Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

WannaCry

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

WannaCry

#1 Příspěvek od Boriss »

Zdravím môžete mi poradiť čo mám robiť s týmto? Viem že je to celosvetové ale neviem čo mám s tým robiť.

http://prntscr.com/f9qhga
http://prntscr.com/f9qhpr
http://prntscr.com/f9qhu2

Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

Re: WannaCry

#2 Příspěvek od Boriss »

FRST3

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2017
Ran by User (administrator) on USER-PC (19-05-2017 18:00:35)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User & UpdatusUser)
Platform: Windows 7 Ultimate (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\User\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-03] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\MountPoints2: J - Call of Duty - Black Ops.part01.exe
HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\MountPoints2: K - K:\autorun.exe
HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\MountPoints2: {5425159c-deed-11e5-bc2f-00215a7343c5} - L:\Setup.exe
HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\MountPoints2: {e23c58ab-af9d-11e5-ac66-00215a7343c5} - K:\setup.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{62553CF7-C999-48C3-9081-6B4D819B8CAA}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-03] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2017-04-08] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-03] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2017-04-08] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 8b1g0pcy.default
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default [2017-05-19]
FF Homepage: Mozilla\Firefox\Profiles\8b1g0pcy.default -> about:home
FF Extension: (Bing Search) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\bingsearch.full@microsoft.com.xpi [2017-01-03]
FF Extension: (Домашняя страница Mail.Ru) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\homepage@mail.ru [2016-11-30]
FF Extension: (Поиск@Mail.Ru) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\search@mail.ru [2016-11-30]
FF Extension: (Визуальные закладки @Mail.Ru) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} [2016-11-30]
FF Extension: (Adblock Plus) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (Seznam lištička) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\8b1g0pcy.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-05-09]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-03]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-09] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.79.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2017-04-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.79.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2017-04-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-03-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-03-14] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-1906443015-4026824225-2091223967-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1906443015-4026824225-2091223967-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-12-15] ()

Chrome:
=======
CHR HomePage: Default -> msn.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR NewTab: Default -> Active:"chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC ... earchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxp://www.bing.com/osjson.aspx?FORM=__PARAM__ ... earchTerms}
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2017-05-19]
CHR Extension: (Prezentácie Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-29]
CHR Extension: (Dokumenty Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-29]
CHR Extension: (Disk Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-29]
CHR Extension: (Seznam Lištička - Email) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-03-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2017-03-21]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-29]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-29]
CHR Extension: (Avast SafePrice) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-17]
CHR Extension: (Bing) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2017-01-10]
CHR Extension: (Tabuľky Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-29]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-09]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-07]
CHR Extension: (Skype) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-17]
CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme [2016-12-04]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2017-03-17]
CHR Extension: (Mail.Ru) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\phkdcinmmljblpnkohlipaiodlonpinf [2016-12-04]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-29]
CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-09]
CHR Extension: (Пульс) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmpoaahleccaibbhfjfimigepmfmmbbk [2017-04-07]
CHR HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [odijcgafkhpobjlnfdgiacpdenpmbgme] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [phkdcinmmljblpnkohlipaiodlonpinf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pmpoaahleccaibbhfjfimigepmfmmbbk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-03] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-03] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1494024 2017-03-11] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2016-07-14] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-03] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-03] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334600 2017-03-03] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-03] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32088 2017-03-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [126600 2017-03-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [100640 2017-03-03] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-03] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [993608 2017-03-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [548928 2017-03-21] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162528 2017-03-03] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [337592 2017-03-14] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-29] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-29] (Disc Soft Ltd)
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-19 18:00 - 2017-05-19 18:01 - 00017137 _____ C:\Users\User\Desktop\FRST.txt
2017-05-19 17:59 - 2017-05-19 18:00 - 00000000 ____D C:\FRST
2017-05-19 17:59 - 2017-05-19 17:59 - 02429952 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2017-05-19 17:56 - 2017-05-19 17:56 - 00112640 _____ (forum.viry.cz) C:\Users\User\Desktop\FRSTLauncher.exe
2017-05-19 17:56 - 2017-05-19 17:56 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-05-07 17:29 - 2017-05-07 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2017-04-30 13:44 - 2017-04-30 13:44 - 00000859 _____ C:\Users\Public\Desktop\Metro Last Light.lnk
2017-04-28 16:00 - 2017-04-28 16:00 - 00000000 ____D C:\Users\User\AppData\LocalLow\uTorrent
2017-04-28 13:29 - 2017-04-28 13:29 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2017-04-28 13:29 - 2017-04-28 13:29 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2017-04-24 19:35 - 2017-04-30 14:01 - 00000000 ____D C:\Users\User\Documents\4A Games

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-19 17:59 - 2016-11-18 18:49 - 00000000 ____D C:\Users\User\AppData\LocalLow\Mozilla
2017-05-19 17:28 - 2016-01-07 19:49 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-19 17:05 - 2015-12-29 22:35 - 00000386 _____ C:\Windows\Tasks\update-S-1-5-21-1906443015-4026824225-2091223967-1001.job
2017-05-19 16:23 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-19 16:23 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-19 16:16 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-19 16:15 - 2015-12-19 16:34 - 00000000 ____D C:\ProgramData\NVIDIA
2017-05-19 13:56 - 2017-04-08 11:58 - 00000000 ____D C:\Users\User\AppData\Roaming\.minecraft
2017-05-19 11:05 - 2015-12-29 22:35 - 00000386 _____ C:\Windows\Tasks\update-sys.job
2017-05-17 17:39 - 2015-12-29 20:08 - 00002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-17 17:39 - 2015-12-29 20:08 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-13 21:36 - 2015-12-29 20:55 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2017-05-12 07:19 - 2017-03-18 10:21 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-05-12 07:19 - 2015-12-29 20:55 - 00000000 ____D C:\ProgramData\Skype
2017-05-09 17:21 - 2015-12-29 20:39 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-05-09 17:21 - 2015-12-29 20:39 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-09 17:21 - 2015-12-29 20:39 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-05-09 17:21 - 2015-12-29 20:39 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-09 17:21 - 2015-12-29 20:39 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-07 17:29 - 2015-12-29 22:35 - 00003258 _____ C:\Windows\System32\Tasks\update-S-1-5-21-1906443015-4026824225-2091223967-1001
2017-05-07 17:29 - 2015-12-29 22:35 - 00000425 _____ C:\Users\User\AppData\Local\UserProducts.xml
2017-05-07 16:00 - 2016-11-18 18:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-07 16:00 - 2015-12-19 17:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-30 16:02 - 2016-06-19 10:27 - 00000000 ____D C:\Users\User\Desktop\Pozadie
2017-04-29 19:51 - 2016-03-07 14:27 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2017-04-29 08:27 - 2015-12-29 21:02 - 00003368 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-29 08:27 - 2015-12-29 21:02 - 00003240 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-28 20:27 - 2015-12-30 11:24 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2017-04-28 16:06 - 2016-01-13 20:00 - 00000000 ____D C:\Users\User\Desktop\Moje dokumenty
2017-04-28 16:04 - 2015-12-29 22:28 - 00000000 ____D C:\Users\User\AppData\Roaming\Seznam.cz
2017-04-28 16:02 - 2016-09-15 16:17 - 00000000 ____D C:\Users\User\Downloads\Dead Island Riptide
2017-04-25 14:58 - 2017-03-03 18:11 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-04-20 14:27 - 2015-12-19 17:06 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-04-20 14:27 - 2015-12-19 17:06 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-04-20 12:09 - 2015-12-29 20:42 - 00000000 ____D C:\Users\User\AppData\Roaming\DAEMON Tools Lite

==================== Files in the root of some directories =======

2016-08-04 18:33 - 2016-08-04 18:33 - 0000097 _____ () C:\Users\User\AppData\Roaming\LauncherSettings_live.cfg
2016-08-01 13:15 - 2016-08-01 13:15 - 0007321 _____ () C:\Users\User\AppData\Roaming\TheHunterPrimevalSettings_live.bin
2016-08-01 19:48 - 2016-08-01 19:55 - 0011097 _____ () C:\Users\User\AppData\Roaming\TheHunterSettings_live.bin
2016-08-01 19:40 - 2016-08-01 19:40 - 0000042 _____ () C:\Users\User\AppData\Roaming\TheHunterSettings_local.cfg
2016-07-14 15:51 - 2016-07-14 15:51 - 0000092 _____ () C:\Users\User\AppData\Local\fusioncache.dat
2015-12-29 22:35 - 2015-12-29 22:35 - 0000003 _____ () C:\Users\User\AppData\Local\updater.log
2015-12-29 22:35 - 2017-05-07 17:29 - 0000425 _____ () C:\Users\User\AppData\Local\UserProducts.xml
2016-07-27 10:39 - 2016-07-27 10:39 - 0000016 _____ () C:\ProgramData\mntemp
2016-06-15 17:00 - 2016-06-15 17:00 - 0010255 _____ () C:\ProgramData\regid.2011-06.com.youtubebyclick_3C521B99-9ACE-47EA-AC9F-26075467D03B.swidtag

Some files in TEMP:
====================
2016-12-14 20:04 - 2016-12-14 20:04 - 0739904 ____N (Oracle Corporation) C:\Users\User\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-04-28 16:04 - 2017-04-28 16:04 - 0534528 _____ () C:\Users\User\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\update-S-1-5-21-1906443015-4026824225-2091223967-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\User\Desktop" je 9638 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

Re: WannaCry

#3 Příspěvek od Boriss »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017
Ran by User (19-05-2017 18:01:43)
Running from C:\Users\User\Desktop
Windows 7 Ultimate (X64) (2015-12-19 14:18:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1906443015-4026824225-2091223967-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1906443015-4026824225-2091223967-1006 - Limited - Enabled)
Guest (S-1-5-21-1906443015-4026824225-2091223967-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1906443015-4026824225-2091223967-1002 - Limited - Enabled)
UpdatusUser (S-1-5-21-1906443015-4026824225-2091223967-1003 - Limited - Enabled) => C:\Users\UpdatusUser
User (S-1-5-21-1906443015-4026824225-2091223967-1001 - Administrator - Enabled) => C:\Users\User

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Aktualizácie NVIDIA 1.12.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.12.12 - NVIDIA Corporation)
Alan Wake (HKLM-x32\...\Alan Wake_is1) (Version: - )
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.2.2288 - AVAST Software)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.70.1080 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform)
Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.2.0.0114 - Disc Soft Ltd)
DiRT 3 Complete Edition (HKLM\...\Steam App 321040) (Version: - Codemasters Racing Studio)
Dota 2 (HKLM\...\Steam App 570) (Version: - Valve)
F.E.A.R. 3 (HKLM-x32\...\F.E.A.R. 3_is1) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Spoločnosť Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Gothic 2 Gold (HKLM-x32\...\{1FDCBE13-B895-4E68-949A-975EA871BC34}) (Version: 2.7 - Nordic Games)
Gothic II - Modification Development Kit (HKLM-x32\...\G2MDK) (Version: 2.6 - Piranha Bytes)
GOTHIC2 - ADDON_RETURNING (HKLM-x32\...\GOTHIC2 - ADDON_RETURNING) (Version: 1.0 - T&G MOD TEAM © 2005 - 2008)
GOTHIC2 - Návraty - 'Systémový balíček' (HKLM-x32\...\GOTHIC2 - Návraty - 'Systémový balíček') (Version: 1.0 - World of Gothic RU © 2014)
GOTHIC2 - Noc Havrana - 'Systémový balíček' (HKLM-x32\...\GOTHIC2 - Noc Havrana - 'Systémový balíček') (Version: 1.0 - World of Gothic RU © 2014)
Insurgency (HKLM\...\Steam App 222880) (Version: - New World Interactive)
Java 7 Update 79 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217079FF}) (Version: 7.0.790 - Oracle)
Lightshot-5.4.0.10 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.10 - Skillbrains)
LIVE gaming on Windows Runtime Version 1.0.6027 (HKLM-x32\...\{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}) (Version: 1.0.6027 - Microsoft Corporation)
Medieval II Total War (HKLM-x32\...\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}) (Version: 1.03.000 - Sega)
Metro: Last Light (HKLM-x32\...\Metro: Last Light_is1) (Version: - Deep Silver)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Slovak/Slovenčina (HKLM-x32\...\Office14.OMUI.sk-sk) (Version: 14.0.4763.1017 - Microsoft Corporation)
Microsoft Office Professional 2007 (HKLM-x32\...\PROR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{1a63c099-febd-4eaf-83ad-a82ea4fdac49}) (Version: 12.0.30501.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}) (Version: 12.0.30501.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{7c3d0734-5e24-446b-85ae-c610ee8eb53d}) (Version: 14.0.23918.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Minecraft1.7.7 (HKLM-x32\...\Minecraft1.7.7) (Version: - )
Mozilla Firefox 53.0.2 (x86 sk) (HKLM-x32\...\Mozilla Firefox 53.0.2 (x86 sk)) (Version: 53.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0 - Mozilla)
NVIDIA 3D Vision radič ovládača 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Grafický ovládač 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Ovládač 3D Vision 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Ovládač zvuku HD 1.3.23.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.23.1 - NVIDIA Corporation)
NVIDIA Softvér systému s podporou technológie PhysX 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Outlast + DLC Whistleblower verze 1.0 (HKLM-x32\...\Outlast + DLC Whistleblower_is1) (Version: 1.0 - Danik1B9)
Ovládací panel NVIDIA 314.22 (Version: 314.22 - NVIDIA Corporation) Hidden
PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 3.55.2393.590 (x32 Version: 3.55.2393.590 - Avast Software) Hidden
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.36 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.36.101 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TSEV Skyrim LE (HKLM-x32\...\TSEV Skyrim LE_is1) (Version: 2.0.0.0 - )
Unity Web Player (HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\...\UnityWebPlayer) (Version: 5.3.5f1 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 26.1 - Ubisoft)
WinRAR 5.30 (64-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
YouTubeByClick (HKLM-x32\...\{786416F8-46FB-4E44-B696-47E2F903D06C}) (Version: 2.2.34 - YouTubeByClick.com)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0E480E66-C233-4378-881D-41FFF2EE3416} - System32\Tasks\{4FD0F90F-1A22-4BC3-9B80-EDB8B7B814F6} => pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller"
Task: {11608ADE-0900-4F0D-81DD-72202F9199D7} - System32\Tasks\{021F0F9E-A937-4D83-BE8B-9AC1D600B5D4} => D:\Wolfenstein The New Order\WolfNewOrder_x64.exe
Task: {1E614734-CFC1-4F2F-81D6-83DD7178DBF4} - System32\Tasks\update-S-1-5-21-1906443015-4026824225-2091223967-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {26E47C96-9CD3-4564-923F-07E8C37B697F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-29] (Google Inc.)
Task: {312066AB-5ADE-451C-ACC9-E4CD322EAD0A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd)
Task: {31C68674-AB29-4D06-AB87-755842EE6CC2} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {3951EC42-116F-449D-992B-D7F3CE247995} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-29] (Google Inc.)
Task: {3C8970C3-DE5A-4BA3-B425-78D090D828F0} - System32\Tasks\{909D3ADA-7429-43F2-B342-6F4584738EAF} => pcalua.exe -a K:\Fairlight\Installer.exe -d "C:\Program Files\DAEMON Tools Lite"
Task: {3E8C71AE-345A-47F7-B2BB-DAC0A5FD5945} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {568D23EF-3DB4-41D0-9BB3-C9936CD217C9} - System32\Tasks\{22DCE9F4-882E-4505-93A9-68F13FBA754A} => pcalua.exe -a J:\SETUP.EXE -d "C:\Program Files\DAEMON Tools Lite"
Task: {7F5B8F5F-3085-4C9B-9818-FE872F81E7C5} - System32\Tasks\{E8839F9E-FCB5-4728-A93C-1D1594870DF2} => pcalua.exe -a C:\Users\User\Downloads\Call.of.Duty.Modern.Warfare.3-RELOADED\rld-mw3a\Setup.EXE -d C:\Users\User\Downloads\Call.of.Duty.Modern.Warfare.3-RELOADED\rld-mw3a
Task: {816785B9-6D1C-401A-AD5E-6FDFB995634B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-09] (Adobe Systems Incorporated)
Task: {B7C93F2A-EDDC-4CA7-897D-73A3060483DB} - System32\Tasks\{DEB4102D-1F8B-4789-94BD-B31AFD594BA5} => pcalua.exe -a "C:\Users\User\Downloads\Half-Life 2 CZ 2004 KAMCA\Half-Life 2.exe" -d "C:\Users\User\Downloads\Half-Life 2 CZ 2004 KAMCA"
Task: {CAF0EFEB-5D4A-4826-B84C-A6E70D2D0C8C} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-03] (AVAST Software)
Task: {D58D5A30-E359-437E-BDAA-9A4C64657057} - System32\Tasks\SafeZone scheduled Autoupdate 1458713836 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-03] (Avast Software)
Task: {EC7D7AEC-A393-41A7-8467-D6BCC2E59D08} - System32\Tasks\{D871AB1C-D82C-497A-8DF1-65C6CDEFF578} => pcalua.exe -a C:\Users\User\Downloads\Call.of.Duty.Modern.Warfare.3-RELOADED\CoDMW3\Setup.EXE -d C:\Users\User\Downloads\Call.of.Duty.Modern.Warfare.3-RELOADED\CoDMW3
Task: {ED9CDFF7-F775-4DB3-B511-8AC54B063784} - System32\Tasks\{52053831-F4D8-47F6-91C0-D7962F6FEED6} => pcalua.exe -a "C:\Program Files (x86)\booddanet\Half-Life 2\Uninstal.exe" -d "C:\Program Files (x86)\booddanet\Half-Life 2"
Task: {FF5B58B1-791E-4B83-B49D-AB5AF9C669AE} - System32\Tasks\{0BFB67BC-ECA5-496D-8C0C-527803C8AB1D} => Firefox.exe hxxp://ui.skype.com/ui/0/7.18.0.112/sk/abandoninstall?page=tsProgressBar

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\update-S-1-5-21-1906443015-4026824225-2091223967-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ВКонтакте.lnk -> C:\Users\User\AppData\Local\Amigo\Application\amigo.exe (No File) <===== Cyrillic
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Одноклассники.lnk -> C:\Users\User\AppData\Local\Amigo\Application\amigo.exe (No File) <===== Cyrillic

==================== Loaded Modules (Whitelisted) ==============

2015-12-19 16:34 - 2013-03-15 06:16 - 00086304 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-01-30 03:40 - 2010-01-30 03:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2016-06-21 17:29 - 2016-07-14 16:35 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2017-03-03 18:10 - 2017-03-03 18:10 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-05-19 13:32 - 2017-05-19 13:32 - 05980160 _____ () C:\Program Files\AVAST Software\Avast\defs\17051900\algo.dll
2010-01-30 03:41 - 2010-01-30 03:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2017-03-03 18:11 - 2017-03-03 18:11 - 00655056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-07-09 12:21 - 2016-07-09 12:21 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-03-03 18:09 - 2017-03-03 18:09 - 00290352 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2016-01-07 19:59 - 2017-03-10 02:13 - 00674592 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-01-07 19:59 - 2016-09-01 03:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-01-07 19:59 - 2016-09-01 03:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-01-07 19:59 - 2016-09-01 03:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-01-07 19:59 - 2017-04-26 01:55 - 02465056 _____ () C:\Program Files (x86)\Steam\video.dll
2016-01-07 19:59 - 2016-01-27 09:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-01-07 19:59 - 2016-01-27 09:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-01-07 19:59 - 2016-01-27 09:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-01-07 19:59 - 2016-01-27 09:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-01-07 19:59 - 2016-01-27 09:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-01-07 19:59 - 2017-04-26 01:55 - 00848672 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-03-09 17:07 - 2016-07-05 00:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2016-12-13 16:15 - 2017-01-30 23:41 - 68875552 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2016-01-07 19:59 - 2017-04-26 01:55 - 00383776 _____ () C:\Program Files (x86)\Steam\steam.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-12-29 22:36 - 00000826 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1906443015-4026824225-2091223967-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{49BB8F4F-2328-4298-BA9A-E7E402FE3AAD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{68A64EEE-D1E0-4CEA-B2FA-DFC033D77EE0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{A8FF8AF0-CDCD-4329-965F-D1185031C10C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{85A501CD-797B-4FD5-8864-D6EB99EED768}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{32B7C496-F9A6-46C4-BD4D-50CF6E40D031}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{CD652806-12E8-4DD7-9D99-8381FA1E94D3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{38CC4CD8-8F05-46E5-9A78-3BBF503B5694}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{63F49844-705D-4350-8872-2FF578F47565}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3826A978-BE10-47DA-A74B-D921382BC701}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{68CD01C0-F458-414B-8409-76AC6FC04CBE}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{555136B4-91AD-4153-BB9D-FE2BD3C08F2D}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7E5DA103-35A3-44B6-A574-9FE8175F87EE}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{B626818D-6487-45B7-B026-7C6D6E493298}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{29DD768D-5AFA-4362-BB3E-0406DA68941F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3738748E-CB58-48B6-AB4B-9598FF99BB60}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EED57439-E2D1-4400-AEA9-8D210139CF1E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{BA2719C9-DDAC-45EE-8B1B-9F713A849A52}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{BEA1A87A-813A-44CC-BE13-0FBB8EE2A504}C:\program files (x86)\steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [UDP Query User{7341DF57-C5AD-4DD7-94D6-B1BFDDE8F9D6}C:\program files (x86)\steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [TCP Query User{06D0A469-E92F-4F60-9706-D27ABACD17EA}C:\program files (x86)\activision\call of duty - black ops\blackops.exe] => (Allow) C:\program files (x86)\activision\call of duty - black ops\blackops.exe
FirewallRules: [UDP Query User{8C824122-0A62-4100-BF19-410AB032F8A2}C:\program files (x86)\activision\call of duty - black ops\blackops.exe] => (Allow) C:\program files (x86)\activision\call of duty - black ops\blackops.exe
FirewallRules: [TCP Query User{AE56E441-C458-4B21-ADEF-D2599E622147}C:\program files (x86)\activision\call of duty - black ops\blackopsmp.exe] => (Block) C:\program files (x86)\activision\call of duty - black ops\blackopsmp.exe
FirewallRules: [UDP Query User{85D3EB30-213C-4AFC-A9F7-7FE93DE70CC3}C:\program files (x86)\activision\call of duty - black ops\blackopsmp.exe] => (Block) C:\program files (x86)\activision\call of duty - black ops\blackopsmp.exe
FirewallRules: [TCP Query User{D9E20E45-5A22-4FE1-A60D-44783011D140}C:\users\user\desktop\medal of honor pacific assault\mohpa.exe] => (Allow) C:\users\user\desktop\medal of honor pacific assault\mohpa.exe
FirewallRules: [UDP Query User{471EEF41-1A96-44CF-9E2B-0841DCD91021}C:\users\user\desktop\medal of honor pacific assault\mohpa.exe] => (Allow) C:\users\user\desktop\medal of honor pacific assault\mohpa.exe
FirewallRules: [{00E36601-1105-4123-8787-62911A4237E8}] => (Allow) D:\Battlefield 3™\bf3.exe
FirewallRules: [{F8C41105-7508-4CF0-B543-74C07456174F}] => (Allow) D:\Battlefield 3™\bf3.exe
FirewallRules: [TCP Query User{65F45160-84B1-4A1F-9BA8-1B8D56A9F5B5}D:\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) D:\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{4663D105-95F6-4F8B-A6F6-0FF2A77AE4A3}D:\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) D:\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [TCP Query User{BA87D6E2-E687-4C92-8BA6-E390F48C3F20}D:\steamlibrary\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe] => (Allow) D:\steamlibrary\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [UDP Query User{004D6A65-3144-4D0C-9209-ECC734DBDEFD}D:\steamlibrary\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe] => (Allow) D:\steamlibrary\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe
FirewallRules: [TCP Query User{2F29E2E5-3B58-4B91-B63D-98886CEED7D2}C:\users\user\desktop\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe] => (Allow) C:\users\user\desktop\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe
FirewallRules: [UDP Query User{5269CBF2-AD4B-404D-B4CC-F7EB99685743}C:\users\user\desktop\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe] => (Allow) C:\users\user\desktop\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe
FirewallRules: [TCP Query User{53A9C84D-C886-4DA9-9C14-D7F005895AF9}C:\users\user\desktop\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe] => (Allow) C:\users\user\desktop\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe
FirewallRules: [UDP Query User{BDBCB797-363E-4D1E-AE0A-9330C4B3C474}C:\users\user\desktop\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe] => (Allow) C:\users\user\desktop\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe
FirewallRules: [TCP Query User{E98DF0CE-8A70-4E69-9EA5-8494511892FB}C:\program files\strogino cs portal\counter-strike global offensive\csgo.exe] => (Block) C:\program files\strogino cs portal\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{0CD98764-A623-4D5E-A7CA-94A3F4EE821F}C:\program files\strogino cs portal\counter-strike global offensive\csgo.exe] => (Block) C:\program files\strogino cs portal\counter-strike global offensive\csgo.exe
FirewallRules: [{C8A88838-B574-4336-85E2-6BF11AD0CEA1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B8A84F3E-71B0-4334-8F09-1A2314B72DC5}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5BD9FA97-47FD-435F-B6DD-31137930D991}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{0CBB5049-17E2-4D63-AC19-8DD77C17B5C1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{5C14BC1D-DB4E-46FC-8CB6-4A3E7F2779EF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CSNZ\Bin\cstrike-online.exe
FirewallRules: [{015E442F-DA7E-435C-8E16-172D3AEAB228}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CSNZ\Bin\cstrike-online.exe
FirewallRules: [TCP Query User{0E20ABA8-C408-4D2E-9F40-B85A54E39712}C:\users\user\downloads\igg-thehunteprimal\igg-thehunteprimal\game\thehunterprimal.exe] => (Block) C:\users\user\downloads\igg-thehunteprimal\igg-thehunteprimal\game\thehunterprimal.exe
FirewallRules: [UDP Query User{E9CE76CE-D1DC-443D-9993-9F2D64BF2ABA}C:\users\user\downloads\igg-thehunteprimal\igg-thehunteprimal\game\thehunterprimal.exe] => (Block) C:\users\user\downloads\igg-thehunteprimal\igg-thehunteprimal\game\thehunterprimal.exe
FirewallRules: [{5DB64CE5-2CD2-4A22-B691-FE0ECA7085F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{21042D1F-C4EF-4BCB-8A4F-BAFE1FADC5B3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{A65E6D59-544C-4AE7-8E85-79BA1C179113}] => (Allow) D:\SteamLibrary\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{21AB28EE-8843-498F-9CAF-A853FDC16198}] => (Allow) D:\SteamLibrary\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [TCP Query User{89D0B057-29B2-442F-94B5-15FDC7EFDD61}D:\dead island\deadislandgame.exe] => (Allow) D:\dead island\deadislandgame.exe
FirewallRules: [UDP Query User{2F7C3B6A-4DD0-405C-BDEE-E489147D56EB}D:\dead island\deadislandgame.exe] => (Allow) D:\dead island\deadislandgame.exe
FirewallRules: [TCP Query User{0FAF317C-8BF9-4EEE-AEE4-7EA805784D80}C:\users\user\downloads\dead island riptide\deadislandgame_x86_rwdi.exe] => (Allow) C:\users\user\downloads\dead island riptide\deadislandgame_x86_rwdi.exe
FirewallRules: [UDP Query User{3560BF05-AE7B-4C31-9307-2B16D2F910D1}C:\users\user\downloads\dead island riptide\deadislandgame_x86_rwdi.exe] => (Allow) C:\users\user\downloads\dead island riptide\deadislandgame_x86_rwdi.exe
FirewallRules: [{56586968-1E43-48C6-A291-C983F643EF58}] => (Allow) D:\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{5066641D-85A1-44FF-9F87-106EDC585FED}] => (Allow) D:\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{CC341C40-916E-4E41-BDB5-F2948CD4D117}] => (Allow) D:\SteamLibrary\steamapps\common\DiRT 3 Complete Edition\dirt3_game.exe
FirewallRules: [{7C7C7AE2-5C70-498A-8865-F8DBED9BB3A2}] => (Allow) D:\SteamLibrary\steamapps\common\DiRT 3 Complete Edition\dirt3_game.exe
FirewallRules: [{01C8F923-6243-4B02-B890-DAC7CD3E4824}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{9F501FC4-3F90-4675-9A60-C6956EEACA0D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{97F07643-6C51-457A-950D-2B84E35E9A4D}C:\program files (x86)\saints row 4\saints row iv\saintsrowiv.exe] => (Block) C:\program files (x86)\saints row 4\saints row iv\saintsrowiv.exe
FirewallRules: [UDP Query User{A2819C5D-A148-4031-8C32-F1E18E718768}C:\program files (x86)\saints row 4\saints row iv\saintsrowiv.exe] => (Block) C:\program files (x86)\saints row 4\saints row iv\saintsrowiv.exe
FirewallRules: [{E9BCC962-8C15-4F94-86BC-6F00866100D4}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{110E3FD8-7187-441D-95F8-3DFEE79A4A8F}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AF999A20-5A26-4619-BEA0-2E7C5D4B4FDD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{29B99358-75CC-456D-BFD3-CB25B5FC880F}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{1A535C6E-9AF1-4C45-9DC3-0C3EFEEB545E}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A25F3F06-B3D4-4885-943B-19BCA439C4B8}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5D21202A-FB63-4116-A636-478BB76EC4FC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E2A8C22A-25C9-4E16-9BDC-D71CF2D53C96}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{94EE8804-94EA-42B2-8D99-7F6F19D6A3D0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A9E8A2E9-6D4E-4B36-AB2F-005FE4DE4553}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3813AB8A-6EBE-466A-BE77-471AEB9BAEA0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B91980F2-E1C1-4701-88F4-8522BF7BF6BA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD8C729A-E1E1-4787-A8B3-45DBE0131312}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4A6F361E-0690-47FA-8101-008B85F2094A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{124D864D-1DF1-4CD3-9174-739868E84E52}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1955D118-8E99-400F-B15F-2236385B4A1C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B0C8E7B3-5210-4B53-A978-37C7A78749B6}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0940EAFF-41F8-4196-8D09-223084E9D25C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6CBB8C36-6243-4D57-BDFB-FEA515EE7F15}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{65ECE7E4-0AB5-42A3-9EF2-124DCDD6B101}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A1E9A8F0-FA31-44C2-B102-ECABD9A88E9D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ABA2C7D2-7A2C-41E3-B664-7D0B2E0A9519}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{82401ECF-9522-4619-AB78-D6BD673A4C2D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AB470561-0CC7-43EF-A227-153CDF3A3405}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{82ED1F11-8BAD-463D-B37F-F167F26F61B8}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0F06E055-A241-4D62-A314-4B72760CA886}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{094B1770-6256-4135-B2AA-8C38577578BA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2D4B25A3-D0BD-4D5C-913F-3A3BE0B201FD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6CAE891C-0B7D-4CAB-B730-518E2831B942}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A680DC79-D80F-4A66-B04C-71E37CC10C9B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B4F277C8-5AF4-4DD5-B13F-CD23CB0BC2DB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3441A129-DEEB-4C87-8A5E-DF37D255EC78}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4DB45F11-0584-49E8-A4BF-74E464077C31}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5E7C8705-4B4C-4AD9-9CC9-45FB6C1991C5}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DA613F39-9F0D-4963-8894-668B35236BCB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1FF95C0D-0FF1-4B8B-A198-FF930C12ABBE}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FF4A2CF0-0035-482A-BB4E-4980A1300809}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{30647E1F-EA21-4B1C-83D0-21ED348D6B3D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A3BA8BBD-C322-415C-92D6-7A81E9E05242}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4463CC6B-8A91-419B-9BDE-92BA3DD2B698}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C13CDC51-6A72-4776-961B-B1167E2CAD82}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{89C4479D-1FB0-4791-B2C3-79A7A1CE6A6C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7259C539-661A-44A1-9996-10EDF77A5F26}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B54990AB-0D54-4774-B80A-5898027FA27C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{019AED60-EB71-4EED-BA4A-5F2220AFEA7D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{59B432C4-BD04-4E3E-AAB6-43DA199E387E}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3F97B16D-E2BD-4F79-9546-8DDE0E445590}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{74CE947D-1EAC-4495-B764-2E2D164D8A37}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E4EA4150-1793-462C-B2BF-20FCC90C3590}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A2F22A33-BFE6-455F-B303-6BD9FBE24C4F}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{88019D57-BC51-4ED5-855B-69C25891CC80}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D8F2EF2C-3A1B-4912-8529-3CE5ABDB8159}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C2112BA0-B46F-401C-A99C-86A292F6664C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3EDE1703-B950-423A-9832-0CF2B8F6EC50}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5C387153-29F9-4FBF-8FE2-6D9CBEA07967}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5507EF04-F2D8-4A29-B7E0-0B8DDAB85693}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{40F906D5-B7F4-4FFA-9D13-3EBF63DDB44A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A0E22CD-6C98-426F-9261-847A7C5D93AB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9B0D9401-13F2-4D57-8E86-364FE0C4E8A4}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F4DAFC2D-8CF0-4D39-B1BF-D1188E99B7A5}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0F3E5EA1-9A5F-4389-A3B3-1939978BFD3E}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CD4117B9-72F3-47E7-A2E0-1F723122F1F2}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{36624AAD-9277-4D4A-A689-71BF56774873}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{77AD8204-C359-4ED6-B63B-B4E2D3ECF13B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{636A372A-5473-4439-A052-3BDE9286FDA2}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{274D71F1-4855-4694-AC04-A1975AFE5BAA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{38DFC3DC-B327-4B9D-AD44-50027CDBD842}D:\f.e.a.r. 3\f.e.a.r. 3.exe] => (Allow) D:\f.e.a.r. 3\f.e.a.r. 3.exe
FirewallRules: [UDP Query User{79737357-26CE-4FC6-807B-8238625105D6}D:\f.e.a.r. 3\f.e.a.r. 3.exe] => (Allow) D:\f.e.a.r. 3\f.e.a.r. 3.exe
FirewallRules: [{47BD4DED-6666-4BA5-884F-969CFD328D32}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{56645E43-6E1C-4E1D-A66A-AB8B8DC2C845}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B54BA576-31DF-40E4-A6CD-AFA8DC5F474A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{52E9D23A-3BEE-4BD1-A584-08A55F61839C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E2E73F4F-7F7D-4330-A983-6B249A6356EA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7FD598C0-F332-41CA-ADAC-12C9422DC2B3}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1BFC7158-87FE-4330-B25C-2A3D361A8DCA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2BE5B745-367E-426A-80F5-890F9B0E9B12}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7CEC4616-4976-42CA-923F-8754011B89A0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7035A57A-1CB9-4888-8034-3CBD46C8612A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{333A88C0-F1FE-4CFB-9878-CC181B6E1345}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.561\SZBrowser.exe
FirewallRules: [{8C70901D-9D1E-451C-BB95-15EAC89A10CC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{53855438-61DE-4326-AE3B-36733E62A8A4}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F7F9639D-EBB9-4A66-993E-3A92FB90314B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{134C493E-2BC1-4687-B05F-3238E037712A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A0EDBA9-FCAC-490A-A5BF-0DE4CE4D1DBD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1447255A-12AB-4466-8FAF-01D8C9C43928}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{151707A5-C41A-462F-B6B0-B2DBA8788906}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590\SZBrowser.exe
FirewallRules: [{2B5FAC63-DA2C-4213-A820-CA74463E7306}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EA750D65-CF83-4266-B077-43BA7B426CDC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{080A2A23-682E-4FB6-95C2-F6EE933A57BE}] => (Allow) D:\SteamLibrary\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{E0787FB8-1290-474D-B56A-D0528763A76D}] => (Allow) D:\SteamLibrary\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [TCP Query User{82492904-D5B0-4CBB-9B36-C51A8BAE28DF}D:\steamlibrary\steamapps\common\insurgency2\insurgency.exe] => (Block) D:\steamlibrary\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [UDP Query User{876F5BF8-0474-4BD2-9554-4409FE87AC41}D:\steamlibrary\steamapps\common\insurgency2\insurgency.exe] => (Block) D:\steamlibrary\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{EEC356E4-B813-42FA-ABFB-47D3D2E3D2C6}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{489B54E5-A913-4DE2-9774-9D2ACBDE4F0C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{16DA6603-CFDF-4D98-9ADE-849DCA2E7E86}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E7398BEC-592E-4983-BC52-C6BEFF8C09D5}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7B7A7B7B-990E-4952-8151-5B44925D5916}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4DDE3A4B-D9DB-449B-9687-14389B95F3F1}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7A5CD4E5-F4AA-4FD2-853D-57390F839D76}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BCA0803E-A56A-4B92-A3D5-13792DC8BA30}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{016836AB-6C35-4ED1-9DEA-DBFECEBAB2B4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{21EC6A94-F7A6-4B67-87D0-C1C94DCC20C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{9CFAAA81-D780-44CF-8F24-279796C9062E}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{CEE0DD1A-38E1-46F0-88A5-85A31F7CE808}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4286D35C-8258-4278-B182-75174F3FDB74}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8ABED78B-BB06-489E-9BDC-3704E10D00EB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6830EF78-8885-4C71-8E81-92A397516A93}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6D68FFBC-7A68-4DCB-8396-DE1106B406AD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AF91030B-3713-4A49-89D9-F43BECC7E229}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{17FD8D31-5BAE-4A61-99BD-A260BF62250C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2AA47791-B127-4183-903E-EBAC684AA15A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{395EAD3B-9B46-41D5-87E0-4859A3F0EDD0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{802E6A52-03B3-4839-8B5C-33636DACF21E}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{ECD41D9D-E3EA-4F98-BBC9-58C264BA743D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F613F7EC-FE32-47B7-BB73-E9EAFEF462DC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C70201AE-C21E-495C-9087-AD34D90AF857}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{45FE0EFE-233B-4E1F-8C81-4314A801B732}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{18AB9D2E-27EC-421F-8D65-D040B02EDB68}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C7D00AE5-B221-482B-ACDD-598A5B7CB6FE}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5D3137E1-303F-4BFF-8F4D-6F019DE6CF8D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{88B134C7-2600-4D46-9D68-056CEF8D769B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C5BCB10D-A99D-4523-8699-D1178FB59E05}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7DF8985E-EBF1-49A7-9AE7-C6D7D4A17F14}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5DA4A5B6-C636-4055-A77F-2E78CF5C0756}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8E3A611C-7A82-47E5-B0E8-8C42E786B006}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{4ADD5A31-74D2-4D45-941A-0F9BBA308D0A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{AC0612A4-0203-4905-9F05-E35378B99524}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D5EA8076-704F-4CF6-9D87-A594D723A1AB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{DC998C76-9813-4EA5-A144-0374F96D0DDD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A8FAB8E5-2587-454F-92A3-D9E7B847A591}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{E6B2F3D9-CD76-49B6-8C2A-BA4CB05035CF}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{851067A0-6C93-43A9-AD5E-51C44B1B0A08}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{FEE68D96-D9A0-4652-AF40-C073EF2976A0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01C09CAF-2693-417F-987B-F8C14C3D5298}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F349C723-161A-4EAE-BE88-B1CD1E04AA77}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B560EFF0-550E-4783-B7E8-EACAFC4D92A1}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5A799DC5-3AE6-45BF-959B-12E30E8410EE}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D86F71A3-9CDF-4FD1-BEE7-4E3EDE3E337B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C43F4131-71AA-4DE5-912D-BE1AA92F3A49}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{90276980-7E85-4793-9A44-9786C413DFE0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{045119C6-5BAD-4564-AAB4-9403103860CC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{35370767-FB08-467B-A88D-CAA622CEEC0D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0CD48872-619F-4A93-907F-F55E6F5AEBE0}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{079681F3-97D6-4F62-A33E-8C0B36689AF7}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8C510F3A-5BD2-49B8-9618-1373BF8DE24C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7AF7D786-6B50-463D-9B90-1C0B052E9CF3}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7A771029-7CD2-4F6A-91C3-3BD5579F5328}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{32509C19-D2ED-4488-87F2-4C45C0060669}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{FE280A19-8841-4018-B779-42E711071F7B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{903449A8-FF4A-40FE-A6FC-EB95EC68E873}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8D42DCC2-88F3-4721-821F-A069C8260987}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F4479F80-9D1C-44C8-AB61-9F72079D25FD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{769D8ABD-40C1-4CD8-9A9E-F0CD5314E089}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C27FD306-CE26-499A-8672-52DC29F27AAD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{710FC4B1-0611-4F06-BF24-94137760BCF1}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6BE28838-4ACD-42BE-946F-107D8209C6EA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5B1DF7A8-ADD4-4F36-84B7-30BA73956EE8}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{EC3BE3ED-E499-4307-A07F-094559285FEB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8B6A4365-3404-40AD-9CEF-8A5AF179B71B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{9EBF97F7-3A27-4EF9-BA1D-5DFE0596E5AB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B94990FC-9DCE-464A-A81A-5C1B7F2E6A8D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{6926D2FC-2FF5-4939-B38D-3CC2DE6B9B18}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{58B148AD-A89A-4033-B317-81A321AE2EAF}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{876FB961-B0D0-4CC9-93A5-A113AF4BF19C}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{27CAF614-E0E9-4DE7-97C2-EBED2AC5C694}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A909A4F6-02FD-40C0-AAAB-F197BB5DE6DD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{29D2F0F3-EED9-402D-8703-AB92236D2669}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B82849D2-3F71-46C3-B3E0-62C0C84C997B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{1425DAB6-22E7-457E-9DEA-EB81D4449F31}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3DA5CAE3-A0DD-49EA-A785-E95D293470BA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{19E2C9FD-078F-4744-83A8-F2B24EE159CE}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D074F862-5792-4CDA-9E2E-0673E1540C5A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{B19280DC-BCAC-4788-89E3-12BDA51F77DF}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{7080DD57-4FCB-4676-BFC6-EF42050D3169}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{3CD5B0A0-EE9B-4CFA-99FA-CA8AF8F0B252}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{E9DBA5F0-6635-4C1F-A9D4-42C19D4E0B47}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{044D9FCD-B689-4453-85FE-D9346C3BD6FA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{BEE9BD57-8E13-4B5E-8A9D-8ECA4544C070}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{0A59CF62-140D-4C38-B040-A5D6396DB72D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{26E731FA-DD46-4E26-9F97-AB9043A294FD}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F36B6547-54B4-4C83-99A8-36BC0A24D36A}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{8ED1B361-C3F6-404B-97CE-44D3B66AEABF}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F46AB3C8-7D72-4D78-A0B2-6D931D1D90A1}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{49532AFF-853E-4488-8D0B-79CD38446916}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{65D397E6-F212-440B-A27A-2B36ADDD52DB}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{F15A7397-B66A-412C-ACF8-8DF2D587368D}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{08967672-8B72-462D-8DE8-DA4600C857A8}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{D05D7F9B-2D8C-4A7D-B16D-00CDA4BF0663}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{C7EC255C-830A-4EA6-B93F-95DD54497FDD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9C02EECF-E831-47C2-9113-1371FE7300EA}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{A36F71A3-8832-4D49-8A15-B0E9C57996C4}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{42A023EB-F9EF-40D7-90E4-312BE8C6F76F}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2707F8D1-FF26-4959-8E6C-66B38238EEEC}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe

==================== Restore Points =========================

Check "winmgmt" service or repair WMI.


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/19/2017 06:02:18 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
.


Operation:
Instantiating VSS server

Error: (05/19/2017 06:02:18 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
]


Operation:
Instantiating VSS server

Error: (05/12/2017 05:09:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 8.0.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 11b0

Start Time: 01d2cb318d92c580

Termination Time: 8

Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

Report Id: f212f341-3724-11e7-bad0-00215a7343c5

Error: (05/06/2017 11:20:38 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
.


Operation:
Instantiating VSS server

Error: (05/06/2017 11:20:38 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
]


Operation:
Instantiating VSS server

Error: (05/06/2017 11:20:37 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
.


Operation:
Instantiating VSS server

Error: (05/06/2017 11:20:37 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
]


Operation:
Instantiating VSS server

Error: (05/06/2017 11:20:37 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
.


Operation:
Instantiating VSS server

Error: (05/06/2017 11:20:37 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
]


Operation:
Instantiating VSS server

Error: (04/30/2017 01:44:51 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvorenie bodu obnovenia zlyhalo. (Proces = D:\Metro 2033 Last Light\Metro Last Light\redist\DirectX\DXSETUP.exe 2033 Last Light\Metro Last Light\redist\DirectX\DXSETUP.exe" /silent; Popis = Installed DirectX; Chyba = 0x80042302).


System errors:
=============
Error: (05/19/2017 04:18:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NVIDIA Update Service Daemon zlyhalo kvôli nasledujúcej chybe:
Pretože zlyhalo prihlásenie, službu sa nepodarilo spustiť.

Error: (05/19/2017 04:18:15 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Službe nvUpdatusService sa nepodarilo s aktuálne nakonfigurovaným heslom prihlásiť ako .\UpdatusUser kvôli nasledujúcej chybe:
Prihlásenie zlyhalo: Doba platnosti hesla pre zadané konto už uplynula.


Ak chcete zabezpečiť správne nakonfigurovanie služby, použite modul Služby konzoly MMC (Microsoft Management Console).

Error: (05/19/2017 03:57:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NVIDIA Update Service Daemon zlyhalo kvôli nasledujúcej chybe:
Pretože zlyhalo prihlásenie, službu sa nepodarilo spustiť.

Error: (05/19/2017 03:57:16 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Službe nvUpdatusService sa nepodarilo s aktuálne nakonfigurovaným heslom prihlásiť ako .\UpdatusUser kvôli nasledujúcej chybe:
Prihlásenie zlyhalo: Doba platnosti hesla pre zadané konto už uplynula.


Ak chcete zabezpečiť správne nakonfigurovanie služby, použite modul Služby konzoly MMC (Microsoft Management Console).

Error: (05/19/2017 09:31:56 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NVIDIA Update Service Daemon zlyhalo kvôli nasledujúcej chybe:
Pretože zlyhalo prihlásenie, službu sa nepodarilo spustiť.

Error: (05/19/2017 09:31:56 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Službe nvUpdatusService sa nepodarilo s aktuálne nakonfigurovaným heslom prihlásiť ako .\UpdatusUser kvôli nasledujúcej chybe:
Prihlásenie zlyhalo: Doba platnosti hesla pre zadané konto už uplynula.


Ak chcete zabezpečiť správne nakonfigurovanie služby, použite modul Služby konzoly MMC (Microsoft Management Console).

Error: (05/18/2017 06:27:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NVIDIA Update Service Daemon zlyhalo kvôli nasledujúcej chybe:
Pretože zlyhalo prihlásenie, službu sa nepodarilo spustiť.

Error: (05/18/2017 06:27:27 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Službe nvUpdatusService sa nepodarilo s aktuálne nakonfigurovaným heslom prihlásiť ako .\UpdatusUser kvôli nasledujúcej chybe:
Prihlásenie zlyhalo: Doba platnosti hesla pre zadané konto už uplynula.


Ak chcete zabezpečiť správne nakonfigurovanie služby, použite modul Služby konzoly MMC (Microsoft Management Console).

Error: (05/18/2017 06:25:15 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 18:23:09 on ‎18. ‎5. ‎2017 was unexpected.

Error: (05/18/2017 05:31:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby NVIDIA Update Service Daemon zlyhalo kvôli nasledujúcej chybe:
Pretože zlyhalo prihlásenie, službu sa nepodarilo spustiť.


CodeIntegrity:
===================================
Date: 2017-03-03 16:50:23.183
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-03 16:50:22.855
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-03 15:29:03.464
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-03 15:29:03.386
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 18:18:56.976
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 18:18:56.914
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 11:36:28.058
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 11:36:27.980
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 07:05:11.557
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2017-03-02 07:05:10.980
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD Athlon(tm) Dual Core Processor 4450B
Percentage of memory in use: 48%
Total physical RAM: 4094.49 MB
Available physical RAM: 2113 MB
Total Virtual: 10233.63 MB
Available Virtual: 8040.21 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:130.61 GB) (Free:8.75 GB) NTFS
Drive d: () (Fixed) (Total:101.97 GB) (Free:6.02 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 5283F0F7)
Partition 1: (Not Active) - (Size=130.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=102 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=300 MB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: WannaCry

#4 Příspěvek od altrok »

Ahoj,

mam mensi podezreni, ze na tento operacni system nemas zakoupenou licenci, ale co delat? Zakoupit si legalni system a povolit automaticke aktualizace operacniho systemu. Pokud se nachazis v tak heterogennim prostredi systemu, ze nelze hromadne aktualizovat a stale nejsi napadem zadnym malwarem, ktery exploit pro SMB zneuziva, nainstaluj alespon MS17-010.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

Re: WannaCry

#5 Příspěvek od Boriss »

Ahoj máš pravdu nemám oficiálny aj ja si myslím že PC je v pohode ale zo sieťou niečo je pretože ked hrám dotu 2 tak mi nechce spustiť zápas lebo VAC security mi to stopne že mám niečo s PC. Čiže nemám žiadny vírus PC? prečo mi potom to hlási? Či je to len varovanie zo strany operátora?

Môžeš mi popísať prosim blžšie k tomu čo mám stiahnuť je to nejaký update ? nezablokuju mi windows?

Ďakujem za odpoveď :)

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: WannaCry

#6 Příspěvek od altrok »

Boriss píše:Čiže nemám žiadny vírus PC?
Na to ses prvne neptal - mas.

Boriss píše:čo je to len varovanie zo strany operátora?
Operatorem myslis poskytovatele internetoveho pripojeni (ISP)? Ten s tebou urcite nebude komunikovat prostrednictvim avastu (vyjadruju se ke screenum z prvniho postu).

Boriss píše:Môžeš mi popísať prosim blžšie k tomu čo mám stiahnuť je to nejaký update ?
https://technet.microsoft.com/en-us/lib ... 7-010.aspx
Zneuzitelnost SMB je tak velka vec, ze k tomu najdes vsude na internetu tunu podrobnych informaci. Co mas delat jsem ti napsal v predchozim prispevku.

Boriss píše:nezablokuju mi windows?
Otazkou je co presne si pod pojmem "zablokovani windows" predstavujes a od koho. Riziko napadeni nezaplatovaneho operacniho systemu malwarem je dle meho docela vysoke a spolehat se jen na ochranu antivirem, je odvazne (mluvim ted o "blokaci" typu ransomare). Blokace ze strany Microsoftu se bat nemusis.

Vzhledem k tomu, ze mas upirateny OS, coz zde nerespektujeme, diskuzi ukoncime.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

Re: WannaCry

#7 Příspěvek od Boriss »

Takže mi s tým nepomôžete? :(

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: WannaCry

#8 Příspěvek od altrok »

Co delat proti napadeni WannaCry jsem ti popsal, s dalsimi vecmi dle pravidel fora pomoct nemuzu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Boriss
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 19 kvě 2017 16:44

Re: WannaCry

#9 Příspěvek od Boriss »

A stiahnuť mám toto? to prvé? http://prntscr.com/f9zuwi

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: WannaCry

#10 Příspěvek od altrok »

Porid si Service Pack 1, pak nainstaluj security update, ktery jsem linknul. Nebo si porid legalni system a pak te navedu konkretneji.

Vic toho nevyresime, at se dari. Mej se krasne.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Zamčeno