{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} (IE Tracking Shell Menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: IE Tracking Shell Menu
CLSID name: IE Tracking Shell Menu
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{44C76ECD-F7FA-411c-9929-1B77BA77F524} (IE Menu Site)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: IE Menu Site
CLSID name: IE Menu Site
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{205D7A97-F16D-4691-86EF-F3075DCCA57D} (IE Menu Desk Bar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: IE Menu Desk Bar
CLSID name: IE Menu Desk Bar
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{871C5380-42A0-1069-A2EA-08002B30309D} (Internet Name Space)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Internet Name Space
CLSID name:
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} (IE RSS Feeder Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: IE RSS Feeder Folder
CLSID name: IE RSS Feeds Folder
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{8856f961-340a-11d0-a96b-00c04fd705a2} (Microsoft Web Browser)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Web Browser
CLSID name: Microsoft Web Browser
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{3050f3d9-98b5-11cf-bb82-00aa00bdce0b} (MSHTML Document)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: MSHTML Document
CLSID name: MHTML Document
Path: C:\Windows\system32\
Long name: mshtml.dll
Short name:
Date (created): 10.1.2009 20:57:30
Date (last access): 10.1.2009 20:57:30
Date (last write): 2.10.2008 4:49:16
Filesize: 3578880
Attributes: archive
MD5: 3E3D3E24BD1F862CD1A772C0DAD3F134
CRC32: 2617EB40
Version: 7.0.6001.18148
{25336920-03f9-11cf-8fd0-00aa00686f13} (HTML Document)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: HTML Document
CLSID name: HTML Document
Path: C:\Windows\system32\
Long name: mshtml.dll
Short name:
Date (created): 10.1.2009 20:57:30
Date (last access): 10.1.2009 20:57:30
Date (last write): 2.10.2008 4:49:16
Filesize: 3578880
Attributes: archive
MD5: 3E3D3E24BD1F862CD1A772C0DAD3F134
CRC32: 2617EB40
Version: 7.0.6001.18148
{b2c761c6-29bc-4f19-9251-e6195265baf1} (Color Control Panel Applet)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Color Control Panel Applet
CLSID name: Color Control Panel Applet
MD5: D41D8CD98F00B204E9800998ECF8427E
{36eef7db-88ad-4e81-ad49-0e313f0c35f8} (Windows Update)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Update
CLSID name: Windows Update
Path: %SystemRoot%\system32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{74246bfc-4c96-11d0-abef-0020af6b0b7a} (Device Manager)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Device Manager
CLSID name: Device Manager
Path: %SystemRoot%\System32\
Long name: devmgr.dll
MD5: 9E6707CAC0A742A0B13C6D238532AD18
Filesize: 377344
{7A979262-40CE-46ff-AEEE-7884AC3B6136} (Add New Hardware)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Add New Hardware
CLSID name: Add New Hardware
MD5: D41D8CD98F00B204E9800998ECF8427E
{7b81be6a-ce2b-4676-a29e-eb907a5126c5} (Programs and Features)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Programs and Features
CLSID name: Programs and Features
Path: %SystemRoot%\System32\
Long name: appwiz.cpl
MD5: 9D28DF863A02971D3FA8B4C1F4DFC785
Filesize: 1122304
{15eae92e-f17a-4431-9f28-805e482dafd4} (Install New Programs)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Install New Programs
CLSID name: Install New Programs
Path: %SystemRoot%\System32\
Long name: appwiz.cpl
MD5: 9D28DF863A02971D3FA8B4C1F4DFC785
Filesize: 1122304
{0BFCF7B7-E7B6-433a-B205-2904FCF040DD} (New Shortcut Wizard Modal)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: New Shortcut Wizard Modal
CLSID name: New Shortcut Wizard Modal
Path: %SystemRoot%\System32\
Long name: appwiz.cpl
MD5: 9D28DF863A02971D3FA8B4C1F4DFC785
Filesize: 1122304
{3e7efb4c-faf1-453d-89eb-56026875ef90} (Get Programs Online)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Get Programs Online
CLSID name: Get Programs Online
MD5: D41D8CD98F00B204E9800998ECF8427E
{44f3dab6-4392-4186-bb7b-6282ccb7a9f6} (MyDocuments menu and properties)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: MyDocuments menu and properties
CLSID name: MyDocuments menu and properties
Path: %SystemRoot%\system32\
Long name: mydocs.dll
MD5: F30D5EE1426D519F0C6E41A24C51D7AD
Filesize: 135680
{3080F90D-D7AD-11D9-BD98-0000947B0257} (Show Desktop)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Show Desktop
CLSID name: Show Desktop
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{3080F90E-D7AD-11D9-BD98-0000947B0257} (Window Switcher)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Window Switcher
CLSID name: Window Switcher
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{eb124705-128b-40d4-8dd8-d93ed12589a4} (WPL property store)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: WPL property store
CLSID name: WPL property store
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{3c2654c6-7372-4f6b-b310-55d6128f49d2} (Alphabetical Categorizer)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Alphabetical Categorizer
CLSID name: Alphabetical Categorizer
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{9DBD2C50-62AD-11d0-B806-00C04FD706EC} (Summary Info Thumbnail handler (DOCFILES))
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Summary Info Thumbnail handler (DOCFILES)
CLSID name: Property Thumbnail Handler
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{708e1662-b832-42a8-bbe1-0a77121e3908} (Tree property value folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Tree property value folder
CLSID name: Tree property value folder
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{71f96385-ddd6-48d3-a0c1-ae06e8b055fb} (Explorer Browser)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Explorer Browser
CLSID name: Explorer Browser
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{b2952b16-0e07-4e5a-b993-58c52cb94cae} (Search Folders)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Search Folders
CLSID name: DB Folder
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{437ff9c0-a07f-4fa0-af80-84b6c6440a16} (Command Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Command Folder
CLSID name: Command Folder
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{90f8c90b-04e0-4e92-a186-e6e9c125d664} (Property Labels)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Property Labels
CLSID name: Property Labels
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{C8494E42-ACDD-4739-B0FB-217361E4894F} (Sam Account Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sam Account Folder
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{E29F9716-5C08-4FCD-955A-119FDB5A522D} (Sam Account Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sam Account Folder
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{b155bdf8-02f0-451e-9a26-ae317cfd7779} (nethood delegate folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: nethood delegate folder
CLSID name: delegate folder that appears in Computer
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{DFFACDC5-679F-4156-8947-C5C76BC0B67F} (users files delegate folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: users files delegate folder
CLSID name: delegate folder that appears in Users Files Folder
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{ed50fc29-b964-48a9-afb3-15ebb9b97f36} (printhood delegate folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: printhood delegate folder
CLSID name: printhood delegate folder
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{328B0346-7EAF-4BBE-A479-7CB88A095F5B} (Layout Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Layout Folder
CLSID name: LayoutFolder
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} (Control Panel command object for Start menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Control Panel command object for Start menu
CLSID name: Control Panel command object for Start menu
MD5: D41D8CD98F00B204E9800998ECF8427E
{E44E5D18-0652-4508-A4E2-8A090067BCB0} (Default Programs command object for Start menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Default Programs command object for Start menu
CLSID name: Default Programs command object for Start menu
MD5: D41D8CD98F00B204E9800998ECF8427E
{4336a54d-038b-4685-ab02-99bb52d3fb8b} (Public Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Public Folder
CLSID name:
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{00021401-0000-0000-C000-000000000046} (Shortcut)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Shortcut
CLSID name: Shortcut
Path:
Long name: shell32.dll
Short name:
Date (created): 28.12.2008 13:20:18
Date (last access): 28.12.2008 13:20:18
Date (last write): 6.11.2008 14:14:26
Filesize: 11580928
Attributes: archive
MD5: 5D62692EEB77E32F67A966F1BDEB551B
CRC32: CE4BF6CB
Version: 6.0.6001.18167
{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9} (Search Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Search Folder
CLSID name:
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B} (.fon, .otf, .ttc or .ttf files)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: .fon, .otf, .ttc or .ttf files
CLSID name:
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{66742402-F9B9-11D1-A202-0000F81FEDEE} (.cpl, .dll, .exe, .ocx, .rll or .sys files)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: .cpl, .dll, .exe, .ocx, .rll or .sys files
CLSID name:
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{D34A6CA6-62C2-4C34-8A7C-14709C1AD938} (Common Places Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Common Places Folder
CLSID name: Common Places FS Folder
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{865e5e76-ad83-4dca-a109-50dc2113ce9a} (Programs Folder and Fast Items)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Programs Folder and Fast Items
CLSID name: Programs Folder and Fast Items
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{21ec2020-3aea-1069-a2dd-08002b30309d} (Control Panel)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Control Panel
CLSID name: Control Panel
Path:
Long name: shell32.dll
Short name:
Date (created): 28.12.2008 13:20:18
Date (last access): 28.12.2008 13:20:18
Date (last write): 6.11.2008 14:14:26
Filesize: 11580928
Attributes: archive
MD5: 5D62692EEB77E32F67A966F1BDEB551B
CRC32: CE4BF6CB
Version: 6.0.6001.18167
{25585dc7-4da0-438d-ad04-e42c8d2d64b9} (Client application shell extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Client application shell extension
CLSID name: Client application shell extension
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{6dfd7c5c-2451-11d3-a299-00c04f8ef6af} (Folder Options)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Folder Options
CLSID name: Folder Options
MD5: D41D8CD98F00B204E9800998ECF8427E
{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3} (Microsoft Windows RTF Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows RTF Preview Handler
CLSID name: Microsoft Windows RTF Preview Handler
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{1531d583-8375-4d3f-b5fb-d23bbd169f22} (Window TXT Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Window TXT Preview Handler
CLSID name: Microsoft Windows TXT Preview Handler
Path: %SystemRoot%\system32\
Long name: shell32.dll
MD5: 5D62692EEB77E32F67A966F1BDEB551B
Filesize: 11580928
{97e467b4-98c6-4f19-9588-161b7773d6f6} (Office Document Property Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Office Document Property Handler
CLSID name: Office Document Property Handler
Path: %SystemRoot%\system32\
Long name: propsys.dll
MD5: 89D74683C859B7982056D15938BACA3E
Filesize: 754176
{056440FD-8568-48e7-A632-72157243B55B} (Explorer Navigation Bar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Explorer Navigation Bar
CLSID name: Explorer Navigation Bar
Path: %SystemRoot%\system32\
Long name: browseui.dll
MD5: A3C1B75B0156D5B68B271C6FE0A5FDE7
Filesize: 1324032
{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980} (Explorer Travel Band)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Explorer Travel Band
CLSID name: Explorer Travel Band
Path: %SystemRoot%\system32\
Long name: browseui.dll
MD5: A3C1B75B0156D5B68B271C6FE0A5FDE7
Filesize: 1324032
{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F} (Explorer Search Band)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Explorer Search Band
CLSID name: Explorer Search Band
Path: %SystemRoot%\system32\
Long name: browseui.dll
MD5: A3C1B75B0156D5B68B271C6FE0A5FDE7
Filesize: 1324032
{2C2577C2-63A7-40e3-9B7F-586602617ECB} (Explorer Query Band)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Explorer Query Band
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{a542e116-8088-4146-a352-b0d06e7f6af6} (Address EditBox)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Address EditBox
CLSID name: Address EditBox
Path: %SystemRoot%\system32\
Long name: browseui.dll
MD5: A3C1B75B0156D5B68B271C6FE0A5FDE7
Filesize: 1324032
{596742A5-1393-4e13-8765-AE1DF71ACAFB} (Microsoft Breadcrumb Bar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Breadcrumb Bar
CLSID name: Microsoft Breadcrumb Bar
Path: %SystemRoot%\system32\
Long name: browseui.dll
MD5: A3C1B75B0156D5B68B271C6FE0A5FDE7
Filesize: 1324032
{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} (File Open Dialog)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: File Open Dialog
CLSID name: File Open Dialog
Path: %SystemRoot%\System32\
Long name: comdlg32.dll
MD5: D71266E0E06421E81CA85F2346B7EE9E
Filesize: 450048
{e82a2d71-5b2f-43a0-97b8-81be15854de8} (ShellLink for Application References)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: ShellLink for Application References
CLSID name: ShellLink for Application References
Path: C:\Windows\system32\
Long name: dfshim.dll
Short name:
Date (created): 28.12.2008 16:54:24
Date (last access): 28.12.2008 16:54:24
Date (last write): 27.7.2008 19:03:18
Filesize: 96760
Attributes: archive
MD5: B6C9A03E1BA3E74E33633369B35AE526
CRC32: 58C7E665
Version: 2.0.50727.3053
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} (Shell Icon Handler for Application References)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Shell Icon Handler for Application References
CLSID name: Shell Icon Handler for Application References
Path: C:\Windows\system32\
Long name: dfshim.dll
Short name:
Date (created): 28.12.2008 16:54:24
Date (last access): 28.12.2008 16:54:24
Date (last write): 27.7.2008 19:03:18
Filesize: 96760
Attributes: archive
MD5: B6C9A03E1BA3E74E33633369B35AE526
CRC32: 58C7E665
Version: 2.0.50727.3053
{92337A8C-E11D-11D0-BE48-00C04FC30DF6} (OlePrn.PrinterURL)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: OlePrn.PrinterURL
CLSID name: prturl Class
Path: %SystemRoot%\system32\
Long name: oleprn.dll
MD5: 4162BB9EF08F8B2658DA85906CBB1D90
Filesize: 96768
{44121072-A222-48f2-A58A-6D9AD51EBBE9} (Microsoft XPS Thumbnail)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft XPS Thumbnail
CLSID name:
Path: %SystemRoot%\system32\
Long name: XPSSHHDR.DLL
MD5: 4A149599A7336DF7ED588761F4A8CFA8
Filesize: 574976
{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b} (View Available Networks)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: View Available Networks
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{13D3C4B8-B179-4ebb-BF62-F704173E7448} (Windows Contact Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Contact Preview Handler
CLSID name: CLSID_ContactReadingPane
Path: %CommonProgramFiles%\System\
Long name: wab32.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} (Contacts folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Contacts folder
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{4F58F63F-244B-4c07-B29F-210BE59BE9B4} (.group shell extension handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: .group shell extension handler
CLSID name: .group shell extension handler
Path: %CommonProgramFiles%\System\
Long name: wab32.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{8082C5E6-4C27-48ec-A809-B8E1122E8F97} (.contact shell extension handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: .contact shell extension handler
CLSID name: .contact shell extension handler
Path: %CommonProgramFiles%\System\
Long name: wab32.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{16C2C29D-0E5F-45f3-A445-03E03F587B7D} (group_wab_auto_file)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: group_wab_auto_file
CLSID name: .group shell context menu
Path: %CommonProgramFiles%\System\
Long name: wab32.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{CF67796C-F57F-45F8-92FB-AD698826C602} (contact_wab_auto_file)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: contact_wab_auto_file
CLSID name: .contact shell context menu
Path: %CommonProgramFiles%\System\
Long name: wab32.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{fcfeecae-ee1b-4849-ae50-685dcf7717ec} (Problem Reports and Solutions)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Problem Reports and Solutions
CLSID name: Problem Reports and Solutions
MD5: D41D8CD98F00B204E9800998ECF8427E
{4026492f-2f69-46b8-b9bf-5654fc07e423} (Windows Firewall)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Firewall
CLSID name: Windows Firewall
MD5: D41D8CD98F00B204E9800998ECF8427E
{D555645E-D4F8-4c29-A827-D93C859C4F2A} (Ease of Access)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Ease of Access
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{60254CA5-953B-11CF-8C96-00AA00B8708C} (Shell extensions for Windows Script Host)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Shell extensions for Windows Script Host
CLSID name: Shell Extension For Windows Script Host
Path: C:\Windows\system32\
Long name: wshext.dll
Short name:
Date (created): 28.12.2008 13:03:38
Date (last access): 28.12.2008 13:03:38
Date (last write): 8.5.2008 22:59:36
Filesize: 90112
Attributes: archive
MD5: F825B8CEC8523C7542C2E397D31DB292
CRC32: D20B93B4
Version: 5.7.0.18068
{a304259d-52b8-4526-8b1a-a1d6cecc8243} (iSCSI Initiator)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: iSCSI Initiator
CLSID name: iSCSI Initiator
MD5: D41D8CD98F00B204E9800998ECF8427E
{8E908FC9-BECC-40f6-915B-F4CA0E70D03D} (Network and Sharing Center)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Network and Sharing Center
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{025A5937-A6BE-4686-A844-36FE4BEC8B6D} (Microsoft Power Options)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Power Options
CLSID name: Power Options
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{BB06C0E4-D293-4f75-8A90-CB05B6477EEE} (System)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: System
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} (Personalization CPL Provider)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Personalization CPL Provider
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{17cd9488-1228-4b2f-88ce-4298e93e0966} (Set User Defaults)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Set User Defaults
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{60632754-c523-4b62-b45c-4172da012619} (User Accounts)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: User Accounts
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{9C60DE1E-E5FC-40f4-A487-460851A8D915} (AutoPlay)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: AutoPlay
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{11dbb47c-a525-400b-9e80-a54615a090c0} (Execute Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Execute Folder
CLSID name: CLSID_ExecuteFolder
Path:
Long name: ExplorerFrame.dll
Short name:
Date (created): 20.4.2008 11:41:08
Date (last access): 20.4.2008 11:41:08
Date (last write): 20.4.2008 11:41:08
Filesize: 20992
Attributes: archive
MD5: B43DC259D9D66075D0E1BCB8A235CBBD
CRC32: 036D9E6F
Version: 6.0.6001.18000
{90b9bce2-b6db-4fd3-8451-35917ea1081b} (Search Execute Command)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Search Execute Command
CLSID name: CLSID_SearchExecute
Path:
Long name: ExplorerFrame.dll
Short name:
Date (created): 20.4.2008 11:41:08
Date (last access): 20.4.2008 11:41:08
Date (last write): 20.4.2008 11:41:08
Filesize: 20992
Attributes: archive
MD5: B43DC259D9D66075D0E1BCB8A235CBBD
CRC32: 036D9E6F
Version: 6.0.6001.18000
{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E} (Microsoft Windows Font File Icon Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows Font File Icon Handler
CLSID name: Microsoft Windows Font File Icon Handler
Path:
Long name: fontext.dll
Short name:
Date (created): 20.4.2008 11:44:42
Date (last access): 20.4.2008 11:44:42
Date (last write): 20.4.2008 11:44:42
Filesize: 142336
Attributes: archive
MD5: 30E6F401DF9897B20006FE095B436FAE
CRC32: 0E00F75B
Version: 6.0.6001.18000
{1a184871-359e-4f67-aad9-5b9905d62232} (Microsoft Windows Font File Context Menu Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows Font File Context Menu Handler
CLSID name: Microsoft Windows Font Context Menu Handler
Path:
Long name: fontext.dll
Short name:
Date (created): 20.4.2008 11:44:42
Date (last access): 20.4.2008 11:44:42
Date (last write): 20.4.2008 11:44:42
Filesize: 142336
Attributes: archive
MD5: 30E6F401DF9897B20006FE095B436FAE
CRC32: 0E00F75B
Version: 6.0.6001.18000
{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01} (Microsoft Windows Font Previewer)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows Font Previewer
CLSID name: Microsoft Windows Font Preview Handler
Path:
Long name: fontext.dll
Short name:
Date (created): 20.4.2008 11:44:42
Date (last access): 20.4.2008 11:44:42
Date (last write): 20.4.2008 11:44:42
Filesize: 142336
Attributes: archive
MD5: 30E6F401DF9897B20006FE095B436FAE
CRC32: 0E00F75B
Version: 6.0.6001.18000
{911051fa-c21c-4246-b470-070cd8df6dc4} (.cab or .zip files)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: .cab or .zip files
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{da67b8ad-e81b-4c70-9b91b417b5e33527} (Windows Search Shell Service)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Search Shell Service
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{a38b883c-1682-497e-97b0-0a3a9e801682} (IPropertyStore Handler for Images)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: IPropertyStore Handler for Images
CLSID name: IPropertyStore Handler for Images
Path: C:\Windows\system32\
Long name: PhotoMetadataHandler.dll
Short name:
Date (created): 28.12.2008 13:20:08
Date (last access): 28.12.2008 13:20:08
Date (last write): 28.8.2008 4:40:10
Filesize: 425472
Attributes: archive
MD5: B1DD63E030763B63EE78E97054375F8E
CRC32: E0AA7784
Version: 6.0.6001.18131
{C7657C4A-9F68-40fa-A4DF-96BC08EB3551} (Photo Thumbnail Provider)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Photo Thumbnail Provider
CLSID name: Photo Thumbnail Provider
Path: C:\Windows\system32\
Long name: PhotoMetadataHandler.dll
Short name:
Date (created): 28.12.2008 13:20:08
Date (last access): 28.12.2008 13:20:08
Date (last write): 28.8.2008 4:40:10
Filesize: 425472
Attributes: archive
MD5: B1DD63E030763B63EE78E97054375F8E
CRC32: E0AA7784
Version: 6.0.6001.18131
{3F30C968-480A-4C6C-862D-EFC0897BB84B} (Photo Thumbnail Extractor)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Photo Thumbnail Extractor
CLSID name: Photo Extract Image
Path: C:\Windows\system32\
Long name: PhotoMetadataHandler.dll
Short name:
Date (created): 28.12.2008 13:20:08
Date (last access): 28.12.2008 13:20:08
Date (last write): 28.8.2008 4:40:10
Filesize: 425472
Attributes: archive
MD5: B1DD63E030763B63EE78E97054375F8E
CRC32: E0AA7784
Version: 6.0.6001.18131
{BC65FB43-1958-4349-971A-210290480130} (Network Explorer Property Sheet Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Network Explorer Property Sheet Handler
CLSID name: Ncd Property Page
Path: %SystemRoot%\System32\
Long name: NcdProp.dll
MD5: FAC2D28000A685B43185F55BEB93AA0D
Filesize: 19968
{d3e34b21-9d75-101a-8c3d-00aa001a1652} (Bitmap Image)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Bitmap Image
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{E598560B-28D5-46aa-A14A-8A3BEA34B576} (Windows Photo Gallery Viewer Video Verbs)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Photo Gallery Viewer Video Verbs
CLSID name: Windows Photo Gallery Viewer Video Verbs
Path: %ProgramFiles%\Windows Photo Gallery\
Long name: PhotoViewer.dll
MD5: 2AAD5D8541ABFD8EC8877773291250AC
Filesize: 2314240
{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3} (Microsoft.ScannersAndCameras)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft.ScannersAndCameras
CLSID name: Scanner and Camera Control Panel
MD5: D41D8CD98F00B204E9800998ECF8427E
{0a4286ea-e355-44fb-8086-af3df7645bd9} (Windows Media Player)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player
CLSID name: &Windows Media Player
Path: C:\PROGRA~1\WI4EB4~1\
Long name: wmpband.dll
Short name:
Date (created): 20.4.2008 11:47:58
Date (last access): 20.4.2008 11:47:58
Date (last write): 20.4.2008 11:47:58
Filesize: 273408
Attributes: archive
MD5: 0A98F049E858B6E5B10B128EAD6107C4
CRC32: E76F58B6
Version: 11.0.6001.7000
{BB6B2374-3D79-41DB-87F4-896C91846510} (EMDFileProperties)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: EMDFileProperties
CLSID name:
Path:
Long name: emdmgmt.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{E95A4861-D57A-4be1-AD0F-35267E261739} (Windows SideShow)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Windows SideShow
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{89D83576-6BD1-4c86-9454-BEB04E94C819} (MAPI Search Namespace Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: MAPI Search Namespace Extension
CLSID name: @%systemroot%\system32\mssvp.dll,-110
Path: %systemroot%\system32\
Long name: mssvp.dll
MD5: AC32DC4D4552151D6842B678D52EB9B7
Filesize: 670208
{7A0F6AB7-ED84-46B6-B47E-02AA159A152B} (Sync Center Simple Conflict Presenter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Simple Conflict Presenter
CLSID name: Simple Conflict Presenter
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{9D687A4C-1404-41ef-A089-883B6FBECDE6} (Windows Photo Gallery Viewer Autoplay Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Photo Gallery Viewer Autoplay Handler
CLSID name: Windows Photo Gallery Viewer Autoplay Handler
MD5: D41D8CD98F00B204E9800998ECF8427E
{D9EF8727-CAC2-4e60-809E-86F80A666C91} (BitLocker Drive Encryption CPL)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: BitLocker Drive Encryption CPL
CLSID name: Secure Startup
Path: %SystemRoot%\system32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{37efd44d-ef8d-41b1-940d-96973a50e9e0} (Windows Sidebar Properties)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Sidebar Properties
CLSID name: Windows Sidebar Properties
MD5: D41D8CD98F00B204E9800998ECF8427E
{00f20eb5-8fd6-4d9d-b75e-36801766c8f1} (PhotoAcqDropTarget)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: PhotoAcqDropTarget
CLSID name: PhotoAcqDropTarget
Path: %ProgramFiles%\Windows Photo Gallery\
Long name: PhotoAcq.dll
MD5: B5D79B4F81DAA75BBB3DD9F481ADF41B
Filesize: 1030144
{BC48B32F-5910-47F5-8570-5074A8A5636A} (Sync Results Delegate Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Results Delegate Folder
CLSID name: Sync Results Delegate Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{ED228FDF-9EA8-4870-83B1-96B02CFE0D52} (Games Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Games Folder
CLSID name: @C:\Windows\System32\shell32.dll,-30579
Path: C:\Windows\System32\
Long name: gameux.dll
Short name:
Date (created): 28.12.2008 13:19:24
Date (last access): 28.12.2008 13:19:24
Date (last write): 8.3.2008 5:21:56
Filesize: 1695744
Attributes: archive
MD5: 94A92ADE4BB64E24C668645F5B9A6FCA
CRC32: 9F71AEBD
Version: 6.0.6001.18032
{E413D040-6788-4C22-957E-175D1C513A34} (Sync Center Conflict Delegate Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Conflict Delegate Folder
CLSID name: Sync Center Conflict Delegate Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{4E77131D-3629-431c-9818-C5679DC83E81} (Offline Files Icon Overlay Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Offline Files Icon Overlay Handler
CLSID name:
Path: %SystemRoot%\System32\
Long name: cscui.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{67718415-c450-4f3c-bf8a-b487642dc39b} (Windows Features)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Features
CLSID name: Windows Features
MD5: D41D8CD98F00B204E9800998ECF8427E
{335a31dd-f04b-4d76-a925-d6b47cf360df} (Backup and Restore Center)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Backup and Restore Center
Path: %SystemRoot%\system32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{91ADC906-6722-4B05-A12B-471ADDCCE132} (Touch Band)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Touch Band
CLSID name: Touch Pointer
Path: %SystemRoot%\System32\
Long name: TouchX.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{2781761E-28E0-4109-99FE-B9D127C57AFE} (Windows Defender IOfficeAntiVirus implementation)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Defender IOfficeAntiVirus implementation
CLSID name: Windows Defender IOfficeAntiVirus implementation
Path: %ProgramFiles%\Windows Defender\
Long name: MpOav.dll
MD5: B7DC98F6F4E7611A9C0849945FB28FB9
Filesize: 90680
{7D4734E6-047E-41e2-AEAA-E763B4739DC4} (Windows Media Player Play as Playlist Context Menu Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player Play as Playlist Context Menu Handler
CLSID name: WMP Play Folder As Playlist Launcher
Path: %SystemRoot%\system32\
Long name: wmpshell.dll
MD5: 0143E15F94FD523C588EDD47609F905F
Filesize: 101376
{96AE8D84-A250-4520-95A5-A47A7E3C548B} (Parental Controls)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Parental Controls
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
Prosím zkontrolujte log Vyřešeno
Re: Prosím zkontrolujte log
{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A} (Windows Photo Gallery Viewer Image Verbs)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Photo Gallery Viewer Image Verbs
CLSID name: Windows Photo Gallery Viewer Image Verbs
Path: %ProgramFiles%\Windows Photo Gallery\
Long name: PhotoViewer.dll
MD5: 2AAD5D8541ABFD8EC8877773291250AC
Filesize: 2314240
{4B534112-3AF6-4697-A77C-D62CE9B9E7CF} (Sync Center Event Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Event Properties Extension
CLSID name: Sync Center Event Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C} (Sync Setup Delegate Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Setup Delegate Folder
CLSID name: Sync Setup Delegate Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} (Offline Files Context Menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Offline Files Context Menu
CLSID name:
Path: %SystemRoot%\System32\
Long name: cscui.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A} (GameUX.RichGameMediaThumbnail)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: GameUX.RichGameMediaThumbnail
CLSID name: RichGameMediaThumbnail Class
Path: C:\Windows\System32\
Long name: gameux.dll
Short name:
Date (created): 28.12.2008 13:19:24
Date (last access): 28.12.2008 13:19:24
Date (last write): 8.3.2008 5:21:56
Filesize: 1695744
Attributes: archive
MD5: 94A92ADE4BB64E24C668645F5B9A6FCA
CRC32: 9F71AEBD
Version: 6.0.6001.18032
{7EFA68C6-086B-43e1-A2D2-55A113531240} (Offline Files Property Sheet Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Offline Files Property Sheet Extension
CLSID name:
Path: %SystemRoot%\System32\
Long name: cscui.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{d8559eb9-20c0-410e-beda-7ed416aecc2a} (Windows Defender)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Defender
CLSID name: Windows Defender
MD5: D41D8CD98F00B204E9800998ECF8427E
{576C9E85-1300-4EF5-BF6B-D00509F4EDCD} (Sync Center Handler Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Handler Properties Extension
CLSID name: Sync Center Handler Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{289978AC-A101-4341-A817-21EBA7FD046D} (Sync Center Conflict Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Conflict Folder
CLSID name: Sync Center Conflict Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{5ea4f148-308c-46d7-98a9-49041b1dd468} (Mobility Center Control Panel)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Mobility Center Control Panel
CLSID name: Mobility Center Control Panel
MD5: D41D8CD98F00B204E9800998ECF8427E
{71D99464-3B6B-475C-B241-E15883207529} (Sync Results Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Results Folder
CLSID name: Sync Results Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{877ca5ac-cb41-4842-9c69-9136e42d47e2} (File Backup Index)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: File Backup Index
CLSID name: File Backup Index
Path: %systemroot%\system32\
Long name: sdshext.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{B32D3949-ED98-4DBB-B347-17A144969BBA} (Sync Center Item Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Item Properties Extension
CLSID name: Sync Center Item Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} (Portable Devices Menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Portable Devices Menu
CLSID name: Portable Devices Menu
Path: %SystemRoot%\system32\
Long name: wpdshext.dll
MD5: 689C2A3B8C6CBC64E6959C7C858B742C
Filesize: 2537472
{58E3C745-D971-4081-9034-86E34B30836A} (Speech Recognition Options)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Speech Recognition Options
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{2E9E59C0-B437-4981-A647-9C34B9B90891} (Sync Setup Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Setup Folder
CLSID name: Sync Setup Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{4D1209BD-36E2-4e2f-840D-6C7FB879DD9E} (Windows Ultimate Extras)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Windows Ultimate Extras
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} (Sync Center Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Folder
CLSID name: Sync Center Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1} (Welcome Center)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Welcome Center
CLSID name: Welcome Center
Path:
Long name: oobefldr.dll
Short name:
Date (created): 20.4.2008 11:37:00
Date (last access): 20.4.2008 11:37:00
Date (last write): 20.4.2008 11:37:00
Filesize: 2153472
Attributes: archive
MD5: 83E4A5435B0FA6AD0166722621A04725
CRC32: 48B1D434
Version: 6.0.6001.18000
{78F3955E-3B90-4184-BD14-5397C15F1EFC} (Performance Information and Tools)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Performance Information and Tools
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{F04CC277-03A2-4277-96A9-77967471BDFF} (Sync Center Conflict Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Conflict Properties Extension
CLSID name: Sync Center Conflict Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{53BEDF0B-4E5B-4183-8DC9-B844344FA104} (Microsoft Windows MAPI Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows MAPI Preview Handler
CLSID name: MAPI Mail Previewer
Path: %SystemRoot%\system32\
Long name: mssvp.dll
MD5: AC32DC4D4552151D6842B678D52EB9B7
Filesize: 670208
{8E25992B-373E-486E-80E5-BD23AE417E66} (Sync Center Device Notification Sink)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Device Notification Sink
CLSID name: Sync Center Device Notification Sink
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{6b9228da-9c15-419e-856c-19e768a13bdc} (Windows gadget DropTarget)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows gadget DropTarget
CLSID name: Windows gadget DropTarget
Path: %ProgramFiles%\Windows Sidebar\
Long name: sbdrop.dll
MD5: A74701976D6D75099B9FCA993685C452
Filesize: 66048
{031EE060-67BC-460d-8847-E4A7C5E45A27} (Windows Media Player Rich Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player Rich Preview Handler
CLSID name: Windows Media Player Rich Preview Handler
MD5: D41D8CD98F00B204E9800998ECF8427E
{1FA9085F-25A2-489B-85D4-86326EEDCD87} (Manage Wireless Networks)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Manage Wireless Networks
CLSID name: Manage Wireless Networks
Path: %SystemRoot%\system32\
Long name: wlanpref.dll
MD5: CFB1737C17BA3172D490F26A4CD17781
Filesize: 1671680
{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60} (RichGameMediaPropertyStore Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: RichGameMediaPropertyStore Class
CLSID name: RichGameMediaPropertyStore Class
Path: C:\Windows\System32\
Long name: gameux.dll
Short name:
Date (created): 28.12.2008 13:19:24
Date (last access): 28.12.2008 13:19:24
Date (last write): 8.3.2008 5:21:56
Filesize: 1695744
Attributes: archive
MD5: 94A92ADE4BB64E24C668645F5B9A6FCA
CRC32: 9F71AEBD
Version: 6.0.6001.18032
{BD7A2E7B-21CB-41b2-A086-B309680C6B7E} (Client Side Cache Namespace Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Client Side Cache Namespace Extension
CLSID name: @%systemroot%\system32\mssvp.dll,-112
Path: %systemroot%\system32\
Long name: mssvp.dll
MD5: AC32DC4D4552151D6842B678D52EB9B7
Filesize: 670208
{8A734961-C4AA-4741-AC1E-791ACEBF5B39} (Windows Media Player Shop Music Context Menu Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player Shop Music Context Menu Handler
CLSID name:
Path: %SystemRoot%\system32\
Long name: wmpshell.dll
MD5: 0143E15F94FD523C588EDD47609F905F
Filesize: 101376
{5E2121EE-0300-11D4-8D3B-444553540000} (Catalyst Context Menu extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Catalyst Context Menu extension
CLSID name: SimpleShlExt Class
Path: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\
Long name: atiacm64.dll
Short name:
Date (created): 19.11.2008 14:54:16
Date (last access): 5.1.2009 20:35:44
Date (last write): 19.11.2008 14:54:16
Filesize: 867840
Attributes: archive
MD5: DCD4F9B57F0E55592C108DF8DDBD0B3B
CRC32: E3BC156E
Version: 6.14.10.2001
{23170F69-40C1-278A-1000-000100020000} (7-Zip Shell Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: 7-Zip Shell Extension
CLSID name:
Path: C:\Program Files\7-Zip\
Long name: 7-zip.dll
Short name:
Date (created): 2.12.2008 12:10:56
Date (last access): 25.12.2008 15:27:08
Date (last write): 2.12.2008 12:10:56
Filesize: 105472
Attributes: archive
MD5: 28DB80D546B87A953F216286D4103BD1
CRC32: 4BA4B4A8
Version: 4.62.0.0
{B089FE88-FB52-11D3-BDF1-0050DA34150D} (Eset Smart Security - Context Menu Shell Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Eset Smart Security - Context Menu Shell Extension
CLSID name: Eset Smart Security - Context Menu Shell Extension
Path: C:\Program Files\ESET\ESET Smart Security\
Long name: shellExt.dll
Short name:
Date (created): 24.10.2008 20:59:56
Date (last access): 26.12.2008 10:20:26
Date (last write): 24.10.2008 20:59:56
Filesize: 199936
Attributes: archive
MD5: C38DDEF2457AF9E369E845E6EA98888E
CRC32: E0CBFE43
Version: 3.0.684.0
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} ()
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
ITBar7Layout ()
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
BHO name:
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
--- ActiveX list ---
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\Windows\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload2.macromedia.com/get/s ... wflash.cab
Path: C:\Windows\SysWow64\Macromed\Flash\
Long name: Flash10a.ocx
Short name:
Date (created): 5.10.2008 4:16:26
Date (last access): 3.1.2009 11:11:14
Date (last write): 5.10.2008 4:16:26
Filesize: 3789728
Attributes: readonly archive
MD5: 466C1355934925768822E380DA6E6E4A
CRC32: 48EC1E52
Version: 10.0.12.36
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Photo Gallery Viewer Image Verbs
CLSID name: Windows Photo Gallery Viewer Image Verbs
Path: %ProgramFiles%\Windows Photo Gallery\
Long name: PhotoViewer.dll
MD5: 2AAD5D8541ABFD8EC8877773291250AC
Filesize: 2314240
{4B534112-3AF6-4697-A77C-D62CE9B9E7CF} (Sync Center Event Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Event Properties Extension
CLSID name: Sync Center Event Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C} (Sync Setup Delegate Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Setup Delegate Folder
CLSID name: Sync Setup Delegate Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} (Offline Files Context Menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Offline Files Context Menu
CLSID name:
Path: %SystemRoot%\System32\
Long name: cscui.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A} (GameUX.RichGameMediaThumbnail)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: GameUX.RichGameMediaThumbnail
CLSID name: RichGameMediaThumbnail Class
Path: C:\Windows\System32\
Long name: gameux.dll
Short name:
Date (created): 28.12.2008 13:19:24
Date (last access): 28.12.2008 13:19:24
Date (last write): 8.3.2008 5:21:56
Filesize: 1695744
Attributes: archive
MD5: 94A92ADE4BB64E24C668645F5B9A6FCA
CRC32: 9F71AEBD
Version: 6.0.6001.18032
{7EFA68C6-086B-43e1-A2D2-55A113531240} (Offline Files Property Sheet Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Offline Files Property Sheet Extension
CLSID name:
Path: %SystemRoot%\System32\
Long name: cscui.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{d8559eb9-20c0-410e-beda-7ed416aecc2a} (Windows Defender)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Defender
CLSID name: Windows Defender
MD5: D41D8CD98F00B204E9800998ECF8427E
{576C9E85-1300-4EF5-BF6B-D00509F4EDCD} (Sync Center Handler Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Handler Properties Extension
CLSID name: Sync Center Handler Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{289978AC-A101-4341-A817-21EBA7FD046D} (Sync Center Conflict Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Conflict Folder
CLSID name: Sync Center Conflict Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{5ea4f148-308c-46d7-98a9-49041b1dd468} (Mobility Center Control Panel)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Mobility Center Control Panel
CLSID name: Mobility Center Control Panel
MD5: D41D8CD98F00B204E9800998ECF8427E
{71D99464-3B6B-475C-B241-E15883207529} (Sync Results Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Results Folder
CLSID name: Sync Results Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{877ca5ac-cb41-4842-9c69-9136e42d47e2} (File Backup Index)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: File Backup Index
CLSID name: File Backup Index
Path: %systemroot%\system32\
Long name: sdshext.dll
MD5: D41D8CD98F00B204E9800998ECF8427E
{B32D3949-ED98-4DBB-B347-17A144969BBA} (Sync Center Item Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Item Properties Extension
CLSID name: Sync Center Item Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} (Portable Devices Menu)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Portable Devices Menu
CLSID name: Portable Devices Menu
Path: %SystemRoot%\system32\
Long name: wpdshext.dll
MD5: 689C2A3B8C6CBC64E6959C7C858B742C
Filesize: 2537472
{58E3C745-D971-4081-9034-86E34B30836A} (Speech Recognition Options)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Speech Recognition Options
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{2E9E59C0-B437-4981-A647-9C34B9B90891} (Sync Setup Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Setup Folder
CLSID name: Sync Setup Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{4D1209BD-36E2-4e2f-840D-6C7FB879DD9E} (Windows Ultimate Extras)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Windows Ultimate Extras
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} (Sync Center Folder)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Folder
CLSID name: Sync Center Folder
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1} (Welcome Center)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Welcome Center
CLSID name: Welcome Center
Path:
Long name: oobefldr.dll
Short name:
Date (created): 20.4.2008 11:37:00
Date (last access): 20.4.2008 11:37:00
Date (last write): 20.4.2008 11:37:00
Filesize: 2153472
Attributes: archive
MD5: 83E4A5435B0FA6AD0166722621A04725
CRC32: 48B1D434
Version: 6.0.6001.18000
{78F3955E-3B90-4184-BD14-5397C15F1EFC} (Performance Information and Tools)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name:
CLSID name: Performance Information and Tools
Path: %SystemRoot%\System32\
Long name: shdocvw.dll
MD5: 86B89709BDFC7A59D566590CC30CDBB1
Filesize: 1067520
{F04CC277-03A2-4277-96A9-77967471BDFF} (Sync Center Conflict Properties Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Conflict Properties Extension
CLSID name: Sync Center Conflict Properties Extension
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{53BEDF0B-4E5B-4183-8DC9-B844344FA104} (Microsoft Windows MAPI Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Microsoft Windows MAPI Preview Handler
CLSID name: MAPI Mail Previewer
Path: %SystemRoot%\system32\
Long name: mssvp.dll
MD5: AC32DC4D4552151D6842B678D52EB9B7
Filesize: 670208
{8E25992B-373E-486E-80E5-BD23AE417E66} (Sync Center Device Notification Sink)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Sync Center Device Notification Sink
CLSID name: Sync Center Device Notification Sink
Path: %SystemRoot%\System32\
Long name: SyncCenter.dll
MD5: C8527AB1BC08E6BB57EA545DA8C6569F
Filesize: 2204672
{6b9228da-9c15-419e-856c-19e768a13bdc} (Windows gadget DropTarget)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows gadget DropTarget
CLSID name: Windows gadget DropTarget
Path: %ProgramFiles%\Windows Sidebar\
Long name: sbdrop.dll
MD5: A74701976D6D75099B9FCA993685C452
Filesize: 66048
{031EE060-67BC-460d-8847-E4A7C5E45A27} (Windows Media Player Rich Preview Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player Rich Preview Handler
CLSID name: Windows Media Player Rich Preview Handler
MD5: D41D8CD98F00B204E9800998ECF8427E
{1FA9085F-25A2-489B-85D4-86326EEDCD87} (Manage Wireless Networks)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Manage Wireless Networks
CLSID name: Manage Wireless Networks
Path: %SystemRoot%\system32\
Long name: wlanpref.dll
MD5: CFB1737C17BA3172D490F26A4CD17781
Filesize: 1671680
{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60} (RichGameMediaPropertyStore Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: RichGameMediaPropertyStore Class
CLSID name: RichGameMediaPropertyStore Class
Path: C:\Windows\System32\
Long name: gameux.dll
Short name:
Date (created): 28.12.2008 13:19:24
Date (last access): 28.12.2008 13:19:24
Date (last write): 8.3.2008 5:21:56
Filesize: 1695744
Attributes: archive
MD5: 94A92ADE4BB64E24C668645F5B9A6FCA
CRC32: 9F71AEBD
Version: 6.0.6001.18032
{BD7A2E7B-21CB-41b2-A086-B309680C6B7E} (Client Side Cache Namespace Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Client Side Cache Namespace Extension
CLSID name: @%systemroot%\system32\mssvp.dll,-112
Path: %systemroot%\system32\
Long name: mssvp.dll
MD5: AC32DC4D4552151D6842B678D52EB9B7
Filesize: 670208
{8A734961-C4AA-4741-AC1E-791ACEBF5B39} (Windows Media Player Shop Music Context Menu Handler)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Windows Media Player Shop Music Context Menu Handler
CLSID name:
Path: %SystemRoot%\system32\
Long name: wmpshell.dll
MD5: 0143E15F94FD523C588EDD47609F905F
Filesize: 101376
{5E2121EE-0300-11D4-8D3B-444553540000} (Catalyst Context Menu extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Catalyst Context Menu extension
CLSID name: SimpleShlExt Class
Path: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\
Long name: atiacm64.dll
Short name:
Date (created): 19.11.2008 14:54:16
Date (last access): 5.1.2009 20:35:44
Date (last write): 19.11.2008 14:54:16
Filesize: 867840
Attributes: archive
MD5: DCD4F9B57F0E55592C108DF8DDBD0B3B
CRC32: E3BC156E
Version: 6.14.10.2001
{23170F69-40C1-278A-1000-000100020000} (7-Zip Shell Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: 7-Zip Shell Extension
CLSID name:
Path: C:\Program Files\7-Zip\
Long name: 7-zip.dll
Short name:
Date (created): 2.12.2008 12:10:56
Date (last access): 25.12.2008 15:27:08
Date (last write): 2.12.2008 12:10:56
Filesize: 105472
Attributes: archive
MD5: 28DB80D546B87A953F216286D4103BD1
CRC32: 4BA4B4A8
Version: 4.62.0.0
{B089FE88-FB52-11D3-BDF1-0050DA34150D} (Eset Smart Security - Context Menu Shell Extension)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
BHO name: Eset Smart Security - Context Menu Shell Extension
CLSID name: Eset Smart Security - Context Menu Shell Extension
Path: C:\Program Files\ESET\ESET Smart Security\
Long name: shellExt.dll
Short name:
Date (created): 24.10.2008 20:59:56
Date (last access): 26.12.2008 10:20:26
Date (last write): 24.10.2008 20:59:56
Filesize: 199936
Attributes: archive
MD5: C38DDEF2457AF9E369E845E6EA98888E
CRC32: E0CBFE43
Version: 3.0.684.0
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} ()
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} (Microsoft Url Search Hook)
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\
BHO name:
CLSID name: Microsoft Url Search Hook
Path: C:\Windows\system32\
Long name: ieframe.dll
Short name:
Date (created): 10.1.2009 20:57:28
Date (last access): 10.1.2009 20:57:28
Date (last write): 2.10.2008 4:49:16
Filesize: 6068736
Attributes: archive
MD5: EB1D1677749CA2BC5B24D0F162EA7A78
CRC32: 178C804B
Version: 7.0.6001.18148
ITBar7Layout ()
location: HKEY_USERS\S-1-5-21-1786912063-3955790279-2565316649-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
BHO name:
CLSID name:
MD5: D41D8CD98F00B204E9800998ECF8427E
--- ActiveX list ---
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\Windows\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload2.macromedia.com/get/s ... wflash.cab
Path: C:\Windows\SysWow64\Macromed\Flash\
Long name: Flash10a.ocx
Short name:
Date (created): 5.10.2008 4:16:26
Date (last access): 3.1.2009 11:11:14
Date (last write): 5.10.2008 4:16:26
Filesize: 3789728
Attributes: readonly archive
MD5: 466C1355934925768822E380DA6E6E4A
CRC32: 48EC1E52
Version: 10.0.12.36
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím zkontrolujte log
PC by mělo být bez nákazy, problém je , že jsou tam chyby nejen v kontrolních součtech a klíčích, ale chybí tam i celé soubory.Jak je vidno již v prvním Tvém logu z HJT.
vyčisti systém CCleanerem
a RegCleanerem
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni select all found, pak klik empty selected.
Pokud chceš zachovat svoje uložená hesla, klikni na No.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Pak pošli nový log z HJT.
vyčisti systém CCleanerem
a RegCleanerem
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni select all found, pak klik empty selected.
Pokud chceš zachovat svoje uložená hesla, klikni na No.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Pak pošli nový log z HJT.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím zkontrolujte log
Všechno jsem vyčistil, pročistil, ale start pořád stejný. Posílám log z HJT i RunAlyzeru, který má taky HJT log. Poněvadž si myslim, že HJT mi nedělá log korektně.
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:47:23, on 12.1.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 86.110.225.166:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 5161 bytes
RunAlyzer
Logfile of RunAlyzer 0.7.3. Copyright © 2000-2007 Safer Networking Limited. All rights reserved.
Scan saved at 12.1.2009 16:48:08
Platform: Windows Vista (Build: 6001) Service Pack 1 (6.0.6001)
Running processes:
[System]
System
svchost.exe
svchost.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
smss.exe
audiodg.exe
SLsvc.exe
csrss.exe
wininit.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
lsm.exe
wmpnetwk.exe
svchost.exe
svchost.exe
Ati2evxx.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
Ati2evxx.exe
ekrn.exe
spoolsv.exe
svchost.exe
svchost.exe
svchost.exe
C:\Windows\System32\taskeng.exe
taskeng.exe
svchost.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\RAVCpl64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
TrustedInstaller.exe
WmiPrvSE.exe
WmiPrvSE.exe
C:\Program Files (x86)\Safer Networking\RunAlyzer\RunAlyzer.exe
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Skytel] C:\Windows\Skytel.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe
O4 - HKLM\..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe
O23 - Service: Ovladač standardu ACPI společnosti Microsoft (ACPI) - /owner unsupported/ - sys
O23 - Service: Ancilliary Function Driver for Winsock (AFD) - /owner unsupported/ - \Sy
O23 - Service: Intel AGP Bus Filter (agp440) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - /owner unsupported/ - System32\alg.exe
O23 - Service: AMD K8 Processor Driver (AmdK8) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\rascfg.dll,-32000 (AsyncMac) - /owner unsupported/ - sys
O23 - Service: Kanál IDE (atapi) - /owner unsupported/ - sys
O23 - Service: Autodesk Licensing Service (Autodesk Licensing Service) - /owner unsupported/ - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bowser (bowser) - /owner unsupported/ - sys
O23 - Service: Brother USB Mass-Storage Lower Filter Driver (BrFiltLo) - /owner unsupported/ - \Sy
O23 - Service: Brother USB Mass-Storage Upper Filter Driver (BrFiltUp) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC Serial Port Interface Driver (WDM) (Brserid) - /owner unsupported/ - \Sy
O23 - Service: Brother WDM Serial driver (BrSerWdm) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC USB Fax Only Modem (BrUsbMdm) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC USB Serial WDM Driver (BrUsbSer) - /owner unsupported/ - \Sy
O23 - Service: Služba Bluetooth Enumerator (BthEnum) - /owner unsupported/ - sys
O23 - Service: Bluetooth Serial Communications Driver (BTHMODEM) - /owner unsupported/ - \Sy
O23 - Service: Zařízení Bluetooth (síť PAN) (BthPan) - /owner unsupported/ - sys
O23 - Service: Ovladač portu Bluetooth (BTHPORT) - /owner unsupported/ - Sys
O23 - Service: Ovladač rozhraní USB radiostanice Bluetooth (BTHUSB) - /owner unsupported/ - Sys
O23 - Service: CD/DVD File System Reader (cdfs) - /owner unsupported/ - sys
O23 - Service: Ovladač jednotky CD-ROM (cdrom) - /owner unsupported/ - sys
O23 - Service: Consumer IR Devices (circlass) - /owner unsupported/ - \Sy
O23 - Service: Common Log (CLFS) (CLFS) - /owner unsupported/ - Sys
O23 - Service: Microsoft .NET Framework NGEN v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
O23 - Service: Microsoft .NET Framework NGEN v2.0.50727_X64 (clr_optimization_v2.0.50727_64) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
O23 - Service: Microsoft Composite Battery Driver (Compbatt) - /owner unsupported/ - \Sy
O23 - Service: Crcdisk Filter Driver (crcdisk) - /owner unsupported/ - sys
O23 - Service: Offline Files Driver (CSC) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\drivers\dfsc.sys,-101 (DfsC) - /owner unsupported/ - Sys
O23 - Service: @dfsrres.dll,-101 (DFSR) - /owner unsupported/ - system32\DFSR.exe
O23 - Service: Ovladač disku (disk) - /owner unsupported/ - sys
O23 - Service: Dekodér zvuků DRM jádra společnosti Microsoft (drmkaud) - /owner unsupported/ - sys
O23 - Service: LDDM Graphics Subsystem (DXGKrnl) - /owner unsupported/ - \Sy
O23 - Service: Intel(R) PRO/1000 NDIS 6 Adapter Driver (E1G60) - /owner unsupported/ - sys
O23 - Service: EAMON (eamon) - /owner unsupported/ - sys
O23 - Service: easdrv (easdrv) - /owner unsupported/ - sys
O23 - Service: ReadyBoost Caching Driver (Ecache) - /owner unsupported/ - Sys
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - /owner unsupported/ - %windir%\system32\svchost.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - /owner unsupported/ - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - /owner unsupported/ - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: epfw (epfw) - /owner unsupported/ - sys
O23 - Service: Eset Personal Firewall (Epfwndis) - /owner unsupported/ - sys
O23 - Service: epfwtdi (epfwtdi) - /owner unsupported/ - sys
O23 - Service: Microsoft Hardware Error Device Driver (ErrDev) - /owner unsupported/ - \Sy
O23 - Service: Protokol událostí systému Windows (Eventlog) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: exFAT File System Driver (exfat) - /owner unsupported/ -
O23 - Service: FAT12/16/32 File System Driver (fastfat) - /owner unsupported/ -
O23 - Service: Ovladač řadiče disketové jednotky (fdc) - /owner unsupported/ - sys
O23 - Service: File Information FS MiniFilter (FileInfo) - /owner unsupported/ - sys
O23 - Service: FileTrace (Filetrace) - /owner unsupported/ - sys
O23 - Service: Ovladač disketové jednotky (flpydisk) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\PresentationHost.exe,-3309 (FontCache3.0.0.0) - /owner unsupported/ - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
O23 - Service: BitLocker Drive Encryption Filter Driver (fvevol) - /owner unsupported/ - Sys
O23 - Service: Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms (gagp30kx) - /owner unsupported/ - \Sy
O23 - Service: gdrv (gdrv) - /owner unsupported/ - \??
O23 - Service: GEST Service for program management. (GEST Service) - /owner unsupported/ - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio (HdAudAddService) - /owner unsupported/ - sys
O23 - Service: Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio (HDAudBus) - /owner unsupported/ - sys
O23 - Service: Microsoft Bluetooth HID Miniport (HidBth) - /owner unsupported/ - \Sy
O23 - Service: Microsoft Infrared HID Driver (HidIr) - /owner unsupported/ - \Sy
O23 - Service: Ovladač třídy standardu HID Microsoft (HidUsb) - /owner unsupported/ - sys
O23 - Service: Intel AHCI Controller (iaStor) - /owner unsupported/ - sys
O23 - Service: Intel RAID Controller Vista (iaStorV) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193 (idsvc) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
O23 - Service: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - /owner unsupported/ - sys
O23 - Service: Ovladač procesoru Intel (intelppm) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32013 (IpFilterDriver) - /owner unsupported/ - sys
O23 - Service: IR Bus Enumerator (IRENUM) - /owner unsupported/ - sys
O23 - Service: PnP ISA/EISA Bus Driver (isapnp) - /owner unsupported/ - \Sy
O23 - Service: Ovladač iScsiPort (iScsiPrt) - /owner unsupported/ - sys
O23 - Service: ITEATAPI_Service_Install (iteatapi) - /owner unsupported/ - \Sy
O23 - Service: ITERAID_Service_Install (iteraid) - /owner unsupported/ - \Sy
O23 - Service: Ovladač klávesnice standardu HID (kbdhid) - /owner unsupported/ - sys
O23 - Service: @keyiso.dll,-100 (KeyIso) - /owner unsupported/ - system32\lsass.exe
O23 - Service: Kernel Streaming Thunks (ksthunk) - /owner unsupported/ - \Sy
O23 - Service: Vstupně výstupní ovladač mapovače zjišťování topologie linkové vrstvy (lltdio) - /owner unsupported/ - sys
O23 - Service: UAC File Virtualization (luafv) - /owner unsupported/ - \Sy
O23 - Service: Služba ovladače funkce třídy monitorů Microsoft (monitor) - /owner unsupported/ - sys
O23 - Service: Ovladač HID myši (mouhid) - /owner unsupported/ - sys
O23 - Service: Mount Point Manager (MountMgr) - /owner unsupported/ - Sys
O23 - Service: Microsoft Multi-Path Bus Driver (mpio) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23092 (mpsdrv) - /owner unsupported/ - Sys
O23 - Service: WebDav Client Redirector Driver (MRxDAV) - /owner unsupported/ - \Sy
O23 - Service: SMB MiniRedirector Wrapper and Engine (mrxsmb) - /owner unsupported/ - sys
O23 - Service: SMB 1.x MiniRedirector (mrxsmb10) - /owner unsupported/ - sys
O23 - Service: SMB 2.0 MiniRedirector (mrxsmb20) - /owner unsupported/ - sys
O23 - Service: Microsoft Multi-Path Device Specific Module (msdsm) - /owner unsupported/ - \Sy
O23 - Service: @comres.dll,-2797 (MSDTC) - /owner unsupported/ - System32\msdtc.exe
O23 - Service: Ovladač třídy ISA/EISA (msisadrv) - /owner unsupported/ - sys
O23 - Service: Server proxy služby datových proudů Microsoft (MSKSSRV) - /owner unsupported/ - sys
O23 - Service: Server proxy hodin datových proudů Microsoft (MSPCLOCK) - /owner unsupported/ - sys
O23 - Service: Server proxy správce kvality datových proudů Microsoft (MSPQM) - /owner unsupported/ - sys
O23 - Service: Ovladač Microsoft System Management BIOS (mssmbios) - /owner unsupported/ - sys
O23 - Service: Konvertor jímka-jímka typu T datových proudů Microsoft (MSTEE) - /owner unsupported/ - sys
O23 - Service: Mup (Mup) - /owner unsupported/ - Sys
O23 - Service: Filtr NativeWiFi (NativeWifiP) - /owner unsupported/ - sys
O23 - Service: NDIS System Driver (NDIS) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32001 (NdisTapi) - /owner unsupported/ - sys
O23 - Service: NDIS Usermode I/O Protocol (Ndisuio) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32002 (NdisWan) - /owner unsupported/ - sys
O23 - Service: NETBT (netbt) - /owner unsupported/ - Sys
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - /owner unsupported/ - system32\lsass.exe
O23 - Service: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201 (NetTcpPortSharing) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
O23 - Service: NSI proxy service (nsiproxy) - /owner unsupported/ - sys
O23 - Service: NVIDIA nForce RAID Driver (nvraid) - /owner unsupported/ - \Sy
O23 - Service: NVIDIA nForce AGP Bus Filter (nv_agp) - /owner unsupported/ - \Sy
O23 - Service: NEC FireWarden OHCI Compliant IEEE 1394 Host Controller (ohci1394) - /owner unsupported/ - \Sy
O23 - Service: Ovladač paralelního portu (Parport) - /owner unsupported/ - sys
O23 - Service: Partition Manager (partmgr) - /owner unsupported/ - Sys
O23 - Service: Řadič sběrnice PCI (pci) - /owner unsupported/ - sys
O23 - Service: PEAUTH (PEAUTH) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - /owner unsupported/ - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\rascfg.dll,-32006 (PptpMiniport) - /owner unsupported/ - sys
O23 - Service: Processor Driver (Processor) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - /owner unsupported/ - system32\lsass.exe
O23 - Service: @%SystemRoot%\System32\drivers\pacer.sys,-101 (PSched) - /owner unsupported/ - sys
O23 - Service: QLogic Fibre Channel Miniport Driver (ql2300) - /owner unsupported/ - \Sy
O23 - Service: QLogic iSCSI Miniport Driver (ql40xx) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\drivers\qwavedrv.sys,-1 (QWAVEdrv) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\rascfg.dll,-32005 (Rasl2tp) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32007 (RasPppoe) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\sstpsvc.dll,-202 (RasSstp) - /owner unsupported/ - sys
O23 - Service: Redirected Buffering Sub Sysytem (rdbss) - /owner unsupported/ - sys
O23 - Service: RDPCDD (RDPCDD) - /owner unsupported/ - Sys
O23 - Service: Ovladač přesměrovače zařízení terminálového serveru (rdpdr) - /owner unsupported/ - sys
O23 - Service: RDP Encoder Mirror Driver (RDPENCDD) - /owner unsupported/ - sys
O23 - Service: Zařízení Bluetooth (RFCOMM protokol TDI) (RFCOMM) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - /owner unsupported/ - system32\locator.exe
O23 - Service: Odpovídající zařízení zjišťování topologie linkové vrstvy (rspndr) - /owner unsupported/ - sys
O23 - Service: RTCore64 (RTCore64) - /owner unsupported/ - \??
O23 - Service: Realtek 8169 NT Driver (RTL8169) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - /owner unsupported/ - system32\lsass.exe
O23 - Service: SBP-2 Transport/Protocol Bus Driver (sbp2port) - /owner unsupported/ - \Sy
O23 - Service: SBSD Security Center Service (SBSDWSCService) - /owner unsupported/ - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Security Driver (secdrv) - /owner unsupported/ -
O23 - Service: Ovladač filtru Serenum (Serenum) - /owner unsupported/ - sys
O23 - Service: Ovladač sériového portu (Serial) - /owner unsupported/ - sys
O23 - Service: Serial Mouse Driver (sermouse) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Class Driver (sffdisk) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Protocol Driver for MMC (sffp_mmc) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Protocol Driver for SDBus (sffp_sd) - /owner unsupported/ - \Sy
O23 - Service: High-Capacity Floppy Disk Drive (sfloppy) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - /owner unsupported/ - system32\SLsvc.exe
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50005 (Smb) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - /owner unsupported/ - System32\snmptrap.exe
O23 - Service: speedfan (speedfan) - /owner unsupported/ - Sys
O23 - Service: Security Processor Loader Driver (spldr) - /owner unsupported/ -
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - /owner unsupported/ - System32\spoolsv.exe
O23 - Service: srv2 (srv2) - /owner unsupported/ - Sys
O23 - Service: Softwarový ovladač sběrnice (swenum) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50003 (Tcpip) - /owner unsupported/ - Sys
O23 - Service: Ovladač protokolu IPv6 společnosti Microsoft (Tcpip6) - /owner unsupported/ - sys
O23 - Service: TCP/IP Registry Compatibility (tcpipreg) - /owner unsupported/ - Sys
O23 - Service: TDPIPE (TDPIPE) - /owner unsupported/ - sys
O23 - Service: TDTCP (TDTCP) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50004 (tdx) - /owner unsupported/ - sys
O23 - Service: Ovladač terminálového zařízení (TermDD) - /owner unsupported/ - sys
O23 - Service: Motivy (Themes) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - /owner unsupported/ - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: Terminal Services Security Filter Driver (tssecsrv) - /owner unsupported/ - Sys
O23 - Service: Microsoft IPv6 Tunnel Miniport Adapter Driver (tunnel) - /owner unsupported/ - sys
O23 - Service: Microsoft AGPv3.5 Filter (uagp35) - /owner unsupported/ - \Sy
O23 - Service: udfs (udfs) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - /owner unsupported/ - system32\UI0Detect.exe
O23 - Service: Uli AGP Bus Filter (uliagpkx) - /owner unsupported/ - \Sy
O23 - Service: Ovladač sběrnice UMBus Enumerator (umbus) - /owner unsupported/ - sys
O23 - Service: Microsoft USB Generic Parent Driver (usbccgp) - /owner unsupported/ - \Sy
O23 - Service: eHome Infrared Receiver (USBCIR) (usbcir) - /owner unsupported/ - \Sy
O23 - Service: Ovladač Miniport vylepšeného hostitelského řadiče Microsoft USB 2.0 (usbehci) - /owner unsupported/ - sys
O23 - Service: Rozbočovač umožňující USB2 (usbhub) - /owner unsupported/ - sys
O23 - Service: Microsoft USB Open Host Controller Miniport Driver (usbohci) - /owner unsupported/ - \Sy
O23 - Service: Microsoft USB PRINTER Class (usbprint) - /owner unsupported/ - \Sy
O23 - Service: Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft (usbuhci) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - /owner unsupported/ - System32\vds.exe
O23 - Service: Ovladač správce svazků (volmgr) - /owner unsupported/ - sys
O23 - Service: Dynamic Volume Manager (volmgrx) - /owner unsupported/ - Sys
O23 - Service: Svazky úložiště (volsnap) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - /owner unsupported/ - system32\vssvc.exe
O23 - Service: Wacom Serial Pen HID Driver (WacomPen) - /owner unsupported/ - \Sy
O23 - Service: Remote Access IPv6 ARP Driver (Wanarpv6) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - /owner unsupported/ - system32\wbengine.exe
O23 - Service: Microsoft Watchdog Timer Driver (Wd) - /owner unsupported/ - \Sy
O23 - Service: Kernel Mode Driver Frameworks service (Wdf01000) - /owner unsupported/ - sys
O23 - Service: Microsoft Windows Management Interface for ACPI (WmiAcpi) - /owner unsupported/ - \Sy
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - /owner unsupported/ - system32\wbem\WmiApSrv.exe
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - /owner unsupported/ - C:\Program Files\Windows Media Player\wmpnetwk.exe
O23 - Service: Winsock IFS driver (ws2ifsl) - /owner unsupported/ - \Sy
O23 - Service: Centrum zabezpečení (wscsvc) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: Vyhledávání systému Windows (WSearch) - /owner unsupported/ - C:\Windows\system32\SearchIndexer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} () - http://fpdownload2.macromedia.com/get/s ... wflash.cab
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:47:23, on 12.1.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 86.110.225.166:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 5161 bytes
RunAlyzer
Logfile of RunAlyzer 0.7.3. Copyright © 2000-2007 Safer Networking Limited. All rights reserved.
Scan saved at 12.1.2009 16:48:08
Platform: Windows Vista (Build: 6001) Service Pack 1 (6.0.6001)
Running processes:
[System]
System
svchost.exe
svchost.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
smss.exe
audiodg.exe
SLsvc.exe
csrss.exe
wininit.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
lsm.exe
wmpnetwk.exe
svchost.exe
svchost.exe
Ati2evxx.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
Ati2evxx.exe
ekrn.exe
spoolsv.exe
svchost.exe
svchost.exe
svchost.exe
C:\Windows\System32\taskeng.exe
taskeng.exe
svchost.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\RAVCpl64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
TrustedInstaller.exe
WmiPrvSE.exe
WmiPrvSE.exe
C:\Program Files (x86)\Safer Networking\RunAlyzer\RunAlyzer.exe
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Skytel] C:\Windows\Skytel.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe
O4 - HKLM\..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe
O23 - Service: Ovladač standardu ACPI společnosti Microsoft (ACPI) - /owner unsupported/ - sys
O23 - Service: Ancilliary Function Driver for Winsock (AFD) - /owner unsupported/ - \Sy
O23 - Service: Intel AGP Bus Filter (agp440) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - /owner unsupported/ - System32\alg.exe
O23 - Service: AMD K8 Processor Driver (AmdK8) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\rascfg.dll,-32000 (AsyncMac) - /owner unsupported/ - sys
O23 - Service: Kanál IDE (atapi) - /owner unsupported/ - sys
O23 - Service: Autodesk Licensing Service (Autodesk Licensing Service) - /owner unsupported/ - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bowser (bowser) - /owner unsupported/ - sys
O23 - Service: Brother USB Mass-Storage Lower Filter Driver (BrFiltLo) - /owner unsupported/ - \Sy
O23 - Service: Brother USB Mass-Storage Upper Filter Driver (BrFiltUp) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC Serial Port Interface Driver (WDM) (Brserid) - /owner unsupported/ - \Sy
O23 - Service: Brother WDM Serial driver (BrSerWdm) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC USB Fax Only Modem (BrUsbMdm) - /owner unsupported/ - \Sy
O23 - Service: Brother MFC USB Serial WDM Driver (BrUsbSer) - /owner unsupported/ - \Sy
O23 - Service: Služba Bluetooth Enumerator (BthEnum) - /owner unsupported/ - sys
O23 - Service: Bluetooth Serial Communications Driver (BTHMODEM) - /owner unsupported/ - \Sy
O23 - Service: Zařízení Bluetooth (síť PAN) (BthPan) - /owner unsupported/ - sys
O23 - Service: Ovladač portu Bluetooth (BTHPORT) - /owner unsupported/ - Sys
O23 - Service: Ovladač rozhraní USB radiostanice Bluetooth (BTHUSB) - /owner unsupported/ - Sys
O23 - Service: CD/DVD File System Reader (cdfs) - /owner unsupported/ - sys
O23 - Service: Ovladač jednotky CD-ROM (cdrom) - /owner unsupported/ - sys
O23 - Service: Consumer IR Devices (circlass) - /owner unsupported/ - \Sy
O23 - Service: Common Log (CLFS) (CLFS) - /owner unsupported/ - Sys
O23 - Service: Microsoft .NET Framework NGEN v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
O23 - Service: Microsoft .NET Framework NGEN v2.0.50727_X64 (clr_optimization_v2.0.50727_64) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
O23 - Service: Microsoft Composite Battery Driver (Compbatt) - /owner unsupported/ - \Sy
O23 - Service: Crcdisk Filter Driver (crcdisk) - /owner unsupported/ - sys
O23 - Service: Offline Files Driver (CSC) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\drivers\dfsc.sys,-101 (DfsC) - /owner unsupported/ - Sys
O23 - Service: @dfsrres.dll,-101 (DFSR) - /owner unsupported/ - system32\DFSR.exe
O23 - Service: Ovladač disku (disk) - /owner unsupported/ - sys
O23 - Service: Dekodér zvuků DRM jádra společnosti Microsoft (drmkaud) - /owner unsupported/ - sys
O23 - Service: LDDM Graphics Subsystem (DXGKrnl) - /owner unsupported/ - \Sy
O23 - Service: Intel(R) PRO/1000 NDIS 6 Adapter Driver (E1G60) - /owner unsupported/ - sys
O23 - Service: EAMON (eamon) - /owner unsupported/ - sys
O23 - Service: easdrv (easdrv) - /owner unsupported/ - sys
O23 - Service: ReadyBoost Caching Driver (Ecache) - /owner unsupported/ - Sys
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - /owner unsupported/ - %windir%\system32\svchost.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - /owner unsupported/ - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - /owner unsupported/ - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: epfw (epfw) - /owner unsupported/ - sys
O23 - Service: Eset Personal Firewall (Epfwndis) - /owner unsupported/ - sys
O23 - Service: epfwtdi (epfwtdi) - /owner unsupported/ - sys
O23 - Service: Microsoft Hardware Error Device Driver (ErrDev) - /owner unsupported/ - \Sy
O23 - Service: Protokol událostí systému Windows (Eventlog) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: exFAT File System Driver (exfat) - /owner unsupported/ -
O23 - Service: FAT12/16/32 File System Driver (fastfat) - /owner unsupported/ -
O23 - Service: Ovladač řadiče disketové jednotky (fdc) - /owner unsupported/ - sys
O23 - Service: File Information FS MiniFilter (FileInfo) - /owner unsupported/ - sys
O23 - Service: FileTrace (Filetrace) - /owner unsupported/ - sys
O23 - Service: Ovladač disketové jednotky (flpydisk) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\PresentationHost.exe,-3309 (FontCache3.0.0.0) - /owner unsupported/ - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
O23 - Service: BitLocker Drive Encryption Filter Driver (fvevol) - /owner unsupported/ - Sys
O23 - Service: Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms (gagp30kx) - /owner unsupported/ - \Sy
O23 - Service: gdrv (gdrv) - /owner unsupported/ - \??
O23 - Service: GEST Service for program management. (GEST Service) - /owner unsupported/ - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio (HdAudAddService) - /owner unsupported/ - sys
O23 - Service: Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio (HDAudBus) - /owner unsupported/ - sys
O23 - Service: Microsoft Bluetooth HID Miniport (HidBth) - /owner unsupported/ - \Sy
O23 - Service: Microsoft Infrared HID Driver (HidIr) - /owner unsupported/ - \Sy
O23 - Service: Ovladač třídy standardu HID Microsoft (HidUsb) - /owner unsupported/ - sys
O23 - Service: Intel AHCI Controller (iaStor) - /owner unsupported/ - sys
O23 - Service: Intel RAID Controller Vista (iaStorV) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193 (idsvc) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
O23 - Service: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - /owner unsupported/ - sys
O23 - Service: Ovladač procesoru Intel (intelppm) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32013 (IpFilterDriver) - /owner unsupported/ - sys
O23 - Service: IR Bus Enumerator (IRENUM) - /owner unsupported/ - sys
O23 - Service: PnP ISA/EISA Bus Driver (isapnp) - /owner unsupported/ - \Sy
O23 - Service: Ovladač iScsiPort (iScsiPrt) - /owner unsupported/ - sys
O23 - Service: ITEATAPI_Service_Install (iteatapi) - /owner unsupported/ - \Sy
O23 - Service: ITERAID_Service_Install (iteraid) - /owner unsupported/ - \Sy
O23 - Service: Ovladač klávesnice standardu HID (kbdhid) - /owner unsupported/ - sys
O23 - Service: @keyiso.dll,-100 (KeyIso) - /owner unsupported/ - system32\lsass.exe
O23 - Service: Kernel Streaming Thunks (ksthunk) - /owner unsupported/ - \Sy
O23 - Service: Vstupně výstupní ovladač mapovače zjišťování topologie linkové vrstvy (lltdio) - /owner unsupported/ - sys
O23 - Service: UAC File Virtualization (luafv) - /owner unsupported/ - \Sy
O23 - Service: Služba ovladače funkce třídy monitorů Microsoft (monitor) - /owner unsupported/ - sys
O23 - Service: Ovladač HID myši (mouhid) - /owner unsupported/ - sys
O23 - Service: Mount Point Manager (MountMgr) - /owner unsupported/ - Sys
O23 - Service: Microsoft Multi-Path Bus Driver (mpio) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23092 (mpsdrv) - /owner unsupported/ - Sys
O23 - Service: WebDav Client Redirector Driver (MRxDAV) - /owner unsupported/ - \Sy
O23 - Service: SMB MiniRedirector Wrapper and Engine (mrxsmb) - /owner unsupported/ - sys
O23 - Service: SMB 1.x MiniRedirector (mrxsmb10) - /owner unsupported/ - sys
O23 - Service: SMB 2.0 MiniRedirector (mrxsmb20) - /owner unsupported/ - sys
O23 - Service: Microsoft Multi-Path Device Specific Module (msdsm) - /owner unsupported/ - \Sy
O23 - Service: @comres.dll,-2797 (MSDTC) - /owner unsupported/ - System32\msdtc.exe
O23 - Service: Ovladač třídy ISA/EISA (msisadrv) - /owner unsupported/ - sys
O23 - Service: Server proxy služby datových proudů Microsoft (MSKSSRV) - /owner unsupported/ - sys
O23 - Service: Server proxy hodin datových proudů Microsoft (MSPCLOCK) - /owner unsupported/ - sys
O23 - Service: Server proxy správce kvality datových proudů Microsoft (MSPQM) - /owner unsupported/ - sys
O23 - Service: Ovladač Microsoft System Management BIOS (mssmbios) - /owner unsupported/ - sys
O23 - Service: Konvertor jímka-jímka typu T datových proudů Microsoft (MSTEE) - /owner unsupported/ - sys
O23 - Service: Mup (Mup) - /owner unsupported/ - Sys
O23 - Service: Filtr NativeWiFi (NativeWifiP) - /owner unsupported/ - sys
O23 - Service: NDIS System Driver (NDIS) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32001 (NdisTapi) - /owner unsupported/ - sys
O23 - Service: NDIS Usermode I/O Protocol (Ndisuio) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32002 (NdisWan) - /owner unsupported/ - sys
O23 - Service: NETBT (netbt) - /owner unsupported/ - Sys
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - /owner unsupported/ - system32\lsass.exe
O23 - Service: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201 (NetTcpPortSharing) - /owner unsupported/ - C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
O23 - Service: NSI proxy service (nsiproxy) - /owner unsupported/ - sys
O23 - Service: NVIDIA nForce RAID Driver (nvraid) - /owner unsupported/ - \Sy
O23 - Service: NVIDIA nForce AGP Bus Filter (nv_agp) - /owner unsupported/ - \Sy
O23 - Service: NEC FireWarden OHCI Compliant IEEE 1394 Host Controller (ohci1394) - /owner unsupported/ - \Sy
O23 - Service: Ovladač paralelního portu (Parport) - /owner unsupported/ - sys
O23 - Service: Partition Manager (partmgr) - /owner unsupported/ - Sys
O23 - Service: Řadič sběrnice PCI (pci) - /owner unsupported/ - sys
O23 - Service: PEAUTH (PEAUTH) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - /owner unsupported/ - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\rascfg.dll,-32006 (PptpMiniport) - /owner unsupported/ - sys
O23 - Service: Processor Driver (Processor) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - /owner unsupported/ - system32\lsass.exe
O23 - Service: @%SystemRoot%\System32\drivers\pacer.sys,-101 (PSched) - /owner unsupported/ - sys
O23 - Service: QLogic Fibre Channel Miniport Driver (ql2300) - /owner unsupported/ - \Sy
O23 - Service: QLogic iSCSI Miniport Driver (ql40xx) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\drivers\qwavedrv.sys,-1 (QWAVEdrv) - /owner unsupported/ - \Sy
O23 - Service: @%systemroot%\system32\rascfg.dll,-32005 (Rasl2tp) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\rascfg.dll,-32007 (RasPppoe) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\sstpsvc.dll,-202 (RasSstp) - /owner unsupported/ - sys
O23 - Service: Redirected Buffering Sub Sysytem (rdbss) - /owner unsupported/ - sys
O23 - Service: RDPCDD (RDPCDD) - /owner unsupported/ - Sys
O23 - Service: Ovladač přesměrovače zařízení terminálového serveru (rdpdr) - /owner unsupported/ - sys
O23 - Service: RDP Encoder Mirror Driver (RDPENCDD) - /owner unsupported/ - sys
O23 - Service: Zařízení Bluetooth (RFCOMM protokol TDI) (RFCOMM) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - /owner unsupported/ - system32\locator.exe
O23 - Service: Odpovídající zařízení zjišťování topologie linkové vrstvy (rspndr) - /owner unsupported/ - sys
O23 - Service: RTCore64 (RTCore64) - /owner unsupported/ - \??
O23 - Service: Realtek 8169 NT Driver (RTL8169) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - /owner unsupported/ - system32\lsass.exe
O23 - Service: SBP-2 Transport/Protocol Bus Driver (sbp2port) - /owner unsupported/ - \Sy
O23 - Service: SBSD Security Center Service (SBSDWSCService) - /owner unsupported/ - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Security Driver (secdrv) - /owner unsupported/ -
O23 - Service: Ovladač filtru Serenum (Serenum) - /owner unsupported/ - sys
O23 - Service: Ovladač sériového portu (Serial) - /owner unsupported/ - sys
O23 - Service: Serial Mouse Driver (sermouse) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Class Driver (sffdisk) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Protocol Driver for MMC (sffp_mmc) - /owner unsupported/ - \Sy
O23 - Service: SFF Storage Protocol Driver for SDBus (sffp_sd) - /owner unsupported/ - \Sy
O23 - Service: High-Capacity Floppy Disk Drive (sfloppy) - /owner unsupported/ - \Sy
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - /owner unsupported/ - system32\SLsvc.exe
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50005 (Smb) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - /owner unsupported/ - System32\snmptrap.exe
O23 - Service: speedfan (speedfan) - /owner unsupported/ - Sys
O23 - Service: Security Processor Loader Driver (spldr) - /owner unsupported/ -
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - /owner unsupported/ - System32\spoolsv.exe
O23 - Service: srv2 (srv2) - /owner unsupported/ - Sys
O23 - Service: Softwarový ovladač sběrnice (swenum) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50003 (Tcpip) - /owner unsupported/ - Sys
O23 - Service: Ovladač protokolu IPv6 společnosti Microsoft (Tcpip6) - /owner unsupported/ - sys
O23 - Service: TCP/IP Registry Compatibility (tcpipreg) - /owner unsupported/ - Sys
O23 - Service: TDPIPE (TDPIPE) - /owner unsupported/ - sys
O23 - Service: TDTCP (TDTCP) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\tcpipcfg.dll,-50004 (tdx) - /owner unsupported/ - sys
O23 - Service: Ovladač terminálového zařízení (TermDD) - /owner unsupported/ - sys
O23 - Service: Motivy (Themes) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - /owner unsupported/ - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: Terminal Services Security Filter Driver (tssecsrv) - /owner unsupported/ - Sys
O23 - Service: Microsoft IPv6 Tunnel Miniport Adapter Driver (tunnel) - /owner unsupported/ - sys
O23 - Service: Microsoft AGPv3.5 Filter (uagp35) - /owner unsupported/ - \Sy
O23 - Service: udfs (udfs) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - /owner unsupported/ - system32\UI0Detect.exe
O23 - Service: Uli AGP Bus Filter (uliagpkx) - /owner unsupported/ - \Sy
O23 - Service: Ovladač sběrnice UMBus Enumerator (umbus) - /owner unsupported/ - sys
O23 - Service: Microsoft USB Generic Parent Driver (usbccgp) - /owner unsupported/ - \Sy
O23 - Service: eHome Infrared Receiver (USBCIR) (usbcir) - /owner unsupported/ - \Sy
O23 - Service: Ovladač Miniport vylepšeného hostitelského řadiče Microsoft USB 2.0 (usbehci) - /owner unsupported/ - sys
O23 - Service: Rozbočovač umožňující USB2 (usbhub) - /owner unsupported/ - sys
O23 - Service: Microsoft USB Open Host Controller Miniport Driver (usbohci) - /owner unsupported/ - \Sy
O23 - Service: Microsoft USB PRINTER Class (usbprint) - /owner unsupported/ - \Sy
O23 - Service: Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft (usbuhci) - /owner unsupported/ - sys
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - /owner unsupported/ - System32\vds.exe
O23 - Service: Ovladač správce svazků (volmgr) - /owner unsupported/ - sys
O23 - Service: Dynamic Volume Manager (volmgrx) - /owner unsupported/ - Sys
O23 - Service: Svazky úložiště (volsnap) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - /owner unsupported/ - system32\vssvc.exe
O23 - Service: Wacom Serial Pen HID Driver (WacomPen) - /owner unsupported/ - \Sy
O23 - Service: Remote Access IPv6 ARP Driver (Wanarpv6) - /owner unsupported/ - sys
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - /owner unsupported/ - system32\wbengine.exe
O23 - Service: Microsoft Watchdog Timer Driver (Wd) - /owner unsupported/ - \Sy
O23 - Service: Kernel Mode Driver Frameworks service (Wdf01000) - /owner unsupported/ - sys
O23 - Service: Microsoft Windows Management Interface for ACPI (WmiAcpi) - /owner unsupported/ - \Sy
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - /owner unsupported/ - system32\wbem\WmiApSrv.exe
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - /owner unsupported/ - C:\Program Files\Windows Media Player\wmpnetwk.exe
O23 - Service: Winsock IFS driver (ws2ifsl) - /owner unsupported/ - \Sy
O23 - Service: Centrum zabezpečení (wscsvc) - /owner unsupported/ - C:\Windows\System32\svchost.exe
O23 - Service: Vyhledávání systému Windows (WSearch) - /owner unsupported/ - C:\Windows\system32\SearchIndexer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} () - http://fpdownload2.macromedia.com/get/s ... wflash.cab
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím zkontrolujte log
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Stáhni si : Dr. Web CureIt
http://www.studna.cz/go/download/fid/48 ... 8c7f27dce2
dej update , po aktualizaci dej start.
Tlacitky dole muzeš soubor léčit, smazat, přesunout nebo přejmenovat.
Pokud nic nenajde, bude to vše, jestli budou problémy je třeba opravit windows vista pomocí instalačního DVD s win vista ultimatex64. Bohužel program na opravu win vista žádný nemám , jen na XP.
Kód: Vybrat vše
O13 - Gopher Prefix:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
Stáhni si : Dr. Web CureIt
http://www.studna.cz/go/download/fid/48 ... 8c7f27dce2
dej update , po aktualizaci dej start.
Tlacitky dole muzeš soubor léčit, smazat, přesunout nebo přejmenovat.
Pokud nic nenajde, bude to vše, jestli budou problémy je třeba opravit windows vista pomocí instalačního DVD s win vista ultimatex64. Bohužel program na opravu win vista žádný nemám , jen na XP.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím zkontrolujte log
Nic nenašel, tak asi čisto. Ten start už asi vyřeší jen reinstal, do kterýho zatím jít nechci. Děkuju ti mockrát za tvůj čas strávený nad tímto tématem. Díky
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím zkontrolujte log
Ten reinstal bych udělal až jako poslední možnost, zkusil bych tu opravu win, neznám ale přesný postup jak je to u visty. Stálo by za to dát nové téma zde do sekce windows a požádat o radu jak opravit windows vistax64.
Těch chybějících souborů je dost:
vds.exe is a Virtual Disk Service from Microsoft Corporation
součásti WMP
UI0Detect.exe-Vista Interactive Services Detection Service
spoolsv.exe is a Microsoft Windows system executable which handles the printing process
snmptrap.exe is a process belonging to the Microsoft Windows Operating System, related to the Simple Network Management Protocol (SNMP)
slsvc.exe is a Software Licensing Service from Microsoft Corporation
The process lsass.exe serves as the Local Security Authentication Server by Microsoft, Inc.
locator.exe is the remote procedure call locator service and is essential for the smooth running of Microsoft Windows
msdtc.exe is the Microsoft Distributed Transaction Coordinator
DFSR.exe-Distributed File System Replication
The alg.exe executable allows applications (such as IM clients, RTSP, BitTorrent, SIP, and FTP) from a client computer to dynamically utilize passive TCP/ UDP ports in communicating with known ports on a server
Ati2evxx.exe atd..
Možná někdo zná i prográmek na opravu visty.
Tady můžeš dát vyřešeno, viry už to není, pomalý start je příčinou chybějících souborů.
Jinak nemáš zač..
Těch chybějících souborů je dost:
vds.exe is a Virtual Disk Service from Microsoft Corporation
součásti WMP
UI0Detect.exe-Vista Interactive Services Detection Service
spoolsv.exe is a Microsoft Windows system executable which handles the printing process
snmptrap.exe is a process belonging to the Microsoft Windows Operating System, related to the Simple Network Management Protocol (SNMP)
slsvc.exe is a Software Licensing Service from Microsoft Corporation
The process lsass.exe serves as the Local Security Authentication Server by Microsoft, Inc.
locator.exe is the remote procedure call locator service and is essential for the smooth running of Microsoft Windows
msdtc.exe is the Microsoft Distributed Transaction Coordinator
DFSR.exe-Distributed File System Replication
The alg.exe executable allows applications (such as IM clients, RTSP, BitTorrent, SIP, and FTP) from a client computer to dynamically utilize passive TCP/ UDP ports in communicating with known ports on a server
Ati2evxx.exe atd..
Možná někdo zná i prográmek na opravu visty.
Tady můžeš dát vyřešeno, viry už to není, pomalý start je příčinou chybějících souborů.
Jinak nemáš zač..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 121 hostů