
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Crash Norton, chrome
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Crash Norton, chrome
Dobrý den,
po rannim spusteni PC se mi objevila hlaska ,,areg.exe nemohl byt spusten protoze pamet neni read"(zhruba + nejaka adresa do pameti) ...zaroven prestal fungovat Norton respektive bezi, ale ma pozastavene vsechny sluzby a nejde ani otevrit. Nejde reinstalovat ani za pomoci Norton Removal tool nejde odstranit. Chrome je na tom podobne nejde spustit ani reinstalovat. IE bezi bez problemu stejne jako vsechno ostatni, alespon jsem si nicoho dalsiho nevsiml.
Diky za pomoc, radu ci nazor.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jejda at 2012-03-07 10:32:06
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (19%) free of 122 GB
Total RAM: 3949 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:12, on 7.3.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
(Unable to list running processes)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Logitech Scroll App - {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [S6000Mnt] C:\Windows\SysWOW64\Rundll32.exe S6000Rmv.dll,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10090 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\alg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe" /c /a /s UserSession
taskeng.exe {AB666476-FF6C-4BD6-87E0-4023D5C6D5CC}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
taskeng.exe {9F601ECB-F20C-403B-AC9D-83FE038D6E1D}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
"C:\Program Files\Logitech\ScrollApp\KhalScroll.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
KHALMNPR.EXE /API
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
C:\Windows\WebCam\S6000\S6000Mnt.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"C:\Program Files\Logitech\SetPointG\SetPointII.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
taskeng.exe {397D510C-9631-4618-850E-4AA0A9831785}
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
ATKOSD.exe
WDC.exe
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe -Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2452147725-53928134-1200324153-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2452147725-53928134-1200324153-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Users\Jejda\Desktop\Norton-Removal-Tool_2012.0.5.15.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
"C:\Users\Jejda\AppData\Local\Temp\7zS13CE.tmp\SymNRT.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\Jejda\Desktop\RSITx64.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
Logitech Scroll App - C:\Program Files\Logitech\ScrollApp\LogiSmooth.dll [2011-12-14 435992]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll [2011-12-09 436152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL [2011-03-31 210872]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-02-20 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-02-20 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
Logitech Scroll App - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll [2011-12-14 367384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll [2011-12-09 436152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-05 2085160]
"THXCfg64"=C:\Windows\system32\THXCfg64.dll [2009-10-15 17920]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
"LogiScrollApp"=C:\Program Files\Logitech\ScrollApp\KhalScroll.exe [2011-12-14 156440]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 136176]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-12-08 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-08-17 11438696]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"S6000Mnt"=C:\Windows\SysWOW64\Rundll32.exe [2009-07-14 44544]
"THX TruStudio NB Settings"=C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [2010-03-24 899072]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-06-24 6806144]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-05-03 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-08-11 1597440]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
"HTC Sync Loader"=C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2010-09-08 249856]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 month======
2012-03-07 10:32:06 ----D---- C:\rsit
2012-03-07 10:32:06 ----D---- C:\Program Files\trend micro
2012-03-07 08:36:30 ----D---- C:\Windows\system32\Macromed
2012-03-07 08:08:53 ----D---- C:\Program Files (x86)\HD Tune
2012-03-07 07:49:14 ----N---- C:\bootsqm.dat
2012-03-02 13:49:18 ----D---- C:\ProgramData\NVIDIA
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvvsvc.exe
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvsvcr.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvsvc64.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvshext.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvmctray.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvcpl.dll
2012-03-02 13:48:28 ----D---- C:\ProgramData\NVIDIA Corporation
2012-03-02 13:47:31 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\OpenCL.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvoglv64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvhdap64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvgenco64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvdispco64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuvid.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuda.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcompiler.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvapi64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-03-02 13:47:30 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-02-21 07:56:59 ----D---- C:\Users\Jejda\AppData\Roaming\AIMP3
2012-02-21 07:56:57 ----D---- C:\Program Files (x86)\AIMP3
2012-02-20 15:01:06 ----D---- C:\Program Files (x86)\Lineage II
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\java.exe
2012-02-20 10:31:49 ----D---- C:\ProgramData\EA Logs
2012-02-16 13:54:33 ----A---- C:\Windows\system32\shell32.dll
2012-02-16 13:54:32 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-02-16 13:54:32 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-02-16 13:54:32 ----A---- C:\Windows\system32\ntshrui.dll
2012-02-16 13:54:30 ----A---- C:\Windows\system32\win32k.sys
2012-02-16 13:54:30 ----A---- C:\Windows\system32\drivers\afd.sys
2012-02-16 13:54:27 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-02-16 13:54:27 ----A---- C:\Windows\system32\msvcrt.dll
2012-02-16 13:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-02-16 13:54:26 ----A---- C:\Windows\system32\mshtml.dll
2012-02-16 13:54:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-02-16 13:54:25 ----A---- C:\Windows\system32\urlmon.dll
2012-02-16 13:54:25 ----A---- C:\Windows\system32\ieframe.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\url.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\wininet.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\url.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\mshtmled.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\msfeeds.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\jsproxy.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\ieui.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\iertutil.dll
2012-02-16 13:14:53 ----A---- C:\Windows\system32\schannel.dll
2012-02-16 13:14:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\webio.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\sspisrv.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\sspicli.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\secur32.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\lsass.exe
2012-02-16 13:14:52 ----A---- C:\Windows\system32\lsasrv.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-02-16 13:14:52 ----A---- C:\Windows\system32\drivers\cng.sys
2012-02-09 20:05:44 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
======List of files/folders modified in the last 1 month======
2012-03-07 10:32:08 ----D---- C:\Windows\Temp
2012-03-07 10:32:06 ----RD---- C:\Program Files
2012-03-07 10:32:02 ----D---- C:\Windows\system32\config
2012-03-07 10:29:12 ----D---- C:\Windows\system32\Tasks
2012-03-07 10:29:10 ----D---- C:\Program Files\P4G
2012-03-07 10:29:10 ----A---- C:\Windows\system32\acovcnt.exe
2012-03-07 10:29:06 ----SHD---- C:\System Volume Information
2012-03-07 10:29:05 ----A---- C:\Windows\SYSWOW64\log.txt
2012-03-07 10:21:01 ----D---- C:\Windows\System32
2012-03-07 10:21:01 ----D---- C:\Windows\inf
2012-03-07 10:21:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-07 10:18:59 ----D---- C:\Windows\Prefetch
2012-03-07 08:41:16 ----D---- C:\Windows
2012-03-07 08:36:33 ----D---- C:\Windows\Downloaded Program Files
2012-03-07 08:08:53 ----RD---- C:\Program Files (x86)
2012-03-07 08:02:08 ----HD---- C:\ProgramData
2012-03-07 08:00:37 ----SHD---- C:\Windows\Installer
2012-03-07 08:00:37 ----SHD---- C:\Config.Msi
2012-03-07 08:00:37 ----D---- C:\ProgramData\Sonic
2012-03-07 08:00:32 ----D---- C:\Program Files (x86)\Common Files
2012-03-07 08:00:19 ----D---- C:\Windows\system32\drivers
2012-03-07 08:00:19 ----D---- C:\Windows\system32\catroot
2012-03-07 08:00:01 ----D---- C:\Program Files (x86)\ASUS
2012-03-07 07:59:51 ----D---- C:\Program Files\Common Files
2012-03-07 07:58:49 ----D---- C:\Users\Jejda\AppData\Roaming\uTorrent
2012-03-07 07:58:49 ----D---- C:\Users\Jejda\AppData\Roaming\DAEMON Tools Lite
2012-03-06 06:52:43 ----D---- C:\Windows\system32\wdi
2012-03-02 13:49:59 ----D---- C:\Windows\system32\DriverStore
2012-03-02 13:49:37 ----D---- C:\Windows\SysWOW64
2012-03-02 13:49:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-03-02 13:49:19 ----RD---- C:\Users
2012-03-02 13:49:19 ----D---- C:\Program Files\NVIDIA Corporation
2012-03-02 13:47:50 ----D---- C:\Windows\system32\catroot2
2012-03-02 13:42:41 ----D---- C:\Windows\LiveKernelReports
2012-02-26 10:50:36 ----D---- C:\Program Files (x86)\uTorrent
2012-02-22 07:15:05 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2012-02-20 14:58:14 ----D---- C:\Windows\ModemLogs
2012-02-20 14:57:48 ----D---- C:\Program Files\CCleaner
2012-02-20 14:55:15 ----D---- C:\Windows\Minidump
2012-02-20 14:55:15 ----D---- C:\Windows\Logs
2012-02-20 14:55:15 ----D---- C:\Windows\debug
2012-02-20 14:55:15 ----D---- C:\Users\Jejda\AppData\Roaming\TS3Client
2012-02-20 14:54:54 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-02-20 14:54:53 ----D---- C:\Program Files (x86)\Activision
2012-02-20 10:46:21 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-02-20 10:40:30 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-02-20 10:30:35 ----RSD---- C:\Windows\assembly
2012-02-20 09:58:07 ----D---- C:\Program Files (x86)\World of Warcraft
2012-02-17 13:18:41 ----D---- C:\Windows\Microsoft.NET
2012-02-17 08:55:44 ----D---- C:\Windows\winsxs
2012-02-17 01:04:01 ----D---- C:\Windows\SYSWOW64\migration
2012-02-17 01:04:01 ----D---- C:\Windows\system32\migration
2012-02-17 01:04:01 ----D---- C:\Program Files\Internet Explorer
2012-02-17 01:04:01 ----D---- C:\Program Files (x86)\Internet Explorer
2012-02-17 01:00:44 ----D---- C:\Program Files (x86)\Microsoft Office
2012-02-17 00:54:06 ----A---- C:\Windows\system32\MRT.exe
2012-02-16 17:31:48 ----D---- C:\Windows\system32\drivers\N360x64
2012-02-16 13:06:04 ----SHD---- C:\$Recycle.Bin
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-12-08 35384]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-06-08 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2011-12-09 272480]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-01-22 530488]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMDS64.SYS [2011-01-27 450680]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMEFA64.SYS [2011-03-15 912504]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2011-12-01 1157240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-22 279616]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2012-02-16 482936]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120306.002\IDSvia64.sys [2012-03-06 488568]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\0502000.00D\SRTSPX64.SYS [2011-03-31 40568]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\0502000.00D\Ironx64.SYS [2010-11-16 171128]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\N360x64\0502000.00D\SYMNETS.SYS [2011-04-21 386168]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2009-08-06 13784]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver; C:\Windows\system32\DRIVERS\FLxHCIc.sys [2010-05-28 108032]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2011-07-06 34288]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-08-17 2462440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120305.032\ENG64.SYS [2012-02-22 117880]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120305.032\EX64.SYS [2012-02-22 2048632]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-01-17 188224]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2010-07-26 318056]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 333928]
R3 S6000KNT;S6000KNT_WebCam Driver; C:\Windows\System32\Drivers\S6000KNT.sys [2010-05-13 190464]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\N360x64\0502000.00D\SRTSP64.SYS [2011-03-31 744568]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2011-12-08 174200]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-05 316464]
S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer; \??\D:\I386\AsPrOb64.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-01-15 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-15 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-15 21288]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbbus;LGE CDMA Composite USB Device; C:\Windows\system32\DRIVERS\lgx64bus.sys [2010-01-21 17920]
S3 UsbDiag;LGE CDMA USB Serial Port; C:\Windows\system32\DRIVERS\lgx64diag.sys [2010-01-21 27648]
S3 USBModem;LGE CDMA USB Modem; C:\Windows\system32\DRIVERS\lgx64modem.sys [2010-01-21 33280]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM); C:\Windows\system32\DRIVERS\vwmfbus.sys [2009-11-11 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfdiag.sys [2009-11-11 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~; C:\Windows\system32\DRIVERS\vwmfmdfl.sys [2009-11-11 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver; C:\Windows\system32\DRIVERS\vwmfmdm.sys [2009-11-11 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfserd.sys [2009-11-11 128512]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2010-06-22 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-11 873248]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 262144]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe [2011-04-17 130008]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-02-10 889664]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
R2 Správce výběru OS;Aktivátor Správce výběru OS Acronis; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-10-28 2156952]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-12-27 76888]
S3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S3 TurboBoost;TurboBoost; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-10 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
po rannim spusteni PC se mi objevila hlaska ,,areg.exe nemohl byt spusten protoze pamet neni read"(zhruba + nejaka adresa do pameti) ...zaroven prestal fungovat Norton respektive bezi, ale ma pozastavene vsechny sluzby a nejde ani otevrit. Nejde reinstalovat ani za pomoci Norton Removal tool nejde odstranit. Chrome je na tom podobne nejde spustit ani reinstalovat. IE bezi bez problemu stejne jako vsechno ostatni, alespon jsem si nicoho dalsiho nevsiml.
Diky za pomoc, radu ci nazor.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jejda at 2012-03-07 10:32:06
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (19%) free of 122 GB
Total RAM: 3949 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:12, on 7.3.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
(Unable to list running processes)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Logitech Scroll App - {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [S6000Mnt] C:\Windows\SysWOW64\Rundll32.exe S6000Rmv.dll,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10090 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\alg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe" /c /a /s UserSession
taskeng.exe {AB666476-FF6C-4BD6-87E0-4023D5C6D5CC}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
taskeng.exe {9F601ECB-F20C-403B-AC9D-83FE038D6E1D}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
"C:\Program Files\Logitech\ScrollApp\KhalScroll.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
KHALMNPR.EXE /API
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
C:\Windows\WebCam\S6000\S6000Mnt.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"C:\Program Files\Logitech\SetPointG\SetPointII.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
taskeng.exe {397D510C-9631-4618-850E-4AA0A9831785}
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
ATKOSD.exe
WDC.exe
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe -Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2452147725-53928134-1200324153-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2452147725-53928134-1200324153-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Users\Jejda\Desktop\Norton-Removal-Tool_2012.0.5.15.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
"C:\Users\Jejda\AppData\Local\Temp\7zS13CE.tmp\SymNRT.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\Jejda\Desktop\RSITx64.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
Logitech Scroll App - C:\Program Files\Logitech\ScrollApp\LogiSmooth.dll [2011-12-14 435992]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll [2011-12-09 436152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL [2011-03-31 210872]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-02-20 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-02-20 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
Logitech Scroll App - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll [2011-12-14 367384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\coIEPlg.dll [2011-12-09 436152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-05 2085160]
"THXCfg64"=C:\Windows\system32\THXCfg64.dll [2009-10-15 17920]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
"LogiScrollApp"=C:\Program Files\Logitech\ScrollApp\KhalScroll.exe [2011-12-14 156440]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 136176]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-12-08 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-08-17 11438696]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"S6000Mnt"=C:\Windows\SysWOW64\Rundll32.exe [2009-07-14 44544]
"THX TruStudio NB Settings"=C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [2010-03-24 899072]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-06-24 6806144]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-05-03 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-08-11 1597440]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
"HTC Sync Loader"=C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2010-09-08 249856]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 month======
2012-03-07 10:32:06 ----D---- C:\rsit
2012-03-07 10:32:06 ----D---- C:\Program Files\trend micro
2012-03-07 08:36:30 ----D---- C:\Windows\system32\Macromed
2012-03-07 08:08:53 ----D---- C:\Program Files (x86)\HD Tune
2012-03-07 07:49:14 ----N---- C:\bootsqm.dat
2012-03-02 13:49:18 ----D---- C:\ProgramData\NVIDIA
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvvsvc.exe
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvsvcr.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvsvc64.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvshext.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvmctray.dll
2012-03-02 13:48:56 ----A---- C:\Windows\system32\nvcpl.dll
2012-03-02 13:48:28 ----D---- C:\ProgramData\NVIDIA Corporation
2012-03-02 13:47:31 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-03-02 13:47:30 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\OpenCL.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvoglv64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvhdap64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvgenco64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvdispco64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuvid.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcuda.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvcompiler.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\nvapi64.dll
2012-03-02 13:47:30 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-03-02 13:47:30 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-02-21 07:56:59 ----D---- C:\Users\Jejda\AppData\Roaming\AIMP3
2012-02-21 07:56:57 ----D---- C:\Program Files (x86)\AIMP3
2012-02-20 15:01:06 ----D---- C:\Program Files (x86)\Lineage II
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-02-20 10:40:35 ----A---- C:\Windows\SYSWOW64\java.exe
2012-02-20 10:31:49 ----D---- C:\ProgramData\EA Logs
2012-02-16 13:54:33 ----A---- C:\Windows\system32\shell32.dll
2012-02-16 13:54:32 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-02-16 13:54:32 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-02-16 13:54:32 ----A---- C:\Windows\system32\ntshrui.dll
2012-02-16 13:54:30 ----A---- C:\Windows\system32\win32k.sys
2012-02-16 13:54:30 ----A---- C:\Windows\system32\drivers\afd.sys
2012-02-16 13:54:27 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-02-16 13:54:27 ----A---- C:\Windows\system32\msvcrt.dll
2012-02-16 13:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-02-16 13:54:26 ----A---- C:\Windows\system32\mshtml.dll
2012-02-16 13:54:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-02-16 13:54:25 ----A---- C:\Windows\system32\urlmon.dll
2012-02-16 13:54:25 ----A---- C:\Windows\system32\ieframe.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\url.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-02-16 13:54:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\wininet.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\url.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\mshtmled.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\msfeeds.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\jsproxy.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\ieui.dll
2012-02-16 13:54:24 ----A---- C:\Windows\system32\iertutil.dll
2012-02-16 13:14:53 ----A---- C:\Windows\system32\schannel.dll
2012-02-16 13:14:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-02-16 13:14:52 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\webio.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\sspisrv.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\sspicli.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\secur32.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\lsass.exe
2012-02-16 13:14:52 ----A---- C:\Windows\system32\lsasrv.dll
2012-02-16 13:14:52 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-02-16 13:14:52 ----A---- C:\Windows\system32\drivers\cng.sys
2012-02-09 20:05:44 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
======List of files/folders modified in the last 1 month======
2012-03-07 10:32:08 ----D---- C:\Windows\Temp
2012-03-07 10:32:06 ----RD---- C:\Program Files
2012-03-07 10:32:02 ----D---- C:\Windows\system32\config
2012-03-07 10:29:12 ----D---- C:\Windows\system32\Tasks
2012-03-07 10:29:10 ----D---- C:\Program Files\P4G
2012-03-07 10:29:10 ----A---- C:\Windows\system32\acovcnt.exe
2012-03-07 10:29:06 ----SHD---- C:\System Volume Information
2012-03-07 10:29:05 ----A---- C:\Windows\SYSWOW64\log.txt
2012-03-07 10:21:01 ----D---- C:\Windows\System32
2012-03-07 10:21:01 ----D---- C:\Windows\inf
2012-03-07 10:21:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-07 10:18:59 ----D---- C:\Windows\Prefetch
2012-03-07 08:41:16 ----D---- C:\Windows
2012-03-07 08:36:33 ----D---- C:\Windows\Downloaded Program Files
2012-03-07 08:08:53 ----RD---- C:\Program Files (x86)
2012-03-07 08:02:08 ----HD---- C:\ProgramData
2012-03-07 08:00:37 ----SHD---- C:\Windows\Installer
2012-03-07 08:00:37 ----SHD---- C:\Config.Msi
2012-03-07 08:00:37 ----D---- C:\ProgramData\Sonic
2012-03-07 08:00:32 ----D---- C:\Program Files (x86)\Common Files
2012-03-07 08:00:19 ----D---- C:\Windows\system32\drivers
2012-03-07 08:00:19 ----D---- C:\Windows\system32\catroot
2012-03-07 08:00:01 ----D---- C:\Program Files (x86)\ASUS
2012-03-07 07:59:51 ----D---- C:\Program Files\Common Files
2012-03-07 07:58:49 ----D---- C:\Users\Jejda\AppData\Roaming\uTorrent
2012-03-07 07:58:49 ----D---- C:\Users\Jejda\AppData\Roaming\DAEMON Tools Lite
2012-03-06 06:52:43 ----D---- C:\Windows\system32\wdi
2012-03-02 13:49:59 ----D---- C:\Windows\system32\DriverStore
2012-03-02 13:49:37 ----D---- C:\Windows\SysWOW64
2012-03-02 13:49:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-03-02 13:49:19 ----RD---- C:\Users
2012-03-02 13:49:19 ----D---- C:\Program Files\NVIDIA Corporation
2012-03-02 13:47:50 ----D---- C:\Windows\system32\catroot2
2012-03-02 13:42:41 ----D---- C:\Windows\LiveKernelReports
2012-02-26 10:50:36 ----D---- C:\Program Files (x86)\uTorrent
2012-02-22 07:15:05 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2012-02-20 14:58:14 ----D---- C:\Windows\ModemLogs
2012-02-20 14:57:48 ----D---- C:\Program Files\CCleaner
2012-02-20 14:55:15 ----D---- C:\Windows\Minidump
2012-02-20 14:55:15 ----D---- C:\Windows\Logs
2012-02-20 14:55:15 ----D---- C:\Windows\debug
2012-02-20 14:55:15 ----D---- C:\Users\Jejda\AppData\Roaming\TS3Client
2012-02-20 14:54:54 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-02-20 14:54:53 ----D---- C:\Program Files (x86)\Activision
2012-02-20 10:46:21 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-02-20 10:40:30 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-02-20 10:30:35 ----RSD---- C:\Windows\assembly
2012-02-20 09:58:07 ----D---- C:\Program Files (x86)\World of Warcraft
2012-02-17 13:18:41 ----D---- C:\Windows\Microsoft.NET
2012-02-17 08:55:44 ----D---- C:\Windows\winsxs
2012-02-17 01:04:01 ----D---- C:\Windows\SYSWOW64\migration
2012-02-17 01:04:01 ----D---- C:\Windows\system32\migration
2012-02-17 01:04:01 ----D---- C:\Program Files\Internet Explorer
2012-02-17 01:04:01 ----D---- C:\Program Files (x86)\Internet Explorer
2012-02-17 01:00:44 ----D---- C:\Program Files (x86)\Microsoft Office
2012-02-17 00:54:06 ----A---- C:\Windows\system32\MRT.exe
2012-02-16 17:31:48 ----D---- C:\Windows\system32\drivers\N360x64
2012-02-16 13:06:04 ----SHD---- C:\$Recycle.Bin
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-12-08 35384]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-06-08 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2011-12-09 272480]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-01-22 530488]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMDS64.SYS [2011-01-27 450680]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMEFA64.SYS [2011-03-15 912504]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2011-12-01 1157240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-22 279616]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2012-02-16 482936]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120306.002\IDSvia64.sys [2012-03-06 488568]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\0502000.00D\SRTSPX64.SYS [2011-03-31 40568]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\0502000.00D\Ironx64.SYS [2010-11-16 171128]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\N360x64\0502000.00D\SYMNETS.SYS [2011-04-21 386168]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2009-08-06 13784]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver; C:\Windows\system32\DRIVERS\FLxHCIc.sys [2010-05-28 108032]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2011-07-06 34288]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-08-17 2462440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120305.032\ENG64.SYS [2012-02-22 117880]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120305.032\EX64.SYS [2012-02-22 2048632]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-01-17 188224]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2010-07-26 318056]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 333928]
R3 S6000KNT;S6000KNT_WebCam Driver; C:\Windows\System32\Drivers\S6000KNT.sys [2010-05-13 190464]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\N360x64\0502000.00D\SRTSP64.SYS [2011-03-31 744568]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2011-12-08 174200]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-05 316464]
S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer; \??\D:\I386\AsPrOb64.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-01-15 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-15 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-15 21288]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbbus;LGE CDMA Composite USB Device; C:\Windows\system32\DRIVERS\lgx64bus.sys [2010-01-21 17920]
S3 UsbDiag;LGE CDMA USB Serial Port; C:\Windows\system32\DRIVERS\lgx64diag.sys [2010-01-21 27648]
S3 USBModem;LGE CDMA USB Modem; C:\Windows\system32\DRIVERS\lgx64modem.sys [2010-01-21 33280]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM); C:\Windows\system32\DRIVERS\vwmfbus.sys [2009-11-11 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfdiag.sys [2009-11-11 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~; C:\Windows\system32\DRIVERS\vwmfmdfl.sys [2009-11-11 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver; C:\Windows\system32\DRIVERS\vwmfmdm.sys [2009-11-11 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM); C:\Windows\system32\DRIVERS\vwmfserd.sys [2009-11-11 128512]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2010-06-22 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-11 873248]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 262144]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\5.2.0.13\ccSvcHst.exe [2011-04-17 130008]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-02-10 889664]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
R2 Správce výběru OS;Aktivátor Správce výběru OS Acronis; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-10-28 2156952]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-12-27 76888]
S3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S3 TurboBoost;TurboBoost; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-10 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119378
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Crash Norton, chrome
Zdravím!
Poprosím o log ComboFix.
Poprosím o log ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Crash Norton, chrome
CombFix log a díky za zájem 
ComboFix 12-03-07.05 - Jejda 07.03.2012 21:35:44.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2945 [GMT 1:00]
Spuštěný z: c:\users\Jejda\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\SysWow64\tmp3938.tmp
c:\windows\SysWow64\tmp3E96.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-07 do 2012-03-07 )))))))))))))))))))))))))))))))
.
.
2012-03-07 20:39 . 2012-03-07 20:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-07 10:25 . 2012-03-07 10:25 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- C:\rsit
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- c:\program files\trend micro
2012-03-07 09:19 . 2012-03-07 09:23 -------- d-----w- c:\users\Jejda\AppData\Local\Deployment
2012-03-07 09:19 . 2012-03-07 09:19 -------- d-----w- c:\users\Jejda\AppData\Local\Apps
2012-03-07 07:36 . 2012-03-07 07:36 -------- d-----w- c:\windows\system32\Macromed
2012-03-07 07:08 . 2012-03-07 07:08 -------- d-----w- c:\program files (x86)\HD Tune
2012-03-02 12:49 . 2012-03-02 12:49 -------- d-----w- c:\users\UpdatusUser
2012-03-02 12:49 . 2012-03-07 10:21 -------- d-----w- c:\programdata\NVIDIA
2012-03-02 12:48 . 2012-02-10 03:14 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-03-02 12:48 . 2012-02-10 03:14 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-03-02 12:48 . 2012-02-10 03:07 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-03-02 12:48 . 2012-02-10 03:07 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-03-02 12:48 . 2012-02-10 03:07 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-03-02 12:48 . 2012-02-10 03:07 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-03-02 12:48 . 2012-03-02 12:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-02-21 06:56 . 2012-03-07 16:29 -------- d-----w- c:\users\Jejda\AppData\Roaming\AIMP3
2012-02-21 06:56 . 2012-02-21 06:56 -------- d-----w- c:\program files (x86)\AIMP3
2012-02-20 14:01 . 2012-03-07 11:12 -------- d-----w- c:\program files (x86)\Lineage II
2012-02-20 09:40 . 2012-02-20 09:40 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-20 09:31 . 2012-02-20 09:42 -------- d-----w- c:\programdata\EA Logs
2012-02-16 12:21 . 2012-03-07 10:21 -------- d-----w- c:\windows\system32\drivers\N360x64\0502000.00D
2012-02-09 19:05 . 2012-02-09 19:05 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 10:22 . 2011-12-10 13:44 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-02-20 09:46 . 2011-12-27 13:25 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-20 09:46 . 2011-12-27 13:24 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-20 09:42 . 2011-12-27 13:24 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-20 09:40 . 2011-12-20 16:17 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-22 18:09 . 2012-01-22 18:06 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-05 09:34 . 2012-01-05 09:34 53248 ----a-r- c:\users\Jejda\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-05 09:34 . 2012-01-05 09:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-12-27 13:24 . 2011-12-27 13:24 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-27 13:24 . 2011-12-27 13:24 840264 ----a-w- c:\windows\SysWow64\pbsvc.exe
2011-12-09 09:02 . 2011-12-09 09:02 272480 ----a-w- c:\windows\system32\drivers\snapman.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:25 367384 ----a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2010-03-24 899072]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-08-11 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
.
c:\users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registrace produktu.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-12-8 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;d:\i386\AsPrOb64.sys [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
R3 vwmfbus;Vertex Wireless Composite Device driver (WDM);c:\windows\system32\DRIVERS\vwmfbus.sys [x]
R3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfdiag.sys [x]
R3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;c:\windows\system32\DRIVERS\vwmfmdfl.sys [x]
R3 vwmfmdm;Vertex Wireless CDC Modem Driver;c:\windows\system32\DRIVERS\vwmfmdm.sys [x]
R3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfserd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\Drivers\S6000KNT.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 21:35]
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 21:35]
.
2012-03-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
- c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 13:34]
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
- c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 13:34]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:24 435992 ----a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
"LogiScrollApp"="c:\program files\Logitech\ScrollApp\KhalScroll.exe" [2011-12-14 156440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}\86F6D656E2E65647: NameServer = 10.1.19.10,10.1.19.201
.
.
------- Asociace souborů -------
.
txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-S6000Mnt - S6000Rmv.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-03-07 21:40:49
ComboFix-quarantined-files.txt 2012-03-07 20:40
.
Před spuštěním: Volných bajtů: 24 673 251 328
Po spuštění: Volných bajtů: 24 597 913 600
.
- - End Of File - - F06D37155C7AB9996C7FE6C767266453

ComboFix 12-03-07.05 - Jejda 07.03.2012 21:35:44.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2945 [GMT 1:00]
Spuštěný z: c:\users\Jejda\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\SysWow64\tmp3938.tmp
c:\windows\SysWow64\tmp3E96.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-07 do 2012-03-07 )))))))))))))))))))))))))))))))
.
.
2012-03-07 20:39 . 2012-03-07 20:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-07 10:25 . 2012-03-07 10:25 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- C:\rsit
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- c:\program files\trend micro
2012-03-07 09:19 . 2012-03-07 09:23 -------- d-----w- c:\users\Jejda\AppData\Local\Deployment
2012-03-07 09:19 . 2012-03-07 09:19 -------- d-----w- c:\users\Jejda\AppData\Local\Apps
2012-03-07 07:36 . 2012-03-07 07:36 -------- d-----w- c:\windows\system32\Macromed
2012-03-07 07:08 . 2012-03-07 07:08 -------- d-----w- c:\program files (x86)\HD Tune
2012-03-02 12:49 . 2012-03-02 12:49 -------- d-----w- c:\users\UpdatusUser
2012-03-02 12:49 . 2012-03-07 10:21 -------- d-----w- c:\programdata\NVIDIA
2012-03-02 12:48 . 2012-02-10 03:14 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-03-02 12:48 . 2012-02-10 03:14 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-03-02 12:48 . 2012-02-10 03:07 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-03-02 12:48 . 2012-02-10 03:07 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-03-02 12:48 . 2012-02-10 03:07 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-03-02 12:48 . 2012-02-10 03:07 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-03-02 12:48 . 2012-03-02 12:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-02-21 06:56 . 2012-03-07 16:29 -------- d-----w- c:\users\Jejda\AppData\Roaming\AIMP3
2012-02-21 06:56 . 2012-02-21 06:56 -------- d-----w- c:\program files (x86)\AIMP3
2012-02-20 14:01 . 2012-03-07 11:12 -------- d-----w- c:\program files (x86)\Lineage II
2012-02-20 09:40 . 2012-02-20 09:40 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-20 09:31 . 2012-02-20 09:42 -------- d-----w- c:\programdata\EA Logs
2012-02-16 12:21 . 2012-03-07 10:21 -------- d-----w- c:\windows\system32\drivers\N360x64\0502000.00D
2012-02-09 19:05 . 2012-02-09 19:05 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 10:22 . 2011-12-10 13:44 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-02-20 09:46 . 2011-12-27 13:25 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-20 09:46 . 2011-12-27 13:24 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-20 09:42 . 2011-12-27 13:24 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-20 09:40 . 2011-12-20 16:17 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-22 18:09 . 2012-01-22 18:06 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-05 09:34 . 2012-01-05 09:34 53248 ----a-r- c:\users\Jejda\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-05 09:34 . 2012-01-05 09:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-12-27 13:24 . 2011-12-27 13:24 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-27 13:24 . 2011-12-27 13:24 840264 ----a-w- c:\windows\SysWow64\pbsvc.exe
2011-12-09 09:02 . 2011-12-09 09:02 272480 ----a-w- c:\windows\system32\drivers\snapman.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:25 367384 ----a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2010-03-24 899072]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-08-11 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
.
c:\users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registrace produktu.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-12-8 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;d:\i386\AsPrOb64.sys [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 136176]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
R3 vwmfbus;Vertex Wireless Composite Device driver (WDM);c:\windows\system32\DRIVERS\vwmfbus.sys [x]
R3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfdiag.sys [x]
R3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;c:\windows\system32\DRIVERS\vwmfmdfl.sys [x]
R3 vwmfmdm;Vertex Wireless CDC Modem Driver;c:\windows\system32\DRIVERS\vwmfmdm.sys [x]
R3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfserd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\Drivers\S6000KNT.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 21:35]
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-09 21:35]
.
2012-03-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
- c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 13:34]
.
2012-03-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
- c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-08 13:34]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:24 435992 ----a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
"LogiScrollApp"="c:\program files\Logitech\ScrollApp\KhalScroll.exe" [2011-12-14 156440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}\86F6D656E2E65647: NameServer = 10.1.19.10,10.1.19.201
.
.
------- Asociace souborů -------
.
txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-S6000Mnt - S6000Rmv.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-03-07 21:40:49
ComboFix-quarantined-files.txt 2012-03-07 20:40
.
Před spuštěním: Volných bajtů: 24 673 251 328
Po spuštění: Volných bajtů: 24 597 913 600
.
- - End Of File - - F06D37155C7AB9996C7FE6C767266453
- Rudy
- Site Admin
- Příspěvky: 119378
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Crash Norton, chrome
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:

Uložte na plochu jako CFSCript.txt. pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.KillAll::
Folder::
c:\program files (x86)\Google\Update
c:\users\Jejda\AppData\Local\Google\Update
Collect::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
Driver::
gupdate
gupdatem
Regnull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Crash Norton, chrome
Mno, pisu z jineho NB. Pri spusteni IE se mi objevila hlaska ,,Pokus použít neplatnou operaci na klíč registru, který je označen pro odstranění." ...napíše se i při spuštění instalace chrome.
Log se přetáhl přes flasku.
ComboFix 12-03-07.05 - Jejda 07.03.2012 22:01:19.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2487 [GMT 1:00]
Spuštěný z: c:\users\Jejda\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jejda\Desktop\CFSCript.TXT
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.99\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.99\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.99\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.99\psuser.dll
c:\program files (x86)\Google\Update\Download\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\0.0.0.0\GoogleEarth-Win-Plugin-6.1.0.5001.exe
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.99\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler64.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateBroker.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateHelper.msi
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateOnDemand.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdate.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_am.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ar.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_bg.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_bn.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ca.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_cs.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_da.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_de.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_el.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_en-GB.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_en.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_es-419.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_es.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_et.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fa.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fil.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_gu.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hu.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_id.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_is.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_it.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_iw.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ja.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_kn.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ko.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_lt.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_lv.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ml.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_mr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ms.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_nl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_no.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pt-BR.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pt-PT.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ro.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ru.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sk.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sv.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sw.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ta.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_te.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_th.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_tr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_uk.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ur.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_vi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_zh-CN.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_zh-TW.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\psmachine.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\psuser.dll
c:\users\Jejda\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.99\GoogleUpdateSetup.exe
c:\users\Jejda\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\17.0.963.66\chrome_updater.exe
c:\users\Jejda\AppData\Local\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\17.0.963.66\chrome_installer.exe
c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update\Install\{BE601FC6-2F36-4DEE-AE55-2738981DF566}\chrome_installer.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-07 do 2012-03-07 )))))))))))))))))))))))))))))))
.
.
2012-03-07 10:25 . 2012-03-07 10:25 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- C:\rsit
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- c:\program files\trend micro
2012-03-07 09:19 . 2012-03-07 09:23 -------- d-----w- c:\users\Jejda\AppData\Local\Deployment
2012-03-07 09:19 . 2012-03-07 09:19 -------- d-----w- c:\users\Jejda\AppData\Local\Apps
2012-03-07 07:36 . 2012-03-07 07:36 -------- d-----w- c:\windows\system32\Macromed
2012-03-07 07:08 . 2012-03-07 07:08 -------- d-----w- c:\program files (x86)\HD Tune
2012-03-02 12:49 . 2012-03-02 12:49 -------- d-----w- c:\users\UpdatusUser
2012-03-02 12:49 . 2012-03-07 21:04 -------- d-----w- c:\programdata\NVIDIA
2012-03-02 12:48 . 2012-02-10 03:14 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-03-02 12:48 . 2012-02-10 03:14 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-03-02 12:48 . 2012-02-10 03:07 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-03-02 12:48 . 2012-02-10 03:07 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-03-02 12:48 . 2012-02-10 03:07 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-03-02 12:48 . 2012-02-10 03:07 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-03-02 12:48 . 2012-03-02 12:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-02-21 06:56 . 2012-03-07 16:29 -------- d-----w- c:\users\Jejda\AppData\Roaming\AIMP3
2012-02-21 06:56 . 2012-02-21 06:56 -------- d-----w- c:\program files (x86)\AIMP3
2012-02-20 14:01 . 2012-03-07 11:12 -------- d-----w- c:\program files (x86)\Lineage II
2012-02-20 09:40 . 2012-02-20 09:40 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-20 09:31 . 2012-02-20 09:42 -------- d-----w- c:\programdata\EA Logs
2012-02-16 12:21 . 2012-03-07 10:21 -------- d-----w- c:\windows\system32\drivers\N360x64\0502000.00D
2012-02-09 19:05 . 2012-02-09 19:05 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 21:05 . 2011-12-10 13:44 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-02-20 09:46 . 2011-12-27 13:25 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-20 09:46 . 2011-12-27 13:24 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-20 09:42 . 2011-12-27 13:24 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-20 09:40 . 2011-12-20 16:17 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-22 18:09 . 2012-01-22 18:06 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-05 09:34 . 2012-01-05 09:34 53248 ----a-r- c:\users\Jejda\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-05 09:34 . 2012-01-05 09:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-12-27 13:24 . 2011-12-27 13:24 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-27 13:24 . 2011-12-27 13:24 840264 ----a-w- c:\windows\SysWow64\pbsvc.exe
2011-12-09 09:02 . 2011-12-09 09:02 272480 ----a-w- c:\windows\system32\drivers\snapman.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-07_20.39.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-08 17:00 . 2012-03-07 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-12-08 17:00 . 2012-03-07 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-12-08 17:00 . 2012-03-07 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-08 17:00 . 2012-03-07 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-07 21:04 . 2012-03-07 21:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-07 10:21 . 2012-03-07 10:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-07 10:21 . 2012-03-07 10:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-03-07 21:04 . 2012-03-07 21:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-12-08 14:09 . 2012-03-07 10:21 553624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-12-08 14:09 . 2012-03-07 21:04 553624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2012-03-07 21:04 275068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-03-07 10:21 275068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:25 367384 ----a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2010-03-24 899072]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-08-11 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
.
c:\users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registrace produktu.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-12-8 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;d:\i386\AsPrOb64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
R3 vwmfbus;Vertex Wireless Composite Device driver (WDM);c:\windows\system32\DRIVERS\vwmfbus.sys [x]
R3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfdiag.sys [x]
R3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;c:\windows\system32\DRIVERS\vwmfmdfl.sys [x]
R3 vwmfmdm;Vertex Wireless CDC Modem Driver;c:\windows\system32\DRIVERS\vwmfmdm.sys [x]
R3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfserd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\Drivers\S6000KNT.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:24 435992 ----a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
"LogiScrollApp"="c:\program files\Logitech\ScrollApp\KhalScroll.exe" [2011-12-14 156440]
"combofix"="c:\combofix\CF18880.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}\86F6D656E2E65647: NameServer = 10.1.19.10,10.1.19.201
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
.
**************************************************************************
.
Celkový čas: 2012-03-07 22:06:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-03-07 21:06
ComboFix2.txt 2012-03-07 20:40
.
Před spuštěním: Volných bajtů: 24 648 982 528
Po spuštění: Volných bajtů: 24 255 524 864
.
- - End Of File - - 5574B3EEE8B5D5D54B58365179A2E5D8
Nahr nˇ probŘhlo ŁspŘçnŘ
Log se přetáhl přes flasku.
ComboFix 12-03-07.05 - Jejda 07.03.2012 22:01:19.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2487 [GMT 1:00]
Spuštěný z: c:\users\Jejda\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jejda\Desktop\CFSCript.TXT
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.99\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.99\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.99\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.99\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.99\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.99\psuser.dll
c:\program files (x86)\Google\Update\Download\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\0.0.0.0\GoogleEarth-Win-Plugin-6.1.0.5001.exe
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.99\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler64.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateBroker.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateHelper.msi
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\GoogleUpdateOnDemand.exe
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdate.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_am.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ar.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_bg.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_bn.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ca.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_cs.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_da.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_de.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_el.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_en-GB.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_en.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_es-419.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_es.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_et.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fa.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fil.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_fr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_gu.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_hu.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_id.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_is.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_it.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_iw.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ja.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_kn.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ko.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_lt.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_lv.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ml.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_mr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ms.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_nl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_no.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pt-BR.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_pt-PT.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ro.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ru.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sk.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sl.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sv.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_sw.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ta.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_te.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_th.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_tr.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_uk.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_ur.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_vi.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_zh-CN.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\goopdateres_zh-TW.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\psmachine.dll
c:\users\Jejda\AppData\Local\Google\Update\1.3.21.99\psuser.dll
c:\users\Jejda\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.99\GoogleUpdateSetup.exe
c:\users\Jejda\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\17.0.963.66\chrome_updater.exe
c:\users\Jejda\AppData\Local\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\17.0.963.66\chrome_installer.exe
c:\users\Jejda\AppData\Local\Google\Update\GoogleUpdate.exe
c:\users\Jejda\AppData\Local\Google\Update\Install\{BE601FC6-2F36-4DEE-AE55-2738981DF566}\chrome_installer.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2452147725-53928134-1200324153-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-07 do 2012-03-07 )))))))))))))))))))))))))))))))
.
.
2012-03-07 10:25 . 2012-03-07 10:25 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- C:\rsit
2012-03-07 09:32 . 2012-03-07 09:32 -------- d-----w- c:\program files\trend micro
2012-03-07 09:19 . 2012-03-07 09:23 -------- d-----w- c:\users\Jejda\AppData\Local\Deployment
2012-03-07 09:19 . 2012-03-07 09:19 -------- d-----w- c:\users\Jejda\AppData\Local\Apps
2012-03-07 07:36 . 2012-03-07 07:36 -------- d-----w- c:\windows\system32\Macromed
2012-03-07 07:08 . 2012-03-07 07:08 -------- d-----w- c:\program files (x86)\HD Tune
2012-03-02 12:49 . 2012-03-02 12:49 -------- d-----w- c:\users\UpdatusUser
2012-03-02 12:49 . 2012-03-07 21:04 -------- d-----w- c:\programdata\NVIDIA
2012-03-02 12:48 . 2012-02-10 03:14 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-03-02 12:48 . 2012-02-10 03:14 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-03-02 12:48 . 2012-02-10 03:07 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-03-02 12:48 . 2012-02-10 03:07 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-03-02 12:48 . 2012-02-10 03:07 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-03-02 12:48 . 2012-02-10 03:07 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-03-02 12:48 . 2012-03-02 12:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-02-21 06:56 . 2012-03-07 16:29 -------- d-----w- c:\users\Jejda\AppData\Roaming\AIMP3
2012-02-21 06:56 . 2012-02-21 06:56 -------- d-----w- c:\program files (x86)\AIMP3
2012-02-20 14:01 . 2012-03-07 11:12 -------- d-----w- c:\program files (x86)\Lineage II
2012-02-20 09:40 . 2012-02-20 09:40 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-20 09:31 . 2012-02-20 09:42 -------- d-----w- c:\programdata\EA Logs
2012-02-16 12:21 . 2012-03-07 10:21 -------- d-----w- c:\windows\system32\drivers\N360x64\0502000.00D
2012-02-09 19:05 . 2012-02-09 19:05 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 21:05 . 2011-12-10 13:44 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-02-20 09:46 . 2011-12-27 13:25 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-20 09:46 . 2011-12-27 13:24 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-20 09:42 . 2011-12-27 13:24 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-20 09:40 . 2011-12-20 16:17 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-22 18:09 . 2012-01-22 18:06 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-05 09:34 . 2012-01-05 09:34 53248 ----a-r- c:\users\Jejda\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-05 09:34 . 2012-01-05 09:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-12-27 13:24 . 2011-12-27 13:24 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-27 13:24 . 2011-12-27 13:24 840264 ----a-w- c:\windows\SysWow64\pbsvc.exe
2011-12-09 09:02 . 2011-12-09 09:02 272480 ----a-w- c:\windows\system32\drivers\snapman.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-07_20.39.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-08 17:00 . 2012-03-07 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-12-08 17:00 . 2012-03-07 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-12-08 17:00 . 2012-03-07 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-08 17:00 . 2012-03-07 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-07 21:04 . 2012-03-07 21:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-07 10:21 . 2012-03-07 10:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-07 10:21 . 2012-03-07 10:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-03-07 21:04 . 2012-03-07 21:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-12-08 14:09 . 2012-03-07 10:21 553624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-12-08 14:09 . 2012-03-07 21:04 553624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2012-03-07 21:04 275068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-03-07 10:21 275068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:25 367384 ----a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2010-03-24 899072]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-08-11 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
.
c:\users\Jejda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registrace produktu.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-12-8 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;d:\i386\AsPrOb64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-08 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-08 79360]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-08-06 118672]
R3 vwmfbus;Vertex Wireless Composite Device driver (WDM);c:\windows\system32\DRIVERS\vwmfbus.sys [x]
R3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfdiag.sys [x]
R3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;c:\windows\system32\DRIVERS\vwmfmdfl.sys [x]
R3 vwmfmdm;Vertex Wireless CDC Modem Driver;c:\windows\system32\DRIVERS\vwmfmdm.sys [x]
R3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfserd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\Drivers\S6000KNT.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-12-14 07:24 435992 ----a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
"LogiScrollApp"="c:\program files\Logitech\ScrollApp\KhalScroll.exe" [2011-12-14 156440]
"combofix"="c:\combofix\CF18880.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}: NameServer = 10.1.19.10,10.1.19.201
TCP: Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}\86F6D656E2E65647: NameServer = 10.1.19.10,10.1.19.201
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
.
**************************************************************************
.
Celkový čas: 2012-03-07 22:06:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-03-07 21:06
ComboFix2.txt 2012-03-07 20:40
.
Před spuštěním: Volných bajtů: 24 648 982 528
Po spuštění: Volných bajtů: 24 255 524 864
.
- - End Of File - - 5574B3EEE8B5D5D54B58365179A2E5D8
Nahr nˇ probŘhlo ŁspŘçnŘ
Re: Crash Norton, chrome
Tak po restartu se ta hlaska uz neobjevuje.IE jede. Chrome ci Norton, ale nainstalovat porad nejdou. Spusti se parkrat problikne a nic.
- Rudy
- Site Admin
- Příspěvky: 119378
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Crash Norton, chrome
Udělejte kompletní sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Crash Norton, chrome
Chvili po spusteni instalace Kaspersky Removal tool vylítne hlaska ,,Aplikaci (0xc000007b) se nepodarilo spravne pusti. kliknutim na tlacitko ji ukoncite... 

- Rudy
- Site Admin
- Příspěvky: 119378
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Crash Norton, chrome
Zkuste sken GMER: http://forum.viry.cz/viewtopic.php?f=29&t=62878 a dejte oba logy.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Crash Norton, chrome
GMER mi bouzel nenabidl vsechny moznosti jen (Sevices, Registry, Files) ...jako spravce byl spusteny, v nouzovem rezimu to same. Do prvního malého logu se neulozilo nic.
Druhy log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-08 21:23:41
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR9285 \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06dbc5655
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\6To4\{EF85D805-0B7B-418E-866F-41E446C542CC}@InterfaceName Reusable Microsoft 6To4 Adapter
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\6To4\{EF85D805-0B7B-418E-866F-41E446C542CC}@ReusableType 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1D 0x3F 0xD8 0xE6 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF0 0x6C 0x79 0x48 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8A 0xDF 0x36 0x30 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x37 0x89 0x7A 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemStartTime 0x59 0xFC 0x9D 0xD3 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemLastStartTime 0xC8 0x49 0x45 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFStartTime 0x59 0xFC 0x9D 0xD3 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFLastStartTime 0xC8 0x49 0x45 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData\BootLanguages@cs-CZ 88
Reg HKLM\SYSTEM\ControlSet002\Control\Diagnostics\Performance@ActiveShutdownDCL C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001
Reg HKLM\SYSTEM\ControlSet002\Control\GraphicsDrivers\Configuration\AUO22EC0_01_07D9_C0^4EA9F56D234B0A8BC22D458D6788508F@Timestamp 0xE1 0x23 0xF7 0xD4 ...
Reg HKLM\SYSTEM\ControlSet002\Control\Lsa@LsaPid 700
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR9285 \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Microsoft ISATAP Adapter 1?2?3?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}\Connection@Name isatap.{A20A90D2-836C-40C9-9448-DCFC9455F5DE}
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@DefaultNameResourceId 1801
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@DefaultNameIndex 3
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@Name Reusable ISATAP Interface {4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@DefaultNameResourceId 1801
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@DefaultNameIndex 3
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@Name isatap.oslavany.net
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"{EF85D805-0B7B-418E-866F-41E446C542CC}"?"{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\TCPIP6TUNNEL_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\TCPIP6TUNNEL_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\TCPIP6TUNNEL_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BootId 98
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 344614933
Reg HKLM\SYSTEM\ControlSet002\Control\Terminal Server@InstanceID 91d9e687-9bdf-4d81-a03a-15223a2
Reg HKLM\SYSTEM\ControlSet002\Control\WDI\Config@ServerName \BaseNamedObjects\WDI_{4a24fdd6-10cc-44a0-8465-bad60df25c7c}
Reg HKLM\SYSTEM\ControlSet002\Control\WMI\Autologger\WdiContextLog@FileCounter 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06dbc5655 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}@InterfaceName isatap.{A20A90D2-836C-40C9-9448-DCFC9455F5DE}
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}@InterfaceName Reusable ISATAP Interface {4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}@ReusableType 1
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}@InterfaceName isatap.oslavany.net
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route "Smb" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Smb" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Smb" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Smb" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Smb" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Smb" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Smb" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export \Device\LanmanServer_Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanServer_Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanServer_Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanServer_Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanServer_Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\LanmanServer_Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\LanmanServer_Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\LanmanServer_Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\LanmanServer_Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanServer_Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanServer_Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\LanmanServer_Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanServer_Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\LanmanServer_Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanServer_Smb_Tcpip6_{F
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route "Smb" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Smb" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Smb" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Smb" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Smb" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Smb" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Smb" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export \Device\LanmanWorkstation_Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanWorkstation_Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanWorkstation_Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanWorkstation_Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanWorkstation_Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\LanmanWorkstation_Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\LanmanWorkstation_Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\LanmanWorkstation_Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\LanmanWorkstation_Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanWorkstation_Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanWorkstation_Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\LanmanWorkstation_Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanWorkstation_Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\LanmanWorkstation_Smb_Tcpip6_{7F
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind \Device\NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route "NetBT" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"NetBT" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"NetBT" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"NetBT" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"NetBT" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"NetBT" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"NetBT" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"NetBT" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"NetBT" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"NetBT" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"NetBT" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"NetBT" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"NetBT" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"NetBT" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"NetBT" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export \Device\NetBIOS_NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBIOS_NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBIOS_NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBIOS_NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBIOS_NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBIOS_NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBIOS_NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBIOS_NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBIOS_NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBIOS_NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBIOS_NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBIOS_NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBIOS_NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBIOS_NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBIOS_NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Parameters@MaxLana 14
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Bind \Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export \Device\NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\rdyboost\Parameters@LastBootPlanUserTime ??t?, ?3 ?08 ?12, 08:45:13 dop.????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\SharedAccess\Epoch@Epoch 2448
Reg HKLM\SYSTEM\ControlSet002\services\SharedAccess\Epoch2@Epoch 802
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind \Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Route "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Export \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE6 0xA7 0xF5 0xBD ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF0 0x6C 0x79 0x48 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8A 0xDF 0x36 0x30 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x37 0x89 0x7A 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\services\SynTP\Parameters@DetectTimeMS 656
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@LeaseObtainedTime 1331192906
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@T1 1331495306
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@T2 1331722106
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@LeaseTerminatesTime 1331797706
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Bind \Device\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Route "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"{EF85D805-0B7B-418E-866F-41E446C542CC}"?"{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Export \Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712}@Dhcpv6Iaid 318767104
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712}@Dhcpv6State 0
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04}@Dhcpv6Iaid 503316480
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04}@Dhcpv6State 0
---- Files - GMER 1.0.15 ----
File C:\ADSM_PData_0150 0 bytes
File C:\ADSM_PData_0150\DB 0 bytes
File C:\ADSM_PData_0150\DB\SI.db 624 bytes
File C:\ADSM_PData_0150\DB\UL.db 16 bytes
File C:\ADSM_PData_0150\DB\VL.db 16 bytes
File C:\ADSM_PData_0150\DB\WAL.db 2048 bytes
File C:\ADSM_PData_0150\DragWait.exe 315392 bytes executable
File C:\ADSM_PData_0150\_avt 512 bytes
File C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Cookies\W4WL11QE.txt 102 bytes
File C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Cookies\XHBNSQEZ.txt 636 bytes
---- EOF - GMER 1.0.15 ----
Druhy log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-08 21:23:41
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR9285 \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06dbc5655
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\6To4\{EF85D805-0B7B-418E-866F-41E446C542CC}@InterfaceName Reusable Microsoft 6To4 Adapter
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\6To4\{EF85D805-0B7B-418E-866F-41E446C542CC}@ReusableType 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1D 0x3F 0xD8 0xE6 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF0 0x6C 0x79 0x48 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8A 0xDF 0x36 0x30 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x37 0x89 0x7A 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemStartTime 0x59 0xFC 0x9D 0xD3 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemLastStartTime 0xC8 0x49 0x45 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFStartTime 0x59 0xFC 0x9D 0xD3 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFLastStartTime 0xC8 0x49 0x45 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData\BootLanguages@cs-CZ 88
Reg HKLM\SYSTEM\ControlSet002\Control\Diagnostics\Performance@ActiveShutdownDCL C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001
Reg HKLM\SYSTEM\ControlSet002\Control\GraphicsDrivers\Configuration\AUO22EC0_01_07D9_C0^4EA9F56D234B0A8BC22D458D6788508F@Timestamp 0xE1 0x23 0xF7 0xD4 ...
Reg HKLM\SYSTEM\ControlSet002\Control\Lsa@LsaPid 700
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR9285 \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Microsoft ISATAP Adapter 1?2?3?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}\Connection@Name isatap.{A20A90D2-836C-40C9-9448-DCFC9455F5DE}
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@DefaultNameResourceId 1801
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@DefaultNameIndex 3
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}\Connection@Name Reusable ISATAP Interface {4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@DefaultNameResourceId 1801
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@DefaultNameIndex 3
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}\Connection@Name isatap.oslavany.net
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"{EF85D805-0B7B-418E-866F-41E446C542CC}"?"{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\TCPIP6TUNNEL_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\TCPIP6TUNNEL_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\TCPIP6TUNNEL_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BootId 98
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 344614933
Reg HKLM\SYSTEM\ControlSet002\Control\Terminal Server@InstanceID 91d9e687-9bdf-4d81-a03a-15223a2
Reg HKLM\SYSTEM\ControlSet002\Control\WDI\Config@ServerName \BaseNamedObjects\WDI_{4a24fdd6-10cc-44a0-8465-bad60df25c7c}
Reg HKLM\SYSTEM\ControlSet002\Control\WMI\Autologger\WdiContextLog@FileCounter 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06dbc5655 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}@InterfaceName isatap.{A20A90D2-836C-40C9-9448-DCFC9455F5DE}
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}@InterfaceName Reusable ISATAP Interface {4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}@ReusableType 1
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}@InterfaceName isatap.oslavany.net
Reg HKLM\SYSTEM\ControlSet002\services\iphlpsvc\Parameters\Isatap\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route "Smb" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Smb" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Smb" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Smb" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Smb" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Smb" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Smb" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export \Device\LanmanServer_Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanServer_Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanServer_Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanServer_Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanServer_Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\LanmanServer_Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\LanmanServer_Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\LanmanServer_Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\LanmanServer_Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanServer_Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanServer_Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\LanmanServer_Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanServer_Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\LanmanServer_Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanServer_Smb_Tcpip6_{F
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route "Smb" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Smb" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Smb" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Smb" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Smb" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Smb" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Smb" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Smb" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Smb" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Smb" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Smb" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export \Device\LanmanWorkstation_Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanWorkstation_Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanWorkstation_Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanWorkstation_Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\LanmanWorkstation_Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\LanmanWorkstation_Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\LanmanWorkstation_Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\LanmanWorkstation_Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\LanmanWorkstation_Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\LanmanWorkstation_Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\LanmanWorkstation_Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\LanmanWorkstation_Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\LanmanWorkstation_Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\LanmanWorkstation_Smb_Tcpip6_{7F
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind \Device\NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route "NetBT" "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"NetBT" "Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"NetBT" "Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"NetBT" "Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"NetBT" "Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"NetBT" "Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"NetBT" "Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"NetBT" "Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"NetBT" "Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"NetBT" "Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"NetBT" "Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"NetBT" "Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"NetBT" "Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"NetBT" "Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"NetBT" "Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export \Device\NetBIOS_NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBIOS_NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBIOS_NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBIOS_NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBIOS_NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBIOS_NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBIOS_NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBIOS_NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBIOS_NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBIOS_NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBIOS_NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBIOS_NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBIOS_NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBIOS_NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBIOS_NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Parameters@MaxLana 14
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Bind \Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export \Device\NetBT_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\NetBT_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\NetBT_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\NetBT_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\NetBT_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\NetBT_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\NetBT_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\NetBT_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\NetBT_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\NetBT_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\NetBT_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\rdyboost\Parameters@LastBootPlanUserTime ??t?, ?3 ?08 ?12, 08:45:13 dop.????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\SharedAccess\Epoch@Epoch 2448
Reg HKLM\SYSTEM\ControlSet002\services\SharedAccess\Epoch2@Epoch 802
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind \Device\Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Route "Tcpip" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?"Tcpip6" "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"Tcpip6" "{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"Tcpip6" "{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"Tcpip6" "{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"Tcpip6" "{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"Tcpip6" "{EF85D805-0B7B-418E-866F-41E446C542CC}"?"Tcpip6" "{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"Tcpip6" "{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"Tcpip6" "{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"Tcpip6" "{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Export \Device\Smb_Tcpip_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip_{F1531650-5AAB-4B72-B28A-4478D905E102}?\Device\Smb_Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Smb_Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Smb_Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Smb_Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Smb_Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Smb_Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Smb_Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Smb_Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Smb_Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Smb_Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE6 0xA7 0xF5 0xBD ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF0 0x6C 0x79 0x48 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8A 0xDF 0x36 0x30 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x37 0x89 0x7A 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\services\SynTP\Parameters@DetectTimeMS 656
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@LeaseObtainedTime 1331192906
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@T1 1331495306
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@T2 1331722106
Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F1531650-5AAB-4B72-B28A-4478D905E102}@LeaseTerminatesTime 1331797706
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Bind \Device\{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Route "{8D6A83BF-CB08-48D0-BC60-4A880245CC04}"?"{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}"?"{4100F196-A12C-44D5-8E61-C7476AAEC3F1}"?"{A20A90D2-836C-40C9-9448-DCFC9455F5DE}"?"{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}"?"{EF85D805-0B7B-418E-866F-41E446C542CC}"?"{41CDA350-0415-48F6-BDE6-275B3CD81B78}"?"{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}"?"{7F5681F8-5B27-43B8-AC49-A819E2B26F86}"?"{F1531650-5AAB-4B72-B28A-4478D905E102}"?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Export \Device\Tcpip6_{8D6A83BF-CB08-48D0-BC60-4A880245CC04}?\Device\Tcpip6_{4FD97E7F-3CC5-494E-A3DC-AD00E46A5712}?\Device\Tcpip6_{4100F196-A12C-44D5-8E61-C7476AAEC3F1}?\Device\Tcpip6_{A20A90D2-836C-40C9-9448-DCFC9455F5DE}?\Device\Tcpip6_{77F0B6F3-AA28-4B48-A40D-9C12892F9FD9}?\Device\Tcpip6_{EF85D805-0B7B-418E-866F-41E446C542CC}?\Device\Tcpip6_{41CDA350-0415-48F6-BDE6-275B3CD81B78}?\Device\Tcpip6_{D2FAD9D4-8DA6-4C9D-B3A7-1F9B3B80BD43}?\Device\Tcpip6_{7F5681F8-5B27-43B8-AC49-A819E2B26F86}?\Device\Tcpip6_{F1531650-5AAB-4B72-B28A-4478D905E102}?
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712}@Dhcpv6Iaid 318767104
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{4fd97e7f-3cc5-494e-a3dc-ad00e46a5712}@Dhcpv6State 0
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04}@Dhcpv6Iaid 503316480
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Parameters\Interfaces\{8d6a83bf-cb08-48d0-bc60-4a880245cc04}@Dhcpv6State 0
---- Files - GMER 1.0.15 ----
File C:\ADSM_PData_0150 0 bytes
File C:\ADSM_PData_0150\DB 0 bytes
File C:\ADSM_PData_0150\DB\SI.db 624 bytes
File C:\ADSM_PData_0150\DB\UL.db 16 bytes
File C:\ADSM_PData_0150\DB\VL.db 16 bytes
File C:\ADSM_PData_0150\DB\WAL.db 2048 bytes
File C:\ADSM_PData_0150\DragWait.exe 315392 bytes executable
File C:\ADSM_PData_0150\_avt 512 bytes
File C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Cookies\W4WL11QE.txt 102 bytes
File C:\Users\Jejda\AppData\Roaming\Microsoft\Windows\Cookies\XHBNSQEZ.txt 636 bytes
---- EOF - GMER 1.0.15 ----
- Rudy
- Site Admin
- Příspěvky: 119378
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Crash Norton, chrome
V logu není nic nebezpečného. Zkuste obnovu systému k datu, kdy korektně fungoval.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.