Re: Padá net, nelze odeslat HijackThis log mailem
Napsal: 12 kvě 2010 16:14
od Kryšpín
DDS (Ver_10-03-17.01) - NTFSx86
Run by chir-lekar at 17:05:06,59 on st 12.05.2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1584 [GMT 2:00]
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NetTime\NeTmSvNT.exe
C:\WINDOWS\system32\LFXGDIPO.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Documents and Settings\chir-lekar.MNCASLAV\plocha\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://portal
uSearch Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
uDefault_Page_URL = hxxp://portal
mDefault_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
mDefault_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
mLocal Page = %SystemRoot%\system32\blank.htm
mStart Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
uInternet Connection Wizard,ShellNext = hxxp://windowsupdate.microsoft.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
mSearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
mCustomizeSearch = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
uURLSearchHooks: Microsoft Url Search Hook: {cfbfae00-17a6-11d0-99cb-00c04fd64497} - c:\windows\system32\ieframe.dll
mWinlogon: Shell=Explorer.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,
mWinlogon: UIHost=logonui.exe
mWinlogon: SFCDisable=0 (0x0)
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Tip d&ne: {4d5c8c25-d075-11d0-b416-00c04fb90376} - %SystemRoot%\system32\shdocvw.dll
uRun: [ctfmon.exe] ; c:\windows\system32\ctfmon.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [Adobe ARM] ; "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Alcmtr] ; ALCMTR.EXE
mRun: [HotKeysCmds] ; c:\windows\system32\hkcmd.exe
mRun: [IgfxTray] ; c:\windows\system32\igfxtray.exe
mRun: [NetTime] ; c:\program files\nettime\NetTime.exe
mRun: [Persistence] ; c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] ; RTHDCPL.EXE
mRun: [SkyTel] ; SkyTel.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-explorer: NoDriveTypeAutoRun = 323 (0x143)
uPolicies-explorer: NoDriveAutoRun = 67108863 (0x3ffffff)
uPolicies-system: DisableRegistryTools = 0 (0x0)
mPolicies-explorer: HonorAutoRunSetting = 1 (0x1)
mPolicies-explorer: NoDriveAutoRun = 67108863 (0x3ffffff)
mPolicies-explorer: NoDriveTypeAutoRun = 323 (0x143)
mPolicies-system: dontdisplaylastusername = 0 (0x0)
mPolicies-system: legalnoticecaption =
mPolicies-system: legalnoticetext =
mPolicies-system: shutdownwithoutlogon = 1 (0x1)
mPolicies-system: undockwithoutlogon = 1 (0x1)
dPolicies-explorer: NoDriveTypeAutoRun = 323 (0x143)
dPolicies-explorer: NoDriveAutoRun = 67108863 (0x3ffffff)
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: %SystemRoot%\system32\mswsock.dll
LSP: %SystemRoot%\system32\rsvpsp.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227294162531
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - c:\windows\system32\urlmon.dll
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} -
Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - c:\progra~1\common~1\micros~1\office12\MSOXMLMF.DLL
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - c:\windows\system32\urlmon.dll
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - c:\windows\system32\msvidctl.dll
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} -
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - c:\program files\common files\microsoft shared\help\hxds.dll
Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} -
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - c:\windows\system32\msvidctl.dll
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - c:\windows\system32\wiascr.dll
Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Notify: crypt32chain - crypt32.dll
Notify: cryptnet - cryptnet.dll
Notify: cscdll - cscdll.dll
Notify: dimsntfy - c:\windows\system32\dimsntfy.dll
Notify: igfxcui - igfxdev.dll
Notify: ScCertProp - wlnotify.dll
Notify: Schedule - wlnotify.dll
Notify: sclgntfy - sclgntfy.dll
Notify: SensLogn - WlNotify.dll
Notify: termsrv - wlnotify.dll
Notify: WgaLogon - WgaLogon.dll
Notify: wlballoon - wlnotify.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - c:\windows\system32\stobject.dll
STS: Browseui preloader: {438755c2-a8ba-11d1-b96b-00a0c90312e1} - %SystemRoot%\system32\browseui.dll
STS: Proces mezipaměti kategorií součástí: {8c7461ef-2b13-11d2-be35-3078302c2030} - %SystemRoot%\system32\browseui.dll
SEH: URL Exec Hook: {aeb6717e-7e19-11d0-97ee-00c04fd91972} - shell32.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
LSA: Authentication Packages = msv1_0
LSA: Notification Packages = scecli
SubSystems: Windows = basesrv
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\msnetmtg.inf,NetMtg.Install.PerUser.NT
mASetup: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\msmsgs.inf,BLC.QuietInstall.PerUser
mASetup: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\wmp.inf,PerUserStub
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4383} - c:\windows\system32\ie4uinit.exe -BaseSettings
mASetup: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - c:\windows\system32\ieudinit.exe
mASetup: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - c:\windows\inf\unregmp2.exe /ShowWMP
mASetup: >{26923b43-4d38-484f-9b9e-de460746276c} - c:\windows\system32\ie4uinit.exe -UserIconConfig
mASetup: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
mASetup: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
mASetup: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chir-l~1.mnc\dataap~1\mozilla\firefox\profiles\d8j2jph8.default\
FF - component: c:\documents and settings\chir-lekar.mncaslav\data aplikací\mozilla\firefox\profiles\d8j2jph8.default\extensions\{d1e06b91-60e6-4492-af9f-53043fa32716}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\chir-lekar.mncaslav\data aplikací\mozilla\firefox\profiles\d8j2jph8.default\extensions\{d1e06b91-60e6-4492-af9f-53043fa32716}\components\RadioWMPCore.dll
FF - component: c:\program files\mozilla firefox\components\browserdirprovider.dll
FF - component: c:\program files\mozilla firefox\components\brwsrcmp.dll
FF - component: c:\program files\mozilla firefox\extensions\{b13721c7-f507-4982-b2e5-502a71474fed}\components\NPComponent.dll
FF - component: c:\program files\mozilla firefox\extensions\{b13721c7-f507-4982-b2e5-502a71474fed}\components\PNRComponent.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\browser\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\3.0.50106.0\npctrl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll
FF - plugin: c:\program files\windows media player\npdrmv2.dll
FF - plugin: c:\program files\windows media player\npdsplay.dll
FF - plugin: c:\program files\windows media player\npwmsdrm.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome.manifest
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\install.rdf
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\content\ffjcext\ffjcext.js
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\content\ffjcext\ffjcext.xul
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\de-de\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\en-us\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\es-es\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\fr-fr\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\it-it\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\ja-jp\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\ko-kr\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\sv-se\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\zh-cn\ffjcext\ffjcext.dtd
c:\program files\mozilla firefox\extensions\{cafeefac-0016-0000-0016-abcdeffedcba}\chrome\locale\zh-tw\ffjcext\ffjcext.dtd
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.jit.chrome", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
---- Add-ons/Extensions Installed ----
Default
Java Console
Java Quick Starter
ScrapBook
Skype extension for Firefox
TheFreeDictionarycom Toolbar
============= SERVICES / DRIVERS ===============
R0 ACPI;Microsoft ACPI Driver;c:\windows\system32\drivers\acpi.sys [2008-4-14 188288]
R0 atapi;Standardní řadič disku IDE/ESDI;c:\windows\system32\drivers\atapi.sys [2008-4-14 96512]
R0 Disk;Ovladač disku;c:\windows\system32\drivers\disk.sys [2008-4-14 36352]
R0 dmio;Ovladač správce logických disků;c:\windows\system32\drivers\dmio.sys [2008-4-14 153856]
R0 dmload;dmload;c:\windows\system32\drivers\dmload.sys [2007-10-29 5888]
R0 FltMgr;FltMgr;c:\windows\system32\drivers\fltMgr.sys [2008-11-21 129792]
R0 Ftdisk;Ovladač správce svazků;c:\windows\system32\drivers\ftdisk.sys [2007-10-29 125184]
R0 isapnp;Řadič Plug and Play sběrnice ISA/EISA;c:\windows\system32\drivers\isapnp.sys [2008-4-14 37248]
R0 KSecDD;KSecDD;c:\windows\system32\drivers\ksecdd.sys [2008-4-14 92928]
R0 MountMgr;MountMgr;c:\windows\system32\drivers\mountmgr.sys [2008-4-14 42368]
R0 Mup;Služba Multiple UNC Provider;c:\windows\system32\drivers\mup.sys [2008-4-14 105344]
R0 NDIS;Systémový ovladač NDIS;c:\windows\system32\drivers\ndis.sys [2008-4-14 182656]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA;c:\windows\system32\drivers\ohci1394.sys [2008-4-14 61696]
R0 PartMgr;PartMgr;c:\windows\system32\drivers\partmgr.sys [2008-4-14 19712]
R0 PCI;Řadič sběrnice PCI;c:\windows\system32\drivers\pci.sys [2008-4-14 68736]
R0 PCIIde;PCIIde;c:\windows\system32\drivers\pciide.sys [2007-10-29 3328]
R0 sr;Ovladač filtru Obnovy systému;c:\windows\system32\drivers\sr.sys [2008-11-21 73344]
R0 VolSnap;VolSnap;c:\windows\system32\drivers\volsnap.sys [2008-4-14 52480]
R1 AFD;AFD;c:\windows\system32\drivers\afd.sys [2008-4-14 138496]
R1 Beep;Beep;c:\windows\system32\drivers\beep.sys [2007-10-29 4224]
R1 Cdrom;Ovladač jednotky CD-ROM;c:\windows\system32\drivers\cdrom.sys [2008-4-14 62976]
R1 easdrv;easdrv;c:\windows\system32\drivers\easdrv.sys [2008-8-18 54184]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-8-18 35168]
R1 Fips;Fips;c:\windows\system32\drivers\fips.sys [2008-4-14 44544]
R1 i8042prt;i8042 Keyboard and PS/2 Mouse Port Driver;c:\windows\system32\drivers\i8042prt.sys [2008-4-14 52096]
R1 intelppm;Řadič procesoru Intel;c:\windows\system32\drivers\intelppm.sys [2008-4-14 40192]
R1 IPSec;Ovladač IPSEC;c:\windows\system32\drivers\ipsec.sys [2008-4-14 75264]
R1 Kbdclass;Ovladač třídy klávesnic;c:\windows\system32\drivers\kbdclass.sys [2008-4-14 24576]
R1 mnmdd;mnmdd;c:\windows\system32\drivers\mnmdd.sys [2007-10-29 4224]
R1 Mouclass;Ovladač třídy myší;c:\windows\system32\drivers\mouclass.sys [2008-4-14 23040]
R1 MRxSmb;MRXSMB;c:\windows\system32\drivers\mrxsmb.sys [2008-4-14 455680]
R1 Msfs;Msfs;c:\windows\system32\drivers\msfs.sys [2008-4-14 19072]
R1 NetBIOS;Rozhraní NetBIOS;c:\windows\system32\drivers\netbios.sys [2008-4-14 34688]
R1 NetBT;Rozhraní NetBios nad protokolem TCP/IP;c:\windows\system32\drivers\netbt.sys [2008-4-14 162816]
R1 Npfs;Npfs;c:\windows\system32\drivers\npfs.sys [2008-4-14 30848]
R1 Null;Null;c:\windows\system32\drivers\null.sys [2007-10-29 2944]
R1 RasAcd;Ovladač automatického připojení pomocí vzdáleného přístupu;c:\windows\system32\drivers\rasacd.sys [2007-10-29 8832]
R1 Rdbss;Rdbss;c:\windows\system32\drivers\rdbss.sys [2008-4-14 175744]
R1 RDPCDD;RDPCDD;c:\windows\system32\drivers\rdpcdd.sys [2007-10-29 4224]
R1 redbook;Digital CD Audio Playback Filter Driver;c:\windows\system32\drivers\redbook.sys [2008-11-21 58496]
R1 Serial;Ovladač sériového portu;c:\windows\system32\drivers\serial.sys [2008-4-14 64256]
R1 Tcpip;Ovladač protokolu TCP/IP;c:\windows\system32\drivers\tcpip.sys [2008-4-14 361600]
R1 TermDD;Ovladač terminálového zařízení;c:\windows\system32\drivers\termdd.sys [2008-11-21 40840]
R1 VgaSave;VgaSave;c:\windows\system32\drivers\vga.sys [2008-4-14 20992]
R2 AudioSrv;Zvuk systému Windows;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 CryptSvc;CryptSvc;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 DcomLaunch;Spouštěč procesů serveru DCOM;c:\windows\system32\svchost -k dcomlaunch --> c:\windows\system32\svchost -k DcomLaunch [?]
R2 Dhcp;Klient DHCP;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 dmserver;Správce logických disků;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 Dnscache;Klient DNS;c:\windows\system32\svchost.exe -k NetworkService [2008-4-14 14336]
R2 eamon;EAMON;c:\windows\system32\drivers\eamon.sys [2008-8-18 40824]
R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2008-8-18 472280]
R2 ERSvc;Zasílání zpráv o chybách;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 Eventlog;Protokol událostí;c:\windows\system32\services.exe [2008-4-14 111104]
R2 helpsvc;Nápověda a odborná pomoc;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\java\jre6\bin\jqs.exe [2009-12-7 153376]
R2 LanmanServer;Server;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 lanmanworkstation;Pracovní stanice;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 LmHosts;Podpora rozhraní NetBIOS nad protokolem TCP/IP;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
R2 Netlogon;Přihlašování k síti;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 NetTimeSvc;NetTime;c:\program files\nettime\NeTmSvNT.exe [2003-1-31 452096]
R2 PlugPlay;Plug and Play;c:\windows\system32\services.exe [2008-4-14 111104]
R2 PolicyAgent;Služby IPSEC;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 ProtectedStorage;Chráněné úložiště;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 RemoteRegistry;Vzdálený registr;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
R2 RpcSs;Vzdálené volání procedur (RPC);c:\windows\system32\svchost -k rpcss --> c:\windows\system32\svchost -k rpcss [?]
R2 SamSs;Správce zabezpečení účtů;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 seclogon;Secondary Logon;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 SENS;Oznamování systémových událostí;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 SharedAccess;Brána Firewall / Sdílení připojení k Internetu (ICS);c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 ShellHWDetection;Rozpoznávání hardwaru;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 Schedule;Plánovač úloh;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 Spooler;Zařazování tisku;c:\windows\system32\spoolsv.exe [2008-4-14 57856]
R2 srservice;Služba obnovení systému;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 Themes;Motivy;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 TrkWks;Klient služby sledování distribuovaných propojení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 W32Time;Systémový čas;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 WebClient;Webový klient;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
R2 winmgmt;Služba WMI;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 wuauserv;Automatické aktualizace;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 WZCSVC;Automatická konfigurace bezdrátových zařízení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 ALG;Služba brány aplikačního rozhraní;c:\windows\system32\alg.exe [2008-4-14 44544]
R3 audstub;Prázdný zvukový ovladač;c:\windows\system32\drivers\audstub.sys [2008-11-21 3072]
R3 EventSystem;Systém událostí modelu COM+;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 Gpc;Obecné třídění paketů;c:\windows\system32\drivers\msgpc.sys [2008-4-14 35072]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio;c:\windows\system32\drivers\hdaudbus.sys [2008-4-13 144384]
R3 HTTP;HTTP;c:\windows\system32\drivers\http.sys [2008-4-14 265728]
R3 ialm;ialm;c:\windows\system32\drivers\igxpmp32.sys [2009-10-1 5760096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM);c:\windows\system32\drivers\RtkHDAud.sys [2009-10-1 4405248]
R3 IpNat;IP Network Address Translator;c:\windows\system32\drivers\ipnat.sys [2008-4-14 152832]
R3 MRxDAV;Přesměrovač klienta WebDav;c:\windows\system32\drivers\mrxdav.sys [2008-4-14 180608]
R3 mssmbios;Ovladač Microsoft System Management BIOS;c:\windows\system32\drivers\mssmbios.sys [2008-4-14 15488]
R3 NdisTapi;Ovladač Remote Access NDIS TAPI;c:\windows\system32\drivers\ndistapi.sys [2008-4-14 10112]
R3 Ndisuio;Protokol NDIS uživatelského režimu V/V;c:\windows\system32\drivers\ndisuio.sys [2008-4-14 14592]
R3 NdisWan;Ovladač Remote Access NDIS WAN;c:\windows\system32\drivers\ndiswan.sys [2008-4-14 91520]
R3 NDProxy;Služba NDIS Proxy;c:\windows\system32\drivers\ndproxy.sys [2008-4-14 40576]
R3 Netman;Síťová připojení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 Nla;Sledování umístění v síti (NLA);c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 PptpMiniport;WAN Miniport (PPTP);c:\windows\system32\drivers\raspptp.sys [2008-4-14 48384]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2008-4-14 69120]
R3 Ptilink;Direct Parallel Link Driver;c:\windows\system32\drivers\ptilink.sys [2007-10-29 17792]
R3 Rasl2tp;WAN Miniport (L2TP);c:\windows\system32\drivers\rasl2tp.sys [2008-4-14 51328]
R3 RasMan;Správce vzdáleného přístupu;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 RasPppoe;Remote Access PPPOE Driver;c:\windows\system32\drivers\raspppoe.sys [2008-4-14 41472]
R3 Raspti;Přímé propojení paralelním kabelem;c:\windows\system32\drivers\raspti.sys [2007-10-29 16512]
R3 rdpdr;Ovladač přesměrovače zařízení terminálového serveru;c:\windows\system32\drivers\rdpdr.sys [2008-11-21 196224]
R3 RDPWD;RDPWD;c:\windows\system32\drivers\rdpwd.sys [2008-11-21 139656]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver;c:\windows\system32\drivers\Rtenicxp.sys [2009-10-1 115328]
R3 serenum;Ovladač filtru Serenum;c:\windows\system32\drivers\serenum.sys [2008-4-14 15744]
R3 Srv;Srv;c:\windows\system32\drivers\srv.sys [2008-4-14 353792]
R3 SSDPSRV;Služba rozpoznávání pomocí protokolu SSDP;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
R3 swenum;Softwarový ovladač sběrnice;c:\windows\system32\drivers\swenum.sys [2008-4-14 4352]
R3 sysaudio;Microsoft Kernel System Audio Device;c:\windows\system32\drivers\sysaudio.sys [2009-10-1 60800]
R3 TapiSrv;Telefonní subsystém;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R3 TDTCP;TDTCP;c:\windows\system32\drivers\tdtcp.sys [2008-11-21 21896]
R3 TermService;Terminálová služba;c:\windows\system32\svchost -k dcomlaunch --> c:\windows\system32\svchost -k DComLaunch [?]
R3 Update;Ovladač aktualizace mikrokódu;c:\windows\system32\drivers\update.sys [2008-4-14 384768]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB;c:\windows\system32\drivers\usbccgp.sys [2008-4-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0;c:\windows\system32\drivers\usbehci.sys [2008-4-14 30208]
R3 usbhub;Rozbočovač umožnující USB2;c:\windows\system32\drivers\usbhub.sys [2008-4-14 59520]
R3 usbprint;Třída USB Printer;c:\windows\system32\drivers\usbprint.sys [2009-11-3 25856]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft;c:\windows\system32\drivers\usbuhci.sys [2009-10-1 20608]
R3 Wanarp;Ovladač Remote Access IP ARP;c:\windows\system32\drivers\wanarp.sys [2008-4-14 34560]
R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;c:\windows\system32\drivers\wdmaud.sys [2009-10-1 83072]
R4 Cdfs;Cdfs;c:\windows\system32\drivers\cdfs.sys [2008-4-14 63744]
R4 Ntfs;Ntfs;c:\windows\system32\drivers\ntfs.sys [2008-4-14 574976]
S1 Cdaudio;Cdaudio;c:\windows\system32\drivers\cdaudio.sys [2001-8-17 18688]
S1 Fdc;Fdc;c:\windows\system32\drivers\fdc.sys [2008-4-14 27392]
S1 Flpydisk;Flpydisk;c:\windows\system32\drivers\flpydisk.sys [2008-4-14 20480]
S1 Changer;Changer; [x]
S1 i2omgmt;i2omgmt; [x]
S1 Imapi;CD-Burning Filter Driver;c:\windows\system32\drivers\imapi.sys [2008-4-14 42112]
S1 kbdhid;Ovladač klávesnice standardu HID;c:\windows\system32\drivers\kbdhid.sys [2008-4-14 14592]
S1 lbrtfdc;lbrtfdc; [x]
S1 PCIDump;PCIDump; [x]
S1 Processor;Ovladač procesoru;c:\windows\system32\drivers\processr.sys [2008-4-14 39680]
S1 Sfloppy;Sfloppy;c:\windows\system32\drivers\sfloppy.sys [2008-4-14 11392]
S2 Browser;Prohledávání počítačů;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S2 wscsvc;Centrum zabezpečení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 aec;Microsoft Kernel Acoustic Echo Canceller;c:\windows\system32\drivers\aec.sys [2009-10-1 142592]
S3 AppMgmt;Správa aplikací;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 Arp1394;Protokol 1394 ARP Client;c:\windows\system32\drivers\arp1394.sys [2008-4-14 60800]
S3 AsyncMac;Ovladač asynchronních médií připojení RAS;c:\windows\system32\drivers\asyncmac.sys [2008-4-14 14336]
S3 Atmarpc;Protokol ATM ARP Client;c:\windows\system32\drivers\atmarpc.sys [2008-4-14 59904]
S3 BITS;Služba inteligentního přenosu na pozadí;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 catchme;catchme;\??\c:\docume~1\chir-l~1.mnc\locals~1\temp\catchme.sys --> c:\docume~1\chir-l~1.mnc\locals~1\temp\catchme.sys [?]
S3 CiSvc;Indexing Service;c:\windows\system32\cisvc.exe [2008-4-14 5632]
S3 ClipSrv;Síťová schránka;c:\windows\system32\clipsrv.exe [2008-4-14 33280]
S3 COMSysApp;Systémové aplikace modelu COM+;c:\windows\system32\dllhost.exe [2008-4-14 5120]
S3 dmadmin;Služba správy pro Správce logických disků;c:\windows\system32\dmadmin.exe [2008-4-14 225280]
S3 DMusic;Syntezátor Microsoft Kernel DLS;c:\windows\system32\drivers\DMusic.sys [2009-10-1 52864]
S3 Dot3svc;Automatická konfigurace pevné sítě;c:\windows\system32\svchost.exe -k dot3svc [2008-4-14 14336]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler;c:\windows\system32\drivers\drmkaud.sys [2009-10-1 2944]
S3 EapHost;Služba EAP (Extensible Authentication Protocol);c:\windows\system32\svchost.exe -k eapsvcs [2008-4-14 14336]
S3 EhttpSrv;Eset HTTP Server;c:\program files\eset\eset nod32 antivirus\EHttpSrv.exe [2009-10-7 20680]
S3 FastUserSwitchingCompatibility;Kompatibilita pro rychlé přepínání uživatelů;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 hidusb;Ovladač třídy standardu HID;c:\windows\system32\drivers\hidusb.sys [2008-4-14 10368]
S3 hkmsvc;Služba Správa klíčů a certifikátů stavu;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 HTTPFilter;HTTP SSL;c:\windows\system32\svchost.exe -k HTTPFilter [2008-4-14 14336]
S3 ImapiService;Služba modelu COM pro zápis na disk CD (IMAPI);c:\windows\system32\imapi.exe [2008-4-14 150528]
S3 Ip6Fw;Ovladač IPv6 brány firewall systému Windows;c:\windows\system32\drivers\ip6fw.sys [2008-4-14 36608]
S3 IpFilterDriver;IP Traffic Filter Driver;c:\windows\system32\drivers\ipfltdrv.sys [2007-10-29 32896]
S3 IpInIp;IP in IP Tunnel Driver;c:\windows\system32\drivers\ipinip.sys [2008-4-14 20864]
S3 IRENUM;Služba čítače výčtu IR;c:\windows\system32\drivers\irenum.sys [2008-11-21 11264]
S3 kmixer;Směšovač Microsoft Kernel Wave Audio Mixer;c:\windows\system32\drivers\kmixer.sys [2009-10-1 172416]
S3 mnmsrvc;NetMeeting - Vzdálené sdílení plochy;c:\windows\system32\mnmsrvc.exe [2008-11-21 32768]
S3 Modem;Modem;c:\windows\system32\drivers\modem.sys [2008-4-14 30080]
S3 motmodem;Motorola USB CDC ACM Driver;c:\windows\system32\drivers\motmodem.sys [2009-11-9 23680]
S3 mouhid;Ovladač myši standardu HID;c:\windows\system32\drivers\mouhid.sys [2001-10-24 12160]
S3 MSDTC;Koordinátor DTC;c:\windows\system32\msdtc.exe [2008-11-21 6144]
S3 MSIServer;Windows Installer;c:\windows\system32\msiexec.exe [2008-4-14 78848]
S3 MSKSSRV;Microsoft Streaming Service Proxy;c:\windows\system32\drivers\MSKSSRV.sys [2009-10-1 7552]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy;c:\windows\system32\drivers\MSPCLOCK.sys [2009-10-1 5376]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy;c:\windows\system32\drivers\MSPQM.sys [2009-10-1 4992]
S3 napagent;Agent architektury NAP (Network Access Protection);c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 NIC1394;1394 Net Driver;c:\windows\system32\drivers\nic1394.sys [2008-4-14 61824]
S3 NtLmSsp;Zprostředkovatel zabezpečení NT LM;c:\windows\system32\lsass.exe [2008-4-14 13312]
S3 NtmsSvc;Vyměnitelné úložiště;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 NwlnkFlt;IPX Traffic Filter Driver;c:\windows\system32\drivers\nwlnkflt.sys [2007-10-29 12416]
S3 NwlnkFwd;IPX Traffic Forwarder Driver;c:\windows\system32\drivers\nwlnkfwd.sys [2007-10-29 32512]
S3 odserv;Microsoft Office Diagnostics Service;c:\program files\common files\microsoft shared\office12\ODSERV.EXE [2008-11-4 441712]
S3 ose;Office Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2006-10-26 145184]
S3 Parport;Ovladač paralelního portu;c:\windows\system32\drivers\parport.sys [2008-4-14 80000]
S3 PDCOMP;PDCOMP; [x]
S3 PDFRAME;PDFRAME; [x]
S3 PDRELI;PDRELI; [x]
S3 PDRFRAME;PDRFRAME; [x]
S3 RasAuto;Správce automatického připojení pomocí vzdáleného přístupu;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 RDSessMgr;Správce relací nápovědy ke vzdálené ploše;c:\windows\system32\sessmgr.exe [2008-11-21 141824]
S3 RpcLocator;Lokátor vzdáleného volání procedur (RPC);c:\windows\system32\locator.exe [2008-4-14 75264]
S3 RSVP;QoS RSVP;c:\windows\system32\rsvp.exe [2007-10-29 132608]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\RTL8139.sys [2008-11-21 20992]
S3 SCardSvr;Smart Card;c:\windows\system32\scardsvr.exe [2008-4-14 97792]
S3 Secdrv;Secdrv;c:\windows\system32\drivers\secdrv.sys [2008-4-13 20480]
S3 splitter;Microsoft Kernel Audio Splitter;c:\windows\system32\drivers\splitter.sys [2009-10-1 6272]
S3 stisvc;Načítání obrázků (WIA);c:\windows\system32\svchost.exe -k imgsvc [2008-4-14 14336]
S3 swmidi;Microsoft Kernel GS Wavetable Synthesizer;c:\windows\system32\drivers\swmidi.sys [2009-10-1 56576]
S3 SwPrv;MS Software Shadow Copy Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120]
S3 SysmonLog;Výstrahy a protokolování výkonu;c:\windows\system32\smlogsvc.exe [2008-4-14 90112]
S3 TDPIPE;TDPIPE;c:\windows\system32\drivers\tdpipe.sys [2008-11-21 12040]
S3 TlntSvr;Telnet;c:\windows\system32\tlntsvr.exe [2008-4-14 73728]
S3 upnphost;Hostitel zařízení UPnP;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
S3 UPS;Nepřerušitelný zdroj napájení (UPS);c:\windows\system32\ups.exe [2008-4-14 18432]
S3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;c:\windows\system32\drivers\usbohci.sys [2008-4-14 17152]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;c:\windows\system32\drivers\USBSTOR.SYS [2008-11-21 26368]
S3 VSS;Stínová kopie svazku;c:\windows\system32\vssvc.exe [2008-4-14 290816]
S3 Wdf01000;Wdf01000;c:\windows\system32\drivers\wdf01000.sys [2006-11-2 492000]
S3 WDICA;WDICA; [x]
S3 WmdmPmSN;Služba sériového čísla přenosného zařízení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 Wmi;Rozšíření ovladače WMI;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 WmiApSrv;Adaptér výkonu služby WMI;c:\windows\system32\wbem\wmiapsrv.exe [2008-11-21 126464]
S3 xmlprov;Služba pro síťová ustanovení;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S4 Abiosdsk;Abiosdsk; [x]
S4 abp480n5;abp480n5; [x]
S4 ACPIEC;ACPIEC;c:\windows\system32\drivers\acpiec.sys [2007-10-29 11776]
S4 adpu160m;adpu160m; [x]
S4 Aha154x;Aha154x; [x]
S4 aic78u2;aic78u2; [x]
S4 aic78xx;aic78xx; [x]
S4 Alerter;Výstrahy;c:\windows\system32\svchost.exe -k LocalService [2008-4-14 14336]
S4 AliIde;AliIde; [x]
S4 amsint;amsint; [x]
S4 asc;asc; [x]
S4 asc3350p;asc3350p; [x]
S4 asc3550;asc3550; [x]
S4 Atdisk;Atdisk; [x]
S4 cbidf2k;cbidf2k;c:\windows\system32\drivers\cbidf2k.sys [2007-10-29 13952]
S4 cd20xrnt;cd20xrnt; [x]
S4 CmdIde;CmdIde; [x]
S4 Cpqarray;Cpqarray; [x]
S4 dac960nt;dac960nt; [x]
S4 dmboot;dmboot;c:\windows\system32\drivers\dmboot.sys [2008-4-14 800000]
S4 dpti2o;dpti2o; [x]
S4 Fastfat;Fastfat;c:\windows\system32\drivers\fastfat.sys [2008-4-14 143744]
S4 HidServ;Přístup k zařízením standardu HID;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S4 hpn;hpn; [x]
S4 i2omp;i2omp; [x]
S4 ini910u;ini910u; [x]
S4 IntelIde;IntelIde; [x]
S4 Messenger;Kurýrní služba;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S4 mraid35x;mraid35x; [x]
S4 NetDDE;Služba DDE v síti;c:\windows\system32\netdde.exe [2008-4-14 111616]
S4 NetDDEdsdm;Správce DSDM služby DDE v síti;c:\windows\system32\netdde.exe [2008-4-14 111616]
S4 ParVdm;ParVdm;c:\windows\system32\drivers\parvdm.sys [2007-10-29 6784]
S4 Pcmcia;Pcmcia;c:\windows\system32\drivers\pcmcia.sys [2008-4-14 120064]
S4 perc2;perc2; [x]
S4 perc2hib;perc2hib; [x]
S4 ql1080;ql1080; [x]
S4 Ql10wnt;Ql10wnt; [x]
S4 ql12160;ql12160; [x]
S4 ql1240;ql1240; [x]
S4 ql1280;ql1280; [x]
S4 RemoteAccess;Směrování a vzdálený přístup;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S4 Simbad;Simbad; [x]
S4 Sparrow;Sparrow; [x]
S4 sym_hi;sym_hi; [x]
S4 sym_u3;sym_u3; [x]
S4 symc810;symc810; [x]
S4 symc8xx;symc8xx; [x]
S4 TosIde;TosIde; [x]
S4 Udfs;Udfs;c:\windows\system32\drivers\udfs.sys [2008-4-14 66048]
S4 ultra;ultra; [x]
S4 ViaIde;ViaIde; [x]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS;c:\windows\system32\drivers\ws2ifsl.sys [2007-10-29 12032]
============== File Associations ===============
batfile="%1" %*
chm.file="c:\windows\hh.exe" %1
cmdfile="%1" %*
comfile="%1" %*
exefile="%1" %*
inffile=%SystemRoot%\System32\NOTEPAD.EXE %1
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1
JSEFile=%SystemRoot%\System32\WScript.exe "%1" %*
piffile="%1" %*
regedit=regedit.exe %1
regfile=regedit.exe "%1"
scrfile="%1" /S
txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1
VBEFile=%SystemRoot%\System32\WScript.exe "%1" %*
VBSFile=%SystemRoot%\System32\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-05-12 14:52:37 77312 ----a-w- C:\mbr.exe
2010-05-12 13:40:18 0 dc-h--w- c:\windows\$NtUninstallKB978542$
2010-05-10 20:54:43 0 d-s---w- C:\abraka
2010-05-10 16:03:33 9638 ----a-w- C:\Qoobox.zip
2010-05-09 19:22:23 211 ----a-w- C:\Boot.bak
2010-05-09 19:22:20 261312 ----a-w- C:\cmldr
2010-05-09 19:22:17 0 d-sha-r- C:\cmdcons
2010-05-09 19:19:11 77312 ----a-w- c:\windows\MBR.exe
2010-05-09 19:19:11 31232 ----a-w- c:\windows\NIRCMD.exe
2010-05-09 19:19:09 256512 ----a-w- c:\windows\PEV.exe
2010-05-09 19:19:09 161792 ----a-w- c:\windows\SWREG.exe
2010-05-09 19:19:08 98816 ----a-w- c:\windows\sed.exe
2010-05-09 19:19:08 80412 ----a-w- c:\windows\grep.exe
2010-05-09 19:19:08 68096 ----a-w- c:\windows\zip.exe
2010-05-09 19:19:07 212480 ----a-w- c:\windows\SWXCACLS.exe
2010-05-09 19:19:07 136704 ----a-w- c:\windows\SWSC.exe
2010-05-09 19:18:53 0 d-----w- c:\windows\ERDNT
2010-05-09 19:17:39 0 d-----w- C:\Qoobox
2010-05-07 20:07:29 0 d-----w- C:\rsit
2010-05-05 18:55:25 0 d-----w- c:\docume~1\alluse~1\dataap~1\Spybot - Search & Destroy
2010-05-05 18:54:57 0 d-----w- c:\windows\pss
2010-05-05 18:54:05 1640400 ----a-w- c:\windows\PCTBDCore.dll.old
2010-05-05 18:52:46 0 d---a-w- c:\docume~1\alluse~1\dataap~1\TEMP
2010-05-05 16:37:11 0 d-----w- c:\program files\Crawler
2010-04-28 11:21:07 0 d-----w- c:\documents and settings\all users\Studio14Trial
2010-04-28 10:36:10 2013892704 ----a-w- C:\PinnacleStudio14Trial.exe
2010-04-21 05:11:27 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-20 06:46:03 0 d-----w- c:\program files\Zeallsoft
2010-04-16 17:59:40 0 d-----w- c:\program files\common files\Adobe
2010-04-16 17:59:40 0 d-----w- c:\program files\Adobe
2010-04-15 13:28:06 0 dc-h--w- c:\windows\$NtUninstallKB979683$
2010-04-15 13:27:57 0 dc-h--w- c:\windows\$NtUninstallKB980232$
2010-04-15 13:27:56 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-04-15 13:27:52 0 dc-h--w- c:\windows\$NtUninstallKB979402_WM9$
2010-04-15 13:27:13 0 dc-h--w- c:\windows\$NtUninstallKB981349$
2010-04-15 13:27:06 0 dc-h--w- c:\windows\$NtUninstallKB978338$
2010-04-15 13:26:59 0 dc-h--w- c:\windows\$NtUninstallKB977816$
2010-04-13 21:48:09 0 dc-h--w- c:\windows\$NtUninstallKB978601$
2010-04-13 21:48:03 0 dc-h--w- c:\windows\$NtUninstallKB979309$
==================== Find3M ====================
2010-05-12 15:05:03 49152 ---ha-w- c:\documents and settings\chir-lekar.mncaslav\ntuser.dat.LOG
2010-05-12 15:03:07 1570834 ----a-w- c:\windows\WindowsUpdate.log
2010-05-12 14:53:16 2048 --s-a-w- c:\windows\bootstat.dat
2010-05-12 14:53:13 2145386496 --sha-w- C:\pagefile.sys
2010-05-12 13:41:16 32578 ----a-w- c:\windows\SchedLgU.Txt
2010-05-12 13:41:15 3932160 ---ha-w- c:\documents and settings\chir-lekar.mncaslav\NTUSER.DAT
2010-05-12 13:40:24 738297 ----a-w- c:\windows\iis6.log
2010-05-12 13:40:24 642816 ----a-w- c:\windows\FaxSetup.log
2010-05-12 13:40:24 45142 ----a-w- c:\windows\MedCtrOC.log
2010-05-12 13:40:24 40340 ----a-w- c:\windows\ocmsn.log
2010-05-12 13:40:24 33016 ----a-w- c:\windows\tabletoc.log
2010-05-12 13:40:24 32559 ----a-w- c:\windows\msgsocm.log
2010-05-12 13:40:24 319144 ----a-w- c:\windows\ocgen.log
2010-05-12 13:40:24 303508 ----a-w- c:\windows\tsoc.log
2010-05-12 13:40:24 225791 ----a-w- c:\windows\comsetup.log
2010-05-12 13:40:24 135513 ----a-w- c:\windows\ntdtcsetup.log
2010-05-12 13:40:24 113765 ----a-w- c:\windows\netfxocm.log
2010-05-12 13:40:23 209734 ----a-w- c:\windows\msmqinst.log
2010-05-12 13:39:38 178 --sh--w- c:\documents and settings\chir-lekar.mncaslav\ntuser.ini
2010-05-10 04:57:17 281 --sha-r- C:\boot.ini
2010-05-01 13:46:56 751563 ----a-w- c:\windows\setupapi.log
2010-04-30 18:51:06 32058312 ----a-w- c:\windows\system32\MRT.exe
2010-04-26 05:35:25 88544 ----a-w- c:\windows\inf\oem15.PNF
2010-04-26 05:35:25 68754 ----a-w- c:\windows\inf\oem17.PNF
2010-04-26 05:35:25 12606 ----a-w- c:\windows\inf\oem19.PNF
2010-04-26 05:35:24 88012 ----a-w- c:\windows\inf\oem8.PNF
2010-04-26 05:35:24 11992 ----a-w- c:\windows\inf\oem16.PNF
2010-04-26 05:35:24 11184 ----a-w- c:\windows\inf\oem18.PNF
2010-04-26 05:32:27 4676 ----a-w- c:\windows\inf\branches.PNF
2010-04-26 05:32:27 1553392 ----a-w- c:\windows\inf\INFCACHE.1
2010-04-15 15:55:04 10677 ----a-w- c:\windows\spupdsvc.log
2010-04-15 13:27:56 9512 ----a-w- c:\windows\wmsetup.log
2010-04-13 21:48:12 65235 ----a-w- c:\windows\updspapi.log
2010-04-01 07:43:18 723102 ----a-w- c:\windows\system32\PerfStringBackup.INI
2010-04-01 07:43:18 47206 ----a-w- c:\windows\system32\perfc005.dat
2010-04-01 07:43:18 40836 ----a-w- c:\windows\system32\perfc009.dat
2010-04-01 07:43:18 314508 ----a-w- c:\windows\system32\perfh009.dat
2010-04-01 07:43:18 312970 ----a-w- c:\windows\system32\perfh005.dat
2010-03-31 13:20:24 98835 ----a-w- c:\windows\KB980182-IE7.log
2010-03-24 07:35:42 9808 ----a-w- c:\windows\EventSystem.log
2010-03-19 16:05:50 4874240 ----a-w- c:\windows\system32\wmp.dll
2010-03-10 14:03:44 6462 ----a-w- c:\windows\KB975561.log
2010-03-10 13:17:46 389120 ----a-w- c:\windows\system32\html.iec
2010-03-10 13:17:16 70656 ----a-w- c:\windows\system32\ie4uinit.exe
2010-03-10 13:17:16 13824 ----a-w- c:\windows\system32\ieudinit.exe
2010-03-09 11:11:23 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 23:25:47 3786 ----a-w- c:\windows\KB979306.log
2010-02-24 23:25:47 217930 ----a-w- c:\windows\system32\TZLog.log
2010-02-23 05:18:28 161792 ----a-w- c:\windows\system32\ieakui.dll
2010-02-20 17:46:27 62380 ----a-w- c:\windows\inf\font.PNF
2010-02-16 19:08:57 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:08:57 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:35:01 100864 ----a-w- c:\windows\system32\6to4svc.dll
2009-11-04 13:19:50 13826 ----a-w- c:\windows\inf\oem12.PNF
2009-11-04 13:19:47 44964 ----a-w- c:\windows\inf\printupg.PNF
2009-11-04 13:19:45 1317460 ----a-w- c:\windows\inf\ntprint.PNF
2009-11-03 09:02:04 61308 ----a-w- c:\windows\inf\msnetmtg.PNF
2009-11-03 09:00:48 5492 ----a-w- c:\windows\inf\usbprint.PNF
2009-10-02 06:57:03 465292 ----a-w- c:\windows\inf\intl.PNF
2009-10-01 15:14:45 24696 ----a-w- c:\windows\inf\ksfilter.PNF
2009-10-01 15:14:44 240260 ----a-w- c:\windows\inf\oem9.PNF
2009-10-01 15:14:41 93340 ----a-w- c:\windows\inf\ks.PNF
2009-10-01 15:14:41 45016 ----a-w- c:\windows\inf\wdmaudio.PNF
2009-10-01 15:14:22 108468 ----a-w- c:\windows\inf\monitor.PNF
2009-10-01 15:14:15 10654 ----a-w- c:\windows\inf\oem7.PNF
2009-10-01 15:13:53 9248 ----a-w- c:\windows\inf\oem6.PNF
2009-10-01 15:13:51 6768 ----a-w- c:\windows\inf\oem5.PNF
2009-10-01 15:13:46 10346 ----a-w- c:\windows\inf\oem4.PNF
2009-10-01 15:13:44 5672 ----a-w- c:\windows\inf\oem3.PNF
2009-10-01 15:13:38 221928 ----a-w- c:\windows\inf\oem2.PNF
2009-08-06 18:22:18 57552 ----a-w- c:\windows\inf\wuau.adm
2008-11-24 21:31:01 3788 ----a-w- c:\windows\inf\minioc.PNF
2008-11-21 19:48:24 38104 ----a-w- c:\windows\inf\usbstor.PNF
2008-11-21 18:56:04 11098 ----a-w- c:\windows\inf\oem1.PNF
2008-11-21 18:55:57 4440 ----a-w- c:\windows\inf\ieaccess.PNF
2008-11-21 18:55:43 1612 ----a-w- c:\windows\inf\ieaccess.inf
2008-11-21 18:45:34 139136 ----a-w- c:\windows\inf\sapi5.PNF
2008-11-21 18:41:33 7548 ----a-w- c:\windows\inf\msnmsn.PNF
2008-11-21 17:57:09 222468 ----a-w- c:\windows\inf\drvindex.PNF
2008-11-21 17:57:09 17704 ----a-w- c:\windows\inf\fp40ext.PNF
2008-11-21 17:57:09 101948 ----a-w- c:\windows\inf\syssetup.PNF
2008-11-21 17:57:06 21368 ----a-w- c:\windows\inf\wab50.PNF
2008-11-21 17:57:05 57572 ----a-w- c:\windows\inf\wmp.PNF
2008-11-21 17:57:04 87736 ----a-w- c:\windows\inf\msmsgs.PNF
2008-11-21 17:57:04 36124 ----a-w- c:\windows\inf\msoe50.PNF
2008-11-21 17:57:02 16784 ----a-w- c:\windows\inf\wordpad.PNF
2008-11-21 17:57:02 1056884 ----a-w- c:\windows\inf\LAYOUT.PNF
2008-10-20 03:35:42 559370 ----a-w- c:\windows\inf\oem2.inf
2008-04-14 09:49:42 411768 ----a-w- c:\windows\inf\layout.inf
2008-04-14 08:16:02 51902 ----a-w- c:\windows\inf\accessor.inf
2008-04-14 08:16:02 239806 ----a-w- c:\windows\inf\tsoc.inf
2008-04-14 08:16:02 16216 ----a-w- c:\windows\inf\wordpad.inf
2008-04-14 08:16:02 11802 ----a-w- c:\windows\inf\multimed.inf
2008-04-14 08:16:00 858162 ----a-w- c:\windows\inf\iis.inf
2008-04-14 08:16:00 102002 ----a-w- c:\windows\inf\fxsocm.inf
2008-04-13 21:15:00 1498978 ----a-w- c:\windows\inf\ntprint.inf
2008-04-13 21:14:26 925108 ----a-w- c:\windows\inf\intl.inf
2008-04-13 21:13:44 67899 ----a-w- c:\windows\inf\drvindex.inf
2008-04-13 21:13:26 48046 ----a-w- c:\windows\inf\biosinfo.inf
2008-03-28 20:33:26 16034 ----a-w- c:\windows\inf\fp40ext.inf
2007-11-02 14:53:32 8015 ----a-w- c:\windows\inf\oem19.inf
2007-11-02 14:49:52 7095 ----a-w- c:\windows\inf\oem16.inf
2007-11-02 14:48:08 5921 ----a-w- c:\windows\inf\oem18.inf
2007-11-02 14:48:04 51833 ----a-w- c:\windows\inf\oem17.inf
2007-11-02 14:38:58 103869 ----a-w- c:\windows\inf\oem15.inf
2007-10-15 19:27:40 1803734 ----a-w- c:\windows\inf\system.adm
2007-10-04 08:12:30 39158 ----a-w- c:\windows\inf\iem\0405\inetset.iem
2007-10-04 08:12:28 2417894 ----a-w- c:\windows\inf\inetres.adm
2007-10-04 08:12:22 14026 ----a-w- c:\windows\inf\iem\0405\inetcorp.iem
2007-08-09 17:32:43 6151 ----a-w- c:\windows\inf\oem6.inf
2007-08-09 17:32:42 5873 ----a-w- c:\windows\inf\oem4.inf
2007-08-09 17:32:42 3970 ----a-w- c:\windows\inf\oem5.inf
2007-08-09 17:32:39 5876 ----a-w- c:\windows\inf\oem7.inf
2007-08-09 17:32:37 3722 ----a-w- c:\windows\inf\oem3.inf
2007-07-09 23:51:58 16944 ----a-w- c:\windows\inf\oem12.inf
2007-04-16 06:16:58 67595 ----a-w- c:\windows\inf\oem8.inf
2007-03-14 16:13:20 69570 ----a-w- c:\windows\inf\wmplayer.adm
2007-03-14 16:06:30 19177 ----a-w- c:\windows\inf\inetset.adm
2007-03-14 16:04:02 41300 ----a-w- c:\windows\inf\conf.adm
2007-01-08 11:17:20 36782 ----a-w- c:\windows\inf\AER_1029.ADM
2006-12-21 08:30:00 160283 ----a-w- c:\windows\inf\oem9.inf
2006-08-24 07:35:04 5484 ----a-w- c:\windows\inf\oem1.inf
2007-10-29 12:00:00 48680 --sha-w- c:\windows\winnt.bmp
2007-10-29 12:00:00 48680 --sha-w- c:\windows\winnt256.bmp
2008-11-21 17:53:34 67 --sha-w- c:\windows\fonts\desktop.ini
2008-04-14 08:05:50 2880966 --sha-r- c:\windows\pchealth\helpctr\packagestore\instance_Professional_32_1029.cab
2008-11-21 17:53:12 783 --sha-r- c:\windows\pchealth\helpctr\packagestore\package_1.cab
2008-11-21 17:53:12 20362 --sha-r- c:\windows\pchealth\helpctr\packagestore\package_2.cab
2008-11-21 17:53:12 246755 --sha-r- c:\windows\pchealth\helpctr\packagestore\package_3.cab
2007-10-29 12:00:00 7068 --sha-r- c:\windows\pchealth\helpctr\packagestore\package_4.cab
2007-03-14 16:05:32 354884 --sha-r- c:\windows\pchealth\helpctr\packagestore\package_5.cab
2008-11-21 18:45:13 62 --sha-w- c:\windows\system32\config\systemprofile\data aplikací\desktop.ini
2008-11-21 17:57:04 2568 --sha-w- c:\windows\system32\config\systemprofile\data aplikací\microsoft\internet explorer\Desktop.htt
2008-11-21 17:57:10 125 --sha-w- c:\windows\system32\config\systemprofile\data aplikací\microsoft\internet explorer\quick launch\desktop.ini
2008-11-21 18:59:17 81 --sha-w- c:\windows\system32\config\systemprofile\dokumenty\desktop.ini
2008-11-21 18:59:17 186 --sha-w- c:\windows\system32\config\systemprofile\dokumenty\hudba\Desktop.ini
2008-11-21 18:59:17 279 --sha-w- c:\windows\system32\config\systemprofile\dokumenty\obrázky\Desktop.ini
2009-10-01 10:07:18 62 --sha-w- c:\windows\system32\config\systemprofile\local settings\desktop.ini
2008-11-21 18:59:20 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\desktop.ini
2008-11-21 19:02:29 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\index.dat
2008-11-21 18:59:20 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\beall32t\desktop.ini
2008-11-21 18:59:20 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\ca36ymgx\desktop.ini
2008-11-21 18:59:20 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\k9f8tadq\desktop.ini
2008-11-21 18:59:20 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\data aplikací\microsoft\feeds cache\qn5qhloq\desktop.ini
2009-10-02 06:28:04 145 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\desktop.ini
2009-10-02 06:28:04 145 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\desktop.ini
2009-11-03 09:00:52 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009110320091104\index.dat
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\desktop.ini
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\desktop.ini
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\m6joofod\desktop.ini
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\n4of67lq\desktop.ini
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\uok8cpij\desktop.ini
2009-10-02 06:28:04 67 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\yujyi3iv\desktop.ini
2008-11-21 18:45:13 62 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\desktop.ini
2008-11-21 17:57:10 231 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\programy\desktop.ini
2008-11-21 17:54:03 84 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\programy\po spuštění\desktop.ini
2008-11-21 17:57:06 576 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\programy\příslušenství\desktop.ini
2008-11-21 17:54:03 293 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\programy\příslušenství\usnadnění\desktop.ini
2008-11-21 17:54:03 84 --sha-w- c:\windows\system32\config\systemprofile\nabídka start\programy\příslušenství\zábava\desktop.ini
2008-11-21 17:57:10 122 --sha-w- c:\windows\system32\config\systemprofile\oblíbené položky\Desktop.ini
2008-11-21 17:57:10 150 --sha-w- c:\windows\system32\config\systemprofile\recent\Desktop.ini
2008-11-21 17:52:56 188 --sha-w- c:\windows\system32\config\systemprofile\sendto\desktop.ini
2006-12-28 23:31:32 19569 --sh--r- c:\windows\system32\restore\filelist.xml
2009-11-03 09:01:20 16384 --sha-w- c:\windows\temp\cookies\index.dat
2009-10-02 06:57:08 145 --sh--w- c:\windows\temp\history\history.ie5\desktop.ini
2009-11-03 09:01:20 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat
2009-10-02 06:57:08 67 --sh--w- c:\windows\temp\temporary internet files\content.ie5\desktop.ini
2009-11-03 09:01:20 16384 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat
2009-10-02 06:57:08 67 --sh--w- c:\windows\temp\temporary internet files\content.ie5\1x5y86as\desktop.ini
2009-10-02 06:57:08 67 --sh--w- c:\windows\temp\temporary internet files\content.ie5\5fzfc33t\desktop.ini
2009-10-02 06:57:08 67 --sh--w- c:\windows\temp\temporary internet files\content.ie5\9po9qpmr\desktop.ini
2009-10-02 06:57:08 67 --sh--w- c:\windows\temp\temporary internet files\content.ie5\a0n6ny1i\desktop.ini
============= FINISH: 17:05:15,59 ===============
Re: Padá net, nelze odeslat HijackThis log mailem
Napsal: 08 čer 2010 14:26
od Kryšpín
Nevím jestli je to to, co potřebuješ, ale dám to sem
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"User Agent"="Mozilla/4.0 (compatible; MSIE 7.0; Win32)"
"IE5_UA_Backup_Flag"="5.0"
"NoNetAutodial"=dword:00000000
"MigrateProxy"=dword:00000001
"EmailName"="IEUser@"
"AutoConfigProxy"="wininet.dll"
"MimeExclusionListForCache"="multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "
"WarnOnPost"=hex:01,00,00,00
"UseSchannelDirectly"=hex:01,00,00,00
"EnableHttp1_1"=dword:00000001
"PrivacyAdvanced"=dword:00000000
"EnableNegotiate"=dword:00000001
"ProxyEnable"=dword:00000000
"UrlEncoding"=dword:00000000
"SecureProtocols"=dword:000000a0
"PrivDiscUiShown"=dword:00000001
"ZonesSecurityUpgradeDone"=dword:00000001
"DisableCachingOfSSLPages"=dword:00000000
"WarnonZoneCrossing"=dword:00000000
"CertificateRevocation"=dword:00000000
"GlobalUserOffline"=dword:00000000
"ProxyOverride"="<local>"
"EnableAutodial"=dword:00000000
"ProxyServer"="http=127.0.0.1:5555"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache]
"Signature"="Client UrlCache MMF Ver 5.2"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix"=""
"CacheLimit"=dword:00e8e035
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix"="Cookie:"
"CacheLimit"=dword:00002000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,20,00,53,00,65,00,74,\
00,74,00,69,00,6e,00,67,00,73,00,5c,00,44,00,61,00,74,00,61,00,20,00,61,00,\
70,00,6c,00,69,00,6b,00,61,00,63,00,ed,00,5c,00,4d,00,69,00,63,00,72,00,6f,\
00,73,00,6f,00,66,00,74,00,5c,00,46,00,65,00,65,00,64,00,73,00,20,00,43,00,\
61,00,63,00,68,00,65,00,00,00
"CachePrefix"="feedplat:"
"CacheLimit"=dword:00002000
"CacheOptions"=dword:00000000
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010051720100524]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,20,00,53,00,65,00,74,\
00,74,00,69,00,6e,00,67,00,73,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,\
79,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,79,00,2e,00,49,00,45,00,35,\
00,5c,00,4d,00,53,00,48,00,69,00,73,00,74,00,30,00,31,00,32,00,30,00,31,00,\
30,00,30,00,35,00,31,00,37,00,32,00,30,00,31,00,30,00,30,00,35,00,32,00,34,\
00,00,00
"CachePrefix"=":2010051720100524: "
"CacheLimit"=dword:00002000
"CacheOptions"=dword:0000000b
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010052420100531]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,20,00,53,00,65,00,74,\
00,74,00,69,00,6e,00,67,00,73,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,\
79,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,79,00,2e,00,49,00,45,00,35,\
00,5c,00,4d,00,53,00,48,00,69,00,73,00,74,00,30,00,31,00,32,00,30,00,31,00,\
30,00,30,00,35,00,32,00,34,00,32,00,30,00,31,00,30,00,30,00,35,00,33,00,31,\
00,00,00
"CachePrefix"=":2010052420100531: "
"CacheLimit"=dword:00002000
"CacheOptions"=dword:0000000b
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010053120100607]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,20,00,53,00,65,00,74,\
00,74,00,69,00,6e,00,67,00,73,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,\
79,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,79,00,2e,00,49,00,45,00,35,\
00,5c,00,4d,00,53,00,48,00,69,00,73,00,74,00,30,00,31,00,32,00,30,00,31,00,\
30,00,30,00,35,00,33,00,31,00,32,00,30,00,31,00,30,00,30,00,36,00,30,00,37,\
00,00,00
"CachePrefix"=":2010053120100607: "
"CacheLimit"=dword:00002000
"CacheOptions"=dword:0000000b
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010060720100608]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,20,00,53,00,65,00,74,\
00,74,00,69,00,6e,00,67,00,73,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,\
79,00,5c,00,48,00,69,00,73,00,74,00,6f,00,72,00,79,00,2e,00,49,00,45,00,35,\
00,5c,00,4d,00,53,00,48,00,69,00,73,00,74,00,30,00,31,00,32,00,30,00,31,00,\
30,00,30,00,36,00,30,00,37,00,32,00,30,00,31,00,30,00,30,00,36,00,30,00,38,\
00,00,00
"CachePrefix"=":2010060720100608: "
"CacheLimit"=dword:00002000
"CacheOptions"=dword:0000000b
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData]
"CachePath"=hex(2):25,00,55,00,53,00,45,00,52,00,50,00,52,00,4f,00,46,00,49,00,\
4c,00,45,00,25,00,5c,00,55,00,73,00,65,00,72,00,44,00,61,00,74,00,61,00,00,\
00
"CachePrefix"="UserData"
"CacheLimit"=dword:000003e8
"CacheOptions"=dword:00000008
"CacheRepair"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix"="Visited:"
"CacheLimit"=dword:00002000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache]
"Persistent"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Content]
"CacheLimit"=dword:00e8e035
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Cookies]
"CacheLimit"=dword:00002000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\History]
"CacheLimit"=dword:00002000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings"=hex:46,00,00,00,07,00,00,00,01,00,00,00,13,00,00,\
00,68,74,74,70,3d,31,32,37,2e,30,2e,30,2e,31,3a,35,35,35,35,07,00,00,00,3c,\
6c,6f,63,61,6c,3e,00,00,00,00,00,00,00,00,00,00,00,00,00,26,ea,db,06,4c,c9,\
01,01,00,00,00,c0,a8,58,09,00,00,00,00,00,00,00,00,00,00,00,00
"SavedLegacySettings"=hex:46,00,00,00,1e,03,00,00,01,00,00,00,13,00,00,00,68,\
74,74,70,3d,31,32,37,2e,30,2e,30,2e,31,3a,35,35,35,35,07,00,00,00,3c,6c,6f,\
63,61,6c,3e,00,00,00,00,00,00,00,00,00,00,00,00,00,26,ea,db,06,4c,c9,01,01,\
00,00,00,c0,a8,58,09,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
@=""
"DisplayName"="My Computer"
"Description"="Your computer"
"Icon"="explorer.exe#0100"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000021
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000000
"1207"=dword:00000003
"1400"=dword:00000001
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000000
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000000
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000000
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000000
"1805"=dword:00000000
"1806"=dword:00000000
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000003
"180D"=dword:00000000
"1A00"=dword:00000000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000000
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00000000
"1E05"=dword:00030000
"2000"=dword:00010000
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"PMDisplayName"="My Computer [Protected Mode]"
"LowIcon"="inetcpl.cpl#005422"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000000
"180A"=dword:00000000
"180C"=dword:00000000
"2301"=dword:00000003
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
@=""
"DisplayName"="Local intranet"
"Description"="This zone contains all Web sites that are on your organization's intranet."
"Icon"="shell32.dll#0018"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000143
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000000
"1207"=dword:00000003
"1400"=dword:00000001
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000001
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000000
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000000
"1806"=dword:00000000
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000003
"180D"=dword:00000000
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000000
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00000000
"1E05"=dword:00030000
"2000"=dword:00010000
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"PMDisplayName"="Local intranet [Protected Mode]"
"LowIcon"="inetcpl.cpl#005423"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000003
"180A"=dword:00000000
"180C"=dword:00000000
"2301"=dword:00000003
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
@=""
"DisplayName"="Trusted sites"
"Description"="This zone contains Web sites that you trust not to damage your computer or data."
"Icon"="inetcpl.cpl#00004480"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000021
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000003
"1400"=dword:00000001
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000003
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000003
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000001
"1806"=dword:00000001
"1807"=dword:00000001
"1808"=dword:00000000
"1809"=dword:00000003
"180D"=dword:00000000
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000001
"1A06"=dword:00000000
"1A10"=dword:00000001
"1C00"=dword:00000000
"1E05"=dword:00020000
"2000"=dword:00010000
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"PMDisplayName"="Trusted sites [Protected Mode]"
"LowIcon"="inetcpl.cpl#005424"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000003
"180A"=dword:00000003
"180C"=dword:00000000
"2301"=dword:00000000
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
@=""
"DisplayName"="Internet"
"Description"="This zone contains all Web sites you haven't placed in other zones"
"Icon"="inetcpl.cpl#001313"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000021
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000003
"1400"=dword:00000001
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000003
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000003
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000001
"1806"=dword:00000001
"1807"=dword:00000001
"1808"=dword:00000000
"1809"=dword:00000000
"180D"=dword:00000001
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000001
"1A06"=dword:00000000
"1A10"=dword:00000001
"1C00"=dword:00000000
"1E05"=dword:00030000
"2000"=dword:00010000
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"PMDisplayName"="Internet [Protected Mode]"
"LowIcon"="inetcpl.cpl#005425"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000003
"180A"=dword:00000003
"180C"=dword:00000003
"2301"=dword:00000000
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
@=""
"DisplayName"="Restricted sites"
"Description"="This zone contains Web sites that could potentially damage your computer or data."
"Icon"="inetcpl.cpl#00004481"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000021
"1001"=dword:00000003
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000003
"1400"=dword:00000003
"1402"=dword:00000003
"1405"=dword:00000003
"1406"=dword:00000003
"1407"=dword:00000003
"1601"=dword:00000001
"1604"=dword:00000003
"1605"=dword:00000000
"1606"=dword:00000003
"1607"=dword:00000003
"1608"=dword:00000003
"1609"=dword:00000001
"1800"=dword:00000003
"1802"=dword:00000001
"1803"=dword:00000003
"1804"=dword:00000003
"1805"=dword:00000001
"1806"=dword:00000003
"1807"=dword:00000001
"1808"=dword:00000000
"1809"=dword:00000000
"180B"=dword:00000003
"180D"=dword:00000001
"1A00"=dword:00010000
"1A02"=dword:00000003
"1A03"=dword:00000003
"1A04"=dword:00000003
"1A05"=dword:00000003
"1A06"=dword:00000003
"1A10"=dword:00000003
"1C00"=dword:00000000
"1E05"=dword:00030000
"2000"=dword:00000003
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"PMDisplayName"="Restricted sites [Protected Mode]"
"LowIcon"="inetcpl.cpl#005426"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000003
"180A"=dword:00000003
"180C"=dword:00000003
"2301"=dword:00000000
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000003
"2401"=dword:00000003
"2402"=dword:00000003
"2600"=dword:00000003
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport\DAMap]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols\Mailto]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\High]
"1400"=dword:00000003
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) "=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
@=""
"ProxyByPass"=dword:00000001
"IntranetName"=dword:00000001
"UNCAsIntranet"=dword:00000001
"AutoDetect"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com\*.update]
"http"=dword:00000002
"https"=dword:00000002
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones]
@=""
"SelfHealCount"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
@=""
"DisplayName"="My Computer"
"Description"="Your computer"
"Icon"="explorer.exe#0100"
"CurrentLevel"=dword:00000000
"Flags"=dword:00000021
"1001"=dword:00000000
"1004"=dword:00000000
"1200"=dword:00000000
"1201"=dword:00000001
"1206"=dword:00000000
"1207"=dword:00000000
"1400"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000000
"1407"=dword:00000000
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000000
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000000
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000000
"1805"=dword:00000000
"1806"=dword:00000000
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000003
"180D"=dword:00000000
"1A00"=dword:00000000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000000
"1A05"=dword:00000000
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00020000
"1E05"=dword:00030000
"2100"=dword:00000000
"2101"=dword:00000003
"2102"=dword:00000000
"2200"=dword:00000000
"2201"=dword:00000000
"2300"=dword:00000001
"2000"=dword:00000000
"PMDisplayName"="My Computer [Protected Mode]"
"LowIcon"="inetcpl.cpl#005422"
"1208"=dword:00000000
"1209"=dword:00000000
"120A"=dword:00000000
"1408"=dword:00000000
"160A"=dword:00000000
"180A"=dword:00000000
"180C"=dword:00000000
"2301"=dword:00000003
"2103"=dword:00000000
"2104"=dword:00000000
"2105"=dword:00000000
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
@=""
"DisplayName"="Local intranet"
"Description"="This zone contains all Web sites that are on your organization's intranet."
"Icon"="shell32.dll#0018"
"CurrentLevel"=dword:00000000
"MinLevel"=dword:00010000
"RecommendedLevel"=dword:00010500
"Flags"=dword:000001db
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000000
"1201"=dword:00000003
"1206"=dword:00000000
"1207"=dword:00000000
"1400"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000001
"1407"=dword:00000000
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000000
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000000
"1806"=dword:00000000
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000003
"180D"=dword:00000000
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000000
"1A05"=dword:00000000
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00020000
"1E05"=dword:00020000
"2100"=dword:00000000
"2101"=dword:00000000
"2102"=dword:00000000
"2200"=dword:00000000
"2201"=dword:00000000
"2300"=dword:00000001
"2000"=dword:00000000
"PMDisplayName"="Local intranet [Protected Mode]"
"LowIcon"="inetcpl.cpl#005423"
"1208"=dword:00000000
"1209"=dword:00000000
"120A"=dword:00000003
"1408"=dword:00000000
"160A"=dword:00000000
"180A"=dword:00000000
"180C"=dword:00000000
"2301"=dword:00000003
"2103"=dword:00000000
"2104"=dword:00000000
"2105"=dword:00000000
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
@=""
"DisplayName"="Trusted sites"
"Description"="This zone contains Web sites that you trust not to damage your computer or data."
"Icon"="inetcpl.cpl#00004480"
"CurrentLevel"=dword:00000000
"MinLevel"=dword:00010000
"RecommendedLevel"=dword:00010000
"Flags"=dword:00000047
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000000
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000000
"1400"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000003
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000003
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000001
"1806"=dword:00000001
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000000
"180D"=dword:00000000
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000001
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00010000
"1E05"=dword:00020000
"2100"=dword:00000000
"2101"=dword:00000001
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"2300"=dword:00000001
"2000"=dword:00000000
"PMDisplayName"="Trusted sites [Protected Mode]"
"LowIcon"="inetcpl.cpl#005424"
"1208"=dword:00000000
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000000
"160A"=dword:00000000
"180A"=dword:00000003
"180C"=dword:00000000
"2301"=dword:00000000
"2103"=dword:00000000
"2104"=dword:00000000
"2105"=dword:00000000
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
@=""
"DisplayName"="Internet"
"Description"="This zone contains all Web sites you haven't placed in other zones"
"Icon"="inetcpl.cpl#001313"
"CurrentLevel"=dword:00011500
"MinLevel"=dword:00011000
"RecommendedLevel"=dword:00011000
"Flags"=dword:00000001
"1001"=dword:00000001
"1004"=dword:00000003
"1200"=dword:00000000
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000003
"1400"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000003
"1407"=dword:00000001
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000003
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000001
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1805"=dword:00000001
"1806"=dword:00000001
"1807"=dword:00000001
"1808"=dword:00000000
"1809"=dword:00000000
"180D"=dword:00000001
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000001
"1A06"=dword:00000000
"1A10"=dword:00000001
"1C00"=dword:00010000
"1E05"=dword:00020000
"2100"=dword:00000000
"2101"=dword:00000000
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"2300"=dword:00000001
"2000"=dword:00000000
"{AEBA21FA-782A-4A90-978D-B72164C80120}"=hex:1a,37,61,59,23,52,35,0c,7a,5f,20,\
17,2f,1e,1a,19,0e,2b,01,73,1e,28,1a,04,1b,0c,3b,c2,21,27,53,0d,36,05,2c,05,\
04,3d,4f,3a,4a,44,33,3a,0a,06,12,68,53,7c,20,13,35,5d,4c,10,27,01,56,7a,2d,\
3f,38,4f,79,0f,16,26,75,53,1c,31,00,56,7a,3e,32,24,4f,79,1b,00,33,71,4d,23,\
32,29,7c,6a,35,31,34,40,72,3b,01,2e,5d,4c,2a,07,15,48,72,38,12,00,56,7a,3e,\
16,3c,71,4d,24,33,35,7c,72,35,0e,3c,1a,41,44,19,0f,31,3a,56,7a,2e,3e,31,0c,\
7c,6a,10,27,0c,05,5d,4c,39,19,12,15,61,54,2e,00,33,32,40,52,03,25,1f,05,5d,\
4c,2c,0c,0a,15,61,54,1a,26,1f,05,5d,4c,10,21,1d,1b,71,4d,3b,24,3a,21,6d,72,\
24,16,3c,32,40,72,21,0f,3a,1a,41,44,1b,1e,01,01,71,4d,32,23,30,27,6d,4d,1f,\
28,10,3c,56,7a,2f,2e,32,16,7c,6a,3a,12,3b,28,75,53,0b,3f,12,01,71,4d,23,32,\
29,27,75,53,12,30,32,1e,4f,79,12,38,17,01,71,4d,30,3e,37,27,6d,72,38,12,3f,\
04,41,44,0a,0e,32,28,49,5f,1c,24,0b,1b,36,21,41,7b,5b,24,39,31,7c,6a,2b,0e,\
25,75,53,1a,2e,26,41,72,34,16,26,71,4d,30,30,3a,7c,6a,07,33,1a,56,7a,3a,00,\
33,71,4d,23,32,29,7c,6a,1a,26,1a,40,52,24,3f,1a,6d,4d,1c,22,28,75,53,13,25,\
20,41,44,0a,0e,32,75,53,08,07,20,71,4d,10,27,0d,05,5d,4c,24,1a,1e,1b,71,4d,\
3f,20,3f,21,6d,4d,10,27,0c,05,5d,4c,39,19,12,3a,56,7a,3a,20,2c,0c,7c,6a,3e,\
0c,37,07,75,53,12,30,32,3a,56,7a,25,2d,23,0c,7c,6a,2b,08,21,3a,56,7a,22,3a,\
32,3a,56,72,24,1e,26,1a,41,44,07,1f,03,1b,75,53,1c,31,01,01,71,4d,32,23,30,\
27,6d,72,34,1e,30,04,41,44,1b,1e,3b,28,49,5f,07,33,12,1b,5d,4c,35,0b,0a,1f,\
75,53,0b,00,34,28,40,72,3b,01,2d,04,41,44,01,05,34,28,40,52,22,36,04,34,48,\
72,38,12,3f,04,41,44,0a,0e,1f,01,71,4d,24,33,35,27,06,1c,68,53,49,14,21,01,\
40,52,10,27,0d,40,52,2c,29,05,6d,4d,1f,28,05,56,7a,2f,2e,32,75,53,07,33,12,\
40,52,3f,3a,19,6d,72,20,00,34,71,4d,1a,26,1a,40,52,24,3f,1a,6d,72,35,08,38,\
5d,4c,2d,01,18,48,7a,27,23,1f,56,7a,3b,2f,3f,4f,79,08,39,01,1b,71,72,33,1f,\
39,3a,56,7a,2e,3e,31,0c,7c,72,35,0e,3f,1a,41,44,0a,0a,35,3a,56,7a,3a,20,2c,\
0c,7c,6a,03,25,1f,05,5d,4c,2c,0c,0a,15,61,54,27,05,34,32,40,52,10,21,09,05,\
5d,4c,2d,01,18,15,61,54,07,37,17,05,5d,4c,1c,24,03,1b,71,4d,30,30,3b,27,6d,\
72,33,17,3f,28,40,72,34,1e,30,04,41,44,1b,1e,00,01,71,4d,2f,2c,2c,27,6d,4d,\
0b,26,3f,3c,56,7a,3a,20,23,16,7c,6a,35,05,33,28,75,53,12,30,17,01,71,4d,30,\
3e,37,27,75,53,13,25,20,1e,4f,79,1f,29,1f,01,71,4d,24,33,35,27,06,21,41,7b,\
5b,3d,24,37,7c,6a,2b,0e,25,40,72,33,1f,39,5d,72,34,1e,30,5d,4c,2a,0d,18,48,\
7a,27,12,3b,71,4d,23,32,12,56,72,20,0c,2e,5d,4c,2c,0c,0a,75,53,1a,26,1f,40,\
72,35,08,38,5d,4c,2d,01,18,75,53,0f,21,27,41,44,07,1f,3e,61,54,3d,06,22,32,\
40,52,2c,29,05,32,48,72,34,1e,05,1b,71,4d,10,27,0c,05,5d,4c,39,19,1a,1b,71,\
4d,23,32,24,21,6d,4d,03,25,1f,05,5d,4c,2c,0c,0a,3a,56,7a,25,2d,23,0c,7c,6a,\
2b,08,21,07,75,53,13,25,20,3a,56,7a,3e,3e,3b,0c,7c,6a,3f,0f,23,3a,56,7a,2f,\
2e,3d,3c,56,72,33,1f,39,04,41,44,1a,0e,05,01,75,53,1c,31,00,01,71,4d,2f,2c,\
2c,27,6d,72,20,0c,2d,04,41,44,06,18,2a,28,49,5f,1a,26,1a,1b,5d,4c,2c,0c,0f,\
1f,75,53,1c,1c,3e,28,40,72,38,12,3f,04,41,44,0a,16,3c,28,40,52,3e,39,06,34,\
21,21,41,7b,5b,23,27,3c,7c,6a,17,37,17,40,52,32,24,05,6d,4d,0e,21,2c,75,53,\
0b,31,31,75,53,08,3e,21,41,44,07,1e,3c,61,54,17,37,17,05,5d,4c,00,33,1e,1b,\
71,4d,2e,39,3b,21,6d,72,20,06,32,32,40,72,21,0f,3c,1a,41,44,1a,0e,1f,01,71,\
4d,20,2c,30,27,6d,4d,0e,21,2c,3c,56,7a,3a,2e,2d,16,7c,6a,3f,07,22,28,6e,02,\
68,4a,7c,21,09,26,5d,4c,29,1d,1f,56,7a,3f,32,38,4f,79,1e,30,01,56,7a,3a,2e,\
2d,4f,79,14,07,22,71,4d,24,30,3b,7c,6a,2a,1e,2f,07,75,53,0c,2d,26,3a,56,7a,\
31,25,3d,0c,7c,6a,3e,0e,35,3a,56,7a,3b,2f,3d,3a,56,72,34,1e,26,04,41,44,0b,\
0a,1e,01,75,53,0e,38,01,01,71,4d,23,30,2b,27,6d,72,21,0f,3c,04,28,1b,67,6b,\
5f,00,22,10,75,53,1f,21,27,41,44,0b,0a,31,75,53,0e,1d,22,71,4d,03,27,1d,40,\
52,3e,39,08,75,53,08,31,21,41,44,1a,0e,32,3a,56,7a,3f,32,38,0c,7c,6a,06,3e,\
0d,05,5d,4c,35,0d,09,15,61,54,29,07,22,32,40,52,17,37,17,1b,5d,4c,3a,19,16,\
1f,61,54,06,3e,0d,1b,5d,4c,03,27,11,01,71,4d,24,33,3b,27,06,21,41,73,41,11,\
25,1d,56,7a,2e,3e,3b,4f,79,18,12,3f,71,4d,2e,39,3b,7c,6a,3e,0e,35,40,72,21,\
0f,3c,5d,4c,36,0d,19,48,72,34,1e,1f,1b,71,4d,00,33,16,05,5d,4c,38,04,01,1b,\
71,4d,23,30,2b,21,6d,4d,1c,24,0d,05,5d,4c,29,1d,17,3c,56,7a,3f,32,38,16,7c,\
6a,39,09,25,09,75,53,0b,31,31,3c,56,7a,3b,2f,3d,16,15,39,5f,7b,42,03,38,02,\
40,20,2c,1e,4f,37,41,7b,5b,23,27,3c,7c,14,07,22,6e,14,68,4a,7c,20,13,35,5d,\
30,37,08,06,37,41,7b,5b,23,27,3c,7c,1b,39,1d,30,02,7c,50,68,3a,3b,34,4f,1b,\
1e,3b,6e,14,68,73,41,0b,22,0a,56,12,30,32,28,09,67,73,41,0b,22,2a,41,2c,0c,\
0f,21,37,41,7b,5b,23,27,3c,7c,08,1c,3e,66,0e,44,4f,56,06,13,05,61,27,23,1f,\
4f,3f,5b,53,7c,20,13,35,5d,3e,39,06,06,0a,68,53,7c,21,09,26,5d,32,12,3f,6e,\
14,68,4a,44,3e,37,02,6d,1c,24,01,4f,3f,5b,73,41,08,38,27,41,38,04,19,6e,14,\
68,4a,44,3e,37,02,6d,3e,0e,35,3b,37,41,7b,5b,24,39,31,7c,08,39,00,4f,3f,7c,\
50,68,3b,1d,3c,71,25,2d,2c,20,3a,7c,50,68,3b,25,3b,4f,01,1d,2a,6e,14,68,4a,\
44,3e,37,02,6d,10,21,09,29,1f,5e,45,67,14,30,07,49,12,16,3c,66,0e,44,73,41,\
08,38,27,41,36,0a,1b,21,3f,42,73,41,10,3b,2d,41,00,33,1e,4f,3f,5b,53,5e,2e,\
07,1d,75,21,07,22,66,0e,7c,50,68,23,24,31,4f,0d,15,01,4f,3f,5b,53,5e,2e,07,\
1d,48,0b,18,3c,6e,14,68,4a,44,26,36,0c,6d,2b,06,25,66,37,41,7b,5b,14,21,01,\
40,3a,31,24,15,37,41,7b,5b,3c,3e,3f,7c,12,38,17,4f,3f,5b,53,5e,2e,07,1d,75,\
35,08,38,36,03,56,76,74,37,08,19,40,07,37,17,29,1f,7c,50,68,23,24,31,4f,07,\
1f,3e,16,17,7c,50,68,20,3a,39,75,25,12,3f,66,0e,44,4f,56,1c,12,1d,56,1c,24,\
0d,29,37,41,7b,5b,3d,24,37,7c,1e,1d,22,66,0e,44,4f,56,1c,12,30,61,23,13,11,\
4f,3f,5b,53,5e,2f,01,15,48,10,27,0c,6e,14,68,4a,7c,36,12,38,5d,24,3f,19,6e,\
14,68,4a,44,21,2c,04,6d,35,05,34,66,0e,44,4f,56,1c,12,1d,56,1c,3b,25,28,09,\
67,6b,5f,01,2c,28,75,24,1e,26,36,37,41,7b,5b,3d,24,37,7c,14,3a,0b,30,37,41,\
7b,5b,36,0c,7c
"{A8A88C49-5EB2-4990-A1A2-0876022C854F}"=hex:1a,37,61,59,23,52,35,0c,7a,5f,20,\
17,2f,1e,1a,19,0e,2b,01,73,1e,28,1a,04,1b,0c,3b,c2,21,2d,53,49,07,25,0f,29,\
01,7c,50,68,3a,3b,34,4f,79,08,39,0d,49,72,33,1f,39,5d,4c,17,37,05,56,7a,2f,\
2e,32,4f,79,1f,12,3b,75,53,0b,3f,12,56,7a,3a,20,23,4f,79,12,05,33,71,4d,3a,\
31,29,7c,6a,2b,08,21,40,72,38,12,3f,5d,4c,39,1d,17,48,72,21,0f,03,56,7a,2f,\
06,22,32,40,52,2c,29,05,3a,56,7a,2e,3e,31,0c,7c,6a,2b,06,25,32,40,52,33,24,\
01,32,75,53,0b,3f,32,04,4f,79,1b,3b,1f,0c,40,72,3b,01,2d,1a,75,53,12,30,3f,\
04,4f,79,08,3f,09,0c,75,53,13,25,20,04,75,53,07,37,17,05,5d,4c,36,0a,1b,3a,\
56,72,35,0e,3c,3c,56,7a,2d,3f,38,16,7c,6a,17,37,01,1b,5d,4c,2a,0d,18,1f,61,\
54,12,12,3b,28,40,52,3f,3a,19,34,48,72,20,0c,17,01,71,4d,1a,26,1a,1b,5d,4c,\
2c,0c,17,01,71,4d,30,3e,37,27,6d,4d,1b,3b,0c,1b,5d,4c,39,1d,17,3c,56,7a,3b,\
2f,3f,16,15,39,5f,7b,42,29,1d,3c,71,4d,30,06,22,71,4d,32,23,30,7c,6a,2a,1e,\
19,75,53,1c,31,20,41,72,24,12,3b,71,4d,23,32,24,7c,6a,03,25,17,56,7a,25,05,\
33,71,4d,3a,31,29,7c,6a,10,21,09,40,52,27,2c,0b,6d,4d,0f,28,2a,75,53,08,3e,\
23,41,44,1b,1e,3c,3a,56,7a,12,34,16,05,75,53,1f,21,2d,04,4f,79,10,27,0c,05,\
5d,4c,39,19,12,15,75,53,0b,3f,32,04,4f,79,1b,00,34,32,40,52,24,3f,19,32,48,\
7a,2c,10,17,1b,71,4d,30,1c,3e,32,40,52,27,2c,0b,32,48,7a,27,16,3c,32,40,52,\
3e,07,20,3a,56,7a,2f,2e,3d,16,7c,6a,12,34,1e,01,71,4d,17,37,01,1b,5d,4c,2a,\
0d,18,3c,56,7a,3e,32,24,16,7c,6a,3e,0c,34,09,75,53,0b,3f,3f,1e,4f,79,12,38,\
12,01,71,72,3b,01,2e,3c,56,7a,2f,24,39,16,7c,72,38,12,3f,04,41,44,0a,0e,32,\
3c,56,7a,3b,2f,3f,16,15,39,7c,50,68,23,24,31,4f,79,08,39,0d,49,5f,12,34,16,\
40,52,17,37,01,40,52,22,38,0b,6d,4d,0f,34,1a,56,7a,3a,20,2c,75,53,03,25,1f,\
40,52,24,3f,19,6d,72,3b,05,34,71,4d,10,21,09,40,52,27,2c,0b,6d,72,24,1e,26,\
5d,4c,36,0a,1b,48,7a,36,13,01,1b,71,4d,32,23,30,21,6d,4d,17,37,01,3a,56,7a,\
2f,06,25,32,40,52,33,24,01,3a,56,7a,3a,20,2c,0c,7c,6a,3e,00,34,32,40,52,24,\
3f,19,32,75,53,12,30,3f,04,4f,79,08,3f,09,0c,40,72,38,12,3f,1a,75,53,0f,21,\
27,04,4f,79,14,3a,0b,0c,75,53,1c,31,21,1e,75,53,12,34,16,1b,5d,4c,29,1d,1d,\
3c,56,72,35,0e,3f,3c,56,7a,3e,32,24,16,7c,6a,03,25,1a,1b,5d,4c,35,0b,0f,1f,\
61,54,27,05,33,28,40,52,24,3f,1a,34,48,72,35,08,1d,01,71,4d,1b,3b,0c,1b,5d,\
4c,39,1d,1f,01,71,4d,24,33,35,27,06,1c,7c,50,68,20,3a,39,4f,79,08,06,22,71,\
4d,32,23,30,7c,6a,2a,1e,19,40,72,35,0e,3f,5d,72,24,1a,25,5d,4c,35,0b,0a,48,\
7a,23,00,34,71,4d,3a,31,12,56,72,3b,01,2e,5d,4c,2a,07,15,75,53,1b,3b,0c,40,\
72,24,1e,26,5d,4c,36,0a,1b,75,53,1c,31,21,04,4f,79,0a,2a,06,0c,40,72,34,1e,\
30,1a,41,44,1b,1e,3b,3a,56,7a,07,33,12,05,75,53,0b,3f,32,04,4f,79,03,25,1f,\
05,5d,4c,2c,0c,0a,15,75,53,12,30,3f,04,4f,79,08,1c,3e,32,40,52,27,2c,0b,32,\
48,7a,27,23,1f,1b,71,4d,24,07,20,32,40,52,22,38,08,34,48,7a,34,17,3f,28,40,\
52,23,16,26,3c,56,7a,2f,2e,32,16,7c,6a,07,33,1a,01,71,4d,03,25,1a,1b,5d,4c,\
35,0b,0f,3c,56,7a,25,2d,2c,16,7c,6a,35,31,37,09,75,53,1c,3b,25,1e,4f,79,13,\
35,00,01,71,72,24,1e,26,3c,56,7a,3b,2f,3f,16,15,21,41,7b,5b,23,27,3c,7c,6a,\
2a,16,3c,71,4d,20,2c,30,7c,6a,06,3e,0d,40,52,3f,38,18,6d,4d,08,27,2c,75,53,\
08,31,21,75,53,1f,21,27,04,4f,79,18,2d,06,0c,75,53,0e,38,21,04,75,53,03,27,\
1d,05,5d,4c,36,0a,19,3a,56,72,34,1e,26,3c,56,7a,3f,32,38,16,7c,6a,06,3e,0d,\
1b,5d,4c,35,0d,09,1f,61,54,29,07,22,28,29,01,5e,45,67,14,30,1f,56,7a,17,37,\
17,40,72,25,1a,39,5d,4c,38,04,01,56,7a,3a,2e,2d,4f,79,14,3a,01,56,7a,3b,2e,\
3d,4f,79,0f,16,3c,32,40,52,32,24,05,32,48,7a,18,28,01,1b,71,4d,23,06,32,32,\
40,52,3e,39,08,32,48,7a,37,16,3c,28,40,52,32,12,3f,3c,56,7a,31,25,3d,16,7c,\
6a,03,27,11,01,71,4d,1c,24,0d,1b,36,1d,56,76,74,14,21,01,40,52,23,28,02,6d,\
4d,0c,34,2b,75,53,0e,38,21,41,44,06,1e,2c,75,53,08,07,22,71,4d,1c,27,0d,40,\
52,23,28,02,3a,56,7a,3f,32,38,0c,7c,6a,39,1d,22,32,40,52,3f,38,18,32,75,53,\
08,3e,21,04,4f,79,0f,29,07,02,40,72,25,1a,39,04,75,53,0e,38,21,1e,4f,79,1b,\
39,1d,02,75,53,08,3e,21,1e,6e,02,7c,50,68,20,3a,39,4f,79,0f,16,3c,75,53,0c,\
2d,1e,56,7a,31,25,3d,4f,79,1b,06,32,71,4d,24,33,3b,7c,6a,3f,0e,25,40,72,34,\
1e,26,1a,41,44,0b,0a,31,3a,56,7a,06,3e,0d,05,75,53,0b,31,31,04,4f,79,1c,24,\
0d,05,5d,4c,29,1d,17,1f,75,53,0c,2d,26,1e,4f,79,1e,1d,22,28,40,52,3f,38,18,\
34,48,7a,22,12,01,01,66,1c,44,73,41,0b,22,2a,41,3a,19,16,21,2d,42,73,41,0b,\
22,2a,41,1c,24,01,4f,2d,5b,53,5e,35,1e,22,75,27,1d,22,66,1c,7c,50,68,3a,3b,\
34,4f,06,1e,11,4f,2d,5b,53,5e,35,1e,22,48,1c,18,2d,6e,02,68,4a,44,3f,2d,31,\
6d,35,05,33,66,21,41,7b,5b,03,38,02,40,3a,31,29,15,21,41,7b,5b,23,27,3c,7c,\
08,3f,1d,4f,2d,5b,53,5e,35,1e,22,75,24,1e,26,36,1d,56,76,74,3e,03,1c,40,1c,\
24,0b,29,01,7c,50,68,3b,25,3b,4f,0b,0a,31,16,05,7c,50,68,3b,25,3b,75,21,07,\
22,66,1c,44,4f,56,07,15,1f,56,06,3e,0d,29,21,41,7b,5b,24,39,31,7c,1b,06,32,\
66,1c,44,4f,56,07,15,32,61,36,13,00,4f,2d,5b,53,5e,36,04,17,48,1a,26,1a,6e,\
02,68,4a,7c,21,09,26,5d,24,3f,1a,6e,02,68,4a,44,3e,37,02,6d,2b,1c,3e,66,1c,\
44,4f,56,07,15,1f,56,0f,21,27,28,1b,67,6b,5f,08,21,2a,75,21,0f,3a,36,21,41,\
7b,5b,3c,3e,3f,7c,18,2d,06,30,21,41,7b,5b,3c,3e,05,56,1c,24,0d,29,01,5e,45,\
67,0c,1c,26,75,27,09,3c,6e,02,68,4a,44,26,36,0c,6d,03,27,1d,29,01,5e,45,67,\
0c,3f,31,49,3d,06,25,66,1c,44,4f,56,1f,14,38,75,3b,01,12,4f,2d,5b,73,41,10,\
3b,2d,41,2c,0c,17,4f,2d,5b,53,5e,2e,07,1d,48,10,21,09,29,01,5e,45,67,0c,1c,\
26,71,3e,3e,3b,20,28,74,4e,68,2a,29,05,56,08,3e,23,6e,02,68,4a,44,21,2c,04,\
6d,3b,1a,20,6e,02,68,4a,44,21,1a,3e,75,21,0f,3c,36,1d,56,76,74,15,3b,1d,56,\
0e,38,01,4f,2d,5b,53,5e,2f,01,15,75,20,0e,2c,36,1d,56,76,74,28,02,21,40,10,\
27,0c,29,01,5e,45,67,0d,35,1d,56,12,05,33,66,1c,7c,50,68,20,3a,39,4f,01,05,\
34,66,1c,44,4f,56,1c,12,30,75,35,08,38,36,1d,56,76,74,15,3b,09,40,2f,20,31,\
15,39,5f,7b,42,20,1a,3e,71,3b,2f,03,4f,2d,5b,53,5e,20,39,74
"PMDisplayName"="Internet [Protected Mode]"
"LowIcon"="inetcpl.cpl#005425"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000000
"180A"=dword:00000003
"180C"=dword:00000003
"2301"=dword:00000000
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2600"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
@=""
"DisplayName"="Restricted sites"
"Description"="This zone contains Web sites that could potentially damage your computer or data."
"Icon"="inetcpl.cpl#00004481"
"CurrentLevel"=dword:00000000
"MinLevel"=dword:00012000
"RecommendedLevel"=dword:00012000
"Flags"=dword:00000003
"1001"=dword:00000003
"1004"=dword:00000003
"1200"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000003
"1400"=dword:00000003
"1402"=dword:00000003
"1405"=dword:00000003
"1406"=dword:00000003
"1407"=dword:00000003
"1601"=dword:00000001
"1604"=dword:00000001
"1605"=dword:00000000
"1606"=dword:00000003
"1607"=dword:00000003
"1608"=dword:00000003
"1609"=dword:00000001
"1800"=dword:00000003
"1802"=dword:00000001
"1803"=dword:00000003
"1804"=dword:00000003
"1805"=dword:00000001
"1806"=dword:00000003
"1807"=dword:00000001
"1808"=dword:00000000
"1809"=dword:00000000
"180B"=dword:00000001
"180D"=dword:00000001
"1A00"=dword:00010000
"1A02"=dword:00000003
"1A03"=dword:00000003
"1A04"=dword:00000003
"1A05"=dword:00000003
"1A06"=dword:00000003
"1A10"=dword:00000003
"1C00"=dword:00000000
"1E05"=dword:00010000
"2100"=dword:00000003
"2101"=dword:00000003
"2102"=dword:00000003
"2200"=dword:00000003
"2201"=dword:00000003
"2300"=dword:00000003
"2000"=dword:00000003
"{AEBA21FA-782A-4A90-978D-B72164C80120}"=hex:1a,37,61,59,23,52,35,0c,7a,5f,20,\
17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12,14,1a,15,39
"{A8A88C49-5EB2-4990-A1A2-0876022C854F}"=hex:1a,37,61,59,23,52,35,0c,7a,5f,20,\
17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12,14,1a,15,39
"PMDisplayName"="Restricted sites [Protected Mode]"
"LowIcon"="inetcpl.cpl#005426"
"1208"=dword:00000003
"1209"=dword:00000003
"120A"=dword:00000003
"1408"=dword:00000003
"160A"=dword:00000003
"180A"=dword:00000003
"180C"=dword:00000003
"2301"=dword:00000000
"2103"=dword:00000003
"2104"=dword:00000003
"2105"=dword:00000003
"2400"=dword:00000003
"2401"=dword:00000003
"2402"=dword:00000003
"2600"=dword:00000003