:06.0038 0x0c5c WerSvc - ok
08:31:06.0178 0x0c5c [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
08:31:06.0194 0x0c5c WinDefend - ok
08:31:06.0256 0x0c5c WinHttpAutoProxySvc - ok
08:31:06.0397 0x0c5c [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
08:31:06.0412 0x0c5c Winmgmt - ok
08:31:06.0927 0x0c5c [ 7CFE68BDC065E55AA5E8421607037511, C2CE76D52AD4E31FC4216E94457DC16ABF65A5F3E883F0BD97AD387FB7574533 ] WinRM C:\Windows\system32\WsmSvc.dll
08:31:07.0036 0x0c5c WinRM - ok
08:31:07.0161 0x0c5c [ 676F4B665BDD8053EAA53AC1695B8074, 98521FCB6B6B33DD8BF38A703745053481681C7981DFE5A59116D6BDE187D6F6 ] winusb C:\Windows\system32\DRIVERS\WinUSB.SYS
08:31:07.0161 0x0c5c winusb - ok
08:31:07.0255 0x0c5c [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc C:\Windows\System32\wlansvc.dll
08:31:07.0317 0x0c5c Wlansvc - ok
08:31:07.0598 0x0c5c [ 6067ACEF367E79914AF628FA1E9B5330, 491A705267B48C103E00B26BBD21FA8829DB03A88343CBC27264CEE5DE8C8DEF ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
08:31:07.0645 0x0c5c wlcrasvc - ok
08:31:08.0206 0x0c5c [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:31:08.0300 0x0c5c wlidsvc - ok
08:31:08.0394 0x0c5c [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
08:31:08.0394 0x0c5c WmiAcpi - ok
08:31:08.0550 0x0c5c [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
08:31:08.0565 0x0c5c wmiApSrv - ok
08:31:08.0971 0x0c5c [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
08:31:09.0018 0x0c5c WMPNetworkSvc - ok
08:31:09.0142 0x0c5c [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc C:\Windows\System32\wpcsvc.dll
08:31:09.0158 0x0c5c WPCSvc - ok
08:31:09.0283 0x0c5c [ 801FBDB89D472B3C467EB112A0FC9246, C24053FA12732089384D3AF06C676FF201D282FC5AD56A42B6EE8BAED4379CB2 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
08:31:09.0298 0x0c5c WPDBusEnum - ok
08:31:09.0548 0x0c5c [ DE9D36F91A4DF3D911626643DEBF11EA, 8029ECE76E29276BFB6ED3387AC560A9A779AAF683A4416E96334FAF7BDBADA0 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
08:31:09.0548 0x0c5c WpdUsb - ok
08:31:09.0844 0x0c5c [ F8D3544ACBCE9110362119F7C10D848E, 31C49201A931751A36286874AC0B929D886F490D7CE48CCC9283850A56AD9FD9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
08:31:09.0891 0x0c5c WPFFontCache_v0400 - ok
08:31:09.0985 0x0c5c [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
08:31:09.0985 0x0c5c ws2ifsl - ok
08:31:10.0110 0x0c5c [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc C:\Windows\System32\wscsvc.dll
08:31:10.0125 0x0c5c wscsvc - ok
08:31:10.0219 0x0c5c WSearch - ok
08:31:10.0531 0x0c5c [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
08:31:10.0656 0x0c5c wuauserv - ok
08:31:10.0749 0x0c5c [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
08:31:10.0765 0x0c5c WudfPf - ok
08:31:10.0890 0x0c5c [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
08:31:10.0905 0x0c5c WUDFRd - ok
08:31:11.0014 0x0c5c [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
08:31:11.0030 0x0c5c wudfsvc - ok
08:31:11.0155 0x0c5c ================ Scan global ===============================
08:31:11.0186 0x0c5c [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll
08:31:11.0264 0x0c5c [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
08:31:11.0420 0x0c5c [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
08:31:11.0560 0x0c5c [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe
08:31:11.0592 0x0c5c [ Global ] - ok
08:31:11.0623 0x0c5c ================ Scan MBR ==================================
08:31:11.0638 0x0c5c [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
08:31:12.0106 0x0c5c \Device\Harddisk0\DR0 - ok
08:31:12.0122 0x0c5c ================ Scan VBR ==================================
08:31:12.0122 0x0c5c [ FAD0CBFEF0D6F91A26D1E55FF6930AC3 ] \Device\Harddisk0\DR0\Partition1
08:31:12.0153 0x0c5c \Device\Harddisk0\DR0\Partition1 - ok
08:31:12.0231 0x0c5c ================ Scan generic autorun ======================
08:31:12.0949 0x0c5c [ D8D82420048EC795DE3481DA1DDA758E, 6533BFC7B22B6A68D503C26773DD32BA555CBF785FA63437F99DE34811F4A445 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
08:31:13.0308 0x0c5c RtHDVCpl - ok
08:31:13.0510 0x0c5c [ A192F366A80D34961823D0FA6FD3EC66, D9BA08A8E430FA881AF720C4DBCB82C0EBA158BF4AB2790802030C422C157736 ] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
08:31:13.0620 0x0c5c Skytel - ok
08:31:14.0680 0x0c5c [ 26B558B2D31C7425B455B00E562EAD93, B64D128A2F1FC42BA4376F8EB08D70F4B705745CB983D0631DB45851BF34BBDF ] C:\Program Files\Alwil Software\Avast5\AvastUI.exe
08:31:14.0946 0x0c5c AvastUI.exe - ok
08:31:15.0289 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:15.0382 0x0c5c Sidebar - ok
08:31:15.0460 0x0c5c WindowsWelcomeCenter - ok
08:31:15.0632 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:15.0694 0x0c5c Sidebar - ok
08:31:15.0804 0x0c5c WindowsWelcomeCenter - ok
08:31:15.0913 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:15.0975 0x0c5c Sidebar - ok
08:31:16.0100 0x0c5c [ BF08674925F151BD4537B89A493E3E0C, 6A97562E998A2B90649FF7986313AD33823053FF98BBE163AD39AAA5E01FC545 ] C:\Windows\ehome\ehTray.exe
08:31:16.0116 0x0c5c ehTray.exe - ok
08:31:16.0178 0x0c5c [ 35937EAD711207544E219C2A19A78A7D, EE6E5EAE00F577D7C3FFB8C0D8EE484552A337CEAA27FCB107174A9879FE7362 ] C:\Program Files\Windows Media Player\WMPNSCFG.exe
08:31:16.0194 0x0c5c WMPNSCFG - ok
08:31:16.0630 0x0c5c [ 0C30D008B853CD7D8C2D604FD9790C59, F9A3D55B787DB3EE056922772D60622B6E4E3AA31235368BC2F2C7F8F5B02C07 ] C:\Program Files\DAEMON Tools Lite\DTLite.exe
08:31:16.0927 0x0c5c DAEMON Tools Lite - ok
08:31:17.0098 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:17.0192 0x0c5c Sidebar - ok
08:31:17.0270 0x0c5c WindowsWelcomeCenter - ok
08:31:17.0457 0x0c5c [ 5B2185DA1CDCDC40565B3F1ECDB11E75, 7AB5AE9C70E6DED079CA0F0459B5A06BD02F185692F9FBBDF369278A73DB28B3 ] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
08:31:17.0473 0x0c5c BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - ok
08:31:17.0535 0x0c5c [ BF08674925F151BD4537B89A493E3E0C, 6A97562E998A2B90649FF7986313AD33823053FF98BBE163AD39AAA5E01FC545 ] C:\Windows\ehome\ehTray.exe
08:31:17.0551 0x0c5c ehTray.exe - ok
08:31:17.0629 0x0c5c swg - ok
08:31:18.0222 0x0c5c [ 2A3FB4C98F139038E23330D2439DB8A4, DE9253AD362B03FA5D3D4912662398E5C4AC76F7274B83E51C251A6921A5B838 ] C:\Users\Adéla\AppData\Local\Facebook\Update\FacebookUpdate.exe
08:31:18.0253 0x0c5c Facebook Update - ok
08:31:18.0331 0x0c5c Zoner Photo Studio Autoupdate - ok
08:31:18.0393 0x0c5c [ 35937EAD711207544E219C2A19A78A7D, EE6E5EAE00F577D7C3FFB8C0D8EE484552A337CEAA27FCB107174A9879FE7362 ] C:\Program Files\Windows Media Player\WMPNSCFG.exe
08:31:18.0409 0x0c5c WMPNSCFG - ok
08:31:18.0471 0x0c5c [ 0B729DBAE22BCEACB1FA39B19748EBDC, 267CB064201C3F284B9602CFC5526B6313D8AC326588D710C5BAB0BFD2A36454 ] C:\Windows\system32\p2phost.exe
08:31:18.0487 0x0c5c CollaborationHost - ok
08:31:18.0768 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
08:31:18.0830 0x0c5c Sidebar - ok
08:31:18.0846 0x0c5c WindowsWelcomeCenter - ok
08:31:18.0970 0x0c5c [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
08:31:19.0033 0x0c5c Sidebar - ok
08:31:19.0048 0x0c5c WindowsWelcomeCenter - ok
08:31:19.0064 0x0c5c AVG-Secure-Search-Update_JUNE2013_TB - ok
08:31:19.0064 0x0c5c AVG-Secure-Search-Update_JUNE2013_HP - ok
08:31:19.0158 0x0c5c AV detected via SS2: avast! Antivirus, C:\Program Files\Alwil Software\Avast5\VisthAux.exe ( 9.0.2021.515 ), 0x40000 ( disabled : updated )
08:31:19.0173 0x0c5c FW detected via SS2: avast! Antivirus, C:\Program Files\Alwil Software\Avast5\VisthAux.exe ( 9.0.2021.515 ), 0x40010 ( disabled )
08:31:19.0189 0x0c5c Win FW state via NFP2: disabled
08:31:19.0189 0x0c5c ============================================================
08:31:19.0189 0x0c5c Scan finished
08:31:19.0189 0x0c5c ============================================================
08:31:19.0220 0x0c10 Detected object count: 0
08:31:19.0220 0x0c10 Actual detected object count: 0
08:33:14.0971 0x04bc Deinitialize success
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - celkové pročištění
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu - celkové pročištění
ComboFix 14-09-05.01 - Eva 06.09.2014 11:29:42.1.1 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1983.1184 [GMT 2:00]
Spuštěný z: c:\users\Eva\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Eva\064.jpg
c:\windows\IsUn0405.exe
c:\windows\unin0405.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-06 do 2014-09-06 )))))))))))))))))))))))))))))))
.
.
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\Eva\AppData\Local\temp
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\Kaku\AppData\Local\temp
2014-09-06 07:39 . 2014-09-06 06:33 24064 ----a-w- c:\windows\zoek-delete.exe
2014-09-04 20:33 . 2014-09-06 06:03 33512 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-09-04 20:33 . 2014-09-04 20:33 -------- d-----w- c:\programdata\RogueKiller
2014-09-04 19:29 . 2014-09-04 19:29 -------- d-----w- c:\windows\ERUNT
2014-09-04 14:43 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-09-04 14:37 . 2014-09-04 20:57 -------- d-----w- C:\AdwCleaner
2014-09-02 07:47 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A49EC999-5B2E-4FA2-85CC-C3610D9EE2D5}\mpengine.dll
2014-09-01 21:48 . 2014-09-01 21:48 -------- d-----w- c:\users\Eva\AppData\Roaming\TeamViewer
2014-09-01 21:48 . 2014-09-01 21:48 -------- d-----w- c:\program files\TeamViewer
2014-09-01 20:53 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-01 20:53 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-01 19:03 . 2014-09-01 19:04 -------- d-----w- c:\program files\Defraggler
2014-09-01 19:02 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-09-01 19:02 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 19:02 . 2014-09-01 19:02 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-09-01 18:33 . 2014-09-01 18:33 -------- d-----w- c:\users\Eva\AppData\Local\Seven Zip
2014-08-18 06:59 . 2014-08-18 06:59 -------- d-----w- c:\program files\Common Files\Skype
2014-08-14 20:29 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 20:29 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 20:29 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 20:29 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-14 08:38 . 2014-06-02 10:31 2263552 ----a-w- c:\windows\system32\msi.dll
2014-08-14 08:38 . 2014-06-02 10:31 332800 ----a-w- c:\windows\system32\msihnd.dll
2014-08-14 08:38 . 2014-06-02 10:30 1993728 ----a-w- c:\windows\system32\authui.dll
2014-08-14 08:38 . 2014-06-02 10:30 33280 ----a-w- c:\windows\system32\appinfo.dll
2014-08-14 08:38 . 2014-06-02 08:56 82432 ----a-w- c:\windows\system32\consent.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-04 19:49 . 2011-01-13 20:13 110296 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-09-01 21:13 . 2012-10-12 10:04 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-01 21:13 . 2011-08-25 06:43 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-19 05:41 . 2011-03-28 17:36 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-05 07:20 . 2009-10-03 07:25 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-10 17:02 . 2008-12-25 12:59 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-10 16:58 . 2013-04-28 15:54 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-10 16:58 . 2011-12-10 09:44 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-10 16:58 . 2008-12-25 12:59 57800 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-07-10 16:58 . 2014-05-27 12:00 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-10 16:58 . 2013-04-28 15:54 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-10 16:58 . 2008-12-25 12:59 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-10 16:58 . 2008-12-25 12:59 55112 ----a-w- c:\windows\system32\drivers\aswrdr.sys
2014-07-10 16:58 . 2014-07-10 16:58 43152 ----a-w- c:\windows\avastSS.scr
2014-07-10 16:58 . 2008-12-25 12:59 276432 ----a-w- c:\windows\system32\aswBoot.exe
1999-05-05 21:22 222390 --sha-r- c:\windows\ConfigSetRoot\IO.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-10 16:58 578240 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-11-12 6687264]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2008-11-12 1833504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-08-02 4085896]
.
c:\users\Adéla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Obsah aplikace OneNote.onetoc2 [2010-12-1 3656]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Obsah aplikace OneNote.onetoc2 [2014-5-25 3656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eva^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Eva^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2013-05-08 21:20 41056 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2013-01-31 19:15 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 03:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-08-03 11:51 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-05-07 16:45 138096 ----atw- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2011-10-28 11:18 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-08-08 08:25 1828136 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-07-24 16:26 21650016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 08:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 12:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-14 18:27 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-12 21:13]
.
2014-09-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000Core.job
- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-07 16:45]
.
2014-09-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000UA.job
- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-07 16:45]
.
2014-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 15:20]
.
2014-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 15:20]
.
2014-09-06 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2013-01-07 13:24]
.
.
------- Doplňkový sken -------
.
mStart Page = www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\sign
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojeplatba.cz\www
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.2.254
FF - ProfilePath - c:\users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - ExtSQL: !HIDDEN! 2012-11-17 13:08; 4zffxtbr@VideoDownloadConverter_4z.com; c:\program files\VideoDownloadConverter_4z\bar\1.bin
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-VDC_is1 - c:\program files\Video Download Converter\unins000.exe
AddRemove-{1B602410-D983-4947-98FE-EE749073D15E} - c:\programdata\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\Setup.exe
AddRemove-Rayman Origins Packages - c:\users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T\Rayman Origins Packages\uninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-06 11:55
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
C:\avast! sandbox
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
Celkový čas: 2014-09-06 12:01:36
ComboFix-quarantined-files.txt 2014-09-06 10:01
.
Před spuštěním: Volných bajtů: 151 145 553 920
Po spuštění: Volných bajtů: 151 042 723 840
.
- - End Of File - - AF60072F5168AE3AE2167D2809DFE2BB
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1983.1184 [GMT 2:00]
Spuštěný z: c:\users\Eva\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Eva\064.jpg
c:\windows\IsUn0405.exe
c:\windows\unin0405.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-06 do 2014-09-06 )))))))))))))))))))))))))))))))
.
.
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\Eva\AppData\Local\temp
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-06 09:55 . 2014-09-06 09:55 -------- d-----w- c:\users\Kaku\AppData\Local\temp
2014-09-06 07:39 . 2014-09-06 06:33 24064 ----a-w- c:\windows\zoek-delete.exe
2014-09-04 20:33 . 2014-09-06 06:03 33512 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-09-04 20:33 . 2014-09-04 20:33 -------- d-----w- c:\programdata\RogueKiller
2014-09-04 19:29 . 2014-09-04 19:29 -------- d-----w- c:\windows\ERUNT
2014-09-04 14:43 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-09-04 14:37 . 2014-09-04 20:57 -------- d-----w- C:\AdwCleaner
2014-09-02 07:47 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A49EC999-5B2E-4FA2-85CC-C3610D9EE2D5}\mpengine.dll
2014-09-01 21:48 . 2014-09-01 21:48 -------- d-----w- c:\users\Eva\AppData\Roaming\TeamViewer
2014-09-01 21:48 . 2014-09-01 21:48 -------- d-----w- c:\program files\TeamViewer
2014-09-01 20:53 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-01 20:53 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-01 19:03 . 2014-09-01 19:04 -------- d-----w- c:\program files\Defraggler
2014-09-01 19:02 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-09-01 19:02 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 19:02 . 2014-09-01 19:02 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-09-01 18:33 . 2014-09-01 18:33 -------- d-----w- c:\users\Eva\AppData\Local\Seven Zip
2014-08-18 06:59 . 2014-08-18 06:59 -------- d-----w- c:\program files\Common Files\Skype
2014-08-14 20:29 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 20:29 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 20:29 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 20:29 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-14 08:38 . 2014-06-02 10:31 2263552 ----a-w- c:\windows\system32\msi.dll
2014-08-14 08:38 . 2014-06-02 10:31 332800 ----a-w- c:\windows\system32\msihnd.dll
2014-08-14 08:38 . 2014-06-02 10:30 1993728 ----a-w- c:\windows\system32\authui.dll
2014-08-14 08:38 . 2014-06-02 10:30 33280 ----a-w- c:\windows\system32\appinfo.dll
2014-08-14 08:38 . 2014-06-02 08:56 82432 ----a-w- c:\windows\system32\consent.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-04 19:49 . 2011-01-13 20:13 110296 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-09-01 21:13 . 2012-10-12 10:04 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-01 21:13 . 2011-08-25 06:43 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-19 05:41 . 2011-03-28 17:36 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-05 07:20 . 2009-10-03 07:25 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-10 17:02 . 2008-12-25 12:59 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-10 16:58 . 2013-04-28 15:54 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-10 16:58 . 2011-12-10 09:44 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-10 16:58 . 2008-12-25 12:59 57800 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-07-10 16:58 . 2014-05-27 12:00 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-10 16:58 . 2013-04-28 15:54 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-10 16:58 . 2008-12-25 12:59 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-10 16:58 . 2008-12-25 12:59 55112 ----a-w- c:\windows\system32\drivers\aswrdr.sys
2014-07-10 16:58 . 2014-07-10 16:58 43152 ----a-w- c:\windows\avastSS.scr
2014-07-10 16:58 . 2008-12-25 12:59 276432 ----a-w- c:\windows\system32\aswBoot.exe
1999-05-05 21:22 222390 --sha-r- c:\windows\ConfigSetRoot\IO.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-10 16:58 578240 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 08:34 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-11-12 6687264]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2008-11-12 1833504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-08-02 4085896]
.
c:\users\Adéla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Obsah aplikace OneNote.onetoc2 [2010-12-1 3656]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Obsah aplikace OneNote.onetoc2 [2014-5-25 3656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eva^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Eva^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Eva\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2013-05-08 21:20 41056 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2013-01-31 19:15 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 03:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-08-03 11:51 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-05-07 16:45 138096 ----atw- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2011-10-28 11:18 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-08-08 08:25 1828136 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-07-24 16:26 21650016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 08:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 12:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-14 18:27 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-12 21:13]
.
2014-09-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000Core.job
- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-07 16:45]
.
2014-09-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000UA.job
- c:\users\Eva\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-07 16:45]
.
2014-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 15:20]
.
2014-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 15:20]
.
2014-09-06 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2013-01-07 13:24]
.
.
------- Doplňkový sken -------
.
mStart Page = www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\sign
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojeplatba.cz\www
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.2.254
FF - ProfilePath - c:\users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\mgx5xa5t.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - ExtSQL: !HIDDEN! 2012-11-17 13:08; 4zffxtbr@VideoDownloadConverter_4z.com; c:\program files\VideoDownloadConverter_4z\bar\1.bin
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-VDC_is1 - c:\program files\Video Download Converter\unins000.exe
AddRemove-{1B602410-D983-4947-98FE-EE749073D15E} - c:\programdata\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\Setup.exe
AddRemove-Rayman Origins Packages - c:\users\Eva\AppData\Roaming\0F1F1C2Y1H1P1C0I0T\Rayman Origins Packages\uninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-06 11:55
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
C:\avast! sandbox
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2229433316-4178244195-4092863301-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
Celkový čas: 2014-09-06 12:01:36
ComboFix-quarantined-files.txt 2014-09-06 10:01
.
Před spuštěním: Volných bajtů: 151 145 553 920
Po spuštění: Volných bajtů: 151 042 723 840
.
- - End Of File - - AF60072F5168AE3AE2167D2809DFE2BB
5C616939100B85E558DA92B899A0FC36
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - celkové pročištění
Odinstaluj:
McAfee Security Scan
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
McAfee Security Scan
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2229433316-4178244195-4092863301-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\users\Eva\AppData\Local\Facebook\Update
c:\program files\Google\Update
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 118 hostů