Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Lilly [FR]

Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#1 Příspěvek od Lilly [FR] »

:) Zdravim, potřebovala bych pomoc a ujistit se zda je všechno v pořadku

:?: Nevim co se stalo, ale chtěla jsem si stahnout čestinu do hry call of duty 3 modern warfare, později jsem se od kamaradu a kamaradek dostala avizo, že to ještě neexistuje, takže bude to asi fake aplikace, ikdyž štit mi nesděloval přitomnost nebezpečne stranky a antivirus ESET-5 neskenoval hrozbu mam podezřeni na virus a malware v systemu.

:?: Na strance virustotal.com nemůžu zkontrolovat tuhle 64 mb aplikaci, protože uploadovat soubor lze max do 20 mb, takže těch 40 antiviraku si nemůže posvitit na tuhle aplikaci.

:?: Co se stalo po otevřeni čestiny v sanboxu comodo firewal mi vypsalo hlašku -TATO APLIKACE NENI SOUČAST WIN32 - a najednou restart

:?: Negativita po restartu.Poškozene zvukove ovladače, pomalost stahovani a načteni web stranek max 4 kb/s chova se jako internet 32 kb misto 2048 kb, samovolne přehazovani nastaveni windowsu 7 do vychozi polohy zvuk a obraz, samovolne otevirani opticke mechaniky někdy mi to leze, už fakt na nervy jako kdyby to byl kanadsky žertik :roll:

= Přestal mi fungovat bod obnoveni po každym vyberu bodu mi po restartu vyhazuje ERROR, že bod nebyl obnoven a nejsem schopna si to sama opravit =

:o Moje aktivity:Kompletni kontrola ESET 5 - nenašel nic, aktualizace firmware opticke mechaniky z TN02 na TN03/Přestalo blbnout otevirani a zlepšil se průbeh načteni všech DVD-Medii/

Reinstalace zvukoveho ovladače a grafickeho ovladače, kontrola superantispyware FREE -Ještě neni ukončeny 4 hodinovy sken na Full zatim nenašel nic

Posilam vam log.txt z moji 7 je tam malware a virus nebo je to čisty system ?

Mnohokrat děkuji za pomoc a info :worship: :worship: :worship:

RSIT mi vyhazuje error a chybu ohledne programu HIJACK THIS posilam to jako upload

http://leteckaposta.cz/176908221

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#2 Příspěvek od chodnik74 »

Ahoj princezno :wub:
Tak si tě vezmu tentokrát já :) S dovolením si vložím log sem a mrknu na něj..

log z RSIT:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin - 7 at 2011-12-14 11:34:37
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 27 GB (39%) free of 71 GB
Total RAM: 6142 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:39:56, on 14.12.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
E:\Počitačové Programy\Windows-7\Daemon Profesional\DTShellHlp.exe
E:\Počitačové Programy\Windows-7\Menič Tapet\Tapety.exe
C:\Program Files (x86)\AVG - Link Scanner\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Windows\SysWOW64\Ctxfihlp.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\O2 - Internet\O2CZ\EMMSN.exe
C:\Program Files (x86)\O2 - Internet\Nori\Nori.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Admin - 7.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG - Link Scanner\avgssie.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG - Link Scanner\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Tapety 2.12.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://E:\POITAO~2\WINDOW~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\POITAO~2\WINDOW~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66A877B6-AA58-4C35-B595-F04F7873304E}: NameServer = 160.218.167.5 160.218.161.60
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B5352CA-DA4F-41A8-BD71-03949963594E}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG - Link Scanner\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - E:\Počitačové Programy\Windows-7\Super Antispyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG - Link Scanner\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - E:\Počitačové Programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - E:\Počitačové Programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9518 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"E:\Počitačové Programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"E:\Počitačové Programy\Windows-7\Super Antispyware\SASCORE64.EXE"
"C:\Program Files (x86)\AVG - Link Scanner\avgwdsvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"E:\Počitačové Programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1992
"C:\Program Files (x86)\AVG - Link Scanner\avgnsa.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d9c08206-69b3-4eab-975d-bf26c7471b2e -SystemEventPortName:HostProcess-16dc1989-80cb-4b86-a258-77bfb2e6b70b -IoCancelEventPortName:HostProcess-76e12421-6e48-4fd0-a1ca-a79e1d9ff4ac -NonStateChangingEventPortName:HostProcess-f14c1fda-c03d-4adf-9afa-b69642830f7d -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:1db70363-714e-4c6a-b986-dbce87c5e3c2
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"E:\Počitačové Programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesApp64.exe" /TUStart /pid:1924
C:\Windows\Explorer.EXE
"E:\Počitačové Programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cfp.exe" -h
"E:\Počitačové Programy\Windows-7\Daemon Profesional\DTShellHlp.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"E:\Počitačové Programy\Windows-7\Menič Tapet\Tapety.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\AVG - Link Scanner\avgtray.exe"
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"C:\Windows\System32\Ctxfihlp.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\SysWOW64\CTXFISPI.EXE" -Embedding
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\O2 - Internet\O2CZ\EMMSN.exe"
"C:\Program Files (x86)\O2 - Internet\Nori\Nori.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://www.O2pripojse.cz
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2596.a565d40.2103079966 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.8.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 2596 "\\.\pipe\gecko-crash-server-pipe.2596" plugin
"C:\Users\Admin - 7\4 - Poštova Schránka\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Windows 7 Manager - Logon Background Changer.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Admin - 7\AppData\Roaming\Mozilla\Firefox\Profiles\13f15940.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "keyword.URL" - "http://isearch.avg.com/search?cid=%7B4d ... &sap=ku&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=E:\Počitačové Programy\Windows-7\Adobe Reader-CZ\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Admin - 7\AppData\Roaming\Mozilla\Firefox\Profiles\13f15940.default\extensions\
avg@toolbar

C:\Users\Admin - 7\AppData\Roaming\Mozilla\Firefox\Profiles\13f15940.default\searchplugins\
avg-secure-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG - Link Scanner\avgssiea.dll [2011-11-11 1942368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG - Link Scanner\avgssie.dll [2011-11-11 1378144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-12 1451336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-12 1451336]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=E:\Počitačové Programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cfp.exe [2011-10-20 9264456]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-22 4035152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"=C:\Program Files (x86)\AVG - Link Scanner\avgtray.exe [2011-12-03 2415456]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2011-11-12 218464]
"CTxfiHlp"=CTXFIHLP.EXE []

C:\Users\Admin - 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp
Tapety 2.12.lnk - E:\Počitačové Programy\Windows-7\Menič Tapet\Tapety.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0x0301FF03

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-12-14 11:34:37 ----D---- C:\rsit
2011-12-14 11:34:37 ----D---- C:\Program Files\trend micro
2011-12-13 22:19:33 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-13 22:19:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-13 22:19:32 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-13 22:19:32 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-13 22:19:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-13 22:19:32 ----A---- C:\Windows\system32\url.dll
2011-12-13 22:19:32 ----A---- C:\Windows\system32\iertutil.dll
2011-12-13 22:19:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-13 22:19:31 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-13 22:19:31 ----A---- C:\Windows\system32\wininet.dll
2011-12-13 22:19:31 ----A---- C:\Windows\system32\urlmon.dll
2011-12-13 22:19:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-13 22:19:31 ----A---- C:\Windows\system32\ieui.dll
2011-12-13 22:19:30 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-12-13 22:19:30 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-12-13 22:19:30 ----A---- C:\Windows\system32\jscript9.dll
2011-12-13 22:19:30 ----A---- C:\Windows\system32\jscript.dll
2011-12-13 22:19:29 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-13 22:19:29 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-13 22:19:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-13 22:19:27 ----A---- C:\Windows\system32\mshtml.dll
2011-12-13 22:19:27 ----A---- C:\Windows\system32\ieframe.dll
2011-12-13 22:15:17 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-13 22:15:17 ----A---- C:\Windows\system32\tzres.dll
2011-12-13 22:13:46 ----A---- C:\Windows\system32\EncDec.dll
2011-12-13 22:13:45 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-13 22:13:35 ----A---- C:\Windows\system32\win32k.sys
2011-12-13 22:13:33 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-10 23:33:10 ----D---- C:\ProgramData\Creative
2011-12-10 23:30:39 ----D---- C:\Program Files\Creative
2011-12-10 23:30:23 ----D---- C:\Program Files (x86)\Creative
2011-12-10 07:26:04 ----D---- C:\ProgramData\ESET
2011-12-10 07:26:04 ----D---- C:\Program Files\ESET
2011-12-10 07:04:52 ----D---- C:\Users\Admin - 7\AppData\Roaming\SUPERAntiSpyware.com
2011-12-10 07:04:08 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-12-05 07:16:50 ----AH---- C:\DiskMonitorService.ini
2011-12-03 04:54:13 ----A---- C:\Windows\system32\RtNicProp64.dll
2011-12-03 04:54:13 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2011-12-03 04:54:12 ----A---- C:\Windows\system32\nvhdap64.dll
2011-12-03 04:54:12 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2011-12-03 04:54:12 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-12-03 04:10:11 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-12-03 04:09:39 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\tosade.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\tepeqapo64.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\tadefxapo264.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\tadefxapo.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-12-03 04:09:39 ----A---- C:\Windows\system32\SRSHP64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\SFSS_APO.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\SFNHK64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\SFCOM64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\SFAPO64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RtkApi64.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\RTEED64A.dll
2011-12-03 04:09:38 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-12-03 04:09:37 ----A---- C:\Windows\system32\RTCOM64.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\RCoRes64.dat
2011-12-03 04:09:37 ----A---- C:\Windows\system32\RCoInst64.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\R4EEP64A.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\R4EEL64A.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\R4EEG64A.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\R4EED64A.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\R4EEA64A.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-12-03 04:09:37 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2011-12-03 04:09:36 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-12-03 04:09:36 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-12-03 04:09:36 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-12-03 04:09:36 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-12-03 04:09:36 ----A---- C:\Windows\system32\KAAPORT64.dll
2011-12-03 04:09:33 ----A---- C:\Windows\system32\FMAPO64.dll
2011-12-03 04:09:33 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2011-12-03 04:09:32 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2011-12-03 04:09:31 ----A---- C:\Windows\system32\AERTAR64.dll
2011-12-03 04:09:31 ----A---- C:\Windows\system32\AERTAC64.dll
2011-12-02 06:32:32 ----A---- C:\Windows\system32\drivers\Rtlh64.sys
2011-11-30 16:58:40 ----A---- C:\Windows\system32\unrar.dll
2011-11-30 16:58:39 ----A---- C:\Windows\system32\ff_vfw.dll
2011-11-30 16:58:38 ----D---- C:\Program Files\K-Lite Codec Pack x64
2011-11-30 16:47:55 ----D---- C:\Users\Admin - 7\AppData\Roaming\InstallShield Installation Information
2011-11-30 15:10:41 ----A---- C:\Windows\system32\drivers\AmUStor.sys
2011-11-30 15:10:41 ----A---- C:\Windows\system32\AmUStor.dll
2011-11-30 14:56:18 ----A---- C:\Windows\system32\drivers\gHidPnp.sys
2011-11-30 06:04:49 ----A---- C:\Windows\game.ini
2011-11-29 05:14:19 ----A---- C:\Users\Admin - 7\AppData\Roaming\All CPU Meter_Settings.ini
2011-11-28 05:14:51 ----A---- C:\Windows\system32\drivers\gMouUsb.sys
2011-11-28 05:14:50 ----A---- C:\Windows\system32\drivers\MxEFUF64.sys
2011-11-27 03:36:31 ----A---- C:\Windows\system32\drivers\UBUMAPI.sys
2011-11-27 03:36:31 ----A---- C:\Windows\system32\drivers\UBSBM.sys
2011-11-27 03:36:31 ----A---- C:\Windows\system32\drivers\ubohci.sys
2011-11-27 03:36:31 ----A---- C:\Windows\system32\drivers\UB1394.sys
2011-11-27 03:36:30 ----A---- C:\Windows\system32\drivers\amdide64.sys
2011-11-27 01:22:19 ----D---- C:\ProgramData\Bluetooth
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\VHIDMini.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\VcommMgr.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\VComm.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\VBTEnum.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\BTNetFilter.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\BtNetDrv.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\BTHidMgr.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\BlueletSCOAudio.sys
2011-11-27 01:18:31 ----A---- C:\Windows\system32\drivers\blueletaudio.sys
2011-11-27 01:18:23 ----D---- C:\Program Files (x86)\IVT Corporation
2011-11-27 00:53:34 ----D---- C:\ProgramData\NVIDIA
2011-11-27 00:53:32 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvvsvc.exe
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvsvcr.dll
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvsvc64.dll
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvshext.dll
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvmctray.dll
2011-11-27 00:53:24 ----A---- C:\Windows\system32\nvcpl.dll
2011-11-27 00:53:24 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2011-11-27 00:53:18 ----D---- C:\ProgramData\NVIDIA Corporation
2011-11-27 00:52:58 ----A---- C:\Windows\system32\nvhdagenco6420102.dll
2011-11-27 00:52:57 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-11-27 00:52:57 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-11-27 00:52:57 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-11-27 00:52:57 ----A---- C:\Windows\system32\OpenCL.dll
2011-11-27 00:52:57 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-11-27 00:52:57 ----A---- C:\Windows\system32\nvoglv64.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-11-27 00:52:56 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvgenco64.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvdispco64.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvcuvid.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvcuda.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvcompiler.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\nvapi64.dll
2011-11-27 00:52:56 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-11-27 00:52:12 ----D---- C:\Program Files\NVIDIA Corporation
2011-11-27 00:51:14 ----D---- C:\Program Files\Nvidia - Ovladače
2011-11-24 03:51:16 ----D---- C:\ProgramData\Futuremark
2011-11-23 23:01:25 ----D---- C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2011-11-23 22:59:09 ----D---- C:\Windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2011-11-23 22:56:32 ----D---- C:\Users\Admin - 7\AppData\Roaming\InstallShield
2011-11-23 22:55:31 ----D---- C:\Program Files (x86)\Futuremark
2011-11-23 22:54:36 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-11-23 22:54:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-11-23 22:54:36 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-11-23 22:54:36 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-11-23 22:54:35 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-11-23 22:54:35 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-11-23 22:54:34 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-11-23 22:54:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-11-23 22:54:34 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-11-23 22:54:34 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-11-23 22:54:33 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-11-23 22:54:33 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-11-23 22:54:32 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-11-23 22:54:32 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-11-23 22:54:31 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-11-23 22:54:31 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-11-23 22:46:56 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-11-21 22:15:59 ----D---- C:\ProgramData\Innovative Solutions
2011-11-21 06:52:32 ----A---- C:\Windows\etdrv.sys
2011-11-21 06:51:33 ----A---- C:\Windows\GVTDrv64.sys
2011-11-20 01:43:08 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-11-20 01:43:08 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-11-20 01:43:08 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-11-20 01:43:08 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-11-20 01:43:07 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-11-20 01:43:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-11-20 01:43:07 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-11-20 01:43:07 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-11-20 01:43:06 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-11-20 01:43:06 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-11-20 01:43:02 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-11-20 01:43:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-11-20 01:43:02 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-11-20 01:43:02 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-11-20 01:43:01 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-11-20 01:43:01 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-11-20 01:43:01 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-11-20 01:43:01 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-11-20 01:43:00 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-11-20 01:43:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-11-20 01:43:00 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-11-20 01:43:00 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-11-20 01:42:59 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-11-20 01:42:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-11-20 01:42:59 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-11-20 01:42:59 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-11-20 01:42:58 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-11-20 01:42:58 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-11-20 01:42:57 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-11-20 01:42:57 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-11-20 01:42:57 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-11-20 01:42:57 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-11-20 01:42:57 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-11-20 01:42:57 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-11-20 01:42:56 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-11-20 01:42:56 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-11-20 01:42:55 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-11-20 01:42:55 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-11-20 01:42:55 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-11-20 01:42:55 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-11-20 01:42:55 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-11-20 01:42:55 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-11-20 01:42:54 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-11-20 01:42:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-11-20 01:42:54 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-11-20 01:42:54 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-11-20 01:42:53 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-11-20 01:42:53 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-11-20 01:42:52 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-11-20 01:42:52 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-11-20 01:42:52 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-11-20 01:42:52 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-11-20 01:42:52 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-11-20 01:42:52 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-11-20 01:42:51 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-11-20 01:42:51 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-11-20 01:42:51 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-11-20 01:42:51 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-11-20 01:42:50 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-11-20 01:42:50 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-11-20 01:42:49 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-11-20 01:42:49 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-11-20 01:42:48 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-11-20 01:42:48 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-11-20 01:42:48 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-11-20 01:42:48 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-11-20 01:42:48 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-11-20 01:42:48 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-11-20 01:42:47 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-11-20 01:42:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-11-20 01:42:47 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-11-20 01:42:47 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-11-20 01:42:46 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-11-20 01:42:46 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-11-20 01:42:45 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-11-20 01:42:45 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-11-20 01:42:44 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-11-20 01:42:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-11-20 01:42:44 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-11-20 01:42:44 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-11-20 01:42:43 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-11-20 01:42:43 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-11-20 01:42:42 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-11-20 01:42:42 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-11-20 01:42:41 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-11-20 01:42:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-11-20 01:42:41 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-11-20 01:42:41 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-11-20 01:42:40 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-11-20 01:42:40 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-11-20 01:42:39 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-11-20 01:42:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-11-20 01:42:39 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-11-20 01:42:39 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-11-20 01:42:38 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-11-20 01:42:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-11-20 01:42:38 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-11-20 01:42:38 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-11-20 01:42:37 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-11-20 01:42:37 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-11-20 01:42:35 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-11-20 01:42:35 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-11-20 01:42:34 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-11-20 01:42:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-11-20 01:42:34 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-11-20 01:42:34 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-11-20 01:42:33 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-11-20 01:42:33 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-11-20 01:42:33 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-11-20 01:42:33 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-11-20 01:42:32 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-11-20 01:42:32 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-11-20 01:42:31 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-11-20 01:42:31 ----A---- C:\Windows\system32\d3dx10.dll
2011-11-20 01:42:30 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-11-20 01:42:30 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-11-20 01:42:29 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-11-20 01:42:29 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-11-20 01:42:29 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-11-20 01:42:29 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-11-20 01:42:28 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-11-20 01:42:28 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-11-20 01:42:27 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-11-20 01:42:27 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-11-20 01:42:27 ----A---- C:\Windows\system32\xinput1_2.dll
2011-11-20 01:42:27 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-11-20 01:42:26 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-11-20 01:42:26 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-11-20 01:42:26 ----A---- C:\Windows\system32\xinput1_1.dll
2011-11-20 01:42:26 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-11-20 01:42:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-11-20 01:42:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-11-20 01:42:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-11-20 01:42:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-11-20 01:42:19 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-11-20 01:42:19 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-11-20 01:42:19 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-11-20 01:42:19 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-11-20 01:42:18 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-11-20 01:42:18 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-11-20 01:42:16 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-11-20 01:42:16 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-11-20 01:42:15 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-11-20 01:42:15 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-11-20 01:42:14 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-11-20 01:42:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-11-20 01:42:13 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-11-20 01:42:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-11-20 01:42:12 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-11-20 01:42:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-11-19 22:54:13 ----D---- C:\ProgramData\InstallShield
2011-11-19 22:38:05 ----D---- C:\ProgramData\AmUStor
2011-11-19 22:35:01 ----D---- C:\Program Files (x86)\Mobile Partner
2011-11-19 21:29:14 ----A---- C:\Windows\SYSWOW64\drivers\DrvAgent64.SYS
2011-11-19 07:47:51 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-11-19 07:47:51 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-11-19 07:47:51 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-11-19 07:47:51 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-11-19 07:47:50 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-11-19 07:47:50 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-11-19 07:47:49 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-11-19 07:47:49 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-11-19 07:47:48 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-11-19 07:47:48 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-11-19 07:47:48 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-11-19 07:47:48 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-11-19 07:47:47 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-11-19 07:47:47 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-11-19 07:47:45 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-11-19 07:47:45 ----A---- C:\Windows\system32\xinput1_3.dll
2011-11-17 19:24:38 ----D---- C:\Program Files (x86)\SystemRequirementsLab

======List of files/folders modified in the last 1 month======

2011-12-14 11:34:53 ----D---- C:\Windows\Prefetch
2011-12-14 11:34:37 ----RD---- C:\Program Files
2011-12-14 11:33:38 ----D---- C:\Users\Admin - 7\AppData\Roaming\Winamp
2011-12-14 11:33:37 ----D---- C:\Windows\inf
2011-12-14 11:33:37 ----D---- C:\Windows\debug
2011-12-14 11:33:37 ----D---- C:\Windows
2011-12-14 10:56:50 ----D---- C:\Windows\Temp
2011-12-14 10:47:04 ----D---- C:\Windows\system32\config
2011-12-14 10:38:48 ----D---- C:\Windows\System32
2011-12-14 10:38:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-14 10:33:31 ----SHD---- C:\Config.Msi
2011-12-14 10:33:29 ----D---- C:\Program Files (x86)\AVG - Link Scanner
2011-12-14 09:11:33 ----D---- C:\ProgramData\MFAData
2011-12-14 09:11:32 ----SHD---- C:\Windows\Installer
2011-12-14 04:17:56 ----D---- C:\Windows\rescache
2011-12-13 22:34:45 ----D---- C:\Windows\winsxs
2011-12-13 22:32:55 ----D---- C:\Windows\SYSWOW64\migration
2011-12-13 22:32:55 ----D---- C:\Windows\SysWOW64
2011-12-13 22:32:55 ----D---- C:\Windows\system32\migration
2011-12-13 22:32:55 ----D---- C:\Program Files\Internet Explorer
2011-12-13 22:32:55 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-13 22:22:06 ----D---- C:\ProgramData\Microsoft Help
2011-12-13 22:21:55 ----D---- C:\Windows\system32\catroot2
2011-12-13 22:21:55 ----D---- C:\Windows\system32\catroot
2011-12-13 22:20:30 ----A---- C:\Windows\system32\MRT.exe
2011-12-13 22:18:55 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-13 22:18:55 ----D---- C:\Windows\system32\cs-CZ
2011-12-13 22:18:39 ----SHD---- C:\System Volume Information
2011-12-10 23:33:10 ----HD---- C:\ProgramData
2011-12-10 23:31:05 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-10 23:30:33 ----D---- C:\Program Files (x86)\Common Files
2011-12-10 23:30:31 ----HD---- C:\Program Files (x86)\Creative Installation Information
2011-12-10 23:30:23 ----RD---- C:\Program Files (x86)
2011-12-10 23:29:49 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-12-10 23:29:49 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-12-10 23:29:49 ----A---- C:\Windows\system32\wrap_oal.dll
2011-12-10 23:29:49 ----A---- C:\Windows\system32\OpenAL32.dll
2011-12-10 23:29:36 ----D---- C:\Windows\system32\Data
2011-12-10 23:29:32 ----D---- C:\Windows\system32\drivers
2011-12-10 22:49:51 ----D---- C:\Windows\system32\wbem
2011-12-10 22:49:07 ----D---- C:\Windows\AppCompat
2011-12-10 22:49:06 ----D---- C:\Windows\Tasks
2011-12-10 22:49:06 ----D---- C:\Windows\system32\wfp
2011-12-10 22:49:06 ----D---- C:\Windows\system32\oobe
2011-12-10 22:49:06 ----D---- C:\Windows\system32\DriverStore
2011-12-10 22:49:06 ----D---- C:\Windows\system32\CodeIntegrity
2011-12-10 22:49:06 ----D---- C:\Windows\registration
2011-12-10 21:28:06 ----D---- C:\Users\Admin - 7\AppData\Roaming\IrfanView
2011-12-10 21:28:05 ----D---- C:\Windows\system32\Tasks
2011-12-10 21:02:08 ----HD---- C:\VritualRoot
2011-12-10 06:43:35 ----D---- C:\Windows\SoftwareDistribution
2011-12-10 05:19:45 ----D---- C:\Users\Admin - 7\AppData\Roaming\uTorrent
2011-12-06 03:05:56 ----D---- C:\Windows\Logs
2011-12-05 18:07:36 ----D---- C:\Users\Admin - 7\AppData\Roaming\Skype
2011-12-05 09:40:22 ----D---- C:\Users\Admin - 7\AppData\Roaming\DAEMON Tools Pro
2011-12-03 13:38:38 ----RSD---- C:\Windows\assembly
2011-12-03 04:10:34 ----HD---- C:\Program Files (x86)\Temp
2011-11-30 15:50:02 ----D---- C:\Windows\Downloaded Installations
2011-11-30 11:39:29 ----SHD---- C:\$Recycle.Bin
2011-11-29 03:31:03 ----RSD---- C:\Windows\Fonts
2011-11-27 01:18:30 ----D---- C:\Windows\SYSWOW64\drivers
2011-11-27 00:53:34 ----RHD---- C:\Users
2011-11-27 00:53:23 ----D---- C:\Windows\Help
2011-11-25 09:14:58 ----AD---- C:\ProgramData\Temp
2011-11-23 22:55:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-19 22:38:07 ----D---- C:\Program Files (x86)\AmIcoSingLun
2011-11-19 20:04:41 ----D---- C:\Windows\SYSWOW64\directx
2011-11-19 04:20:47 ----D---- C:\Windows\system32\NDF
2011-11-19 04:20:46 ----D---- C:\Users\Admin - 7\AppData\Roaming\Ulozto File Manager
2011-11-19 04:20:46 ----D---- C:\ProgramData\AVG2012

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdide64;amdide64; C:\Windows\system32\DRIVERS\amdide64.sys [2010-03-30 11832]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-06-17 16440]
R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 26704]
R0 BTHidEnum;Bluetooth HID Enumerator; C:\Windows\System32\Drivers\vbtenum.sys [2007-03-05 24976]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\Windows\System32\Drivers\BTHidMgr.sys [2007-03-05 49680]
R0 MxEFUF;Matrox Extio Upper Function Filter; C:\Windows\system32\DRIVERS\MxEFUF64.sys [2010-11-04 143688]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2011-07-11 375376]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-10-07 574216]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-10-07 43248]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-09-10 272448]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-10-07 93200]
R1 SASDIFSV;SASDIFSV; \??\E:\Počitačové Programy\Windows-7\Super Antispyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\E:\Počitačové Programy\Windows-7\Super Antispyware\SASKUTIL64.SYS [2011-07-12 12368]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2011-08-04 137144]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\E:\Počitačové Programy\Windows-7\Power DVD - 2011\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-08-24 75248]
R2 ubsbm;Unibrain 1394 SBM Driver; C:\Windows\system32\DRIVERS\ubsbm.sys [2011-09-13 24064]
R2 ubumapi;Unibrain 1394 FireAPI Driver; C:\Windows\system32\DRIVERS\ubumapi.sys [2011-09-13 92160]
R3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2011-03-23 75352]
R3 BlueletAudio;Bluetooth Audio Service; C:\Windows\system32\DRIVERS\blueletaudio.sys [2007-05-11 38160]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 37648]
R3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys [2007-05-23 19728]
R3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2010-07-07 697816]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2010-07-07 15960]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2010-07-07 213080]
R3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2010-07-07 118360]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2009-11-02 25088]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2009-11-02 14336]
R3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-10-18 2957544]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-11-09 187200]
R3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2010-07-07 179288]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\E:\Počitačové Programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesDriver64.sys [2011-10-20 11856]
R3 ubohci;Unibrain 1394 OHCI Driver; C:\Windows\system32\DRIVERS\ubohci.sys [2011-09-13 132608]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2011-08-17 53376]
R3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys [2007-03-05 47120]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys [2007-03-05 63248]
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\Windows\System32\Drivers\btcusb.sys [2007-05-23 44688]
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2010-07-07 580696]
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2011-11-21 25640]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-11-21 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2011-11-21 30528]
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2010-07-07 1567832]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2011-09-08 508520]
S3 scramby;Scramby Microphone; C:\Windows\system32\drivers\scramby.sys [2007-02-13 29480]
S3 scramby_out;Scramby Output; C:\Windows\system32\drivers\scramby_out.sys [2007-08-08 34336]
S3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2011-10-28 34032]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 vcd10bus;Virtual CD v10 Bus Enumerator; C:\Windows\system32\DRIVERS\vcd10bus.sys [2008-06-17 40464]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM); C:\Windows\system32\DRIVERS\vwmfbus.sys [2009-11-11 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfdiag.sys [2009-11-11 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~; C:\Windows\system32\DRIVERS\vwmfmdfl.sys [2009-11-11 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver; C:\Windows\system32\DRIVERS\vwmfmdm.sys [2009-11-11 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfserd.sys [2009-11-11 128512]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; E:\Počitačové Programy\Windows-7\Super Antispyware\SASCORE64.EXE [2011-08-12 140672]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG - Link Scanner\avgwdsvc.exe [2011-08-02 192776]
R2 cmdAgent;COMODO Internet Security Helper Service; E:\Počitačové Programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cmdagent.exe [2011-10-07 2663568]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; E:\Počitačové Programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesService64.exe [2011-10-20 2072896]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 vToolbarUpdater;vToolbarUpdater; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-11-12 246624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-09-05 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-09-05 79360]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-12-08 419624]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-05 1255736]
S4 Active@ Disk Monitor;Active@ Disk Monitor; E:\Počitačové Programy\Windows-7\Manager Hardisku\DiskMonitorService.exe [2011-06-16 1465016]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; E:\Počitačové Programy\Windows-7\Power DVD - 2011\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-08-24 83240]
S4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; E:\Počitačové Programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-08-26 75048]
S4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; E:\Počitačové Programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [2011-08-26 292136]
S4 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-03-01 130976]
S4 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [2009-04-17 247152]

-----------------EOF-----------------
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#3 Příspěvek od chodnik74 »

Log vypadá čistě.. Zkusíme sken MBAM..

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#4 Příspěvek od Lilly [FR] »

Zdravim tebe tady ještě neznam, ale podle avataru předpokladam, že mam čest s mechanikem ohledem softwaru a železa na pc

Provedene moje aktivity :)

- Uplny sken ESET - 5, žadny virus ani spyware
- Uplny sken SuperAntispyware - žadny virus ani spyware
- Uplny sken Malwarebytes - žadny virus ani spyware /Tu detekci znam je falešna ve skutečnosti je to moje nastaveni a zobrazeni položek v nabídce -START, už jsem to tady jednou řešila na foru /

- Posilam LOG :| z malwarebytes

- Graficky a zvukovy ovladač po reinstalaci zatim oba v pohodě funguji
- Stahovaní se zlepšilo ze 4kb/s jedu zase na 128-256 kb/s takže je to zase INTERNET-2048 z O2, asi mně brzdi provider FUP nebo maji technicku zavadu. možna, že jsem zazmatkovala :oops:

- Co dal ? :idea: :arrow: Ještě jsem nevyřešila opravu bodu obnoveni a ten hijack nebo co to je co mi oba vyhazuji chybu, pokoušela jsem se o dalši novši bod obnovy systemu a mam pořad hlašku.Bod obnovy nebyl uspešně obnoveny

:wink: :wink: :wink:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Verze databáze: 8369

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

14.12.2011 16:39:03
mbam-log-2011-12-14 (16-38-45).txt

Typ: Úplná kontrola (C:\|D:\|E:\|F:\|)
Kontrolované objekty: 413683
Uplynulý čas: 34 minut, 42 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 1
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#5 Příspěvek od chodnik74 »

Taky tě rád poznávám :) už jsem tě tu dostkrát viděl na forum a vždy se mi líbil tvůj styl komunikace ;-)

Zkusím na tu obnovu poslat naši ultilitku OTM a její příkaz, který smaže všechny dosavadní body obnovy a vytvoří nový... :) snad nezklame..


:arrow: Stáhneme si na Plochu program OTMObrázek
  • Spustíme soubor OTM.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Spustí se nám program OTM a do levého okna ,,Paste Instructions for Items to be Moved,, vložíme následující skript a stiskneme tlačítko MoveIt

    Kód: Vybrat vše

    :Commands
    [ClearAllRestorePoints]
    [EmptyFlash]
    [EmptyTemp]
    
    
  • Po restartu pc se vám objeví log z OTM,ten mi sem prosím vložte..
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#6 Příspěvek od Lilly [FR] »

:) Ahoj, velice moc děkuji za přizeň, ochotu a vstřicnost a omlouvam se, že odpovidam pozdě doteďka jsme byli bez proudu, včera nam kolem 20:00 hod někdo vyrazil pojistky a soused jako vždycky zase nervozne 4 hodiny na nas nadaval, protože dival se na nějaky film a nemoh ho dokoukat. :x Později jsme zjistili, že na vine byli japonske studentky /Smaženi a opekani jidla a žehleni pradla na pokoji / :boxed:

- Už, abych byla doma ve francii a na vanoce byla s mamou a tatou, dneska jsem si byla koupit letenku a zarezervovat ji :?:

- :arrow: Posilam ten vypis z OTM, hodně to tam pročistil, zatim zkusim udělat novy bod obnovy a restartovat pc bude ještě potřeba něco dal udělat, hledam ten HIJACK co mi z RSIT vyhodil do Erroru, ale koukam, že ho v systemu nemam

:wub: Tady je zprava OTM-Log

All processes killed
========== COMMANDS ==========

Restore point Set: OTM Restore Point

[EMPTYFLASH]

User: Admin - 7
->Flash cache emptied: 721 bytes

User: All Users

User: Default

User: Default User

User: Public

User: UpdatusUser

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: Admin - 7
->Temp folder emptied: 1077831 bytes
->Temporary Internet Files folder emptied: 1110211 bytes
->Java cache emptied: 5912000 bytes
->FireFox cache emptied: 156425086 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 356352 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1519633 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67978 bytes
RecycleBin emptied: 523264 bytes

Total Files Cleaned = 159,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 12152011_134158

Files moved on Reboot...
C:\Users\Admin - 7\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#7 Příspěvek od chodnik74 »

V pořádku.. jak vypadá obnova systému nyní? :turned:
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#8 Příspěvek od Lilly [FR] »

:?: Ahoj, problematika ovladaču na grafiku a zvuk v pořadku a samovolne nastaveni windowsu 7 do vychozi polohy, už neni, jsem rada, že v systemu neni spyware ani virus - LOG Analiza

:) Ohledně MICTRO HIHAJCK 2.02 spustila jsem ještě jednou RSIT - 64 Bit a tam se HIJACK spustil, už normalně bez chyb

:x Ale bod obnoveni pořad selhava, zkoušela jsem udělat novy nebo posledni co si system sam udělal a u obou testech to selhalo, ja nevim jak to opravim pokud takhle bod obnovy bude blbnout je velika skryta hrozba, že nemam možnost k restartu k uspešnemu poslednímu bodu obnoveni a můžu zase instalovat system od začatku při napadeni viru a zakerne havěti

:arrow: Podivej tohle mi pořad ukazuje http://imageshack.us/f/202/43331247.jpg/

:worship: Je možnost zachrany nebo mam instalovat system od začatku?ale to mi bude trvat minimalne 6 hodin, než to všechno reinstaluji, aktualizace mam toho hodně

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#9 Příspěvek od chodnik74 »

Zkusil bych jednu věc..

Podle tohoto návodu odstranit všechny body obnovy, vypnout obnovení systému, restartovat pc, zapnout obnovení a vytvořit nový bod :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#10 Příspěvek od Lilly [FR] »

:?: :( Ahoj, podle návodu jsem udělala tak jak mi to přikazuje navod tetda tutorial z fora, vymazani bodu, vypinani nastroje bodu obnoveni, restart, zapnuti nastroje bodu obnoveni, vytvořeni noveho bodu a pak restart.

:?: Pořad ten problem zůstava chyba a selhani nastroje bodu obnoveni systemu ja se obavam zda v ukryte složce v systemu volume information na E/Disku nezůstali nasledky - Trojsky Kůň, před půl měsicem ho objevil superantispyware v full kontrole a odstranil ho pryč, ikdyž system 7 /64 bit/ mam na C/Disku

:?: Nebo v registrech bude něco co je vypnute a zakazane, prohledala jsem všechny fora aj microsoftu, ale nikde jsem nenalezla odpověď

:) Budu asi muset odstranit aj zalohu nastaveni a bit kopie systemu, protože při zalohovani souboru nejsem si jista, jestli se nezalohuje i virus.Externy disk je nastaveny 1x do měsice zalohovat.

:) Je ještě nejaka možnost zachrany ? Promin nezlob se, ale zůstala jsem teď bezmocna - problematika Kontrola Logu je vyřešena, ale jak jsme spolem zapracovali, objevili se dalši chyby o kteých jsem nemněla ani zdaní, to je ten nastroj obnovy systemu

:arrow: Tohle se mi ještě nestalo :idea:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#11 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Omlouvam se kolegovi za vstup, pisu na zadost uzivatelky via PM

:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Kliknete na tlacitko Nekontrolovat
  • U polozky Specificke registry zaskrtnete vse
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#12 Příspěvek od Lilly [FR] »

:) Ja tě zdravim Vyosekty můj oblibeny moderatore :wink: Nevim co se konkretne z moji 7 stalo, ale budu se řidit všemu to co mi doporučuješ, promin stat se může cokoli a vždycky budu rada pokud se sprovozni NASTROJ PRO OBNOVU SYSTEMU.Bod jde udělat teda vytvořit, ale všechna operace hned selhava při restartu a žadna změna sa tím padem nekona.Děkuji ti za odezvu :wub:

:arrow: Dobře udělala jsem test OTL, ale během par vteřin byl hotov co mam dale udělat ?

:idea: Tady jsou vysledky :

OTL.txt
--------

OTL logfile created on: 15.12.2011 22:39:21 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin - 7\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

6,00 Gb Total Physical Memory | 4,42 Gb Available Physical Memory | 73,65% Memory free
12,00 Gb Paging File | 10,36 Gb Available in Paging File | 86,38% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 69,34 Gb Total Space | 27,08 Gb Free Space | 39,06% Space Free | Partition Type: NTFS
Drive D: | 11,19 Gb Total Space | 4,90 Gb Free Space | 43,79% Space Free | Partition Type: NTFS
Drive E: | 465,82 Gb Total Space | 366,15 Gb Free Space | 78,60% Space Free | Partition Type: NTFS
Drive F: | 49,81 Gb Total Space | 49,65 Gb Free Space | 99,70% Space Free | Partition Type: NTFS
Drive L: | 1863,01 Gb Total Space | 1398,13 Gb Free Space | 75,05% Space Free | Partition Type: NTFS

Computer Name: AMD-POČITAČ | User Name: Admin - 7 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

< End of report >


Extras.txt
----------

OTL Extras logfile created on: 15.12.2011 22:39:21 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin - 7\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

6,00 Gb Total Physical Memory | 4,42 Gb Available Physical Memory | 73,65% Memory free
12,00 Gb Paging File | 10,36 Gb Available in Paging File | 86,38% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 69,34 Gb Total Space | 27,08 Gb Free Space | 39,06% Space Free | Partition Type: NTFS
Drive D: | 11,19 Gb Total Space | 4,90 Gb Free Space | 43,79% Space Free | Partition Type: NTFS
Drive E: | 465,82 Gb Total Space | 366,15 Gb Free Space | 78,60% Space Free | Partition Type: NTFS
Drive F: | 49,81 Gb Total Space | 49,65 Gb Free Space | 99,70% Space Free | Partition Type: NTFS
Drive L: | 1863,01 Gb Total Space | 1398,13 Gb Free Space | 75,05% Space Free | Partition Type: NTFS

Computer Name: AMD-POČITAČ | User Name: Admin - 7 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "E:\Počitačové Programy\Windows-7\Microsoft Office - 2007\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "E:\Počitačové Programy\Windows-7\Microsoft Office - 2007\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "E:\Počitačové Programy\Windows-7\Microsoft Office - 2007\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "E:\Počitačové Programy\Windows-7\Microsoft Office - 2007\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{4EAB2511-0135-48CA-A47B-CE1E6836793A}" = COMODO Internet Security
"{65510247-DAA8-4161-9898-42C78EAF1BC5}" = AVG 2012
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Ovladače videa společnosti Pinnacle
"{784291AE-71B5-45C6-A465-4A8B1E046151}" = Windows 7 Manager
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{7FC31537-1378-4B54-9BB6-1F43F4C6AE46}" = Fire-i Application 3.90 64-bit
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-041B-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Slovak) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A324DC11-FF02-3CE8-9D6F-67EBC006D970}" = Microsoft .NET Framework 4 Extended CSY Language Pack
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.2.24.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CCE9E238-0912-1D72-C1AA-0CE3B30EA5E0}" = AMD Catalyst Install Manager
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{F0F5F73E-3E69-4521-A9D1-B1AE8DEE0F15}" = ESET NOD32 Antivirus
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX 64" = Adobe Flash Player 10 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"AVG" = AVG 2012
"CCleaner" = CCleaner
"KLiteCodecPack64_is1" = K-Lite Codec Pack 5.5.0 (64-bit)
"MediaInfo" = MediaInfo 0.7.36
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended CSY Language Pack" = Microsoft .NET Framework 4 Extended CSY Language Pack
"Recuva" = Recuva
"SereneScreen Marine Aquarium 3_is1" = SereneScreen Marine Aquarium 3
"Speccy" = Speccy
"WinRAR archiver" = WinRAR archivátor

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1C42D474-BDBD-4200-829D-28246879365D}" = Active@ Hard Disk Monitor
"{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20288888-A7AF-4B24-8AEB-398D20CD563C}" = Sound Blaster X-Fi
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 29
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{34D8A788-9397-4695-86BF-B6920284CC65}_is1" = Power AMR MP3 WAV WMA M4A AC3 Audio Converter 1.6
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"{48106FE4-B1AF-4941-BF3D-83E6C4B7CAF3}" = Alcor Micro USB Card Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{5588D686-D23B-4C9D-BDFA-2A7875CD3722}" = GIGABYTE OC_GURU
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty(R) 2 Patch 1.3
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{8190420D-F4BA-4744-8940-A466F81AF89C}_is1" = Ulož.to File Manager verze 1.4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846AC73B-9394-48B9-B941-8F7F472F0047}" = Bluesoleil2.6.0.9 Release 070606
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0016-041B-0000-0000000FF1CE}_STANDARD_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}_STANDARD_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}_STANDARD_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}_STANDARD_{4754EB3B-ED3D-4095-A2FD-684A3058A4FF}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_STANDARD_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_STANDARD_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-040E-0000-0000000FF1CE}_STANDARD_{0AD4BB83-13B4-4C9D-9BAC-7F64E0B2D5D7}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_STANDARD_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_STANDARD_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-041B-1000-0000000FF1CE}_STANDARD_{8382BA92-20E3-47B6-971B-F673F0492D4E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}_STANDARD_{8382BA92-20E3-47B6-971B-F673F0492D4E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AADD1C8F-D59F-4D55-A726-768C71A205A8}" = Pinnacle Studio 14
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.6 - Czech
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"{F241EC95-C81A-466E-8006-6B0B364B07A0}" = PCMark Vantage
"{F2979AAA-FDD7-4CB3-93BC-5C24D965D679}" = Windows Live Messenger
"{F5C372A1-40F3-49DA-A049-F75CDE9177DC}" = Pinnacle Studio Ultimate Collection Plugins
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"5513-1208-7298-9440" = JDownloader 0.9
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 5" = Acoustica Mixcraft 5
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AmUStor" = Alcor Micro USB Card Reader
"Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9
"Ashampoo Photo Optimizer FREE_is1" = Ashampoo Photo Optimizer FREE
"AudioCS" = Creative Audio Control Panel
"Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2
"Call of Duty: Black Ops_is1" = Call of Duty: Black Ops
"ColorCastFX for Digital Cameras_is1" = ColorCastFX for Digital Cameras
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"CyberLink PowerDVD 11.0.1719.51" = CyberLink PowerDVD 11.0.1719.51 - odinstalovat češtinu
"DAEMON Tools Pro" = DAEMON Tools Pro
"DMX5_is1" = DriverMax 5
"EasyBCD" = EasyBCD 2.1
"EximiousSoft Banner Maker_is1" = EximiousSoft Banner Maker V3.02
"FormatFactory" = FormatFactory 2.70
"HUAWEI DataCard Driver" = HUAWEI DataCard Driver 4.20.03.00
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}" = GIGABYTE OC_GURU
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"IrfanView" = IrfanView (remove only)
"Knoll Light Factory EZ Studio" = Knoll Light Factory EZ Studio
"Magic Bullet Looks Studio" = Magic Bullet Looks Studio
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware verze 1.51.2.1300
"Mobile Partner" = Mobile Partner
"Mozilla Firefox 8.0 (x86 cs)" = Mozilla Firefox 8.0 (x86 cs)
"Mozilla Thunderbird (6.0)" = Mozilla Thunderbird (6.0)
"Mp3 Knife_is1" = Mp3 Knife 3.2
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"O2CZ" = O2
"OpenAL" = OpenAL
"Photo Collage Maker_is1" = Photo Collage Maker 1.42
"Red Giant ToonIt Studio" = Red Giant ToonIt Studio
"SFBM" = SoundFont Bank Manager
"STANDARD" = Microsoft Office Standard 2007
"Steam App 10680" = Aliens vs. Predator
"Steam App 43110" = Metro 2033
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Stellarium_is1" = Stellarium 0.10.6.1
"Tapety 2.12" = Tapety 2.12
"Totalcmd" = Total Commander (Remove or Repair)
"Trapcode 3DStroke Studio" = Trapcode 3DStroke Studio
"Trapcode Particular Studio" = Trapcode Particular Studio
"Trapcode Shine Studio" = Trapcode Shine Studio
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Update Service" = Sony Ericsson Update Service
"Virtual Painter 5 (Standalone)" = Virtual Painter 5 (Standalone)
"VW100 Connection Manager" = Odinstalovat U:fonův 3G mobilní internet
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{7FC31537-1378-4B54-9BB6-1F43F4C6AE46}" = Fire-i Application 3.90 64-bit
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#13 Příspěvek od vyosek »

:arrow: Tak tady se nam nastaveni bodu obnovy nezobrazilo ac melo :?: Bud obnovy tvorit jde, to potvrdil i OTL, kdyz se mu jej podarilo vytvorit

:arrow: Podivame se tedy na registr ci je OK

:arrow: Stahnete SytemLook a ulozte jej na plochu http://jpshortstuff.247fixes.com/SystemLook_x64.exe
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :reg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore /sub
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Lilly [FR]

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#14 Příspěvek od Lilly [FR] »

:thumbsup: Mam to tady :


SystemLook 30.07.11 by jpshortstuff
Log created at 23:13 on 15/12/2011 by Admin - 7
Administrator - Elevation successful

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"RPSessionInterval"= 0x0000000001 (1)
"FirstRun"= 0x0000000000 (0)
"LastIndex"= 0x00000000cb (203)
"RestoreStatusResult"= 0x0000000005 (5)
"RestoreStatusRestore"="{45F60EB6-931A-46A6-A013-17631DB56E53}"
"RestoreStatusUndo"="{B4E19BBB-FBD0-4704-9AB1-E81A80627FFC}"
"LastRestoreId"="{050A1352-1718-4DAC-95EB-5F00B117A837}"
"RestoreStatusTimeStamp"=85 06 18 ee 53 bb cc 01 (REG_QWORD)
"RestoreStatusDescription"="1"
"RestoreStatusSource"= 0x0000000001 (1)
"GenerateErrorReport"= 0x0000000000 (0)
"RestoreErrorContext"="Nástroj Obnovení systému selhal při obnovení registru z bodu obnovení."
"RestoreStatusDetails"="0x80070002"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\cfg]
"DiskPercent"= 0x000000000f (15)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\ErrorReportFiles]
"restore"="C:\Windows\Logs\SystemRestore\restore.0.etl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup\Unattend]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup_Last]
"Generalize_DisableSR"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile]
"NestingLevel"= 0x0000000000 (0)
"StartNesting"=00 00 00 00 00 00 00 00 (REG_QWORD)


-= EOF =-

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola Logu - Podivuhodne Chovani Systemu - Windows 7

#15 Příspěvek od vyosek »

No registr nam toho moc nerekl, asi takto, zkusil bych kontaktovat technickou podporu microsoftu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět