Re: Trojan-proxy agent
Napsal: 20 bře 2011 09:46
Tak po restartu ComboFix už šel, takže log:
ComboFix 11-03-19.03 - Jirka 20.03.2011 9:21.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1246 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jirka\Plocha\ComboFix.exe
FW: Internet Security Firewall *Disabled* {2BF21FEC-A5BE-424D-BDD7-3229CC84ED22}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\page
c:\documents and settings\All Users\Data aplikací\page\page.ico
c:\documents and settings\All Users\Data aplikací\page\page.URL
c:\documents and settings\All Users\ntuser.pol
c:\webupdater\WebUpdater.exe
c:\windows\AutoRun.ini
c:\windows\d.ini
c:\windows\system32\csftxctl.ocx
c:\windows\system32\drivers\FSC__PI__ESPRIMO Mobile V5505 __FUJITSU SIEMENS_ESPRIMO Mobile V5505 __Ver 1.00PARTTBLM_FSC - 6040000_R01-A0W .MRK
c:\windows\system32\zip32.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-20 do 2011-03-20 )))))))))))))))))))))))))))))))
.
.
2011-03-20 06:51 . 2011-03-20 06:51 -------- d-----w- C:\rsit
2011-03-20 06:02 . 2011-03-20 06:02 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKslb2470c1c.sys
2011-03-19 19:23 . 2011-03-19 19:23 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKsle723e2ae.sys
2011-03-19 19:23 . 2011-02-11 06:54 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\mpengine.dll
2011-03-18 21:52 . 2011-03-18 21:52 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\IObit
2011-03-18 21:52 . 2011-02-23 15:54 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-03-18 21:52 . 2011-02-23 16:04 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-03-18 21:51 . 2011-03-18 21:51 -------- d-----w- c:\program files\IObit
2011-03-17 19:55 . 2011-03-19 22:28 -------- d-----w- C:\Conspiracy Theory with Jesse Ventura
2011-03-15 20:09 . 2011-03-15 20:12 -------- d-----w- c:\program files\NutsAboutNets
2011-03-12 19:15 . 2011-03-14 19:44 -------- d-----w- C:\axaxax
2011-03-11 18:15 . 2011-03-11 18:15 -------- d-----w- c:\documents and settings\Jirka\Local Settings\Data aplikací\Kolor
2011-03-11 18:14 . 2011-03-11 18:14 -------- d-----w- c:\program files\Kolor
2011-03-11 17:07 . 2011-03-11 17:07 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-25 21:28 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\Leadertech
2011-02-25 21:28 . 2011-02-25 21:28 53248 ----a-r- c:\documents and settings\Jirka\Data aplikací\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-02-25 21:28 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\Jirka\Local Settings\Data aplikací\Logishrd
2011-02-25 21:28 . 2011-03-09 16:52 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-02-25 21:25 . 2010-08-24 17:30 10448 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2011-02-25 21:25 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Logishrd
2011-02-25 21:25 . 2011-02-25 21:25 -------- d-----w- c:\program files\Logitech
2011-02-25 21:20 . 2011-02-25 21:21 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\Logishrd
2011-02-25 20:51 . 2011-02-25 20:51 -------- d-----w- c:\program files\PowerISO
2011-02-25 20:43 . 2011-02-25 20:55 -------- d-----w- C:\f2e68d3c69ec0e37226d12
2011-02-25 20:24 . 2011-02-25 20:28 -------- d-----w- C:\1bc24d913a575e916ab87aa8
2011-02-25 19:06 . 2008-10-29 06:28 221184 ----a-r- c:\windows\system32\RaCoInst.dll
2011-02-25 19:06 . 2008-10-29 06:34 644096 ----a-r- c:\windows\system32\drivers\rt2870.sys
2011-02-22 20:32 . 2011-02-22 20:34 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\TrustPort
2011-02-20 07:56 . 2011-02-20 07:56 -------- d-----w- C:\Log
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-11 06:54 . 2010-11-14 07:13 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2007-08-07 14:14 270848 ------w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2007-08-07 14:14 186880 ------w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2007-08-07 14:28 2067456 ------w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-08-07 14:28 677888 ------w- c:\windows\system32\mstsc.exe
2011-01-23 07:54 . 2008-05-29 18:05 741692 ----a-w- c:\documents and settings\Jirka\Data aplikací\mdbu.bin
2011-01-21 14:44 . 2007-08-07 14:14 440320 ------w- c:\windows\system32\shimgvw.dll
2011-01-17 08:11 . 2011-02-02 20:23 125248 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-01-17 08:10 . 2011-02-02 19:31 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-01-12 11:04 . 2011-01-12 11:04 535880 ----a-w- c:\windows\system32\oodssrs.dll
2011-01-12 10:36 . 2011-02-02 20:23 89472 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-01-07 14:09 . 2007-08-07 14:14 290048 ----a-w- c:\windows\system32\atmfd.dll
2011-01-07 13:54 . 2011-02-02 20:20 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-01-07 13:54 . 2011-02-02 20:20 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-01-07 13:54 . 2011-02-02 20:20 2000848 ----a-w- c:\windows\PCTBDCore.dll
2011-01-07 13:54 . 2011-02-02 20:20 767952 ----a-w- c:\windows\BDTSupport.dll
2011-01-06 10:54 . 2011-02-02 20:20 2125 ----a-w- c:\windows\UDB.zip
2010-12-31 14:04 . 2007-08-07 14:15 1854976 ------w- c:\windows\system32\win32k.sys
2010-12-31 08:36 . 2011-02-03 17:19 69392 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2010-12-31 08:36 . 2011-02-03 17:19 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2010-12-31 08:36 . 2011-02-03 17:19 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2010-12-22 12:34 . 2007-08-07 14:14 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2007-08-07 14:15 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2007-08-07 14:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2007-08-07 14:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2007-08-07 14:14 729088 ------w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2011-01-06 19:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2011-01-06 19:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2007-08-07 14:14 385024 ----a-w- c:\windows\system32\html.iec
2008-07-25 08:31 . 2008-11-26 20:02 28672 ----a-w- c:\program files\mozilla firefox\components\flashgetXpi.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2011-01-28 1239040]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 90624]
"iTV"="c:\program files\iTV\iTV.exe" [2011-03-17 623616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-10-02 1191936]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-10-02 1368064]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 221184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496]
"Hard Disk Sentinel"="c:\program files\Hard Disk Sentinel\HDSentinel.exe" [2010-12-27 3913216]
"ClipX"="c:\program files\ClipX\clipx.exe" [2005-11-30 68608]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2009-12-18 22486]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoRecentDocsNetHood"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"SignupShield"="c:\documents and settings\jirka\dokumenty\my programs\signupshield\bin-06-02-07\SignupShield.exe" /e"1"
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe"
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe"
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"HotKeysCmds"="c:\windows\system32\hkcmd.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\ANWSOFT\\CAMagic Mobile for Bluetooth\\LiveCheck.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsvsvr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Xi\\NetXfer\\NetTransport.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Jirka\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"50629:TCP"= 50629:TCP:utorrent
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"1518:TCP"= 1518:TCP:Akamai NetSession Interface
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [21.11.2009 9:16 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2.2.2011 20:30 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2.2.2011 20:31 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2.2.2011 20:31 656320]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [18.3.2011 22:52 13496]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.5.2008 16:17 691696]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [3.2.2011 18:19 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [3.2.2011 18:19 69392]
R1 MpKslb2470c1c;MpKslb2470c1c;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKslb2470c1c.sys [20.3.2011 7:02 28752]
R1 MpKsle723e2ae;MpKsle723e2ae;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKsle723e2ae.sys [19.3.2011 20:23 28752]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2.2.2011 20:31 251560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41 67656]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [29.1.2009 18:03 13360]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [2.2.2011 21:20 247760]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [25.2.2011 22:25 10448]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [28.4.2010 21:56 63488]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [20.10.2009 19:19 50704]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2.2.2011 20:30 160448]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [29.1.2009 18:03 69168]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [14.12.2010 14:41 1517376]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [1.8.2010 10:51 251736]
R3 MaBtPort;MA Bluetooth VCOM Driver;c:\windows\system32\drivers\MaBtPort.sys [21.12.2007 14:55 102272]
R3 MaBtVad;Mobile Action Bluetooth Audio;c:\windows\system32\drivers\MaBtVad.sys [21.12.2007 14:55 22990]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2.2.2011 21:23 89472]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2.2.2011 21:23 56536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [3.2.2011 18:19 33552]
S1 mailKmd;mailKmd; [x]
S1 MpKsl38b5dc63;MpKsl38b5dc63;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsl38b5dc63.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsl38b5dc63.sys [?]
S1 MpKsl4659c199;MpKsl4659c199;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl4659c199.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl4659c199.sys [?]
S1 MpKsl484feab8;MpKsl484feab8;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl484feab8.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl484feab8.sys [?]
S1 MpKsl73b8711c;MpKsl73b8711c;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AC209245-29F3-4BD6-95D5-C448A20FC1EA}\MpKsl73b8711c.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AC209245-29F3-4BD6-95D5-C448A20FC1EA}\MpKsl73b8711c.sys [?]
S1 MpKsl7cd78fba;MpKsl7cd78fba;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{59616143-F792-479C-B660-F44DB52DB280}\MpKsl7cd78fba.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{59616143-F792-479C-B660-F44DB52DB280}\MpKsl7cd78fba.sys [?]
S1 MpKsl7e12149b;MpKsl7e12149b;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{72371A8E-0EF7-4E18-B958-E15A83D6D465}\MpKsl7e12149b.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{72371A8E-0EF7-4E18-B958-E15A83D6D465}\MpKsl7e12149b.sys [?]
S1 MpKsl9d1cbabf;MpKsl9d1cbabf;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{1629FC2B-DC6A-44AC-B748-A09AC9249F1A}\MpKsl9d1cbabf.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{1629FC2B-DC6A-44AC-B748-A09AC9249F1A}\MpKsl9d1cbabf.sys [?]
S1 MpKsla1604b66;MpKsla1604b66;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{81566B12-45E2-4994-BC6E-70D5DF2A7220}\MpKsla1604b66.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{81566B12-45E2-4994-BC6E-70D5DF2A7220}\MpKsla1604b66.sys [?]
S1 MpKsla8fa49e6;MpKsla8fa49e6;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsla8fa49e6.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsla8fa49e6.sys [?]
S1 MpKsla98453fe;MpKsla98453fe;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{9A0BA89A-EBEF-4356-BD87-C2BFE111C0B7}\MpKsla98453fe.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{9A0BA89A-EBEF-4356-BD87-C2BFE111C0B7}\MpKsla98453fe.sys [?]
S1 MpKslcd8a1294;MpKslcd8a1294;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{8CC4EE05-42F8-4939-81AB-6C443ADC0151}\MpKslcd8a1294.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{8CC4EE05-42F8-4939-81AB-6C443ADC0151}\MpKslcd8a1294.sys [?]
S1 MpKslce4b28d2;MpKslce4b28d2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKslce4b28d2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKslce4b28d2.sys [?]
S1 MpKslf5b8c6c5;MpKslf5b8c6c5;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{27B42E4A-BA60-4375-AA51-EF3326962E0D}\MpKslf5b8c6c5.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{27B42E4A-BA60-4375-AA51-EF3326962E0D}\MpKslf5b8c6c5.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18.4.2010 17:40 136176]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 7\DfSdkS.exe [17.2.2011 18:20 406016]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [21.9.2009 18:19 36608]
S3 NANMp50;NANMp50 NDIS Protocol Driver; [x]
S3 P730C;P730C;c:\windows\system32\drivers\P730C.sys [21.12.2007 14:58 25300]
S3 P730M;P730M;c:\windows\system32\drivers\P730M.sys [21.12.2007 14:58 25300]
S3 P730U;P730U;c:\windows\system32\drivers\P730U.sys [21.12.2007 14:58 49365]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2.2.2011 21:23 56536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2.2.2011 21:23 125248]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2.2.2011 20:30 70536]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [13.8.2009 18:42 38976]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [23.12.2008 10:41 160256]
S3 Rts516xIR;Realtek IR Driver; [x]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [3.2.2011 18:18 366840]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service --> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [29.11.2010 19:27 10064]
S3 usbvm328;A4 Tech USB2.0 PC Camera F;c:\windows\system32\drivers\usbvm326.sys [22.2.2008 16:36 348160]
S3 vmfilter326;326 MRD filter service;c:\windows\system32\drivers\vmfilter326.sys [22.2.2008 16:36 483072]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [13.12.2007 13:10 118784]
S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]
S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [21.9.2009 18:19 233472]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - PCTSDInjDriver32
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-02-09 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-21 13:13]
.
2011-01-28 c:\windows\Tasks\GlaryOneClickOptimizer.job
- c:\program files\Glary Utilities\oneclickoptimizer.exe [2009-05-21 13:13]
.
2011-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 16:40]
.
2011-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 16:40]
.
2011-03-19 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe [2011-03-18 17:19]
.
2011-03-20 c:\windows\Tasks\User_Feed_Synchronization-{1EB9FB64-F7D5-4E4B-9C99-A6FF1FBEBD0D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
mStart Page = hxxp://www.pctools.com/mrc/fix_homepage/
uInternet Settings,ProxyServer = http=221.130.17.62:80;ftp=221.130.17.62:80;https=221.130.17.62:80
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
IE: Stáhnout pomocí NetXferu - c:\program files\Xi\NetXfer\NXAddLink.html
IE: Stáhnout pomocí USD
IE: Stáhnout vše pomocí Net&Xferu - c:\program files\Xi\NetXfer\NXAddList.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
.
------- Asociace souborů -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-SBAMSvc
AddRemove-Mozilla Firefox (2.0.0.20) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-Mozilla Firefox (3.0.15) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-Mozilla Firefox (3.0.19) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-SLABCOMM&10C4&EA60 - c:\windows\system32\Silabs\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-20 09:35
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\EncryptionInterface*]
"l_encryption_d"="585A4556465F"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="64724AC8CA559A2DEF15F1ED23AF4C828D3B788AE78BB64A904C81A6266C519D34077A0401A4F08B9A8607CDB4C600EE5C98840D32DE4E0B2162A17340FC67FD56D1F973B616FB7F6866CAA6433060F191BFB888BE5914C4B9081F01127CDEA3E4A6F1363474777533C3B33BA703C12DE89BF286160417EE16A6603A777EA0F93E0B743C43FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D6794A9C6AECB7A5D1407A6A0AC4980AC7933A4ADD3A7F4991B511FBDFA33CFA7C9FE836A1130E0059071CA64A025A5011E26577B6ACA1ABAD4D0F9F8D234B539E40F5508A411A82033AE86B1A4FEF4791187A2676CDF4EFCC65F829C1FD1D17C6961617368A78ACE86A2C772CAF7C3D9993CC557C6BCB19C556E0467C383615941592061D229FDC097C15277C2A8693E88E8F1D37DF91A3E3A733E3BB603D59BA95D7BB07111348A4B825FB4CDEDEEA186B6CC0DA5758EE581E7E22085CDD5F1B458D4DF66A08EA356621C433FE617679052F153E9CF4C008C4A19404D273AEFC83800926157236A45DFAA60027853D4F46CEC9C88ED445A0F9BFB6A4293118D9FF045112FFE3E1DF57E9EED13CB4C9159394303D37A192612619B12AB5F1AA54678E0472AA25D609AC6826E834BDCAC337167C4B1E0A67BF2A679CEE3974D789E4981C44290333E3CC2D00C78A79497CF52C5439C53F55462F68ED95C8D53285F61CBBDFB5C25213304FC942C55B7A64D9C3B05A3C5C98E65644393165889BD11C5D80A705C4FDA2F9CEB776A0CBB1422939933687295EC5306F8FCA9D28022127B33A5CAAC009FB325F4C916494FFC1480281C215683955AF402BEC119FEA7930CDCB1CCACB80895B866C5234B4FE23F3120329832EC137C4EA4A31E107DFE9C08C66F487EB08E02F802C79B16D0AA1475B08AAB8B66D38A349C9A925BAA420601DBC7A70A5216F5067A4F1CF39A9F5621F8DF4EAB31ABB04C98B404E5E8EA7D0E774867F93D62450AFA03D5EF286C1C8E120E859F474E6BBF3C2BEF5ECAD8854AE79E95BD421B1630202B8F592AA3D399051AEC38D45789BB9E5865361CCFF3D3F2A0D88868CCE3A77934214682BB3BA2CE27318B3A46B173493A07A5D976F14D51456851EA687C258D30F88D490CE68DE20196710D7BDB1C3D748BA3B559FCDCAC271054B642045F55D2964B4B543EC426157108943FD56E6BCD40F0146667AEA608318E71126F12BD75915F06B3FCB4F3742D2F4DBB3E29BDB0038D90F15770D2CB3F45EDF40B7C2694116E2EB1344C99D4480E69FC0C0D0C2DC6C1F6B3C5D43A79C2FD39EA75E2E5D15361AB36C5025812540DCA78076027F414164946819157BDD78590589F8DC5F1A963198FEACDE7A8F6580D834C6DD16085"
"OOCC06.00.00.01WSSV"="843D4D5FD15F23892C405683BECC08EE5946B5DEF1F79C67047E80BD4BE2E2BF3309490C22BFA016CFE84D49648A11B211C3B1C84CEE2DB4F9F150CB1E81818F605F19E3004B155789BC8226591AE25C527C0132C4B4D819ECAA9B06934AF4EEA8860B9DE33DEAAECEF4E170BCBD59FA0BC050AE42308C71E42FF3D97EE5DCA64FD8AEA6A8A790F33DE11E31928AD19350F49505149BB60F10952BEC11D65876B9C3D99E0BEE75F112E62E2542EAB01F591085AC68054C363F8E5A17E76E0B0FF04BA55BAE4C9168B07A4CBD969BDA86031F1C575451C39F67595E61FDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A9C6AECB7A5D1407BA7FD869164D6794EAE176F2AE953F4EC56374DF60F70C85E075120A63DF2CA00659B7B171A294EA5A101E831A67523403E1B44B91B56153A374E246D1154EB89FF492F80A392C903B470B9B62445DF4FCD49F1386119DB0685BADFE0D95F19387DBE34E23CDD6524406E1EE8C3E437A8C4CA886FA7C0572CE6CCF3BA4D65A90432015923DF6F03A7ED03BD531AC2216E05B34933A328D524CE99AA3B912FA71A9D707C6F0100DB148ACA2CB7CABC77DFD9A1950A5ADE56DA69DD5070344FCDCE89D0D92E9B46F89D12498F1AE1A344838A427F6332E6AC57A543A58CA2F3BDC830D6B42E64A9273A3C60F8A1B1A21713D1B9F636CB7B040B75FF6AAEED64960C94960433B74A40995A5707DAA94775B0A9E34956D93FEA722912CBA6105683AE8789828CD1D0744D5D998585BB2564A715911B3E74ED0A650457163A9C7131FDB4239291A744D05667CD549B96510651BF5D286A1B6D6D0B057512A61EEF42BF2D457A0AF6A430E1D2C6DA56D5EAAB9812409F9F361F31B80A647313690EE5C53E2FE0D32386587A38C1864AD95E1B7F197B9204CA73F5E5418C7C56C051614F522AF1257D4E57C77C20021C5C6223412885D2D2AA385D89495B754D7E9329A28CAD9F56C80A85CE97AC61D17EF116656B1627AA53645AAFB0CF16EE320BF19091CE8A34FBBC97A2263FEBA165502EB8A52A784E504B15B9B6AC3490F4DEF1D1056B32AF34E940E99ADB2034A7C0244CCAF046CA875B352D5A66F416B5AA51B03408B3C61C18B339D11DCA14F32CD54101140F6BFB565DD63382B529E747C6880A3B23233E2E3E94FC86CE5588458651CC0190E0FB5962FCF9D209EE38CBD3FF84DDF8418C58793A5134644264749A18A10BE3C92294BDBFA566DED09D7EBBEB00EBF5353C09379EAB2435413127A1C4A525734D4883BDC97E6252770CFBA68C13DEFE2BDEB5AC43A6EAE520BBE79C61FDD7BCB788F5110AED7CC5911B014A297B40397BF27DF870810499E8D6C8AFB9E0FB87932BEADB61D36DD"
"OODEFRAG11.00.00.01WORKSTATION"="18454B32E6CD8A4CFAB02D84F2FA9AB9A8658A6BF72068146CC949E372FD905E362F23C6D04B63CDED48BAF779AE6CB99FAD8D9F9352C3A270F731F12EFDB3C26EE2D98CAFC62D2E1E04BD61124F8C096D17BD2F7794AE47E349628B0D4CD280B12CA680B0D352D204239CB4803023D42E6E4BA69F1AAD17A53EFAF6DA9D6EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A6A0AC4980AC79339DB7CE019D40AA5C3C1AE4DB208DC64CBAEB33AD781F35BDB6F551E69E86E9D00051E749A0AD813386C1E3D98A0C34CB5DB58BA2B34BF7604E07A4BA96BAA888771EAB243D084EF2874F9CF6BBD666FBF118C7E13A9B438D512CB3721151F8D7BC459DB4EDF663544253F59B96DF2998E6ECFD41AA55647EB622E9730587C916EC0A190D254A6EE821B5DBA424AC8C910C5E4D8A4553EC9F5AF7B2120F2ACD4B0D01FBAE74666276EFB0BD649056E40A986DD47CEF83B2117814039A6C1DF8B48394A994954277785E548F9DAE8A4B59A3ECB9483667CDA8342FCCCC00D987441C010828E3ECA81E8181498CF109998B2D83A414C4969BEC15D58B59D1E876A006D982CA5F0434C8D1F0E5DA74A9716094AF42FA6CBA3E9B84E73DE98BEB8822D48407502A3D1D102B2C64ABF2D2B6C9A0BE430AA5929825CF9C6398FC1443577F3A09010F60ACBD4F92C9134C0412F1F9575CC20970D62EABF902F3992AF17F63897F98F7C86CCFE0579D9A874DEE32AEEDC59B5439E38EAD5E257FF5872292BC53E3C6F5682B79687F6ABFCCD3FD1A2ED0BC006969F1D34FF9D8B1CE1E253AB0CEB42F3CC3FCA154E6C172E9D2B2EED09D02CB4E0DF43CEF5130F5836F9151C704766BA371B76272BC3597CD154626CD4A59532EC7A740D13EBEAB1513426BEA51AD86261E7889F8045D0A8FFCB36DC31D0BD9D4CE06059A6C1F252CB455CEEBE7E601E40B9D1BFE92D615E5003C22B432659BB46ED168555D702A92932CF2FCCF2F4D248C49CC8213BF7A30A6E35983F9B8C665828FFA70E5D27538026D8634609955CB896409E285BC6FEC8FF1D97BB7D8FA9EFE8A803FAE6BB52FE8046A8FC8BD7566FE98ED643B741C436A731F49031FD0BFE94C727633E48EAD429CB56D8AB57BA57DD5CF2F5C931E7AFD37597FC868D1495DA8FCB0C56D96909D293090FA1F2DDBA84F33D0E1C80780A2536B91C694F9E287B480ED0C3558551F61D721C49EC282B97B54399CC8DA65C51EECDA9287BD552AC7128E7C72539FFB3FDEA964D8E534FB95A0BC2E4A925E68352A1713AB030E1C0179DA64DF7BB5027F299A2CF939B1501D3A148E899B4421F82269836DA120C74133FB6639B6820F2652C642AFCF5E2B5678DA85C6D714978B8755F5BCE941ABABF07F"
"OODEFRAG12.00.00.01PROFESSIONAL"="99A79F148C28ED12C237F129029AD0B610B579E3482266AF2558B2837DCEC6F461B3C2E0C927E8F09A0829529E5C9C10F04D82E994C118A2A41DDAFCCC1B0D0C0DE48DF66A3CD8C793EDBF881A6D3BB143AD579F21B0A130E269982C0F49051BA930C0376B18CC04FC1C3CD47E4C5242B6656851AB5A65541249E6C1524DE7128A3FFCD847DE792BE7770C0FDCE831F8C1390B1E739CE89CA6FE24C4A79316F4456E4CE404A836D52C9B7EE7472848A49A21F8793EC8D5ACDAFD120D27FA135933D018392781003066D7C9E15764ABA53D474F2B5426FB39AA6F5746665683EB73AA3108BB6975F9F4AC0453FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452BA7FD869164D6794C038D530D6EB3452F02C351249CE3E2DC448B9A4CBEBA5C4EBFDC9D63259B56CD5543FC7966C84180A264F1D4FD1F365D7FB6F3F3251E58721B9D3F2DB637B01B11BF73014926BA521003C59BA34DFFC4D8B0CB744E8EBE0DE8B9B504D750F7EE0B9307E31E1C41668C3FB6A40F3A89CC72E0946F9EDA81F56F833DBDD27C7F8C82330F6466FF16195F130895BC1D9C36D9081358ECDEFE23FFA4E182A446557CF3DE7EDF0823AD461FBA07F490563C2E9D134667FABFA25D5FEC69813CB08D765E2E84E119847910BC8382E0DD597BFEA0687CD915DE5B05AE419083B71B40977E06817CDE1280B523485066B032FB4A33681744BEE32230F0266230B1CD54DFC79405A10434F8A7E8DBB90700C45EE4BDDCE74F79DC1703C9FF2BB2F69385E6C62EEBC035492AD59173267E9A758919BEB3F01265C5EDDAEFA283619A78DC6C447167A19E12CE4AE09623B68C04C90D3C5C65C2AD1B507B3C4148B7BD8EA6684C47BE0096D3BF4D00C6C4EC2716936B543FC5F9AD8D5DAA122654A4D37C97232ED095348AAC1F597411378148E59A109309EF5527EB49C4E2CF2134D2C87F0D5C74DC61882A7D4D83CBC253A9CAD43174C0AA07087A96215EFB31BF9D8E5BEFA4CF9C6F691B453F501F4D356D358E0AFCC447458687296D66EC6AC978E0A8B3469E3EF2AA798854D8DE916CF2330952558759832CC2F79F69C6BA2AF577D5A148207F5BB4965D4C74F6F95D0AC724D4E8C68C96713631CDCE386710CED2E8435EB7E9EF8B0127DCCAAFB0CC6C33DCA06760E5828CDF7E57420221C3FC1EB33B2F00F447248F98FC9752AC8E2F394242A1D79A8E7C2B711AC24EA3B1B756D682E4F9B547D31D87033FA39301D795FC11EF66332DCEC562EF9B231FE3AE04CF64CB8315333415359FAFA8BB7AFC6E8E3C771A702027BE51E5487E927771184873553FB55707F6E579C26A8EC1700E099136BC5B997506019364D2E08F1C2799415B84E85D6A8954996273BEC"
"OOCC7.00.00.01PROSTATION"="7E3FCDF198260ABB56E58D80DF70ECF9E5D4647C0F7BEC4EBC65CB80CB7F6A0531626D639204E3DCCE48F34B85E4EE1F938CAB46196003C6FC7BF17E83BF8F35E29DF8770084E0F6A3B653D7E6ADE220214ED9CD900C1EAC904BD67B0D1E96FB911D0B759F8976529D75FCD01E997F74459715400E54584A39AC16C59D9AA3152CB056EFE35C69BC7A6FD4A67A59511AA80A970E5CF4A2EB2F98DD6E1F9AA9BF18CB1D38F4AA5602EA2E56100002B612E9ECB06D7D0CC3E29B2FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA6A0AC4980AC7933A9C6AECB7A5D140735B8BAA50EA15906BB05DEA2C3BCA944CA00EB9B397E96832732C84ED101A05CA44199199435CEB14B0D5E12FA8E338AC3DF6E240634CCFC182D31C627CEAEAA485CBFBD7AD88445A4ACBF6B4B89573105A09E367345AEAA437C8FF77A2B7A7F0F5667FE96A650608D313AA5F2997930CAAF52F2438E4E7A78D0F7C9B10260E67F3E022F97BA7B43E02A3A1C01AA70A264BD14DC8AEC2E031D1D310A88C2B28B336932057A35C5D58BECE08ADAB00746354420DBB543C6F9271733680CE1B43FD66F4F17143A60A0911503163A9EFC7E3479693A00F9833B26BAAE79A156A2F52BAC65E50C73705108FDA8C2AA6F83D2EB5E14A8FC7AC54837478535FD1CA5C987423350DD0E91BA99C78EFC0E2144ECFC347A391132614490C0CD792CB161765292AC9DDA39D0D28459241217B5589C9981296576169CF6F8ECD3048A1CE9DD0BC5F976242B30339BDA10B3D030CF548A10E2063A1C354CCED714FA4EE248054149F4E7B31BA51943BAAAF9179DACACA9EC9CDB40BDDAD380CFC2677C11F9939C4D30E3D4461C67F728FD5E9A0966DD67EB7F8B3CF9B1C19368C3B3EE376F5754C56B3F276E7023C799CCBFE00669C745236A99B8D5506E9FF9B4B1D5670FC137E8A0341D5676F6D2C80BDF412992EE5B6B6DF314D3C4D5D01EE216B33B2FE52536FADE80C6F0B1523261E5698BB577D5644EE7FE038E966833CF785ECD1FFE926BD9C16D8D1EC20F952B5B5ACC1B2F73EE082B7FEE2175395FB3D4823D1F670C0DCF42D07BA841667AFB30680DFB03863246536F2BE45B2D07F78C9DAFE4A2AC642629F0E334E74CA894B43DF108857797EADB7E4E35D1BED63C64824A9854A5FBD72565215613462EEF20D4A5E26F42CD8CA52BF3630B00BDD183D73A57453CA59345980F98C6EE5A390E7FD5A29A74477373CC3932D8136D3FF699AE3362CA73BD804B8D7A2774C3D1FAE2345206B1391EEB8DC15A35B2DEC0AE94DBAFBB3E406C3191016B7D18444E4B77F471D4321EBC1B6AB3073B294DC100EDF7C60816266D9252D3D43A31F7F6430AD4F24D4035B6EF37BA"
"OODEFRAG14.00.00.01PROFESSIONAL"="FA27199735FDA3C25D7DF0ECC9FA2202210B2ADEE130C1CF78EC4846B4B48060B1FC6D390DF6AC116CB71CBCC3CA2B0054F910B8C9CB5CEF7D03214D421009FABED33DEA2FA25F9AA7D1EEBE26D9FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D67945D575E7D6A3B98089DB7CE019D40AA5C71F69F66420FF8302AA28358302A656D53DB2D71C7B8B7F9958DB9D5BCC6D22E67C132EB43F69E6411A6800D8F70BE48B4677377F22066F57149CC1A7CBD2AEB8EA7E62CB4AD6DCC3D33E515E02B5FEBE3887DA4594581320095BC20F1AD45CA90CAF7146ECFB3A619A437800C41AA4CACFAB7509480A5F40E2901A306FA1A84DB8107654AED5FC1D48EDC37FC1329EB1F2F73A5401B96192C72F2B4A6FB46E8A25416B6A68B068263B72373A2ED09E58FC7E724FDD1398B3092D1B8467B865BDA800D706721DD60FA1A3A4571991BE5961CAB21F1D8165132DA3E68D9B8BE52BE77B652F09A446917E4370EDFCD532F0FB83F43C5545D7D90D641515B6775DA4C6043EB3056393C77F89185EAB8CA95995C0107A3DF60BB6BC2C252482D5592C59345A4922C5F0E1F6EA6B692F93F831BF9393BBE8894CA298C93A222272E2D311F35B50B607F26548F367FD82791753B3B8F04CACF93FC72DB64C8EEE1F1F2D843EC2C11B00562A3DA669346C845FC667991D981AC9BB633874CA238E1B8BDCBF62DEB1ECC80B15B02BCF7665D043F4CC431871C898E749D1D45618B9E3BFC5AE399A8B1D925198EECA60949549BF4E061422EDF43F243285CAD88F9825AB41B65B7ECCC6DCAB0953576F581937B6C5D4580BF0E2D7146093948F21BEB19FB698FF4967896EDA489A9DD3FA774B886BC1E0906708CD8B3405E3BCA852E9CFDE2A71F573D522EB5CB4DF6BE58C20EB840CA5B1BD41B1CD58D2591925A91B17AE8A46B34AB1750B67DD53E1CB040D60CEBDD5E6F09864E0975A0B81FB7CE464423B67009554BBA9206AD1259D5A2931D079FDAC565722BC1C2958398C6976CC1FABE2881D04B7AC2927439C6EF126A1E1E8A7E38BEF3910602FA29FA2F8C5D6F1E52F320B8683ED890FB5B0C292BA35481505BB07594026F83FDC2999D4672DC7E3A963B2C65DB78334A84A3337FAB194552657067D3A12C5C7ECE96464FAA2CD27437FACDF9C9DBF11AA55C401594594129F70A7922BB00E792B1EB5D27A89516B3615FC3D323CC885B92D88763129692A0CD6495E53E3FC101AFE59C403463055A843839102A2DF4AE8391C5D8FD6598370B3DA879B955C947F226C18137F52305F3AC5DC64170FA6C954FBA5554EF7721B323A12B6540A7950CA08EC541BFB480E736E17CF09FA21EC930292EB6731846307B76BC1B9243D06B9F485D05C8C54E"
"OODI05.00.00.01PRO"="2354FEE84798D27738C179DC3776FCBBD8C68FAE93492F955AA3B4D57550038A86D186DD04AFC6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794A9C6AECB7A5D1407A6171C11EC38DE3D786C020EDC3D05CEC7EB50EFB2B7628CCCD60E81C61B6CA207ED2965FA6B12CE107F7AC9194CEF9B25B457AF055BCCEA8C6F003ACA12DF92C4B84693F243738583C19CDEAD184F0E8AEEE8384CAF749842F8A2C88440AB8D2E98D0EC8E4E5EBD2C49C55F0A7447590613BA03BABA6D00D0EC2E300C79ED559BA71C996B539D30F57184BEF0397150B85DB86EDA84BB2EAD088756CE98B952F8C4AC2B7B9C70BEE0581956F84259ECD74D82BA06995956E2CCCD850E7A968DC4113D9385790D6D8063FB628C6E01CB2D276C0EEC0B354C0F7ECFECDD817E3791733A2C22BB9962FE37D6816A22DC2D14F3FC71136C328CE5A8139F289261A2881545AE40BAB2EA964109BA27C3D6F6017F705251D724B2AB95CF912718A2C5E2E5B43BA0D1E8F7192F24F4A6BFCCB1F5593583D1E8D602BA58F21EEE00173A71171155D9DDBF9BE874EEFC26070D8A8E56EFB715C0875F03461C85E13B0DC1961E18E3D5C2AE8D8148E483B30CDED1F50F780B6F84E756057721E7B93FC03EC9363B32D06623ABEBA6321CB045F97CEF5E587888DB9F93D8C9894D030667B5175CA0EFDD34FB74C9CCBBBFD5B00DA3CF645163DBF2C6E8275D121E1E8D26D39C54A1B0621B8D0CCF3F184AACCCB6840006559038FCECCC2E98AB2B40D699688E224C6B988CA0BA46C590FC151D8E7F7D6C8D28C2AB92D7C1A47A2573E7CEE3B312DFFB8E7F6F6A8769A37C41A99B99598154B9F33AAFC9C76D5623124ACADEE73254A224EE2C2F07FB83CF377D5CFB3977B83594632D84B8A5CD9FCE8B049319D2D28090D9F8B8C60F19E35229C0F3D5C00070C7E7680CA4411FF8AC3E64E2CB8AB89FDD426FE05FF87C8A42BFAD717C961FA4008DB38B2DF940F086F6CC4C17B41668E92F9A237DD67C7688D87D0A0F74456F041D56D089CB582E87508FF9266F322DE52BF99FE0071DBF7D107CF5829BCD5270E109CD02F9C5BB31667234B81C051FD7C4831B5F2C93E44906EA13608FCF32352D7A19F6081807585C32EB21E03E57988F1EFB5FADCAC4ED5D7F62C41890D996D3CC6A59BF936326D7FD33C629BED057A0254FDDB661233B3E628662420C74AA2E95A230AEB187950076C0A5211A6A1513E9436B37A8A9D9D3AF4BFDDC72945F195EC094251E8C788635EECC3B1C672807AFAD2CE12AE4434EF81C717D27B0F2F427EC37B83AF0741AC3BD5F2FC0EFB89C2E05572D1DC4C7E0C40A29FA4120F9A7DFEF5742981902F1A2509476BB8EC7FC13E6BB54729D09C30A4A27"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
@DACL=(02 0000)
@="Bezdrátové"
"ProcessGroupPolicy"="ProcessWIRELESSPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75}]
@DACL=(02 0000)
@="Group Policy Environment"
"ProcessGroupPolicy"="ProcessGroupPolicyEnviron"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyEnviron"
"ProcessGroupPolicyEx 0"=""
"EventSources"="(Group Policy Environment,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-1"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{17D89FEC-5C44-4972-B12D-241CAEF74509}]
@DACL=(02 0000)
@="Group Policy Local Users and Groups"
"ProcessGroupPolicy"="ProcessGroupPolicyLocUsAndGroups"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyLocUsAndGroups"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExLocUsAndGroups"
"EventSources"="(Group Policy Local Users and Groups,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-2"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{1A6364EB-776B-4120-ADE1-B63A406A76B5}]
@DACL=(02 0000)
@="Group Policy Device Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyDevices"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDevices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDevices"
"EventSources"="(Group Policy Device Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-3"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@DACL=(02 0000)
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"=expand:"fdeploy.dll"
"NoMachinePolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"NoGPOListChanges"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"=multi:"(Folder Redirection,Application)\00\00"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]
@DACL=(02 0000)
"Status"=dword:00000000
"RsopStatus"=dword:00000000
"LastPolicyTime"=dword:00e2f997
"PrevSlowLink"=dword:00000000
"PrevRsopLogging"=dword:00000001
"ForceRefreshFG"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@DACL=(02 0000)
@="Disková kvóta Microsoft"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=expand:"dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}]
@DACL=(02 0000)
@="Group Policy Network Options"
"ProcessGroupPolicy"="ProcessGroupPolicyNetworkOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetworkOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetworkOptions"
"EventSources"="(Group Policy Network Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-4"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@DACL=(02 0000)
@="Plánovač paketů technologie QoS"
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"Status"=dword:00000000
"RsopStatus"=dword:80070032
"LastPolicyTime"=dword:00e2f997
"PrevSlowLink"=dword:00000000
"PrevRsopLogging"=dword:00000001
"ForceRefreshFG"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
@DACL=(02 0000)
@="Skripty"
"ProcessGroupPolicy"="ProcessScriptsGroupPolicy"
"ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx"
"GenerateGroupPolicy"="GenerateScriptsGroupPolicy"
"DllName"=expand:"gptext.dll"
"NoSlowLink"=dword:00000001
"NoGPOListChanges"=dword:00000001
"NotifyLinkTransition"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@DACL=(02 0000)
@="Internet Explorer Zonemapping"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"NoGPOListChanges"=dword:00000001
"RequiresSucessfulRegistry"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{5794DAFD-BE60-433f-88A2-1A31939AC01F}]
@DACL=(02 0000)
@="Group Policy Drive Maps"
"ProcessGroupPolicy"="ProcessGroupPolicyDrives"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDrives"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDrives"
"EventSources"="(Group Policy Drive Maps,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-5"
"PerUserLocalSettings"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6232C319-91AC-4931-9385-E70C2B099F0E}]
@DACL=(02 0000)
@="Group Policy Folders"
"ProcessGroupPolicy"="ProcessGroupPolicyFolders"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolders"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolders"
"EventSources"="(Group Policy Folders,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-6"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=""
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}]
@DACL=(02 0000)
@="Group Policy Network Shares"
"ProcessGroupPolicy"="ProcessGroupPolicyNetShares"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetShares"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetShares"
"EventSources"="(Group Policy Network Shares,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-7"
"NoUserPolicy"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}]
@DACL=(02 0000)
@="Group Policy Files"
"ProcessGroupPolicy"="ProcessGroupPolicyFiles"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFiles"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFiles"
"EventSources"="(Group Policy Files,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-8"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{728EE579-943C-4519-9EF7-AB56765798ED}]
@DACL=(02 0000)
@="Group Policy Data Sources"
"ProcessGroupPolicy"="ProcessGroupPolicyDataSources"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDataSources"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDataSources"
"EventSources"="(Group Policy Data Sources,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-9"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{74EE6C03-5363-4554-B161-627540339CAB}]
@DACL=(02 0000)
@="Group Policy Ini Files"
"ProcessGroupPolicy"="ProcessGroupPolicyIniFile"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyIniFile"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExIniFile"
"EventSources"="(Group Policy Ini Files,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-10"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
@DACL=(02 0000)
@="Internet Explorer User Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=expand:"scecli.dll"
@="Security"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:000003c0
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325}]
@DACL=(02 0000)
@="Group Policy Services"
"ProcessGroupPolicy"="ProcessGroupPolicyServices"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyServices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExServices"
"EventSources"="(Group Policy Services,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-11"
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
@DACL=(02 0000)
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
@="Internet Explorer Branding"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3014"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A3F3E39B-5D83-4940-B954-28315B82F0A8}]
@DACL=(02 0000)
@="Group Policy Folder Options"
"ProcessGroupPolicy"="ProcessGroupPolicyFolderOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolderOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolderOptions"
"EventSources"="(Group Policy Folder Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-12"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{AADCED64-746C-4633-A97C-D61349046527}]
@DACL=(02 0000)
@="Group Policy Scheduled Tasks"
"ProcessGroupPolicy"="ProcessGroupPolicySchedTasks"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicySchedTasks"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExSchedTasks"
"EventSources"="(Group Policy Scheduled Tasks,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-13"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B087BE9D-ED37-454f-AF9C-04291E351182}]
@DACL=(02 0000)
@="Group Policy Registry"
"ProcessGroupPolicy"="ProcessGroupPolicyRegistry"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegistry"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegistry"
"EventSources"="(Group Policy Registry,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-14"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=expand:"scecli.dll"
@="EFS recovery"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@DACL=(02 0000)
@="802.3 Group Policy"
"DisplayName"=expand:"@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=expand:"dot3gpclnt.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}]
@DACL=(02 0000)
@="Group Policy Printers"
"ProcessGroupPolicy"="ProcessGroupPolicyPrinters"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPrinters"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPrinters"
"EventSources"="(Group Policy Printers,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-16"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}]
@DACL=(02 0000)
@="Group Policy Shortcuts"
"ProcessGroupPolicy"="ProcessGroupPolicyShortcuts"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyShortcuts"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExShortcuts"
"EventSources"="(Group Policy Shortcuts,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-17"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@DACL=(02 0000)
@="Microsoft Offline Files"
"DllName"=expand:"%SystemRoot%\\System32\\cscui.dll"
"EnableAsynchronousProcessing"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@DACL=(02 0000)
@="Instalace softwaru"
"DllName"=expand:"appmgmts.dll"
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoBackgroundPolicy"=dword:00000000
"RequiresSucessfulRegistry"=dword:00000000
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"EventSources"=multi:"(Application Management,Application)\00(MsiInstaller,Application)\00\00"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
@DACL=(02 0000)
@="Internet Explorer Machine Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@DACL=(02 0000)
@="Zabezpečení protokolu IP"
"ProcessGroupPolicy"="ProcessIPSECPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}]
@DACL=(02 0000)
@="Group Policy Internet Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyShortcuts"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyInternet"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExInternet"
"EventSources"="(Group Policy Internet Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-18"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}]
@DACL=(02 0000)
@="Group Policy Start Menu Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyStartMenu"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyStartMenu"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExStartMenu"
"EventSources"="(Group Policy Start Menu Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-19"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E5094040-C46C-4115-B030-04FB2E545B00}]
@DACL=(02 0000)
@="Group Policy Regional Options"
"ProcessGroupPolicy"="ProcessGroupPolicyRegionOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegionOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegionOptions"
"EventSources"="(Group Policy Regional Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-20"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}]
@DACL=(02 0000)
@="Group Policy Power Options"
"ProcessGroupPolicy"="ProcessGroupPolicyPowerOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPowerOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPowerOptions"
"EventSources"="(Group Policy Power Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-21"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F9C77450-3A41-477E-9310-9ACD617BD9E3}]
@DACL=(02 0000)
@="Group Policy Applications"
"ProcessGroupPolicy"="ProcessGroupPolicyApplications"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyApplications"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExApplications"
"EventSources"="(Group Policy Applications,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-15"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"crypt32.dll"
"Logoff"="ChainWlxLogoffEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"cryptnet.dll"
"Logoff"="CryptnetWlxLogoffEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
@DACL=(02 0000)
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
@DACL=(02 0000)
"Asynchronous"=dword:00000001
"DllName"=expand:"%SystemRoot%\\System32\\dimsntfy.dll"
"Startup"="WlDimsStartup"
"Shutdown"="WlDimsShutdown"
"Logon"="WlDimsLogon"
"Logoff"="WlDimsLogoff"
"StartShell"="WlDimsStartShell"
"Lock"="WlDimsLock"
"Unlock"="WlDimsUnlock"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@DACL=(02 0000)
@=""
"DLLName"="igfxdev.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
@DACL=(02 0000)
"DLLName"="c:\\program files\\common files\\logishrd\\bluetooth\\LBTWlgn.dll"
"Asynchronous"=dword:00000000
"Startup"="OnStartup"
"Logon"="OnLogon"
"StartShell"="OnStartShell"
"Logoff"="OnLogoff"
"Shutdown"="OnShutdown"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
@DACL=(02 0000)
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=expand:"sclgntfy.dll"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
@DACL=(02 0000)
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
@DACL=(02 0000)
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=expand:"WgaLogon.dll"
"Event"=dword:00000002
"InstallEvent"="1.9.0040.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
@DACL=(02 0000)
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
"ASPNET"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(524)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\netprovcredman.dll
c:\program files\PC Tools Security\TFEngine\TFMon.dll
c:\program files\PC Tools Security\TFEngine\TFRK.dll
.
Celkový čas: 2011-03-20 09:43:44
ComboFix-quarantined-files.txt 2011-03-20 08:43
.
Před spuštěním: Volných bajtů: 29 649 637 376
Po spuštění: Volných bajtů: 29 626 990 592
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=6K5HAP /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=6K5HAP-BAK
.
- - End Of File - - 6BF7A6F814DD473D869118716D61879A
ComboFix 11-03-19.03 - Jirka 20.03.2011 9:21.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1246 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jirka\Plocha\ComboFix.exe
FW: Internet Security Firewall *Disabled* {2BF21FEC-A5BE-424D-BDD7-3229CC84ED22}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\page
c:\documents and settings\All Users\Data aplikací\page\page.ico
c:\documents and settings\All Users\Data aplikací\page\page.URL
c:\documents and settings\All Users\ntuser.pol
c:\webupdater\WebUpdater.exe
c:\windows\AutoRun.ini
c:\windows\d.ini
c:\windows\system32\csftxctl.ocx
c:\windows\system32\drivers\FSC__PI__ESPRIMO Mobile V5505 __FUJITSU SIEMENS_ESPRIMO Mobile V5505 __Ver 1.00PARTTBLM_FSC - 6040000_R01-A0W .MRK
c:\windows\system32\zip32.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-20 do 2011-03-20 )))))))))))))))))))))))))))))))
.
.
2011-03-20 06:51 . 2011-03-20 06:51 -------- d-----w- C:\rsit
2011-03-20 06:02 . 2011-03-20 06:02 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKslb2470c1c.sys
2011-03-19 19:23 . 2011-03-19 19:23 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKsle723e2ae.sys
2011-03-19 19:23 . 2011-02-11 06:54 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\mpengine.dll
2011-03-18 21:52 . 2011-03-18 21:52 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\IObit
2011-03-18 21:52 . 2011-02-23 15:54 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-03-18 21:52 . 2011-02-23 16:04 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-03-18 21:51 . 2011-03-18 21:51 -------- d-----w- c:\program files\IObit
2011-03-17 19:55 . 2011-03-19 22:28 -------- d-----w- C:\Conspiracy Theory with Jesse Ventura
2011-03-15 20:09 . 2011-03-15 20:12 -------- d-----w- c:\program files\NutsAboutNets
2011-03-12 19:15 . 2011-03-14 19:44 -------- d-----w- C:\axaxax
2011-03-11 18:15 . 2011-03-11 18:15 -------- d-----w- c:\documents and settings\Jirka\Local Settings\Data aplikací\Kolor
2011-03-11 18:14 . 2011-03-11 18:14 -------- d-----w- c:\program files\Kolor
2011-03-11 17:07 . 2011-03-11 17:07 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-25 21:28 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\Leadertech
2011-02-25 21:28 . 2011-02-25 21:28 53248 ----a-r- c:\documents and settings\Jirka\Data aplikací\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-02-25 21:28 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\Jirka\Local Settings\Data aplikací\Logishrd
2011-02-25 21:28 . 2011-03-09 16:52 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-02-25 21:25 . 2010-08-24 17:30 10448 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2011-02-25 21:25 . 2011-02-25 21:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Logishrd
2011-02-25 21:25 . 2011-02-25 21:25 -------- d-----w- c:\program files\Logitech
2011-02-25 21:20 . 2011-02-25 21:21 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\Logishrd
2011-02-25 20:51 . 2011-02-25 20:51 -------- d-----w- c:\program files\PowerISO
2011-02-25 20:43 . 2011-02-25 20:55 -------- d-----w- C:\f2e68d3c69ec0e37226d12
2011-02-25 20:24 . 2011-02-25 20:28 -------- d-----w- C:\1bc24d913a575e916ab87aa8
2011-02-25 19:06 . 2008-10-29 06:28 221184 ----a-r- c:\windows\system32\RaCoInst.dll
2011-02-25 19:06 . 2008-10-29 06:34 644096 ----a-r- c:\windows\system32\drivers\rt2870.sys
2011-02-22 20:32 . 2011-02-22 20:34 -------- d-----w- c:\documents and settings\Jirka\Data aplikací\TrustPort
2011-02-20 07:56 . 2011-02-20 07:56 -------- d-----w- C:\Log
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-11 06:54 . 2010-11-14 07:13 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2007-08-07 14:14 270848 ------w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2007-08-07 14:14 186880 ------w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2007-08-07 14:28 2067456 ------w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-08-07 14:28 677888 ------w- c:\windows\system32\mstsc.exe
2011-01-23 07:54 . 2008-05-29 18:05 741692 ----a-w- c:\documents and settings\Jirka\Data aplikací\mdbu.bin
2011-01-21 14:44 . 2007-08-07 14:14 440320 ------w- c:\windows\system32\shimgvw.dll
2011-01-17 08:11 . 2011-02-02 20:23 125248 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-01-17 08:10 . 2011-02-02 19:31 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-01-12 11:04 . 2011-01-12 11:04 535880 ----a-w- c:\windows\system32\oodssrs.dll
2011-01-12 10:36 . 2011-02-02 20:23 89472 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-01-07 14:09 . 2007-08-07 14:14 290048 ----a-w- c:\windows\system32\atmfd.dll
2011-01-07 13:54 . 2011-02-02 20:20 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-01-07 13:54 . 2011-02-02 20:20 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-01-07 13:54 . 2011-02-02 20:20 2000848 ----a-w- c:\windows\PCTBDCore.dll
2011-01-07 13:54 . 2011-02-02 20:20 767952 ----a-w- c:\windows\BDTSupport.dll
2011-01-06 10:54 . 2011-02-02 20:20 2125 ----a-w- c:\windows\UDB.zip
2010-12-31 14:04 . 2007-08-07 14:15 1854976 ------w- c:\windows\system32\win32k.sys
2010-12-31 08:36 . 2011-02-03 17:19 69392 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2010-12-31 08:36 . 2011-02-03 17:19 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2010-12-31 08:36 . 2011-02-03 17:19 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2010-12-22 12:34 . 2007-08-07 14:14 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2007-08-07 14:15 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2007-08-07 14:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2007-08-07 14:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2007-08-07 14:14 729088 ------w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2011-01-06 19:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2011-01-06 19:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2007-08-07 14:14 385024 ----a-w- c:\windows\system32\html.iec
2008-07-25 08:31 . 2008-11-26 20:02 28672 ----a-w- c:\program files\mozilla firefox\components\flashgetXpi.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\Jirka\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2011-01-28 1239040]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 90624]
"iTV"="c:\program files\iTV\iTV.exe" [2011-03-17 623616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-10-02 1191936]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-10-02 1368064]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 221184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496]
"Hard Disk Sentinel"="c:\program files\Hard Disk Sentinel\HDSentinel.exe" [2010-12-27 3913216]
"ClipX"="c:\program files\ClipX\clipx.exe" [2005-11-30 68608]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2009-12-18 22486]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoRecentDocsNetHood"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"SignupShield"="c:\documents and settings\jirka\dokumenty\my programs\signupshield\bin-06-02-07\SignupShield.exe" /e"1"
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe"
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe"
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"HotKeysCmds"="c:\windows\system32\hkcmd.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\ANWSOFT\\CAMagic Mobile for Bluetooth\\LiveCheck.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsvsvr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Xi\\NetXfer\\NetTransport.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Jirka\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"50629:TCP"= 50629:TCP:utorrent
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"1518:TCP"= 1518:TCP:Akamai NetSession Interface
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [21.11.2009 9:16 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2.2.2011 20:30 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2.2.2011 20:31 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2.2.2011 20:31 656320]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [18.3.2011 22:52 13496]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.5.2008 16:17 691696]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [3.2.2011 18:19 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [3.2.2011 18:19 69392]
R1 MpKslb2470c1c;MpKslb2470c1c;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKslb2470c1c.sys [20.3.2011 7:02 28752]
R1 MpKsle723e2ae;MpKsle723e2ae;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E11B1EC6-4665-4091-881F-0C998EA0F373}\MpKsle723e2ae.sys [19.3.2011 20:23 28752]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2.2.2011 20:31 251560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41 67656]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [29.1.2009 18:03 13360]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [2.2.2011 21:20 247760]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [25.2.2011 22:25 10448]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [28.4.2010 21:56 63488]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [20.10.2009 19:19 50704]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2.2.2011 20:30 160448]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [29.1.2009 18:03 69168]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [14.12.2010 14:41 1517376]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [1.8.2010 10:51 251736]
R3 MaBtPort;MA Bluetooth VCOM Driver;c:\windows\system32\drivers\MaBtPort.sys [21.12.2007 14:55 102272]
R3 MaBtVad;Mobile Action Bluetooth Audio;c:\windows\system32\drivers\MaBtVad.sys [21.12.2007 14:55 22990]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2.2.2011 21:23 89472]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2.2.2011 21:23 56536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [3.2.2011 18:19 33552]
S1 mailKmd;mailKmd; [x]
S1 MpKsl38b5dc63;MpKsl38b5dc63;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsl38b5dc63.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsl38b5dc63.sys [?]
S1 MpKsl4659c199;MpKsl4659c199;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl4659c199.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl4659c199.sys [?]
S1 MpKsl484feab8;MpKsl484feab8;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl484feab8.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AA260F0E-E05E-4B65-B479-2256B91EBD9F}\MpKsl484feab8.sys [?]
S1 MpKsl73b8711c;MpKsl73b8711c;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AC209245-29F3-4BD6-95D5-C448A20FC1EA}\MpKsl73b8711c.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{AC209245-29F3-4BD6-95D5-C448A20FC1EA}\MpKsl73b8711c.sys [?]
S1 MpKsl7cd78fba;MpKsl7cd78fba;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{59616143-F792-479C-B660-F44DB52DB280}\MpKsl7cd78fba.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{59616143-F792-479C-B660-F44DB52DB280}\MpKsl7cd78fba.sys [?]
S1 MpKsl7e12149b;MpKsl7e12149b;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{72371A8E-0EF7-4E18-B958-E15A83D6D465}\MpKsl7e12149b.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{72371A8E-0EF7-4E18-B958-E15A83D6D465}\MpKsl7e12149b.sys [?]
S1 MpKsl9d1cbabf;MpKsl9d1cbabf;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{1629FC2B-DC6A-44AC-B748-A09AC9249F1A}\MpKsl9d1cbabf.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{1629FC2B-DC6A-44AC-B748-A09AC9249F1A}\MpKsl9d1cbabf.sys [?]
S1 MpKsla1604b66;MpKsla1604b66;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{81566B12-45E2-4994-BC6E-70D5DF2A7220}\MpKsla1604b66.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{81566B12-45E2-4994-BC6E-70D5DF2A7220}\MpKsla1604b66.sys [?]
S1 MpKsla8fa49e6;MpKsla8fa49e6;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsla8fa49e6.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKsla8fa49e6.sys [?]
S1 MpKsla98453fe;MpKsla98453fe;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{9A0BA89A-EBEF-4356-BD87-C2BFE111C0B7}\MpKsla98453fe.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{9A0BA89A-EBEF-4356-BD87-C2BFE111C0B7}\MpKsla98453fe.sys [?]
S1 MpKslcd8a1294;MpKslcd8a1294;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{8CC4EE05-42F8-4939-81AB-6C443ADC0151}\MpKslcd8a1294.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{8CC4EE05-42F8-4939-81AB-6C443ADC0151}\MpKslcd8a1294.sys [?]
S1 MpKslce4b28d2;MpKslce4b28d2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKslce4b28d2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2BE1B962-D600-463F-93A3-A573D8467CC0}\MpKslce4b28d2.sys [?]
S1 MpKslf5b8c6c5;MpKslf5b8c6c5;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{27B42E4A-BA60-4375-AA51-EF3326962E0D}\MpKslf5b8c6c5.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{27B42E4A-BA60-4375-AA51-EF3326962E0D}\MpKslf5b8c6c5.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18.4.2010 17:40 136176]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 7\DfSdkS.exe [17.2.2011 18:20 406016]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [21.9.2009 18:19 36608]
S3 NANMp50;NANMp50 NDIS Protocol Driver; [x]
S3 P730C;P730C;c:\windows\system32\drivers\P730C.sys [21.12.2007 14:58 25300]
S3 P730M;P730M;c:\windows\system32\drivers\P730M.sys [21.12.2007 14:58 25300]
S3 P730U;P730U;c:\windows\system32\drivers\P730U.sys [21.12.2007 14:58 49365]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2.2.2011 21:23 56536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2.2.2011 21:23 125248]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2.2.2011 20:30 70536]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [13.8.2009 18:42 38976]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [23.12.2008 10:41 160256]
S3 Rts516xIR;Realtek IR Driver; [x]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [3.2.2011 18:18 366840]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service --> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [29.11.2010 19:27 10064]
S3 usbvm328;A4 Tech USB2.0 PC Camera F;c:\windows\system32\drivers\usbvm326.sys [22.2.2008 16:36 348160]
S3 vmfilter326;326 MRD filter service;c:\windows\system32\drivers\vmfilter326.sys [22.2.2008 16:36 483072]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [13.12.2007 13:10 118784]
S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]
S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [21.9.2009 18:19 233472]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - PCTSDInjDriver32
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-02-09 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-21 13:13]
.
2011-01-28 c:\windows\Tasks\GlaryOneClickOptimizer.job
- c:\program files\Glary Utilities\oneclickoptimizer.exe [2009-05-21 13:13]
.
2011-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 16:40]
.
2011-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 16:40]
.
2011-03-19 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe [2011-03-18 17:19]
.
2011-03-20 c:\windows\Tasks\User_Feed_Synchronization-{1EB9FB64-F7D5-4E4B-9C99-A6FF1FBEBD0D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
mStart Page = hxxp://www.pctools.com/mrc/fix_homepage/
uInternet Settings,ProxyServer = http=221.130.17.62:80;ftp=221.130.17.62:80;https=221.130.17.62:80
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
IE: Stáhnout pomocí NetXferu - c:\program files\Xi\NetXfer\NXAddLink.html
IE: Stáhnout pomocí USD
IE: Stáhnout vše pomocí Net&Xferu - c:\program files\Xi\NetXfer\NXAddList.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
.
------- Asociace souborů -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-SBAMSvc
AddRemove-Mozilla Firefox (2.0.0.20) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-Mozilla Firefox (3.0.15) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-Mozilla Firefox (3.0.19) - e:\system\Apps\3C9F7B3F-D55C-42cd-8537-B878518B73AF\Exec\firefox\uninstall\helper.exe
AddRemove-SLABCOMM&10C4&EA60 - c:\windows\system32\Silabs\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-20 09:35
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\EncryptionInterface*]
"l_encryption_d"="585A4556465F"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="64724AC8CA559A2DEF15F1ED23AF4C828D3B788AE78BB64A904C81A6266C519D34077A0401A4F08B9A8607CDB4C600EE5C98840D32DE4E0B2162A17340FC67FD56D1F973B616FB7F6866CAA6433060F191BFB888BE5914C4B9081F01127CDEA3E4A6F1363474777533C3B33BA703C12DE89BF286160417EE16A6603A777EA0F93E0B743C43FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D6794A9C6AECB7A5D1407A6A0AC4980AC7933A4ADD3A7F4991B511FBDFA33CFA7C9FE836A1130E0059071CA64A025A5011E26577B6ACA1ABAD4D0F9F8D234B539E40F5508A411A82033AE86B1A4FEF4791187A2676CDF4EFCC65F829C1FD1D17C6961617368A78ACE86A2C772CAF7C3D9993CC557C6BCB19C556E0467C383615941592061D229FDC097C15277C2A8693E88E8F1D37DF91A3E3A733E3BB603D59BA95D7BB07111348A4B825FB4CDEDEEA186B6CC0DA5758EE581E7E22085CDD5F1B458D4DF66A08EA356621C433FE617679052F153E9CF4C008C4A19404D273AEFC83800926157236A45DFAA60027853D4F46CEC9C88ED445A0F9BFB6A4293118D9FF045112FFE3E1DF57E9EED13CB4C9159394303D37A192612619B12AB5F1AA54678E0472AA25D609AC6826E834BDCAC337167C4B1E0A67BF2A679CEE3974D789E4981C44290333E3CC2D00C78A79497CF52C5439C53F55462F68ED95C8D53285F61CBBDFB5C25213304FC942C55B7A64D9C3B05A3C5C98E65644393165889BD11C5D80A705C4FDA2F9CEB776A0CBB1422939933687295EC5306F8FCA9D28022127B33A5CAAC009FB325F4C916494FFC1480281C215683955AF402BEC119FEA7930CDCB1CCACB80895B866C5234B4FE23F3120329832EC137C4EA4A31E107DFE9C08C66F487EB08E02F802C79B16D0AA1475B08AAB8B66D38A349C9A925BAA420601DBC7A70A5216F5067A4F1CF39A9F5621F8DF4EAB31ABB04C98B404E5E8EA7D0E774867F93D62450AFA03D5EF286C1C8E120E859F474E6BBF3C2BEF5ECAD8854AE79E95BD421B1630202B8F592AA3D399051AEC38D45789BB9E5865361CCFF3D3F2A0D88868CCE3A77934214682BB3BA2CE27318B3A46B173493A07A5D976F14D51456851EA687C258D30F88D490CE68DE20196710D7BDB1C3D748BA3B559FCDCAC271054B642045F55D2964B4B543EC426157108943FD56E6BCD40F0146667AEA608318E71126F12BD75915F06B3FCB4F3742D2F4DBB3E29BDB0038D90F15770D2CB3F45EDF40B7C2694116E2EB1344C99D4480E69FC0C0D0C2DC6C1F6B3C5D43A79C2FD39EA75E2E5D15361AB36C5025812540DCA78076027F414164946819157BDD78590589F8DC5F1A963198FEACDE7A8F6580D834C6DD16085"
"OOCC06.00.00.01WSSV"="843D4D5FD15F23892C405683BECC08EE5946B5DEF1F79C67047E80BD4BE2E2BF3309490C22BFA016CFE84D49648A11B211C3B1C84CEE2DB4F9F150CB1E81818F605F19E3004B155789BC8226591AE25C527C0132C4B4D819ECAA9B06934AF4EEA8860B9DE33DEAAECEF4E170BCBD59FA0BC050AE42308C71E42FF3D97EE5DCA64FD8AEA6A8A790F33DE11E31928AD19350F49505149BB60F10952BEC11D65876B9C3D99E0BEE75F112E62E2542EAB01F591085AC68054C363F8E5A17E76E0B0FF04BA55BAE4C9168B07A4CBD969BDA86031F1C575451C39F67595E61FDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A9C6AECB7A5D1407BA7FD869164D6794EAE176F2AE953F4EC56374DF60F70C85E075120A63DF2CA00659B7B171A294EA5A101E831A67523403E1B44B91B56153A374E246D1154EB89FF492F80A392C903B470B9B62445DF4FCD49F1386119DB0685BADFE0D95F19387DBE34E23CDD6524406E1EE8C3E437A8C4CA886FA7C0572CE6CCF3BA4D65A90432015923DF6F03A7ED03BD531AC2216E05B34933A328D524CE99AA3B912FA71A9D707C6F0100DB148ACA2CB7CABC77DFD9A1950A5ADE56DA69DD5070344FCDCE89D0D92E9B46F89D12498F1AE1A344838A427F6332E6AC57A543A58CA2F3BDC830D6B42E64A9273A3C60F8A1B1A21713D1B9F636CB7B040B75FF6AAEED64960C94960433B74A40995A5707DAA94775B0A9E34956D93FEA722912CBA6105683AE8789828CD1D0744D5D998585BB2564A715911B3E74ED0A650457163A9C7131FDB4239291A744D05667CD549B96510651BF5D286A1B6D6D0B057512A61EEF42BF2D457A0AF6A430E1D2C6DA56D5EAAB9812409F9F361F31B80A647313690EE5C53E2FE0D32386587A38C1864AD95E1B7F197B9204CA73F5E5418C7C56C051614F522AF1257D4E57C77C20021C5C6223412885D2D2AA385D89495B754D7E9329A28CAD9F56C80A85CE97AC61D17EF116656B1627AA53645AAFB0CF16EE320BF19091CE8A34FBBC97A2263FEBA165502EB8A52A784E504B15B9B6AC3490F4DEF1D1056B32AF34E940E99ADB2034A7C0244CCAF046CA875B352D5A66F416B5AA51B03408B3C61C18B339D11DCA14F32CD54101140F6BFB565DD63382B529E747C6880A3B23233E2E3E94FC86CE5588458651CC0190E0FB5962FCF9D209EE38CBD3FF84DDF8418C58793A5134644264749A18A10BE3C92294BDBFA566DED09D7EBBEB00EBF5353C09379EAB2435413127A1C4A525734D4883BDC97E6252770CFBA68C13DEFE2BDEB5AC43A6EAE520BBE79C61FDD7BCB788F5110AED7CC5911B014A297B40397BF27DF870810499E8D6C8AFB9E0FB87932BEADB61D36DD"
"OODEFRAG11.00.00.01WORKSTATION"="18454B32E6CD8A4CFAB02D84F2FA9AB9A8658A6BF72068146CC949E372FD905E362F23C6D04B63CDED48BAF779AE6CB99FAD8D9F9352C3A270F731F12EFDB3C26EE2D98CAFC62D2E1E04BD61124F8C096D17BD2F7794AE47E349628B0D4CD280B12CA680B0D352D204239CB4803023D42E6E4BA69F1AAD17A53EFAF6DA9D6EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A6A0AC4980AC79339DB7CE019D40AA5C3C1AE4DB208DC64CBAEB33AD781F35BDB6F551E69E86E9D00051E749A0AD813386C1E3D98A0C34CB5DB58BA2B34BF7604E07A4BA96BAA888771EAB243D084EF2874F9CF6BBD666FBF118C7E13A9B438D512CB3721151F8D7BC459DB4EDF663544253F59B96DF2998E6ECFD41AA55647EB622E9730587C916EC0A190D254A6EE821B5DBA424AC8C910C5E4D8A4553EC9F5AF7B2120F2ACD4B0D01FBAE74666276EFB0BD649056E40A986DD47CEF83B2117814039A6C1DF8B48394A994954277785E548F9DAE8A4B59A3ECB9483667CDA8342FCCCC00D987441C010828E3ECA81E8181498CF109998B2D83A414C4969BEC15D58B59D1E876A006D982CA5F0434C8D1F0E5DA74A9716094AF42FA6CBA3E9B84E73DE98BEB8822D48407502A3D1D102B2C64ABF2D2B6C9A0BE430AA5929825CF9C6398FC1443577F3A09010F60ACBD4F92C9134C0412F1F9575CC20970D62EABF902F3992AF17F63897F98F7C86CCFE0579D9A874DEE32AEEDC59B5439E38EAD5E257FF5872292BC53E3C6F5682B79687F6ABFCCD3FD1A2ED0BC006969F1D34FF9D8B1CE1E253AB0CEB42F3CC3FCA154E6C172E9D2B2EED09D02CB4E0DF43CEF5130F5836F9151C704766BA371B76272BC3597CD154626CD4A59532EC7A740D13EBEAB1513426BEA51AD86261E7889F8045D0A8FFCB36DC31D0BD9D4CE06059A6C1F252CB455CEEBE7E601E40B9D1BFE92D615E5003C22B432659BB46ED168555D702A92932CF2FCCF2F4D248C49CC8213BF7A30A6E35983F9B8C665828FFA70E5D27538026D8634609955CB896409E285BC6FEC8FF1D97BB7D8FA9EFE8A803FAE6BB52FE8046A8FC8BD7566FE98ED643B741C436A731F49031FD0BFE94C727633E48EAD429CB56D8AB57BA57DD5CF2F5C931E7AFD37597FC868D1495DA8FCB0C56D96909D293090FA1F2DDBA84F33D0E1C80780A2536B91C694F9E287B480ED0C3558551F61D721C49EC282B97B54399CC8DA65C51EECDA9287BD552AC7128E7C72539FFB3FDEA964D8E534FB95A0BC2E4A925E68352A1713AB030E1C0179DA64DF7BB5027F299A2CF939B1501D3A148E899B4421F82269836DA120C74133FB6639B6820F2652C642AFCF5E2B5678DA85C6D714978B8755F5BCE941ABABF07F"
"OODEFRAG12.00.00.01PROFESSIONAL"="99A79F148C28ED12C237F129029AD0B610B579E3482266AF2558B2837DCEC6F461B3C2E0C927E8F09A0829529E5C9C10F04D82E994C118A2A41DDAFCCC1B0D0C0DE48DF66A3CD8C793EDBF881A6D3BB143AD579F21B0A130E269982C0F49051BA930C0376B18CC04FC1C3CD47E4C5242B6656851AB5A65541249E6C1524DE7128A3FFCD847DE792BE7770C0FDCE831F8C1390B1E739CE89CA6FE24C4A79316F4456E4CE404A836D52C9B7EE7472848A49A21F8793EC8D5ACDAFD120D27FA135933D018392781003066D7C9E15764ABA53D474F2B5426FB39AA6F5746665683EB73AA3108BB6975F9F4AC0453FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452BA7FD869164D6794C038D530D6EB3452F02C351249CE3E2DC448B9A4CBEBA5C4EBFDC9D63259B56CD5543FC7966C84180A264F1D4FD1F365D7FB6F3F3251E58721B9D3F2DB637B01B11BF73014926BA521003C59BA34DFFC4D8B0CB744E8EBE0DE8B9B504D750F7EE0B9307E31E1C41668C3FB6A40F3A89CC72E0946F9EDA81F56F833DBDD27C7F8C82330F6466FF16195F130895BC1D9C36D9081358ECDEFE23FFA4E182A446557CF3DE7EDF0823AD461FBA07F490563C2E9D134667FABFA25D5FEC69813CB08D765E2E84E119847910BC8382E0DD597BFEA0687CD915DE5B05AE419083B71B40977E06817CDE1280B523485066B032FB4A33681744BEE32230F0266230B1CD54DFC79405A10434F8A7E8DBB90700C45EE4BDDCE74F79DC1703C9FF2BB2F69385E6C62EEBC035492AD59173267E9A758919BEB3F01265C5EDDAEFA283619A78DC6C447167A19E12CE4AE09623B68C04C90D3C5C65C2AD1B507B3C4148B7BD8EA6684C47BE0096D3BF4D00C6C4EC2716936B543FC5F9AD8D5DAA122654A4D37C97232ED095348AAC1F597411378148E59A109309EF5527EB49C4E2CF2134D2C87F0D5C74DC61882A7D4D83CBC253A9CAD43174C0AA07087A96215EFB31BF9D8E5BEFA4CF9C6F691B453F501F4D356D358E0AFCC447458687296D66EC6AC978E0A8B3469E3EF2AA798854D8DE916CF2330952558759832CC2F79F69C6BA2AF577D5A148207F5BB4965D4C74F6F95D0AC724D4E8C68C96713631CDCE386710CED2E8435EB7E9EF8B0127DCCAAFB0CC6C33DCA06760E5828CDF7E57420221C3FC1EB33B2F00F447248F98FC9752AC8E2F394242A1D79A8E7C2B711AC24EA3B1B756D682E4F9B547D31D87033FA39301D795FC11EF66332DCEC562EF9B231FE3AE04CF64CB8315333415359FAFA8BB7AFC6E8E3C771A702027BE51E5487E927771184873553FB55707F6E579C26A8EC1700E099136BC5B997506019364D2E08F1C2799415B84E85D6A8954996273BEC"
"OOCC7.00.00.01PROSTATION"="7E3FCDF198260ABB56E58D80DF70ECF9E5D4647C0F7BEC4EBC65CB80CB7F6A0531626D639204E3DCCE48F34B85E4EE1F938CAB46196003C6FC7BF17E83BF8F35E29DF8770084E0F6A3B653D7E6ADE220214ED9CD900C1EAC904BD67B0D1E96FB911D0B759F8976529D75FCD01E997F74459715400E54584A39AC16C59D9AA3152CB056EFE35C69BC7A6FD4A67A59511AA80A970E5CF4A2EB2F98DD6E1F9AA9BF18CB1D38F4AA5602EA2E56100002B612E9ECB06D7D0CC3E29B2FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA6A0AC4980AC7933A9C6AECB7A5D140735B8BAA50EA15906BB05DEA2C3BCA944CA00EB9B397E96832732C84ED101A05CA44199199435CEB14B0D5E12FA8E338AC3DF6E240634CCFC182D31C627CEAEAA485CBFBD7AD88445A4ACBF6B4B89573105A09E367345AEAA437C8FF77A2B7A7F0F5667FE96A650608D313AA5F2997930CAAF52F2438E4E7A78D0F7C9B10260E67F3E022F97BA7B43E02A3A1C01AA70A264BD14DC8AEC2E031D1D310A88C2B28B336932057A35C5D58BECE08ADAB00746354420DBB543C6F9271733680CE1B43FD66F4F17143A60A0911503163A9EFC7E3479693A00F9833B26BAAE79A156A2F52BAC65E50C73705108FDA8C2AA6F83D2EB5E14A8FC7AC54837478535FD1CA5C987423350DD0E91BA99C78EFC0E2144ECFC347A391132614490C0CD792CB161765292AC9DDA39D0D28459241217B5589C9981296576169CF6F8ECD3048A1CE9DD0BC5F976242B30339BDA10B3D030CF548A10E2063A1C354CCED714FA4EE248054149F4E7B31BA51943BAAAF9179DACACA9EC9CDB40BDDAD380CFC2677C11F9939C4D30E3D4461C67F728FD5E9A0966DD67EB7F8B3CF9B1C19368C3B3EE376F5754C56B3F276E7023C799CCBFE00669C745236A99B8D5506E9FF9B4B1D5670FC137E8A0341D5676F6D2C80BDF412992EE5B6B6DF314D3C4D5D01EE216B33B2FE52536FADE80C6F0B1523261E5698BB577D5644EE7FE038E966833CF785ECD1FFE926BD9C16D8D1EC20F952B5B5ACC1B2F73EE082B7FEE2175395FB3D4823D1F670C0DCF42D07BA841667AFB30680DFB03863246536F2BE45B2D07F78C9DAFE4A2AC642629F0E334E74CA894B43DF108857797EADB7E4E35D1BED63C64824A9854A5FBD72565215613462EEF20D4A5E26F42CD8CA52BF3630B00BDD183D73A57453CA59345980F98C6EE5A390E7FD5A29A74477373CC3932D8136D3FF699AE3362CA73BD804B8D7A2774C3D1FAE2345206B1391EEB8DC15A35B2DEC0AE94DBAFBB3E406C3191016B7D18444E4B77F471D4321EBC1B6AB3073B294DC100EDF7C60816266D9252D3D43A31F7F6430AD4F24D4035B6EF37BA"
"OODEFRAG14.00.00.01PROFESSIONAL"="FA27199735FDA3C25D7DF0ECC9FA2202210B2ADEE130C1CF78EC4846B4B48060B1FC6D390DF6AC116CB71CBCC3CA2B0054F910B8C9CB5CEF7D03214D421009FABED33DEA2FA25F9AA7D1EEBE26D9FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D67945D575E7D6A3B98089DB7CE019D40AA5C71F69F66420FF8302AA28358302A656D53DB2D71C7B8B7F9958DB9D5BCC6D22E67C132EB43F69E6411A6800D8F70BE48B4677377F22066F57149CC1A7CBD2AEB8EA7E62CB4AD6DCC3D33E515E02B5FEBE3887DA4594581320095BC20F1AD45CA90CAF7146ECFB3A619A437800C41AA4CACFAB7509480A5F40E2901A306FA1A84DB8107654AED5FC1D48EDC37FC1329EB1F2F73A5401B96192C72F2B4A6FB46E8A25416B6A68B068263B72373A2ED09E58FC7E724FDD1398B3092D1B8467B865BDA800D706721DD60FA1A3A4571991BE5961CAB21F1D8165132DA3E68D9B8BE52BE77B652F09A446917E4370EDFCD532F0FB83F43C5545D7D90D641515B6775DA4C6043EB3056393C77F89185EAB8CA95995C0107A3DF60BB6BC2C252482D5592C59345A4922C5F0E1F6EA6B692F93F831BF9393BBE8894CA298C93A222272E2D311F35B50B607F26548F367FD82791753B3B8F04CACF93FC72DB64C8EEE1F1F2D843EC2C11B00562A3DA669346C845FC667991D981AC9BB633874CA238E1B8BDCBF62DEB1ECC80B15B02BCF7665D043F4CC431871C898E749D1D45618B9E3BFC5AE399A8B1D925198EECA60949549BF4E061422EDF43F243285CAD88F9825AB41B65B7ECCC6DCAB0953576F581937B6C5D4580BF0E2D7146093948F21BEB19FB698FF4967896EDA489A9DD3FA774B886BC1E0906708CD8B3405E3BCA852E9CFDE2A71F573D522EB5CB4DF6BE58C20EB840CA5B1BD41B1CD58D2591925A91B17AE8A46B34AB1750B67DD53E1CB040D60CEBDD5E6F09864E0975A0B81FB7CE464423B67009554BBA9206AD1259D5A2931D079FDAC565722BC1C2958398C6976CC1FABE2881D04B7AC2927439C6EF126A1E1E8A7E38BEF3910602FA29FA2F8C5D6F1E52F320B8683ED890FB5B0C292BA35481505BB07594026F83FDC2999D4672DC7E3A963B2C65DB78334A84A3337FAB194552657067D3A12C5C7ECE96464FAA2CD27437FACDF9C9DBF11AA55C401594594129F70A7922BB00E792B1EB5D27A89516B3615FC3D323CC885B92D88763129692A0CD6495E53E3FC101AFE59C403463055A843839102A2DF4AE8391C5D8FD6598370B3DA879B955C947F226C18137F52305F3AC5DC64170FA6C954FBA5554EF7721B323A12B6540A7950CA08EC541BFB480E736E17CF09FA21EC930292EB6731846307B76BC1B9243D06B9F485D05C8C54E"
"OODI05.00.00.01PRO"="2354FEE84798D27738C179DC3776FCBBD8C68FAE93492F955AA3B4D57550038A86D186DD04AFC6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794A9C6AECB7A5D1407A6171C11EC38DE3D786C020EDC3D05CEC7EB50EFB2B7628CCCD60E81C61B6CA207ED2965FA6B12CE107F7AC9194CEF9B25B457AF055BCCEA8C6F003ACA12DF92C4B84693F243738583C19CDEAD184F0E8AEEE8384CAF749842F8A2C88440AB8D2E98D0EC8E4E5EBD2C49C55F0A7447590613BA03BABA6D00D0EC2E300C79ED559BA71C996B539D30F57184BEF0397150B85DB86EDA84BB2EAD088756CE98B952F8C4AC2B7B9C70BEE0581956F84259ECD74D82BA06995956E2CCCD850E7A968DC4113D9385790D6D8063FB628C6E01CB2D276C0EEC0B354C0F7ECFECDD817E3791733A2C22BB9962FE37D6816A22DC2D14F3FC71136C328CE5A8139F289261A2881545AE40BAB2EA964109BA27C3D6F6017F705251D724B2AB95CF912718A2C5E2E5B43BA0D1E8F7192F24F4A6BFCCB1F5593583D1E8D602BA58F21EEE00173A71171155D9DDBF9BE874EEFC26070D8A8E56EFB715C0875F03461C85E13B0DC1961E18E3D5C2AE8D8148E483B30CDED1F50F780B6F84E756057721E7B93FC03EC9363B32D06623ABEBA6321CB045F97CEF5E587888DB9F93D8C9894D030667B5175CA0EFDD34FB74C9CCBBBFD5B00DA3CF645163DBF2C6E8275D121E1E8D26D39C54A1B0621B8D0CCF3F184AACCCB6840006559038FCECCC2E98AB2B40D699688E224C6B988CA0BA46C590FC151D8E7F7D6C8D28C2AB92D7C1A47A2573E7CEE3B312DFFB8E7F6F6A8769A37C41A99B99598154B9F33AAFC9C76D5623124ACADEE73254A224EE2C2F07FB83CF377D5CFB3977B83594632D84B8A5CD9FCE8B049319D2D28090D9F8B8C60F19E35229C0F3D5C00070C7E7680CA4411FF8AC3E64E2CB8AB89FDD426FE05FF87C8A42BFAD717C961FA4008DB38B2DF940F086F6CC4C17B41668E92F9A237DD67C7688D87D0A0F74456F041D56D089CB582E87508FF9266F322DE52BF99FE0071DBF7D107CF5829BCD5270E109CD02F9C5BB31667234B81C051FD7C4831B5F2C93E44906EA13608FCF32352D7A19F6081807585C32EB21E03E57988F1EFB5FADCAC4ED5D7F62C41890D996D3CC6A59BF936326D7FD33C629BED057A0254FDDB661233B3E628662420C74AA2E95A230AEB187950076C0A5211A6A1513E9436B37A8A9D9D3AF4BFDDC72945F195EC094251E8C788635EECC3B1C672807AFAD2CE12AE4434EF81C717D27B0F2F427EC37B83AF0741AC3BD5F2FC0EFB89C2E05572D1DC4C7E0C40A29FA4120F9A7DFEF5742981902F1A2509476BB8EC7FC13E6BB54729D09C30A4A27"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
@DACL=(02 0000)
@="Bezdrátové"
"ProcessGroupPolicy"="ProcessWIRELESSPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75}]
@DACL=(02 0000)
@="Group Policy Environment"
"ProcessGroupPolicy"="ProcessGroupPolicyEnviron"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyEnviron"
"ProcessGroupPolicyEx 0"=""
"EventSources"="(Group Policy Environment,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-1"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{17D89FEC-5C44-4972-B12D-241CAEF74509}]
@DACL=(02 0000)
@="Group Policy Local Users and Groups"
"ProcessGroupPolicy"="ProcessGroupPolicyLocUsAndGroups"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyLocUsAndGroups"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExLocUsAndGroups"
"EventSources"="(Group Policy Local Users and Groups,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-2"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{1A6364EB-776B-4120-ADE1-B63A406A76B5}]
@DACL=(02 0000)
@="Group Policy Device Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyDevices"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDevices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDevices"
"EventSources"="(Group Policy Device Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-3"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@DACL=(02 0000)
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"=expand:"fdeploy.dll"
"NoMachinePolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"NoGPOListChanges"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"=multi:"(Folder Redirection,Application)\00\00"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]
@DACL=(02 0000)
"Status"=dword:00000000
"RsopStatus"=dword:00000000
"LastPolicyTime"=dword:00e2f997
"PrevSlowLink"=dword:00000000
"PrevRsopLogging"=dword:00000001
"ForceRefreshFG"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@DACL=(02 0000)
@="Disková kvóta Microsoft"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=expand:"dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}]
@DACL=(02 0000)
@="Group Policy Network Options"
"ProcessGroupPolicy"="ProcessGroupPolicyNetworkOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetworkOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetworkOptions"
"EventSources"="(Group Policy Network Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-4"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@DACL=(02 0000)
@="Plánovač paketů technologie QoS"
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"Status"=dword:00000000
"RsopStatus"=dword:80070032
"LastPolicyTime"=dword:00e2f997
"PrevSlowLink"=dword:00000000
"PrevRsopLogging"=dword:00000001
"ForceRefreshFG"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
@DACL=(02 0000)
@="Skripty"
"ProcessGroupPolicy"="ProcessScriptsGroupPolicy"
"ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx"
"GenerateGroupPolicy"="GenerateScriptsGroupPolicy"
"DllName"=expand:"gptext.dll"
"NoSlowLink"=dword:00000001
"NoGPOListChanges"=dword:00000001
"NotifyLinkTransition"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@DACL=(02 0000)
@="Internet Explorer Zonemapping"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"NoGPOListChanges"=dword:00000001
"RequiresSucessfulRegistry"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{5794DAFD-BE60-433f-88A2-1A31939AC01F}]
@DACL=(02 0000)
@="Group Policy Drive Maps"
"ProcessGroupPolicy"="ProcessGroupPolicyDrives"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDrives"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDrives"
"EventSources"="(Group Policy Drive Maps,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-5"
"PerUserLocalSettings"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6232C319-91AC-4931-9385-E70C2B099F0E}]
@DACL=(02 0000)
@="Group Policy Folders"
"ProcessGroupPolicy"="ProcessGroupPolicyFolders"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolders"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolders"
"EventSources"="(Group Policy Folders,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-6"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=""
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}]
@DACL=(02 0000)
@="Group Policy Network Shares"
"ProcessGroupPolicy"="ProcessGroupPolicyNetShares"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetShares"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetShares"
"EventSources"="(Group Policy Network Shares,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-7"
"NoUserPolicy"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}]
@DACL=(02 0000)
@="Group Policy Files"
"ProcessGroupPolicy"="ProcessGroupPolicyFiles"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFiles"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFiles"
"EventSources"="(Group Policy Files,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-8"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{728EE579-943C-4519-9EF7-AB56765798ED}]
@DACL=(02 0000)
@="Group Policy Data Sources"
"ProcessGroupPolicy"="ProcessGroupPolicyDataSources"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDataSources"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDataSources"
"EventSources"="(Group Policy Data Sources,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-9"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{74EE6C03-5363-4554-B161-627540339CAB}]
@DACL=(02 0000)
@="Group Policy Ini Files"
"ProcessGroupPolicy"="ProcessGroupPolicyIniFile"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyIniFile"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExIniFile"
"EventSources"="(Group Policy Ini Files,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-10"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
@DACL=(02 0000)
@="Internet Explorer User Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=expand:"scecli.dll"
@="Security"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:000003c0
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325}]
@DACL=(02 0000)
@="Group Policy Services"
"ProcessGroupPolicy"="ProcessGroupPolicyServices"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyServices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExServices"
"EventSources"="(Group Policy Services,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-11"
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
@DACL=(02 0000)
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
@="Internet Explorer Branding"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3014"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A3F3E39B-5D83-4940-B954-28315B82F0A8}]
@DACL=(02 0000)
@="Group Policy Folder Options"
"ProcessGroupPolicy"="ProcessGroupPolicyFolderOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolderOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolderOptions"
"EventSources"="(Group Policy Folder Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-12"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{AADCED64-746C-4633-A97C-D61349046527}]
@DACL=(02 0000)
@="Group Policy Scheduled Tasks"
"ProcessGroupPolicy"="ProcessGroupPolicySchedTasks"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicySchedTasks"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExSchedTasks"
"EventSources"="(Group Policy Scheduled Tasks,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-13"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B087BE9D-ED37-454f-AF9C-04291E351182}]
@DACL=(02 0000)
@="Group Policy Registry"
"ProcessGroupPolicy"="ProcessGroupPolicyRegistry"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegistry"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegistry"
"EventSources"="(Group Policy Registry,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-14"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=expand:"scecli.dll"
@="EFS recovery"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@DACL=(02 0000)
@="802.3 Group Policy"
"DisplayName"=expand:"@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=expand:"dot3gpclnt.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}]
@DACL=(02 0000)
@="Group Policy Printers"
"ProcessGroupPolicy"="ProcessGroupPolicyPrinters"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPrinters"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPrinters"
"EventSources"="(Group Policy Printers,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-16"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}]
@DACL=(02 0000)
@="Group Policy Shortcuts"
"ProcessGroupPolicy"="ProcessGroupPolicyShortcuts"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyShortcuts"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExShortcuts"
"EventSources"="(Group Policy Shortcuts,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-17"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@DACL=(02 0000)
@="Microsoft Offline Files"
"DllName"=expand:"%SystemRoot%\\System32\\cscui.dll"
"EnableAsynchronousProcessing"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@DACL=(02 0000)
@="Instalace softwaru"
"DllName"=expand:"appmgmts.dll"
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoBackgroundPolicy"=dword:00000000
"RequiresSucessfulRegistry"=dword:00000000
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"EventSources"=multi:"(Application Management,Application)\00(MsiInstaller,Application)\00\00"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
@DACL=(02 0000)
@="Internet Explorer Machine Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@DACL=(02 0000)
@="Zabezpečení protokolu IP"
"ProcessGroupPolicy"="ProcessIPSECPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}]
@DACL=(02 0000)
@="Group Policy Internet Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyShortcuts"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyInternet"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExInternet"
"EventSources"="(Group Policy Internet Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-18"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}]
@DACL=(02 0000)
@="Group Policy Start Menu Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyStartMenu"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyStartMenu"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExStartMenu"
"EventSources"="(Group Policy Start Menu Settings,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-19"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E5094040-C46C-4115-B030-04FB2E545B00}]
@DACL=(02 0000)
@="Group Policy Regional Options"
"ProcessGroupPolicy"="ProcessGroupPolicyRegionOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegionOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegionOptions"
"EventSources"="(Group Policy Regional Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-20"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}]
@DACL=(02 0000)
@="Group Policy Power Options"
"ProcessGroupPolicy"="ProcessGroupPolicyPowerOptions"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPowerOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPowerOptions"
"EventSources"="(Group Policy Power Options,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-21"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F9C77450-3A41-477E-9310-9ACD617BD9E3}]
@DACL=(02 0000)
@="Group Policy Applications"
"ProcessGroupPolicy"="ProcessGroupPolicyApplications"
"DllName"=expand:"gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyApplications"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExApplications"
"EventSources"="(Group Policy Applications,Application)"
"DisplayName"=expand:"@gpprefcl.dll,-15"
"PerUserLocalSettings"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"crypt32.dll"
"Logoff"="ChainWlxLogoffEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"cryptnet.dll"
"Logoff"="CryptnetWlxLogoffEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
@DACL=(02 0000)
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
@DACL=(02 0000)
"Asynchronous"=dword:00000001
"DllName"=expand:"%SystemRoot%\\System32\\dimsntfy.dll"
"Startup"="WlDimsStartup"
"Shutdown"="WlDimsShutdown"
"Logon"="WlDimsLogon"
"Logoff"="WlDimsLogoff"
"StartShell"="WlDimsStartShell"
"Lock"="WlDimsLock"
"Unlock"="WlDimsUnlock"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@DACL=(02 0000)
@=""
"DLLName"="igfxdev.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
@DACL=(02 0000)
"DLLName"="c:\\program files\\common files\\logishrd\\bluetooth\\LBTWlgn.dll"
"Asynchronous"=dword:00000000
"Startup"="OnStartup"
"Logon"="OnLogon"
"StartShell"="OnStartShell"
"Logoff"="OnLogoff"
"Shutdown"="OnShutdown"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
@DACL=(02 0000)
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=expand:"sclgntfy.dll"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
@DACL=(02 0000)
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
@DACL=(02 0000)
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=expand:"WgaLogon.dll"
"Event"=dword:00000002
"InstallEvent"="1.9.0040.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
@DACL=(02 0000)
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
"ASPNET"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(524)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\netprovcredman.dll
c:\program files\PC Tools Security\TFEngine\TFMon.dll
c:\program files\PC Tools Security\TFEngine\TFRK.dll
.
Celkový čas: 2011-03-20 09:43:44
ComboFix-quarantined-files.txt 2011-03-20 08:43
.
Před spuštěním: Volných bajtů: 29 649 637 376
Po spuštění: Volných bajtů: 29 626 990 592
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=6K5HAP /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=6K5HAP-BAK
.
- - End Of File - - 6BF7A6F814DD473D869118716D61879A