Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc bráchu Mc_Murphyho

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Prosím o pomoc bráchu Mc_Murphyho

#1 Příspěvek od David Langr »

Brách, holkám se začal z ničehož nic vypínat PC. Během hraní her, práce ale i samovolně se prostě bez příkazu vypne. Posílám dnešní Rsit. Díky brácha David
Logfile of random's system information tool 1.09 (written by random/random)
Run by Dagmar at 2012-09-15 09:58:38
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 73 GB (51%) free of 145 GB
Total RAM: 1023 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:59:35, on 15.9.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Dagmar\Desktop\RSIT.exe
C:\Program Files\trend micro\Dagmar.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{D290AD1E-1CEB-40B5-A3B7-6F4B4DECA40C}: NameServer = 172.20.2.69,217.197.152.132
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 5116 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Norton Security Scan for Dagmar.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\4geh67ov.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.15"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{3112ca9c-de6d-4884-a869-9855de68056c}"=C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571]
"Description"=RealMedia Plugin
"Path"=D:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739]
"Description"=RealPlayer Version Plugin
"Path"=D:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat

C:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
npnul32.dll
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\4geh67ov.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-26 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
"OsdMaestro"=C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [2007-02-15 118784]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-07-06 4669440]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2006-11-02 215552]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"=C:\Windows\SMINST\launcher.exe [2007-04-03 44168]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Sony Ericsson PC Companion"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2010-04-19 405712]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-09-15 09:58:38 ----D---- C:\rsit
2012-09-09 15:40:32 ----D---- C:\Program Files\Alternative Software Ltd
2012-09-05 21:51:55 ----D---- C:\Program Files\Common Files\Skype
2012-08-16 14:36:30 ----A---- C:\Windows\system32\mshtmled.dll
2012-08-16 14:36:29 ----A---- C:\Windows\system32\iertutil.dll
2012-08-16 14:36:27 ----A---- C:\Windows\system32\ieUnatt.exe
2012-08-16 14:36:27 ----A---- C:\Windows\system32\ieui.dll
2012-08-16 14:36:25 ----A---- C:\Windows\system32\wininet.dll
2012-08-16 14:36:25 ----A---- C:\Windows\system32\jscript9.dll
2012-08-16 14:36:25 ----A---- C:\Windows\system32\jscript.dll
2012-08-16 14:36:24 ----A---- C:\Windows\system32\url.dll
2012-08-16 14:36:23 ----A---- C:\Windows\system32\jsproxy.dll
2012-08-16 14:36:21 ----A---- C:\Windows\system32\urlmon.dll
2012-08-16 14:36:17 ----A---- C:\Windows\system32\mshtml.dll
2012-08-16 14:36:15 ----A---- C:\Windows\system32\ieframe.dll
2012-08-16 14:35:38 ----A---- C:\Windows\system32\win32k.sys

======List of files/folders modified in the last 1 month======

2012-09-15 09:58:42 ----D---- C:\Program Files\trend micro
2012-09-15 09:58:29 ----D---- C:\Windows\Temp
2012-09-15 09:39:18 ----D---- C:\Users\Dagmar\AppData\Roaming\Skype
2012-09-15 09:25:04 ----D---- C:\Windows\Debug
2012-09-15 09:24:12 ----D---- C:\Windows\Prefetch
2012-09-15 09:10:53 ----D---- C:\Windows\SMINST
2012-09-14 16:37:34 ----SHD---- C:\System Volume Information
2012-09-14 15:07:28 ----D---- C:\Windows\system32\catroot2
2012-09-12 20:11:27 ----D---- C:\Windows\System32
2012-09-12 20:11:27 ----D---- C:\Windows\inf
2012-09-12 20:11:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-12 14:29:48 ----SHD---- C:\Windows\Installer
2012-09-12 14:29:43 ----D---- C:\ProgramData\Microsoft Help
2012-09-12 14:25:42 ----A---- C:\Windows\system32\mrt.exe
2012-09-12 14:25:13 ----D---- C:\Windows\winsxs
2012-09-12 14:25:12 ----D---- C:\Windows\system32\catroot
2012-09-10 13:07:58 ----D---- C:\Program Files\Common Files\Symantec Shared
2012-09-09 15:45:50 ----HD---- C:\Program Files\InstallShield Installation Information
2012-09-09 15:40:32 ----RD---- C:\Program Files
2012-09-05 21:52:14 ----D---- C:\ProgramData\Skype
2012-09-05 21:51:55 ----RD---- C:\Program Files\Skype
2012-09-05 21:51:55 ----D---- C:\Program Files\Common Files
2012-09-03 13:30:29 ----D---- C:\Windows
2012-09-01 19:00:53 ----D---- C:\Users\Dagmar\AppData\Roaming\dvdcss
2012-08-24 12:22:27 ----D---- C:\Windows\SoftwareDistribution
2012-08-24 12:10:06 ----D---- C:\Users\Dagmar\AppData\Roaming\skypePM
2012-08-18 12:18:41 ----RSD---- C:\Windows\assembly
2012-08-16 16:07:11 ----D---- C:\Program Files\Atari
2012-08-16 15:30:44 ----D---- C:\Windows\system32\migration
2012-08-16 15:30:44 ----D---- C:\Program Files\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2007-06-20 43872]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2008-06-17 5632]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-09-29 6472192]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-09-29 228352]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 968064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-07-11 1793880]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
R3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-03-05 76288]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-09-29 6472192]
S3 DCamUSBSTK014;STK014 Camera; C:\Windows\system32\DRIVERS\STK014W2.sys [2003-07-15 99476]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 74112]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM); C:\Windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-01 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 123504]
S3 SMARTMouseFilterx86;HID-compliant mouse; C:\Windows\system32\DRIVERS\SMARTMouseFilterx86.sys []
S3 SMARTVHidMini2000x86;SMART HID Device; C:\Windows\system32\DRIVERS\SMARTVHidMini2000x86.sys []
S3 SMARTVTabletPCx86;SMART Virtual TabletPC; C:\Windows\system32\DRIVERS\SMARTVTabletPCx86.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ssm_bus.sys [2007-05-02 83592]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\Windows\system32\DRIVERS\ssm_mdfl.sys [2007-05-02 15112]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\Windows\system32\DRIVERS\ssm_mdm.sys [2007-05-02 109704]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:\Windows\system32\DRIVERS\w810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\w810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\w810mdm.sys [2006-02-20 94064]
S3 winusb;Služba WinUSB; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-09-29 176128]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-05-24 61440]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-07-25 79136]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2006-11-10 99936]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 214952]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB9;RoxMediaDB9; c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-05-11 887544]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2010-03-11 153736]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-05-03 74656]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Prosím o pomoc bráchu Mc_Murphyho

#2 Příspěvek od Mc_Murphy »

:arrow: Brácho, na první pohled v logu nic špatného nevidím. Stejně na to ale pustíme trošku silnější nástroj a kdyby se nic po opravném scriptu nezlepšilo, musíme na to jít s ještě větší palicí. :boxed:
:arrow: Jinak v PC je antivir Microsoft Security Essentials (MSE). Pokud bys chtěl, můžeme (nemusíme) se jej pak pokusit odpálit a nahradit buď Avastem a nebo Avirou, jak jsem Ti psal na Skype.
:arrow: Taky se mi nelíbí Mozilla Firefox - je strašně zaliskaná všemožnými doplňky a rozšířeními, co tam zřejmě Tvé dceruny naflákaly. To by chtělo projít a odebrat v ní to, co vyloženě k ničemu nepoužíváte. Systému to nevadí, ale Mozillu to může dost zpomalovat.


:arrow: Takže si stáhni OTL z tohoto odkazu a ulož jej na Plochu.
  • Pokud používáš Win Vista či Win7, klikni na OTL pravým myšítkem a dej Run As Administrator či Spustit jako správce.
  • Pokud používáš 64bitový OS, zkontroluj, zda-li je zaškrtnutý čtvereček Pro 64 bitové OS. Pokud ne, zaškrtni jej.
  • Zaškrtni okénko Pro všechny uživatele.
  • Zaškrtni okénko Kontrola na havěť "LOP".
  • Zaškrtni okénko Kontrola na havěť "Purity".
  • Stáři souborů změň z 30 dnů na 7 dnů!!
  • Do spodního okénka Vlastní skenování/opravy vlož tento script (pouze zelená písmenka v bílém poli!):

Kód: Vybrat vše

CREATERESTOREPOINT
netsvc
drivers32
savembr:0
/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop
%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe
%userprofile%\Plocha\*.*
%userprofile%\Desktop\*.*
%ALLUSERSPROFILE%\Plocha\*.*
%ALLUSERSPROFILE%\Desktop\*.*
*crack* /s
*keygen* /s
*loader* /s
*RemoveWAT* /s
*minodlogin* /s
*tnod* /s
*TemDono* /s
*AutoKMS* /s
*KMSEmulator* /s
*activator* /s
*serial* /s
*w7lxe* /s
*AutoRearm* /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /s
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run /s
%SystemDrive%\PhysicalMBR.bin /md5
  • Klikni na tlačítko [Prohledat].
  • Po dokončení skenu se objeví logy OTL.txt a Extras.txt, oba mi sem vlož.
  • Logy se nevejdou do jednoho, rozděl je tedy prosím do více příspěvků.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#3 Příspěvek od David Langr »

Takže exáč Extras:
OTL Extras logfile created on: 15.9.2012 11:42:12 - Run 1
OTL by OldTimer - Version 3.2.61.4 Folder = C:\Users\Dagmar\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1022,64 Mb Total Physical Memory | 519,69 Mb Available Physical Memory | 50,82% Memory free
2,26 Gb Paging File | 1,31 Gb Available in Paging File | 58,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141,80 Gb Total Space | 71,66 Gb Free Space | 50,54% Space Free | Partition Type: NTFS
Drive D: | 7,25 Gb Total Space | 1,29 Gb Free Space | 17,86% Space Free | Partition Type: NTFS
Drive E: | 4,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: DAGMAR-PC | User Name: Dagmar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01461A57-34FC-4620-B458-9D0834EDFD8D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0322CA8E-5A6B-426E-8873-ECFE80A93004}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{050B9D6F-ECCB-4A30-883F-EAA5F46BF034}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{11B7AD0D-BCB3-42BA-8593-F7C700FAE615}" = lport=10243 | protocol=6 | dir=in | app=system |
"{17C3855B-A3EB-4031-8E7F-C7FC6A8F777C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{19BB793B-93EE-40F9-9113-EEA32681EBAC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1AB26085-00F0-4CA0-BADD-F23F73FB8D87}" = rport=139 | protocol=6 | dir=out | app=system |
"{21914BC1-ADB6-4435-805B-EAD0D2BD97D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{3521495D-BAB3-4A05-B596-B6DECFA7B245}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3D8209A3-E426-4B3A-91EC-F2E2A462C642}" = rport=10243 | protocol=6 | dir=out | app=system |
"{45498B2D-2FEE-4D69-92C0-AFDF7B74AAC1}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6865BA88-3875-4C00-BF66-12585A475251}" = rport=138 | protocol=17 | dir=out | app=system |
"{6D9B62E3-9FCD-4099-AE64-A8BB3812C49D}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{82A847A6-4B21-4CD9-884B-87EFC3F0B7A9}" = rport=445 | protocol=6 | dir=out | app=system |
"{8BE06E52-05D0-47AA-B473-0C50DBB5F9E9}" = lport=139 | protocol=6 | dir=in | app=system |
"{9E6CBD82-C618-4A38-9ED4-49B81F03E1C5}" = lport=445 | protocol=6 | dir=in | app=system |
"{A057A37B-3068-4C45-9786-AB297761FAE2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2FBF5EA-8E91-43D0-9F45-D283FC00B33F}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AEDB8526-FAB0-46A7-9E7B-30345CBC4E9D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B3C02BF2-8B32-432E-96B8-C640B8E5BE0D}" = lport=138 | protocol=17 | dir=in | app=system |
"{DD8D2E6E-2137-4012-99C0-500DF4075212}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E878C60D-1213-43D2-9124-E24A91989483}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EA779879-58AC-44BF-AE60-FED1E2F583A6}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7AC3C2C-5EBE-41FE-B52D-3A04330E8DB9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{168CA46F-9650-414B-8C63-85E25D3ACCA0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2648F810-CDD8-47CA-B16F-828EDD5F6529}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{2BC781FD-EA47-41B9-9083-1A1CAE5FAAF4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{329A80C1-2237-4327-82FB-E5A94FF4E103}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{35318B6E-F6B4-4FFD-89EE-093DE210FA9A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3A35472C-EFE5-4B5A-9372-F7F1D9AD5EC7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3AFB1268-DB76-445D-A674-D455A496D6C4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{51605D60-57E3-4407-8619-D552D44CD695}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5CB963F2-3EBC-429B-81F9-E6FD1168492C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6729561D-0DE6-4AC1-806E-5712A839E3F3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{69D71332-3EEE-492B-B21E-2A4A4E5F9C95}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8550DF30-A395-42BC-82EA-8353625966CF}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{90E59D2C-6C61-4472-A9B1-46E9663E5C33}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{9159B46F-EEEE-405F-A757-83B49D5E21EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CEDA10A-0187-4246-96A0-41B7FDFF846C}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{A5A90886-59D9-4D24-9A90-4FAD06F9A8DB}" = protocol=6 | dir=out | app=system |
"{A66213E5-37A3-4CCC-BD00-70F1DAC2A6A6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{AEF7E158-15EA-4276-98D5-E2B7ABBA9BAE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B90A7E8A-84E8-4FF4-8D0F-9AE4CD70F090}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C64B2BD5-40C5-4601-A9AF-6EF8D761B4B5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C72B23AD-E7B7-41EB-8A9F-5FA52162CADF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D6BAAACB-1945-4622-B3EF-DB26DD364FFF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DC0E2E65-E4C9-44A6-87EF-D9D05990B1FD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{DEF8740C-C465-4C3B-8349-6A111130F968}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E127A30A-9A0B-48C3-8399-80D449033BA7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"TCP Query User{118D24CF-7D45-47D1-93FE-637E883CF2DB}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{181A837F-CA92-4BE9-A745-B30085F45406}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{33C63ED8-F4FC-4186-A9C1-D3BEB8D1885A}C:\program files\nero\nero8\nero showtime\showtime.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero8\nero showtime\showtime.exe |
"TCP Query User{3C38A6C8-2A3D-4AEF-BAB1-70305282E472}C:\windows\ehome\ehexthost.exe" = protocol=6 | dir=in | app=c:\windows\ehome\ehexthost.exe |
"TCP Query User{4403E7DB-644D-4BBD-8E20-89DCB4ECB974}C:\program files\microsoft office\office12\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"TCP Query User{4D7080F7-BB80-47CE-9B69-1C37C3473BA6}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe |
"TCP Query User{85515208-808D-4F62-A72D-90A82A3CD147}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B747FF0A-2625-44F6-BAD3-ADC05DAAE0FA}C:\program files\net-bubble\net-bubble.exe" = protocol=6 | dir=in | app=c:\program files\net-bubble\net-bubble.exe |
"TCP Query User{C17E60CE-60C4-4055-B8F7-F21D1391D473}C:\windows\ehome\ehexthost.exe" = protocol=6 | dir=in | app=c:\windows\ehome\ehexthost.exe |
"TCP Query User{DDB7EEAC-2A3F-4FB7-B2B1-AC7DA9C664FE}C:\program files\qip\qip.exe" = protocol=6 | dir=in | app=c:\program files\qip\qip.exe |
"TCP Query User{E079B087-2896-4E95-92B4-6AF7C558A179}E:\autoplay\docs\dslman.exe" = protocol=6 | dir=in | app=e:\autoplay\docs\dslman.exe |
"TCP Query User{E9547DF3-A8BF-450D-AF6F-0BAB9BDFBFBD}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe |
"TCP Query User{F102CF90-FDA7-4195-ADC0-0C923AA59B5D}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe |
"UDP Query User{0FC00874-C4A7-45D6-8979-41A8D9CCA886}E:\autoplay\docs\dslman.exe" = protocol=17 | dir=in | app=e:\autoplay\docs\dslman.exe |
"UDP Query User{15250AC9-44CE-4306-8112-0642F63EB1BB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1A02DA7F-7AD6-41A9-9B2E-5DA4B94E4CA0}C:\windows\ehome\ehexthost.exe" = protocol=17 | dir=in | app=c:\windows\ehome\ehexthost.exe |
"UDP Query User{274222E5-BF9E-4CA0-B335-A9864F6D82A8}C:\program files\nero\nero8\nero showtime\showtime.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero8\nero showtime\showtime.exe |
"UDP Query User{27FB5E33-0B4A-4448-8BE5-7156611DE432}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe |
"UDP Query User{477C0631-398A-4D19-BB12-8AC6183A50B7}C:\program files\qip\qip.exe" = protocol=17 | dir=in | app=c:\program files\qip\qip.exe |
"UDP Query User{5F5EB60B-CD20-4897-8481-B06D1FED8781}C:\windows\ehome\ehexthost.exe" = protocol=17 | dir=in | app=c:\windows\ehome\ehexthost.exe |
"UDP Query User{6762EA94-50A5-4A1D-BDBF-7BD6ADD101D3}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe |
"UDP Query User{79C4809A-48B4-48FA-834F-E4ECF81873AB}C:\program files\net-bubble\net-bubble.exe" = protocol=17 | dir=in | app=c:\program files\net-bubble\net-bubble.exe |
"UDP Query User{A65EA9DE-7487-4BD0-ADC2-FEE625A6DFD9}C:\program files\qip\qip.exe" = protocol=17 | dir=in | app=c:\program files\qip\qip.exe |
"UDP Query User{D9C7217E-87F2-44A5-A06C-A13CC3FF7E01}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{DCAC63A3-9237-461E-A67D-A42D3282205B}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{F9293A75-9486-4B4E-B322-F9E892C61E27}C:\program files\microsoft office\office12\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{023EC958-023C-42D1-B2A4-E9E4BEF599FC}" = SweetIM for Messenger 2.6
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07A540AB-D785-11D5-8E89-0090275862A0}" = Corel Graphics Suite 11
"{07E4651B-B10D-B079-6A2D-A328E7F97DF8}" = CCC Help Hungarian
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}" = HP Active Support Library
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0E3FD8AB-3DBA-E2B5-F207-51D4F2F03381}" = CCC Help English
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{0FAEE4E9-81DF-3B79-0B2B-D9E8D830E16D}" = CCC Help Thai
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series" = Canon MP140 series
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{13771F48-69A8-714D-FDB0-EBBA0635A9D4}" = Catalyst Control Center Localization Russian
"{148D9D03-5D23-4D4F-B5D0-BA6030C45DCF}" = Adobe Flash Player 10 ActiveX
"{14AF024E-2E3B-49D0-A175-D1C1A06B155A}" = muvee autoProducer 6.0
"{17CA32D1-73BD-4990-B8F6-369D8D34B05D}" = Microsoft Antimalware Service CS-CZ Language Pack
"{1A736043-F483-D644-613B-C84D74B5F63A}" = CCC Help Spanish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200F584F-848D-4B6B-B1A1-C74D735F18A4}" = InstallRTC
"{2161DD18-607D-83B5-2DC7-600EFDA46063}" = CCC Help German
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{266C7330-C0F4-49E5-8F20-A56F9F822875}" = SweetIM Toolbar for Internet Explorer 3.3
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{2BD8C31B-F368-99CE-5F5C-A53B0BDD19B0}" = CCC Help Norwegian
"{2BDF9A0B-01C6-4BC3-4288-0BC0160E3ABD}" = CCC Help Czech
"{30C0CF88-8368-5783-A72E-F9A5B9F9A917}" = Catalyst Control Center Graphics Previews Vista
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{343F1CC7-F8BF-F564-AA4C-D34B77EEAA95}" = Catalyst Control Center Localization Portuguese
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{36486D0E-2DBB-ADD3-1504-4772FA6B285A}" = CCC Help Japanese
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{49E7D0F0-BD9F-FAEC-11C4-9B4C22B6E828}" = Catalyst Control Center Localization Italian
"{4F027497-15AE-4DE5-B3BC-8E721C6127DE}" = ccc-Branding
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client CS-CZ Language Pack
"{51AD07A2-F7D5-E76E-3B8B-2CF123D82597}" = CCC Help French
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DC2E459-D485-ADB7-4FFC-F2A41D9BE686}" = Catalyst Control Center Localization Turkish
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62BFDFDD-2310-F283-9428-D552F6D8AC93}" = CCC Help English
"{651AAC88-4728-E17A-9823-F630A315F9F9}" = Catalyst Control Center Graphics Previews Vista
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66FA1F4C-A83B-6759-068D-DF511CC00E28}" = CCC Help Danish
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6E65247F-58F9-41CA-BE69-0316F7907170}" = Disc2Phone
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{729A36DE-DB17-6B4A-59DF-279DEE32ED15}" = CCC Help Finnish
"{74DD653A-0577-DEDC-2C9B-F32669E06921}" = Catalyst Control Center Graphics Previews Common
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{76308844-456A-4D76-99CA-511F0DED1029}" = Nero 8
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A80850F-0D2B-2BD8-E083-BAACCB93630B}" = Catalyst Control Center Localization Korean
"{8018AD38-3EBB-A031-D4F8-EF6A5952F168}" = ATI Catalyst Install Manager
"{806C85BF-25A8-CDC1-76CB-12365D7818C6}" = Catalyst Control Center Localization Spanish
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{82841374-147F-DBBC-962C-C931119F9046}" = Catalyst Control Center Localization Japanese
"{8305D1B0-EA11-7E6E-D3CD-E20E85F92EC8}" = CCC Help Chinese Traditional
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{84DEF790-8E3E-FCFF-D0C9-FD4782561AE4}" = CCC Help Dutch
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B7AAD00-5A06-F0F3-23C8-A2D220AE3903}" = CCC Help Swedish
"{8C31BF2A-AFB3-6018-F91B-66339FF8F37F}" = Catalyst Control Center Localization Thai
"{8D3785C1-E967-12DF-CF94-1913D920C466}" = CCC Help Turkish
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9257E10D-54A7-D942-DBC0-DAB30E8ED34A}" = Catalyst Control Center Localization Greek
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{9531658F-BA09-EBFB-B2EE-06D639030828}" = Catalyst Control Center InstallProxy
"{973C52C6-533B-1EC1-9738-0553446DFA7E}" = Catalyst Control Center Localization Polish
"{99E3CD2E-22C5-77F6-61F2-D14D6BCB7A23}" = CCC Help Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CDE63FA-D807-2B59-748B-40C5CB523CD0}" = Catalyst Control Center Localization Chinese Standard
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A27D8FDB-6912-E419-A0B0-3C92D137CFDA}" = Catalyst Control Center Localization Finnish
"{A44ED15C-4398-7353-D4B2-9F7E9921FC91}" = Catalyst Control Center Graphics Previews Common
"{A7579D16-2CC1-4464-B226-A4422564BB4C}" = Spider-Man Creative Studio
"{A92C9CFB-E16F-2387-00E3-63F67E3631AC}" = Catalyst Control Center Localization French
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{AECEFE78-F109-0D11-AC80-116A0E36CC19}" = Catalyst Control Center Localization German
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
"{BEE02DB1-ED44-BCF3-F560-E79861C30EE0}" = Catalyst Control Center Localization Norwegian
"{BFC3E1CF-D886-BFA5-AF9A-AB3E8D3B84B0}" = CCC Help Italian
"{C16F1E5A-96E8-160D-93FA-8962346108C2}" = Catalyst Control Center Localization Dutch
"{C3DE93B9-BF12-DFB3-1320-49C2A1D50F71}" = CCC Help Portuguese
"{C73B5B3B-F974-48CA-8B91-3E8A432AEA5B}" = Microsoft Works
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF840AAD-CDE5-4E18-378B-32B0280D154B}" = CCC Help Russian
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D67B3404-93AC-C8CC-EF85-11AD62C9BAEA}" = CCC Help Polish
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{E6FB43A3-28EC-C6ED-D071-B62F547188A3}" = CCC Help Greek
"{E8DE1122-09F3-7A50-4813-6895B62F0B03}" = Catalyst Control Center Localization Hungarian
"{E91A5A51-4BFB-2B85-8BB8-1110625DDD91}" = CCC Help Korean
"{EA6348E0-1696-549D-3EFF-58F94CCDA81A}" = ccc-core-static
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{ED64E78D-1BA3-3EEC-108B-04F16AA38E2C}" = ccc-utility
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.00.134
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F8766327-4B94-6613-5CE6-F841AF2C7693}" = Catalyst Control Center Localization Chinese Traditional
"{F9A35214-6A0E-EE01-C17E-86EE33C53869}" = Catalyst Control Center Localization Swedish
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Asterix at the Olympic Games Demo" = Demo Asterix a Olympijské hry
"AviSynth" = AviSynth 2.5
"Building Panic" = Building Panic
"CANONIJPLM100" = PIXMA Extended Survey Program
"Caterpillars - The Revenge" = Caterpillars - The Revenge
"CCleaner" = CCleaner
"City Racing_is1" = City Racing
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Čistič_is1" = Čistič 1.5
"Defraggler" = Defraggler
"DVD slideshow GUI_is1" = DVD slideshow GUI 0.86
"DzSoftWebPhotoResizer_is1" = Quick Web Photo Resizer 2.4
"Easy-LayoutPrint" = Canon Utilities Easy-LayoutPrint
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Farm Frenzy 3: American Pie" = Farm Frenzy 3: American Pie
"ffdshow_is1" = ffdshow [rev 1201] [2007-05-26]
"Food Force" = Food Force 1.0
"Google Chrome" = Google Chrome
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"ICEMANIA" = ICEMANIA
"ICQ6" = ICQ6 build 6043
"Imager Enhancer" = Imager Enhancer 1.4 - Freeware graphics editor
"InstallShield_{07A540AB-D785-11D5-8E89-0090275862A0}" = CorelDRAW Graphics Suite 11
"InstallShield_{A7579D16-2CC1-4464-B226-A4422564BB4C}" = Spider-Man Creative Studio
"Khanoo" = Khanoo
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"Moorhuhn 2 V1.1" = Moorhuhn 2 V1.1
"Moorhuhn Winter-Edition" = Moorhuhn Winter-Edition
"Moorhuhnjagd" = Moorhuhnjagd
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"MP Navigator 3.1" = Canon MP Navigator 3.1
"MultiTranse_is1" = MultiTranse 4.7.2
"Net-Bubble" = Net-Bubble
"Nový Robinson" = Nový Robinson
"NSS" = Norton Security Scan
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"Pacman 3D" = Pacman 3D
"PacMario" = PacMario
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PhotoFiltre" = PhotoFiltre
"PhotoFiltre Studio" = PhotoFiltre Studio
"Picasa 3" = Picasa 3
"QuickTime" = QuickTime
"rajče.net_is1" = rajče verze 56 sestavení 166
"Registrace uživatele zařízení Canon MP140 series" = Registrace uživatele zařízení Canon MP140 series
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Sectors Of Death" = Sectors Of Death
"Stylish Profile" = Stylish Profile
"Ta-Ta Mahatta_is1" = Ta-Ta Mahatta v1.02
"The Matrix-Rayne" = The Matrix-Rayne
"ThumbsPlus7" = ThumbsPlus version 7 SP2
"Trigger" = Trigger
"Wandering Fighter" = Wandering Fighter
"WinRAR archiver" = WinRAR
"Zoner Photo Studio 8_is1" = Zoner Photo Studio 8

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Midnight Racing" = Midnight Racing
"QIP 2005" = QIP 2005 8095
"QipGuard" = QIP Internet Guardian

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 24.8.2012 6:16:57 | Computer Name = Dagmar-PC | Source = Application Hang | ID = 1002
Description = Program Skype.exe verze 5.0.0.156 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení problémů.
ID
procesu: 884 Čas zahájení: 01cd81e0742d0096 Čas ukončení: 101

Error - 25.8.2012 6:06:11 | Computer Name = Dagmar-PC | Source = Application Hang | ID = 1002
Description = Program firefox.exe verze 1.9.1.3951 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení problémů.
ID
procesu: b50 Čas zahájení: 01cd8298420c9920 Čas ukončení: 43

Error - 3.9.2012 7:23:47 | Computer Name = Dagmar-PC | Source = VSS | ID = 8194
Description =

Error - 4.9.2012 8:19:30 | Computer Name = Dagmar-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace TATA_MAHATTA.exe, verze 0.0.0.0, časové razítko
0x3edf20ef, chybující modul TATA_MAHATTA.exe, verze 0.0.0.0, časové razítko 0x3edf20ef,
kód výjimky 0xc0000005, posun chyby 0x00005403, ID procesu 0x9f0, čas spuštění aplikace
0x01cd8a8bdca94360.

Error - 9.9.2012 9:33:57 | Computer Name = Dagmar-PC | Source = VSS | ID = 8194
Description =

Error - 9.9.2012 9:50:56 | Computer Name = Dagmar-PC | Source = Application Hang | ID = 1002
Description = Program Explorer.EXE verze 6.0.6002.18005 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení
problémů. ID procesu: 7c8 Čas zahájení: 01cd8e73ad294af0 Čas ukončení: 153

Error - 9.9.2012 10:02:26 | Computer Name = Dagmar-PC | Source = Application Hang | ID = 1002
Description = Program Explorer.EXE verze 6.0.6002.18005 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení
problémů. ID procesu: 7dc Čas zahájení: 01cd8e938c6bfc05 Čas ukončení: 720

Error - 12.9.2012 14:14:27 | Computer Name = Dagmar-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace Picasa3.exe, verze 3.9.135.93, časové razítko 0x4f6b811b,
chybující modul QuickTime.qts, verze 6.5.2.10, časové razítko 0x415367ee, kód výjimky
0xc0000005, posun chyby 0x00102df8, ID procesu 0x8ec, čas spuštění aplikace 0x01cd91125373a8a0.

Error - 13.9.2012 9:02:33 | Computer Name = Dagmar-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace Picasa3.exe, verze 3.9.135.93, časové razítko 0x4f6b811b,
chybující modul QuickTime.qts, verze 6.5.2.10, časové razítko 0x415367ee, kód výjimky
0xc0000005, posun chyby 0x00102df8, ID procesu 0x15b8, čas spuštění aplikace 0x01cd91afeae912e0.

Error - 13.9.2012 9:25:14 | Computer Name = Dagmar-PC | Source = Application Hang | ID = 1002
Description = Program Explorer.EXE verze 6.0.6002.18005 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení
problémů. ID procesu: 14c Čas zahájení: 01cd9186061ec804 Čas ukončení: 497

[ Media Center Events ]
Error - 4.6.2012 1:22:03 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 5.6.2012 4:35:39 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 6.6.2012 9:36:50 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 7.6.2012 8:23:16 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 8.6.2012 11:21:07 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 9.6.2012 4:46:07 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 10.6.2012 2:24:57 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 11.6.2012 3:13:28 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 12.6.2012 4:04:35 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 82
Description = Informace o události: Nebyl vybrán poskytovatel programu televize.
Přejděte k volbě Nastavit program televize v nabídce Nastavení televize aplikace
Windows Media Center. Proces: DefaultDomain Název objektu: Microsoft.Ehome.Epg.EhepgdatSingleton


Error - 5.7.2012 6:11:59 | Computer Name = Dagmar-PC | Source = Media Center Guide | ID = 0
Description = Informace o události: ERROR: SqmApiWrapper.TimerRecord failed; Win32
GetLastError returned 10000105 Proces: DefaultDomain Název objektu: Media Center
Guide

[ System Events ]
Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 11:47:13 | Computer Name = Dagmar-PC | Source = amdkmdag | ID = 6145
Description = System shutdown due to graphics card overheating

Error - 14.9.2012 12:05:17 | Computer Name = Dagmar-PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (17:46:55, 14.9.2012) bylo neočekávané.


< End of report >

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#4 Příspěvek od David Langr »

A TEXŤÁK OTL: :P
OTL logfile created on: 15.9.2012 11:42:12 - Run 1
OTL by OldTimer - Version 3.2.61.4 Folder = C:\Users\Dagmar\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1022,64 Mb Total Physical Memory | 519,69 Mb Available Physical Memory | 50,82% Memory free
2,26 Gb Paging File | 1,31 Gb Available in Paging File | 58,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141,80 Gb Total Space | 71,66 Gb Free Space | 50,54% Space Free | Partition Type: NTFS
Drive D: | 7,25 Gb Total Space | 1,29 Gb Free Space | 17,86% Space Free | Partition Type: NTFS
Drive E: | 4,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: DAGMAR-PC | User Name: Dagmar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.09.15 11:33:50 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Dagmar\Desktop\OTL.exe
PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010.11.02 16:55:03 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.09.29 03:51:26 | 000,380,928 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2010.09.29 03:50:58 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007.07.06 13:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.04.07 02:56:47 | 000,132,760 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\jusched.exe
PRC - [2007.02.15 13:59:00 | 000,118,784 | ---- | M] (OsdMaestro) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2006.11.02 11:45:59 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe


========== Modules (No Company Name) ==========

MOD - [2011.12.11 21:33:49 | 006,276,768 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2010.09.29 03:13:06 | 000,023,040 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2008.11.27 12:29:42 | 000,243,200 | ---- | M] () -- C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll
MOD - [2008.11.27 12:29:42 | 000,239,616 | ---- | M] () -- C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
MOD - [2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
MOD - [2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
MOD - [2006.07.27 19:51:18 | 000,057,451 | ---- | M] () -- C:\Program Files\ICQLite\ICQLiteShell.dll
MOD - [2004.12.26 20:34:38 | 000,121,344 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll


========== Services (SafeList) ==========

SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.09.29 03:50:58 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2010.03.11 10:01:02 | 000,153,736 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 09:36:49 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008.01.19 09:36:15 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006.11.10 08:12:30 | 000,099,936 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTVTabletPCx86.sys -- (SMARTVTabletPCx86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTVHidMini2000x86.sys -- (SMARTVHidMini2000x86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTMouseFilterx86.sys -- (SMARTMouseFilterx86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.03.20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010.09.29 04:25:14 | 006,472,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2010.09.29 04:25:14 | 006,472,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2010.09.29 03:14:30 | 000,228,352 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010.03.01 11:43:16 | 000,098,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039bus.sys -- (s1039bus)
DRV - [2010.03.01 11:43:12 | 000,124,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mdm.sys -- (s1039mdm)
DRV - [2010.03.01 11:43:12 | 000,117,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mgmt.sys -- (s1039mgmt)
DRV - [2010.03.01 11:43:12 | 000,113,904 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039obex.sys -- (s1039obex)
DRV - [2010.03.01 11:43:12 | 000,014,960 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039mdfl.sys -- (s1039mdfl)
DRV - [2010.03.01 11:43:10 | 000,123,504 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039unic.sys -- (s1039unic)
DRV - [2010.03.01 11:43:10 | 000,025,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1039nd5.sys -- (s1039nd5)
DRV - [2009.04.11 06:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)
DRV - [2008.10.21 10:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s0017bus.sys -- (s0017bus)
DRV - [2008.06.17 10:25:10 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2007.06.11 11:49:22 | 000,968,064 | ---- | M] (Hauppauge Computer Works) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HCW85BDA.sys -- (HCW85BDA)
DRV - [2007.05.02 11:12:36 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2007.05.02 11:12:36 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2007.05.02 11:12:34 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_bus.sys -- (ssm_bus)
DRV - [2007.05.02 11:11:18 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2007.05.02 11:11:18 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2007.05.02 11:11:16 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bus.sys -- (ss_bus)
DRV - [2007.03.05 23:28:00 | 000,076,288 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2006.02.20 18:59:33 | 000,094,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006.02.20 18:59:31 | 000,008,336 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006.02.20 18:59:27 | 000,058,288 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\w810bus.sys -- (w810bus)
DRV - [2005.12.12 19:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2003.07.15 11:25:48 | 000,099,476 | ---- | M] (Syntek Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\STK014W2.sys -- (DCamUSBSTK014)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKLM\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = http://search.qip.ru/?query={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://google.icq.com/search/search_frame.php
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes,DefaultScope = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... 1I7GGLL_en
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = http://search.qip.ru/?query={searchTerms}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}: "URL" = http://www.icq.com/search/results.php?q ... &ch_id=osd
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{E6A0E8A3-0BC1-4916-8338-B6BEF00D6AB2}: "URL" = http://search.seznam.cz/?q={searchTerms ... =SearchBox
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\search13: "URL" = http://search13.net/search.php?q={searchTerms}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search13.net/search.php?clid=486&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.1.9&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_result ... id=afex&q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: D:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: D:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009.09.20 18:26:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.05 13:29:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.03.14 22:27:46 | 000,000,000 | ---D | M]

[2008.09.14 19:17:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dagmar\AppData\Roaming\mozilla\Extensions
[2012.09.14 19:06:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dagmar\AppData\Roaming\mozilla\Firefox\Profiles\4geh67ov.default\extensions
[2009.09.03 09:16:16 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dagmar\AppData\Roaming\mozilla\Firefox\Profiles\4geh67ov.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.07.06 16:49:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009.09.20 18:26:38 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}
[2010.11.02 16:55:15 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.11.02 16:55:15 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2010.11.02 16:55:15 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2010.11.02 16:55:15 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - homepage: http://www.seznam.cz/
CHR - default_search_provider: Seznam (Enabled)
CHR - default_search_provider: search_url = http://search.seznam.cz/?q={searchTerms}
CHR - default_search_provider: suggest_url = http:///suggest.fulltext.seznam.cz/?dict=fulltext_ff&phrase={searchTerms}&encoding={inputEncoding}&response_encoding=utf-8
CHR - homepage: http://www.seznam.cz/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Facebook Sidebar Chat Reversion = C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfophgoebcoehkldfgeffhnlcabhhomn\1.4.10_0\
CHR - Extension: Gmail = C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012.07.05 13:45:23 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe ()
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O7 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D290AD1E-1CEB-40B5-A3B7-6F4B4DECA40C}: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D290AD1E-1CEB-40B5-A3B7-6F4B4DECA40C}: NameServer = 172.20.2.69,217.197.152.132
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.09.06 22:17:55 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.07.31 15:10:04 | 000,331,918 | R--- | M] () - E:\AutoApp.exe -- [ CDFS ]
O32 - AutoRun File - [2001.09.21 15:36:46 | 000,000,042 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\Shell - "" = AutoRun
O33 - MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\Shell\AutoRun\command - "" = J:\Startme.exe
O33 - MountPoints2\{1d1d627e-7258-11e0-81f2-001bb9d317ae}\Shell - "" = AutoRun
O33 - MountPoints2\{1d1d627e-7258-11e0-81f2-001bb9d317ae}\Shell\AutoRun\command - "" = J:\VW100_Modem_Installation.exe
O33 - MountPoints2\{46f12a46-b2cf-11dc-99b5-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{46f12a46-b2cf-11dc-99b5-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoApp.exe -- [2009.07.31 15:10:04 | 000,331,918 | R--- | M] ()
O33 - MountPoints2\{d788c0c6-7ef9-11df-a988-001bb9d317ae}\Shell - "" = AutoRun
O33 - MountPoints2\{d788c0c6-7ef9-11df-a988-001bb9d317ae}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.09.15 11:33:46 | 000,599,552 | ---- | C] (OldTimer Tools) -- C:\Users\Dagmar\Desktop\OTL.exe
[2012.09.15 09:58:38 | 000,000,000 | ---D | C] -- C:\rsit
[2012.09.09 15:41:30 | 000,000,000 | ---D | C] -- C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spider-Man Creative Studio
[2012.09.09 15:41:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spider-Man Creative Studio
[2012.09.09 15:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Alternative Software Ltd
[2012.05.22 08:06:24 | 003,654,896 | ---- | C] (Piriform Ltd) -- C:\Users\Dagmar\ccsetup318.exe

========== Files - Modified Within 7 Days ==========

[2012.09.15 11:45:39 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.09.15 11:33:50 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Dagmar\Desktop\OTL.exe
[2012.09.15 11:23:10 | 001,845,405 | ---- | M] () -- C:\Users\Dagmar\Desktop\P1180626_2.jpg
[2012.09.15 11:10:37 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 11:10:37 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 09:57:55 | 000,781,383 | ---- | M] () -- C:\Users\Dagmar\Desktop\RSIT.exe
[2012.09.15 09:10:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.13 15:24:10 | 000,105,276 | ---- | M] () -- C:\Users\Dagmar\Desktop\WallpaperButterflyDreamBlue1.jpg
[2012.09.12 20:27:28 | 000,164,131 | ---- | M] () -- C:\Users\Dagmar\Desktop\1280px_20120910_165926_DSC_9830.jpg
[2012.09.12 20:11:27 | 000,621,164 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.09.12 20:11:27 | 000,609,396 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.12 20:11:27 | 000,124,958 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.09.12 20:11:27 | 000,109,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.12 20:10:36 | 000,086,016 | ---- | M] () -- C:\Users\Dagmar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.12 19:14:03 | 005,266,293 | ---- | M] () -- C:\Users\Dagmar\Desktop\2012-09-10_Buresovi_1280px.zip
[2012.09.10 13:37:15 | 439,932,816 | ---- | M] () -- C:\Users\Dagmar\Desktop\LegendsofAtlantisExodusCs_13712.exe
[2012.09.10 13:17:52 | 000,000,412 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Dagmar.job
[2012.09.10 13:06:47 | 000,000,206 | ---- | M] () -- C:\Users\Dagmar\Desktop\Jednotka CD-ROM – zástupce.lnk

========== Files Created - No Company Name ==========

[2012.09.15 11:45:39 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.09.15 11:22:35 | 001,845,405 | ---- | C] () -- C:\Users\Dagmar\Desktop\P1180626_2.jpg
[2012.09.15 09:57:48 | 000,781,383 | ---- | C] () -- C:\Users\Dagmar\Desktop\RSIT.exe
[2012.09.13 15:24:27 | 000,105,276 | ---- | C] () -- C:\Users\Dagmar\Desktop\WallpaperButterflyDreamBlue1.jpg
[2012.09.12 20:26:58 | 000,164,131 | ---- | C] () -- C:\Users\Dagmar\Desktop\1280px_20120910_165926_DSC_9830.jpg
[2012.09.12 19:14:07 | 005,266,293 | ---- | C] () -- C:\Users\Dagmar\Desktop\2012-09-10_Buresovi_1280px.zip
[2012.09.10 13:29:12 | 439,932,816 | ---- | C] () -- C:\Users\Dagmar\Desktop\LegendsofAtlantisExodusCs_13712.exe
[2012.09.10 13:06:47 | 000,000,206 | ---- | C] () -- C:\Users\Dagmar\Desktop\Jednotka CD-ROM – zástupce.lnk
[2011.12.09 16:09:14 | 000,000,680 | ---- | C] () -- C:\Users\Dagmar\AppData\Local\d3d9caps.dat
[2011.12.01 18:32:23 | 000,000,270 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.11.02 17:23:43 | 000,000,109 | ---- | C] () -- C:\Windows\wininit.ini
[2010.11.02 17:04:10 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.09.29 03:13:06 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2008.07.10 12:13:37 | 000,000,094 | ---- | C] () -- C:\Users\Dagmar\AppData\Local\fusioncache.dat
[2008.06.17 10:25:13 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2008.03.06 13:05:35 | 000,000,104 | ---- | C] () -- C:\Users\Dagmar\AppData\Roaming\wklnhst.dat
[2008.02.01 19:00:17 | 000,000,644 | RHS- | C] () -- C:\Users\Dagmar\ntuser.pol
[2008.01.30 11:47:09 | 000,031,802 | ---- | C] () -- C:\Users\Dagmar\AppData\Roaming\UserTile.png
[2007.12.26 21:26:00 | 000,086,016 | ---- | C] () -- C:\Users\Dagmar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2008.04.16 17:04:55 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Canon
[2010.02.28 14:43:24 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.02.24 21:48:36 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\GHISLER
[2012.04.01 15:06:23 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQ
[2008.04.20 18:18:18 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQ Toolbar
[2008.04.20 17:54:52 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQLite
[2012.02.24 21:33:42 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\IObit
[2008.04.23 08:58:10 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\mbin.jp
[2008.04.10 18:11:04 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\muvee Technologies
[2008.01.30 11:47:09 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\PeerNetworking
[2008.08.06 15:08:52 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\QIP
[2010.04.29 16:31:30 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Samsung
[2011.09.29 21:10:08 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\SMART Technologies
[2011.09.29 20:14:45 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\SMART Technologies Inc
[2008.03.06 13:05:50 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Template
[2009.04.09 09:43:13 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ThumbsPlus
[2009.03.07 18:09:32 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\TigerPlayer
[2007.12.28 13:57:47 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Zoner
[2008.06.12 08:23:19 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\ICQ Toolbar
[2012.09.14 19:29:46 | 000,032,586 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< netsvc >

< MD5 for: ATAPI.SYS >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.04.20 20:29:39 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.04.20 20:29:39 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.04.20 20:29:38 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2009.04.11 08:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\System32\autochk.exe
[2009.04.11 08:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2008.01.19 09:33:01 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2006.11.02 11:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe

< MD5 for: CDROM.SYS >
[2008.01.19 07:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_a29e71c6\cdrom.sys
[2008.01.19 07:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6001.18000_none_5fa95be2a3c76a4a\cdrom.sys
[2009.04.11 06:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\drivers\cdrom.sys
[2009.04.11 06:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_c949a5b6\cdrom.sys
[2009.04.11 06:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys
[2006.11.02 10:51:44 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=8D1866E61AF096AE8B582454F5E4D303 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_e487f727\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008.04.20 20:33:44 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2008.04.20 20:33:44 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008.01.19 09:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: HAL.DLL >
[2009.04.11 08:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Windows\System32\hal.dll

< MD5 for: SCECLI.DLL >
[2008.01.19 09:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< MD5 for: SVCHOST.EXE >
[2006.11.02 11:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008.01.19 09:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008.01.19 09:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.26 10:08:16 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=01EC1E92595F839BEE70D439C46796E3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys
[2009.04.11 08:33:02 | 000,897,000 | ---- | M] (Microsoft Corporation) MD5=0E6B0885C3D5E4643ED2D043DE3433D8 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_b5098b5e63880c42\tcpip.sys
[2011.09.20 23:02:55 | 000,913,280 | ---- | M] (Microsoft Corporation) MD5=16731B631F28F63CD9F4CB60940E7DDD -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_b58c64c97caa1c43\tcpip.sys
[2009.12.08 22:52:30 | 000,897,624 | ---- | M] (Microsoft Corporation) MD5=1ACBB7A47E78F4CC82D2EFFB72901528 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18377_none_b2d96a966698ad63\tcpip.sys
[2009.08.15 23:30:53 | 000,816,640 | ---- | M] (Microsoft Corporation) MD5=2512B4D1353370D6688B1AF1F5AFA1CF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\tcpip.sys
[2009.08.14 19:01:55 | 000,900,168 | ---- | M] (Microsoft Corporation) MD5=2608E71AAD54564647D4BB984E1925AA -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys
[2011.06.17 22:13:55 | 000,905,104 | ---- | M] (Microsoft Corporation) MD5=2756186E287139310997090797E0182B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18484_none_b4b2134c63c9c70f\tcpip.sys
[2012.03.30 14:39:11 | 000,905,600 | ---- | M] (Microsoft Corporation) MD5=27D470DABC77BC60D0A3B0E4DEB6CB91 -- C:\Windows\SoftwareDistribution\Download\c1025705c7a6a05076ba159d67e7ebd9\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18604_none_b50896786388e1d5\tcpip.sys
[2012.05.12 12:47:20 | 000,905,600 | ---- | M] (Microsoft Corporation) MD5=27D470DABC77BC60D0A3B0E4DEB6CB91 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18604_none_b50896786388e1d5\tcpip.sys
[2010.02.18 13:51:51 | 000,818,688 | ---- | M] (Microsoft Corporation) MD5=2C1F7005AA3B62721BFDB307BD5F5010 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_6019359fab5bb15b\tcpip.sys
[2010.02.18 16:49:38 | 000,898,952 | ---- | M] (Microsoft Corporation) MD5=2EAE4500984C2F8DACFB977060300A15 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys
[2009.08.14 16:24:47 | 000,813,568 | ---- | M] (Microsoft Corporation) MD5=300208927321066EA53761FDC98747C6 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\tcpip.sys
[2009.12.08 22:15:00 | 000,907,832 | ---- | M] (Microsoft Corporation) MD5=46E6685F3E92AEC743773ADD4CD54F57 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22283_none_b53aaa1b7ce8560d\tcpip.sys
[2010.02.18 16:07:16 | 000,904,576 | ---- | M] (Microsoft Corporation) MD5=48CBE6D53632D0067C2D6B20F90D84CA -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_b50d905263846bec\tcpip.sys
[2010.02.18 14:05:37 | 000,815,104 | ---- | M] (Microsoft Corporation) MD5=4A82FA8F0DF67AA354580C3FAAF8BDE3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_5f8a957c924295b7\tcpip.sys
[2008.04.20 20:28:44 | 000,806,400 | ---- | M] (Microsoft Corporation) MD5=52A8BD6294F7D1443C6184C67AE13AF4 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys
[2009.12.08 22:37:09 | 000,900,696 | ---- | M] (Microsoft Corporation) MD5=5653230D480A9C54D169E1B080B72CF5 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys
[2008.04.20 20:28:44 | 000,803,328 | ---- | M] (Microsoft Corporation) MD5=5DF77458AA92FDB36FCE79C60F74AB5D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
[2010.06.16 17:55:58 | 000,902,032 | ---- | M] (Microsoft Corporation) MD5=6216A954ED7045B62880A92D6C9B9FC7 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys
[2009.08.14 18:27:34 | 000,904,776 | ---- | M] (Microsoft Corporation) MD5=65877AA1B6A7CB797488E831698973E9 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_b4a43aea63d4a25f\tcpip.sys
[2011.06.17 22:13:55 | 000,913,296 | ---- | M] (Microsoft Corporation) MD5=6647FCE6FC4970DAAFE5C64C794513D3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_b54f51417cd8f970\tcpip.sys
[2010.06.16 18:39:32 | 000,912,776 | ---- | M] (Microsoft Corporation) MD5=6A10AFCE0B38371064BE41C1FBFD3C6B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_b57d8e037cb5db63\tcpip.sys
[2010.06.16 17:59:54 | 000,898,952 | ---- | M] (Microsoft Corporation) MD5=782568AB6A43160A159B6215B70BCCE9 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys
[2011.09.20 23:02:55 | 000,905,088 | ---- | M] (Microsoft Corporation) MD5=814A1C66FBD4E1B310A517221F1456BF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18519_none_b502c618638c7f52\tcpip.sys
[2008.04.26 10:26:49 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=82E266BEE5F0167E41C6ECFDD2A79C02 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys
[2009.12.08 19:58:13 | 000,813,568 | ---- | M] (Microsoft Corporation) MD5=8734BD051FFDCBF8425CF222141C3741 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16973_none_5f56ae52926920d8\tcpip.sys
[2009.08.14 19:07:56 | 000,897,608 | ---- | M] (Microsoft Corporation) MD5=8A7AD2A214233F684242F289ED83EBC3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys
[2010.02.18 19:36:50 | 000,902,024 | ---- | M] (Microsoft Corporation) MD5=93A5655CD9CD2F080EF1CB71A3666215 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys
[2010.06.16 18:04:57 | 000,905,088 | ---- | M] (Microsoft Corporation) MD5=A474879AFA4A596B3A531F3E69730DBF -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_b4baded863c37e22\tcpip.sys
[2010.04.05 19:03:01 | 000,902,024 | ---- | M] (Microsoft Corporation) MD5=A6A02EF5B5E40FBD31A1ADC577DA54BB -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22665_none_b36bda857faff8dc\tcpip.sys
[2009.12.08 19:45:32 | 000,816,640 | ---- | M] (Microsoft Corporation) MD5=CA3A5756672013A66BB9D547A5A62DCA -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21175_none_5fe223d3ab852692\tcpip.sys
[2010.04.05 22:00:48 | 000,910,208 | ---- | M] (Microsoft Corporation) MD5=CC9993701AC57F995554C696DDA49C12 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22377_none_b5497d157cdc9c9f\tcpip.sys
[2006.11.02 10:58:38 | 000,802,816 | ---- | M] (Microsoft Corporation) MD5=D944522B048A5FEB7700B5170D3D9423 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
[2010.02.18 16:22:11 | 000,910,216 | ---- | M] (Microsoft Corporation) MD5=D9F5DD5BBC8348E8F8220CCBF14C022E -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_b563eb1d7cc9b0c2\tcpip.sys
[2009.12.08 22:01:08 | 000,904,776 | ---- | M] (Microsoft Corporation) MD5=DA467E7619AE5F4588E6262C13C8940A -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18160_none_b4c3ac4a63bd325c\tcpip.sys
[2012.03.30 14:39:11 | 000,914,304 | ---- | M] (Microsoft Corporation) MD5=EE7E10BED85C312C1D5D30C435BDDA9F -- C:\Windows\SoftwareDistribution\Download\c1025705c7a6a05076ba159d67e7ebd9\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22828_none_b58096797cb31c04\tcpip.sys
[2012.05.12 12:47:20 | 000,914,304 | ---- | M] (Microsoft Corporation) MD5=EE7E10BED85C312C1D5D30C435BDDA9F -- C:\Windows\System32\drivers\tcpip.sys
[2012.05.12 12:47:20 | 000,914,304 | ---- | M] (Microsoft Corporation) MD5=EE7E10BED85C312C1D5D30C435BDDA9F -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22828_none_b58096797cb31c04\tcpip.sys
[2008.01.19 09:43:39 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=FC6E2835D667774D409C7C7021EAF9C4 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys
[2009.08.14 18:33:50 | 000,905,784 | ---- | M] (Microsoft Corporation) MD5=FF71856BD4CD6D4367F9FD84BE79A874 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_b58e289d7caa2a80\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%*.* /U /s >
[95 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\91ae82cb0f345a3c3f4bf16f721256f9\*.tmp files -> C:\Windows\SoftwareDistribution\Download\91ae82cb0f345a3c3f4bf16f721256f9\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\ba0888a79dfb30234773c132b1e12d7d\*.tmp files -> C:\Windows\SoftwareDistribution\Download\ba0888a79dfb30234773c132b1e12d7d\*.tmp -> ]
[3 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#5 Příspěvek od David Langr »

Druhá půlka:
< %APPDATA%\*. >
[2010.05.06 16:40:58 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Adobe
[2007.12.25 12:19:53 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ATI
[2008.04.16 17:04:55 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Canon
[2010.02.28 14:43:24 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.07.23 16:58:27 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Corel
[2012.09.01 19:00:53 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\dvdcss
[2009.02.24 21:48:36 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\GHISLER
[2008.12.04 12:55:52 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Google
[2007.12.25 12:16:06 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Hewlett-Packard
[2012.04.01 15:06:23 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQ
[2008.04.20 18:18:18 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQ Toolbar
[2008.04.20 17:54:52 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ICQLite
[2007.12.25 12:19:02 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Identities
[2012.02.24 21:33:42 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\IObit
[2007.12.25 12:16:37 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Macromedia
[2008.04.23 08:58:10 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\mbin.jp
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Media Center Programs
[2012.02.24 21:51:00 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Media Player Classic
[2008.12.09 11:53:35 | 000,000,000 | --SD | M] -- C:\Users\Dagmar\AppData\Roaming\Microsoft
[2008.09.14 19:17:19 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Mozilla
[2008.04.10 18:11:04 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\muvee Technologies
[2007.12.28 13:45:00 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Nero
[2008.01.30 11:47:09 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\PeerNetworking
[2008.08.06 15:08:52 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\QIP
[2009.04.24 11:19:39 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Roxio
[2010.04.29 16:31:30 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Samsung
[2012.09.15 12:01:11 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Skype
[2012.08.24 12:10:06 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\skypePM
[2011.09.29 21:10:08 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\SMART Technologies
[2011.09.29 20:14:45 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\SMART Technologies Inc
[2008.03.06 13:05:50 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Template
[2009.04.09 09:43:13 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\ThumbsPlus
[2009.03.07 18:09:32 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\TigerPlayer
[2010.06.24 17:45:05 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\U3
[2010.07.31 13:34:36 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\vlc
[2007.12.28 13:57:47 | 000,000,000 | ---D | M] -- C:\Users\Dagmar\AppData\Roaming\Zoner

< %APPDATA%\*.exe /s >
[2006.08.15 10:15:04 | 000,110,592 | ---- | M] () -- C:\Users\Dagmar\AppData\Roaming\U3\temp\cleanup.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2012.09.10 13:17:52 | 000,000,412 | -H-- | M] () -- C:\Windows\Tasks\Norton Security Scan for Dagmar.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.09.15 11:10:37 | 000,003,568 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.15 11:10:37 | 000,003,568 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.12 14:25:42 | 062,164,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mrt.exe
[2012.09.12 20:11:27 | 000,124,958 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2012.09.12 20:11:27 | 000,109,672 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2012.09.12 20:11:27 | 000,621,164 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2012.09.12 20:11:27 | 000,609,396 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2012.09.12 20:11:27 | 001,459,328 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI

< %SYSTEMDRIVE%\*.exe >

< %userprofile%\Plocha\*.* >

< %userprofile%\Desktop\*.* >
[2012.09.12 20:27:28 | 000,164,131 | ---- | M] () -- C:\Users\Dagmar\Desktop\1280px_20120910_165926_DSC_9830.jpg
[2012.09.12 19:14:03 | 005,266,293 | ---- | M] () -- C:\Users\Dagmar\Desktop\2012-09-10_Buresovi_1280px.zip
[2012.04.21 15:48:50 | 000,001,894 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArtSmall.jpg
[2009.11.17 12:22:46 | 000,011,043 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{0446F4FA-2465-4581-A855-189C346A67EA}_Large.jpg
[2009.11.17 12:22:44 | 000,002,802 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{0446F4FA-2465-4581-A855-189C346A67EA}_Small.jpg
[2010.01.11 21:32:35 | 000,012,963 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{73C3B23B-AD56-4804-85D8-5ECF6AE9BEF0}_Large.jpg
[2010.01.11 21:32:35 | 000,003,177 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{73C3B23B-AD56-4804-85D8-5ECF6AE9BEF0}_Small.jpg
[2009.12.03 12:38:15 | 000,009,849 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{7443DB61-A2B3-423A-8F61-2442D3574412}_Large.jpg
[2009.12.03 12:38:15 | 000,002,293 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{7443DB61-A2B3-423A-8F61-2442D3574412}_Small.jpg
[2012.04.21 15:29:13 | 000,007,741 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{7B0C8F9C-C792-48E5-8C78-C9465B5374B9}_Large.jpg
[2012.04.21 15:29:13 | 000,002,413 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{7B0C8F9C-C792-48E5-8C78-C9465B5374B9}_Small.jpg
[2009.05.04 16:20:13 | 000,012,125 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{8A4A76A9-A8D6-424D-A5BD-CD9C03B8743B}_Large.jpg
[2009.05.04 16:20:12 | 000,002,924 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{8A4A76A9-A8D6-424D-A5BD-CD9C03B8743B}_Small.jpg
[2012.04.21 15:21:29 | 000,008,943 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{DA1B5F4B-F194-4742-9A2F-B4F8A1CFAA5D}_Large.jpg
[2012.04.21 15:21:25 | 000,002,457 | -HS- | M] () -- C:\Users\Dagmar\Desktop\AlbumArt_{DA1B5F4B-F194-4742-9A2F-B4F8A1CFAA5D}_Small.jpg
[2012.08.02 09:35:41 | 000,000,460 | -HS- | M] () -- C:\Users\Dagmar\Desktop\desktop.ini
[2008.01.25 15:47:30 | 000,241,152 | -HS- | M] () -- C:\Users\Dagmar\Desktop\ehthumbs_vista.db
[2012.04.21 15:48:50 | 000,005,830 | -HS- | M] () -- C:\Users\Dagmar\Desktop\Folder.jpg
[2011.03.13 19:33:48 | 000,001,991 | ---- | M] () -- C:\Users\Dagmar\Desktop\Google Chrome.lnk
[2012.07.06 10:27:16 | 018,719,024 | ---- | M] (Microsoft Corporation) -- C:\Users\Dagmar\Desktop\IE9-WindowsVista-x86-csy.exe
[2012.08.22 20:00:49 | 000,000,205 | ---- | M] () -- C:\Users\Dagmar\Desktop\Jednotka CD-ROM – zástupce (2).lnk
[2012.09.10 13:06:47 | 000,000,206 | ---- | M] () -- C:\Users\Dagmar\Desktop\Jednotka CD-ROM – zástupce.lnk
[2008.11.08 11:47:03 | 000,001,614 | ---- | M] () -- C:\Users\Dagmar\Desktop\kalkulátor.lnk
[2011.02.15 10:40:33 | 000,000,945 | ---- | M] () -- C:\Users\Dagmar\Desktop\Launch Internet Explorer.lnk
[2012.09.10 13:37:15 | 439,932,816 | ---- | M] () -- C:\Users\Dagmar\Desktop\LegendsofAtlantisExodusCs_13712.exe
[2011.01.21 18:32:32 | 000,001,835 | ---- | M] () -- C:\Users\Dagmar\Desktop\MP Navigator 3.1.lnk
[2008.09.14 19:16:54 | 000,001,744 | ---- | M] () -- C:\Users\Dagmar\Desktop\ONDRA.lnk
[2012.09.15 11:33:50 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Dagmar\Desktop\OTL.exe
[2012.09.15 11:23:10 | 001,845,405 | ---- | M] () -- C:\Users\Dagmar\Desktop\P1180626_2.jpg
[2008.03.31 09:52:46 | 000,000,104 | ---- | M] () -- C:\Users\Dagmar\Desktop\počítač.lnk
[2012.09.15 09:57:55 | 000,781,383 | ---- | M] () -- C:\Users\Dagmar\Desktop\RSIT.exe
[2012.09.05 21:53:26 | 000,288,690 | ---- | M] () -- C:\Users\Dagmar\Desktop\salamander-glacier--glacier-national-park--montana.jpg
[2012.08.24 12:25:04 | 000,002,395 | ---- | M] () -- C:\Users\Dagmar\Desktop\Skype.lnk
[2012.09.13 15:24:10 | 000,105,276 | ---- | M] () -- C:\Users\Dagmar\Desktop\WallpaperButterflyDreamBlue1.jpg
[2012.09.10 21:46:20 | 000,059,431 | ---- | M] () -- C:\Users\Dagmar\Desktop\Zásady při ošetřování muslima.pptx
[2009.01.07 16:28:15 | 000,000,162 | -H-- | M] () -- C:\Users\Dagmar\Desktop\~$akomec.docx

< %ALLUSERSPROFILE%\Plocha\*.* >

< %ALLUSERSPROFILE%\Desktop\*.* >

< *crack* /s >
[1999.06.11 20:18:36 | 000,092,827 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 18:31:34 | 000,016,068 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 19:15:39 | 000,010,560 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2004.12.14 15:30:24 | 000,303,953 | ---- | M] () -- \Program Files\DVD slideshow GUI\Transitions\crack.jpg

< *keygen* /s >

< *loader* /s >
[2006.09.23 03:34:28 | 000,040,960 | ---- | M] () -- \hp\bin\Python\Lib\site-packages\isapi\PyISAPI_loader.dll
[2006.09.23 03:28:26 | 000,005,632 | ---- | M] () -- \hp\bin\Python\Lib\site-packages\win32\_win32sysloader.pyd
[2006.10.26 14:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 14:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2007.10.26 09:05:08 | 000,107,816 | ---- | M] () -- \Program Files\Common Files\Nero\Shared\NSCLoader.dll
[2007.05.11 10:38:28 | 000,053,511 | R--- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\Common Resources\Shared\Generic\Images\themeloader_default_chapter.jpg
[2007.05.11 10:38:28 | 000,053,511 | R--- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\Common Resources\Shared\Generic\Images\themeloader_default_menu.jpg
[2007.05.11 17:24:48 | 000,006,401 | R--- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\Common Resources\Shared\Locale\1033\Strings\RCMFormatLoaderStrings.xml
[2007.05.11 11:14:26 | 000,211,704 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFileLoader.dll
[2007.05.11 11:14:28 | 000,084,728 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderBMP.dll
[2007.05.11 11:14:30 | 000,072,440 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderECDC.dll
[2007.05.11 11:14:30 | 000,092,920 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderGIF.dll
[2007.05.11 11:14:32 | 000,203,512 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderJPG2.dll
[2007.05.11 11:14:40 | 000,072,440 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderMDC.dll
[2007.05.11 11:14:34 | 000,133,880 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderPNG.dll
[2007.05.11 11:14:34 | 000,105,208 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\CPSFormatLoaderTIFF.dll
[2007.05.11 11:15:14 | 000,150,264 | ---- | M] () -- \Program Files\Common Files\Roxio Shared\9.0\SharedCom\LeResourceLoader.dll
[2011.06.14 19:22:04 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.06.14 19:22:05 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.06.14 19:22:04 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.07.27 19:28:06 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\icq_profile\preloader.html
[2011.06.14 19:25:39 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\profile_forms\preloader.html
[2011.06.14 19:25:39 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\profile_lightboxs\preloader.html
[2005.08.18 14:12:12 | 000,144,233 | R--- | M] () -- \Program Files\Longman\Opportunities Intermediate\Opportunities Intermediate\minidict\loader.swf
[2007.05.27 14:13:00 | 001,073,192 | ---- | M] () -- \Program Files\muvee Technologies\muvee autoProducer 6.0 - HPD\Flash\loader_pc_mprojector.exe
[2006.12.04 14:21:14 | 000,012,804 | ---- | M] () -- \Program Files\muvee Technologies\muvee autoProducer 6.0 - HPD\Flash\qp6_qt_loader_web.swf
[2007.01.12 06:27:12 | 000,126,976 | ---- | M] () -- \Program Files\Roxio\VideoCore 9\VOBLoader.ax
[2007.02.10 13:09:58 | 000,159,744 | ---- | M] () -- \Program Files\Roxio\VideoUI 9\DSThemeLoader.dll
[2007.05.15 12:04:36 | 000,106,496 | ---- | M] () -- \Program Files\Roxio\VideoUI 9\DVDFormatLoaderPlugIn.dll
[2007.05.15 11:49:14 | 000,053,511 | R--- | M] () -- \Program Files\Roxio\VideoUI 9\Skins\Default\Generic\Images\themeloader_default_chapter.jpg
[2007.05.15 11:49:14 | 000,053,511 | R--- | M] () -- \Program Files\Roxio\VideoUI 9\Skins\Default\Generic\Images\themeloader_default_menu.jpg
[2007.05.15 11:49:14 | 000,040,000 | R--- | M] () -- \Program Files\Roxio\VideoUI 9\Skins\Default\Generic\Images\themeloader_hourglass.jpg
[2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- \ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
[2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- \ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
[2007.10.23 09:07:44 | 000,000,232 | ---- | M] () -- \ProgramData\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- \Users\All Users\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
[2008.11.27 12:29:42 | 000,043,008 | ---- | M] () -- \Users\All Users\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
[2007.10.23 09:07:44 | 000,000,232 | ---- | M] () -- \Users\All Users\Nero\Nero8\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2007.12.26 20:58:37 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2008.01.19 09:34:04 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2010.10.22 13:43:22 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2012.05.03 12:45:42 | 000,009,622 | ---- | M] () -- \Windows\System32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
[2012.09.14 18:15:30 | 000,003,306 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader
[2008.09.01 12:47:59 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2008.09.01 12:47:59 | 000,027,648 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winload.exe.mui_3bc5b827
[2008.09.01 12:47:59 | 000,019,968 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15_winresume.exe.mui_ff8b5358
[2010.05.01 17:12:11 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2010.05.01 17:12:11 | 000,986,600 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winload.exe_75835076
[2010.05.01 17:12:12 | 000,926,184 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94_winresume.exe_85cd1215
[2008.09.01 12:47:07 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2008.09.01 12:47:07 | 000,021,048 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2_spldr.sys_98bd87a0
[2008.04.20 18:01:07 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_de-de_cb9c6772f81a418b.manifest
[2008.04.20 18:00:35 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_en-us_748d3d6be6f84d50.manifest
[2008.04.20 18:01:29 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_es-es_74589a4fe71f3ef5.manifest
[2008.04.20 18:00:37 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_fr-fr_1710104ed9f15557.manifest
[2008.04.20 18:02:19 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_it-it_01380695b1233ad5.manifest
[2008.04.20 18:02:29 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_ja-jp_a35d85a2a43e4cb0.manifest
[2008.04.20 18:03:08 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.16646_nl-nl_2d992eca70004957.manifest
[2008.04.20 18:01:06 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_de-de_cbf6c366115bebbd.manifest
[2008.04.20 18:00:34 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_en-us_74e7995f0039f782.manifest
[2008.04.20 18:01:28 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_es-es_74b2f6430060e927.manifest
[2008.04.20 18:00:36 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_fr-fr_176a6c41f332ff89.manifest
[2008.04.20 18:02:18 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_it-it_01926288ca64e507.manifest
[2008.04.20 18:02:28 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_ja-jp_a3b7e195bd7ff6e2.manifest
[2008.04.20 18:03:07 | 000,003,414 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6000.20782_nl-nl_2df38abd8941f389.manifest
[2008.01.19 04:14:52 | 000,003,402 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_33426ea9fd097a15.manifest
[2008.04.20 18:00:21 | 000,004,858 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.16646_none_591b3d986f9b5725.manifest
[2008.04.20 18:00:20 | 000,004,858 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6000.20782_none_5975998b88dd0157.manifest
[2008.01.19 00:00:00 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18000_none_5b26ba326ca6e048.manifest
[2008.04.20 17:59:52 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.18027_none_5b181c606cb0c98b.manifest
[2008.04.20 17:59:52 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6001.22125_none_5b9fb89785d036a7.manifest
[2009.04.11 00:12:44 | 000,004,864 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.0.6002.18005_none_5d12333e69c8ab94.manifest
[2006.11.02 12:13:06 | 000,003,970 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6000.16386_none_68fc663d5430d3de.manifest
[2008.01.19 00:05:22 | 000,003,885 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.0.6001.18000_none_6b332839511be4b2.manifest
[2006.11.02 14:34:33 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6000.16386_none_43bd59f592b7be86\dmloader.dll
[2008.01.19 09:34:04 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6001.18000_none_45f41bf18fa2cf5a\dmloader.dll
[2008.01.19 09:34:04 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.0.6002.18005_none_47df94fd8cc49aa6\dmloader.dll

< *RemoveWAT* /s >

< *minodlogin* /s >

< *tnod* /s >
[2007.05.15 11:49:14 | 000,003,262 | R--- | M] () -- \Program Files\Roxio\VideoUI 9\Skins\Default\Generic\Images\Cursors\selectnode.cur

< *TemDono* /s >

< *AutoKMS* /s >

< *KMSEmulator* /s >

< *activator* /s >
[2007.01.12 06:17:34 | 000,155,648 | ---- | M] () -- \Program Files\Roxio\VideoCore 9\CGActivator.dll

< *serial* /s >
[1999.09.02 11:33:40 | 000,003,121 | ---- | M] () -- \hp\bin\Python\Lib\site-packages\pythonwin\pywin\Demos\ocx\ocxserialtest.py
[2007.09.06 21:50:41 | 000,004,989 | ---- | M] () -- \hp\bin\Python\Lib\site-packages\pythonwin\pywin\Demos\ocx\ocxserialtest.pyc
[2007.09.06 21:50:43 | 000,004,989 | ---- | M] () -- \hp\bin\Python\Lib\site-packages\pythonwin\pywin\Demos\ocx\ocxserialtest.pyo
[2012.03.29 06:01:00 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.dll
[2012.05.12 12:16:23 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.ni.dll
[2007.05.16 02:54:52 | 000,001,701 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport.p5i
[2007.05.16 02:54:52 | 000,002,803 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport.p5m
[2007.05.16 02:54:52 | 000,011,377 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport.p5p
[2007.05.16 02:54:50 | 000,052,224 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport.p5x
[2007.05.16 02:54:50 | 000,010,973 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_de.p5p
[2007.05.16 02:54:52 | 000,000,957 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_de_hp.p5p
[2007.05.16 02:54:52 | 000,011,417 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_es.p5p
[2007.05.16 02:54:52 | 000,000,948 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_es_hp.p5p
[2007.05.16 02:54:52 | 000,010,844 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_fr.p5p
[2007.05.16 02:54:52 | 000,000,953 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_fr_hp.p5p
[2007.05.16 02:54:52 | 000,001,081 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_hp.p5p
[2007.05.16 02:54:52 | 000,000,990 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_hp_asp.p5i
[2007.05.16 02:54:52 | 000,001,109 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_hp_mc.p5i
[2007.05.16 02:54:52 | 000,000,990 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_hp_odm.p5i
[2007.05.16 02:54:52 | 000,001,109 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_hp_pe.p5i
[2007.05.16 02:54:50 | 000,010,812 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_it.p5p
[2007.05.16 02:54:52 | 000,000,954 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_it_hp.p5p
[2007.05.16 02:54:52 | 000,011,610 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ja.p5p
[2007.05.16 02:54:52 | 000,000,964 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ja_hp.p5p
[2007.05.16 02:54:52 | 000,011,149 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ko.p5p
[2007.05.16 02:54:52 | 000,000,950 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ko_hp.p5p
[2007.05.16 02:54:52 | 000,010,673 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_nl.p5p
[2007.05.16 02:54:52 | 000,000,966 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_nl_hp.p5p
[2007.05.16 02:54:52 | 000,010,145 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_pt.p5p
[2007.05.16 02:54:50 | 000,000,962 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_pt_hp.p5p
[2007.05.16 02:54:52 | 000,016,346 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ru.p5p
[2007.05.16 02:54:52 | 000,001,020 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_ru_hp.p5p
[2007.05.16 02:54:52 | 000,009,077 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_zh-cn.p5p
[2007.05.16 02:54:52 | 000,000,905 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_zh-cn_hp.p5p
[2007.05.16 02:54:52 | 000,009,398 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_zh-tw.p5p
[2007.05.16 02:54:52 | 000,000,904 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\pcdrserialport_zh-tw_hp.p5p
[2007.05.16 03:00:06 | 000,017,137 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\serialport.jpg
[2007.05.16 03:00:08 | 000,004,055 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\serialport.png
[2007.05.16 03:00:20 | 000,014,658 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\img16_16\serialport.jpg
[2007.05.16 03:00:26 | 000,000,833 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\img16_16\serialport.png
[2007.05.16 03:00:30 | 000,001,413 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\img24_24\serialport.png
[2007.05.16 03:00:20 | 000,015,233 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\img32_32\serialport.jpg
[2007.05.16 03:00:24 | 000,002,178 | ---- | M] () -- \Program Files\PC-Doctor 5 for Windows\Images\img32_32\serialport.png
[2010.04.12 14:21:01 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2012.06.05 20:24:02 | 000,000,024 | ---- | M] () -- \Users\Dagmar\AppData\Local\Google\Picasa2\cache\cacheindex_serial.pmp
[2011.02.28 19:00:30 | 019,628,986 | ---- | M] () -- \Users\Public\Winzip 15.0 + serial cislo.rar
[2008.07.10 12:13:24 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2009.03.31 20:04:50 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.03.30 06:42:19 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2010.04.12 14:21:01 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2012.05.12 13:02:25 | 002,346,496 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1619144e1a9eaca847e53b952b21820b\System.Runtime.Serialization.ni.dll
[2012.05.12 13:01:27 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1ee6b56dc9985fbbdeb373b611ac4fb3\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.05.12 13:09:49 | 000,311,296 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\5a4d233916a69d48fa12a9f7f103d893\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.05.12 13:09:38 | 002,647,040 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
[2012.05.12 13:13:55 | 000,009,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\4b540b784465ca3f0742990e5af444e3\System.Xml.Serialization.ni.dll
[2005.12.15 04:17:50 | 000,017,133 | R--- | M] () -- \Windows\inf\SocketSerialBT.inf
[2011.06.16 13:40:44 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2012.06.14 21:46:40 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.06.16 13:40:44 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2012.06.14 21:46:37 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2012.06.14 21:46:50 | 000,011,120 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2004.07.15 14:31:54 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
[2009.03.30 06:42:19 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2009.03.31 20:04:50 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.04.12 14:21:15 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2010.03.18 14:16:28 | 001,026,936 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 14:16:28 | 000,122,264 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2011.04.06 16:48:20 | 000,011,120 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2010.06.15 03:33:16 | 000,017,840 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.06.15 03:33:16 | 000,099,208 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2008.01.19 09:36:21 | 000,015,360 | ---- | M] () -- \Windows\System32\serialui.dll
[2007.09.07 06:53:16 | 000,005,632 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2006.11.02 10:51:30 | 000,083,456 | ---- | M] () -- \Windows\System32\drivers\serial.sys
[2007.09.07 06:53:18 | 000,004,096 | ---- | M] () -- \Windows\System32\drivers\cs-CZ\grserial.sys.mui
[2007.09.07 06:53:18 | 000,010,240 | ---- | M] () -- \Windows\System32\drivers\cs-CZ\serial.sys.mui
[2008.01.19 07:49:35 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\hiddigi.inf_33048ac2\serial.sys
[2006.11.02 10:51:30 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\hiddigi.inf_9d4661e2\serial.sys
[2006.11.02 09:41:49 | 001,010,560 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\mdmmotsm.inf_91bbdacd\smserial.sys
[2008.01.19 07:49:35 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_44880ea7\serial.sys
[2006.11.02 10:51:30 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_ac874de4\serial.sys
[2006.11.02 10:51:28 | 000,031,232 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_a24cc104\grserial.sys
[2008.01.19 07:49:33 | 000,031,232 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\smartcrd.inf_bec36faa\grserial.sys
[2010.05.01 17:12:26 | 000,003,462 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18005_none_13a1062aa9ccba61.manifest
[2010.05.01 17:12:26 | 000,017,384 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18005_none_13a1062aa9ccba61_kdcom.dll_db5e7744
[2008.09.01 12:47:11 | 000,005,632 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_4e6ae191e3aac47c_serialui.dll.mui_7d29d2a3
[2010.05.01 17:13:23 | 000,015,360 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_f6ed1a9a1bcc8805_serialui.dll_bea29328
[2006.11.02 14:33:50 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16386_none_d24e4473b7df83f3.manifest
[2008.06.23 04:05:53 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16708_none_d2461403b7e6edc1.manifest
[2008.06.23 04:02:26 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.20864_none_bb7eca1fd1887f4d.manifest
[2008.01.19 00:05:26 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18000_none_d222c62fb8372cbf.manifest
[2008.06.23 04:40:19 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18096_none_d22b4019b82faa94.manifest
[2008.06.23 03:58:46 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.22208_none_bb54690bd1df5a1e.manifest
[2009.04.11 00:16:00 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18005_none_d1fe4b6bb888c0d3.manifest
[2010.04.12 20:29:50 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18239_none_d200f0e1b88673fe.manifest
[2010.04.12 21:40:05 | 000,003,028 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.22380_none_bb39189bd2286c0e.manifest
[2007.09.07 06:51:38 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_cs-cz_5ff98b2cc72ba40d.manifest
[2006.11.02 14:39:55 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_en-us_bb16054302d6ef1f.manifest
[2008.06.23 04:30:17 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16708_en-us_bb0dd4d302de58ed.manifest
[2008.08.14 07:39:56 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16730_cs-cz_5ff511dac72f8cd8.manifest
[2008.06.23 04:23:53 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20864_en-us_a4468aef1c7fea79.manifest
[2008.08.14 07:23:06 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20895_cs-cz_492cfaeee0d2050d.manifest
[2008.01.19 04:14:26 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18000_cs-cz_5fce0ce8c7834cd9.manifest
[2008.06.23 04:32:13 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18096_en-us_baf300e9032715c0.manifest
[2008.08.14 10:36:16 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18121_cs-cz_5fcff690c7819979.manifest
[2008.06.23 04:09:44 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22208_en-us_a41c29db1cd6c54a.manifest
[2008.08.14 09:03:05 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22243_cs-cz_490422d4e1275f6f.manifest
[2009.04.11 11:04:50 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18005_cs-cz_5fa99224c7d4e0ed.manifest
[2010.04.13 00:15:50 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_cs-cz_5fac379ac7d29418.manifest
[2010.04.12 19:44:55 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_en-us_bac8b1b1037ddf2a.manifest
[2010.04.13 00:51:48 | 000,002,584 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_cs-cz_48e45f54e1748c28.manifest
[2010.04.12 20:41:31 | 000,000,633 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_en-us_a400d96b1d1fd73a.manifest
[2006.11.02 14:33:50 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16386_none_02917a0ddf868526.manifest
[2008.06.23 04:05:31 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16708_none_0289499ddf8deef4.manifest
[2008.06.23 04:02:01 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.20864_none_ebc1ffb9f92f8080.manifest
[2008.01.19 00:04:20 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18000_none_0265fbc9dfde2df2.manifest
[2008.06.23 04:39:55 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18096_none_026e75b3dfd6abc7.manifest
[2008.06.23 03:58:14 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.22208_none_eb979ea5f9865b51.manifest
[2009.04.11 00:15:32 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18005_none_02418105e02fc206.manifest
[2010.04.12 20:29:29 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531.manifest
[2010.04.12 21:39:45 | 000,003,227 | ---- | M] () -- \Windows\winsxs\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41.manifest
[2006.11.02 12:18:20 | 000,003,462 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6000.16386_none_0f7ecb22afbfde41.manifest
[2008.01.19 00:01:04 | 000,003,462 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6001.18000_none_11b58d1eacaaef15.manifest
[2009.04.11 00:13:32 | 000,003,462 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.0.6002.18005_none_13a1062aa9ccba61.manifest
[2006.11.02 12:02:09 | 000,001,406 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.0.6000.16386_none_2a8610ec098ae6c4.manifest
[2006.11.02 14:33:50 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_076c25db205d1f68.manifest
[2008.06.23 04:08:38 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_0763f56b20648936.manifest
[2008.06.23 04:05:46 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_f09cab873a061ac2.manifest
[2008.01.19 00:13:44 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_0740a79720b4c834.manifest
[2008.06.23 04:43:41 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_0749218120ad4609.manifest
[2008.06.23 04:02:24 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_f0724a733a5cf593.manifest
[2009.04.11 00:18:56 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_071c2cd321065c48.manifest
[2010.04.12 20:32:33 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73.manifest
[2010.04.12 21:42:39 | 000,003,062 | ---- | M] () -- \Windows\winsxs\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783.manifest
[2006.10.20 03:14:53 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16386_none_483e6ea12378b3a8\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.27 20:00:27 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.16720_none_4838f505237d831c\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.27 19:55:55 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6000.20883_none_31710ba93d1fc80f\System.Runtime.Serialization.Formatters.Soap.dll
[2008.01.05 13:26:58 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18000_none_4812f05d23d05c74\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.27 20:03:15 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.18111_none_4813d9bb23cf8fbd\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.27 19:58:35 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6001.22230_none_31484a573d7508d0\System.Runtime.Serialization.Formatters.Soap.dll
[2009.03.30 06:42:19 | 000,131,072 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.0.6002.18005_none_47ee75992421f088\System.Runtime.Serialization.Formatters.Soap.dll
[2007.09.07 06:52:35 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.16386_cs-cz_0167850d1d10bca1\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.13 00:57:47 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.16754_cs-cz_0164b12f1d133e9e\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.13 00:56:42 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6000.20921_cs-cz_ea944dc536bd060d\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.01.05 13:27:19 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.18000_cs-cz_013c06c91d68656d\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.16 00:24:37 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.18145_cs-cz_013f95e51d654b3f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.16 00:25:16 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6001.22269_cs-cz_ea739499370b4477\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.03.31 20:04:50 | 000,011,776 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.0.6002.18005_cs-cz_01178c051db9f981\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2006.11.02 14:36:03 | 000,888,832 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16386_none_d24e4473b7df83f3\System.Runtime.Serialization.dll
[2008.06.20 03:17:50 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.16708_none_d2461403b7e6edc1\System.Runtime.Serialization.dll
[2008.06.20 03:12:45 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6000.20864_none_bb7eca1fd1887f4d\System.Runtime.Serialization.dll
[2008.01.05 13:21:39 | 000,929,792 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18000_none_d222c62fb8372cbf\System.Runtime.Serialization.dll
[2008.06.20 03:14:31 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.18096_none_d22b4019b82faa94\System.Runtime.Serialization.dll
[2008.06.20 03:13:19 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6001.22208_none_bb54690bd1df5a1e\System.Runtime.Serialization.dll
[2009.02.18 20:38:43 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18005_none_d1fe4b6bb888c0d3\System.Runtime.Serialization.dll
[2010.04.12 14:21:15 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.18239_none_d200f0e1b88673fe\System.Runtime.Serialization.dll
[2010.04.12 14:22:49 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.ref_b77a5c561934e089_6.0.6002.22380_none_bb39189bd2286c0e\System.Runtime.Serialization.dll
[2007.09.07 06:53:24 | 000,081,920 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16386_cs-cz_5ff98b2cc72ba40d\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:12:07 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.16730_cs-cz_5ff511dac72f8cd8\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:12:26 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6000.20895_cs-cz_492cfaeee0d2050d\System.RunTime.Serialization.Resources.dll
[2008.01.05 13:27:23 | 000,086,016 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18000_cs-cz_5fce0ce8c7834cd9\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:15:53 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.18121_cs-cz_5fcff690c7819979\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:16:19 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6001.22243_cs-cz_490422d4e1275f6f\System.RunTime.Serialization.Resources.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18005_cs-cz_5fa99224c7d4e0ed\System.RunTime.Serialization.Resources.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.18239_cs-cz_5fac379ac7d29418\System.RunTime.Serialization.Resources.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization.resources_b77a5c561934e089_6.0.6002.22380_cs-cz_48e45f54e1748c28\System.RunTime.Serialization.Resources.dll
[2006.11.02 14:36:03 | 000,888,832 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16386_none_02917a0ddf868526\System.Runtime.Serialization.dll
[2008.06.20 03:17:48 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.16708_none_0289499ddf8deef4\System.Runtime.Serialization.dll
[2008.06.20 03:12:43 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6000.20864_none_ebc1ffb9f92f8080\System.Runtime.Serialization.dll
[2008.01.05 13:21:38 | 000,929,792 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18000_none_0265fbc9dfde2df2\System.Runtime.Serialization.dll
[2008.06.20 03:14:29 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.18096_none_026e75b3dfd6abc7\System.Runtime.Serialization.dll
[2008.06.20 03:13:17 | 000,966,656 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6001.22208_none_eb979ea5f9865b51\System.Runtime.Serialization.dll
[2009.02.18 20:38:39 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18005_none_02418105e02fc206\System.Runtime.Serialization.dll
[2010.04.12 14:21:01 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.18239_none_0244267be02d7531\System.Runtime.Serialization.dll
[2010.04.12 14:22:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\msil_system.runtime.serialization_b77a5c561934e089_6.0.6002.22380_none_eb7c4e35f9cf6d41\System.Runtime.Serialization.dll
[2007.09.07 06:53:18 | 000,010,240 | ---- | M] () -- \Windows\winsxs\x86_hiddigi.inf.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_f15fa7f9f28d5343\serial.sys.mui
[2008.01.19 07:49:35 | 000,083,456 | ---- | M] () -- \Windows\winsxs\x86_hiddigi.inf_31bf3856ad364e35_6.0.6001.18000_none_955c449145dbf667\serial.sys
[2007.09.07 06:53:08 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_bdf5a8f7ae6b024a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.13 00:57:47 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16754_cs-cz_be141fbfae547065\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.13 00:56:42 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20921_cs-cz_bebb2d56c75c6d7e\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.01.05 13:27:19 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_c02c6af3ab56131e\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.16 00:24:37 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18145_cs-cz_c0062e9bab71febc\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.09.16 00:25:16 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22269_cs-cz_c07e2cb6c49c3bc4\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2009.03.31 20:04:50 | 000,011,776 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_cs-cz_c217e3ffa877de6a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2007.09.07 06:53:16 | 000,005,632 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_4c341f95e6bfb3a8\serialui.dll.mui
[2007.09.07 06:53:16 | 000,005,632 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_4e6ae191e3aac47c\serialui.dll.mui
[2006.11.02 11:46:12 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6000.16386_none_f2cadf9221bfabe5\serialui.dll
[2008.01.19 09:36:21 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6001.18000_none_f501a18e1eaabcb9\serialui.dll
[2008.01.19 09:36:21 | 000,015,360 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.0.6002.18005_none_f6ed1a9a1bcc8805\serialui.dll
[2007.09.07 06:53:24 | 000,081,920 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_5b3d50955593c887\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:12:07 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.16730_cs-cz_5b6d660d55709964\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:12:26 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6000.20895_cs-cz_5bbb24c26eba5f87\System.RunTime.Serialization.Resources.dll
[2008.01.05 13:27:23 | 000,086,016 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_cs-cz_5d741291527ed95b\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:15:53 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.18121_cs-cz_5d5f74e9528e27bb\System.RunTime.Serialization.Resources.dll
[2008.08.13 00:16:19 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6001.22243_cs-cz_5dd572706bba3215\System.RunTime.Serialization.Resources.dll
[2009.02.19 03:11:23 | 000,090,112 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_cs-cz_5f5f8b9d4fa0a4a7\System.RunTime.Serialization.Resources.dll
[2007.09.07 06:52:39 | 000,010,240 | ---- | M] () -- \Windows\winsxs\x86_msports.inf.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_c27f608a4f515351\serial.sys.mui
[2008.01.19 07:49:35 | 000,083,456 | ---- | M] () -- \Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.0.6001.18000_none_f897b0b1b85e4433\serial.sys
[2007.09.07 06:53:18 | 000,004,096 | ---- | M] () -- \Windows\winsxs\x86_smartcrd.inf.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_b4070b50f198e261\grserial.sys.mui
[2008.01.19 07:49:33 | 000,031,232 | ---- | M] () -- \Windows\winsxs\x86_smartcrd.inf_31bf3856ad364e35_6.0.6001.18000_none_72a9e15f343dcd03\grserial.sys
[2006.11.02 14:36:02 | 000,888,832 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16386_none_076c25db205d1f68\System.Runtime.Serialization.dll
[2008.06.20 03:17:48 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.16708_none_0763f56b20648936\System.Runtime.Serialization.dll
[2008.06.20 03:12:43 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6000.20864_none_f09cab873a061ac2\System.Runtime.Serialization.dll
[2008.01.05 13:21:38 | 000,929,792 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18000_none_0740a79720b4c834\System.Runtime.Serialization.dll
[2008.06.20 03:14:29 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.18096_none_0749218120ad4609\System.Runtime.Serialization.dll
[2008.06.20 03:13:17 | 000,966,656 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6001.22208_none_f0724a733a5cf593\System.Runtime.Serialization.dll
[2009.02.18 20:38:39 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18005_none_071c2cd321065c48\System.Runtime.Serialization.dll
[2010.04.12 14:21:01 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.18239_none_071ed24921040f73\System.Runtime.Serialization.dll
[2010.04.12 14:22:23 | 000,970,752 | ---- | M] () -- \Windows\winsxs\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.0.6002.22380_none_f056fa033aa60783\System.Runtime.Serialization.dll

< *w7lxe* /s >

< *AutoRearm* /s >

< HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /s >
"KBD" = C:\HP\KBD\KbdStub.EXE -- [2006.12.08 18:16:56 | 000,065,536 | ---- | M] ()
"OsdMaestro" = "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" -- [2007.02.15 13:59:00 | 000,118,784 | ---- | M] (OsdMaestro)
"RtHDVCpl" = RtHDVCpl.exe -- [2007.07.06 13:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor)
"Windows Mobile-based device management" = %windir%\WindowsMobile\wmdSync.exe -- [2006.11.02 11:45:59 | 000,215,552 | ---- | M] (Microsoft Corporation)
"MSC" = "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey -- [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
"" =
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"" =
"Installed" = 1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"" =
"Installed" = 1
"NoChange" = 1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"" =
"Installed" = 1

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008.01.19 09:33:09 | 000,125,952 | ---- | M] (Microsoft Corporation)
"Sony Ericsson PC Companion" = "C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background -- [2010.04.19 13:12:08 | 000,405,712 | ---- | M] ()
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OsdMaestro]
"ModelName" = 5189URF
"Version" = 1.00.007
"Language" = 16
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OsdMaestro\Config]
"DisplayLabel" = 0
"TaskbarIcon" = 1
"ShowLockOSD" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run /s >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.09.15 11:45:39 | 000,000,512 | ---- | M] () MD5=89AD5D9CEE1200D39413FDD5933332F5 -- C:\PhysicalMBR.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:7838B9E0

< End of report >

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Prosím o pomoc bráchu Mc_Murphyho

#6 Příspěvek od Mc_Murphy »

:!: :!: Asi to mám! Počítač se vypíná kvůli přehřívání grafické karty. 9x je zaznamenána systémová událost System shutdown due to graphics card overheating.
Musíš zkontrolovat ventilátor grafické karty, jestli není ucpaný prachem, zaseknutý či zda se neodpojil.

:arrow: Pokud to jde, odinstaluj SweetIM.
:arrow: Vyčisti holkám Plochu, brácho. Mají tam zbytečně hodně a jeden moc velký soubor (LegendsofAtlantisExodusCs_13712.exe). Plocha by měla mít maximálně tak 300 MB, plus mínus autobus, jinak se bude systém zpomalovat.

:arrow: Pak spusť znovu OTL.
  • Pokud používáš operační systém Windows Vista či Windows 7, klikni na OTL pravým myšítkem a dej Run As Administrator či Spustit jako správce.
  • Pokud používáš 64bitový OS, zkontroluj, zda-li je zaškrtnutý čtvereček Pro 64 bitové OS. Pokud ne, zaškrtni jej.
  • Do spodního okénka Vlastní skenování/opravy vlož tento script (pouze zelená písmenka v bílém poli, včetně té dvojtečky před Commands!):

Kód: Vybrat vše

:Commands
[clearallrestorepoints]
[resethosts]
[purity]
[emptytemp]
[emptyflash]

:Services
SkypeUpdate

:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTVTabletPCx86.sys -- (SMARTVTabletPCx86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTVHidMini2000x86.sys -- (SMARTVHidMini2000x86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SMARTMouseFilterx86.sys -- (SMARTMouseFilterx86)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = http://search.qip.ru/?query={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://google.icq.com/search/search_frame.php
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes,DefaultScope = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_en
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = http://search.qip.ru/?query={searchTerms}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}: "URL" = http://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\{E6A0E8A3-0BC1-4916-8338-B6BEF00D6AB2}: "URL" = http://search.seznam.cz/?q={searchTerms}&sourceid=SearchBox
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\SearchScopes\search13: "URL" = http://search13.net/search.php?q={searchTerms}
IE - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search13.net/search.php?clid=486&q="
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - user.js - File not found
[2009.09.20 18:26:38 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}
CHR - Extension: Facebook Sidebar Chat Reversion = C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfophgoebcoehkldfgeffhnlcabhhomn\1.4.10_0\
O1 - Hosts: ::1 localhost
O3 - HKU\S-1-5-21-3206674485-1805527527-224621083-1000\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O13 - gopher Prefix: missing
O33 - MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\Shell - "" = AutoRun
O33 - MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\Shell\AutoRun\command - "" = J:\Startme.exe
[2012.09.12 20:11:27 | 000,621,164 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.09.12 20:11:27 | 000,609,396 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.12 20:11:27 | 000,124,958 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.09.12 20:11:27 | 000,109,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[95 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\91ae82cb0f345a3c3f4bf16f721256f9\*.tmp files -> C:\Windows\SoftwareDistribution\Download\91ae82cb0f345a3c3f4bf16f721256f9\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\ba0888a79dfb30234773c132b1e12d7d\*.tmp files -> C:\Windows\SoftwareDistribution\Download\ba0888a79dfb30234773c132b1e12d7d\*.tmp -> ]
[3 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:7838B9E0

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\Users\Dagmar\AppData\Roaming\ICQ Toolbar
C:\Users\Dagmar\AppData\Roaming\IObit
C:\Users\Guest\AppData\Roaming\ICQ Toolbar
C:\Windows\tasks\Norton Security Scan for Dagmar.job

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1"=-
"VistaSp2"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
""=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
""=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
""=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
""=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=-
  • Klikni na tlačítko [Opravit].
  • Po dokončení skenu se objeví log, ten mi sem vlož.
  • Pokud se log nevejde do jednoho příspěvku, rozděl jej na více částí.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#7 Příspěvek od David Langr »

Takže texťáček z druhého OTL:
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Dagmar
->Temp folder emptied: 65307968 bytes
->Temporary Internet Files folder emptied: 1616659 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 66769568 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 228679 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Lucík

User: Peťka

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 169038170 bytes
RecycleBin emptied: 442089125 bytes

Total Files Cleaned = 711,00 mb


[EMPTYFLASH]

User: All Users

User: Dagmar
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Guest

User: Lucík

User: Peťka

User: Public

Total Flash Files Cleaned = 0,00 mb

========== SERVICES/DRIVERS ==========
Service SkypeUpdate stopped successfully!
Service SkypeUpdate deleted successfully!
========== OTL ==========
Service SMARTVTabletPCx86 stopped successfully!
Service SMARTVTabletPCx86 deleted successfully!
File system32\DRIVERS\SMARTVTabletPCx86.sys not found.
Service SMARTVHidMini2000x86 stopped successfully!
Service SMARTVHidMini2000x86 deleted successfully!
File system32\DRIVERS\SMARTVHidMini2000x86.sys not found.
Service SMARTMouseFilterx86 stopped successfully!
Service SMARTMouseFilterx86 deleted successfully!
File system32\DRIVERS\SMARTMouseFilterx86.sys not found.
Service NwlnkFwd stopped successfully!
Service NwlnkFwd deleted successfully!
File system32\DRIVERS\nwlnkfwd.sys not found.
Service NwlnkFlt stopped successfully!
Service NwlnkFlt deleted successfully!
File system32\DRIVERS\nwlnkflt.sys not found.
Service IpInIp stopped successfully!
Service IpInIp deleted successfully!
File system32\DRIVERS\ipinip.sys not found.
Service blbdrive stopped successfully!
Service blbdrive deleted successfully!
File C:\Windows\system32\drivers\blbdrive.sys not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Prev Search Bar| /E : value set successfully!
HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Prev Search Page| /E : value set successfully!
HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-3206674485-1805527527-224621083-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E6A0E8A3-0BC1-4916-8338-B6BEF00D6AB2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6A0E8A3-0BC1-4916-8338-B6BEF00D6AB2}\ not found.
Registry key HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
HKU\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "http://search13.net/search.php?clid=486&q=" removed from browser.search.defaulturl
Prefs.js: "http://search.icq.com/search/afe_result ... r=1.1.9&q=" removed from keyword.URL
Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.selectedEngine
Prefs.js: "http://search.icq.com/search/afe_result ... id=afex&q=" removed from sweetim.toolbar.previous.keyword.URL
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\META-INF folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\libraries folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\lib folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\defaults\preferences folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\defaults\custombuttons folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\defaults\contenthandling folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\defaults folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\components folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C}\chrome folder moved successfully.
C:\PROGRAMDATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C} folder moved successfully.
C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfophgoebcoehkldfgeffhnlcabhhomn\1.4.10_0 folder moved successfully.
::1 localhost removed from HOSTS file successfully
Registry value HKEY_USERS\S-1-5-21-3206674485-1805527527-224621083-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171aa1f4-dc8c-11e0-9117-001bb9d317ae}\ not found.
File J:\Startme.exe not found.
C:\Windows\System32\perfh005.dat moved successfully.
C:\Windows\System32\perfh009.dat moved successfully.
C:\Windows\System32\perfc005.dat moved successfully.
C:\Windows\System32\perfc009.dat moved successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC159F.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC15B3.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC161C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC17AC.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1920.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC196.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC19B3.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1AF1.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1B66.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1C28.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1E99.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC1EEB.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC25FF.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2688.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC28B9.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2A1C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2AC6.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2AF0.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2F0A.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2FE5.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC311.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC385D.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC3AE0.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC3C10.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC3C2.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC3EF.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC3F9C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4327.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4413.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4562.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4931.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4EE7.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4EF7.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC4FDF.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC5094.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC51B8.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC51F0.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC5412.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC5482.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC5D9F.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6519.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC66EC.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6736.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6D32.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6D4B.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6E6B.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7145.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC71EA.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC75DC.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7977.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7ABA.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7AD1.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7BED.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC7F20.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC8275.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9203.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC958C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC96D6.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9852.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC993D.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9A68.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9B13.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9BD2.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9E60.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC9F2A.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA06B.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA66A.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA6AB.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA6F6.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA99E.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACA9CE.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACAA99.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACAD3C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACB106.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACB308.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACB37.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACB3E4.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACB569.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACBE0C.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACC382.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACC3E0.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCA2F.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCA8B.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCB0B.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCC64.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCFE2.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACCFEC.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACDAD5.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACDC2E.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACE7AE.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACEA53.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACEB6F.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACEFE2.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACF41.tmp deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACF5D4.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\91ae82cb0f345a3c3f4bf16f721256f9\BIT6CE8.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\ba0888a79dfb30234773c132b1e12d7d\BIT6E21.tmp deleted successfully.
ADS C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT deleted successfully.
ADS C:\ProgramData\TEMP:7838B9E0 deleted successfully.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Users\Dagmar\AppData\Roaming\ICQ Toolbar folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit\Advanced SystemCare V5\Toolbox folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit\Advanced SystemCare V5\Log folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit\Advanced SystemCare V5\Boottime folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit\Advanced SystemCare V5\Backup folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit\Advanced SystemCare V5 folder moved successfully.
C:\Users\Dagmar\AppData\Roaming\IObit folder moved successfully.
C:\Users\Guest\AppData\Roaming\ICQ Toolbar folder moved successfully.
C:\Windows\tasks\Norton Security Scan for Dagmar.job moved successfully.
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\\VistaSp1 scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\\VistaSp2 scheduled to be deleted on reboot.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG deleted successfully.

OTL by OldTimer - Version 3.2.61.4 log created on 09152012_150402

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\\VistaSp1 scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\\VistaSp2 scheduled to be deleted on reboot.

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Prosím o pomoc bráchu Mc_Murphyho

#8 Příspěvek od Mc_Murphy »

Super, OTL nám provedlo, co mělo. :thumbsup:

:???: Mrknul jsi na ten ventilátor? Podle mě se buď netočí vůbec a nebo se značně zpomalil.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#9 Příspěvek od David Langr »

Jj ventík odešel do nebíčka. Už se pracuje na výměně. Tedy máme hotovo?? :)

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Prosím o pomoc bráchu Mc_Murphyho

#10 Příspěvek od Mc_Murphy »

OK, tak to vyměňte a pak uvidíš, mělo by být vše v pořádku. A my zde už jen dočistíme a máme hoťovo. :|


:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stáhni a spusť.
  • Klikni na CleanUp a potvrď YES.
  • Program uklidí a může (nemusí) restartovat PC.
:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stáhni a spusť.
  • Klikni na Start a potvrď OK.
  • Program uklidí a může (nemusí) restartovat PC.
  • Po použití utilitu smaž.
:arrow: Pokud nemáš, stáhni CCleaner z tohoto odkazu.
  • Panel čistič
  • Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
  • Panel registry
  • Klikni na Hledej problémy.
  • Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
  • Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
  • Panel nástroje
  • Zde můžeš odinstalovat nepotřebné programy.
Obrázek CCleaner doporučuji používat cca jednou za týden.

... a pokud nejsou žádné dotazy, bylo by to z mé strany vše. :happy:
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

David Langr
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 12 kvě 2012 20:37

Re: Prosím o pomoc bráchu Mc_Murphyho

#11 Příspěvek od David Langr »

:| Jupí, vše je provedeno a počítač jede. Kamarád vyhodil grafiku a pustili jsme to přes grafiku která je na základní desce. Tu druhou si vzal domů na opravu. Pak mi ji zapojí. Jinak je vše v pořádku. Mockrát díky. Děti jsem poučil tak snad bude již vše v pořádku. :idea: Večer se přihlásím ještě jednou kvůli kontrole HDD na mém PC. Takže zatím díky a ahoj :worship:

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Prosím o pomoc bráchu Mc_Murphyho

#12 Příspěvek od Mc_Murphy »

Super, jsem rád, že vše šlape jak má. ;)


Není tedy vůbec zač, brácho a rádo se stalo. :85: Přeji pěkný den Tobě i rodině. :fez:

A na závěr Ti jako vždy zahraje a zazpívá naše kapela Virocracy.
:171: :lolsign: :95: :156: :150: :151: :152: :153: :154: :196: :guitar:


:closed:
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Zamčeno