19:43:44.0388 1888 umbus - ok
19:43:44.0388 1888 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
19:43:44.0388 1888 UmPass - ok
19:43:44.0419 1888 [ AF0AC98EE5077EB844413EB54287FDE3 ] UmRdpService C:\Windows\System32\umrdp.dll
19:43:44.0419 1888 UmRdpService - ok
19:43:44.0434 1888 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
19:43:44.0434 1888 upnphost - ok
19:43:44.0466 1888 [ 77B01BC848298223A95D4EC23E1785A1 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
19:43:44.0466 1888 usbaudio - ok
19:43:44.0497 1888 [ 5FCC71487888589A9244AF54CFEFAB29 ] usbbus C:\Windows\system32\DRIVERS\lgx64bus.sys
19:43:44.0497 1888 usbbus - ok
19:43:44.0512 1888 [ B26AFB54A534D634523C4FB66765B026 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:43:44.0512 1888 usbccgp - ok
19:43:44.0544 1888 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
19:43:44.0544 1888 usbcir - ok
19:43:44.0575 1888 [ 3FB6E423F7567C92C32EA786F5FD0C69 ] UsbDiag C:\Windows\system32\DRIVERS\lgx64diag.sys
19:43:44.0575 1888 UsbDiag - ok
19:43:44.0575 1888 [ 2EA4AFF7BE7EB4632E3AA8595B0803B5 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
19:43:44.0575 1888 usbehci - ok
19:43:44.0590 1888 [ 4C9042B8DF86C1E8E6240C218B99B39B ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:43:44.0606 1888 usbhub - ok
19:43:44.0606 1888 [ 78D551F5B93488B4666F5FC8DD4815F3 ] USBModem C:\Windows\system32\DRIVERS\lgx64modem.sys
19:43:44.0622 1888 USBModem - ok
19:43:44.0622 1888 [ 58E546BBAF87664FC57E0F6081E4F609 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
19:43:44.0622 1888 usbohci - ok
19:43:44.0637 1888 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:43:44.0637 1888 usbprint - ok
19:43:44.0668 1888 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
19:43:44.0668 1888 usbscan - ok
19:43:44.0684 1888 [ 080D3820DA6C046BE82FC8B45A893E83 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:43:44.0684 1888 USBSTOR - ok
19:43:44.0700 1888 [ 6D14D8EC1DD33A072653E75E3B28B062 ] usbUDisc C:\Windows\system32\DRIVERS\USBDrv_AMD64.sys
19:43:44.0700 1888 usbUDisc - ok
19:43:44.0715 1888 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
19:43:44.0715 1888 usbuhci - ok
19:43:44.0731 1888 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
19:43:44.0731 1888 UxSms - ok
19:43:44.0746 1888 [ 0793F40B9B8A1BDD266296409DBD91EA ] VaultSvc C:\Windows\system32\lsass.exe
19:43:44.0746 1888 VaultSvc - ok
19:43:44.0746 1888 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
19:43:44.0746 1888 vdrvroot - ok
19:43:44.0778 1888 [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds C:\Windows\System32\vds.exe
19:43:44.0778 1888 vds - ok
19:43:44.0793 1888 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:43:44.0793 1888 vga - ok
19:43:44.0809 1888 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
19:43:44.0809 1888 VgaSave - ok
19:43:44.0809 1888 [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
19:43:44.0809 1888 vhdmp - ok
19:43:44.0824 1888 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
19:43:44.0824 1888 viaide - ok
19:43:44.0840 1888 [ 1501699D7EDA984ABC4155A7DA5738D1 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
19:43:44.0840 1888 vmbus - ok
19:43:44.0840 1888 [ AE10C35761889E65A6F7176937C5592C ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
19:43:44.0840 1888 VMBusHID - ok
19:43:44.0856 1888 [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
19:43:44.0856 1888 volmgr - ok
19:43:44.0871 1888 [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:43:44.0871 1888 volmgrx - ok
19:43:44.0887 1888 [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
19:43:44.0887 1888 volsnap - ok
19:43:44.0902 1888 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
19:43:44.0902 1888 vsmraid - ok
19:43:44.0949 1888 [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS C:\Windows\system32\vssvc.exe
19:43:44.0965 1888 VSS - ok
19:43:44.0980 1888 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
19:43:44.0980 1888 vwifibus - ok
19:43:44.0996 1888 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
19:43:44.0996 1888 W32Time - ok
19:43:45.0012 1888 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
19:43:45.0012 1888 WacomPen - ok
19:43:45.0027 1888 [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:43:45.0027 1888 WANARP - ok
19:43:45.0027 1888 [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:43:45.0027 1888 Wanarpv6 - ok
19:43:45.0058 1888 [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine C:\Windows\system32\wbengine.exe
19:43:45.0074 1888 wbengine - ok
19:43:45.0074 1888 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:43:45.0090 1888 WbioSrvc - ok
19:43:45.0105 1888 [ 8321C2CA3B62B61B293CDA3451984468 ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:43:45.0105 1888 wcncsvc - ok
19:43:45.0121 1888 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:43:45.0121 1888 WcsPlugInService - ok
19:43:45.0121 1888 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
19:43:45.0121 1888 Wd - ok
19:43:45.0136 1888 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:43:45.0136 1888 Wdf01000 - ok
19:43:45.0152 1888 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:43:45.0152 1888 WdiServiceHost - ok
19:43:45.0168 1888 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:43:45.0168 1888 WdiSystemHost - ok
19:43:45.0183 1888 [ 8A438CBB8C032A0C798B0C642FFBE572 ] WebClient C:\Windows\System32\webclnt.dll
19:43:45.0183 1888 WebClient - ok
19:43:45.0199 1888 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:43:45.0199 1888 Wecsvc - ok
19:43:45.0214 1888 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:43:45.0214 1888 wercplsupport - ok
19:43:45.0230 1888 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
19:43:45.0246 1888 WerSvc - ok
19:43:45.0246 1888 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:43:45.0246 1888 WfpLwf - ok
19:43:45.0261 1888 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:43:45.0261 1888 WIMMount - ok
19:43:45.0261 1888 WinDefend - ok
19:43:45.0277 1888 WinHttpAutoProxySvc - ok
19:43:45.0308 1888 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:43:45.0308 1888 Winmgmt - ok
19:43:45.0355 1888 [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM C:\Windows\system32\WsmSvc.dll
19:43:45.0417 1888 WinRM - ok
19:43:45.0464 1888 [ 817EAFF5D38674EDD7713B9DFB8E9791 ] WinUSB C:\Windows\system32\DRIVERS\WinUSB.sys
19:43:45.0464 1888 WinUSB - ok
19:43:45.0480 1888 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
19:43:45.0495 1888 Wlansvc - ok
19:43:45.0604 1888 [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:43:45.0620 1888 wlidsvc - ok
19:43:45.0636 1888 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
19:43:45.0636 1888 WmiAcpi - ok
19:43:45.0636 1888 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:43:45.0651 1888 wmiApSrv - ok
19:43:45.0651 1888 WMPNetworkSvc - ok
19:43:45.0651 1888 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:43:45.0667 1888 WPCSvc - ok
19:43:45.0667 1888 [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:43:45.0682 1888 WPDBusEnum - ok
19:43:45.0682 1888 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:43:45.0682 1888 ws2ifsl - ok
19:43:45.0698 1888 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
19:43:45.0714 1888 wscsvc - ok
19:43:45.0714 1888 WSearch - ok
19:43:45.0792 1888 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
19:43:45.0823 1888 wuauserv - ok
19:43:45.0823 1888 [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:43:45.0838 1888 WudfPf - ok
19:43:45.0854 1888 [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:43:45.0854 1888 WUDFRd - ok
19:43:45.0870 1888 [ B551D6637AA0E132C18AC6E504F7B79B ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:43:45.0870 1888 wudfsvc - ok
19:43:45.0885 1888 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
19:43:45.0885 1888 WwanSvc - ok
19:43:45.0948 1888 X6va012 - ok
19:43:45.0963 1888 ================ Scan global ===============================
19:43:45.0979 1888 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
19:43:45.0994 1888 [ 457B44AB6D502E55F64A867D4F35C76C ] C:\Windows\system32\winsrv.dll
19:43:46.0010 1888 [ 457B44AB6D502E55F64A867D4F35C76C ] C:\Windows\system32\winsrv.dll
19:43:46.0041 1888 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
19:43:46.0057 1888 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
19:43:46.0072 1888 [Global] - ok
19:43:46.0072 1888 ================ Scan MBR ==================================
19:43:46.0088 1888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:43:46.0509 1888 \Device\Harddisk0\DR0 - ok
19:43:46.0509 1888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
19:43:46.0509 1888 \Device\Harddisk1\DR1 - ok
19:43:46.0509 1888 ================ Scan VBR ==================================
19:43:46.0525 1888 [ 488DD06B71A06B614A544B22A72199DD ] \Device\Harddisk0\DR0\Partition1
19:43:46.0525 1888 \Device\Harddisk0\DR0\Partition1 - ok
19:43:46.0540 1888 [ 8F7A16FF11B97ABAFEC9A88E8A083775 ] \Device\Harddisk0\DR0\Partition2
19:43:46.0540 1888 \Device\Harddisk0\DR0\Partition2 - ok
19:43:46.0540 1888 [ E7BD7AD71D0809087A33198407FBA1C7 ] \Device\Harddisk1\DR1\Partition1
19:43:46.0540 1888 \Device\Harddisk1\DR1\Partition1 - ok
19:43:46.0540 1888 ============================================================
19:43:46.0540 1888 Scan finished
19:43:46.0540 1888 ============================================================
19:43:46.0540 4632 Detected object count: 0
19:43:46.0540 4632 Actual detected object count: 0
19:43:55.0354 0724 Deinitialize success
Nemohl jsem to poslat celé najednou, omezuje mě maximální počet znaků
Prosím o kontrolu logu-zamrzání pc Vyřešeno
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
I use Arch BTW
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
OK.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
ComboFix 13-07-11.03 - Já 12.07.2013 11:12:49.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.4094.2751 [GMT 2:00]
Spuštěný z: c:\users\Já\Desktop\PROGRAMY\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\SysWow64\3gpvideoconvertera.dat
c:\windows\SysWow64\3gpvideoconverterb.dat
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-12 do 2013-07-12 )))))))))))))))))))))))))))))))
.
.
2013-07-12 09:17 . 2013-07-12 09:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-12 09:17 . 2013-07-12 09:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-11 18:28 . 2013-07-11 18:28 -------- d-----w- c:\users\Já\AppData\Local\Adobe
2013-07-10 14:59 . 2013-07-10 14:59 -------- d-----w- c:\windows\ERUNT
2013-07-10 14:32 . 2013-07-11 17:02 844 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\users\Já\AppData\Roaming\Malwarebytes
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\programdata\Malwarebytes
2013-07-10 11:52 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-08 09:15 . 2013-07-08 09:15 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-07-07 10:03 . 2013-07-07 10:03 -------- d-----w- c:\users\Já\AppData\Local\Chromium
2013-07-06 21:05 . 2013-07-06 21:05 -------- d-----w- c:\users\J
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Local\Skyrim
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Roaming\XRay Engine
2013-06-30 21:09 . 2013-07-01 07:20 -------- d-----w- c:\programdata\WarThunder
2013-06-30 21:09 . 2013-06-30 21:09 -------- d-----w- c:\users\Já\AppData\Local\WarThunder
2013-06-23 10:51 . 2013-06-23 10:51 -------- d-----w- c:\users\Já
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-06-18 17:53 . 2013-07-07 14:33 -------- d-----w- c:\users\Spusť toto
2013-06-14 14:43 . 2013-06-14 14:43 -------- d-----w- c:\users\Já\AppData\Roaming\Sony Creative Software Inc
2013-06-14 14:33 . 2013-06-14 14:33 -------- d-----w- c:\users\Já\AppData\Roaming\Publish Providers
2013-06-14 14:14 . 2013-06-14 14:23 -------- d-----w- c:\users\Já\AppData\Local\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\programdata\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\program files (x86)\Sony
2013-06-14 14:12 . 2013-06-14 14:47 -------- d-----w- c:\users\Já\AppData\Roaming\Sony
2013-06-14 14:08 . 2013-06-14 14:08 -------- d-----w- c:\programdata\id Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-11 18:45 . 2012-08-18 16:34 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-07-11 18:45 . 2012-08-16 09:51 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-11 18:44 . 2012-08-16 09:51 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-06-21 12:06 . 2013-03-26 15:51 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-03-23 17:02 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2012-08-15 13:59 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2012-08-15 13:59 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2012-08-15 13:59 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2012-08-15 13:59 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2012-08-15 13:59 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 10:23 . 2012-08-15 13:59 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2012-08-15 13:59 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2012-08-15 13:59 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2012-09-13 17:55 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2012-08-15 13:59 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2012-08-15 13:59 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-20 04:17 . 2012-08-15 13:59 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-06-12 14:31 . 2012-08-15 13:48 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 14:31 . 2012-08-15 13:48 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-02 17:19 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-23 11:54 . 2013-04-23 11:54 30112 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 98304]
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\DTLite.exe" [2012-04-11 3672384]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"LogMeIn Hamachi Ui"="d:\programy\Hamachi\hamachi-2-ui.exe" [2013-05-15 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswVmm;aswVmm; [x]
R3 cpuz135;cpuz135;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TunngleService;TunngleService;d:\programy\Tunngle\TnglCtrl.exe;d:\programy\Tunngle\TnglCtrl.exe [x]
R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\programy\Hamachi\hamachi-2.exe;d:\programy\Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;d:\programy\Version8\TeamViewer_Service.exe;d:\programy\Version8\TeamViewer_Service.exe [x]
S3 ALSysIO;ALSysIO;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 14:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"BCSSync"="d:\programy\MS Office 2010\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=Quicksearch_16194&q=
FF - ExtSQL: 2013-06-10 19:21; toolbar@ask.com; c:\users\JĂ¡\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-EaseUS EPM tray - d:\programy\EaseUS Partition Master 9.2.2\bin\EpmNews.exe
Wow6432Node-HKLM-Run-Aimersoft Helper Compact.exe - c:\program files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1 - d:\programy\Convert MOV to AVI\unins000.exe
AddRemove-SOE-DC Universe Online Live - d:\hry\DCUniverse\uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-07-12 11:19:00
ComboFix-quarantined-files.txt 2013-07-12 09:19
.
Před spuštěním: 9 713 696 768
Po spuštění: 9 423 167 488
.
- - End Of File - - 4130A7B0D217B925FCD86740CDDE28CB
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.4094.2751 [GMT 2:00]
Spuštěný z: c:\users\Já\Desktop\PROGRAMY\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\SysWow64\3gpvideoconvertera.dat
c:\windows\SysWow64\3gpvideoconverterb.dat
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-12 do 2013-07-12 )))))))))))))))))))))))))))))))
.
.
2013-07-12 09:17 . 2013-07-12 09:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-12 09:17 . 2013-07-12 09:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-11 18:28 . 2013-07-11 18:28 -------- d-----w- c:\users\Já\AppData\Local\Adobe
2013-07-10 14:59 . 2013-07-10 14:59 -------- d-----w- c:\windows\ERUNT
2013-07-10 14:32 . 2013-07-11 17:02 844 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\users\Já\AppData\Roaming\Malwarebytes
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\programdata\Malwarebytes
2013-07-10 11:52 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-08 09:15 . 2013-07-08 09:15 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-07-07 10:03 . 2013-07-07 10:03 -------- d-----w- c:\users\Já\AppData\Local\Chromium
2013-07-06 21:05 . 2013-07-06 21:05 -------- d-----w- c:\users\J
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Local\Skyrim
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Roaming\XRay Engine
2013-06-30 21:09 . 2013-07-01 07:20 -------- d-----w- c:\programdata\WarThunder
2013-06-30 21:09 . 2013-06-30 21:09 -------- d-----w- c:\users\Já\AppData\Local\WarThunder
2013-06-23 10:51 . 2013-06-23 10:51 -------- d-----w- c:\users\Já
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-06-18 17:53 . 2013-07-07 14:33 -------- d-----w- c:\users\Spusť toto
2013-06-14 14:43 . 2013-06-14 14:43 -------- d-----w- c:\users\Já\AppData\Roaming\Sony Creative Software Inc
2013-06-14 14:33 . 2013-06-14 14:33 -------- d-----w- c:\users\Já\AppData\Roaming\Publish Providers
2013-06-14 14:14 . 2013-06-14 14:23 -------- d-----w- c:\users\Já\AppData\Local\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\programdata\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\program files (x86)\Sony
2013-06-14 14:12 . 2013-06-14 14:47 -------- d-----w- c:\users\Já\AppData\Roaming\Sony
2013-06-14 14:08 . 2013-06-14 14:08 -------- d-----w- c:\programdata\id Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-11 18:45 . 2012-08-18 16:34 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-07-11 18:45 . 2012-08-16 09:51 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-11 18:44 . 2012-08-16 09:51 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-06-21 12:06 . 2013-03-26 15:51 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-03-23 17:02 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2012-08-15 13:59 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2012-08-15 13:59 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2012-08-15 13:59 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2012-08-15 13:59 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2012-08-15 13:59 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 10:23 . 2012-08-15 13:59 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2012-08-15 13:59 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2012-08-15 13:59 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2012-09-13 17:55 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2012-08-15 13:59 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2012-08-15 13:59 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-20 04:17 . 2012-08-15 13:59 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-06-12 14:31 . 2012-08-15 13:48 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 14:31 . 2012-08-15 13:48 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-02 17:19 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-23 11:54 . 2013-04-23 11:54 30112 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 98304]
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\DTLite.exe" [2012-04-11 3672384]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"LogMeIn Hamachi Ui"="d:\programy\Hamachi\hamachi-2-ui.exe" [2013-05-15 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswVmm;aswVmm; [x]
R3 cpuz135;cpuz135;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TunngleService;TunngleService;d:\programy\Tunngle\TnglCtrl.exe;d:\programy\Tunngle\TnglCtrl.exe [x]
R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\programy\Hamachi\hamachi-2.exe;d:\programy\Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;d:\programy\Version8\TeamViewer_Service.exe;d:\programy\Version8\TeamViewer_Service.exe [x]
S3 ALSysIO;ALSysIO;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 14:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"BCSSync"="d:\programy\MS Office 2010\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=Quicksearch_16194&q=
FF - ExtSQL: 2013-06-10 19:21; toolbar@ask.com; c:\users\JĂ¡\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-EaseUS EPM tray - d:\programy\EaseUS Partition Master 9.2.2\bin\EpmNews.exe
Wow6432Node-HKLM-Run-Aimersoft Helper Compact.exe - c:\program files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1 - d:\programy\Convert MOV to AVI\unins000.exe
AddRemove-SOE-DC Universe Online Live - d:\hry\DCUniverse\uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-07-12 11:19:00
ComboFix-quarantined-files.txt 2013-07-12 09:19
.
Před spuštěním: 9 713 696 768
Po spuštění: 9 423 167 488
.
- - End Of File - - 4130A7B0D217B925FCD86740CDDE28CB
A36C5E4F47E84449FF07ED3517B43A31
I use Arch BTW
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Nemáš málo volného místa na disku??
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\DeleteOnReboot.bat
c:\windows\SysWOW64\Drivers\X6va012
Folder::
c:\program files (x86)\Skype\Updater
Driver::
SkypeUpdate
X6va012
Registry::
[-HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
Firefox::
FF - ProfilePath - c:\users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=Quicksearch_16194&q=
FF - ExtSQL: 2013-06-10 19:21; toolbar@ask.com; c:\users\JĂ¡\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Nemáš málo volného místa na disku??
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
ComboFix 13-07-11.03 - Já 12.07.2013 23:07:19.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.4094.2545 [GMT 2:00]
Spuštěný z: c:\users\Jß\Desktop\PROGRAMY\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jß\Desktop\PROGRAMY\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-12 do 2013-07-12 )))))))))))))))))))))))))))))))
.
.
2013-07-12 21:12 . 2013-07-12 21:12 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-12 21:12 . 2013-07-12 21:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-11 18:28 . 2013-07-11 18:28 -------- d-----w- c:\users\Já\AppData\Local\Adobe
2013-07-10 14:59 . 2013-07-10 14:59 -------- d-----w- c:\windows\ERUNT
2013-07-10 14:32 . 2013-07-11 17:02 844 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\users\Já\AppData\Roaming\Malwarebytes
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\programdata\Malwarebytes
2013-07-10 11:52 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-08 09:15 . 2013-07-08 09:15 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-07-07 10:03 . 2013-07-07 10:03 -------- d-----w- c:\users\Já\AppData\Local\Chromium
2013-07-06 21:05 . 2013-07-06 21:05 -------- d-----w- c:\users\J
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Local\Skyrim
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Roaming\XRay Engine
2013-06-30 21:09 . 2013-07-01 07:20 -------- d-----w- c:\programdata\WarThunder
2013-06-30 21:09 . 2013-06-30 21:09 -------- d-----w- c:\users\Já\AppData\Local\WarThunder
2013-06-23 10:51 . 2013-07-12 09:19 -------- d-----w- c:\users\Já
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-06-18 17:53 . 2013-07-07 14:33 -------- d-----w- c:\users\Spusť toto
2013-06-14 14:43 . 2013-06-14 14:43 -------- d-----w- c:\users\Já\AppData\Roaming\Sony Creative Software Inc
2013-06-14 14:33 . 2013-06-14 14:33 -------- d-----w- c:\users\Já\AppData\Roaming\Publish Providers
2013-06-14 14:14 . 2013-06-14 14:23 -------- d-----w- c:\users\Já\AppData\Local\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\programdata\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\program files (x86)\Sony
2013-06-14 14:12 . 2013-06-14 14:47 -------- d-----w- c:\users\Já\AppData\Roaming\Sony
2013-06-14 14:08 . 2013-06-14 14:08 -------- d-----w- c:\programdata\id Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-12 19:48 . 2012-08-18 16:34 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-07-12 19:48 . 2012-08-16 09:51 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-12 19:48 . 2012-08-16 09:51 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-06-21 12:06 . 2013-03-26 15:51 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-03-23 17:02 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2012-08-15 13:59 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2012-08-15 13:59 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2012-08-15 13:59 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2012-08-15 13:59 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2012-08-15 13:59 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 10:23 . 2012-08-15 13:59 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2012-08-15 13:59 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2012-08-15 13:59 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2012-09-13 17:55 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2012-08-15 13:59 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2012-08-15 13:59 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-20 04:17 . 2012-08-15 13:59 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-06-12 14:31 . 2012-08-15 13:48 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 14:31 . 2012-08-15 13:48 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-02 17:19 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-23 11:54 . 2013-04-23 11:54 30112 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 98304]
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\DTLite.exe" [2012-04-11 3672384]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"LogMeIn Hamachi Ui"="d:\programy\Hamachi\hamachi-2-ui.exe" [2013-05-15 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswVmm;aswVmm; [x]
R3 cpuz135;cpuz135;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TunngleService;TunngleService;d:\programy\Tunngle\TnglCtrl.exe;d:\programy\Tunngle\TnglCtrl.exe [x]
R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\programy\Hamachi\hamachi-2.exe;d:\programy\Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;d:\programy\Version8\TeamViewer_Service.exe;d:\programy\Version8\TeamViewer_Service.exe [x]
S3 ALSysIO;ALSysIO;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ALSYSIO
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 14:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"BCSSync"="d:\programy\MS Office 2010\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=Quicksearch_16194&q=
FF - ExtSQL: 2013-06-10 19:21; toolbar@ask.com; c:\users\JĂ¡\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1 - d:\programy\Convert MOV to AVI\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-07-12 23:13:33
ComboFix-quarantined-files.txt 2013-07-12 21:13
ComboFix2.txt 2013-07-12 09:19
.
Před spuštěním: 9 287 720 960
Po spuštění: 9 204 559 872
.
- - End Of File - - 7D62F1CC1612C0B59B48C05F36181EDB
A36C5E4F47E84449FF07ED3517B43A31
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:15:23, on 12.7.2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
D:\Programy\Hamachi\hamachi-2-ui.exe
C:\Users\Já\Desktop\PROGRAMY\hijackthis.exe
C:\Windows\SysWOW64\DllHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Programy\Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKUS\S-1-5-21-2661186389-136383515-1521028768-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Programy\Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - D:\Programy\Version8\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Programy\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8024 bytes
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-07-12 23:17:34
-----------------------------
23:17:34.040 OS Version: Windows x64 6.1.7600
23:17:34.040 Number of processors: 4 586 0x503
23:17:34.040 ComputerName: PC UserName: Já
23:17:34.305 Initialize success
23:17:34.383 AVAST engine defs: 13071201
23:17:41.512 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:17:41.528 Disk 0 Vendor: WDC_WD10EZEX-00KUWA0 15.01H15 Size: 953869MB BusType: 3
23:17:41.528 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1
23:17:41.544 Disk 1 Vendor: SAMSUNG_HD322GJ 1AR10001 Size: 305245MB BusType: 3
23:17:41.653 Disk 0 MBR read successfully
23:17:41.653 Disk 0 MBR scan
23:17:41.653 Disk 0 Windows 7 default MBR code
23:17:41.668 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 57223 MB offset 63
23:17:41.684 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 896643 MB offset 117194175
23:17:41.700 Disk 0 scanning C:\Windows\system32\drivers
23:17:47.674 Service scanning
23:17:57.986 Modules scanning
23:17:58.002 Disk 0 trace - called modules:
23:17:58.017 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
23:17:58.017 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a45060]
23:17:58.033 3 CLASSPNP.SYS[fffff8800185b43f] -> nt!IofCallDriver -> [0xfffffa80047f8520]
23:17:58.033 5 ACPI.sys[fffff88000ed8781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80047d8060]
23:17:58.267 AVAST engine scan C:\Windows
23:17:59.796 AVAST engine scan C:\Windows\system32
23:19:21.540 AVAST engine scan C:\Windows\system32\drivers
23:19:26.298 AVAST engine scan C:\Users\Já
23:23:23.481 AVAST engine scan C:\ProgramData
23:25:14.350 Scan finished successfully
23:25:49.450 Disk 0 MBR has been saved successfully to "C:\Users\Já\Desktop\logys\MBR.dat"
23:25:49.466 The log file has been saved successfully to "C:\Users\Já\Desktop\logys\aswMBR.txt"
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.4094.2545 [GMT 2:00]
Spuštěný z: c:\users\Jß\Desktop\PROGRAMY\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jß\Desktop\PROGRAMY\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-12 do 2013-07-12 )))))))))))))))))))))))))))))))
.
.
2013-07-12 21:12 . 2013-07-12 21:12 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-12 21:12 . 2013-07-12 21:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-11 18:28 . 2013-07-11 18:28 -------- d-----w- c:\users\Já\AppData\Local\Adobe
2013-07-10 14:59 . 2013-07-10 14:59 -------- d-----w- c:\windows\ERUNT
2013-07-10 14:32 . 2013-07-11 17:02 844 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\users\Já\AppData\Roaming\Malwarebytes
2013-07-10 11:52 . 2013-07-10 11:52 -------- d-----w- c:\programdata\Malwarebytes
2013-07-10 11:52 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-08 09:15 . 2013-07-08 09:15 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-07-07 10:03 . 2013-07-07 10:03 -------- d-----w- c:\users\Já\AppData\Local\Chromium
2013-07-06 21:05 . 2013-07-06 21:05 -------- d-----w- c:\users\J
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Local\Skyrim
2013-07-06 14:25 . 2013-07-06 14:25 -------- d-----w- c:\users\Já\AppData\Roaming\XRay Engine
2013-06-30 21:09 . 2013-07-01 07:20 -------- d-----w- c:\programdata\WarThunder
2013-06-30 21:09 . 2013-06-30 21:09 -------- d-----w- c:\users\Já\AppData\Local\WarThunder
2013-06-23 10:51 . 2013-07-12 09:19 -------- d-----w- c:\users\Já
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-06-18 17:53 . 2013-07-07 14:33 -------- d-----w- c:\users\Spusť toto
2013-06-14 14:43 . 2013-06-14 14:43 -------- d-----w- c:\users\Já\AppData\Roaming\Sony Creative Software Inc
2013-06-14 14:33 . 2013-06-14 14:33 -------- d-----w- c:\users\Já\AppData\Roaming\Publish Providers
2013-06-14 14:14 . 2013-06-14 14:23 -------- d-----w- c:\users\Já\AppData\Local\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\programdata\Sony
2013-06-14 14:14 . 2013-06-14 14:14 -------- d-----w- c:\program files (x86)\Sony
2013-06-14 14:12 . 2013-06-14 14:47 -------- d-----w- c:\users\Já\AppData\Roaming\Sony
2013-06-14 14:08 . 2013-06-14 14:08 -------- d-----w- c:\programdata\id Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-12 19:48 . 2012-08-18 16:34 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-07-12 19:48 . 2012-08-16 09:51 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-12 19:48 . 2012-08-16 09:51 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-06-21 12:06 . 2013-03-26 15:51 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-03-23 17:02 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2012-08-15 13:59 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2012-08-15 13:59 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2012-08-15 13:59 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2012-08-15 13:59 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2012-08-15 13:59 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 10:23 . 2012-08-15 13:59 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2012-08-15 13:59 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2012-08-15 13:59 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2012-09-13 17:55 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2012-08-15 13:59 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2012-08-15 13:59 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-20 04:17 . 2012-08-15 13:59 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-06-12 14:31 . 2012-08-15 13:48 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 14:31 . 2012-08-15 13:48 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-02 17:19 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-23 11:54 . 2013-04-23 11:54 30112 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 98304]
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\DTLite.exe" [2012-04-11 3672384]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"LogMeIn Hamachi Ui"="d:\programy\Hamachi\hamachi-2-ui.exe" [2013-05-15 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswVmm;aswVmm; [x]
R3 cpuz135;cpuz135;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\JA30B~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TunngleService;TunngleService;d:\programy\Tunngle\TnglCtrl.exe;d:\programy\Tunngle\TnglCtrl.exe [x]
R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\programy\Hamachi\hamachi-2.exe;d:\programy\Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;d:\programy\Version8\TeamViewer_Service.exe;d:\programy\Version8\TeamViewer_Service.exe [x]
S3 ALSysIO;ALSysIO;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\JA30B~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ALSYSIO
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 14:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"BCSSync"="d:\programy\MS Office 2010\Office14\BCSSync.exe" [2010-03-13 112512]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - d:\programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=Quicksearch_16194&q=
FF - ExtSQL: 2013-06-10 19:21; toolbar@ask.com; c:\users\JĂ¡\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1 - d:\programy\Convert MOV to AVI\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-07-12 23:13:33
ComboFix-quarantined-files.txt 2013-07-12 21:13
ComboFix2.txt 2013-07-12 09:19
.
Před spuštěním: 9 287 720 960
Po spuštění: 9 204 559 872
.
- - End Of File - - 7D62F1CC1612C0B59B48C05F36181EDB
A36C5E4F47E84449FF07ED3517B43A31
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:15:23, on 12.7.2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
D:\Programy\Hamachi\hamachi-2-ui.exe
C:\Users\Já\Desktop\PROGRAMY\hijackthis.exe
C:\Windows\SysWOW64\DllHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Programy\Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKUS\S-1-5-21-2661186389-136383515-1521028768-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Programy\Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - D:\Programy\Version8\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Programy\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8024 bytes
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-07-12 23:17:34
-----------------------------
23:17:34.040 OS Version: Windows x64 6.1.7600
23:17:34.040 Number of processors: 4 586 0x503
23:17:34.040 ComputerName: PC UserName: Já
23:17:34.305 Initialize success
23:17:34.383 AVAST engine defs: 13071201
23:17:41.512 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:17:41.528 Disk 0 Vendor: WDC_WD10EZEX-00KUWA0 15.01H15 Size: 953869MB BusType: 3
23:17:41.528 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1
23:17:41.544 Disk 1 Vendor: SAMSUNG_HD322GJ 1AR10001 Size: 305245MB BusType: 3
23:17:41.653 Disk 0 MBR read successfully
23:17:41.653 Disk 0 MBR scan
23:17:41.653 Disk 0 Windows 7 default MBR code
23:17:41.668 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 57223 MB offset 63
23:17:41.684 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 896643 MB offset 117194175
23:17:41.700 Disk 0 scanning C:\Windows\system32\drivers
23:17:47.674 Service scanning
23:17:57.986 Modules scanning
23:17:58.002 Disk 0 trace - called modules:
23:17:58.017 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
23:17:58.017 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a45060]
23:17:58.033 3 CLASSPNP.SYS[fffff8800185b43f] -> nt!IofCallDriver -> [0xfffffa80047f8520]
23:17:58.033 5 ACPI.sys[fffff88000ed8781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80047d8060]
23:17:58.267 AVAST engine scan C:\Windows
23:17:59.796 AVAST engine scan C:\Windows\system32
23:19:21.540 AVAST engine scan C:\Windows\system32\drivers
23:19:26.298 AVAST engine scan C:\Users\Já
23:23:23.481 AVAST engine scan C:\ProgramData
23:25:14.350 Scan finished successfully
23:25:49.450 Disk 0 MBR has been saved successfully to "C:\Users\Já\Desktop\logys\MBR.dat"
23:25:49.466 The log file has been saved successfully to "C:\Users\Já\Desktop\logys\aswMBR.txt"
I use Arch BTW
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
Na systémovém disku mám cca. 9GB volného místa a na ostatních několik set GB.
I use Arch BTW
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
Právě systémový je nejdůležitější , windows pak odmítá ukládat dočasné soubory , historii , ap.
nemaže to.
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
nemaže to.
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
OTL logfile created on: 13.7.2013 12:23:47 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Já\Desktop\PROGRAMY
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,17% Memory free
7,99 Gb Paging File | 6,72 Gb Available in Paging File | 84,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55,88 Gb Total Space | 8,94 Gb Free Space | 16,01% Space Free | Partition Type: NTFS
Drive D: | 875,63 Gb Total Space | 577,72 Gb Free Space | 65,98% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Já | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Já\Desktop\PROGRAMY\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - D:\Programy\Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - D:\Programy\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_MouseDeviceManager.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\Data\X7\Forms\OSD_Text\OSD_Text.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_Wheel4D.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_ZoomControl.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_ScrollbarControl.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInRight.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInOne.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (TunngleService) -- D:\Programy\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Hamachi2Svc) -- D:\Programy\Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (TeamViewer8) -- D:\Programy\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (KMService) -- C:\Windows\SysWOW64\srvany.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (nTuneService) -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
========== Driver Services (SafeList) ==========
DRV:64bit: - (usbUDisc) -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys (Scott)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (pcouffin) -- C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (pneteth) -- C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (LgBttPort) -- C:\Windows\SysNative\drivers\lgbtpt64.sys (LG Electronics Inc.)
DRV:64bit: - (LGVMODEM) -- C:\Windows\SysNative\drivers\lgvmdm64.sys (LG Electronics Inc.)
DRV:64bit: - (lgbusenum) -- C:\Windows\SysNative\drivers\lgbtbs64.sys (LG Electronics Inc.)
DRV:64bit: - (tap0901t) -- C:\Windows\SysNative\drivers\tap0901t.sys (Tunngle.net)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (USBModem) -- C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) -- C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) -- C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NVR0Dev) -- C:\Windows\nvoclk64.sys (NVidia Corp.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz"
FF - prefs.js..extensions.enabledAddons: battlefieldheroespatcher%40ea.com:5.0.203.0
FF - prefs.js..extensions.enabledAddons: donottrackplus%40abine.com:2.2.9.618
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=Quicksearch_16194&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Programy\MSOFFI~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Já\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: D:\Hry\HAWX 2\orbitlauncher\npuplaypc.dll (Ubisoft)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.04.02 17:25:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: D:\Programy\Firefox\components [2013.07.03 09:30:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: D:\Programy\Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: D:\Programy\Firefox\components [2013.07.03 09:30:26 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: D:\Programy\Firefox\plugins
[2012.08.24 23:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Extensions
[2013.07.12 11:21:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions
[2013.05.17 17:40:58 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\battlefieldheroespatcher@ea.com
[2013.07.12 11:21:00 | 000,000,000 | ---D | M] (DoNotTrackMe) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\donottrackplus@abine.com
[2013.06.10 19:21:39 | 000,000,000 | ---D | M] (KMPlayer Toolbar) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
[2013.05.01 12:53:31 | 000,002,055 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\firmycz.xml
[2013.05.01 12:53:30 | 000,002,047 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\mapycz.xml
[2013.05.01 12:53:31 | 000,002,213 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\zbocz.xml
File not found (No name found) -- C:\USERS\Já\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6EJLKD02.DEFAULT\EXTENSIONS\BATTLEFIELDHEROESPATCHER@EA.COM
File not found (No name found) -- C:\USERS\Já\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6EJLKD02.DEFAULT\EXTENSIONS\DONOTTRACKPLUS@ABINE.COM
O1 HOSTS File: ([2013.07.12 11:17:33 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programy\MS Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Pomocná služba pro přihlášení k účtu Microsoft) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.)
O4:64bit: - HKLM..\Run: [BCSSync] D:\Programy\MS Office 2010\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] D:\Programy\Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Programy\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [OscarEditor] C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.99.25.113 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0BB736B4-1894-4BD8-846C-5AE28EBE05CF}: DhcpNameServer = 7.254.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E441F964-0EB1-42B1-B606-4DF7EC813335}: DhcpNameServer = 10.99.25.113 192.168.1.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.05.29 15:40:21 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.13 10:20:41 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.12 23:14:05 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logys
[2013.07.12 23:13:35 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.12 11:10:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.12 11:10:08 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.11 20:28:14 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Adobe
[2013.07.11 19:01:15 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logyyy
[2013.07.10 16:59:13 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.07.10 16:37:08 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logy2
[2013.07.10 14:44:18 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logy
[2013.07.10 13:52:10 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Malwarebytes
[2013.07.10 13:52:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.10 13:52:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.07.10 13:52:00 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.08 11:15:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.07.08 11:13:37 | 027,781,920 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.07.08 11:13:37 | 021,102,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.07.08 11:13:37 | 007,641,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.07.08 11:13:37 | 006,324,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.07.08 11:13:37 | 000,925,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll
[2013.07.08 11:13:37 | 000,572,704 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
[2013.07.08 11:13:37 | 000,570,656 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
[2013.07.08 11:13:37 | 000,467,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
[2013.07.08 11:13:37 | 000,266,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll
[2013.07.08 11:13:37 | 000,218,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll
[2013.07.08 11:13:37 | 000,214,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll
[2013.07.08 11:13:37 | 000,194,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
[2013.07.08 11:13:37 | 000,181,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll
[2013.07.08 11:13:37 | 000,031,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
[2013.07.08 11:13:36 | 025,256,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.07.08 11:13:36 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.07.08 11:13:36 | 009,239,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.07.08 11:13:36 | 007,687,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.07.08 11:13:36 | 002,953,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.07.08 11:13:36 | 002,777,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.07.08 11:13:36 | 002,363,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.07.08 11:13:36 | 002,002,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.07.08 11:13:36 | 001,832,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432049.dll
[2013.07.08 11:13:36 | 001,511,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432049.dll
[2013.07.08 11:13:36 | 000,465,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
[2013.07.07 12:03:24 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Chromium
[2013.07.07 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Já\Documents\Arktos
[2013.07.06 20:45:49 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2013.07.06 20:37:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013.07.06 16:25:29 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Skyrim
[2013.07.06 16:25:21 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\XRay Engine
[2013.07.06 15:12:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
[2013.07.06 15:06:11 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\All Zombies Must Die!
[2013.07.04 17:13:01 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Nová složka (2)
[2013.07.02 14:47:13 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\SPcommandswe
[2013.06.30 23:09:12 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\WarThunder
[2013.06.30 23:09:12 | 000,000,000 | ---D | C] -- C:\ProgramData\WarThunder
[2013.06.30 23:07:02 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
[2013.06.30 21:03:40 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
[2013.06.29 15:18:02 | 000,000,000 | ---D | C] -- C:\Users\Já\Documents\Stronghold Crusader
[2013.06.27 17:25:53 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\androidromm
[2013.06.27 17:25:10 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\androidrom
[2013.06.23 12:49:51 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\totaln
[2013.06.23 11:47:50 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Chocolate
[2013.06.23 11:38:01 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\modsss
[2013.06.22 10:01:53 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Copy the contents in this folder into your .minecraft folder
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Já\Desktop\PROGRAMY
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,17% Memory free
7,99 Gb Paging File | 6,72 Gb Available in Paging File | 84,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55,88 Gb Total Space | 8,94 Gb Free Space | 16,01% Space Free | Partition Type: NTFS
Drive D: | 875,63 Gb Total Space | 577,72 Gb Free Space | 65,98% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Já | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Já\Desktop\PROGRAMY\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - D:\Programy\Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - D:\Programy\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_MouseDeviceManager.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\Data\X7\Forms\OSD_Text\OSD_Text.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_Wheel4D.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_ZoomControl.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_ScrollbarControl.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInRight.dll ()
MOD - C:\Program Files (x86)\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInOne.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (TunngleService) -- D:\Programy\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Hamachi2Svc) -- D:\Programy\Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (TeamViewer8) -- D:\Programy\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (KMService) -- C:\Windows\SysWOW64\srvany.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (nTuneService) -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
========== Driver Services (SafeList) ==========
DRV:64bit: - (usbUDisc) -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys (Scott)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (pcouffin) -- C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (pneteth) -- C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (LgBttPort) -- C:\Windows\SysNative\drivers\lgbtpt64.sys (LG Electronics Inc.)
DRV:64bit: - (LGVMODEM) -- C:\Windows\SysNative\drivers\lgvmdm64.sys (LG Electronics Inc.)
DRV:64bit: - (lgbusenum) -- C:\Windows\SysNative\drivers\lgbtbs64.sys (LG Electronics Inc.)
DRV:64bit: - (tap0901t) -- C:\Windows\SysNative\drivers\tap0901t.sys (Tunngle.net)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (USBModem) -- C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) -- C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) -- C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NVR0Dev) -- C:\Windows\nvoclk64.sys (NVidia Corp.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz"
FF - prefs.js..extensions.enabledAddons: battlefieldheroespatcher%40ea.com:5.0.203.0
FF - prefs.js..extensions.enabledAddons: donottrackplus%40abine.com:2.2.9.618
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=Quicksearch_16194&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Programy\MSOFFI~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Já\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: D:\Hry\HAWX 2\orbitlauncher\npuplaypc.dll (Ubisoft)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.04.02 17:25:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: D:\Programy\Firefox\components [2013.07.03 09:30:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: D:\Programy\Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: D:\Programy\Firefox\components [2013.07.03 09:30:26 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: D:\Programy\Firefox\plugins
[2012.08.24 23:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Extensions
[2013.07.12 11:21:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions
[2013.05.17 17:40:58 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\battlefieldheroespatcher@ea.com
[2013.07.12 11:21:00 | 000,000,000 | ---D | M] (DoNotTrackMe) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\donottrackplus@abine.com
[2013.06.10 19:21:39 | 000,000,000 | ---D | M] (KMPlayer Toolbar) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
[2013.05.01 12:53:31 | 000,002,055 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\firmycz.xml
[2013.05.01 12:53:30 | 000,002,047 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\mapycz.xml
[2013.05.01 12:53:31 | 000,002,213 | ---- | M] () -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\searchplugins\zbocz.xml
File not found (No name found) -- C:\USERS\Já\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6EJLKD02.DEFAULT\EXTENSIONS\BATTLEFIELDHEROESPATCHER@EA.COM
File not found (No name found) -- C:\USERS\Já\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6EJLKD02.DEFAULT\EXTENSIONS\DONOTTRACKPLUS@ABINE.COM
O1 HOSTS File: ([2013.07.12 11:17:33 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programy\MS Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Pomocná služba pro přihlášení k účtu Microsoft) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.)
O4:64bit: - HKLM..\Run: [BCSSync] D:\Programy\MS Office 2010\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] D:\Programy\Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Programy\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [OscarEditor] C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.99.25.113 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0BB736B4-1894-4BD8-846C-5AE28EBE05CF}: DhcpNameServer = 7.254.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E441F964-0EB1-42B1-B606-4DF7EC813335}: DhcpNameServer = 10.99.25.113 192.168.1.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.05.29 15:40:21 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.13 10:20:41 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.12 23:14:05 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logys
[2013.07.12 23:13:35 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.12 11:10:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.12 11:10:08 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.11 20:28:14 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Adobe
[2013.07.11 19:01:15 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logyyy
[2013.07.10 16:59:13 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.07.10 16:37:08 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logy2
[2013.07.10 14:44:18 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\logy
[2013.07.10 13:52:10 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Malwarebytes
[2013.07.10 13:52:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.10 13:52:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.07.10 13:52:00 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.08 11:15:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.07.08 11:13:37 | 027,781,920 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.07.08 11:13:37 | 021,102,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.07.08 11:13:37 | 007,641,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.07.08 11:13:37 | 006,324,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.07.08 11:13:37 | 000,925,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll
[2013.07.08 11:13:37 | 000,572,704 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
[2013.07.08 11:13:37 | 000,570,656 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
[2013.07.08 11:13:37 | 000,467,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
[2013.07.08 11:13:37 | 000,266,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll
[2013.07.08 11:13:37 | 000,218,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll
[2013.07.08 11:13:37 | 000,214,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll
[2013.07.08 11:13:37 | 000,194,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
[2013.07.08 11:13:37 | 000,181,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll
[2013.07.08 11:13:37 | 000,031,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
[2013.07.08 11:13:36 | 025,256,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.07.08 11:13:36 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.07.08 11:13:36 | 009,239,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.07.08 11:13:36 | 007,687,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.07.08 11:13:36 | 002,953,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.07.08 11:13:36 | 002,777,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.07.08 11:13:36 | 002,363,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.07.08 11:13:36 | 002,002,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.07.08 11:13:36 | 001,832,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432049.dll
[2013.07.08 11:13:36 | 001,511,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432049.dll
[2013.07.08 11:13:36 | 000,465,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
[2013.07.07 12:03:24 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Chromium
[2013.07.07 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Já\Documents\Arktos
[2013.07.06 20:45:49 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2013.07.06 20:37:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013.07.06 16:25:29 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Skyrim
[2013.07.06 16:25:21 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\XRay Engine
[2013.07.06 15:12:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
[2013.07.06 15:06:11 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\All Zombies Must Die!
[2013.07.04 17:13:01 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Nová složka (2)
[2013.07.02 14:47:13 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\SPcommandswe
[2013.06.30 23:09:12 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\WarThunder
[2013.06.30 23:09:12 | 000,000,000 | ---D | C] -- C:\ProgramData\WarThunder
[2013.06.30 23:07:02 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
[2013.06.30 21:03:40 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
[2013.06.29 15:18:02 | 000,000,000 | ---D | C] -- C:\Users\Já\Documents\Stronghold Crusader
[2013.06.27 17:25:53 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\androidromm
[2013.06.27 17:25:10 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\androidrom
[2013.06.23 12:49:51 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\totaln
[2013.06.23 11:47:50 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Chocolate
[2013.06.23 11:38:01 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\modsss
[2013.06.22 10:01:53 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\Copy the contents in this folder into your .minecraft folder
I use Arch BTW
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
[2013.06.22 09:53:09 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\mc
[2013.06.21 05:16:02 | 000,566,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2013.06.18 17:53:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
[2013.06.18 17:52:53 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat
[2013.06.14 16:43:13 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Sony Creative Software Inc
[2013.06.14 16:33:13 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Publish Providers
[2013.06.14 16:14:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2013.06.14 16:12:52 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Sony
[2013.06.14 16:11:23 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\sonyvegas
[2013.06.14 16:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\id Software
[2013.06.14 16:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\id Software
[2013.06.13 15:31:17 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\gfdfghdfg
[2013.01.09 16:56:53 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Já\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2013.07.13 12:20:56 | 000,330,220 | ---- | M] () -- C:\Users\Já\Desktop\qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.png
[2013.07.13 12:19:59 | 000,019,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.13 12:19:59 | 000,019,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.13 12:12:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.13 12:12:25 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.13 10:31:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.12 21:48:52 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.07.12 21:48:52 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.07.12 21:48:21 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.07.12 11:17:33 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.07.12 11:07:09 | 000,336,313 | ---- | M] () -- C:\Users\Já\Desktop\aaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.11 19:02:02 | 000,000,844 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.07.11 19:00:57 | 000,388,992 | ---- | M] () -- C:\Users\Já\Desktop\ooooooooooooooooooooooooooooooooooooooooo.png
[2013.07.10 19:31:11 | 000,234,990 | ---- | M] () -- C:\Users\Já\Desktop\dfaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.10 16:44:16 | 000,241,626 | ---- | M] () -- C:\Users\Já\Desktop\dfagsadfgsdfgsdfgsdffffffffffffffffffffffg.png
[2013.07.09 18:35:24 | 513,490,424 | ---- | M] () -- C:\Users\Já\Desktop\Chlapec-v-pruhovaném-pyžamu--cz-dabing.avi
[2013.07.09 17:45:45 | 001,577,410 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.09 17:45:45 | 000,666,406 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2013.07.09 17:45:45 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.09 17:45:45 | 000,140,102 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2013.07.09 17:45:45 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.06 11:45:48 | 002,121,488 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0332.jpg
[2013.07.05 21:49:17 | 576,580,712 | ---- | M] () -- C:\Users\Já\Desktop\Šmejdi-(2013)-dokument-NOVINKA.avi
[2013.07.05 13:45:26 | 000,000,644 | RHS- | M] () -- C:\Users\Já\ntuser.pol
[2013.07.04 18:18:02 | 003,891,338 | ---- | M] () -- C:\Users\Já\Desktop\wart.png
[2013.07.04 17:02:53 | 000,168,416 | ---- | M] () -- C:\Users\Já\Desktop\49369bv.jpg
[2013.07.02 15:17:38 | 000,264,400 | ---- | M] () -- C:\Users\Já\Desktop\93036gv.jpg
[2013.07.01 18:22:13 | 000,101,594 | ---- | M] () -- C:\Users\Já\Desktop\oie_118513NARBu6ee.gif
[2013.07.01 17:49:42 | 000,104,725 | ---- | M] () -- C:\Users\Já\Desktop\homam-tryglodyt.gif
[2013.06.30 19:45:08 | 000,112,111 | ---- | M] () -- C:\Users\Já\Desktop\Bez názvu.jpg
[2013.06.28 21:12:44 | 007,473,242 | R--- | M] () -- C:\Users\Já\Desktop\px-cwm-v2.zip
[2013.06.27 17:23:18 | 159,072,730 | ---- | M] () -- C:\Users\Já\Desktop\rc19.zip
[2013.06.27 17:17:28 | 005,093,376 | ---- | M] () -- C:\Users\Já\Desktop\boot.img
[2013.06.23 11:48:31 | 000,903,979 | ---- | M] () -- C:\Users\Já\Desktop\BetterDungeons.zip
[2013.06.23 11:47:16 | 002,158,701 | ---- | M] () -- C:\Users\Já\Desktop\Chocolate.7z
[2013.06.21 14:06:36 | 027,781,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.06.21 14:06:36 | 025,256,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.06.21 14:06:36 | 021,102,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.06.21 14:06:36 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.06.21 14:06:36 | 015,920,536 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2013.06.21 14:06:36 | 015,144,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2013.06.21 14:06:36 | 013,411,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2013.06.21 14:06:36 | 012,427,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2013.06.21 14:06:36 | 009,239,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.06.21 14:06:36 | 007,687,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.06.21 14:06:36 | 007,641,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.06.21 14:06:36 | 006,324,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.06.21 14:06:36 | 002,953,504 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.06.21 14:06:36 | 002,936,208 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2013.06.21 14:06:36 | 002,777,888 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.06.21 14:06:36 | 002,597,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2013.06.21 14:06:36 | 002,363,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.06.21 14:06:36 | 002,002,720 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.06.21 14:06:36 | 001,832,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432049.dll
[2013.06.21 14:06:36 | 001,511,712 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432049.dll
[2013.06.21 14:06:36 | 001,059,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll
[2013.06.21 14:06:36 | 000,925,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll
[2013.06.21 14:06:36 | 000,572,704 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
[2013.06.21 14:06:36 | 000,570,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
[2013.06.21 14:06:36 | 000,467,232 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
[2013.06.21 14:06:36 | 000,465,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
[2013.06.21 14:06:36 | 000,266,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll
[2013.06.21 14:06:36 | 000,218,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll
[2013.06.21 14:06:36 | 000,214,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll
[2013.06.21 14:06:36 | 000,181,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll
[2013.06.21 14:06:36 | 000,021,578 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2013.06.21 12:23:16 | 006,496,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2013.06.21 12:23:16 | 003,514,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2013.06.21 12:23:10 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2013.06.21 12:23:10 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2013.06.21 12:23:10 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2013.06.21 05:16:02 | 000,566,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2013.06.20 18:56:34 | 001,327,018 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0316.jpg
[2013.06.20 15:54:08 | 002,085,060 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0315.jpg
[2013.06.20 15:53:14 | 001,660,988 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0314.jpg
[2013.06.20 13:55:38 | 001,807,557 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0313.jpg
[2013.06.20 13:52:18 | 001,386,598 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0312.jpg
[2013.06.20 13:52:10 | 001,608,771 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0311.jpg
[2013.06.20 06:17:49 | 003,253,909 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin
[2013.06.19 16:37:53 | 000,003,944 | ---- | M] () -- C:\Users\Já\Desktop\pht.png
[2013.06.18 19:04:49 | 000,006,581 | ---- | M] () -- C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
[2013.06.15 11:32:31 | 000,925,176 | ---- | M] () -- C:\Users\Já\Desktop\Bez názvu.png
[2013.06.14 17:04:51 | 009,148,408 | ---- | M] () -- C:\Users\Já\Documents\Untitled.m2v
[2013.06.14 17:04:51 | 000,000,182 | ---- | M] () -- C:\Users\Já\Documents\Untitled.m2v.sfl
[2013.06.13 15:35:24 | 013,996,932 | ---- | M] () -- C:\Users\Já\Desktop\absdhfmbsdasdasg.zip
========== Files Created - No Company Name ==========
[2013.07.13 12:20:56 | 000,330,220 | ---- | C] () -- C:\Users\Já\Desktop\qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.png
[2013.07.12 11:07:09 | 000,336,313 | ---- | C] () -- C:\Users\Já\Desktop\aaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.11 19:00:57 | 000,388,992 | ---- | C] () -- C:\Users\Já\Desktop\ooooooooooooooooooooooooooooooooooooooooo.png
[2013.07.10 19:31:11 | 000,234,990 | ---- | C] () -- C:\Users\Já\Desktop\dfaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.10 16:44:16 | 000,241,626 | ---- | C] () -- C:\Users\Já\Desktop\dfagsadfgsdfgsdfgsdffffffffffffffffffffffg.png
[2013.07.10 16:32:36 | 000,000,844 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.07.09 18:35:37 | 513,490,424 | ---- | C] () -- C:\Users\Já\Desktop\Chlapec-v-pruhovaném-pyžamu--cz-dabing.avi
[2013.07.06 11:50:12 | 002,121,488 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0332.jpg
[2013.07.05 21:50:53 | 576,580,712 | ---- | C] () -- C:\Users\Já\Desktop\Šmejdi-(2013)-dokument-NOVINKA.avi
[2013.07.04 18:18:02 | 003,891,338 | ---- | C] () -- C:\Users\Já\Desktop\wart.png
[2013.07.04 17:02:51 | 000,168,416 | ---- | C] () -- C:\Users\Já\Desktop\49369bv.jpg
[2013.07.02 15:17:37 | 000,264,400 | ---- | C] () -- C:\Users\Já\Desktop\93036gv.jpg
[2013.07.02 15:04:56 | 000,828,135 | ---- | C] () -- C:\Users\Já\Desktop\WorldEdit.jar
[2013.07.01 18:22:24 | 000,101,594 | ---- | C] () -- C:\Users\Já\Desktop\oie_118513NARBu6ee.gif
[2013.07.01 17:49:42 | 000,104,725 | ---- | C] () -- C:\Users\Já\Desktop\homam-tryglodyt.gif
[2013.06.30 19:45:08 | 000,112,111 | ---- | C] () -- C:\Users\Já\Desktop\Bez názvu.jpg
[2013.06.28 21:16:35 | 007,473,242 | R--- | C] () -- C:\Users\Já\Desktop\px-cwm-v2.zip
[2013.06.27 17:23:33 | 159,072,730 | ---- | C] () -- C:\Users\Já\Desktop\rc19.zip
[2013.06.27 17:17:48 | 005,093,376 | ---- | C] () -- C:\Users\Já\Desktop\boot.img
[2013.06.23 11:48:15 | 000,903,979 | ---- | C] () -- C:\Users\Já\Desktop\BetterDungeons.zip
[2013.06.23 11:46:56 | 002,158,701 | ---- | C] () -- C:\Users\Já\Desktop\Chocolate.7z
[2013.06.22 23:30:12 | 003,763,119 | ---- | C] () -- C:\Users\Já\Desktop\NITRO CIRCUS.fc3map
[2013.06.22 23:29:14 | 004,088,466 | ---- | C] () -- C:\Users\Já\Desktop\FULL DIRT.fc3map
[2013.06.20 18:58:20 | 002,085,060 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0315.jpg
[2013.06.20 18:58:20 | 001,807,557 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0313.jpg
[2013.06.20 18:58:20 | 001,660,988 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0314.jpg
[2013.06.20 18:58:20 | 001,608,771 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0311.jpg
[2013.06.20 18:58:20 | 001,386,598 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0312.jpg
[2013.06.20 18:58:20 | 001,327,018 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0316.jpg
[2013.06.19 16:37:53 | 000,003,944 | ---- | C] () -- C:\Users\Já\Desktop\pht.png
[2013.06.18 19:50:34 | 000,000,644 | RHS- | C] () -- C:\Users\Já\ntuser.pol
[2013.06.18 19:04:38 | 000,006,581 | ---- | C] () -- C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
[2013.06.15 11:32:31 | 000,925,176 | ---- | C] () -- C:\Users\Já\Desktop\Bez názvu.png
[2013.06.14 17:04:51 | 000,000,182 | ---- | C] () -- C:\Users\Já\Documents\Untitled.m2v.sfl
[2013.06.14 17:04:37 | 009,148,408 | ---- | C] () -- C:\Users\Já\Documents\Untitled.m2v
[2013.06.13 15:35:23 | 013,996,932 | ---- | C] () -- C:\Users\Já\Desktop\absdhfmbsdasdasg.zip
[2013.06.10 17:34:41 | 000,721,917 | ---- | C] () -- C:\Windows\SysWow64\AiCM64.dll
[2013.06.10 17:34:41 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\AiCM32.dll
[2013.05.21 19:15:52 | 000,000,017 | ---- | C] () -- C:\Users\Já\AppData\Local\resmon.resmoncfg
[2013.04.20 15:44:06 | 000,000,853 | ---- | C] () -- C:\Users\Já\AppData\Local\recently-used.xbel
[2013.04.12 21:33:07 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2013.04.12 21:33:07 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2013.03.15 18:15:35 | 000,682,280 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.01.09 16:59:07 | 000,001,189 | ---- | C] () -- C:\Users\Já\AppData\Roaming\vso_ts_preview.xml
[2013.01.09 16:56:53 | 000,099,384 | ---- | C] () -- C:\Users\Já\AppData\Roaming\inst.exe
[2013.01.09 16:56:53 | 000,007,859 | ---- | C] () -- C:\Users\Já\AppData\Roaming\pcouffin.cat
[2013.01.09 16:56:53 | 000,001,167 | ---- | C] () -- C:\Users\Já\AppData\Roaming\pcouffin.inf
[2012.12.30 13:40:26 | 000,581,642 | ---- | C] () -- C:\Users\Já\AppData\Roaming\technic-launcher.jar
[2012.12.11 15:24:55 | 000,000,021 | ---- | C] () -- C:\Users\Já\AppData\Roaming\ISOWorkshop.ini
[2012.11.23 17:54:17 | 000,000,701 | ---- | C] () -- C:\Windows\eReg.dat
[2012.11.10 14:38:57 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2012.10.10 18:29:33 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2012.09.15 14:09:56 | 001,555,696 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.08.19 18:17:32 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2012.08.17 21:03:27 | 000,000,384 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.08.16 11:51:25 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.08.16 11:51:22 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.08.16 11:51:19 | 000,000,290 | ---- | C] () -- C:\Windows\game.ini
[2012.08.15 15:29:23 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 03:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 03:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.07.10 21:05:57 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\.minecraft
[2012.12.30 13:40:56 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\.techniclauncher
[2013.06.10 17:40:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Aimersoft Video Converter Ultimate
[2013.06.10 18:10:41 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Audacity
[2013.06.01 15:24:54 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Autodesk
[2013.07.10 14:39:56 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\DAEMON Tools Lite
[2013.05.23 18:29:19 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\InfraRecorder
[2013.05.16 14:58:29 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\JonDo
[2012.09.15 13:39:53 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Leadertech
[2012.12.30 13:40:24 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\logs
[2013.05.26 08:01:44 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\LolClient
[2013.06.08 20:15:30 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\MAXON
[2013.02.18 16:44:20 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\mightypocket
[2012.10.12 22:06:15 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\mkvtoolnix
[2013.03.13 19:04:35 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Need for Speed World
[2013.03.03 15:06:25 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\NetBeans
[2013.03.22 18:29:35 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\OCS
[2013.04.16 19:49:17 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Opera
[2013.06.14 16:33:13 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Publish Providers
[2013.05.01 13:02:03 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Seznam.cz
[2013.06.14 16:47:17 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Sony
[2013.06.14 16:43:13 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Sony Creative Software Inc
[2013.02.14 18:25:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\TeamViewer
[2013.02.24 16:57:33 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\TS3Client
[2013.07.06 15:57:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Tunngle
[2013.04.15 18:13:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Unity
[2013.07.13 12:21:55 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\uTorrent
[2013.03.12 20:21:32 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Vso
[2012.09.17 19:12:51 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\wargaming.net
[2013.07.06 16:25:21 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\XRay Engine
[2013.06.10 17:15:50 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:A1EDB939
< End of report >
[2013.06.21 05:16:02 | 000,566,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2013.06.18 17:53:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
[2013.06.18 17:52:53 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat
[2013.06.14 16:43:13 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Sony Creative Software Inc
[2013.06.14 16:33:13 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Publish Providers
[2013.06.14 16:14:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Local\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2013.06.14 16:14:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2013.06.14 16:12:52 | 000,000,000 | ---D | C] -- C:\Users\Já\AppData\Roaming\Sony
[2013.06.14 16:11:23 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\sonyvegas
[2013.06.14 16:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\id Software
[2013.06.14 16:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\id Software
[2013.06.13 15:31:17 | 000,000,000 | ---D | C] -- C:\Users\Já\Desktop\gfdfghdfg
[2013.01.09 16:56:53 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Já\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2013.07.13 12:20:56 | 000,330,220 | ---- | M] () -- C:\Users\Já\Desktop\qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.png
[2013.07.13 12:19:59 | 000,019,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.13 12:19:59 | 000,019,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.13 12:12:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.13 12:12:25 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.13 10:31:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.12 21:48:52 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.07.12 21:48:52 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.07.12 21:48:21 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.07.12 11:17:33 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.07.12 11:07:09 | 000,336,313 | ---- | M] () -- C:\Users\Já\Desktop\aaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.11 19:02:02 | 000,000,844 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.07.11 19:00:57 | 000,388,992 | ---- | M] () -- C:\Users\Já\Desktop\ooooooooooooooooooooooooooooooooooooooooo.png
[2013.07.10 19:31:11 | 000,234,990 | ---- | M] () -- C:\Users\Já\Desktop\dfaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.10 16:44:16 | 000,241,626 | ---- | M] () -- C:\Users\Já\Desktop\dfagsadfgsdfgsdfgsdffffffffffffffffffffffg.png
[2013.07.09 18:35:24 | 513,490,424 | ---- | M] () -- C:\Users\Já\Desktop\Chlapec-v-pruhovaném-pyžamu--cz-dabing.avi
[2013.07.09 17:45:45 | 001,577,410 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.09 17:45:45 | 000,666,406 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2013.07.09 17:45:45 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.09 17:45:45 | 000,140,102 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2013.07.09 17:45:45 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.06 11:45:48 | 002,121,488 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0332.jpg
[2013.07.05 21:49:17 | 576,580,712 | ---- | M] () -- C:\Users\Já\Desktop\Šmejdi-(2013)-dokument-NOVINKA.avi
[2013.07.05 13:45:26 | 000,000,644 | RHS- | M] () -- C:\Users\Já\ntuser.pol
[2013.07.04 18:18:02 | 003,891,338 | ---- | M] () -- C:\Users\Já\Desktop\wart.png
[2013.07.04 17:02:53 | 000,168,416 | ---- | M] () -- C:\Users\Já\Desktop\49369bv.jpg
[2013.07.02 15:17:38 | 000,264,400 | ---- | M] () -- C:\Users\Já\Desktop\93036gv.jpg
[2013.07.01 18:22:13 | 000,101,594 | ---- | M] () -- C:\Users\Já\Desktop\oie_118513NARBu6ee.gif
[2013.07.01 17:49:42 | 000,104,725 | ---- | M] () -- C:\Users\Já\Desktop\homam-tryglodyt.gif
[2013.06.30 19:45:08 | 000,112,111 | ---- | M] () -- C:\Users\Já\Desktop\Bez názvu.jpg
[2013.06.28 21:12:44 | 007,473,242 | R--- | M] () -- C:\Users\Já\Desktop\px-cwm-v2.zip
[2013.06.27 17:23:18 | 159,072,730 | ---- | M] () -- C:\Users\Já\Desktop\rc19.zip
[2013.06.27 17:17:28 | 005,093,376 | ---- | M] () -- C:\Users\Já\Desktop\boot.img
[2013.06.23 11:48:31 | 000,903,979 | ---- | M] () -- C:\Users\Já\Desktop\BetterDungeons.zip
[2013.06.23 11:47:16 | 002,158,701 | ---- | M] () -- C:\Users\Já\Desktop\Chocolate.7z
[2013.06.21 14:06:36 | 027,781,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.06.21 14:06:36 | 025,256,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.06.21 14:06:36 | 021,102,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.06.21 14:06:36 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.06.21 14:06:36 | 015,920,536 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2013.06.21 14:06:36 | 015,144,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2013.06.21 14:06:36 | 013,411,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2013.06.21 14:06:36 | 012,427,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2013.06.21 14:06:36 | 009,239,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.06.21 14:06:36 | 007,687,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.06.21 14:06:36 | 007,641,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.06.21 14:06:36 | 006,324,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.06.21 14:06:36 | 002,953,504 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.06.21 14:06:36 | 002,936,208 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2013.06.21 14:06:36 | 002,777,888 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.06.21 14:06:36 | 002,597,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2013.06.21 14:06:36 | 002,363,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.06.21 14:06:36 | 002,002,720 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.06.21 14:06:36 | 001,832,224 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432049.dll
[2013.06.21 14:06:36 | 001,511,712 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432049.dll
[2013.06.21 14:06:36 | 001,059,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll
[2013.06.21 14:06:36 | 000,925,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll
[2013.06.21 14:06:36 | 000,572,704 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
[2013.06.21 14:06:36 | 000,570,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
[2013.06.21 14:06:36 | 000,467,232 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
[2013.06.21 14:06:36 | 000,465,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
[2013.06.21 14:06:36 | 000,266,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll
[2013.06.21 14:06:36 | 000,218,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll
[2013.06.21 14:06:36 | 000,214,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll
[2013.06.21 14:06:36 | 000,181,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll
[2013.06.21 14:06:36 | 000,021,578 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2013.06.21 12:23:16 | 006,496,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2013.06.21 12:23:16 | 003,514,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2013.06.21 12:23:10 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2013.06.21 12:23:10 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2013.06.21 12:23:10 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2013.06.21 05:16:02 | 000,566,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2013.06.20 18:56:34 | 001,327,018 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0316.jpg
[2013.06.20 15:54:08 | 002,085,060 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0315.jpg
[2013.06.20 15:53:14 | 001,660,988 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0314.jpg
[2013.06.20 13:55:38 | 001,807,557 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0313.jpg
[2013.06.20 13:52:18 | 001,386,598 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0312.jpg
[2013.06.20 13:52:10 | 001,608,771 | ---- | M] () -- C:\Users\Já\Desktop\Fotografie-0311.jpg
[2013.06.20 06:17:49 | 003,253,909 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin
[2013.06.19 16:37:53 | 000,003,944 | ---- | M] () -- C:\Users\Já\Desktop\pht.png
[2013.06.18 19:04:49 | 000,006,581 | ---- | M] () -- C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
[2013.06.15 11:32:31 | 000,925,176 | ---- | M] () -- C:\Users\Já\Desktop\Bez názvu.png
[2013.06.14 17:04:51 | 009,148,408 | ---- | M] () -- C:\Users\Já\Documents\Untitled.m2v
[2013.06.14 17:04:51 | 000,000,182 | ---- | M] () -- C:\Users\Já\Documents\Untitled.m2v.sfl
[2013.06.13 15:35:24 | 013,996,932 | ---- | M] () -- C:\Users\Já\Desktop\absdhfmbsdasdasg.zip
========== Files Created - No Company Name ==========
[2013.07.13 12:20:56 | 000,330,220 | ---- | C] () -- C:\Users\Já\Desktop\qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.png
[2013.07.12 11:07:09 | 000,336,313 | ---- | C] () -- C:\Users\Já\Desktop\aaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.11 19:00:57 | 000,388,992 | ---- | C] () -- C:\Users\Já\Desktop\ooooooooooooooooooooooooooooooooooooooooo.png
[2013.07.10 19:31:11 | 000,234,990 | ---- | C] () -- C:\Users\Já\Desktop\dfaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.png
[2013.07.10 16:44:16 | 000,241,626 | ---- | C] () -- C:\Users\Já\Desktop\dfagsadfgsdfgsdfgsdffffffffffffffffffffffg.png
[2013.07.10 16:32:36 | 000,000,844 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.07.09 18:35:37 | 513,490,424 | ---- | C] () -- C:\Users\Já\Desktop\Chlapec-v-pruhovaném-pyžamu--cz-dabing.avi
[2013.07.06 11:50:12 | 002,121,488 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0332.jpg
[2013.07.05 21:50:53 | 576,580,712 | ---- | C] () -- C:\Users\Já\Desktop\Šmejdi-(2013)-dokument-NOVINKA.avi
[2013.07.04 18:18:02 | 003,891,338 | ---- | C] () -- C:\Users\Já\Desktop\wart.png
[2013.07.04 17:02:51 | 000,168,416 | ---- | C] () -- C:\Users\Já\Desktop\49369bv.jpg
[2013.07.02 15:17:37 | 000,264,400 | ---- | C] () -- C:\Users\Já\Desktop\93036gv.jpg
[2013.07.02 15:04:56 | 000,828,135 | ---- | C] () -- C:\Users\Já\Desktop\WorldEdit.jar
[2013.07.01 18:22:24 | 000,101,594 | ---- | C] () -- C:\Users\Já\Desktop\oie_118513NARBu6ee.gif
[2013.07.01 17:49:42 | 000,104,725 | ---- | C] () -- C:\Users\Já\Desktop\homam-tryglodyt.gif
[2013.06.30 19:45:08 | 000,112,111 | ---- | C] () -- C:\Users\Já\Desktop\Bez názvu.jpg
[2013.06.28 21:16:35 | 007,473,242 | R--- | C] () -- C:\Users\Já\Desktop\px-cwm-v2.zip
[2013.06.27 17:23:33 | 159,072,730 | ---- | C] () -- C:\Users\Já\Desktop\rc19.zip
[2013.06.27 17:17:48 | 005,093,376 | ---- | C] () -- C:\Users\Já\Desktop\boot.img
[2013.06.23 11:48:15 | 000,903,979 | ---- | C] () -- C:\Users\Já\Desktop\BetterDungeons.zip
[2013.06.23 11:46:56 | 002,158,701 | ---- | C] () -- C:\Users\Já\Desktop\Chocolate.7z
[2013.06.22 23:30:12 | 003,763,119 | ---- | C] () -- C:\Users\Já\Desktop\NITRO CIRCUS.fc3map
[2013.06.22 23:29:14 | 004,088,466 | ---- | C] () -- C:\Users\Já\Desktop\FULL DIRT.fc3map
[2013.06.20 18:58:20 | 002,085,060 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0315.jpg
[2013.06.20 18:58:20 | 001,807,557 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0313.jpg
[2013.06.20 18:58:20 | 001,660,988 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0314.jpg
[2013.06.20 18:58:20 | 001,608,771 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0311.jpg
[2013.06.20 18:58:20 | 001,386,598 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0312.jpg
[2013.06.20 18:58:20 | 001,327,018 | ---- | C] () -- C:\Users\Já\Desktop\Fotografie-0316.jpg
[2013.06.19 16:37:53 | 000,003,944 | ---- | C] () -- C:\Users\Já\Desktop\pht.png
[2013.06.18 19:50:34 | 000,000,644 | RHS- | C] () -- C:\Users\Já\ntuser.pol
[2013.06.18 19:04:38 | 000,006,581 | ---- | C] () -- C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
[2013.06.15 11:32:31 | 000,925,176 | ---- | C] () -- C:\Users\Já\Desktop\Bez názvu.png
[2013.06.14 17:04:51 | 000,000,182 | ---- | C] () -- C:\Users\Já\Documents\Untitled.m2v.sfl
[2013.06.14 17:04:37 | 009,148,408 | ---- | C] () -- C:\Users\Já\Documents\Untitled.m2v
[2013.06.13 15:35:23 | 013,996,932 | ---- | C] () -- C:\Users\Já\Desktop\absdhfmbsdasdasg.zip
[2013.06.10 17:34:41 | 000,721,917 | ---- | C] () -- C:\Windows\SysWow64\AiCM64.dll
[2013.06.10 17:34:41 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\AiCM32.dll
[2013.05.21 19:15:52 | 000,000,017 | ---- | C] () -- C:\Users\Já\AppData\Local\resmon.resmoncfg
[2013.04.20 15:44:06 | 000,000,853 | ---- | C] () -- C:\Users\Já\AppData\Local\recently-used.xbel
[2013.04.12 21:33:07 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2013.04.12 21:33:07 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2013.03.15 18:15:35 | 000,682,280 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.01.09 16:59:07 | 000,001,189 | ---- | C] () -- C:\Users\Já\AppData\Roaming\vso_ts_preview.xml
[2013.01.09 16:56:53 | 000,099,384 | ---- | C] () -- C:\Users\Já\AppData\Roaming\inst.exe
[2013.01.09 16:56:53 | 000,007,859 | ---- | C] () -- C:\Users\Já\AppData\Roaming\pcouffin.cat
[2013.01.09 16:56:53 | 000,001,167 | ---- | C] () -- C:\Users\Já\AppData\Roaming\pcouffin.inf
[2012.12.30 13:40:26 | 000,581,642 | ---- | C] () -- C:\Users\Já\AppData\Roaming\technic-launcher.jar
[2012.12.11 15:24:55 | 000,000,021 | ---- | C] () -- C:\Users\Já\AppData\Roaming\ISOWorkshop.ini
[2012.11.23 17:54:17 | 000,000,701 | ---- | C] () -- C:\Windows\eReg.dat
[2012.11.10 14:38:57 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2012.10.10 18:29:33 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2012.09.15 14:09:56 | 001,555,696 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.08.19 18:17:32 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2012.08.17 21:03:27 | 000,000,384 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.08.16 11:51:25 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.08.16 11:51:22 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.08.16 11:51:19 | 000,000,290 | ---- | C] () -- C:\Windows\game.ini
[2012.08.15 15:29:23 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 03:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 03:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.07.10 21:05:57 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\.minecraft
[2012.12.30 13:40:56 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\.techniclauncher
[2013.06.10 17:40:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Aimersoft Video Converter Ultimate
[2013.06.10 18:10:41 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Audacity
[2013.06.01 15:24:54 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Autodesk
[2013.07.10 14:39:56 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\DAEMON Tools Lite
[2013.05.23 18:29:19 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\InfraRecorder
[2013.05.16 14:58:29 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\JonDo
[2012.09.15 13:39:53 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Leadertech
[2012.12.30 13:40:24 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\logs
[2013.05.26 08:01:44 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\LolClient
[2013.06.08 20:15:30 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\MAXON
[2013.02.18 16:44:20 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\mightypocket
[2012.10.12 22:06:15 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\mkvtoolnix
[2013.03.13 19:04:35 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Need for Speed World
[2013.03.03 15:06:25 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\NetBeans
[2013.03.22 18:29:35 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\OCS
[2013.04.16 19:49:17 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Opera
[2013.06.14 16:33:13 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Publish Providers
[2013.05.01 13:02:03 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Seznam.cz
[2013.06.14 16:47:17 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Sony
[2013.06.14 16:43:13 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Sony Creative Software Inc
[2013.02.14 18:25:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\TeamViewer
[2013.02.24 16:57:33 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\TS3Client
[2013.07.06 15:57:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Tunngle
[2013.04.15 18:13:12 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Unity
[2013.07.13 12:21:55 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\uTorrent
[2013.03.12 20:21:32 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\Vso
[2012.09.17 19:12:51 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\wargaming.net
[2013.07.06 16:25:21 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\XRay Engine
[2013.06.10 17:15:50 | 000,000,000 | ---D | M] -- C:\Users\Já\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:A1EDB939
< End of report >
I use Arch BTW
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
OTL Extras logfile created on: 13.7.2013 12:23:47 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Já\Desktop\PROGRAMY
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,17% Memory free
7,99 Gb Paging File | 6,72 Gb Available in Paging File | 84,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55,88 Gb Total Space | 8,94 Gb Free Space | 16,01% Space Free | Partition Type: NTFS
Drive D: | 875,63 Gb Total Space | 577,72 Gb Free Space | 65,98% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Já | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Programy\Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Programy\MS Office 2010\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Programy\MS Office 2010\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{059A37D4-4486-4EE9-87AA-F3E5AD671C30}" = lport=8090 | protocol=6 | dir=in | name=war thunder |
"{07A58854-0C10-479D-A4B4-2459D8036B3E}" = lport=56889 | protocol=6 | dir=in | name=pando media booster |
"{174B15AB-0E8A-401B-B9B7-B95237660182}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{186E246B-625E-4423-9823-8494FE73333A}" = lport=56889 | protocol=17 | dir=in | name=pando media booster |
"{191F290B-41DE-4D61-A67A-29631C5DA316}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{19781F16-59A4-4B95-AF76-E4F31B786F6C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{1CDF2DBC-57FF-4A87-9ECD-D59F0C3D8C66}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1E95E256-0BD6-406B-9E2F-DBF7D08586E2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{201135C4-17B2-4B70-BF78-E8187BBF0858}" = lport=2869 | protocol=6 | dir=in | app=system |
"{27BD663A-8355-4A18-8FA7-93B0902EDD1D}" = lport=56889 | protocol=6 | dir=in | name=pando media booster |
"{2DC4B6E7-5834-4E9C-8C80-619FF8896B4E}" = lport=27022 | protocol=6 | dir=in | name=war thunder |
"{31E42FF7-FDD8-4B4D-92B7-2E1F65EFE2E3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{44B30A00-ABF6-4EA0-B800-8A4671C9E1B1}" = lport=3478 | protocol=17 | dir=in | name=war thunder |
"{474F47D3-884D-4113-BC2F-268DE2FE834E}" = lport=20443 | protocol=6 | dir=in | name=war thunder |
"{61BC601F-4DE2-4EE9-A8CB-6B22B042F4B6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7886314F-C1D6-43A8-A3FF-3824D4EF6AFF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{84159C6E-7CB7-4957-9337-F99748214FF0}" = lport=6881 | protocol=6 | dir=in | name=war thunder |
"{9ADB9A53-7F4B-4B72-9B00-BACCADA97D10}" = lport=20010 | protocol=17 | dir=in | name=war thunder |
"{AA732939-FE92-4E04-9AA4-AD79E34C8F76}" = lport=80 | protocol=6 | dir=in | name=war thunder |
"{ADE3267F-862F-4009-BC89-0F041BED4FF4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BBCC64A7-A91D-4898-A53F-6C51503F3ECD}" = lport=33333 | protocol=6 | dir=in | name=war thunder |
"{C2C700A7-A081-4728-A6D1-F4E2C95DDAEB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C2D55B00-6EDE-4672-A90D-3C610298519B}" = lport=56889 | protocol=17 | dir=in | name=pando media booster |
"{C62079C8-EC23-4EC7-824E-E31890317948}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CBEF320E-2169-4FF6-ABEB-070B55667392}" = lport=7850 | protocol=6 | dir=in | name=war thunder |
"{D58EEA1D-7C6B-4EC7-9972-29FD9CD2300E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DE3A953B-B58B-49FC-825D-64BABD17F38B}" = lport=443 | protocol=6 | dir=in | name=war thunder |
"{F7D35F11-1366-4E75-A6E1-819B0FE23634}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F742DD-1E35-4358-877E-5F9ED2D9A5FB}" = protocol=58 | dir=in | app=system |
"{03837A36-24C1-4820-B027-7923AB99D9D0}" = protocol=6 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{054B1BB6-FB70-4346-B050-35C774EB3E1B}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\farcry3_d3d11.exe |
"{08C0D8B6-552F-4607-B607-B7ACD42A1820}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\fc3editor.exe |
"{0ACF4E29-FED2-4AD2-8399-BEA9FD31E485}" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwawmp.exe |
"{0AED8745-063F-40A3-B052-80EDC3A18547}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0C3696DA-F126-4C62-88C8-1ED7BB8AD494}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0DDD0EC7-E841-489F-B630-18CC94EE7086}" = protocol=6 | dir=in | app=d:\programy\tunngle\tnglctrl.exe |
"{0FFBCB24-1DB8-4EA0-A364-4DB36D9199ED}" = protocol=17 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{1F9E1830-B75B-4F16-97C0-C0FC41AB4DF3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{241B0AF9-1BB1-4F9B-8DAC-604440DA5AD1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{24A296A4-7596-4E2A-B6DA-5E42798AFF94}" = protocol=17 | dir=in | app=d:\programy\steam\steam.exe |
"{25E4B556-5DA9-45E4-83DE-B28215AC1513}" = protocol=6 | dir=in | app=d:\hry\apache air assault\launcher.exe |
"{2A43910F-2DC2-428E-9588-B724B98DEE55}" = protocol=6 | dir=in | app=d:\hry\bfme 2\game.dat |
"{2A6BAC8B-619E-440B-A920-22306AC49E76}" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwaw.exe |
"{2EC1B8F5-0C16-48AC-BD8E-A9B3B1833C3D}" = protocol=6 | dir=in | app=d:\programy\version8\teamviewer_service.exe |
"{3123E988-7B82-429C-A6EA-AA9D473DD6BC}" = protocol=17 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"{317EEDD2-700A-4E99-AFFA-8EFD87DFADD0}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{326CD0C6-67B8-4A38-BE61-3BA189A32342}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{35580B4F-8542-4650-ACCE-E27DB9A78D44}" = protocol=17 | dir=in | app=d:\programy\version8\teamviewer_service.exe |
"{385A23F3-987D-4616-803F-A36DD59E19C1}" = protocol=17 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"{419ECE60-7278-4769-A94C-620680872C90}" = protocol=17 | dir=in | app=d:\programy\tunngle\tunngle.exe |
"{4BFBE2F7-3DAB-4FCE-BEF5-537254952A6C}" = protocol=17 | dir=in | app=d:\programy\steam\steam.exe |
"{4E7C0991-24CD-4757-B5FD-37FD21AF5B1A}" = protocol=6 | dir=in | app=d:\programy\steam\steam.exe |
"{5D66A307-2A44-4A0D-B801-C5AD5F8ACE22}" = protocol=6 | dir=in | app=d:\programy\version8\teamviewer.exe |
"{60B5F2B0-804B-4148-BEF4-D6B33C9DAC8A}" = protocol=6 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe |
"{61DEA71C-8292-41AC-AE84-224B6B72E8A7}" = protocol=6 | dir=in | app=d:\hry\war thunder\launcher.exe |
"{625C5BD1-6B59-4FA1-B191-FB1D9CC21312}" = protocol=6 | dir=in | app=d:\hry\battlefield 2\bf2.exe |
"{645F6ED9-5179-4B91-9044-A395B005ED95}" = protocol=17 | dir=in | app=d:\hry\the battle for middle-earth ii\game.dat |
"{65880108-D8F0-4434-8201-299C2E779F4A}" = protocol=17 | dir=in | app=d:\programy\version8\teamviewer.exe |
"{6729CEEC-830B-4D76-A9C3-391721229415}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\fc3updater.exe |
"{68ADE188-F584-4EE1-A7A4-B12FC616DC3A}" = protocol=6 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"{6CAD2638-72D0-4742-8F89-EADE912E4D93}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D53B554-8D9B-4EA0-91D8-793812A12697}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{73B95841-00AF-4600-A07E-DA80AAFF33EA}" = protocol=6 | dir=in | app=d:\programy\utorrent\utorrent.exe |
"{75119316-B6C3-4599-92C3-B55134E62566}" = protocol=6 | dir=out | app=system |
"{75E61068-684D-4B18-A1CA-20C8B65E2EE1}" = protocol=6 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe |
"{7B2CE005-074D-4B4D-B93D-DB990D947C11}" = protocol=17 | dir=in | app=d:\programy\tunngle\tnglctrl.exe |
"{7DF02985-E613-4C61-8EAF-147150B4E11C}" = protocol=17 | dir=in | app=d:\hry\apache air assault\yuplay\yuplay.exe |
"{80E1C7E5-4CCD-4DFD-A1D5-47630D9CCA27}" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwaw.exe |
"{8347FC48-B6CE-497C-B682-AA0610DD463F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{847A9C5C-BC43-4478-ADF9-3D7C20BED20D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{860072C2-A1EF-4EE7-B1AA-B749FC0D496F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8AE7418F-7A44-4693-9208-EE552F6F9043}" = protocol=17 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"{8BE4D55F-C8FF-486B-9C75-A9B9C8180C76}" = protocol=6 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"{8CDBCC2F-3486-4272-AC71-C5BC4C72168C}" = protocol=17 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{8F551603-7F9D-4FAC-A6BC-743D832D7134}" = protocol=17 | dir=in | app=d:\programy\utorrent\utorrent.exe |
"{93FCC37E-3F5C-4710-BA45-10B976D6350B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{942F160C-0161-4AFC-AE7C-533494334F35}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{94CB5EF6-A67C-4811-912D-AC2A2B1031A3}" = protocol=6 | dir=in | app=d:\hry\apache air assault\yuplay\yuplay.exe |
"{9549A25E-6F66-4E54-9989-0E7332142EBE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{96F35C06-8383-4152-8DB9-21E47E86E414}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{978F36B8-B4CA-4CFC-86C6-7F8BFE12B54F}" = protocol=17 | dir=in | app=d:\hry\bfme 2\game.dat |
"{97936A49-8B93-4740-BCC2-F0633A9BC74B}" = protocol=17 | dir=in | app=d:\hry\battlefield 2\bf2.exe |
"{97BAB3E1-C805-489C-8E42-E6C69DE630EA}" = protocol=17 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe |
"{99017A49-0588-4AF2-89B2-1898816B6666}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9A6266D4-F17B-46E6-8E8F-F3ACEE992C43}" = protocol=17 | dir=in | app=d:\hry\steam\steamapps\common\warincbattlezone\rsupdate.exe |
"{A00B46CB-1B11-4A3E-9CC5-5542D759A281}" = protocol=17 | dir=in | app=d:\hry\steam\steam.exe |
"{A35C3E16-EA1D-407F-80CF-4F05EE04112A}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\farcry3.exe |
"{A7220947-B9BA-42D0-BAC8-CA8085204276}" = protocol=6 | dir=in | app=d:\hry\steam\steam.exe |
"{AF1B5460-3225-4AA7-8A09-DCECFA5EA50A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B4DACE87-18C6-4A42-ACF5-CDE39D133080}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B6D12C6E-809C-4F03-A3D9-02E516FA6605}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\farcry3_d3d11.exe |
"{B7684CEE-8632-405C-85AA-595AA4304D8A}" = protocol=17 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe |
"{B872DEF9-0994-40CE-A508-4554EBE7B0E7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B9229531-96C4-4BBA-9A61-582D6B9FF15C}" = protocol=6 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{BB07B85C-AD32-493C-BA6B-916568358AA7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BFCC7567-5284-4F4F-B1AC-92D55863C969}" = protocol=17 | dir=in | app=d:\hry\war thunder\launcher.exe |
"{C4CD191A-7D4E-4D73-AD9A-37476ED5A503}" = protocol=17 | dir=in | app=d:\hry\battlefield 3™\bf3.exe |
"{C55A2DFA-A57E-40DF-AC8D-E384AD770F40}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{C7C78E06-DFDF-4940-B305-90F015E6895D}" = protocol=17 | dir=in | app=d:\programy\opera\opera.exe |
"{C92E8E75-42EE-4CD4-BC23-C5EAE57E4F4C}" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwawmp.exe |
"{CF3C47B6-7511-43C1-B050-7BE72AFCF49C}" = dir=in | app=d:\programy\vegas pro 12\vegas120.exe |
"{D1D85D9C-3E2B-4B39-8463-3DC02299EB4F}" = protocol=6 | dir=in | app=d:\programy\steam\steam.exe |
"{DAB6DA04-ED89-4AA6-9D94-2308A7574214}" = protocol=6 | dir=in | app=d:\programy\opera\opera.exe |
"{DBD77E5B-4C17-4512-9D99-D70214069203}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{DDC19DB7-E92A-49F5-BCE9-DD785D91A202}" = protocol=6 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"{DE2812A8-545A-48D4-956C-DF75964A12FD}" = protocol=6 | dir=in | app=d:\programy\tunngle\tunngle.exe |
"{DFB66DC4-FCCE-4C4A-8417-87BDED79EC0D}" = protocol=6 | dir=in | app=d:\hry\steam\steamapps\common\warincbattlezone\rsupdate.exe |
"{E01EBE5E-FB2B-4D39-ADDA-F4FE18447DD8}" = protocol=17 | dir=in | app=d:\hry\apache air assault\launcher.exe |
"{E22BB368-6F60-4DFD-8113-9F12A2C164D4}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\fc3editor.exe |
"{E2C19749-8A3B-4B02-B9E9-933E2FBFE9BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E51F9326-61EC-4DE2-BC0D-0D6E5B30AEA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E8756760-0CD7-447D-9EA6-BDB2391B7ABB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E8E2227D-E004-460D-9CCA-869FE23CD4F7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EAE795B0-8D53-454D-B935-69885EFCF3B4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{EBFE1B0F-BA33-46BF-9289-5095193B5D35}" = protocol=6 | dir=in | app=d:\hry\battlefield 3™\bf3.exe |
"{EC4E9BA3-52A3-4B17-94B6-02A3E42BE679}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EF3179B5-F981-4BA7-AD96-3C58F907CD42}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F44BE500-1EA4-414A-88F7-AFA5E8D23B0F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F6DD5DDE-AE71-4048-B6D4-EA6C1E044059}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\farcry3.exe |
"{FABD95FD-7618-4AC8-AB0E-B1F9634DA0A8}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FB28A8E6-CA38-42F3-B2BA-665BEAAD458F}" = protocol=6 | dir=in | app=d:\hry\the battle for middle-earth ii\game.dat |
"{FD2D339E-876C-4C5F-9610-D42CE79795D3}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\fc3updater.exe |
"TCP Query User{01925F99-2E38-414B-8C29-676290F5B02B}D:\hry\hawx 2\data\browser\uplaybrowser.exe" = protocol=6 | dir=in | app=d:\hry\hawx 2\data\browser\uplaybrowser.exe |
"TCP Query User{082AFA3F-C6E0-49F1-A91F-2DB17C3CB869}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"TCP Query User{09852CFE-4466-4F84-AD54-9B3EE8CA6F82}D:\hry\rise of nations\nations.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\nations.exe |
"TCP Query User{0A332DA6-FEAF-4929-899A-8F257753A389}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=6 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"TCP Query User{0BFCEC14-6648-4E0C-B7A8-B9124C221D78}D:\hry\call of duty black ops ii\t6sp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty black ops ii\t6sp.exe |
"TCP Query User{0CA9FA86-2099-4470-A59F-682C1B98D484}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"TCP Query User{1566CFB5-78A8-4E41-9D90-C7D21A737232}D:\hry\battlefield heroes\bfheroes.exe" = protocol=6 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"TCP Query User{17830623-E83A-4264-8213-E39CE4DAAE57}D:\hry\call od duty 5\codwaw lanfixed.exe" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwaw lanfixed.exe |
"TCP Query User{194F066C-CA91-4488-8E97-7F8C3E73EB93}D:\hry\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"TCP Query User{224522F8-BE2A-4270-A563-5D7A7F172AC1}C:\program files (x86)\microsoft games\rise of legends\legends.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe |
"TCP Query User{298CE109-F7AA-4F4E-ADAC-9B0F82B5DE78}D:\hry\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"TCP Query User{2CA7547B-C503-46F5-BAC5-B040A7E6F0CD}D:\hry\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"TCP Query User{305B949F-F358-48E7-8B78-C98B87308E07}D:\hry\nhl 09\nhl2009.exe" = protocol=6 | dir=in | app=d:\hry\nhl 09\nhl2009.exe |
"TCP Query User{31970E65-227A-4A19-B0B5-6A1AF1786B57}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"TCP Query User{3212219C-0822-4F44-825B-B7A1D0DE5049}D:\hry\heroes of might and magic v\bin\h5_game.exe" = protocol=6 | dir=in | app=d:\hry\heroes of might and magic v\bin\h5_game.exe |
"TCP Query User{35979C62-6DBC-42A7-9F31-411A09524369}D:\hry\war thunder\aces.exe" = protocol=6 | dir=in | app=d:\hry\war thunder\aces.exe |
"TCP Query User{3B028548-5D13-4806-AC33-58A87C210A82}D:\hry\rise of nations bez dd\nations.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations bez dd\nations.exe |
"TCP Query User{3E71986A-837F-4C75-B194-BD06D4DBA09C}D:\hry\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"TCP Query User{43F06CC9-B079-41B5-B7A8-B9E8F0A30464}D:\hry\call of duty 4 mw\iw3mp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"TCP Query User{4879F8C8-44B7-4C18-BD2F-F50E9C6E98C7}D:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe" = protocol=6 | dir=in | app=d:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe |
"TCP Query User{4B646060-334C-424A-BE3D-7C22C1FAD342}D:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe" = protocol=6 | dir=in | app=d:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe |
"TCP Query User{5BF0854A-3B80-4574-AAF8-6F029504628B}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{60C6C79A-DF85-4703-84E4-48B020009962}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"TCP Query User{6558EAB0-44ED-4F37-B094-1E844FB1B1E6}D:\záloha\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=d:\záloha\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{6860A20C-D95F-4CAD-953F-086D299AA69C}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"TCP Query User{6A814828-2288-46C6-8C50-B4334B8F2270}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{6E582680-2DBF-4D3E-95A1-235EF8A53919}D:\hry\arma iii alpha\arma3.exe" = protocol=6 | dir=in | app=d:\hry\arma iii alpha\arma3.exe |
"TCP Query User{6EA01609-BF38-4EC0-AB34-641E7FF87EC4}D:\hry\stronghold 2\stronghold crusader.exe" = protocol=6 | dir=in | app=d:\hry\stronghold 2\stronghold crusader.exe |
"TCP Query User{7084A08E-EBF2-4C37-862D-048EA8F785E8}D:\hry\rise of nations\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"TCP Query User{80518A23-94FA-4449-A560-70D6FEBED855}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{81B03E20-C113-41DF-8B2C-31C94D4F43DB}D:\hry\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"TCP Query User{83E633D2-7C1A-4CF7-97BB-761F2172886E}D:\hry\hawx 2\hawx2_dx11.exe" = protocol=6 | dir=in | app=d:\hry\hawx 2\hawx2_dx11.exe |
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Já\Desktop\PROGRAMY
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,17% Memory free
7,99 Gb Paging File | 6,72 Gb Available in Paging File | 84,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55,88 Gb Total Space | 8,94 Gb Free Space | 16,01% Space Free | Partition Type: NTFS
Drive D: | 875,63 Gb Total Space | 577,72 Gb Free Space | 65,98% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Já | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Programy\Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Programy\MS Office 2010\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Programy\MS Office 2010\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{059A37D4-4486-4EE9-87AA-F3E5AD671C30}" = lport=8090 | protocol=6 | dir=in | name=war thunder |
"{07A58854-0C10-479D-A4B4-2459D8036B3E}" = lport=56889 | protocol=6 | dir=in | name=pando media booster |
"{174B15AB-0E8A-401B-B9B7-B95237660182}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{186E246B-625E-4423-9823-8494FE73333A}" = lport=56889 | protocol=17 | dir=in | name=pando media booster |
"{191F290B-41DE-4D61-A67A-29631C5DA316}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{19781F16-59A4-4B95-AF76-E4F31B786F6C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{1CDF2DBC-57FF-4A87-9ECD-D59F0C3D8C66}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1E95E256-0BD6-406B-9E2F-DBF7D08586E2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{201135C4-17B2-4B70-BF78-E8187BBF0858}" = lport=2869 | protocol=6 | dir=in | app=system |
"{27BD663A-8355-4A18-8FA7-93B0902EDD1D}" = lport=56889 | protocol=6 | dir=in | name=pando media booster |
"{2DC4B6E7-5834-4E9C-8C80-619FF8896B4E}" = lport=27022 | protocol=6 | dir=in | name=war thunder |
"{31E42FF7-FDD8-4B4D-92B7-2E1F65EFE2E3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{44B30A00-ABF6-4EA0-B800-8A4671C9E1B1}" = lport=3478 | protocol=17 | dir=in | name=war thunder |
"{474F47D3-884D-4113-BC2F-268DE2FE834E}" = lport=20443 | protocol=6 | dir=in | name=war thunder |
"{61BC601F-4DE2-4EE9-A8CB-6B22B042F4B6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7886314F-C1D6-43A8-A3FF-3824D4EF6AFF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{84159C6E-7CB7-4957-9337-F99748214FF0}" = lport=6881 | protocol=6 | dir=in | name=war thunder |
"{9ADB9A53-7F4B-4B72-9B00-BACCADA97D10}" = lport=20010 | protocol=17 | dir=in | name=war thunder |
"{AA732939-FE92-4E04-9AA4-AD79E34C8F76}" = lport=80 | protocol=6 | dir=in | name=war thunder |
"{ADE3267F-862F-4009-BC89-0F041BED4FF4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BBCC64A7-A91D-4898-A53F-6C51503F3ECD}" = lport=33333 | protocol=6 | dir=in | name=war thunder |
"{C2C700A7-A081-4728-A6D1-F4E2C95DDAEB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C2D55B00-6EDE-4672-A90D-3C610298519B}" = lport=56889 | protocol=17 | dir=in | name=pando media booster |
"{C62079C8-EC23-4EC7-824E-E31890317948}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CBEF320E-2169-4FF6-ABEB-070B55667392}" = lport=7850 | protocol=6 | dir=in | name=war thunder |
"{D58EEA1D-7C6B-4EC7-9972-29FD9CD2300E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DE3A953B-B58B-49FC-825D-64BABD17F38B}" = lport=443 | protocol=6 | dir=in | name=war thunder |
"{F7D35F11-1366-4E75-A6E1-819B0FE23634}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F742DD-1E35-4358-877E-5F9ED2D9A5FB}" = protocol=58 | dir=in | app=system |
"{03837A36-24C1-4820-B027-7923AB99D9D0}" = protocol=6 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{054B1BB6-FB70-4346-B050-35C774EB3E1B}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\farcry3_d3d11.exe |
"{08C0D8B6-552F-4607-B607-B7ACD42A1820}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\fc3editor.exe |
"{0ACF4E29-FED2-4AD2-8399-BEA9FD31E485}" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwawmp.exe |
"{0AED8745-063F-40A3-B052-80EDC3A18547}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0C3696DA-F126-4C62-88C8-1ED7BB8AD494}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0DDD0EC7-E841-489F-B630-18CC94EE7086}" = protocol=6 | dir=in | app=d:\programy\tunngle\tnglctrl.exe |
"{0FFBCB24-1DB8-4EA0-A364-4DB36D9199ED}" = protocol=17 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{1F9E1830-B75B-4F16-97C0-C0FC41AB4DF3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{241B0AF9-1BB1-4F9B-8DAC-604440DA5AD1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{24A296A4-7596-4E2A-B6DA-5E42798AFF94}" = protocol=17 | dir=in | app=d:\programy\steam\steam.exe |
"{25E4B556-5DA9-45E4-83DE-B28215AC1513}" = protocol=6 | dir=in | app=d:\hry\apache air assault\launcher.exe |
"{2A43910F-2DC2-428E-9588-B724B98DEE55}" = protocol=6 | dir=in | app=d:\hry\bfme 2\game.dat |
"{2A6BAC8B-619E-440B-A920-22306AC49E76}" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwaw.exe |
"{2EC1B8F5-0C16-48AC-BD8E-A9B3B1833C3D}" = protocol=6 | dir=in | app=d:\programy\version8\teamviewer_service.exe |
"{3123E988-7B82-429C-A6EA-AA9D473DD6BC}" = protocol=17 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"{317EEDD2-700A-4E99-AFFA-8EFD87DFADD0}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{326CD0C6-67B8-4A38-BE61-3BA189A32342}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{35580B4F-8542-4650-ACCE-E27DB9A78D44}" = protocol=17 | dir=in | app=d:\programy\version8\teamviewer_service.exe |
"{385A23F3-987D-4616-803F-A36DD59E19C1}" = protocol=17 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"{419ECE60-7278-4769-A94C-620680872C90}" = protocol=17 | dir=in | app=d:\programy\tunngle\tunngle.exe |
"{4BFBE2F7-3DAB-4FCE-BEF5-537254952A6C}" = protocol=17 | dir=in | app=d:\programy\steam\steam.exe |
"{4E7C0991-24CD-4757-B5FD-37FD21AF5B1A}" = protocol=6 | dir=in | app=d:\programy\steam\steam.exe |
"{5D66A307-2A44-4A0D-B801-C5AD5F8ACE22}" = protocol=6 | dir=in | app=d:\programy\version8\teamviewer.exe |
"{60B5F2B0-804B-4148-BEF4-D6B33C9DAC8A}" = protocol=6 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe |
"{61DEA71C-8292-41AC-AE84-224B6B72E8A7}" = protocol=6 | dir=in | app=d:\hry\war thunder\launcher.exe |
"{625C5BD1-6B59-4FA1-B191-FB1D9CC21312}" = protocol=6 | dir=in | app=d:\hry\battlefield 2\bf2.exe |
"{645F6ED9-5179-4B91-9044-A395B005ED95}" = protocol=17 | dir=in | app=d:\hry\the battle for middle-earth ii\game.dat |
"{65880108-D8F0-4434-8201-299C2E779F4A}" = protocol=17 | dir=in | app=d:\programy\version8\teamviewer.exe |
"{6729CEEC-830B-4D76-A9C3-391721229415}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\fc3updater.exe |
"{68ADE188-F584-4EE1-A7A4-B12FC616DC3A}" = protocol=6 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"{6CAD2638-72D0-4742-8F89-EADE912E4D93}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D53B554-8D9B-4EA0-91D8-793812A12697}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{73B95841-00AF-4600-A07E-DA80AAFF33EA}" = protocol=6 | dir=in | app=d:\programy\utorrent\utorrent.exe |
"{75119316-B6C3-4599-92C3-B55134E62566}" = protocol=6 | dir=out | app=system |
"{75E61068-684D-4B18-A1CA-20C8B65E2EE1}" = protocol=6 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe |
"{7B2CE005-074D-4B4D-B93D-DB990D947C11}" = protocol=17 | dir=in | app=d:\programy\tunngle\tnglctrl.exe |
"{7DF02985-E613-4C61-8EAF-147150B4E11C}" = protocol=17 | dir=in | app=d:\hry\apache air assault\yuplay\yuplay.exe |
"{80E1C7E5-4CCD-4DFD-A1D5-47630D9CCA27}" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwaw.exe |
"{8347FC48-B6CE-497C-B682-AA0610DD463F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{847A9C5C-BC43-4478-ADF9-3D7C20BED20D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{860072C2-A1EF-4EE7-B1AA-B749FC0D496F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8AE7418F-7A44-4693-9208-EE552F6F9043}" = protocol=17 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"{8BE4D55F-C8FF-486B-9C75-A9B9C8180C76}" = protocol=6 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"{8CDBCC2F-3486-4272-AC71-C5BC4C72168C}" = protocol=17 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{8F551603-7F9D-4FAC-A6BC-743D832D7134}" = protocol=17 | dir=in | app=d:\programy\utorrent\utorrent.exe |
"{93FCC37E-3F5C-4710-BA45-10B976D6350B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{942F160C-0161-4AFC-AE7C-533494334F35}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{94CB5EF6-A67C-4811-912D-AC2A2B1031A3}" = protocol=6 | dir=in | app=d:\hry\apache air assault\yuplay\yuplay.exe |
"{9549A25E-6F66-4E54-9989-0E7332142EBE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{96F35C06-8383-4152-8DB9-21E47E86E414}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{978F36B8-B4CA-4CFC-86C6-7F8BFE12B54F}" = protocol=17 | dir=in | app=d:\hry\bfme 2\game.dat |
"{97936A49-8B93-4740-BCC2-F0633A9BC74B}" = protocol=17 | dir=in | app=d:\hry\battlefield 2\bf2.exe |
"{97BAB3E1-C805-489C-8E42-E6C69DE630EA}" = protocol=17 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe |
"{99017A49-0588-4AF2-89B2-1898816B6666}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9A6266D4-F17B-46E6-8E8F-F3ACEE992C43}" = protocol=17 | dir=in | app=d:\hry\steam\steamapps\common\warincbattlezone\rsupdate.exe |
"{A00B46CB-1B11-4A3E-9CC5-5542D759A281}" = protocol=17 | dir=in | app=d:\hry\steam\steam.exe |
"{A35C3E16-EA1D-407F-80CF-4F05EE04112A}" = protocol=6 | dir=in | app=d:\hry\far cry 3\bin\farcry3.exe |
"{A7220947-B9BA-42D0-BAC8-CA8085204276}" = protocol=6 | dir=in | app=d:\hry\steam\steam.exe |
"{AF1B5460-3225-4AA7-8A09-DCECFA5EA50A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B4DACE87-18C6-4A42-ACF5-CDE39D133080}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B6D12C6E-809C-4F03-A3D9-02E516FA6605}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\farcry3_d3d11.exe |
"{B7684CEE-8632-405C-85AA-595AA4304D8A}" = protocol=17 | dir=in | app=d:\hry\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe |
"{B872DEF9-0994-40CE-A508-4554EBE7B0E7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B9229531-96C4-4BBA-9A61-582D6B9FF15C}" = protocol=6 | dir=in | app=d:\hry\age of empires iii\aoe3\age3.exe |
"{BB07B85C-AD32-493C-BA6B-916568358AA7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BFCC7567-5284-4F4F-B1AC-92D55863C969}" = protocol=17 | dir=in | app=d:\hry\war thunder\launcher.exe |
"{C4CD191A-7D4E-4D73-AD9A-37476ED5A503}" = protocol=17 | dir=in | app=d:\hry\battlefield 3™\bf3.exe |
"{C55A2DFA-A57E-40DF-AC8D-E384AD770F40}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{C7C78E06-DFDF-4940-B305-90F015E6895D}" = protocol=17 | dir=in | app=d:\programy\opera\opera.exe |
"{C92E8E75-42EE-4CD4-BC23-C5EAE57E4F4C}" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwawmp.exe |
"{CF3C47B6-7511-43C1-B050-7BE72AFCF49C}" = dir=in | app=d:\programy\vegas pro 12\vegas120.exe |
"{D1D85D9C-3E2B-4B39-8463-3DC02299EB4F}" = protocol=6 | dir=in | app=d:\programy\steam\steam.exe |
"{DAB6DA04-ED89-4AA6-9D94-2308A7574214}" = protocol=6 | dir=in | app=d:\programy\opera\opera.exe |
"{DBD77E5B-4C17-4512-9D99-D70214069203}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{DDC19DB7-E92A-49F5-BCE9-DD785D91A202}" = protocol=6 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"{DE2812A8-545A-48D4-956C-DF75964A12FD}" = protocol=6 | dir=in | app=d:\programy\tunngle\tunngle.exe |
"{DFB66DC4-FCCE-4C4A-8417-87BDED79EC0D}" = protocol=6 | dir=in | app=d:\hry\steam\steamapps\common\warincbattlezone\rsupdate.exe |
"{E01EBE5E-FB2B-4D39-ADDA-F4FE18447DD8}" = protocol=17 | dir=in | app=d:\hry\apache air assault\launcher.exe |
"{E22BB368-6F60-4DFD-8113-9F12A2C164D4}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\fc3editor.exe |
"{E2C19749-8A3B-4B02-B9E9-933E2FBFE9BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E51F9326-61EC-4DE2-BC0D-0D6E5B30AEA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E8756760-0CD7-447D-9EA6-BDB2391B7ABB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E8E2227D-E004-460D-9CCA-869FE23CD4F7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EAE795B0-8D53-454D-B935-69885EFCF3B4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{EBFE1B0F-BA33-46BF-9289-5095193B5D35}" = protocol=6 | dir=in | app=d:\hry\battlefield 3™\bf3.exe |
"{EC4E9BA3-52A3-4B17-94B6-02A3E42BE679}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EF3179B5-F981-4BA7-AD96-3C58F907CD42}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F44BE500-1EA4-414A-88F7-AFA5E8D23B0F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F6DD5DDE-AE71-4048-B6D4-EA6C1E044059}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\farcry3.exe |
"{FABD95FD-7618-4AC8-AB0E-B1F9634DA0A8}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FB28A8E6-CA38-42F3-B2BA-665BEAAD458F}" = protocol=6 | dir=in | app=d:\hry\the battle for middle-earth ii\game.dat |
"{FD2D339E-876C-4C5F-9610-D42CE79795D3}" = protocol=17 | dir=in | app=d:\hry\far cry 3\bin\fc3updater.exe |
"TCP Query User{01925F99-2E38-414B-8C29-676290F5B02B}D:\hry\hawx 2\data\browser\uplaybrowser.exe" = protocol=6 | dir=in | app=d:\hry\hawx 2\data\browser\uplaybrowser.exe |
"TCP Query User{082AFA3F-C6E0-49F1-A91F-2DB17C3CB869}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"TCP Query User{09852CFE-4466-4F84-AD54-9B3EE8CA6F82}D:\hry\rise of nations\nations.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\nations.exe |
"TCP Query User{0A332DA6-FEAF-4929-899A-8F257753A389}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=6 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"TCP Query User{0BFCEC14-6648-4E0C-B7A8-B9124C221D78}D:\hry\call of duty black ops ii\t6sp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty black ops ii\t6sp.exe |
"TCP Query User{0CA9FA86-2099-4470-A59F-682C1B98D484}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"TCP Query User{1566CFB5-78A8-4E41-9D90-C7D21A737232}D:\hry\battlefield heroes\bfheroes.exe" = protocol=6 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"TCP Query User{17830623-E83A-4264-8213-E39CE4DAAE57}D:\hry\call od duty 5\codwaw lanfixed.exe" = protocol=6 | dir=in | app=d:\hry\call od duty 5\codwaw lanfixed.exe |
"TCP Query User{194F066C-CA91-4488-8E97-7F8C3E73EB93}D:\hry\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"TCP Query User{224522F8-BE2A-4270-A563-5D7A7F172AC1}C:\program files (x86)\microsoft games\rise of legends\legends.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe |
"TCP Query User{298CE109-F7AA-4F4E-ADAC-9B0F82B5DE78}D:\hry\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"TCP Query User{2CA7547B-C503-46F5-BAC5-B040A7E6F0CD}D:\hry\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"TCP Query User{305B949F-F358-48E7-8B78-C98B87308E07}D:\hry\nhl 09\nhl2009.exe" = protocol=6 | dir=in | app=d:\hry\nhl 09\nhl2009.exe |
"TCP Query User{31970E65-227A-4A19-B0B5-6A1AF1786B57}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"TCP Query User{3212219C-0822-4F44-825B-B7A1D0DE5049}D:\hry\heroes of might and magic v\bin\h5_game.exe" = protocol=6 | dir=in | app=d:\hry\heroes of might and magic v\bin\h5_game.exe |
"TCP Query User{35979C62-6DBC-42A7-9F31-411A09524369}D:\hry\war thunder\aces.exe" = protocol=6 | dir=in | app=d:\hry\war thunder\aces.exe |
"TCP Query User{3B028548-5D13-4806-AC33-58A87C210A82}D:\hry\rise of nations bez dd\nations.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations bez dd\nations.exe |
"TCP Query User{3E71986A-837F-4C75-B194-BD06D4DBA09C}D:\hry\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"TCP Query User{43F06CC9-B079-41B5-B7A8-B9E8F0A30464}D:\hry\call of duty 4 mw\iw3mp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"TCP Query User{4879F8C8-44B7-4C18-BD2F-F50E9C6E98C7}D:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe" = protocol=6 | dir=in | app=d:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe |
"TCP Query User{4B646060-334C-424A-BE3D-7C22C1FAD342}D:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe" = protocol=6 | dir=in | app=d:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe |
"TCP Query User{5BF0854A-3B80-4574-AAF8-6F029504628B}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{60C6C79A-DF85-4703-84E4-48B020009962}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"TCP Query User{6558EAB0-44ED-4F37-B094-1E844FB1B1E6}D:\záloha\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=d:\záloha\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{6860A20C-D95F-4CAD-953F-086D299AA69C}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"TCP Query User{6A814828-2288-46C6-8C50-B4334B8F2270}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{6E582680-2DBF-4D3E-95A1-235EF8A53919}D:\hry\arma iii alpha\arma3.exe" = protocol=6 | dir=in | app=d:\hry\arma iii alpha\arma3.exe |
"TCP Query User{6EA01609-BF38-4EC0-AB34-641E7FF87EC4}D:\hry\stronghold 2\stronghold crusader.exe" = protocol=6 | dir=in | app=d:\hry\stronghold 2\stronghold crusader.exe |
"TCP Query User{7084A08E-EBF2-4C37-862D-048EA8F785E8}D:\hry\rise of nations\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"TCP Query User{80518A23-94FA-4449-A560-70D6FEBED855}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{81B03E20-C113-41DF-8B2C-31C94D4F43DB}D:\hry\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"TCP Query User{83E633D2-7C1A-4CF7-97BB-761F2172886E}D:\hry\hawx 2\hawx2_dx11.exe" = protocol=6 | dir=in | app=d:\hry\hawx 2\hawx2_dx11.exe |
I use Arch BTW
- HappyMental
- Level 4
- Příspěvky: 1420
- Registrován: září 11
- Bydliště: Nýdnol, Bulharsko
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
"TCP Query User{8811FC98-9BBE-44DB-93BA-81495C3A9C9E}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe |
"TCP Query User{8872341A-B21D-4C83-A8AB-BC865BEB12AE}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{8957AF97-1A0D-4FB7-A65D-C4304C68B004}D:\hry\modern warfare 2\iw4mp.exe" = protocol=6 | dir=in | app=d:\hry\modern warfare 2\iw4mp.exe |
"TCP Query User{89FDFF9D-F360-43DE-9524-70967302E51A}D:\hry\warcraft iii\war3.exe" = protocol=6 | dir=in | app=d:\hry\warcraft iii\war3.exe |
"TCP Query User{8F691DA7-FD71-46A0-BE76-CB41DF113A31}D:\instalačky\terrariaretail\terraria.exe" = protocol=6 | dir=in | app=d:\instalačky\terrariaretail\terraria.exe |
"TCP Query User{92238AC1-07D3-4108-BD35-0D6A0779D120}D:\hry\need for speed underground 2\speed2.exe" = protocol=6 | dir=in | app=d:\hry\need for speed underground 2\speed2.exe |
"TCP Query User{92C4C8B8-1ABB-4891-906A-6F84B9892E03}D:\hry\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=d:\hry\crysis 2\bin32\crysis2.exe |
"TCP Query User{9B704264-2D6B-4D23-927E-A3A3CD2DD85E}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=6 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"TCP Query User{B125A05C-90DD-42CA-B8AB-2F74B9674FD5}D:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe" = protocol=6 | dir=in | app=d:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe |
"TCP Query User{B2C655C1-C083-4DBE-BA2E-384FF681E471}C:\users\já\desktop\nemazat\router\easysetupassistant.exe" = protocol=6 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"TCP Query User{B9485081-5288-4D75-9D56-D4CA5800AB9B}D:\hry\flatout2\flatout2.exe" = protocol=6 | dir=in | app=d:\hry\flatout2\flatout2.exe |
"TCP Query User{B97DEE3B-7209-4EC3-A1A7-E4020CE908A3}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=6 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"TCP Query User{BAE1FC79-1326-449C-8EFC-4D1B2CEF934A}D:\hry\need for speed world\game data\data\nfsw.exe" = protocol=6 | dir=in | app=d:\hry\need for speed world\game data\data\nfsw.exe |
"TCP Query User{C64B7A03-14F5-4E4B-8F38-5867972EBA84}D:\hry\rise of nations\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"TCP Query User{C8403276-7898-46C5-81D1-A9F11E0DB835}D:\hry\heroes 3\heroes3.exe" = protocol=6 | dir=in | app=d:\hry\heroes 3\heroes3.exe |
"TCP Query User{CBF9CA4A-90C1-4440-98A2-BF3DB034F497}D:\programy\myphoneexplorer\myphoneexplorer.exe" = protocol=6 | dir=in | app=d:\programy\myphoneexplorer\myphoneexplorer.exe |
"TCP Query User{D28CFE9D-6960-41B3-BF65-BD1118F661CE}D:\hry\orcs must die 2\build\release\orcsmustdie2.exe" = protocol=6 | dir=in | app=d:\hry\orcs must die 2\build\release\orcsmustdie2.exe |
"TCP Query User{D94EC4E0-7EC1-494F-9AC8-CC48E0719847}D:\hry\stronghold\stronghold.exe" = protocol=6 | dir=in | app=d:\hry\stronghold\stronghold.exe |
"TCP Query User{D9832495-E656-44CA-BC4D-99704D5EDFC5}D:\hry\crysis 3\bin32\crysis3.exe" = protocol=6 | dir=in | app=d:\hry\crysis 3\bin32\crysis3.exe |
"TCP Query User{DA64B671-BC2C-4DF4-8F63-194DC60C5E5C}D:\hry\call of duty black ops ii\t6mp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty black ops ii\t6mp.exe |
"TCP Query User{DB5BF8BD-5630-46E4-9AEF-C088ED01F70E}D:\hry\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=d:\hry\left 4 dead 2\left4dead2.exe |
"TCP Query User{DB77D0F4-5F24-499D-A95B-DF96E5C5D4DF}D:\hry\battlefield heroes\bfheroes.exe" = protocol=6 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"TCP Query User{DD59E47B-2FA1-4575-8350-A560F4A3FF79}D:\hry\wiggles\wiggles.exe" = protocol=6 | dir=in | app=d:\hry\wiggles\wiggles.exe |
"TCP Query User{E117F264-E19B-4C4C-BF89-70CFA004DBC9}C:\users\já\desktop\wr740n\easysetupassistant.exe" = protocol=6 | dir=in | app=c:\users\já\desktop\wr740n\easysetupassistant.exe |
"TCP Query User{E586CEA7-FC82-4809-8B9C-89A2950A5973}C:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe" = protocol=6 | dir=in | app=c:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe |
"TCP Query User{E7C02580-FC29-417F-8DAE-F22C8180C3D0}D:\hry\rise of nations bez dd\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations bez dd\patriots.exe |
"TCP Query User{EAC72B26-0BD4-48E1-B2C4-A15EA4A29979}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=6 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"TCP Query User{F47AEC4B-C131-4B41-A1A9-C9F95E2DEAB5}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"TCP Query User{F60C5A67-3B1A-44EC-A271-5222C5EADEE8}D:\programy\wcl\webcam.exe" = protocol=6 | dir=in | app=d:\programy\wcl\webcam.exe |
"TCP Query User{F658F2F4-C4F5-4455-B781-83FA5D3D452E}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{FB29438B-5D99-4F09-97BF-1BC10191BE80}D:\hry\call of juarez\coj.exe" = protocol=6 | dir=in | app=d:\hry\call of juarez\coj.exe |
"TCP Query User{FEF54150-2343-463E-8672-FBBFFF869149}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{00EE3BC9-6AFE-4C31-8E1D-37A7313025D7}D:\hry\need for speed underground 2\speed2.exe" = protocol=17 | dir=in | app=d:\hry\need for speed underground 2\speed2.exe |
"UDP Query User{02B4CD1F-8BE6-4046-BFDA-8BE895414701}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{02DC7E4F-B379-4D92-BA3E-413DD2981B65}D:\hry\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"UDP Query User{0895DD10-AD44-4355-A37B-64DB94ABD8EB}D:\hry\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"UDP Query User{0D1CB0C8-5107-4653-AB78-8C390C860E9C}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{0E6FE625-B31D-4635-8E6D-571F854ACD1C}D:\hry\hawx 2\hawx2_dx11.exe" = protocol=17 | dir=in | app=d:\hry\hawx 2\hawx2_dx11.exe |
"UDP Query User{1285309F-265D-4FF9-9A15-20F8F6E1E9AB}D:\hry\call of duty black ops ii\t6mp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty black ops ii\t6mp.exe |
"UDP Query User{1D8BD468-3835-448D-8513-981C6FB63A70}D:\hry\flatout2\flatout2.exe" = protocol=17 | dir=in | app=d:\hry\flatout2\flatout2.exe |
"UDP Query User{1E43CE53-7966-4F81-A14D-0E28494A97DA}D:\hry\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"UDP Query User{1F232F72-557E-4E15-A746-1882C3E054F2}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=17 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"UDP Query User{20B705DD-B631-4790-A922-AFB78775FA29}C:\users\já\desktop\wr740n\easysetupassistant.exe" = protocol=17 | dir=in | app=c:\users\já\desktop\wr740n\easysetupassistant.exe |
"UDP Query User{20EF6BCF-8437-4FDD-A1D7-D8A9B06A4BE6}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"UDP Query User{2ABB328A-327F-4282-81AE-FA63041C3E23}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"UDP Query User{304352D0-321A-4453-8DAA-7ABA2FD8EE52}D:\instalačky\terrariaretail\terraria.exe" = protocol=17 | dir=in | app=d:\instalačky\terrariaretail\terraria.exe |
"UDP Query User{3174C7D7-72B3-4470-86E2-7CA2BE3C831F}D:\hry\rise of nations\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"UDP Query User{3244039F-D5F9-4504-9555-2DCDCCC1F11B}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"UDP Query User{389A1A31-0B4D-4892-83CA-21CBA43D1815}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"UDP Query User{38DC9959-D385-49DA-85F1-1EF0A0627807}D:\hry\stronghold\stronghold.exe" = protocol=17 | dir=in | app=d:\hry\stronghold\stronghold.exe |
"UDP Query User{3B0F9B3D-D9A1-473C-815F-E35A1D8E55F1}D:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe" = protocol=17 | dir=in | app=d:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe |
"UDP Query User{3B8CE044-C43A-4CC1-91C6-E2DE24D3E4A7}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"UDP Query User{3FBFA4C7-F33C-4DAD-9F02-688762DDA65E}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"UDP Query User{40040635-DEF5-4DEE-9245-DB051355D13A}D:\hry\rise of nations\nations.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\nations.exe |
"UDP Query User{41A07209-C84B-4638-A269-E03E186E4534}D:\hry\arma iii alpha\arma3.exe" = protocol=17 | dir=in | app=d:\hry\arma iii alpha\arma3.exe |
"UDP Query User{4BDFD5EE-1ADA-4C33-9AA6-01D55A23AB5A}C:\users\já\desktop\nemazat\router\easysetupassistant.exe" = protocol=17 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"UDP Query User{4C9D5581-B48A-4529-8DD7-8B0A0BAC646E}D:\hry\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"UDP Query User{54526A34-EF11-482F-AF8A-1F73519E6C86}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{5A71B8DA-8EAB-41AE-BE59-F4DB2C92AA97}D:\hry\call od duty 5\codwaw lanfixed.exe" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwaw lanfixed.exe |
"UDP Query User{6151E011-0DBF-4D56-B88A-C12312D49EAE}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{620A321C-6D15-466A-97E4-0AD14A10D0BB}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{6323B771-8265-4872-9034-8FF057560F8D}D:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe" = protocol=17 | dir=in | app=d:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe |
"UDP Query User{752DB3E5-8B16-466D-BCE2-2E2986EDE8C0}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{80D05626-6511-403F-A1EC-730863416F4D}D:\hry\wiggles\wiggles.exe" = protocol=17 | dir=in | app=d:\hry\wiggles\wiggles.exe |
"UDP Query User{8280C357-BEB8-4045-9CF0-CF404A8F8861}D:\hry\crysis 3\bin32\crysis3.exe" = protocol=17 | dir=in | app=d:\hry\crysis 3\bin32\crysis3.exe |
"UDP Query User{8BB437E8-8407-4280-B3C1-D3DD36A4D571}D:\hry\stronghold 2\stronghold crusader.exe" = protocol=17 | dir=in | app=d:\hry\stronghold 2\stronghold crusader.exe |
"UDP Query User{8BB5F64A-90F9-4F60-8D55-F971F3C0D645}C:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe" = protocol=17 | dir=in | app=c:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe |
"UDP Query User{8D69C16D-5098-4DD1-9F38-411D13A004AE}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{915FF4F9-B831-4B8E-ACA7-4F9B0827331B}D:\programy\wcl\webcam.exe" = protocol=17 | dir=in | app=d:\programy\wcl\webcam.exe |
"UDP Query User{921BE0D5-1C3E-4586-A6ED-BEAB2865EAE4}D:\hry\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=d:\hry\crysis 2\bin32\crysis2.exe |
"UDP Query User{9406E4BB-FF44-4FBB-BE54-5D132D30A564}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=17 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"UDP Query User{98303972-E113-49E8-ABAA-0108D0FD4FE4}D:\hry\modern warfare 2\iw4mp.exe" = protocol=17 | dir=in | app=d:\hry\modern warfare 2\iw4mp.exe |
"UDP Query User{9B4F77E7-5628-4DFF-9CEE-605715BD393C}D:\hry\rise of nations bez dd\nations.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations bez dd\nations.exe |
"UDP Query User{9CB7BABB-DE50-44E0-B262-FF9587534919}D:\hry\heroes of might and magic v\bin\h5_game.exe" = protocol=17 | dir=in | app=d:\hry\heroes of might and magic v\bin\h5_game.exe |
"UDP Query User{A2EEDD00-2F36-4C89-8BD6-C2F14CACDC82}D:\hry\nhl 09\nhl2009.exe" = protocol=17 | dir=in | app=d:\hry\nhl 09\nhl2009.exe |
"UDP Query User{A778A015-A674-47EE-AE0B-3692A0C7C83D}D:\hry\orcs must die 2\build\release\orcsmustdie2.exe" = protocol=17 | dir=in | app=d:\hry\orcs must die 2\build\release\orcsmustdie2.exe |
"UDP Query User{AE1F28AF-7AE3-44CA-8A30-6B0D40E8FBDC}D:\hry\battlefield heroes\bfheroes.exe" = protocol=17 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"UDP Query User{AFFF48B5-5F3F-45D7-B396-670FBA0AB11A}D:\hry\hawx 2\data\browser\uplaybrowser.exe" = protocol=17 | dir=in | app=d:\hry\hawx 2\data\browser\uplaybrowser.exe |
"UDP Query User{B18DD993-BD46-44B2-9CA7-D5210EA032C1}D:\hry\call of duty 4 mw\iw3mp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"UDP Query User{B4006ACA-BA20-4649-A9A4-90401A3D120C}D:\hry\rise of nations bez dd\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations bez dd\patriots.exe |
"UDP Query User{B49EB40F-A3F6-410B-A66C-A17132373688}D:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe" = protocol=17 | dir=in | app=d:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe |
"UDP Query User{B50F6520-F522-41FC-8A38-AB7EEE6EF14B}D:\hry\war thunder\aces.exe" = protocol=17 | dir=in | app=d:\hry\war thunder\aces.exe |
"UDP Query User{B624EA6F-46C8-47F3-B10B-D7AAA9105D55}D:\záloha\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=d:\záloha\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{BA93A638-19E5-4C39-A0E4-3402F7A347FE}D:\hry\warcraft iii\war3.exe" = protocol=17 | dir=in | app=d:\hry\warcraft iii\war3.exe |
"UDP Query User{C3379C83-76FC-4F41-95A0-CC49AC733E33}D:\hry\call of duty black ops ii\t6sp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty black ops ii\t6sp.exe |
"UDP Query User{C6205832-A189-4E7A-9BC0-D6A410E3BBB4}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=17 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"UDP Query User{C88F1D00-779B-4822-BB7D-6798AF83081E}D:\hry\call of juarez\coj.exe" = protocol=17 | dir=in | app=d:\hry\call of juarez\coj.exe |
"UDP Query User{CC3F0ED8-E859-42B6-822B-5A46629A907D}D:\hry\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"UDP Query User{D3D877C3-762F-44DE-8FDC-9EF8CAFD1383}D:\hry\rise of nations\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"UDP Query User{D4020633-2A50-476C-900C-52CCD958281A}D:\hry\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=d:\hry\left 4 dead 2\left4dead2.exe |
"UDP Query User{D603FB47-ABDE-493F-A296-38850D875B4B}D:\hry\battlefield heroes\bfheroes.exe" = protocol=17 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"UDP Query User{DB931ECE-3779-416F-931C-D34FE255E221}D:\hry\need for speed world\game data\data\nfsw.exe" = protocol=17 | dir=in | app=d:\hry\need for speed world\game data\data\nfsw.exe |
"UDP Query User{E6EA0AE7-9E84-499B-AB5D-434BD1978E1B}D:\programy\myphoneexplorer\myphoneexplorer.exe" = protocol=17 | dir=in | app=d:\programy\myphoneexplorer\myphoneexplorer.exe |
"UDP Query User{F3D515D4-5BEC-4185-BA6D-6DDF0AC85E16}D:\hry\heroes 3\heroes3.exe" = protocol=17 | dir=in | app=d:\hry\heroes 3\heroes3.exe |
"UDP Query User{FA2634AE-A31B-48DD-97AA-7C740EFED408}C:\program files (x86)\microsoft games\rise of legends\legends.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe |
"UDP Query User{FDFC3EA4-FD01-4CA0-B042-143CF4BDD305}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=17 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC5
"{08BCFE15-8AA1-4A58-B018-4FEF486BA922}" = Autodesk Inventor Fusion for Inventor 2013 Add-in
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series" = Canon MG5100 series MP Drivers
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{266597A9-1764-0000-0100-DCBF2B69166B}" = Autodesk Vault Basic 2013 (Client) English Language Pack
"{26A24AE4-039D-4CA4-87B4-2F86417015FF}" = Java 7 Update 15 (64-bit)
"{2C22EA92-CB30-4932-0053-000001000000}" = InfraRecorder 0.53 (x64 edition)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52E5D8A7-B129-4A29-AD4B-EBB749DCC3A3}_is1" = GamePark klient 2.0.9.0
"{5783F2D7-B028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2013
"{64A3A4F4-B792-11D6-A78A-00B0D0170150}" = Java SE Development Kit 7 Update 15 (64-bit)
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{792A9A32-718A-40D1-9867-A903F76AE2F8}" = Eco Materials Adviser for Autodesk Inventor 2013
"{7F4DD591-1764-0001-0000-7107D70F3DB4}" = Autodesk Inventor 2013
"{7F4DD591-1764-0001-1029-7107D70F3DB4}" = Autodesk Inventor 2013 Jazykový balíček - čeština (Czech)
"{7F4DD591-1764-0001-1033-7107D70F3DB4}" = Autodesk Inventor 2013 English Language Pack
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-1000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-1000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-1000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-1000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-1000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0405-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Czech) 2010
"{90140000-0044-0405-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A324DC11-FF02-3CE8-9D6F-67EBC006D970}" = Microsoft .NET Framework 4 Extended CSY Language Pack
"{A7500970-FE98-11E1-B560-F04DA23A5C58}" = Vegas Pro 12.0 (64-bit)
"{AB085680-FE98-11E1-A232-F04DA23A5C58}" = MSVCRT Redists
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.13.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 4.11.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.3.24.2
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B46DECD1-1764-4EF1-0000-22D71E81877C}" = Autodesk Inventor Content Center Libraries 2013 (Desktop Content)
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{CF526A26-1764-0000-0000-02E95019B628}" = Autodesk Vault Basic 2013 (Client)
"{D25FF5C1-1764-469A-9794-69309387C193}" = Autodesk Inventor 2013 Quick Uninstaller
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}" = Autodesk Sync
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FFF5619F-2013-0064-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2013
"{FFF5619F-6669-4EC5-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2012
"{FFF7F80F-929E-497F-A112-B070DE816128}" = Autodesk Inventor Fusion 2012 Language Pack
"5BA0ED46C9DC31622E4E843CD031A0D99369D83A" = Balíček ovladače systému Windows - Bobj Excite (WinUSB) AndroidUsbDeviceClass (12/06/2010 4.0.0000.00000)
"Autodesk Inventor 2013" = Autodesk Inventor 2013 English
"Autodesk Inventor Fusion 2013" = Autodesk Inventor Fusion 2013
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.63.0
"DWG TrueView 2013" = DWG TrueView 2013
"GIMP-2_is1" = GIMP 2.8.2
"Jazykový balíček Autodesk Inventor 2013 - čeština (Czech)" = Autodesk Inventor 2013 Jazykový balíček - čeština (Czech)
"MAXON0DB9EF7E" = CINEMA 4D 14.041
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended CSY Language Pack" = Microsoft .NET Framework 4 Extended CSY Language Pack
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Recuva" = Recuva
"TeamSpeak 3 Client" = TeamSpeak 3 Client
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"{07BE4679-4318-4413-9701-B3D92354F11D}" = Heroes of Might and Magic V - Tribes of the East
"{0F3BEAD5-4368-4CBC-9876-11B8475DE285}" = OSCAR Editor
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{127B684B-A002-44C8-99A7-6CF8F1E26873}" = PunkBuster for Battlefield 1942
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}" = Autodesk Design Review 2013
"{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1" = Euro Truck Simulator 2
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{27C6C0A2-2EC9-4FEA-BE2B-659EAAC2C68C}" = Autodesk Material Library Low Resolution Image Library 2013
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{300A2961-B2B5-4889-9CB9-5C2A570D08AD}" = Debugging Tools for Windows (x86)
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3282FBE1-35FC-48D8-98CA-115A5EF1F9B4}" = NVIDIA PhysX
"{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Call of Pripyat [v1.6.02]
"{4198AE83-A3C6-4C41-85C8-EC63E990696E}_is1" = Crysis 3 verze 1.0.0.1
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5DB849D6-9392-4FB7-9ABB-87ED433152E5}" = LG United Mobile Drivers
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{654A4E00-D4E7-11D5-BA56-00C0CA129740}" = Wiggles
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"{76A232AF-B7D6-41A4-B795-6B355E6D32B1}" = Tom Clancy's H.A.W.X. 2
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{779D8CA1-03DD-4AD4-B21F-3E20BFE7BEDE}" = SketchUp 8
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797DC296-ADC5-4A08-8CBC-AEB0D6F4B249}" = Windows Live Essentials
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader HD
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{97370293-96EC-11D4-9DEF-00104B70C5FB}" = Giants
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A035950F-15BA-41C0-9D8F-165FC0536012}" = Movie Maker
"{A1FBD2B3-6768-472D-BA46-C00EACBCE16C}" = Fotogalerie
"{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1" = Convert MOV to AVI 1.0
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free CENZURA 3.5.136
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Czech
"{AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}" = LG Bluetooth Drivers
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BED27751-CD2A-4C2F-9813-00B9B60C76FE}" = Railroad Tycoon II - Platinum
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D4006E71-FF32-44FF-AD5A-B5EE4389B825}_is1" = FlatOut2
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.10.324
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers
"{E18F981B-401C-4D90-BC57-D8903564D558}" = Windows Live UX Platform Language Pack
"{e2e37deb-a157-4c12-83a5-4845f3ef8625}" = Nero 9 Essentials
"{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{EB91007A-0110-42A6-B869-2709955A9B2A}" = Photo Common
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1" = War Thunder Launcher 1.0.1.246
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F9706A8C-D740-42CA-8703-E08EDD0F0778}" = LogMeIn Hamachi
"{FA66CFD7-0977-4C45-AACD-A8BB994B1A05}" = Quake Live Mozilla Plugin
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"ACE COMBAT ASSAULT HORIZON Enhanced Edition_is1" = ACE COMBAT ASSAULT HORIZON Enhanced Edition
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v2.85
"Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build 5.0.1.0)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Autodesk Design Review 2013" = Autodesk Design Review 2013
"Autodesk Vault Basic 2013 (Client)" = Autodesk Vault Basic 2013 (Client)
"avast" = avast! Free Antivirus
"BSPlayerf" = BS.Player FREE
"Counter-Strike 1.6 Non-Steam 1.0" = Counter-Strike 1.6 Non-Steam 1.0
"Crossfire Europe" = Crossfire Europe
"CrystalDiskInfo_is1" = CrystalDiskInfo 5.6.2 Shizuku Edition
"DAEMON Tools Lite" = DAEMON Tools Lite
"FormatFactory" = FormatFactory 3.00
"Fraps" = Fraps (remove only)
"GameParkClient_is1" = GamePark
"GameSpy Arcade" = GameSpy Arcade
"Geekbench 2.4" = Geekbench 2.4
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III Complete
"HWiNFO32_is1" = HWiNFO32 Version 4.16
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"InstallShield_{0F3BEAD5-4368-4CBC-9876-11B8475DE285}" = X7 Oscar Editor
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"ISO Workshop_is1" = ISO Workshop 3.6
"LG PC Suite IV" = LG PC Suite IV
"LogMeIn Hamachi" = LogMeIn Hamachi
"Mafia II_is1" = Mafia II DLC Joe's Adventures
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.75.0.1300
"MKVToolNix" = MKVToolNix 5.6.0
"Mozilla Firefox 20.0.1 (x86 cs)" = Mozilla Firefox 20.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Opera 12.15.1748" = Opera 12.15
"PdaNet_is1" = PdaNet for Android 3.00
"PunkBusterSvc" = PunkBuster Services
"Quake III Arena Point Release 1.32" = Quake III Arena Point Release 1.32
"Registrace uživatele zařízení Canon MG5100 series" = Registrace uživatele zařízení Canon MG5100 series
"Risen 2 Dark Waters_is1" = Risen 2 Dark Waters
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"RiseofNationsExpansion 1.0" = Rise of Nations Thrones and Patriots
"Steam App 107900" = War Inc. Battlezone
"TeamViewer 8" = TeamViewer 8
"The KMPlayer" = The KMPlayer (remove only)
"TmNationsForever_is1" = TmNationsForever
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.11 (32-bit)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 22.0 (x86 cs)" = Mozilla Firefox 22.0 (x86 cs)
"soe-PlanetSide 2 PSG" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
[ System Events ]
Error - 11.7.2013 7:59:18 | Computer Name = PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (13:58:15, ?11.?7.?2013) bylo neočekávané.
Error - 11.7.2013 13:30:47 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Stereoscopic 3D Driver Service byla neočekávaně ukončena.
Tento stav nastal již 1krát.
Error - 11.7.2013 15:22:31 | Computer Name = PC | Source = nvlddmkm | ID = 11141134
Description =
Error - 12.7.2013 5:15:21 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 5:17:08 | Computer Name = PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.
Error - 12.7.2013 5:17:35 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 11:31:30 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Služba nTune Service byla neočekávaně ukončena. Tento stav nastal
již 1krát.
Error - 12.7.2013 15:08:15 | Computer Name = PC | Source = nvlddmkm | ID = 11141134
Description =
Error - 12.7.2013 17:10:01 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 17:12:11 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
< End of report >
"TCP Query User{8872341A-B21D-4C83-A8AB-BC865BEB12AE}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{8957AF97-1A0D-4FB7-A65D-C4304C68B004}D:\hry\modern warfare 2\iw4mp.exe" = protocol=6 | dir=in | app=d:\hry\modern warfare 2\iw4mp.exe |
"TCP Query User{89FDFF9D-F360-43DE-9524-70967302E51A}D:\hry\warcraft iii\war3.exe" = protocol=6 | dir=in | app=d:\hry\warcraft iii\war3.exe |
"TCP Query User{8F691DA7-FD71-46A0-BE76-CB41DF113A31}D:\instalačky\terrariaretail\terraria.exe" = protocol=6 | dir=in | app=d:\instalačky\terrariaretail\terraria.exe |
"TCP Query User{92238AC1-07D3-4108-BD35-0D6A0779D120}D:\hry\need for speed underground 2\speed2.exe" = protocol=6 | dir=in | app=d:\hry\need for speed underground 2\speed2.exe |
"TCP Query User{92C4C8B8-1ABB-4891-906A-6F84B9892E03}D:\hry\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=d:\hry\crysis 2\bin32\crysis2.exe |
"TCP Query User{9B704264-2D6B-4D23-927E-A3A3CD2DD85E}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=6 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"TCP Query User{B125A05C-90DD-42CA-B8AB-2F74B9674FD5}D:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe" = protocol=6 | dir=in | app=d:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe |
"TCP Query User{B2C655C1-C083-4DBE-BA2E-384FF681E471}C:\users\já\desktop\nemazat\router\easysetupassistant.exe" = protocol=6 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"TCP Query User{B9485081-5288-4D75-9D56-D4CA5800AB9B}D:\hry\flatout2\flatout2.exe" = protocol=6 | dir=in | app=d:\hry\flatout2\flatout2.exe |
"TCP Query User{B97DEE3B-7209-4EC3-A1A7-E4020CE908A3}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=6 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"TCP Query User{BAE1FC79-1326-449C-8EFC-4D1B2CEF934A}D:\hry\need for speed world\game data\data\nfsw.exe" = protocol=6 | dir=in | app=d:\hry\need for speed world\game data\data\nfsw.exe |
"TCP Query User{C64B7A03-14F5-4E4B-8F38-5867972EBA84}D:\hry\rise of nations\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"TCP Query User{C8403276-7898-46C5-81D1-A9F11E0DB835}D:\hry\heroes 3\heroes3.exe" = protocol=6 | dir=in | app=d:\hry\heroes 3\heroes3.exe |
"TCP Query User{CBF9CA4A-90C1-4440-98A2-BF3DB034F497}D:\programy\myphoneexplorer\myphoneexplorer.exe" = protocol=6 | dir=in | app=d:\programy\myphoneexplorer\myphoneexplorer.exe |
"TCP Query User{D28CFE9D-6960-41B3-BF65-BD1118F661CE}D:\hry\orcs must die 2\build\release\orcsmustdie2.exe" = protocol=6 | dir=in | app=d:\hry\orcs must die 2\build\release\orcsmustdie2.exe |
"TCP Query User{D94EC4E0-7EC1-494F-9AC8-CC48E0719847}D:\hry\stronghold\stronghold.exe" = protocol=6 | dir=in | app=d:\hry\stronghold\stronghold.exe |
"TCP Query User{D9832495-E656-44CA-BC4D-99704D5EDFC5}D:\hry\crysis 3\bin32\crysis3.exe" = protocol=6 | dir=in | app=d:\hry\crysis 3\bin32\crysis3.exe |
"TCP Query User{DA64B671-BC2C-4DF4-8F63-194DC60C5E5C}D:\hry\call of duty black ops ii\t6mp.exe" = protocol=6 | dir=in | app=d:\hry\call of duty black ops ii\t6mp.exe |
"TCP Query User{DB5BF8BD-5630-46E4-9AEF-C088ED01F70E}D:\hry\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=d:\hry\left 4 dead 2\left4dead2.exe |
"TCP Query User{DB77D0F4-5F24-499D-A95B-DF96E5C5D4DF}D:\hry\battlefield heroes\bfheroes.exe" = protocol=6 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"TCP Query User{DD59E47B-2FA1-4575-8350-A560F4A3FF79}D:\hry\wiggles\wiggles.exe" = protocol=6 | dir=in | app=d:\hry\wiggles\wiggles.exe |
"TCP Query User{E117F264-E19B-4C4C-BF89-70CFA004DBC9}C:\users\já\desktop\wr740n\easysetupassistant.exe" = protocol=6 | dir=in | app=c:\users\já\desktop\wr740n\easysetupassistant.exe |
"TCP Query User{E586CEA7-FC82-4809-8B9C-89A2950A5973}C:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe" = protocol=6 | dir=in | app=c:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe |
"TCP Query User{E7C02580-FC29-417F-8DAE-F22C8180C3D0}D:\hry\rise of nations bez dd\patriots.exe" = protocol=6 | dir=in | app=d:\hry\rise of nations bez dd\patriots.exe |
"TCP Query User{EAC72B26-0BD4-48E1-B2C4-A15EA4A29979}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=6 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"TCP Query User{F47AEC4B-C131-4B41-A1A9-C9F95E2DEAB5}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=6 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"TCP Query User{F60C5A67-3B1A-44EC-A271-5222C5EADEE8}D:\programy\wcl\webcam.exe" = protocol=6 | dir=in | app=d:\programy\wcl\webcam.exe |
"TCP Query User{F658F2F4-C4F5-4455-B781-83FA5D3D452E}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{FB29438B-5D99-4F09-97BF-1BC10191BE80}D:\hry\call of juarez\coj.exe" = protocol=6 | dir=in | app=d:\hry\call of juarez\coj.exe |
"TCP Query User{FEF54150-2343-463E-8672-FBBFFF869149}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{00EE3BC9-6AFE-4C31-8E1D-37A7313025D7}D:\hry\need for speed underground 2\speed2.exe" = protocol=17 | dir=in | app=d:\hry\need for speed underground 2\speed2.exe |
"UDP Query User{02B4CD1F-8BE6-4046-BFDA-8BE895414701}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{02DC7E4F-B379-4D92-BA3E-413DD2981B65}D:\hry\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"UDP Query User{0895DD10-AD44-4355-A37B-64DB94ABD8EB}D:\hry\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"UDP Query User{0D1CB0C8-5107-4653-AB78-8C390C860E9C}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{0E6FE625-B31D-4635-8E6D-571F854ACD1C}D:\hry\hawx 2\hawx2_dx11.exe" = protocol=17 | dir=in | app=d:\hry\hawx 2\hawx2_dx11.exe |
"UDP Query User{1285309F-265D-4FF9-9A15-20F8F6E1E9AB}D:\hry\call of duty black ops ii\t6mp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty black ops ii\t6mp.exe |
"UDP Query User{1D8BD468-3835-448D-8513-981C6FB63A70}D:\hry\flatout2\flatout2.exe" = protocol=17 | dir=in | app=d:\hry\flatout2\flatout2.exe |
"UDP Query User{1E43CE53-7966-4F81-A14D-0E28494A97DA}D:\hry\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=d:\hry\tmnationsforever\tmforever.exe |
"UDP Query User{1F232F72-557E-4E15-A746-1882C3E054F2}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=17 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"UDP Query User{20B705DD-B631-4790-A922-AFB78775FA29}C:\users\já\desktop\wr740n\easysetupassistant.exe" = protocol=17 | dir=in | app=c:\users\já\desktop\wr740n\easysetupassistant.exe |
"UDP Query User{20EF6BCF-8437-4FDD-A1D7-D8A9B06A4BE6}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"UDP Query User{2ABB328A-327F-4282-81AE-FA63041C3E23}D:\hry\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\worldoftanks.exe |
"UDP Query User{304352D0-321A-4453-8DAA-7ABA2FD8EE52}D:\instalačky\terrariaretail\terraria.exe" = protocol=17 | dir=in | app=d:\instalačky\terrariaretail\terraria.exe |
"UDP Query User{3174C7D7-72B3-4470-86E2-7CA2BE3C831F}D:\hry\rise of nations\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"UDP Query User{3244039F-D5F9-4504-9555-2DCDCCC1F11B}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"UDP Query User{389A1A31-0B4D-4892-83CA-21CBA43D1815}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"UDP Query User{38DC9959-D385-49DA-85F1-1EF0A0627807}D:\hry\stronghold\stronghold.exe" = protocol=17 | dir=in | app=d:\hry\stronghold\stronghold.exe |
"UDP Query User{3B0F9B3D-D9A1-473C-815F-E35A1D8E55F1}D:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe" = protocol=17 | dir=in | app=d:\hry\all zombies must die!\binaries\win32\shippingpc-bzb2game.exe |
"UDP Query User{3B8CE044-C43A-4CC1-91C6-E2DE24D3E4A7}D:\hry\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\hry\world_of_tanks\wotlauncher.exe |
"UDP Query User{3FBFA4C7-F33C-4DAD-9F02-688762DDA65E}D:\hry\call of duty 2\call of duty 2\cod2mp_s.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 2\call of duty 2\cod2mp_s.exe |
"UDP Query User{40040635-DEF5-4DEE-9245-DB051355D13A}D:\hry\rise of nations\nations.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\nations.exe |
"UDP Query User{41A07209-C84B-4638-A269-E03E186E4534}D:\hry\arma iii alpha\arma3.exe" = protocol=17 | dir=in | app=d:\hry\arma iii alpha\arma3.exe |
"UDP Query User{4BDFD5EE-1ADA-4C33-9AA6-01D55A23AB5A}C:\users\já\desktop\nemazat\router\easysetupassistant.exe" = protocol=17 | dir=in | app=c:\users\já\desktop\nemazat\router\easysetupassistant.exe |
"UDP Query User{4C9D5581-B48A-4529-8DD7-8B0A0BAC646E}D:\hry\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=d:\hry\planetside 2\planetside2.exe |
"UDP Query User{54526A34-EF11-482F-AF8A-1F73519E6C86}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{5A71B8DA-8EAB-41AE-BE59-F4DB2C92AA97}D:\hry\call od duty 5\codwaw lanfixed.exe" = protocol=17 | dir=in | app=d:\hry\call od duty 5\codwaw lanfixed.exe |
"UDP Query User{6151E011-0DBF-4D56-B88A-C12312D49EAE}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{620A321C-6D15-466A-97E4-0AD14A10D0BB}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{6323B771-8265-4872-9034-8FF057560F8D}D:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe" = protocol=17 | dir=in | app=d:\hry\guerrilla bob\guerrilla bob\guerrillabob.exe |
"UDP Query User{752DB3E5-8B16-466D-BCE2-2E2986EDE8C0}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{80D05626-6511-403F-A1EC-730863416F4D}D:\hry\wiggles\wiggles.exe" = protocol=17 | dir=in | app=d:\hry\wiggles\wiggles.exe |
"UDP Query User{8280C357-BEB8-4045-9CF0-CF404A8F8861}D:\hry\crysis 3\bin32\crysis3.exe" = protocol=17 | dir=in | app=d:\hry\crysis 3\bin32\crysis3.exe |
"UDP Query User{8BB437E8-8407-4280-B3C1-D3DD36A4D571}D:\hry\stronghold 2\stronghold crusader.exe" = protocol=17 | dir=in | app=d:\hry\stronghold 2\stronghold crusader.exe |
"UDP Query User{8BB5F64A-90F9-4F60-8D55-F971F3C0D645}C:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe" = protocol=17 | dir=in | app=c:\users\já\appdata\local\temp\rar$exa0.943\wc3 proxy\wc3proxy.exe |
"UDP Query User{8D69C16D-5098-4DD1-9F38-411D13A004AE}D:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=d:\hry\borderlands\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{915FF4F9-B831-4B8E-ACA7-4F9B0827331B}D:\programy\wcl\webcam.exe" = protocol=17 | dir=in | app=d:\programy\wcl\webcam.exe |
"UDP Query User{921BE0D5-1C3E-4586-A6ED-BEAB2865EAE4}D:\hry\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=d:\hry\crysis 2\bin32\crysis2.exe |
"UDP Query User{9406E4BB-FF44-4FBB-BE54-5D132D30A564}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=17 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
"UDP Query User{98303972-E113-49E8-ABAA-0108D0FD4FE4}D:\hry\modern warfare 2\iw4mp.exe" = protocol=17 | dir=in | app=d:\hry\modern warfare 2\iw4mp.exe |
"UDP Query User{9B4F77E7-5628-4DFF-9CEE-605715BD393C}D:\hry\rise of nations bez dd\nations.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations bez dd\nations.exe |
"UDP Query User{9CB7BABB-DE50-44E0-B262-FF9587534919}D:\hry\heroes of might and magic v\bin\h5_game.exe" = protocol=17 | dir=in | app=d:\hry\heroes of might and magic v\bin\h5_game.exe |
"UDP Query User{A2EEDD00-2F36-4C89-8BD6-C2F14CACDC82}D:\hry\nhl 09\nhl2009.exe" = protocol=17 | dir=in | app=d:\hry\nhl 09\nhl2009.exe |
"UDP Query User{A778A015-A674-47EE-AE0B-3692A0C7C83D}D:\hry\orcs must die 2\build\release\orcsmustdie2.exe" = protocol=17 | dir=in | app=d:\hry\orcs must die 2\build\release\orcsmustdie2.exe |
"UDP Query User{AE1F28AF-7AE3-44CA-8A30-6B0D40E8FBDC}D:\hry\battlefield heroes\bfheroes.exe" = protocol=17 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"UDP Query User{AFFF48B5-5F3F-45D7-B396-670FBA0AB11A}D:\hry\hawx 2\data\browser\uplaybrowser.exe" = protocol=17 | dir=in | app=d:\hry\hawx 2\data\browser\uplaybrowser.exe |
"UDP Query User{B18DD993-BD46-44B2-9CA7-D5210EA032C1}D:\hry\call of duty 4 mw\iw3mp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty 4 mw\iw3mp.exe |
"UDP Query User{B4006ACA-BA20-4649-A9A4-90401A3D120C}D:\hry\rise of nations bez dd\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations bez dd\patriots.exe |
"UDP Query User{B49EB40F-A3F6-410B-A66C-A17132373688}D:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe" = protocol=17 | dir=in | app=d:\hry\heroes v\heroes of might and magic v - tribes of the east\bin\h5_game.exe |
"UDP Query User{B50F6520-F522-41FC-8A38-AB7EEE6EF14B}D:\hry\war thunder\aces.exe" = protocol=17 | dir=in | app=d:\hry\war thunder\aces.exe |
"UDP Query User{B624EA6F-46C8-47F3-B10B-D7AAA9105D55}D:\záloha\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=d:\záloha\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{BA93A638-19E5-4C39-A0E4-3402F7A347FE}D:\hry\warcraft iii\war3.exe" = protocol=17 | dir=in | app=d:\hry\warcraft iii\war3.exe |
"UDP Query User{C3379C83-76FC-4F41-95A0-CC49AC733E33}D:\hry\call of duty black ops ii\t6sp.exe" = protocol=17 | dir=in | app=d:\hry\call of duty black ops ii\t6sp.exe |
"UDP Query User{C6205832-A189-4E7A-9BC0-D6A410E3BBB4}D:\hry\counter-strike 1.6 non-steam\hl.exe" = protocol=17 | dir=in | app=d:\hry\counter-strike 1.6 non-steam\hl.exe |
"UDP Query User{C88F1D00-779B-4822-BB7D-6798AF83081E}D:\hry\call of juarez\coj.exe" = protocol=17 | dir=in | app=d:\hry\call of juarez\coj.exe |
"UDP Query User{CC3F0ED8-E859-42B6-822B-5A46629A907D}D:\hry\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=d:\hry\battlefield 1942\bf1942.exe |
"UDP Query User{D3D877C3-762F-44DE-8FDC-9EF8CAFD1383}D:\hry\rise of nations\patriots.exe" = protocol=17 | dir=in | app=d:\hry\rise of nations\patriots.exe |
"UDP Query User{D4020633-2A50-476C-900C-52CCD958281A}D:\hry\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=d:\hry\left 4 dead 2\left4dead2.exe |
"UDP Query User{D603FB47-ABDE-493F-A296-38850D875B4B}D:\hry\battlefield heroes\bfheroes.exe" = protocol=17 | dir=in | app=d:\hry\battlefield heroes\bfheroes.exe |
"UDP Query User{DB931ECE-3779-416F-931C-D34FE255E221}D:\hry\need for speed world\game data\data\nfsw.exe" = protocol=17 | dir=in | app=d:\hry\need for speed world\game data\data\nfsw.exe |
"UDP Query User{E6EA0AE7-9E84-499B-AB5D-434BD1978E1B}D:\programy\myphoneexplorer\myphoneexplorer.exe" = protocol=17 | dir=in | app=d:\programy\myphoneexplorer\myphoneexplorer.exe |
"UDP Query User{F3D515D4-5BEC-4185-BA6D-6DDF0AC85E16}D:\hry\heroes 3\heroes3.exe" = protocol=17 | dir=in | app=d:\hry\heroes 3\heroes3.exe |
"UDP Query User{FA2634AE-A31B-48DD-97AA-7C740EFED408}C:\program files (x86)\microsoft games\rise of legends\legends.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe |
"UDP Query User{FDFC3EA4-FD01-4CA0-B042-143CF4BDD305}D:\hry\quake 3 arena\quake3\quake3.exe" = protocol=17 | dir=in | app=d:\hry\quake 3 arena\quake3\quake3.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC5
"{08BCFE15-8AA1-4A58-B018-4FEF486BA922}" = Autodesk Inventor Fusion for Inventor 2013 Add-in
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series" = Canon MG5100 series MP Drivers
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{266597A9-1764-0000-0100-DCBF2B69166B}" = Autodesk Vault Basic 2013 (Client) English Language Pack
"{26A24AE4-039D-4CA4-87B4-2F86417015FF}" = Java 7 Update 15 (64-bit)
"{2C22EA92-CB30-4932-0053-000001000000}" = InfraRecorder 0.53 (x64 edition)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52E5D8A7-B129-4A29-AD4B-EBB749DCC3A3}_is1" = GamePark klient 2.0.9.0
"{5783F2D7-B028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2013
"{64A3A4F4-B792-11D6-A78A-00B0D0170150}" = Java SE Development Kit 7 Update 15 (64-bit)
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{792A9A32-718A-40D1-9867-A903F76AE2F8}" = Eco Materials Adviser for Autodesk Inventor 2013
"{7F4DD591-1764-0001-0000-7107D70F3DB4}" = Autodesk Inventor 2013
"{7F4DD591-1764-0001-1029-7107D70F3DB4}" = Autodesk Inventor 2013 Jazykový balíček - čeština (Czech)
"{7F4DD591-1764-0001-1033-7107D70F3DB4}" = Autodesk Inventor 2013 English Language Pack
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-1000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-1000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-1000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-1000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-1000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0405-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Czech) 2010
"{90140000-0044-0405-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A324DC11-FF02-3CE8-9D6F-67EBC006D970}" = Microsoft .NET Framework 4 Extended CSY Language Pack
"{A7500970-FE98-11E1-B560-F04DA23A5C58}" = Vegas Pro 12.0 (64-bit)
"{AB085680-FE98-11E1-A232-F04DA23A5C58}" = MSVCRT Redists
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 320.49
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.13.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 4.11.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.3.24.2
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B46DECD1-1764-4EF1-0000-22D71E81877C}" = Autodesk Inventor Content Center Libraries 2013 (Desktop Content)
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{CF526A26-1764-0000-0000-02E95019B628}" = Autodesk Vault Basic 2013 (Client)
"{D25FF5C1-1764-469A-9794-69309387C193}" = Autodesk Inventor 2013 Quick Uninstaller
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}" = Autodesk Sync
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FFF5619F-2013-0064-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2013
"{FFF5619F-6669-4EC5-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2012
"{FFF7F80F-929E-497F-A112-B070DE816128}" = Autodesk Inventor Fusion 2012 Language Pack
"5BA0ED46C9DC31622E4E843CD031A0D99369D83A" = Balíček ovladače systému Windows - Bobj Excite (WinUSB) AndroidUsbDeviceClass (12/06/2010 4.0.0000.00000)
"Autodesk Inventor 2013" = Autodesk Inventor 2013 English
"Autodesk Inventor Fusion 2013" = Autodesk Inventor Fusion 2013
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.63.0
"DWG TrueView 2013" = DWG TrueView 2013
"GIMP-2_is1" = GIMP 2.8.2
"Jazykový balíček Autodesk Inventor 2013 - čeština (Czech)" = Autodesk Inventor 2013 Jazykový balíček - čeština (Czech)
"MAXON0DB9EF7E" = CINEMA 4D 14.041
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended CSY Language Pack" = Microsoft .NET Framework 4 Extended CSY Language Pack
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Recuva" = Recuva
"TeamSpeak 3 Client" = TeamSpeak 3 Client
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"{07BE4679-4318-4413-9701-B3D92354F11D}" = Heroes of Might and Magic V - Tribes of the East
"{0F3BEAD5-4368-4CBC-9876-11B8475DE285}" = OSCAR Editor
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{127B684B-A002-44C8-99A7-6CF8F1E26873}" = PunkBuster for Battlefield 1942
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}" = Autodesk Design Review 2013
"{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1" = Euro Truck Simulator 2
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{27C6C0A2-2EC9-4FEA-BE2B-659EAAC2C68C}" = Autodesk Material Library Low Resolution Image Library 2013
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{300A2961-B2B5-4889-9CB9-5C2A570D08AD}" = Debugging Tools for Windows (x86)
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3282FBE1-35FC-48D8-98CA-115A5EF1F9B4}" = NVIDIA PhysX
"{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Call of Pripyat [v1.6.02]
"{4198AE83-A3C6-4C41-85C8-EC63E990696E}_is1" = Crysis 3 verze 1.0.0.1
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5DB849D6-9392-4FB7-9ABB-87ED433152E5}" = LG United Mobile Drivers
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{654A4E00-D4E7-11D5-BA56-00C0CA129740}" = Wiggles
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"{76A232AF-B7D6-41A4-B795-6B355E6D32B1}" = Tom Clancy's H.A.W.X. 2
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{779D8CA1-03DD-4AD4-B21F-3E20BFE7BEDE}" = SketchUp 8
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797DC296-ADC5-4A08-8CBC-AEB0D6F4B249}" = Windows Live Essentials
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader HD
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{97370293-96EC-11D4-9DEF-00104B70C5FB}" = Giants
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A035950F-15BA-41C0-9D8F-165FC0536012}" = Movie Maker
"{A1FBD2B3-6768-472D-BA46-C00EACBCE16C}" = Fotogalerie
"{A39EA3C8-7BF3-4FA7-9A67-3D3611BAE59E}_is1" = Convert MOV to AVI 1.0
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free CENZURA 3.5.136
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Czech
"{AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}" = LG Bluetooth Drivers
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BED27751-CD2A-4C2F-9813-00B9B60C76FE}" = Railroad Tycoon II - Platinum
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D4006E71-FF32-44FF-AD5A-B5EE4389B825}_is1" = FlatOut2
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.10.324
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers
"{E18F981B-401C-4D90-BC57-D8903564D558}" = Windows Live UX Platform Language Pack
"{e2e37deb-a157-4c12-83a5-4845f3ef8625}" = Nero 9 Essentials
"{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{EB91007A-0110-42A6-B869-2709955A9B2A}" = Photo Common
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1" = War Thunder Launcher 1.0.1.246
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F9706A8C-D740-42CA-8703-E08EDD0F0778}" = LogMeIn Hamachi
"{FA66CFD7-0977-4C45-AACD-A8BB994B1A05}" = Quake Live Mozilla Plugin
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"ACE COMBAT ASSAULT HORIZON Enhanced Edition_is1" = ACE COMBAT ASSAULT HORIZON Enhanced Edition
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v2.85
"Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build 5.0.1.0)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Autodesk Design Review 2013" = Autodesk Design Review 2013
"Autodesk Vault Basic 2013 (Client)" = Autodesk Vault Basic 2013 (Client)
"avast" = avast! Free Antivirus
"BSPlayerf" = BS.Player FREE
"Counter-Strike 1.6 Non-Steam 1.0" = Counter-Strike 1.6 Non-Steam 1.0
"Crossfire Europe" = Crossfire Europe
"CrystalDiskInfo_is1" = CrystalDiskInfo 5.6.2 Shizuku Edition
"DAEMON Tools Lite" = DAEMON Tools Lite
"FormatFactory" = FormatFactory 3.00
"Fraps" = Fraps (remove only)
"GameParkClient_is1" = GamePark
"GameSpy Arcade" = GameSpy Arcade
"Geekbench 2.4" = Geekbench 2.4
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III Complete
"HWiNFO32_is1" = HWiNFO32 Version 4.16
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"InstallShield_{0F3BEAD5-4368-4CBC-9876-11B8475DE285}" = X7 Oscar Editor
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty(R) - World at War(TM) 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"ISO Workshop_is1" = ISO Workshop 3.6
"LG PC Suite IV" = LG PC Suite IV
"LogMeIn Hamachi" = LogMeIn Hamachi
"Mafia II_is1" = Mafia II DLC Joe's Adventures
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.75.0.1300
"MKVToolNix" = MKVToolNix 5.6.0
"Mozilla Firefox 20.0.1 (x86 cs)" = Mozilla Firefox 20.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Opera 12.15.1748" = Opera 12.15
"PdaNet_is1" = PdaNet for Android 3.00
"PunkBusterSvc" = PunkBuster Services
"Quake III Arena Point Release 1.32" = Quake III Arena Point Release 1.32
"Registrace uživatele zařízení Canon MG5100 series" = Registrace uživatele zařízení Canon MG5100 series
"Risen 2 Dark Waters_is1" = Risen 2 Dark Waters
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"RiseofNationsExpansion 1.0" = Rise of Nations Thrones and Patriots
"Steam App 107900" = War Inc. Battlezone
"TeamViewer 8" = TeamViewer 8
"The KMPlayer" = The KMPlayer (remove only)
"TmNationsForever_is1" = TmNationsForever
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.11 (32-bit)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 22.0 (x86 cs)" = Mozilla Firefox 22.0 (x86 cs)
"soe-PlanetSide 2 PSG" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
Error - 13.7.2013 6:15:43 | Computer Name = PC | Source = ESENT | ID = 412
Description = wuaueng.dll (368) SUS20ClientDataStore: Ze záhlaví souboru protokolu
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log nelze číst. Chyba -546
[ System Events ]
Error - 11.7.2013 7:59:18 | Computer Name = PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (13:58:15, ?11.?7.?2013) bylo neočekávané.
Error - 11.7.2013 13:30:47 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Stereoscopic 3D Driver Service byla neočekávaně ukončena.
Tento stav nastal již 1krát.
Error - 11.7.2013 15:22:31 | Computer Name = PC | Source = nvlddmkm | ID = 11141134
Description =
Error - 12.7.2013 5:15:21 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 5:17:08 | Computer Name = PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.
Error - 12.7.2013 5:17:35 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 11:31:30 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Služba nTune Service byla neočekávaně ukončena. Tento stav nastal
již 1krát.
Error - 12.7.2013 15:08:15 | Computer Name = PC | Source = nvlddmkm | ID = 11141134
Description =
Error - 12.7.2013 17:10:01 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
Error - 12.7.2013 17:12:11 | Computer Name = PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.
< End of report >
I use Arch BTW
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu-zamrzání pc
Ta Tvoje plocha musí vypadat..
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
10.99.25.113
7.254.254.254
http://www.ip-adress.com/ip_tracer/7.254.254.254
Znáš ty IP adresy?
Stáhni si Security Check by screen317 z některého odkazu
http://screen317.spywareinfoforum.org/SecurityCheck.exe
http://screen317.changelog.fr/SecurityCheck.exe
ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=Quicksearch_16194&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll File not found
[2012.08.24 23:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Extensions
[2013.07.12 11:21:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions
[2013.06.10 19:21:39 | 000,000,000 | ---D | M] (KMPlayer Toolbar) -- C:\Users\Já\AppData\Roaming\Mozilla\Firefox\Profiles\6ejlkd02.default\extensions\toolbar@ask.com
O4 - HKLM..\Run: [] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000 File not found
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013.07.09 17:45:45 | 000,666,406 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2013.07.09 17:45:45 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.09 17:45:45 | 000,140,102 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2013.07.09 17:45:45 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:A1EDB939
:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Qoobox
C:\Windows\DeleteOnReboot.bat
C:\Users\Já\AppData\Roaming\inst.exe
:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
10.99.25.113
7.254.254.254
http://www.ip-adress.com/ip_tracer/7.254.254.254
Znáš ty IP adresy?
Stáhni si Security Check by screen317 z některého odkazu
http://screen317.spywareinfoforum.org/SecurityCheck.exe
http://screen317.changelog.fr/SecurityCheck.exe
ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 80 hostů