Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý Explorer

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní: http://forum.viry.cz/viewtopic.php?f=12&t=123975 . Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
HenrikGodi
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 20 říj 2010 19:56

Pomalý Explorer

#1 Příspěvek od HenrikGodi »

po odinstalaci Windows Live a opětovné instalaci Live Essential se mně katastrofálně seká explorer a Windows Live mail a Messenger mi nejdou spustit, nevíte jak to opravit? OS Vista.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:53:25, on 20.10.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Syncplicity\Syncplicity.exe
C:\Windows\system32\wuauclt.exe
C:\totalcmd\TOTALCMD.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Opera\opera.exe
C:\Users\Jindřich Bultas\Desktop\hijackthis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {2913D3DD-9363-4C21-B205-C19A584A0674} - (no file)
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ODDPwr] "C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [Syncplicity] C:\Program Files\Syncplicity\Syncplicity.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {0000036B-C524-4050-81A0-243669A86B9F} - (no file)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - (no file)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - (no file)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
O23 - Service: 1248633509 (.1248633509) - Unknown owner - C:\Program Files\1248633509\Jindřich Bultas1248633509L.exe (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: CLPSLS - Unknown owner - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe (file missing)
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: fsssvc - Unknown owner - C:\Program Files\Windows Live\Family Safety\fsssvc.exe (file missing)
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Keyboard Driver\KMWDSrv.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: Acer ODD Power Service (ODDPwrSvc) - Acer Incorporated - C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9750 bytes

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalý Explorer

#2 Příspěvek od motji »

Dobrý večer :)


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.



:arrow: Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys
cdrom.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
- zaškrtněte okénko Pro všechny uživatele.
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde :)


:arrow: Zkuste defragmentovat disk
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mickeykr
Návštěvník
Návštěvník
Příspěvky: 82
Registrován: 27 říj 2010 21:40

Re: Pomalý Explorer

#3 Příspěvek od mickeykr »

Nejsem odborník, ale logu používáš operu, že ? Podle mě se opera a explorer nemají rádi... Něco podobného se mi stalo na Xpéčko, ale netvrdím, že to bude i tu.
Jsem člověk, který našel svůj domov forum.viry.cz
Nic nedělejte bez rádce, můžete dojít ke kompletní ztrátě dat !
Nejsem rádce, ale chtěl bych se jím stát, ale i tak vám rád pomůžu


Microsoft Essential ke stažení !
RSIT ke stažení !

Chcete pomoct se stránkami nebo grafikou ? Nebojte se mi napsat, rád vám pomůžu

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15654
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Pomalý Explorer

#4 Příspěvek od JaRon »

mickeykr píše:Nejsem odborník, ale logu používáš operu, že ? Podle mě se opera a explorer nemají rádi... Něco podobného se mi stalo na Xpéčko, ale netvrdím, že to bude i tu.
tato uvaha je uplne vedla - bude dobre, ak sa uzivatel bude riadit radami kolegyne motji :wink:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

mickeykr
Návštěvník
Návštěvník
Příspěvky: 82
Registrován: 27 říj 2010 21:40

Re: Pomalý Explorer

#5 Příspěvek od mickeykr »

Je to možné já jen říkám co se dělo mě, nemusí to být stejné.... Možná to bylo verzí
Jsem člověk, který našel svůj domov forum.viry.cz
Nic nedělejte bez rádce, můžete dojít ke kompletní ztrátě dat !
Nejsem rádce, ale chtěl bych se jím stát, ale i tak vám rád pomůžu


Microsoft Essential ke stažení !
RSIT ke stažení !

Chcete pomoct se stránkami nebo grafikou ? Nebojte se mi napsat, rád vám pomůžu

HenrikGodi
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 20 říj 2010 19:56

Re: Pomalý Explorer

#6 Příspěvek od HenrikGodi »

OTL Extras logfile created on: 29.10.2010 23:37:58 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Jindřich Bultas\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 60,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 70,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,12 Gb Total Space | 97,05 Gb Free Space | 43,50% Space Free | Partition Type: NTFS

Computer Name: JINDŘICHBULTAS | User Name: Jindřich Bultas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2236800186-3475897335-322313511-1000\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] -- "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0 -- ()
"UpdatesDisableNotify" = 0 -- ()
"AntiVirusDisableNotify" = 0 -- ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0 -- ()
"AntiSpywareOverride" = 0 -- ()
"FirewallOverride" = 0 -- ()
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 -- ()

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{017861FD-2343-4BD7-A928-503FE9DF7362}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{020C1793-EBBD-418C-AF7F-F3BB9263250E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{0A14F0DD-142D-4121-B876-8C0123D1752E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0F91F9E1-9EC4-4AF0-AA5B-B7E111FE039C}" = lport=445 | protocol=6 | dir=in | app=system |
"{1A414A61-480D-438D-A119-A21E16E76173}" = lport=2869 | protocol=6 | dir=in | app=system |
"{31D18AFE-CEFA-4C64-B3C9-564DEDEF277F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{32927133-6029-45FC-87AB-975ADDBB3FC3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3B709F02-F519-4732-BD15-E50D3D76D86E}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4191C6E4-4E0E-4158-9A54-9B1040DE31DF}" = lport=139 | protocol=6 | dir=in | app=system |
"{4C473B03-CAA4-407E-ADAC-ED61042577A8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{549E83B7-6FF3-4CDD-BA68-E4E11E1C5EBF}" = lport=137 | protocol=17 | dir=in | app=system |
"{5EE3BEB1-4AF3-4802-897A-E73A26442D0F}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{625F8110-D7F7-4262-9908-7964FD118A2F}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{63754F20-0E06-49D5-A199-296A0FA14441}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{64785E46-65BB-4833-8CE3-FD372E5E8AC8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{779EBA35-36E1-4905-BAFA-4C0F0091DB7B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{7FB644FF-CC57-4FE5-9AA1-39E4D7034E7F}" = rport=139 | protocol=6 | dir=out | app=system |
"{89385AB8-7715-41ED-8991-2B3411CA2679}" = rport=137 | protocol=17 | dir=out | app=system |
"{B107D4A2-FEDA-4C90-93C7-FC33C08AF9A2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BA091DD1-5DFB-4B99-A54D-C28B4465B57D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BD9EB2C7-3748-4766-9898-0A691172259B}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C80AC92A-EEEF-4C57-AEE3-B5B0AA795E79}" = rport=445 | protocol=6 | dir=out | app=system |
"{CE97319C-14DB-45E4-8756-A60D9C26420D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{D7A7C0D5-58EB-4F97-855B-9ADC7A109CE0}" = rport=138 | protocol=17 | dir=out | app=system |
"{E2978DAA-B445-4CFE-AF91-317B4519136D}" = lport=138 | protocol=17 | dir=in | app=system |
"{EA959247-3400-4F0E-AB5A-86EB1B9190D0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{ECE1B819-4F20-4AB4-9836-950BD63F0961}" = rport=2869 | protocol=6 | dir=out | app=system |
"{EF19E813-36D7-4B12-AD39-048D17101A7A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F3F4466A-BA79-4E54-AD7C-8BDFB3C2FECE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA43CF10-5755-451C-A0AF-A76FC8907F51}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0016475A-652F-486F-8B85-4FF96B941E31}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{004A8FA7-58C2-417E-9310-9B9405E20CB3}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{013E2A40-FDFE-4D26-8751-047807A98AE6}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{03777497-0F6B-41F8-9BF5-4A2FA5020340}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{0414B91F-C966-4986-99C7-026E13BEF366}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{0B19A184-8B05-43C5-8C61-CC5F8C4C36F8}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{0BCA6DDA-9494-4DD0-830F-5A50E271F927}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0F95DFFA-4A4A-472C-815D-1B2CDF7828CA}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{119EBB1B-B968-4007-BC70-26685E9BC444}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{13515411-5286-4B57-8541-2D3F2F17A233}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{13A55796-5066-468B-ACA0-542580CEED58}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{13AB6E09-03EF-448C-B8E7-BCC2C543D40D}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{146E1320-F9A4-41F2-89D3-8CE1DB491E94}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{14A0B716-2A0E-481F-AE23-D23B4D3040C0}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1596813A-052F-4BA3-A230-DFE291BEE3D5}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{183C62D4-6F62-4A64-9486-D9F936AAA008}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1D6C3CE6-4756-4542-8389-7C78D68FBEF6}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1DAD2DEC-2AF1-4EAE-8B9E-92B8E47EA80C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1F5680C9-3A7C-4CD9-B2E3-746C0DF796C3}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2004346D-A5C2-4910-9864-FDEB81041800}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{20DF0486-4AA5-412C-B10A-14F9389CB5D0}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{22CAF967-F79E-473A-9C9A-75FE27233A5A}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{25CB90D7-EF21-4342-87B3-F969FD7B47B0}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{28A513F2-BE32-415D-BDD7-D34A9C63AF26}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{29406AC8-B8A3-4A15-B037-BD3BC9E58FFC}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2A9A9F57-B97F-4BF9-9C3A-D959B50D5A2E}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer_service.exe |
"{2C8C52F4-F805-4B3F-97A5-1330A6CCA68E}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2E191704-0BC4-4E34-8A37-307F105A04E7}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3637E99A-7179-44DF-8695-9A63713D83B1}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{36A2937C-E0DA-4F3E-A2D1-B95698F448DB}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{3A61B256-29E0-4F62-A3A2-CD530E7483DF}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3BA73FE1-A5CF-4DD6-8843-06A2011FAEEC}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{40AC598B-876C-40C7-A5C8-A4C62F766E39}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4203D4FE-3829-4516-80D3-9A0BFD5A5DB2}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4296647A-8A3B-4EBA-B4BE-34A0034D8B0E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{4344F8A6-61F6-43D8-865E-744E596B3794}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4376ADC0-52A2-4192-B851-215487D4069A}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4434C2C5-D89E-4D06-B45D-A37870126CE1}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{44513D19-FDBF-4EF5-9CF2-5AB9974F507B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{446B29DA-64A9-4C01-A897-F4DE63567084}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{45B1E79C-AE5E-4115-A9F7-C671E183D038}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{464CC4FE-2E83-4C7E-8EBE-9E2C1F6363F4}" = protocol=6 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{464F9086-8EC2-462A-B677-6C2BA945EE87}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{496AF51D-670D-4F49-8ED8-AEA21E17CFF3}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{4A7C297D-BC60-4C90-89B9-B0ECDEA0D2F6}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4B79D8AA-E8C4-4868-A1C0-F24235165F2D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4C02A2C3-37D2-4D56-8A29-05F64154E98E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4D918984-8BEF-4679-88E6-795555FCCB2A}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4FA3791B-308A-4DFD-AE6A-2FBF097CDB27}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4FD2B902-47E0-4D84-B885-C66F1246847E}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{544573FC-1DB2-4F0B-9498-F7CAD8708AD3}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{56C75E86-2EB1-4E3C-921A-50C66CF066D6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5A6C0DC5-17DE-411D-B6D3-DE558389ACA3}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5A897E5A-D5AF-4437-873F-6A9015E56B2E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{5BA0D04C-0F84-47CF-8FA2-A78A8CF6C1F2}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{5C055697-8828-4998-8DB4-4113BA5CB3E0}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{619E0715-0F30-4C53-A281-F6B3A53C9BCE}" = protocol=17 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{670570B6-FDCA-48E9-90DA-EA28BCB000FA}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6711EBF2-6A84-4B80-AE93-0165CA5AFAF9}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{676FD7D5-A267-49E1-AAB4-8363BCBC6898}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{682A1AC7-A5AE-4CAF-B399-CEA783369A96}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{692B7F71-A657-4596-9729-0A6F590B20EB}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{706F8E06-7609-4A19-854E-8054BDAF96CD}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7102F069-8D25-46D8-9493-7DF407A05D24}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{73C0C261-BFE9-48F5-B64D-60BC6248FB68}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{784F8D3C-6CA2-4770-A1E6-CB45F68A79C5}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{79B04B3D-16C9-4926-943A-CB33BB3B04C4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{79EC4E42-528B-4D91-9159-94E71E1DB81B}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7A20A1DB-1876-4B4D-8F88-E8C41BF3A637}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7A9F2BA0-DBEE-4AE1-B995-5439BBAB8B2E}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{7CF46C4D-5EE8-439C-91EF-D734FAD40F21}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7E9E5EEB-C978-4A28-B53E-89AAFA2C7DB8}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe |
"{815AA0B6-5269-42C7-9628-27B20000A612}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8200DC09-A01B-4CBE-A20B-0BDAD3653DE4}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{84C945FB-FD29-4FAB-AF87-465073B77F96}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8532DAA0-EC03-4CAB-9176-98799F9E91E2}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{87DC8B02-28E5-4A50-A080-4B2A061FD26F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8AED65F8-AEEF-4695-A98D-22EC5237EB78}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{8B1C292E-109D-4B41-885F-91CA3AC765AF}" = protocol=17 | dir=in | app=c:\users\jindřich bultas\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{91E098EF-BB73-453F-84E9-FB8624E4AB81}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{970A4414-D6AE-4EC9-93E6-CFE5901D95B2}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{97AA7B13-5681-405A-B521-FC48DA530ACC}" = protocol=6 | dir=in | app=c:\users\jindřich bultas\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{99386890-BD11-4AB8-963D-17542D22B940}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{99CBF152-7C1F-41EB-9B50-9326D738AB2C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9B00CF3D-4EF3-4ADC-9874-071B1D4BE8F5}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{9EDB9EC0-1A57-456C-88A2-527CEB55FF55}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{9F951987-9E4C-4764-B131-ED2C38E9A6E9}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A1A79433-670F-45AC-83EF-D29995F7FB26}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A291E3FD-5074-4084-B36C-6396C9F40859}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A58DC29B-F407-4AA3-AF2A-9425AA9D21CC}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{A80689E7-E6A8-4D06-891D-136BC67060E2}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A83332A1-395C-4FFE-A361-15C5653C038F}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{ADA998DD-CA9E-426F-9397-B7829AC7AEBF}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AFD142C6-5F4A-4EC7-AC64-A0C205FD7931}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer_service.exe |
"{B27DA2A6-22E5-400C-A3F5-D37376322C25}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B39C499D-0B64-4ED3-BF4E-C329339B06DF}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{B4AAF361-CFAD-4063-AFDA-ED93A0D2B17F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B4E7062D-57EF-4A3B-B389-8575AC7EE94E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B59100FE-A736-4A00-B3C2-DF424AC1A37E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B5F61A16-DA05-40E7-B31C-04065476F441}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{BD9154C5-1A17-4AB0-A96B-F30F83099FA1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BED35761-FFF8-43BE-9873-B7C9360245D9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C3B4FE2C-87D0-4A0B-9A88-A66ABA76BC2A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C679D7F3-D5F7-46C4-9FCD-4F0257E01F67}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C6EB5CB8-3738-4C66-8E23-29A44BE34486}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C9B4EDF0-5E7F-429D-942D-31352353EE3B}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{CAB77634-304F-4A56-8FC1-5E4E5CB9B93F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CB470BA9-903A-499D-99D2-E9B24BB6DCFC}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{CBB55CD1-B8DD-4B51-BEB4-1F92A86E19E9}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CCBC92AD-678C-4B38-99E5-9183ED64F482}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CD99B39F-156F-4C84-98DD-98C1E1AE1D68}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CE6D33D7-5639-4084-BDC5-563E7AC1590B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D376DBF4-7A28-4048-BEE1-5DC560E16A29}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D4C71C17-02FA-4949-A11C-706F697D1426}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{DD9C3AAB-C1EA-4740-9318-4C89960F91D3}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{DDB6797B-8E9F-46A0-B45C-E5FCEEAEDB77}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{DF1DF659-94DC-4C8D-B861-19B3429E3BFB}" = dir=in | app=c:\program files\acer\acer vcm\rs_service.exe |
"{DFDF2A3D-DD75-4A6C-BFC2-9474AD7BB531}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{E5482A78-EB84-4C66-95A6-A9DB0ED8F030}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{F2AFA763-D65F-4006-9078-01893B57251B}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{F4345F06-52C3-4596-89A9-91FDD660005F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F59C2264-BD88-48DB-9E2A-5F66949E9D06}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{F63628A1-9D9B-492E-9A4A-D9C26DCB73A6}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F6E6D185-E651-4240-9EA5-FEE2F590FBB7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F732A763-6B10-4B91-8531-A33B7138EF8E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{F81DF13F-83AF-45A4-A359-B772255EC853}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{F8833642-2E62-4C6D-8568-CAB05CD7CA53}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{FA9A2F64-1499-4B10-904C-7FBC0BA499CD}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{FD6259A4-0285-4935-B567-8C7B27A0EF7F}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{FF5E8DE0-BA0B-4AEF-B96D-7778C7ADD9B8}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FF7180AE-B1D8-42BB-B012-3F5F4E9122FF}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"TCP Query User{0ED725A7-43D7-49D9-A164-B0CB2540FA93}C:\users\jindřich bultas\appdata\roaming\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\users\jindřich bultas\appdata\roaming\utorrent\utorrent.exe |
"TCP Query User{1CF516E3-C08B-4E1D-B3C3-C3084252F04E}C:\users\jindřich bultas\appdata\local\radiosure\radiosure.exe" = protocol=6 | dir=in | app=c:\users\jindřich bultas\appdata\local\radiosure\radiosure.exe |
"TCP Query User{725EFBB0-642F-41FD-AE0C-5F739B350744}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{82478830-001C-4E94-8C8A-6917FD18EA99}C:\program files\ea games\ultima online mondain's legacy\client.exe" = protocol=6 | dir=in | app=c:\program files\ea games\ultima online mondain's legacy\client.exe |
"TCP Query User{9DEBFCD3-370B-43DA-82A1-4C8CAA530F76}C:\program files\palm\hotsync.exe" = protocol=6 | dir=in | app=c:\program files\palm\hotsync.exe |
"TCP Query User{C3C3F80C-0B7A-4B15-A2C0-F250311CD75B}C:\program files\ea games\ultima online mondain's legacy\uoautomap\uoam.exe" = protocol=6 | dir=in | app=c:\program files\ea games\ultima online mondain's legacy\uoautomap\uoam.exe |
"UDP Query User{28FDCCE8-0D8E-4D22-B54F-DD08261E22DD}C:\program files\urbanterror\iourbanterror.exe" = protocol=17 | dir=in | app=c:\program files\urbanterror\iourbanterror.exe |
"UDP Query User{823010DB-E434-4049-B35D-01FBFFAAD20E}C:\program files\ea games\ultima online mondain's legacy\client.exe" = protocol=17 | dir=in | app=c:\program files\ea games\ultima online mondain's legacy\client.exe |
"UDP Query User{A7688F6B-FDDA-403D-8647-C604F50E67BC}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"UDP Query User{B0202EE5-BDCA-4C5F-8421-7D33134DF388}C:\users\jindřich bultas\appdata\roaming\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\users\jindřich bultas\appdata\roaming\utorrent\utorrent.exe |
"UDP Query User{C102F894-0BCB-4BD1-8C05-88D94A5AD024}C:\program files\palm\hotsync.exe" = protocol=17 | dir=in | app=c:\program files\palm\hotsync.exe |
"UDP Query User{D1D1D8BD-3D90-4907-9653-11AF8DE66FE3}C:\users\jindřich bultas\appdata\local\radiosure\radiosure.exe" = protocol=17 | dir=in | app=c:\users\jindřich bultas\appdata\local\radiosure\radiosure.exe |
"UDP Query User{F50582A3-4606-4162-A3C5-98B4F8CF7C74}C:\program files\ea games\ultima online mondain's legacy\uoautomap\uoam.exe" = protocol=17 | dir=in | app=c:\program files\ea games\ultima online mondain's legacy\uoautomap\uoam.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0891B708-EF3F-4D7E-9724-265245F46276}" = Windows Live Remote Service Resources
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E0D8F69-A6AB-4934-9B2D-159D9F97BA4A}" = ParetoLogic DriverCure
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Software Intel(R) PROSet/Wireless WiFi
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{454F5782-A4C3-480E-A629-D435795DEFD8}" = Windows Live Remote Client Resources
"{463F67F4-58D0-4C0D-BBC9-D0CC4E56D1B8}" = Windows Live UX Platform Language Pack
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E1CD3D5-D4EE-4246-AE24-F0FD5A60390D}" = OviMPlatform
"{4FFD1AB4-54F0-4069-88D9-3A55B38F874B}" = Nokia Ovi Suite Software Updater
"{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51DD370C-6690-424E-9674-5F14468B323F}" = Corel Graphics - Windows Shell Extension
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{59359B3D-ABE7-46BF-AB55-43B67A64DC68}" = Nokia MTP driver
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{60DED9C2-22BF-47A3-B6C8-6B141BA31DFD}" = Ovi Desktop Sync Engine
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F9B39A2-6AE8-459D-8BE6-863584647C78}" = iQue - Palm Reader
"{70D434C4-FD91-4A3E-B4C7-0B6764B41BA0}" = iQue - Setup Another iQue
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{7397EDED-F38A-4654-B669-BF61065803D0}" = PC Connectivity Solution
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B1AF68B-4606-4152-9991-1E9D4FF5F0FA}" = Microsoft Antimalware Service CS-CZ Language Pack
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{87CC8013-56D1-43E1-A0A5-AD406B4EBA95}" = Opera 10.63
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A30D5C0-BD4A-4E65-AADF-20A457DE6D38}" = Windows Live Family Safety
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-008A-0409-0000-0000000FF1CE}" = Microsoft Office 2007 Recent Documents Gadget
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Centrum zařízení Windows Mobile
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97F81AF1-0E47-DC99-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 ATL (x86) WinSXS MSM
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{99D7DE4C-2775-4B16-B155-7F09AE939E8E}" = Microsoft Works
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam
"{A82B38AC-D204-496B-BF76-6AFCD379AC1D}" = CUEcards® 2005
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.0 - Czech
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B44F3823-52DD-45CA-A916-8B320778715D}" = Messenger Companion
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení
"{B9C9DB4C-6D77-4AE9-AD1C-C708C23239A0}" = Nokia Connectivity Cable Driver
"{C3DAC196-8487-4E2E-94F3-9CBE361EB712}" = Microsoft Image Composite Editor
"{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}" = Nokia Ovi Suite
"{DF7B213D-2065-41ED-BB51-7A3EED31EA7B}" = Ultima Online: Mondain's Legacy
"{DFCDD1CE-6D49-49B8-BFB7-93391D22776B}" = Keyboard Driver
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E49F5ACD-2C94-4775-85BA-E7BFB239DD1A}" = iQue - Basemap
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E7044E25-3038-4A76-9064-344AC038043E}" = Aktualizace ovladače pro aplikaci Centrum zařízení Windows Mobile
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EDE64F8B-5448-402A-99C9-222E6594665B}" = Syncplicity
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"22A03655B083CBA48D06AC6168E58505D985A435" = Balíček ovladače systému Windows - Intel (NETwNv32) net (07/14/2010 13.3.0.24)
"6CF78C20C2A7F2CFD53A10716FFCBBCE4DA156A8" = Balíček ovladače systému Windows - Intel (NETwLv32) net (08/15/2010 13.3.0.137)
"AC3Filter_is1" = AC3Filter 1.63b
"Acer Screensaver" = Acer ScreenSaver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"Ashampoo WinOptimizer 7_is1" = Ashampoo WinOptimizer 7.17
"Belltech Business Card Designer Pro 5.2.2_is1" = Belltech Business Card Designer Pro 5.2.2
"BSPlayerf" = BS.Player FREE
"BusinessCardsMX3_is1" = BusinessCardsMX 3.94
"CanonMyPrinter" = Canon Utilities My Printer
"CCleaner" = CCleaner
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Endor Updater" = Endor Updater 1.3
"FastStone Image Viewer" = FastStone Image Viewer 4.2
"FastStone MaxView" = FastStone MaxView 2.1
"FastStone Photo Resizer" = FastStone Photo Resizer 3.0
"FLVPlayer" = FLV Player 1.3.3
"GENEUIDE" = USB Storage Driver
"Google Desktop" = Google Desktop
"GridVista" = Acer GridVista
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"Ilium Software eWallet_is1" = eWallet 7.0
"Ilium Software eWalletIconPack4_is1" = eWallet Icon Pack 4: Classic Icons IV Professional Edition (Win
"Ilium Software eWalletImagePack1_is1" = eWallet Image Pack 1 Professional Edition (Windows Mobile)
"InstallShield_{DFCDD1CE-6D49-49B8-BFB7-93391D22776B}" = Keyboard Driver
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"Nokia Ovi Suite" = Nokia Ovi Suite
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"ProInst" = Intel PROSet Wireless
"RealPlayer 6.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 5" = TeamViewer 5
"Totalcmd" = Total Commander (Remove or Repair)
"UOAM" = UO Auto-Map
"VirtualCloneDrive" = VirtualCloneDrive
"Winamp" = Winamp
"WinRAR archiver" = WinRAR

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2236800186-3475897335-322313511-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"PhotoFiltre Studio X" = PhotoFiltre Studio X
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:08 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:36:11 | Computer Name = JindřichBultas | Source = Windows Search Service | ID = 3013
Description =

Error - 29.10.2010 13:41:07 | Computer Name = JindřichBultas | Source = VSS | ID = 8194
Description =

Error - 29.10.2010 17:14:47 | Computer Name = JindřichBultas | Source = WinMgmt | ID = 10
Description =

Error - 29.10.2010 17:20:55 | Computer Name = JindřichBultas | Source = Application Error | ID = 1000
Description = Chybující aplikace wlmail.exe, verze 15.4.3502.922, časové razítko
0x4c9b06aa, chybující modul kernel32.dll, verze 6.0.6002.18005, časové razítko
0x49e037dd, kód výjimky 0xc06d007e, posun chyby 0x0003fbae, ID procesu 0x1a8, čas
spuštění aplikace 0x01cb77af2bfd5420.

[ System Events ]
Error - 27.10.2010 14:01:55 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7026
Description =

Error - 28.10.2010 1:56:13 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7000
Description =

Error - 28.10.2010 1:56:17 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7026
Description =

Error - 28.10.2010 1:56:46 | Computer Name = JindřichBultas | Source = DCOM | ID = 10010
Description =

Error - 28.10.2010 17:35:20 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7024
Description =

Error - 29.10.2010 1:06:22 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7000
Description =

Error - 29.10.2010 1:06:22 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7026
Description =

Error - 29.10.2010 17:14:47 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7000
Description =

Error - 29.10.2010 17:14:53 | Computer Name = JindřichBultas | Source = Service Control Manager | ID = 7026
Description =

Error - 29.10.2010 17:15:42 | Computer Name = JindřichBultas | Source = DCOM | ID = 10010
Description =


< End of report >

HenrikGodi
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 20 říj 2010 19:56

Re: Pomalý Explorer

#7 Příspěvek od HenrikGodi »

OTL.txt se nevešel, je tady http://x0.cz/7p5j

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalý Explorer

#8 Příspěvek od motji »

:o ten log je celý?

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět