Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola (podozrive aktivity)

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
111a111
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 02 čer 2010 14:59

Kontrola (podozrive aktivity)

#1 Příspěvek od 111a111 »

Dobry den, prosim o kontrolu, pretoze mam pocit ze sa PC sprava podozrivo. Myslim tym nahodnu a zjavne bezdovodnu aktivitu HDD a CPU v case ked by nic nemalo bezat. Dakujem

Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2013-10-11 11:03:25
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 282 GB (46%) free of 610 GB
Total RAM: 4094 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:03:30, on 11. 10. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Users\Tomas\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.165\GoogleCrashHandler.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Tomas.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 119.226.108.30:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QFan Help] "C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Tomas\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A5F0786-90DF-4E73-B6A6-9D5CF723B63C}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Eltima USB Network Gate (UsbService) - ELTIMA Software - C:\Program Files\Eltima Software\USB Network Gate\UsbService64.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13846 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2208
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
atieclxx
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe"
"C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Tomas\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.165\GoogleCrashHandler.exe"
"C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.165\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe146_ Global\UsGthrCtrlFltPipeMssGthrPipe146 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1672.0.1665147981\1993162319" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,9,18,24,26 --gpu-vendor-id=0x1002 --gpu-device-id=0x6899 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.101.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.1.635867454\806836634" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.2.1248556462\1150454259" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.5.1447702209\967954541" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --instant-process --enable-threaded-compositing --disable-html-notifications --channel="1672.8.975790795\982719732" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.11.557908753\1548121277" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1672.12.2082240330\540832556" --ppapi-flash-args --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/NetworkConnectivity/disable_network_stats/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.15.1697015245\794971144" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R1/CookieRetentionPriorityStudy/ExperimentOff/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/NetworkConnectivity/disable_network_stats/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_40/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="1672.25.1001592712\1256217858" /prefetch:673131151
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Tomas\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1110802894-1155374364-1481155616-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1110802894-1155374364-1481155616-1000UA1cec4bdf12d0300.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\cx8rtuzh.default

prefs.js - "browser.startup.homepage" - "http://www.google.sk/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=1.132.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=1.140.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.7]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.dll

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-06-13 205472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL [2013-09-13 878296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2013-09-13 2328264]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01 139368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-22 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2013-09-13 705240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2013-09-13 1724616]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-22 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-07-27 341448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-03-21 6330568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2013-05-23 1106288]
"Google Update"=C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-05-23 1561968]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2012-07-27 823224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2012-07-27 36800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-01-24 477600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2013-04-25 1075296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-19 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-08-11 2472048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Officejet Pro 8600 (NET)]
C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2011-10-28 49208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage]
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2013-05-23 1106288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload]
C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-05-23 1561968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-05-23 311152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2013-08-28 1811880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Clippings]
C:\Program Files (x86)\Window Clippings 3\wc.exe [2010-11-26 668528]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-06-04 676608]
"QFan Help"=C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe [2010-03-25 611968]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Tomas\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FICV"=ficvdec_x64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2013-10-11 11:03:25 ----D---- C:\rsit
2013-10-11 11:03:25 ----D---- C:\Program Files\trend micro
2013-10-10 07:35:47 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-10-10 07:35:47 ----A---- C:\Windows\system32\ieui.dll
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-10-10 07:35:46 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 07:35:46 ----A---- C:\Windows\system32\msfeeds.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\iesysprep.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\iesetup.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\iertutil.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\iernonce.dll
2013-10-10 07:35:46 ----A---- C:\Windows\system32\ie4uinit.exe
2013-10-10 07:35:45 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-10-10 07:35:45 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-10-10 07:35:45 ----A---- C:\Windows\system32\jscript9.dll
2013-10-10 07:35:45 ----A---- C:\Windows\system32\jscript.dll
2013-10-10 07:35:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-10-10 07:35:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-10-10 07:35:44 ----A---- C:\Windows\system32\urlmon.dll
2013-10-10 07:35:44 ----A---- C:\Windows\system32\jsproxy.dll
2013-10-10 07:35:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-10-10 07:35:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-10-10 07:35:43 ----A---- C:\Windows\system32\wininet.dll
2013-10-10 07:35:42 ----A---- C:\Windows\system32\ieframe.dll
2013-10-10 07:35:41 ----A---- C:\Windows\system32\mshtml.dll
2013-10-10 07:35:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-10-09 23:20:26 ----D---- C:\Windows\system32\MpEngineStore
2013-10-09 23:18:36 ----D---- C:\be1c7df2474db6c06ab79f97dd0d62
2013-10-09 08:35:19 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2013-10-09 08:35:19 ----A---- C:\Windows\system32\comctl32.dll
2013-10-09 08:35:18 ----A---- C:\Windows\SYSWOW64\lpk.dll
2013-10-09 08:35:18 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2013-10-09 08:35:18 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2013-10-09 08:35:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-10-09 08:35:18 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-10-09 08:35:18 ----A---- C:\Windows\system32\lpk.dll
2013-10-09 08:35:18 ----A---- C:\Windows\system32\fontsub.dll
2013-10-09 08:35:18 ----A---- C:\Windows\system32\dciman32.dll
2013-10-09 08:35:18 ----A---- C:\Windows\system32\atmlib.dll
2013-10-09 08:35:18 ----A---- C:\Windows\system32\atmfd.dll
2013-10-09 08:35:17 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-10-09 08:35:15 ----A---- C:\Windows\system32\drivers\usbcir.sys
2013-10-09 08:35:12 ----A---- C:\Windows\system32\drivers\usbscan.sys
2013-10-09 08:35:12 ----A---- C:\Windows\system32\drivers\hidparse.sys
2013-10-09 08:35:12 ----A---- C:\Windows\system32\drivers\hidclass.sys
2013-10-09 08:35:08 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2013-10-09 08:35:08 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2013-10-09 08:35:08 ----A---- C:\Windows\system32\WebClnt.dll
2013-10-09 08:35:08 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2013-10-09 08:35:08 ----A---- C:\Windows\system32\davclnt.dll
2013-10-09 08:35:02 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-10-09 08:35:01 ----A---- C:\Windows\system32\mswsock.dll
2013-10-09 08:35:01 ----A---- C:\Windows\system32\drivers\afd.sys
2013-10-09 08:35:00 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2013-10-09 08:34:55 ----A---- C:\Windows\system32\win32k.sys
2013-10-09 08:34:54 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-10-09 08:34:54 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-10-09 08:34:54 ----A---- C:\Windows\system32\tdh.dll
2013-10-09 08:34:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-10-09 08:34:54 ----A---- C:\Windows\system32\advapi32.dll
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\user.exe
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\tdh.dll
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-10-09 08:34:53 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2013-10-09 08:34:53 ----A---- C:\Windows\system32\wow64.dll
2013-10-09 08:34:53 ----A---- C:\Windows\system32\ntdll.dll
2013-10-09 08:34:50 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 08:34:50 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 08:34:50 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-10-09 08:34:49 ----A---- C:\Windows\system32\scavengeui.dll
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-10-09 08:31:31 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-10-01 17:05:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-09-29 10:47:59 ----D---- C:\Users\Tomas\AppData\Roaming\Sublime Text 2
2013-09-29 10:45:01 ----D---- C:\Users\Tomas\AppData\Roaming\CodeBlocks
2013-09-28 23:42:34 ----D---- C:\Program Files\Sublime Text 2
2013-09-28 17:27:06 ----D---- C:\Program Files (x86)\CodeBlocks
2013-09-28 17:13:20 ----D---- C:\Dev-Cpp
2013-09-28 16:47:29 ----D---- C:\ProgramData\AutoUpdate
2013-09-28 16:47:13 ----D---- C:\ProgramData\Licenses
2013-09-28 16:46:37 ----A---- C:\Windows\system32\drivers\eusbstub.sys
2013-09-28 16:46:11 ----A---- C:\Windows\system32\drivers\vuhub.sys
2013-09-28 16:46:10 ----D---- C:\Program Files\Eltima Software
2013-09-28 09:43:02 ----D---- C:\Users\Tomas\AppData\Roaming\Notepad++
2013-09-28 09:43:02 ----D---- C:\Program Files (x86)\Notepad++
2013-09-27 20:44:25 ----D---- C:\MinGW

======List of files/folders modified in the last 1 month======

2013-10-11 11:03:30 ----D---- C:\Windows\Prefetch
2013-10-11 11:03:27 ----D---- C:\Windows\Temp
2013-10-11 11:03:25 ----RD---- C:\Program Files
2013-10-11 08:32:29 ----D---- C:\Windows\system32\config
2013-10-11 01:00:01 ----D---- C:\Users\Tomas\AppData\Roaming\Dropbox
2013-10-11 00:29:56 ----AD---- C:\ProgramData\TEMP
2013-10-10 15:26:36 ----D---- C:\Windows\rescache
2013-10-10 08:08:42 ----D---- C:\Windows\Microsoft.NET
2013-10-10 08:08:21 ----RSD---- C:\Windows\assembly
2013-10-10 08:07:21 ----D---- C:\Windows\System32
2013-10-10 08:07:21 ----D---- C:\Windows\inf
2013-10-10 08:07:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-10-10 08:02:09 ----D---- C:\Windows
2013-10-10 08:01:52 ----D---- C:\Windows\winsxs
2013-10-10 08:00:25 ----SHD---- C:\Config.Msi
2013-10-10 08:00:25 ----D---- C:\Program Files\Microsoft Silverlight
2013-10-10 08:00:24 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 07:58:01 ----D---- C:\Windows\SysWOW64
2013-10-10 07:58:00 ----D---- C:\Program Files (x86)\Internet Explorer
2013-10-10 07:57:58 ----D---- C:\Program Files\Internet Explorer
2013-10-10 07:57:57 ----D---- C:\Windows\system32\drivers
2013-10-10 07:57:50 ----D---- C:\Windows\AppPatch
2013-10-10 07:57:49 ----D---- C:\Windows\system32\DriverStore
2013-10-10 07:42:20 ----SHD---- C:\Windows\Installer
2013-10-10 07:41:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-10-10 07:39:03 ----D---- C:\ProgramData\Microsoft Help
2013-10-10 07:36:07 ----D---- C:\Windows\system32\catroot2
2013-10-10 07:36:07 ----D---- C:\Windows\system32\catroot
2013-10-10 07:27:53 ----SHD---- C:\System Volume Information
2013-10-10 07:20:53 ----D---- C:\Windows\system32\en-US
2013-10-09 23:18:44 ----D---- C:\Windows\system32\MRT
2013-10-09 23:18:40 ----A---- C:\Windows\system32\MRT.exe
2013-10-09 23:14:29 ----D---- C:\Users\Tomas\AppData\Roaming\uTorrent
2013-10-09 18:44:55 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-10-09 11:23:37 ----D---- C:\Program Files (x86)\The KMPlayer
2013-10-09 09:05:49 ----RD---- C:\Program Files (x86)
2013-10-09 09:05:32 ----D---- C:\Windows\system32\Tasks
2013-10-09 09:05:31 ----D---- C:\Windows\Tasks
2013-10-08 22:13:46 ----D---- C:\Users\Tomas\AppData\Roaming\Skype
2013-10-02 07:07:26 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-28 16:50:28 ----D---- C:\Program Files (x86)\Unigine
2013-09-28 16:49:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-09-28 16:49:48 ----D---- C:\Program Files\Futuremark
2013-09-28 16:49:47 ----HD---- C:\ProgramData
2013-09-28 16:49:22 ----D---- C:\Program Files (x86)\MyFree Codec
2013-09-27 22:36:18 ----A---- C:\Windows\win.ini
2013-09-27 20:47:52 ----SD---- C:\ProgramData\Microsoft
2013-09-27 20:47:52 ----D---- C:\Program Files (x86)\Microsoft
2013-09-12 06:06:55 ----D---- C:\Windows\Panther

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 NBVol;Nero Backup Volume Filter Driver; C:\Windows\system32\DRIVERS\NBVol.sys [2011-07-13 72240]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver; C:\Windows\system32\DRIVERS\NBVolUp.sys [2011-07-13 15920]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-11-29 526392]
R1 ArcSec;archlp; C:\Windows\system32\drivers\ArcSec.sys [2010-09-21 312184]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-04-22 13440]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-02-14 213416]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-01-10 150616]
R2 Dokan;Dokan; \??\C:\Windows\system32\drivers\dokan.sys [2011-01-10 120408]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-01-10 139768]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-06-05 11833856]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-06-04 608768]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-04-24 96768]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-19 271424]
R3 ELTIMA_USB_HUB_FILTER;Eltima usb hub filter; \??\C:\Program Files\Eltima Software\USB Network Gate\drv\NT6x64\fusbhub.sys [2013-09-11 86248]
R3 eustub;Usb Stub (Eltima software); C:\Windows\System32\DRIVERS\eusbstub.sys [2013-09-11 17640]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 StillCam;Still Serial Digital Camera Driver; C:\Windows\system32\drivers\serscan.sys [2009-07-14 12288]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-08-04 1342064]
R3 vuhub;Virtual Usb Hub; C:\Windows\system32\DRIVERS\vuhub.sys [2013-09-11 74984]
S3 ar12ddek;ar12ddek; C:\Windows\system32\drivers\ar12ddek.sys []
S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-05-02 103064]
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\SysWOW64\FsUsbExDisk.SYS [2013-02-05 37344]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [2013-01-17 66800]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-24 16008]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2013-05-02 127488]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2013-05-02 18944]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2013-05-02 161280]
S3 ssudcdf;SAMSUNG Mobile Mode Changer Device; C:\Windows\system32\DRIVERS\ssudcdf.sys [2012-05-11 34488]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-05-02 203672]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9; C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-06-05 241152]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-03-21 1341664]
R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [2013-02-25 9216]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-03-04 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 DokanMounter;DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [2011-01-10 14848]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-09-03 76888]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-06-21 162408]
S2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-04-23 3574624]
S2 UsbService;Eltima USB Network Gate; C:\Program Files\Eltima Software\USB Network Gate\UsbService64.exe [2013-09-11 3865832]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09 257416]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2013-02-17 137336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-01 118680]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-01-25 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-05-04 543656]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-11-19 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola (podozrive aktivity)

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit

:arrow: Predpokladam, ze ten ESET jak ma byt = zakoupena licence :???:

:arrow: Ale ty cracknute Office se mi tam vubec nelibi :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

111a111
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 02 čer 2010 14:59

Re: Kontrola (podozrive aktivity)

#3 Příspěvek od 111a111 »

eset je legalny a aktualny
:oops: no a office ... to by mohol byt zdroj problemov? Rovnaku verziu mam aj na dalsich dvoch PC a tie sa zdaju byt 100% v poriadku

info.txt logfile of random's system information tool 1.09 2013-10-11 11:03:33

======Uninstall list======

-->MsiExec /X{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}
µTorrent-->"C:\Program Files (x86)\uTorrent\uTorrent.exe" /UNINSTALL
3DMark-->"C:\Program Files (x86)\InstallShield Installation Information\{F1A6C690-C12C-4E7A-B4BD-958678215418}\setup.exe" -runfromtemp -l0x0409 -removeonly
64 Bit HP CIO Components Installer-->MsiExec.exe /I{55D55008-E5F6-47D6-B16F-B2A40D4D145F}
Action!-->"C:\Program Files (x86)\Mirillis\Action!\uninstall.exe"
Adobe Acrobat X Pro - Eastern European (Group 1)-->MsiExec.exe /I{AC76BA86-1029-4770-7760-000000000005}
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}
Adobe Download Assistant-->msiexec /qb /x {5E21B617-F52E-BB10-92F9-C8AB2C799A8A}
Adobe Download Assistant-->MsiExec.exe /I{5E21B617-F52E-BB10-92F9-C8AB2C799A8A}
Adobe Flash Player 11 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe -maintain activex
Adobe Flash Player 11 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -maintain plugin
Adobe Help Manager-->msiexec /qb /x {AF37176A-78CA-545B-34EF-8B6A21514DD1}
Adobe Help Manager-->MsiExec.exe /I{AF37176A-78CA-545B-34EF-8B6A21514DD1}
Adobe Muse-->msiexec /qb /x {C935F091-75FD-752B-B19D-6AAE0D24B05B}
Adobe Muse-->MsiExec.exe /I{C935F091-75FD-752B-B19D-6AAE0D24B05B}
Adobe Photoshop CS6-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="2.0" --mode="Uninstall" --mediaSignature="{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}"
Adobe Photoshop Elements 9-->msiexec /i {007F778D-F15C-4EAB-AE92-071D21FAF632} NOT_STANDALONE=1
Adobe Reader XI (11.0.04) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AB0000000001}
Adobe Shockwave Player 12.0-->MsiExec.exe /X{58597FDC-CDF0-4760-A57C-250DF09F4A21}
Adobe Widget Browser-->msiexec /qb /x {EFBE6DD5-B224-96E5-72B9-68D328CB12A6}
Adobe Widget Browser-->MsiExec.exe /I{EFBE6DD5-B224-96E5-72B9-68D328CB12A6}
AI Suite-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{310BC5E2-31AF-49BB-904D-E71EB93645DC}\Setup.exe" -l0x9
Allgemeine Runtime Files (x86)-->"C:\Windows\unins000.exe"
AMD Accelerated Video Transcoding-->MsiExec.exe /X{0C818871-6337-17AC-CA8C-A3942F15D92A}
AMD Accelerated Video Transcoding-->MsiExec.exe /X{41224041-0521-2020-D572-3283A56AB6EB}
AMD APP SDK Runtime-->MsiExec.exe /I{503F672D-6C84-448A-8F8F-4BC35AC83441}
AMD Catalyst Install Manager-->msiexec /q/x{4224C58B-0A19-8C66-0897-700775DB3A19} REBOOT=ReallySuppress
AMD Drag and Drop Transcoding-->MsiExec.exe /X{B69A7CBA-9139-7ACB-7564-4CD5D8C36E26}
AMD Media Foundation Decoders-->MsiExec.exe /X{54FFD5AC-7350-52B9-FB8F-1A8A6CF1FB5B}
AMD Media Foundation Decoders-->MsiExec.exe /X{BFB9CC78-4542-4C4E-44F4-C33C70F61094}
AMD Wireless Display v3.0-->MsiExec.exe /X{F65A4306-D971-407B-0A8F-D8E3F200971E}
ANNO 2070-->"C:\Program Files (x86)\InstallShield Installation Information\{B48E264C-C8CD-4617-B0BE-46E977BAD694}\setup.exe" -runfromtemp -l0x0809 -removeonly
ArcSoft TotalMedia Theatre 5-->"C:\Program Files (x86)\InstallShield Installation Information\{9A2CE5D4-0A1E-42EB-9CE0-ABD5DD79E94E}\setup.exe" -runfromtemp -l0x0409 -removeonly
ArcSoft TotalMedia Theatre 5-->C:\Program Files (x86)\InstallShield Installation Information\{9A2CE5D4-0A1E-42EB-9CE0-ABD5DD79E94E}\setup.exe
Audacity 2.0-->"C:\Program Files (x86)\Audacity\unins000.exe"
AviSynth 2.5-->"C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe"
Battlefield 3™-->"C:\Program Files (x86)\Common Files\EAInstaller\Battlefield 3\Cleanup.exe" uninstall_game -autologging
Battlelog Web Plugins-->C:\Program Files (x86)\Battlelog Web Plugins\uninstall.exe
BioShock Infinite - SK-->C:\Program Files (x86)\BioShock Infinite\Odinštalovať BioShock-Infinite-SK.exe
BioShock Infinite-->"C:\Program Files (x86)\BioShock Infinite\unins000.exe"
Borland C++Builder 6-->MsiExec.exe /I{2864C41B-EF2D-4640-95A2-526276524519}
Borland Delphi 7-->MsiExec.exe /I{72263053-50D1-4598-9502-51ED64E54C51}
Camtasia Studio 6-->MsiExec.exe /I{A589DA26-51BD-475D-8C32-E19E34145842}
Catalyst Control Center - Branding-->MsiExec.exe /I{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Core Temp 1.0 RC5-->"C:\Program Files\Core Temp\unins000.exe"
Counter-Strike: Global Offensive Beta - SDK-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/745
Counter-Strike: Global Offensive Beta-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/730
D.Signer/XAdES v1.1.0.0-->MsiExec.exe /I{2487FBE2-3A7F-4E48-98D5-57A0AD824BF7}
D.Signer/XAdES Xml plugin v1.1.0.0-->MsiExec.exe /I{08223707-D0AD-4128-99FE-A52B3B82A155}
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
DAEMON Tools Pro-->C:\Program Files (x86)\DAEMON Tools Pro\uninst.exe
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{1C936F06-0AE3-432D-9517-C01CAB43F2B3}" "1051" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Dev-C++ 5 beta 9 release (4.9.9.2)-->"C:\Dev-Cpp\uninstall.exe"
Dokan Library 0.6.0-->"C:\Program Files (x86)\Dokan\DokanLibrary\DokanUninstall.exe"
DRSR verzia 0.1-->"C:\Program Files (x86)\DRSR\unins000.exe"
Ekonomický systém Money S3-->C:\Program Files (x86)\Common Files\CIGLER SOFTWARE\Money S3\Setup\Uninst.exe
Elements 9 Organizer-->MsiExec.exe /I{433EACD8-4747-4A6A-826A-FFA9F39B0D40}
Elements STI Installer-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}"
eMotion Demo Revision 1.21-->"C:\Program Files (x86)\eMotion Demo\unins000.exe"
ESN Sonar-->C:\Program Files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
ffdshow (remove only)-->"C:\Program Files (x86)\ffdshow\uninstall.exe"
Fiddler-->"C:\Program Files (x86)\Fiddler2\uninst.exe"
FORM studio-->"C:\Program Files (x86)\KASTNER software\FORM studio SK\unins000.exe"
Fotogaléria-->MsiExec.exe /X{08466673-3905-4437-93E8-34A221B7CA4E}
Fraps (remove only)-->"C:\Program Files (x86)\Fraps\uninstall.exe"
Freemake Video Downloader-->"C:\Program Files (x86)\Freemake\Freemake Video Downloader\Uninstall\unins000.exe"
Futuremark SystemInfo-->"C:\Program Files (x86)\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe" -runfromtemp -l0x0409 -removeonly
Geeks3D.com FurMark 1.10.6-->"C:\Program Files (x86)\Geeks3D\Benchmarks\FurMark_1.10.6\unins000.exe"
Google Earth-->MsiExec.exe /X{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HD Tune Pro 5.50-->"C:\Program Files (x86)\HD Tune Pro\unins000.exe"
HP Officejet Pro 8600 Basic Device Software-->MsiExec.exe /I{791A06E2-340F-43B0-8FAB-62D151339362}
HP Officejet Pro 8600 Help-->MsiExec.exe /I{46235FF7-2CBE-4A84-BEDA-87348D1F7850}
HP Officejet Pro 8600 Product Improvement Study-->MsiExec.exe /I{2BF5E9CC-C55D-4B0F-ACAF-FFE77F333CD8}
HP Update-->MsiExec.exe /X{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}
Cheat Engine 6.1-->"C:\Program Files (x86)\Cheat Engine 6.1\unins000.exe"
I.R.I.S. OCR-->MsiExec.exe /I{CA6BCA2F-EDEB-408F-850B-31404BE16A61}
IrfanView (remove only)-->C:\Program Files (x86)\IrfanView\iv_uninstall.exe
Java 7 Update 25-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217025FF}
JDownloader 0.9-->C:\Program Files (x86)\JDownloader\JDUninstall.exe
LightScribe System Software-->MsiExec.exe /X{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}
MediaInfo 0.7.64-->C:\Program Files\MediaInfo\uninst.exe
Microsoft .NET Framework 1.1 Security Update (KB2698023)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2698023\M2698023Uninstall.msp"
Microsoft .NET Framework 1.1 Security Update (KB2742597)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2742597\M2742597Uninstall.msp"
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 4.5-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5-->MsiExec.exe /X{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}
Microsoft Access MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0015-041B-1000-0000000FF1CE}
Microsoft DCF MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0090-041B-1000-0000000FF1CE}
Microsoft Excel MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0016-041B-1000-0000000FF1CE}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{F2508213-9989-4E85-A078-72BE483917EF}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{4CB0307C-565E-4441-86BE-0DF2E4FB828C}
Microsoft Groove MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00BA-041B-1000-0000000FF1CE}
Microsoft InfoPath MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0044-041B-1000-0000000FF1CE}
Microsoft Lync MUI (Slovak) 2013-->MsiExec.exe /X{90150000-012B-041B-1000-0000000FF1CE}
Microsoft Mathematics (64-bit)-->MsiExec.exe /X{E57B7E0A-8BE5-42E2-BE60-C07ED680A063}
Microsoft Office 2013 Professional Plus-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office 32-bit Components 2013-->MsiExec.exe /X{90150000-00C1-0000-1000-0000000FF1CE}
Microsoft Office Korrekturhilfen 2013 - Deutsch-->MsiExec.exe /X{90150000-001F-0407-1000-0000000FF1CE}
Microsoft Office Nyelvi ellenőrző eszközök 2013 – magyar-->MsiExec.exe /X{90150000-001F-040E-1000-0000000FF1CE}
Microsoft Office OSM MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E1-041B-1000-0000000FF1CE}
Microsoft Office OSM UX MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E2-041B-1000-0000000FF1CE}
Microsoft Office Professional Plus 2013-->MsiExec.exe /X{90150000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2013-->MsiExec.exe /X{90150000-002C-041B-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - English-->MsiExec.exe /X{90150000-001F-0409-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00C1-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2013-->MsiExec.exe /X{90150000-006E-041B-1000-0000000FF1CE}
Microsoft OneNote MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00A1-041B-1000-0000000FF1CE}
Microsoft Outlook MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001A-041B-1000-0000000FF1CE}
Microsoft PowerPoint MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0018-041B-1000-0000000FF1CE}
Microsoft Publisher MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0019-041B-1000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{cbf90bef-21fb-400b-935a-5900785071dd}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022-->MsiExec.exe /X{350AA351-21FA-3270-8B7A-835434E766AD}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523-->MsiExec.exe /X{7CBA9009-7EA4-338B-893D-9607CD829ADF}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727-->"C:\ProgramData\Package Cache\{15134cb0-b767-4960-a911-f2d16ae54797}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610-->"C:\ProgramData\Package Cache\{307a22b8-8353-4c5e-b67b-2404c5734558}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610-->MsiExec.exe /X{3D6AD258-61EA-35F5-812C-B7A02152996E}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610-->MsiExec.exe /X{E7D4E834-93EB-351F-B8FB-82CDAE623003}
Microsoft Visual J# 2.0 Redistributable Package - SE (x64)-->C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)\install.exe
Microsoft Word MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001B-041B-1000-0000000FF1CE}
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Microsoft_VC90_MFCLOC_x86_x64-->MsiExec.exe /I{90BF0360-A1DB-4599-A643-95AB90A52C1E}
Microsoft_VC90_MFCLOC_x86-->MsiExec.exe /I{B6D38690-755E-4F40-A35A-23F8BC2B86AC}
Minecraft-->MsiExec.exe /X{2A334BC8-1953-428F-BE52-D789EFD11783}
Mirror's Edge-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/17410
MKVToolNix 5.8.0-->C:\Program Files (x86)\MKVtoolnix\uninst.exe
Movie Maker-->MsiExec.exe /X{45898170-E68C-4F02-AA35-C2186BF347A3}
Movie Maker-->MsiExec.exe /X{CFBFE244-6269-41DC-85B6-86F99C88ED02}
Mozilla Firefox 24.0 (x86 sk)-->"C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"
Mozilla Maintenance Service-->"C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSVCRT110_amd64-->MsiExec.exe /I{E9FA781F-3E80-4399-825A-AD3E11C28C77}
MSVCRT110-->MsiExec.exe /I{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Mumble 1.2.3-->MsiExec.exe /I{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština-->MsiExec.exe /X{90150000-001F-0405-1000-0000000FF1CE}
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina-->MsiExec.exe /X{90150000-001F-041B-1000-0000000FF1CE}
NAVIGON Fresh 3.4.1-->C:\Program Files (x86)\NAVIGON\NAVIGON Fresh\uninst.exe
Nero 12-->MsiExec.exe /I{560FC78C-A4B2-461D-9B47-820C1EEF87B8}
Nero Audio Pack 1-->MsiExec.exe /X{A7A0BF2E-31CC-49E3-9913-52C503EB969D}
Nero BackItUp Help (CHM)-->MsiExec.exe /X{EF0D1292-8FC1-41BE-9740-DBC134F66415}
Nero BackItUp-->MsiExec.exe /X{0071820F-09B0-4998-8320-F89629DCBC99}
Nero Backup Drivers-->MsiExec.exe /X{D600D357-5CB9-4DE9-8FD4-14E208BD1970}
Nero Blu-ray Player Help (CHM)-->MsiExec.exe /X{5B79E730-D897-4B8F-A1AD-7BB2D1F22B96}
Nero Blu-ray Player-->MsiExec.exe /X{A2FE691E-3F8E-4E30-AA7D-FF17AC77EA87}
Nero Burning ROM Help (CHM)-->MsiExec.exe /X{2890E324-6F3B-4975-8B95-E7D6D80E0226}
Nero Burning ROM-->MsiExec.exe /X{5963F4B4-D138-47CD-ADEF-470E87E185BD}
Nero ControlCenter-->MsiExec.exe /X{ABC88553-8770-4B97-B43E-5A90647A5B63}
Nero Core Components-->MsiExec.exe /X{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
Nero Disc Menus Basic-->MsiExec.exe /X{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}
Nero Effects Basic-->MsiExec.exe /X{29F67D84-3A70-456E-806A-52301B02070B}
Nero Express Help (CHM)-->MsiExec.exe /X{0708FF30-78C0-47B0-81F0-C84604DC769C}
Nero Express-->MsiExec.exe /X{848A7C68-0ADC-4193-8A89-2CEA78E56A0C}
Nero Kwik Themes Basic-->MsiExec.exe /X{1B6F5E51-575E-4693-BCA2-7543570D076D}
Nero PiP Effects Basic-->MsiExec.exe /X{ACE49D50-19CD-44A6-B192-46F985283B26}
Nero Recode Help (CHM)-->MsiExec.exe /X{86847081-B387-4F49-AED1-C9B0A090D66C}
Nero Recode-->MsiExec.exe /X{1943C3BD-4462-4612-92C3-D36DD917C447}
Nero RescueAgent Help (CHM)-->MsiExec.exe /X{0B311221-05A5-4766-8D03-7A6446794156}
Nero RescueAgent-->MsiExec.exe /X{B953732D-B623-4E84-B369-CFFF7B1AE06F}
Nero SharedVideoCodecs-->MsiExec.exe /X{2432E589-6256-4513-B0BF-EFA8E325D5F0}
Nero Video Help (CHM)-->MsiExec.exe /X{B128179D-A5E1-43AC-9422-12A109ECD2A0}
Nero Video-->MsiExec.exe /X{83FCCFCD-46E3-43FB-A397-78BFD5A8980A}
Notepad++-->C:\Program Files (x86)\Notepad++\uninstall.exe
NVIDIA PhysX-->MsiExec.exe /I{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}
Origin-->C:\Program Files (x86)\Origin\OriginUninstall.exe
Pandora Service-->"C:\Program Files (x86)\PANDORA.TV\PanService\unins000.exe"
PDF Settings CS6-->MsiExec.exe /I{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}
Photo Common-->MsiExec.exe /X{140754E1-C019-44A9-A81B-2D7625AABE8A}
Photo Gallery-->MsiExec.exe /X{0F929651-F516-4956-90F2-FFBD2CD5D30E}
PhotoScape-->"C:\Program Files (x86)\PhotoScape\uninstall.exe"
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
rajče průvodce verze 1.59.48.263-->"C:\Program Files (x86)\rajce\unins000.exe"
Realtek 8136 8168 8169 Ethernet Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.exe -runfromtemp -removeonly
Recuva-->"C:\Program Files\Recuva\uninst.exe"
Rusyn Phonetic - Custom-->MsiExec.exe /I{4C3615B9-FFE1-43A0-995C-DD5EDA7C75F1}
Samsung Kies-->"C:\Program Files (x86)\InstallShield Installation Information\{758C8301-2696-4855-AF45-534B1200980A}\setup.exe" -runfromtemp -l0x0409 -removeonly
Samsung Kies-->MsiExec.exe /I{758C8301-2696-4855-AF45-534B1200980A}
SAMSUNG USB Driver for Mobile Phones-->C:\Program Files (x86)\Samsung\USB Drivers\Uninstall.exe
Security Update for Microsoft .NET Framework 4.5 (KB2737083)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {00909A54-CC11-3F00-9279-3CE090432A91}
Security Update for Microsoft .NET Framework 4.5 (KB2742613)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {36E5C79E-06D3-32C3-9251-D284B9F3F7E7}
Security Update for Microsoft .NET Framework 4.5 (KB2789648)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {698F9EB6-6753-318E-8615-53D77414313F}
Security Update for Microsoft .NET Framework 4.5 (KB2804582)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {CEB05EDA-D069-31BF-9789-81637633C0BF}
Security Update for Microsoft .NET Framework 4.5 (KB2833957)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {9BBF7EC5-5F9A-3D5E-85E5-3EE53A16166E}
Security Update for Microsoft .NET Framework 4.5 (KB2840642)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {DDCAB505-6883-380B-97BD-59381822883B}
Security Update for Microsoft .NET Framework 4.5 (KB2840642v2)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {4F658047-A12E-38D9-8EA9-D941E4A84B7D}
Security Update for Microsoft .NET Framework 4.5 (KB2861208)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {6AF12FE8-C359-3748-BDF6-B437C0A42154}
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{41DF329D-1966-484D-8856-53E9491D998D}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2810009) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D6F7BF27-F97C-4D16-9121-7C19A112EA5A}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2817623) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{DF31D4A8-9A1A-4599-A77F-5F16ED9D561B}" "1051" "0"
Skype™ 6.6-->MsiExec.exe /X{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
Sound Forge Pro 10.0-->MsiExec.exe /X{B8A817D7-AE0F-42BA-AEB9-B5F1F3EFB7AF}
Source SDK-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/211
Speccy-->"C:\Program Files\Speccy\uninst.exe"
SpeedFan (remove only)-->"C:\Program Files (x86)\SpeedFan\uninstall.exe"
Splash PRO EX-->"C:\Program Files (x86)\Mirillis\Splash PRO EX\uninstall.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Sublime Text 2.0.2-->"C:\Program Files\Sublime Text 2\unins000.exe"
Subtitle Workshop 2.51-->"C:\Program Files (x86)\URUSoft\Subtitle Workshop\uninstall.exe"
swMSM-->MsiExec.exe /I{612C34C7-5E90-47D8-9B5C-0F717DD82726}
Team Fortress 2-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/440
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
TeamViewer 8-->C:\Program Files (x86)\TeamViewer\Version8\uninstall.exe
The KMPlayer-->C:\Program Files (x86)\The KMPlayer\uninstall.exe
The Sims™ 3-->"C:\Program Files (x86)\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\Sims3Setup.exe" -runfromtemp -l0x0005 -removeonly
Total Commander (Remove or Repair)-->C:\Program Files (x86)\totalcmd\tcuninst.exe
Ubisoft Game Launcher-->"C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
Universal SQL Editor 1.4.5.1-->MsiExec.exe /I{CCE0D148-D6FD-4F2A-A631-748DC7727613}
Update for Microsoft .NET Framework 4.5 (KB2750147)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {BEBBFEB1-EA1C-3479-A39D-23A76BCB7BFC}
Update for Microsoft .NET Framework 4.5 (KB2805221)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {83FD3E08-19A9-3E5F-85EF-C4786CB743B5}
Update for Microsoft .NET Framework 4.5 (KB2805226)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {87B3F837-4DE6-35DE-B11D-D21554DD8412}
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{DC80E018-C612-4FA4-A7E4-11B4C6F5FE22}" "1051" "0"
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-041B-1000-0000000FF1CE}" "{279D6F0F-7988-4CD8-8E93-BA9E61C58672}" "1051" "0"
Update for Microsoft InfoPath 2013 (KB2752078) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D423F677-7EC9-45EC-A746-10398109B562}" "1051" "0"
Update for Microsoft Lync 2013 (KB2817621) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2F2717FB-5567-491F-B493-B6556DB4FFCB}" "1051" "0"
Update for Microsoft Lync 2013 (KB2817621) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{2F2717FB-5567-491F-B493-B6556DB4FFCB}" "1051" "0"
Update for Microsoft Lync 2013 (KB2817621) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{37796A7F-E101-4DF7-B2C9-BCC68BDE2094}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{FEFF9FF6-FF61-455E-A8CC-3A1311A657AD}" "1051" "0"
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{3FF4EA9F-3505-4726-A974-6593A968FFCC}" "1051" "0"
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9406D70B-2D9C-4613-A75A-F35B66BA8AFA}" "1051" "0"
Update for Microsoft Office 2013 (KB2760257) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8BE4747D-008B-4D77-BC7B-D82307A4E12D}" "1051" "0"
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA390537-AA88-450F-A240-5FB4648A124A}" "1051" "0"
Update for Microsoft Office 2013 (KB2760539) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C8D57F4A-0824-4043-89E7-3C6280B67A47}" "1051" "0"
Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AC4470FB-8011-4F16-B5D4-E0A34DE10C87}" "1051" "0"
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D8B3D175-48B8-413F-8484-4D81E744B51C}" "1051" "0"
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8587E5B1-6279-4396-B9AC-20B334F4FF88}" "1051" "0"
Update for Microsoft Office 2013 (KB2817309) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{4C916298-659D-4566-BCCC-A229031D1430}" "1051" "0"
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0405-1000-0000000FF1CE}" "{6CC060C8-E9B8-4BD7-854D-C185AAF3A1AA}" "1051" "0"
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0407-1000-0000000FF1CE}" "{7F1700C7-8D48-4DF5-840D-916F80FF3FB7}" "1051" "0"
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{42811B49-8137-4B2E-ADB4-A6D865E8B3F9}" "1051" "0"
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040E-1000-0000000FF1CE}" "{87F1C60C-C7B3-4D29-9E84-3330A874A814}" "1051" "0"
Update for Microsoft Office 2013 (KB2817311) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-041B-1000-0000000FF1CE}" "{4018A8A2-D4D1-4D3A-B112-1D6C1D679708}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817493) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9DC0AE49-CE9F-4472-AB12-C3A6A666F2D1}" "1051" "0"
Update for Microsoft Office 2013 (KB2817493) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{9DC0AE49-CE9F-4472-AB12-C3A6A666F2D1}" "1051" "0"
Update for Microsoft Office 2013 (KB2817624) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2F791A9F-ADB1-45BA-99D0-786B0952CC38}" "1051" "0"
Update for Microsoft Office 2013 (KB2817624) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{2F791A9F-ADB1-45BA-99D0-786B0952CC38}" "1051" "0"
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F33ABF6A-3007-47E8-8E38-506A18E54641}" "1051" "0"
Update for Microsoft Office 2013 (KB2817630) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{ED8E67AA-8F16-4243-B74C-8DAFD466820D}" "1051" "0"
Update for Microsoft Office 2013 (KB2817630) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{11B5CF8E-BEFF-4F2C-88D3-3ED163ED7A81}" "1051" "0"
Update for Microsoft Office 2013 (KB2817630) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{ED8E67AA-8F16-4243-B74C-8DAFD466820D}" "1051" "0"
Update for Microsoft Office 2013 (KB2817640) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{0BC0B6A7-8881-42E7-8B3C-334C9742B991}" "1051" "0"
Update for Microsoft Office 2013 (KB2817640) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{59C0705D-6C07-4E07-8F8A-6614B0A46968}" "1051" "0"
Update for Microsoft Office 2013 (KB2817640) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{0BC0B6A7-8881-42E7-8B3C-334C9742B991}" "1051" "0"
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2A286156-257B-4528-9DB5-B4D4D53211BC}" "1051" "0"
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F2187E8D-C68A-4655-8551-1932878A5581}" "1051" "0"
Update for Microsoft Office 2013 (KB2827235) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C8A362E9-9E2B-4996-A971-0473937D124E}" "1051" "0"
Update for Microsoft Office 2013 (KB2827235) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C8A362E9-9E2B-4996-A971-0473937D124E}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2810016) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8D26EB4C-B227-48FD-BCF3-240DA47F50EB}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2810016) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-041B-1000-0000000FF1CE}" "{041A92D0-C7F0-4450-AB45-6CB8B060AA0D}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2810016) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{8D26EB4C-B227-48FD-BCF3-240DA47F50EB}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2825632) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{30E750A1-C143-4034-9D53-2964665D6D9D}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2825632) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{9DBE6614-8B1D-4CDC-8BFC-90FE46156C28}" "1051" "0"
Update for Microsoft PowerPoint 2013 (KB2817625) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{825D4557-B242-4DF1-B532-FD39B20A2F40}" "1051" "0"
Update for Microsoft Project 2013 (KB2767859) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{EC17FB25-F671-4D66-9BB7-F3E1B43A50BA}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2752097) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C9E10200-F625-4655-A4CF-6BD5068E6AA4}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2752097) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-041B-1000-0000000FF1CE}" "{4546C0C9-BE94-406A-8D2A-09840DDDAE29}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2825633) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{85256C1A-DC6D-4910-8610-B524A6D2B03E}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2825633) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-041B-1000-0000000FF1CE}" "{19895D1F-D6C6-44E0-B6E5-CFC0F2363650}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2825633) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{85256C1A-DC6D-4910-8610-B524A6D2B03E}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2825633) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-041B-1000-0000000FF1CE}" "{19895D1F-D6C6-44E0-B6E5-CFC0F2363650}" "1051" "0"
Update for Microsoft Visio 2013 (KB2752018) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{619D1EFE-228F-4B12-86DC-4AA9FEDC19C0}" "1051" "0"
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D1F1940B-94DF-4DCB-BF82-9530D7FBB1BF}" "1051" "0"
Update for Microsoft Word 2013 (KB2817631) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A56F7FEB-090D-4AA2-8CCE-90FBEFB00FEF}" "1051" "0"
Update for Microsoft Word 2013 (KB2817631) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{767EA391-91F5-46ED-ABF8-2D712485A28C}" "1051" "0"
Update for Microsoft Word 2013 (KB2817631) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{767EA391-91F5-46ED-ABF8-2D712485A28C}" "1051" "0"
Update for Microsoft Word 2013 (KB2817631) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{767EA391-91F5-46ED-ABF8-2D712485A28C}" "1051" "0"
Update for Microsoft Word 2013 (KB2827218) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{51277A5C-0099-4971-B647-094470DF1D5B}" "1051" "0"
Uplay-->C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
USB Network Gate 6.0 (Build 6.0.413)-->"C:\Program Files\Eltima Software\USB Network Gate\unins000.exe"
VIA Platform Device Manager-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VSO ConvertXToDVD-->"C:\Program Files (x86)\VSO\ConvertX\5\unins000.exe"
Welcome App (Start-up experience)-->MsiExec.exe /X{828175FA-7307-4DBF-95AD-9CEE086B6F45}
Window Clippings-->MsiExec.exe /X{8CA7F8A3-2B3C-471D-8D03-7AB4437F8C80}
Windows Live Communications Platform-->MsiExec.exe /I{03D562B5-C4E2-4846-A920-33178788BE00}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FA29B84F-8306-4A62-A340-F2C41305E7AF}
Windows Live ID Sign-in Assistant-->MsiExec.exe /I{CE52672C-A0E9-4450-8875-88A221D5CD50}
Windows Live Installer-->MsiExec.exe /I{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}
Windows Live Photo Common-->MsiExec.exe /X{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}
Windows Live PIMT Platform-->MsiExec.exe /I{E3445598-4424-4EE2-B71C-C23325F7FB71}
Windows Live SOXE Definitions-->MsiExec.exe /I{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}
Windows Live SOXE-->MsiExec.exe /I{6B6923B9-8719-425B-916C-CD2908F31AAF}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{28950295-A98C-4081-AC82-045E9879945E}
Windows Live UX Platform-->MsiExec.exe /I{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}
WinPcap 4.1.2-->"C:\Program Files\WinPcap\uninstall.exe"
WinRAR 4.01 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
xrecode II 1.0.0.183-->"C:\Program Files (x86)\xrecode II\unins000.exe"

======Hosts File======

127.0.0.1 activate.adobe.com
127.0.0.1 www.nero.com
127.0.0.1 www.nero.com/rus/index.html
127.0.0.1 www.nero.com/rus/support.html
127.0.0.1 http://www.nero.com/rus/support-custome ... ation.html
127.0.0.1 www.nero.com/rus/store-upgrade-center.html
127.0.0.1 www.nero.com/rus/store-volume-licensing.html

127.0.0.1 http://www.nero.com/eng/support.html?Ne ... 25e97a3b80


======System event log======

Computer Name: PC
Event Code: 1014
Message: Name resolution for the name inferno.demonoid.me timed out after none of the configured DNS servers responded.
Record Number: 202834
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20130530060303.725050-000
Event Type: Warning
User: PC\Tomas

Computer Name: PC
Event Code: 219
Message: The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_HP&PROD_&REV_1.00#8&10ADFC6B&0&MY889G12NW0559&0#.
Record Number: 202826
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20130530060220.852598-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: PC
Event Code: 219
Message: The driver \Driver\WUDFRd failed to load for the device USB\VID_04E8&PID_6860&MS_COMP_MTP&GT-P5110\7&395968e9&0&0000.
Record Number: 202664
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20130529175637.846453-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: PC
Event Code: 36
Message: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
Record Number: 202650
Source Name: volsnap
Time Written: 20130529171732.972334-000
Event Type: Error
User:

Computer Name: PC
Event Code: 1014
Message: Name resolution for the name inferno.demonoid.me timed out after none of the configured DNS servers responded.
Record Number: 202555
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20130529095212.271998-000
Event Type: Warning
User: PC\Tomas

=====Application event log=====

Computer Name: PC
Event Code: 1000
Message: Názov chybovej aplikácie: PanProcess.exe, verzia: 1.0.1.2, časová značka: 0x506004cc
Názov chybového modulu: libupnp.dll, verzia: 0.0.0.0, časová značka: 0x4f69a2b4
Kód výnimky: 0xc0000005
Odstup chyby: 0x000081dc
Identifikácia chybného procesu: 0x130c
Čas spustenia chybnej aplikácie: 0x01ce092272acf06c
Cesta chybnej aplikácie: C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe
Cesta chybného modulu: C:\Program Files (x86)\PANDORA.TV\PanService\libupnp.dll
Identifikácia hlásenia: 066e2030-751e-11e2-b550-90e6ba3427aa
Record Number: 55830
Source Name: Application Error
Time Written: 20130212141100.000000-000
Event Type: Error
User:

Computer Name: PC
Event Code: 1000
Message: Názov chybovej aplikácie: WerFault.exe, verzia: 6.1.7600.16385, časová značka: 0x4a5bc2d9
Názov chybového modulu: unknown, verzia: 0.0.0.0, časová značka: 0x00000000
Kód výnimky: 0xc0000005
Odstup chyby: 0x54b6e5ba
Identifikácia chybného procesu: 0x16fc
Čas spustenia chybnej aplikácie: 0x01ce092961abcb05
Cesta chybnej aplikácie: C:\Windows\SysWOW64\WerFault.exe
Cesta chybného modulu: unknown
Identifikácia hlásenia: a1be991c-751c-11e2-b550-90e6ba3427aa
Record Number: 55827
Source Name: Application Error
Time Written: 20130212140101.000000-000
Event Type: Error
User:

Computer Name: PC
Event Code: 1000
Message: Názov chybovej aplikácie: bf3.exe, verzia: 1.5.0.0, časová značka: 0x50c39964
Názov chybového modulu: unknown, verzia: 0.0.0.0, časová značka: 0x00000000
Kód výnimky: 0xc0000005
Odstup chyby: 0x54c6d719
Identifikácia chybného procesu: 0x404
Čas spustenia chybnej aplikácie: 0x01ce0928d9218dc5
Cesta chybnej aplikácie: C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
Cesta chybného modulu: unknown
Identifikácia hlásenia: 9fb7ec14-751c-11e2-b550-90e6ba3427aa
Record Number: 55826
Source Name: Application Error
Time Written: 20130212140058.000000-000
Event Type: Error
User:

Computer Name: PC
Event Code: 1024
Message: Produkt: Adobe Reader X (10.1.5) - Czech – Aktualizáciu Adobe Reader X (10.1.5) sa nepodarilo nainštalovať. Kód chyby je 1603. Inštalátor systému Windows umožňuje vytvárať denníky, ktoré vám môžu pomôcť pri odstraňovaní problémov s inštaláciou softvérových balíkov. Pokyny na zapnutie podpory zapisovania do denníka zobrazíte po kliknutí na nasledovné prepojenie: http://go.microsoft.com/fwlink/?LinkId=23127
Record Number: 55759
Source Name: MsiInstaller
Time Written: 20130212061201.000000-000
Event Type: Error
User: PC\Tomas

Computer Name: PC
Event Code: 11328
Message: Produkt: Adobe Reader X (10.1.5) - Czech -- Chyba 1328.Chyba při aplikování opravy na soubor C:\Config.Msi\PT4CAB.tmp. Asi byl aktualizován jinými prostředky a nelze ho již upravovat touto opravou. Více informací získáte od dodavatele opravy. System Error: -1072807676
Record Number: 55757
Source Name: MsiInstaller
Time Written: 20130212061156.000000-000
Event Type: Error
User: PC\Tomas

=====Security event log=====

Computer Name: PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x220
Process Name: C:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 62169
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121231213252.617642-000
Event Type: Audit Success
User:

Computer Name: PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 62168
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121231213252.617642-000
Event Type: Audit Success
User:

Computer Name: PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x220
Process Name: C:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 62167
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121231213252.617642-000
Event Type: Audit Success
User:

Computer Name: PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5

Privileges: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 62166
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121231213252.134041-000
Event Type: Audit Success
User:

Computer Name: PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x220
Process Name: C:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 62165
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121231213252.134041-000
Event Type: Audit Success
User:

======Environment variables======

"AMDAPPSDKROOT"=C:\Program Files (x86)\AMD APP\
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"NUMBER_OF_PROCESSORS"=4
"OS"=Windows_NT
"Path"=C:\mingw\bin;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\PROGRA~2\Borland\CBUILD~1\Bin;C:\PROGRA~2\Borland\CBUILD~1\Projects\Bpl;C:\Program Files (x86)\Borland\Delphi7\Bin;C:\Program Files (x86)\Borland\Delphi7\Projects\Bpl\;C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\MKVtoolnix;C:\Program Files (x86)\Windows Live\Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
"PROCESSOR_LEVEL"=6
"PROCESSOR_REVISION"=1e05
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola (podozrive aktivity)

#4 Příspěvek od vyosek »

:arrow: Nerikam ze je to (zrejme) zdroj problemu, ale nasem forum se distancuje od nelegalniho SW a softwareoveho piratstvi

:arrow: Pokud chcete pokracovat, tak odinstalujte nelegalni Office a pouzijte nejakou free nahradu (OpenOffice, Libre Office atd..)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět