c:\program files\Microsoft\BingBar\apps\videos\7.0.609\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\images\videos_100.png
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\images\videos_125.png
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\images\videos_150.png
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\js\navigateUrl.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\js\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ar-ploc-sa\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ar-ploc-sa\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\da-dk\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\da-dk\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\de-de\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\de-de\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\el-gr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\el-gr\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-au\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-au\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-ca\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-ca\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-gb\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-gb\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-id\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-id\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-in\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-in\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-my\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-my\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-nz\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-nz\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-ph\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-ph\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-sg\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-sg\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-us\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\en-us\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-es\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-es\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-mx\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-mx\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-us\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\es-us\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fi-fi\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fi-fi\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-be\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-be\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-ca\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-ca\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-fr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\fr-fr\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\it-it\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\it-it\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ja-jp\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ja-jp\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ja-ploc-jp\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ja-ploc-jp\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ko-kr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ko-kr\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nb-no\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nb-no\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nl-be\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nl-be\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nl-nl\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\nl-nl\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pl-pl\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pl-pl\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pt-br\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pt-br\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pt-pt\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\pt-pt\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ru-ru\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\ru-ru\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\sv-se\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\sv-se\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\th-th\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\th-th\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\tr-tr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\tr-tr\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-cn\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-cn\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-hk\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-hk\settings.js
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-tw\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\videos\7.0.609\loc\zh-tw\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\css\bingclient.css
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\css\weather.css
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\footer\footer.css
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\footer\footer.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\footer\progress_indicator.gif
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\alert_notification.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\alert_toast.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\alert_wing.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\back_disabled.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\back_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\back_hover.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\back_pressed.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\back_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_default.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_disabled.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_hover.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_press.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_4_selected.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_disabled_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_disabled_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_down_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_down_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_focus_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_focus_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_hover_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_hover_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_selected_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_selected_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_up_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_5_up_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_disabled_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_disabled_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_down_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_down_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_focus_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_focus_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_hover_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_hover_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_selected_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_selected_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_up_down.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_6_up_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_disabled_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_disabled_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_down_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_down_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_focus_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_focus_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_hover_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_hover_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_selected_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_selected_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_up_left.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\btn_8_up_right.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\close_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\close_hover.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\close_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\gradient_a.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\gradient_b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\gradient_c.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\checkbox_deselected.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\checkbox_deselected_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\checkbox_selected.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\checkbox_selected_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\radio_selected.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\radio_selected_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\radio_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\buttons\radio_up_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\close_a.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\close_b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\forward_disabled.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\forward_focus.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\forward_hover.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\forward_pressed.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\forward_up.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\1.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\11.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\12.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\13_41_46.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\17.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\19.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\19b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\19c.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\20.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\20b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\23.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\25.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\25b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\27.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\27b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\29.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\29b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\31.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\31b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\34_33.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\40.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\43.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\44.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\5.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\7.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\9.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\9b.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\9c.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Blizzard_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Blizzard_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Cloudy_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Cloudy_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\CloudyDust_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\CloudyDust_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\CloudyNighttime_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\CloudyNighttime_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Dust_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Dust_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\DustNight_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\DustNight_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Fair_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Fair_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Fog_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Fog_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\FogNight_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\FogNight_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\FreezingRain_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\FreezingRain_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Frigid_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Frigid_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\FrigidNight_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\HeavyRain_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\HeavyRain_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\IceSnow_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\IceSnow_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Moon_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Moon_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\MostlyCloudy_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\MostlyCloudy_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\MostlyCloudyNight_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\MostlyCloudyNight_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\PartlyCloudy_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\PartlyCloudy_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Rain_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Rain_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\RainSnow_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\RainSnow_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\ShowersClear_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\ShowersClear_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\ShowersNight_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\ShowersNight_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Snow_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Snow_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\SnowWindy_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\SnowWindy_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\SprinklesDrizzle_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\SprinklesDrizzle_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Sun_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Sun_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\tempIcon.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Thunderstorm_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Thunderstorm_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\WeatherDataNotAvailable_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\WeatherDataNotAvailable_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Windy_16x16.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\icons\Windy_43x26.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\pill_weather_150.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\weather_check.png
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\images\WeatherDataNA.jpg
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\common.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\instrumentation.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\jquery-1.4.2.min.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\json2.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\locations.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\options.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\search.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\service.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\serviceutility.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\skycodes.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\utility.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\js\weather.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ar-145\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ar-ploc-sa\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ar-ploc-sa\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ar-ploc-sa\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ar-sa\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\bg-bg\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\bg-bg\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\bg-bg\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ca-es\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ca-es\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ca-es\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\cs-cz\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\cs-cz\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\cs-cz\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\da-dk\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\da-dk\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\da-dk\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-at\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-at\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-at\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-de\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-de\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-de\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-ch\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-ch\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\de-ch\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\el-gr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\el-gr\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\el-gr\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-001\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-001\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-001\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-145\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-145\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-145\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-au\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-au\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-au\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ca\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ca\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ca\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-gb\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-gb\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-gb\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-id\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-id\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-id\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ie\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ie\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ie\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-in\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-in\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-my\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-my\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-my\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-nz\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-nz\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-nz\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ph\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ph\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-ph\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-sg\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-sg\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-sg\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-us\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-us\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-us\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-za\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-za\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\en-za\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-001\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-001\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-001\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-419\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-419\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-419\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-ar\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-ar\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-ar\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-cl\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-cl\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-cl\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-es\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-es\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-es\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-mx\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-mx\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-mx\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-us\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-us\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\es-us\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\et-ee\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\et-ee\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\et-ee\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\eu-es\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\eu-es\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\eu-es\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fi-fi\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fi-fi\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fi-fi\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-145\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-145\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-145\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-be\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-be\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-be\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ca\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ca\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ca\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-fr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-fr\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-fr\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ch\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ch\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\fr-ch\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\gu-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\he-il\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hi-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hr-hr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hr-hr\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hr-hr\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hu-hu\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hu-hu\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\hu-hu\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\id-id\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\id-id\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\id-id\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\it-it\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\it-it\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\it-it\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-jp\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-jp\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-jp\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-ploc-jp\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-ploc-jp\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ja-ploc-jp\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\kn-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ko-kr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ko-kr\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ko-kr\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lt-lt\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lt-lt\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lt-lt\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lv-lv\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lv-lv\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\lv-lv\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ml-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\mr-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ms-my\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ms-my\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ms-my\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nb-no\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nb-no\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nb-no\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-be\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-be\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-be\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-nl\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-nl\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\nl-nl\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pl-pl\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pl-pl\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pl-pl\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-br\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-br\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-br\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-pt\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-pt\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\pt-pt\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ro-ro\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ro-ro\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ro-ro\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ru-ru\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ru-ru\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ru-ru\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sk-sk\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sk-sk\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sk-sk\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sl-si\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sl-si\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sl-si\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-cyrl-cs\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-cyrl-cs\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-cyrl-cs\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-latn-cs\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-latn-cs\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sr-latn-cs\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sv-se\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sv-se\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\sv-se\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\ta-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\te-in\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\th-th\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\th-th\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\th-th\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\tr-tr\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\tr-tr\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\tr-tr\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\uk-ua\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\uk-ua\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\uk-ua\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\vi-vn\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\vi-vn\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\vi-vn\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-cn\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-cn\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-cn\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-hk\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-hk\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-hk\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-tw\appmanifest.xml
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-tw\locStrings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\loc\zh-tw\settings.js
c:\program files\Microsoft\BingBar\apps\weather\7.0.609\weather.html
Prosím o preventivní kontrolu logu HJT Vyřešeno
Re: Prosím o preventivní kontrolu logu HJT
c:\program files\Microsoft\BingBar\BBSvc.EXE
c:\program files\Microsoft\BingBar\BingApp.exe
c:\program files\Microsoft\BingBar\BingBar.exe
c:\program files\Microsoft\BingBar\BingExt.dll
c:\program files\Microsoft\BingBar\common.dll
c:\program files\Microsoft\BingBar\defaultCache.txt
c:\program files\Microsoft\BingBar\DefMgr.dll
c:\program files\Microsoft\BingBar\Installers\BingBar7.0.609\BingBar.msi
c:\program files\Microsoft\BingBar\scripts\debug\trace.js
c:\program files\Microsoft\BingBar\scripts\io\downloader.js
c:\program files\Microsoft\BingBar\scripts\io\io.js
c:\program files\Microsoft\BingBar\scripts\main.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\appapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\appmanagementapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\apppackageapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\buttonapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\configurationapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\servicesapi.js
c:\program files\Microsoft\BingBar\scripts\parsers\activeversionxml.js
c:\program files\Microsoft\BingBar\scripts\parsers\appmanifestxml.js
c:\program files\Microsoft\BingBar\scripts\parsers\json2.js
c:\program files\Microsoft\BingBar\scripts\parsers\xmlparser.js
c:\program files\Microsoft\BingBar\scripts\system\app.js
c:\program files\Microsoft\BingBar\scripts\system\appcatalog.js
c:\program files\Microsoft\BingBar\scripts\system\appcatalogcache.js
c:\program files\Microsoft\BingBar\scripts\system\appinstaller.js
c:\program files\Microsoft\BingBar\scripts\system\appmanager.js
c:\program files\Microsoft\BingBar\scripts\system\apppackage.js
c:\program files\Microsoft\BingBar\scripts\system\blockedapp.js
c:\program files\Microsoft\BingBar\scripts\system\buttonlayout.js
c:\program files\Microsoft\BingBar\scripts\system\configcache.js
c:\program files\Microsoft\BingBar\scripts\system\configcacheproperties.js
c:\program files\Microsoft\BingBar\scripts\system\flightmanager.js
c:\program files\Microsoft\BingBar\scripts\system\platformsettings.js
c:\program files\Microsoft\BingBar\scripts\system\preamble.js
c:\program files\Microsoft\BingBar\scripts\system\settings.js
c:\program files\Microsoft\BingBar\scripts\system\toast.js
c:\program files\Microsoft\BingBar\scripts\system\toasthub.js
c:\program files\Microsoft\BingBar\scripts\system\toasthubQueue.js
c:\program files\Microsoft\BingBar\scripts\utility\utility.js
c:\program files\Microsoft\BingBar\SeaNote.dll
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_BBSvc
-------\Service_McComponentHostService
-------\Service_SkypeUpdate
-------\Service_SeaPort
-------\Service_SeaPort
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-04 do 2013-09-04 )))))))))))))))))))))))))))))))
.
.
2013-09-04 18:04 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC69EC05-AF7E-4790-B909-D94297929EF4}\mpengine.dll
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\pracovní Olda\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\Leonka\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-03 18:06 . 2013-09-04 18:05 -------- d-----w- c:\users\Olda\AppData\Local\temp
2013-09-03 17:59 . 2013-09-03 17:59 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6825F2A1-6DAD-44E9-B11B-06A242B1F688}\offreg.dll
2013-09-03 17:47 . 2013-09-03 17:47 26624 ----a-w- c:\windows\system32\TrueSight.sys
2013-09-03 17:06 . 2013-09-03 17:06 -------- d-----w- c:\windows\ERUNT
2013-09-03 15:50 . 2013-09-03 16:42 -------- d-----w- C:\AdwCleaner
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\users\Olda\AppData\Roaming\Malwarebytes
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\programdata\Malwarebytes
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-03 15:34 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\users\Olda\AppData\Local\Programs
2013-09-02 21:06 . 2013-09-02 21:06 388096 ----a-r- c:\users\Olda\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-09-02 21:06 . 2013-09-02 21:06 -------- d-----w- c:\program files\Trend Micro
2013-08-31 13:04 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6825F2A1-6DAD-44E9-B11B-06A242B1F688}\mpengine.dll
2013-08-07 09:01 . 2013-08-07 09:01 -------- d-----w- c:\users\Olda\AppData\Local\Application Data
2013-08-07 08:57 . 2013-08-09 09:02 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-07 08:57 . 2013-08-09 09:58 -------- d-----w- c:\program files\DAEMON Tools Lite
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-04 18:03 . 2010-10-22 10:29 17488 ----a-w- c:\windows\gdrv.sys
2013-08-07 02:22 . 2010-10-22 10:46 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-07-20 07:55 . 2012-03-31 15:27 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-20 07:55 . 2011-07-26 13:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-28 17:39 . 2013-03-22 06:39 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-28 17:39 . 2011-04-14 13:47 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-28 17:39 . 2010-11-20 22:09 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-11 23:43 . 2013-07-20 08:34 1767936 ----a-w- c:\windows\system32\wininet.dll
2013-06-11 23:43 . 2013-07-20 08:34 2877440 ----a-w- c:\windows\system32\jscript9.dll
2013-06-11 23:42 . 2013-07-20 08:34 61440 ----a-w- c:\windows\system32\iesetup.dll
2013-06-11 23:42 . 2013-07-20 08:34 109056 ----a-w- c:\windows\system32\iesysprep.dll
2013-06-11 22:51 . 2013-07-20 08:34 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-06-07 02:37 . 2013-07-20 08:34 2706432 ----a-w- c:\windows\system32\mshtml.tlb
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Livestation"="c:\program files\Livestation\Livestation.exe" [2010-06-24 4657152]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-08-15 5703920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-03 19603048]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-25 8522272]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-05-20 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
.
c:\users\pracovní Olda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
c:\users\Olda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
YoWindow.lnk - c:\program files\YoWindow\yowindow.exe -mt [2011-9-17 759808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2012-02-18 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Olda\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"BrowserChoice"="c:\windows\System32\browserchoice.exe" /run
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe"
"CLMLServer"="c:\program files\Cyberlink\Power2Go\CLMLSvc.exe"
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
.
R3 AODDriver;AODDriver;c:\program files\GIGABYTE\ET6\i386\AODDriver.sys [x]
R3 GVTDrv;GVTDrv;c:\windows\system32\Drivers\GVTDrv.sys [2010-10-22 24944]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-22 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-09 243128]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2012-02-18 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2012-02-18 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2012-09-13 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2009-07-30 68136]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-02-09 260640]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 550760]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 195944]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-29 18:33 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 07:55]
.
2013-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-22 11:34]
.
2013-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-22 11:34]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe
AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-3815227143-1898963522-1692809862-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3815227143-1898963522-1692809862-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-09-04 20:08:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-04 18:08
ComboFix2.txt 2013-09-03 18:10
.
Před spuštěním: Volných bajtů: 157 257 560 064
Po spuštění: Volných bajtů: 156 818 014 208
.
- - End Of File - - 05EC124E9C902EF9A3D83869A7E45ADA
8E734BD7AA1D4F7E9AF58DF495F6CF9E
c:\program files\Microsoft\BingBar\BingApp.exe
c:\program files\Microsoft\BingBar\BingBar.exe
c:\program files\Microsoft\BingBar\BingExt.dll
c:\program files\Microsoft\BingBar\common.dll
c:\program files\Microsoft\BingBar\defaultCache.txt
c:\program files\Microsoft\BingBar\DefMgr.dll
c:\program files\Microsoft\BingBar\Installers\BingBar7.0.609\BingBar.msi
c:\program files\Microsoft\BingBar\scripts\debug\trace.js
c:\program files\Microsoft\BingBar\scripts\io\downloader.js
c:\program files\Microsoft\BingBar\scripts\io\io.js
c:\program files\Microsoft\BingBar\scripts\main.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\appapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\appmanagementapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\apppackageapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\buttonapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\configurationapi.js
c:\program files\Microsoft\BingBar\scripts\objectmodel\servicesapi.js
c:\program files\Microsoft\BingBar\scripts\parsers\activeversionxml.js
c:\program files\Microsoft\BingBar\scripts\parsers\appmanifestxml.js
c:\program files\Microsoft\BingBar\scripts\parsers\json2.js
c:\program files\Microsoft\BingBar\scripts\parsers\xmlparser.js
c:\program files\Microsoft\BingBar\scripts\system\app.js
c:\program files\Microsoft\BingBar\scripts\system\appcatalog.js
c:\program files\Microsoft\BingBar\scripts\system\appcatalogcache.js
c:\program files\Microsoft\BingBar\scripts\system\appinstaller.js
c:\program files\Microsoft\BingBar\scripts\system\appmanager.js
c:\program files\Microsoft\BingBar\scripts\system\apppackage.js
c:\program files\Microsoft\BingBar\scripts\system\blockedapp.js
c:\program files\Microsoft\BingBar\scripts\system\buttonlayout.js
c:\program files\Microsoft\BingBar\scripts\system\configcache.js
c:\program files\Microsoft\BingBar\scripts\system\configcacheproperties.js
c:\program files\Microsoft\BingBar\scripts\system\flightmanager.js
c:\program files\Microsoft\BingBar\scripts\system\platformsettings.js
c:\program files\Microsoft\BingBar\scripts\system\preamble.js
c:\program files\Microsoft\BingBar\scripts\system\settings.js
c:\program files\Microsoft\BingBar\scripts\system\toast.js
c:\program files\Microsoft\BingBar\scripts\system\toasthub.js
c:\program files\Microsoft\BingBar\scripts\system\toasthubQueue.js
c:\program files\Microsoft\BingBar\scripts\utility\utility.js
c:\program files\Microsoft\BingBar\SeaNote.dll
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_BBSvc
-------\Service_McComponentHostService
-------\Service_SkypeUpdate
-------\Service_SeaPort
-------\Service_SeaPort
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-04 do 2013-09-04 )))))))))))))))))))))))))))))))
.
.
2013-09-04 18:04 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC69EC05-AF7E-4790-B909-D94297929EF4}\mpengine.dll
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\pracovní Olda\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\Leonka\AppData\Local\temp
2013-09-04 18:00 . 2013-09-04 18:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-03 18:06 . 2013-09-04 18:05 -------- d-----w- c:\users\Olda\AppData\Local\temp
2013-09-03 17:59 . 2013-09-03 17:59 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6825F2A1-6DAD-44E9-B11B-06A242B1F688}\offreg.dll
2013-09-03 17:47 . 2013-09-03 17:47 26624 ----a-w- c:\windows\system32\TrueSight.sys
2013-09-03 17:06 . 2013-09-03 17:06 -------- d-----w- c:\windows\ERUNT
2013-09-03 15:50 . 2013-09-03 16:42 -------- d-----w- C:\AdwCleaner
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\users\Olda\AppData\Roaming\Malwarebytes
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\programdata\Malwarebytes
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-03 15:34 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-03 15:34 . 2013-09-03 15:34 -------- d-----w- c:\users\Olda\AppData\Local\Programs
2013-09-02 21:06 . 2013-09-02 21:06 388096 ----a-r- c:\users\Olda\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-09-02 21:06 . 2013-09-02 21:06 -------- d-----w- c:\program files\Trend Micro
2013-08-31 13:04 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6825F2A1-6DAD-44E9-B11B-06A242B1F688}\mpengine.dll
2013-08-07 09:01 . 2013-08-07 09:01 -------- d-----w- c:\users\Olda\AppData\Local\Application Data
2013-08-07 08:57 . 2013-08-09 09:02 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-07 08:57 . 2013-08-09 09:58 -------- d-----w- c:\program files\DAEMON Tools Lite
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-04 18:03 . 2010-10-22 10:29 17488 ----a-w- c:\windows\gdrv.sys
2013-08-07 02:22 . 2010-10-22 10:46 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-07-20 07:55 . 2012-03-31 15:27 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-20 07:55 . 2011-07-26 13:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-28 17:39 . 2013-03-22 06:39 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-28 17:39 . 2011-04-14 13:47 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-28 17:39 . 2010-11-20 22:09 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-11 23:43 . 2013-07-20 08:34 1767936 ----a-w- c:\windows\system32\wininet.dll
2013-06-11 23:43 . 2013-07-20 08:34 2877440 ----a-w- c:\windows\system32\jscript9.dll
2013-06-11 23:42 . 2013-07-20 08:34 61440 ----a-w- c:\windows\system32\iesetup.dll
2013-06-11 23:42 . 2013-07-20 08:34 109056 ----a-w- c:\windows\system32\iesysprep.dll
2013-06-11 22:51 . 2013-07-20 08:34 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-06-07 02:37 . 2013-07-20 08:34 2706432 ----a-w- c:\windows\system32\mshtml.tlb
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Livestation"="c:\program files\Livestation\Livestation.exe" [2010-06-24 4657152]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-08-15 5703920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-03 19603048]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-25 8522272]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-05-20 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
.
c:\users\pracovní Olda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
c:\users\Olda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
YoWindow.lnk - c:\program files\YoWindow\yowindow.exe -mt [2011-9-17 759808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2012-02-18 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Olda\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"BrowserChoice"="c:\windows\System32\browserchoice.exe" /run
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe"
"CLMLServer"="c:\program files\Cyberlink\Power2Go\CLMLSvc.exe"
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
.
R3 AODDriver;AODDriver;c:\program files\GIGABYTE\ET6\i386\AODDriver.sys [x]
R3 GVTDrv;GVTDrv;c:\windows\system32\Drivers\GVTDrv.sys [2010-10-22 24944]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-22 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-09 243128]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2012-02-18 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2012-02-18 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2012-09-13 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2009-07-30 68136]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-02-09 260640]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 550760]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 195944]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-29 18:33 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 07:55]
.
2013-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-22 11:34]
.
2013-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-22 11:34]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe
AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-3815227143-1898963522-1692809862-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3815227143-1898963522-1692809862-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-09-04 20:08:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-04 18:08
ComboFix2.txt 2013-09-03 18:10
.
Před spuštěním: Volných bajtů: 157 257 560 064
Po spuštění: Volných bajtů: 156 818 014 208
.
- - End Of File - - 05EC124E9C902EF9A3D83869A7E45ADA
8E734BD7AA1D4F7E9AF58DF495F6CF9E
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Prosím o preventivní kontrolu logu HJT
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
+ Nový log z HJT
Jak se chová PC?
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
+ Nový log z HJT
Jak se chová PC?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Prosím o preventivní kontrolu logu HJT
Nedaří se mi odinstalovat ComboFix, když dám přes start Combofix / Uninstall a kliknu na ten Uninstall tak se Combofix spustí a chce vytvořit bod obnovy. Můžeš mi to prosím ještě jednou vysvětlit jak ho odinstalovat? Děkuji.
Re: Prosím o preventivní kontrolu logu HJT
Už je pryč
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Prosím o preventivní kontrolu logu HJT
Jak je na tom PC? Nový HJT ještě dej
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Prosím o preventivní kontrolu logu HJT
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:07:19, on 4.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\YoWindow\yowindow.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - (no file)
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Livestation] C:\Program Files\Livestation\Livestation.exe -startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
--
End of file - 8042 bytes
Scan saved at 23:07:19, on 4.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\YoWindow\yowindow.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - (no file)
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Livestation] C:\Program Files\Livestation\Livestation.exe -startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
--
End of file - 8042 bytes
Re: Prosím o preventivní kontrolu logu HJT
Počítač je v pořádku, šlape a zdá se, že je svižnější.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43292
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o preventivní kontrolu logu HJT
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Návod
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - (no file)
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o preventivní kontrolu logu HJT
Vše provedeno. Děkuji memphistovi, jaro 3 a všem, díky kterým fungují tyto výborné stránky. Jste machří, chtěl bych mít vaše znalosti. Ještě na závěr bych se zeptal, jak moc byl můj PC napaden a co byla nejzávžnější bezpečnostní hrozba. Díky.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43292
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o preventivní kontrolu logu HJT
Totálně nakažení spočívalo hlavně v PUP.Optional.SearchProtect.A (vyskakovací okna-Adware) , další infikace toolbarů , klíčů ap.
Vše je v lozích.
Vše je v lozích.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o preventivní kontrolu logu HJT Vyřešeno
Ještě jednou díky.
Kdo je online
Uživatelé prohlížející si toto fórum: Google [Bot] a 96 hostů