
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Černej monitor
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Černej monitor
Dobry den.
Dnes rano jsem spustil PC ktere da se rict normalne nabihalo, ale nenabehlo objevil se jen cerny monitor, nevim cim to je ted to bezi normalne a tak prosim o kontrolu logu dekuji.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Karel at 2012-09-17 15:42:25
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 781 GB (82%) free of 954 GB
Total RAM: 3198 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:42:34, on 17.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\DAODx.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\4game\4game\4GameTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Karel\Downloads\RSIT.exe
C:\Program Files\trend micro\Karel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04:37&v=12.2.5.34&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files\Giant Savings\Giant Savings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [4gameTray] C:\Program Files\4game\4game\4GameTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 4game - Innova Systems LLC - C:\Program Files\4game\4game\4GameService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
--
End of file - 9015 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/firefox?client=fir ... s:official"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1426, toolbar@ask.com:3.14.1.100010, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "https://isearch.avg.com/search?cid=%7B8 ... &sap=ku&q="
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"avg@toolbar"=C:\ProgramData\AVG Secure Search\12.2.5.34\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\4game.com/plugin]
"Description"=
"Path"=C:\Program Files\4game\4game\npplugin4game.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.122.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.132.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.132.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\extensions\
crossriderapp4479@crossrider.com
toolbar@ask.com
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}]
Giant Savings - C:\Program Files\Giant Savings\Giant Savings.dll [2012-08-10 572808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-10 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-10 157672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-08-21 4282728]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
"4gameTray"=C:\Program Files\4game\4game\4GameTray.exe [2012-03-05 813408]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-07 336384]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-09-13 947808]
"ROC_ROC_NT"=C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe [2012-09-13 856160]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-17 15:42:26 ----D---- C:\Program Files\trend micro
2012-09-17 15:42:25 ----D---- C:\rsit
2012-09-17 15:12:35 ----A---- C:\Windows\ntbtlog.txt
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files\Adobe
2012-09-15 23:48:37 ----D---- C:\Program Files\Adobe
2012-09-14 08:03:36 ----D---- C:\ProgramData\Adobe
2012-09-13 09:04:51 ----D---- C:\ProgramData\AVG Secure Search
2012-09-13 09:04:35 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2012-09-13 09:04:33 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-09-13 09:04:31 ----D---- C:\Program Files\AVG Secure Search
2012-09-13 09:04:29 ----D---- C:\Users\Karel\AppData\Roaming\.minecraft
2012-09-13 09:04:24 ----D---- C:\Program Files\Giant Savings
2012-09-13 09:04:10 ----HD---- C:\ProgramData\Common Files
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\netio.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 22:28:08 ----A---- C:\Windows\system32\d3d10level9.dll
2012-09-10 08:46:28 ----D---- C:\Program Files\Common Files\Java
2012-09-10 08:46:16 ----A---- C:\Windows\system32\javaws.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2012-09-10 08:46:10 ----A---- C:\Windows\system32\javaw.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\java.exe
2012-09-10 08:46:03 ----D---- C:\Program Files\Java
2012-09-08 23:59:30 ----D---- C:\Program Files\Mozilla Firefox
2012-08-31 09:59:09 ----D---- C:\Program Files\PANDORA.TV
2012-08-31 09:58:44 ----D---- C:\ProgramData\Ask
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.ini
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.exe
2012-08-18 22:04:18 ----D---- C:\Program Files\Microsoft Synchronization Services
2012-08-18 22:04:17 ----D---- C:\Program Files\Common Files\DESIGNER
2012-08-18 22:04:02 ----D---- C:\Windows\PCHEALTH
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft Sync Framework
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-08-18 22:03:16 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-08-18 22:02:36 ----D---- C:\Program Files\Microsoft Analysis Services
2012-08-18 22:02:02 ----RHD---- C:\MSOCache
2012-08-18 19:57:06 ----D---- C:\Program Files\Microsoft Office
2012-08-18 19:57:05 ----D---- C:\ProgramData\Microsoft Help
======List of files/folders modified in the last 1 month======
2012-09-17 15:42:34 ----D---- C:\Windows\Prefetch
2012-09-17 15:42:28 ----D---- C:\Windows\Temp
2012-09-17 15:42:26 ----D---- C:\Program Files
2012-09-17 15:18:43 ----D---- C:\Windows\System32
2012-09-17 15:18:43 ----D---- C:\Windows\inf
2012-09-17 15:18:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-17 15:18:11 ----D---- C:\Windows\system32\config
2012-09-17 15:15:13 ----D---- C:\Windows
2012-09-15 23:50:26 ----D---- C:\Users\Karel\AppData\Roaming\Adobe
2012-09-15 23:49:10 ----SHD---- C:\Windows\Installer
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files
2012-09-15 23:48:34 ----SHD---- C:\System Volume Information
2012-09-15 23:46:02 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2012-09-14 10:55:31 ----D---- C:\PROGRAMY
2012-09-14 08:47:54 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-09-14 08:04:03 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-09-14 08:03:36 ----HD---- C:\ProgramData
2012-09-13 09:04:35 ----D---- C:\Windows\system32\drivers
2012-09-13 08:47:15 ----D---- C:\Windows\winsxs
2012-09-13 08:45:41 ----D---- C:\Windows\system32\DriverStore
2012-09-13 00:41:16 ----A---- C:\Windows\system32\MRT.exe
2012-09-13 00:40:56 ----D---- C:\Windows\system32\catroot
2012-09-12 22:28:04 ----D---- C:\Windows\system32\catroot2
2012-09-10 08:46:05 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-10 06:14:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-10 01:27:46 ----D---- C:\Windows\Logs
2012-09-09 19:10:32 ----D---- C:\Program Files\Battlelog Web Plugins
2012-09-09 19:02:22 ----RSD---- C:\Windows\assembly
2012-09-09 18:58:29 ----D---- C:\Program Files\Origin
2012-09-03 19:49:49 ----D---- C:\Windows\system32\Tasks
2012-08-31 09:59:06 ----D---- C:\Program Files\The KMPlayer
2012-08-29 12:01:12 ----D---- C:\Program Files\Ask.com
2012-08-25 21:22:02 ----D---- C:\FILM
2012-08-21 11:12:23 ----A---- C:\Windows\system32\aswBoot.exe
2012-08-18 22:24:56 ----D---- C:\Windows\Microsoft.NET
2012-08-18 22:11:30 ----D---- C:\Windows\Tasks
2012-08-18 22:04:44 ----RSD---- C:\Windows\Fonts
2012-08-18 22:04:41 ----D---- C:\Windows\ShellNew
2012-08-18 22:04:40 ----D---- C:\Program Files\Common Files\microsoft shared
2012-08-18 22:04:32 ----D---- C:\Program Files\MSBuild
2012-08-18 22:04:02 ----SD---- C:\ProgramData\Microsoft
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft.NET
2012-08-18 22:02:55 ----A---- C:\Windows\win.ini
2012-08-18 22:02:53 ----D---- C:\Program Files\Common Files\System
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-08-21 44784]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2012-09-13 27496]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2011-03-30 100880]
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 16384]
R3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-05-31 267880]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 4game;4game; C:\Program Files\4game\4game\4GameService.exe [2012-03-05 767840]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-08 176128]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-07 294400]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-08-21 44808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-07-25 76888]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-09-13 722528]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-08 114144]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-23 1343400]
-----------------EOF-----------------
Dnes rano jsem spustil PC ktere da se rict normalne nabihalo, ale nenabehlo objevil se jen cerny monitor, nevim cim to je ted to bezi normalne a tak prosim o kontrolu logu dekuji.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Karel at 2012-09-17 15:42:25
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 781 GB (82%) free of 954 GB
Total RAM: 3198 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:42:34, on 17.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\DAODx.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\4game\4game\4GameTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Karel\Downloads\RSIT.exe
C:\Program Files\trend micro\Karel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04:37&v=12.2.5.34&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files\Giant Savings\Giant Savings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [4gameTray] C:\Program Files\4game\4game\4GameTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 4game - Innova Systems LLC - C:\Program Files\4game\4game\4GameService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
--
End of file - 9015 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/firefox?client=fir ... s:official"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1426, toolbar@ask.com:3.14.1.100010, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "https://isearch.avg.com/search?cid=%7B8 ... &sap=ku&q="
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"avg@toolbar"=C:\ProgramData\AVG Secure Search\12.2.5.34\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\4game.com/plugin]
"Description"=
"Path"=C:\Program Files\4game\4game\npplugin4game.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.122.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.132.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.132.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\extensions\
crossriderapp4479@crossrider.com
toolbar@ask.com
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}]
Giant Savings - C:\Program Files\Giant Savings\Giant Savings.dll [2012-08-10 572808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-10 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-10 157672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-08-21 4282728]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
"4gameTray"=C:\Program Files\4game\4game\4GameTray.exe [2012-03-05 813408]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-07 336384]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-09-13 947808]
"ROC_ROC_NT"=C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe [2012-09-13 856160]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-17 15:42:26 ----D---- C:\Program Files\trend micro
2012-09-17 15:42:25 ----D---- C:\rsit
2012-09-17 15:12:35 ----A---- C:\Windows\ntbtlog.txt
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files\Adobe
2012-09-15 23:48:37 ----D---- C:\Program Files\Adobe
2012-09-14 08:03:36 ----D---- C:\ProgramData\Adobe
2012-09-13 09:04:51 ----D---- C:\ProgramData\AVG Secure Search
2012-09-13 09:04:35 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2012-09-13 09:04:33 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-09-13 09:04:31 ----D---- C:\Program Files\AVG Secure Search
2012-09-13 09:04:29 ----D---- C:\Users\Karel\AppData\Roaming\.minecraft
2012-09-13 09:04:24 ----D---- C:\Program Files\Giant Savings
2012-09-13 09:04:10 ----HD---- C:\ProgramData\Common Files
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\netio.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 22:28:08 ----A---- C:\Windows\system32\d3d10level9.dll
2012-09-10 08:46:28 ----D---- C:\Program Files\Common Files\Java
2012-09-10 08:46:16 ----A---- C:\Windows\system32\javaws.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2012-09-10 08:46:10 ----A---- C:\Windows\system32\javaw.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\java.exe
2012-09-10 08:46:03 ----D---- C:\Program Files\Java
2012-09-08 23:59:30 ----D---- C:\Program Files\Mozilla Firefox
2012-08-31 09:59:09 ----D---- C:\Program Files\PANDORA.TV
2012-08-31 09:58:44 ----D---- C:\ProgramData\Ask
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.ini
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.exe
2012-08-18 22:04:18 ----D---- C:\Program Files\Microsoft Synchronization Services
2012-08-18 22:04:17 ----D---- C:\Program Files\Common Files\DESIGNER
2012-08-18 22:04:02 ----D---- C:\Windows\PCHEALTH
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft Sync Framework
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-08-18 22:03:16 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-08-18 22:02:36 ----D---- C:\Program Files\Microsoft Analysis Services
2012-08-18 22:02:02 ----RHD---- C:\MSOCache
2012-08-18 19:57:06 ----D---- C:\Program Files\Microsoft Office
2012-08-18 19:57:05 ----D---- C:\ProgramData\Microsoft Help
======List of files/folders modified in the last 1 month======
2012-09-17 15:42:34 ----D---- C:\Windows\Prefetch
2012-09-17 15:42:28 ----D---- C:\Windows\Temp
2012-09-17 15:42:26 ----D---- C:\Program Files
2012-09-17 15:18:43 ----D---- C:\Windows\System32
2012-09-17 15:18:43 ----D---- C:\Windows\inf
2012-09-17 15:18:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-17 15:18:11 ----D---- C:\Windows\system32\config
2012-09-17 15:15:13 ----D---- C:\Windows
2012-09-15 23:50:26 ----D---- C:\Users\Karel\AppData\Roaming\Adobe
2012-09-15 23:49:10 ----SHD---- C:\Windows\Installer
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files
2012-09-15 23:48:34 ----SHD---- C:\System Volume Information
2012-09-15 23:46:02 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2012-09-14 10:55:31 ----D---- C:\PROGRAMY
2012-09-14 08:47:54 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-09-14 08:04:03 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-09-14 08:03:36 ----HD---- C:\ProgramData
2012-09-13 09:04:35 ----D---- C:\Windows\system32\drivers
2012-09-13 08:47:15 ----D---- C:\Windows\winsxs
2012-09-13 08:45:41 ----D---- C:\Windows\system32\DriverStore
2012-09-13 00:41:16 ----A---- C:\Windows\system32\MRT.exe
2012-09-13 00:40:56 ----D---- C:\Windows\system32\catroot
2012-09-12 22:28:04 ----D---- C:\Windows\system32\catroot2
2012-09-10 08:46:05 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-10 06:14:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-10 01:27:46 ----D---- C:\Windows\Logs
2012-09-09 19:10:32 ----D---- C:\Program Files\Battlelog Web Plugins
2012-09-09 19:02:22 ----RSD---- C:\Windows\assembly
2012-09-09 18:58:29 ----D---- C:\Program Files\Origin
2012-09-03 19:49:49 ----D---- C:\Windows\system32\Tasks
2012-08-31 09:59:06 ----D---- C:\Program Files\The KMPlayer
2012-08-29 12:01:12 ----D---- C:\Program Files\Ask.com
2012-08-25 21:22:02 ----D---- C:\FILM
2012-08-21 11:12:23 ----A---- C:\Windows\system32\aswBoot.exe
2012-08-18 22:24:56 ----D---- C:\Windows\Microsoft.NET
2012-08-18 22:11:30 ----D---- C:\Windows\Tasks
2012-08-18 22:04:44 ----RSD---- C:\Windows\Fonts
2012-08-18 22:04:41 ----D---- C:\Windows\ShellNew
2012-08-18 22:04:40 ----D---- C:\Program Files\Common Files\microsoft shared
2012-08-18 22:04:32 ----D---- C:\Program Files\MSBuild
2012-08-18 22:04:02 ----SD---- C:\ProgramData\Microsoft
2012-08-18 22:04:02 ----D---- C:\Program Files\Microsoft.NET
2012-08-18 22:02:55 ----A---- C:\Windows\win.ini
2012-08-18 22:02:53 ----D---- C:\Program Files\Common Files\System
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-08-21 44784]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2012-09-13 27496]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2011-03-30 100880]
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 16384]
R3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-05-31 267880]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 4game;4game; C:\Program Files\4game\4game\4GameService.exe [2012-03-05 767840]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-08 176128]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-07 294400]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-08-21 44808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-07-25 76888]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-09-13 722528]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-08 114144]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-23 1343400]
-----------------EOF-----------------
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
Zdravim
Mas to zavsiveny.
Spust Malwarebytes uplnu kontrolu, najdene odstranit, log vloz sem
http://forum.viry.cz/viewtopic.php?f=29 ... 1#p1031821
Mas to zavsiveny.
Spust Malwarebytes uplnu kontrolu, najdene odstranit, log vloz sem
http://forum.viry.cz/viewtopic.php?f=29 ... 1#p1031821
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Černej monitor
Omluva za vstup. Co ten cracklý Ofiice? Odinstalujte, toto fórum nepodporuje pirátský software.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Černej monitor
office odstranen.
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Verze databáze: v2012.09.17.08
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Karel :: KAREL-PC [administrátor]
17.9.2012 19:50:35
mbam-log-2012-09-17 (20-14-41).txt
Typ: Úplná kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 267801
Uplynulý čas: 22 minut, 6 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 1
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 1
HKCU\Software\InstalledBrowserExtensions\215 Apps|4479 (PUP.CrossFire.SA) -> Data: Giant Savings -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Users\Karel\Downloads\minecraft setup.exe (PUP.AdBundle) -> Žádná instrukce nebyla provedena.
(konec)
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Verze databáze: v2012.09.17.08
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Karel :: KAREL-PC [administrátor]
17.9.2012 19:50:35
mbam-log-2012-09-17 (20-14-41).txt
Typ: Úplná kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 267801
Uplynulý čas: 22 minut, 6 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 1
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 1
HKCU\Software\InstalledBrowserExtensions\215 Apps|4479 (PUP.CrossFire.SA) -> Data: Giant Savings -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Users\Karel\Downloads\minecraft setup.exe (PUP.AdBundle) -> Žádná instrukce nebyla provedena.
(konec)
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
Zmaz vsetko co MBAM nasiel,
Odinstaluj program
C:\Program Files\Ask.com
Podla navodu od kolegu vycisti pc.
Enter,,Ano,yes, Ano,, restart a nechaj aby chkdsk skontroloval disk.
A potom napis ako je na tom pc.
Odinstaluj program
C:\Program Files\Ask.com
Podla navodu od kolegu vycisti pc.
2:Zadaj do prikazoveho riadku chkdsk /f/rStahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
dejte Hledej problémy
nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden
Enter,,Ano,yes, Ano,, restart a nechaj aby chkdsk skontroloval disk.
A potom napis ako je na tom pc.
Re: Černej monitor
Takze zatim jsem udelal vse co jste chteli, az na jednu vec a to stim prikazovim radkem. Kliknul jsem na Start dole je prikazovej radek tam jsem to napsal dal enter ale to bylo vse dal se nic nedelo. Zatim prikladam log z rsit.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Karel at 2012-09-17 20:59:09
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 833 GB (87%) free of 954 GB
Total RAM: 3198 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:59:20, on 17.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\DAODx.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\4game\4game\4GameTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\Karel\Desktop\RSIT.exe
C:\Program Files\trend micro\Karel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04:37&v=12.2.5.34&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files\Giant Savings\Giant Savings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [4gameTray] C:\Program Files\4game\4game\4GameTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O23 - Service: 4game - Innova Systems LLC - C:\Program Files\4game\4game\4GameService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
--
End of file - 7577 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/firefox?client=fir ... s:official"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1426, toolbar@ask.com:3.14.1.100010, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "https://isearch.avg.com/search?cid=%7B8 ... &sap=ku&q="
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"avg@toolbar"=C:\ProgramData\AVG Secure Search\12.2.5.34\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\4game.com/plugin]
"Description"=
"Path"=C:\Program Files\4game\4game\npplugin4game.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.122.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.132.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.132.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\extensions\
crossriderapp4479@crossrider.com
toolbar@ask.com
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}]
Giant Savings - C:\Program Files\Giant Savings\Giant Savings.dll [2012-08-10 572808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-10 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-10 157672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-08-21 4282728]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
"4gameTray"=C:\Program Files\4game\4game\4GameTray.exe [2012-03-05 813408]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-07 336384]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-09-13 947808]
"ROC_ROC_NT"=C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe [2012-09-13 856160]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-17 20:44:55 ----D---- C:\Program Files\CCleaner
2012-09-17 19:47:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-09-17 19:47:31 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-09-17 19:44:24 ----SHD---- C:\Config.Msi
2012-09-17 15:42:26 ----D---- C:\Program Files\trend micro
2012-09-17 15:42:25 ----D---- C:\rsit
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files\Adobe
2012-09-15 23:48:37 ----D---- C:\Program Files\Adobe
2012-09-14 08:03:36 ----D---- C:\ProgramData\Adobe
2012-09-13 09:04:51 ----D---- C:\ProgramData\AVG Secure Search
2012-09-13 09:04:35 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2012-09-13 09:04:33 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-09-13 09:04:31 ----D---- C:\Program Files\AVG Secure Search
2012-09-13 09:04:29 ----D---- C:\Users\Karel\AppData\Roaming\.minecraft
2012-09-13 09:04:24 ----D---- C:\Program Files\Giant Savings
2012-09-13 09:04:10 ----HD---- C:\ProgramData\Common Files
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\netio.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 22:28:08 ----A---- C:\Windows\system32\d3d10level9.dll
2012-09-10 08:46:28 ----D---- C:\Program Files\Common Files\Java
2012-09-10 08:46:16 ----A---- C:\Windows\system32\javaws.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2012-09-10 08:46:10 ----A---- C:\Windows\system32\javaw.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\java.exe
2012-09-10 08:46:03 ----D---- C:\Program Files\Java
2012-09-08 23:59:30 ----D---- C:\Program Files\Mozilla Firefox
2012-08-31 09:59:09 ----D---- C:\Program Files\PANDORA.TV
2012-08-31 09:58:44 ----D---- C:\ProgramData\Ask
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.ini
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.exe
2012-08-18 19:57:06 ----D---- C:\Program Files\Microsoft Office
2012-08-18 19:57:05 ----D---- C:\ProgramData\Microsoft Help
======List of files/folders modified in the last 1 month======
2012-09-17 20:59:19 ----D---- C:\Windows\Temp
2012-09-17 20:59:07 ----D---- C:\Windows\Prefetch
2012-09-17 20:57:18 ----D---- C:\Windows
2012-09-17 20:56:22 ----D---- C:\Windows\system32\config
2012-09-17 20:47:37 ----D---- C:\Users\Karel\AppData\Roaming\TS3Client
2012-09-17 20:47:23 ----D---- C:\Windows\Panther
2012-09-17 20:47:23 ----D---- C:\Windows\Minidump
2012-09-17 20:47:23 ----D---- C:\Windows\Logs
2012-09-17 20:47:23 ----D---- C:\Windows\inf
2012-09-17 20:47:23 ----D---- C:\Windows\debug
2012-09-17 20:44:57 ----D---- C:\Windows\system32\Tasks
2012-09-17 20:44:55 ----D---- C:\Program Files
2012-09-17 20:40:01 ----D---- C:\Program Files\Ask.com
2012-09-17 20:36:10 ----D---- C:\Windows\System32
2012-09-17 20:36:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-17 20:29:52 ----D---- C:\Windows\system32\drivers
2012-09-17 20:28:33 ----D---- C:\Windows\Branding
2012-09-17 19:59:36 ----RSD---- C:\Windows\assembly
2012-09-17 19:59:36 ----D---- C:\Windows\Microsoft.NET
2012-09-17 19:56:46 ----D---- C:\Windows\winsxs
2012-09-17 19:47:11 ----SHD---- C:\Windows\Installer
2012-09-17 19:46:31 ----SD---- C:\ProgramData\Microsoft
2012-09-17 19:46:31 ----D---- C:\Program Files\Microsoft.NET
2012-09-17 19:46:31 ----D---- C:\Program Files\Common Files\microsoft shared
2012-09-17 19:45:55 ----RSD---- C:\Windows\Fonts
2012-09-17 19:45:39 ----D---- C:\Windows\ShellNew
2012-09-17 19:45:33 ----D---- C:\Program Files\MSBuild
2012-09-17 19:45:25 ----D---- C:\Program Files\Common Files
2012-09-17 19:44:16 ----D---- C:\Program Files\Common Files\System
2012-09-17 19:44:15 ----A---- C:\Windows\win.ini
2012-09-17 19:43:08 ----SHD---- C:\System Volume Information
2012-09-15 23:50:26 ----D---- C:\Users\Karel\AppData\Roaming\Adobe
2012-09-15 23:46:02 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2012-09-14 10:55:31 ----D---- C:\PROGRAMY
2012-09-14 08:47:54 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-09-14 08:04:03 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-09-14 08:03:36 ----HD---- C:\ProgramData
2012-09-13 08:45:41 ----D---- C:\Windows\system32\DriverStore
2012-09-13 00:41:16 ----A---- C:\Windows\system32\MRT.exe
2012-09-13 00:40:56 ----D---- C:\Windows\system32\catroot
2012-09-12 22:28:04 ----D---- C:\Windows\system32\catroot2
2012-09-10 08:46:05 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-10 06:14:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-09 19:10:32 ----D---- C:\Program Files\Battlelog Web Plugins
2012-09-09 18:58:29 ----D---- C:\Program Files\Origin
2012-08-31 09:59:06 ----D---- C:\Program Files\The KMPlayer
2012-08-25 21:22:02 ----D---- C:\FILM
2012-08-21 11:12:23 ----A---- C:\Windows\system32\aswBoot.exe
2012-08-18 22:11:30 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-08-21 44784]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2012-09-13 27496]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2011-03-30 100880]
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 16384]
R3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-09-07 22856]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-05-31 267880]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 4game;4game; C:\Program Files\4game\4game\4GameService.exe [2012-03-05 767840]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-08 176128]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-07 294400]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-08-21 44808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-07-25 76888]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-09-13 722528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-08 114144]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-23 1343400]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Karel at 2012-09-17 20:59:09
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 833 GB (87%) free of 954 GB
Total RAM: 3198 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:59:20, on 17.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\DAODx.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\4game\4game\4GameTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\Karel\Desktop\RSIT.exe
C:\Program Files\trend micro\Karel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04:37&v=12.2.5.34&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files\Giant Savings\Giant Savings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [4gameTray] C:\Program Files\4game\4game\4GameTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O23 - Service: 4game - Innova Systems LLC - C:\Program Files\4game\4game\4GameService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
--
End of file - 7577 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/firefox?client=fir ... s:official"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1426, toolbar@ask.com:3.14.1.100010, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "https://isearch.avg.com/search?cid=%7B8 ... &sap=ku&q="
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"avg@toolbar"=C:\ProgramData\AVG Secure Search\12.2.5.34\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\4game.com/plugin]
"Description"=
"Path"=C:\Program Files\4game\4game\npplugin4game.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.122.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.132.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\1.132.0\npesnlaunch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\extensions\
crossriderapp4479@crossrider.com
toolbar@ask.com
C:\Users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}]
Giant Savings - C:\Program Files\Giant Savings\Giant Savings.dll [2012-08-10 572808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-10 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-10 157672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2012-05-02 798771]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-08-21 1227224]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll [2012-09-13 1734240]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-08-21 4282728]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
"4gameTray"=C:\Program Files\4game\4game\4GameTray.exe [2012-03-05 813408]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-07 336384]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-09-13 947808]
"ROC_ROC_NT"=C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe [2012-09-13 856160]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-17 20:44:55 ----D---- C:\Program Files\CCleaner
2012-09-17 19:47:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-09-17 19:47:31 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-09-17 19:44:24 ----SHD---- C:\Config.Msi
2012-09-17 15:42:26 ----D---- C:\Program Files\trend micro
2012-09-17 15:42:25 ----D---- C:\rsit
2012-09-15 23:48:37 ----D---- C:\Program Files\Common Files\Adobe
2012-09-15 23:48:37 ----D---- C:\Program Files\Adobe
2012-09-14 08:03:36 ----D---- C:\ProgramData\Adobe
2012-09-13 09:04:51 ----D---- C:\ProgramData\AVG Secure Search
2012-09-13 09:04:35 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2012-09-13 09:04:33 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-09-13 09:04:31 ----D---- C:\Program Files\AVG Secure Search
2012-09-13 09:04:29 ----D---- C:\Users\Karel\AppData\Roaming\.minecraft
2012-09-13 09:04:24 ----D---- C:\Program Files\Giant Savings
2012-09-13 09:04:10 ----HD---- C:\ProgramData\Common Files
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2012-09-12 22:28:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\netio.sys
2012-09-12 22:28:10 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 22:28:08 ----A---- C:\Windows\system32\d3d10level9.dll
2012-09-10 08:46:28 ----D---- C:\Program Files\Common Files\Java
2012-09-10 08:46:16 ----A---- C:\Windows\system32\javaws.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2012-09-10 08:46:10 ----A---- C:\Windows\system32\javaw.exe
2012-09-10 08:46:10 ----A---- C:\Windows\system32\java.exe
2012-09-10 08:46:03 ----D---- C:\Program Files\Java
2012-09-08 23:59:30 ----D---- C:\Program Files\Mozilla Firefox
2012-08-31 09:59:09 ----D---- C:\Program Files\PANDORA.TV
2012-08-31 09:58:44 ----D---- C:\ProgramData\Ask
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.ini
2012-08-18 22:11:30 ----A---- C:\Windows\AutoKMS.exe
2012-08-18 19:57:06 ----D---- C:\Program Files\Microsoft Office
2012-08-18 19:57:05 ----D---- C:\ProgramData\Microsoft Help
======List of files/folders modified in the last 1 month======
2012-09-17 20:59:19 ----D---- C:\Windows\Temp
2012-09-17 20:59:07 ----D---- C:\Windows\Prefetch
2012-09-17 20:57:18 ----D---- C:\Windows
2012-09-17 20:56:22 ----D---- C:\Windows\system32\config
2012-09-17 20:47:37 ----D---- C:\Users\Karel\AppData\Roaming\TS3Client
2012-09-17 20:47:23 ----D---- C:\Windows\Panther
2012-09-17 20:47:23 ----D---- C:\Windows\Minidump
2012-09-17 20:47:23 ----D---- C:\Windows\Logs
2012-09-17 20:47:23 ----D---- C:\Windows\inf
2012-09-17 20:47:23 ----D---- C:\Windows\debug
2012-09-17 20:44:57 ----D---- C:\Windows\system32\Tasks
2012-09-17 20:44:55 ----D---- C:\Program Files
2012-09-17 20:40:01 ----D---- C:\Program Files\Ask.com
2012-09-17 20:36:10 ----D---- C:\Windows\System32
2012-09-17 20:36:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-17 20:29:52 ----D---- C:\Windows\system32\drivers
2012-09-17 20:28:33 ----D---- C:\Windows\Branding
2012-09-17 19:59:36 ----RSD---- C:\Windows\assembly
2012-09-17 19:59:36 ----D---- C:\Windows\Microsoft.NET
2012-09-17 19:56:46 ----D---- C:\Windows\winsxs
2012-09-17 19:47:11 ----SHD---- C:\Windows\Installer
2012-09-17 19:46:31 ----SD---- C:\ProgramData\Microsoft
2012-09-17 19:46:31 ----D---- C:\Program Files\Microsoft.NET
2012-09-17 19:46:31 ----D---- C:\Program Files\Common Files\microsoft shared
2012-09-17 19:45:55 ----RSD---- C:\Windows\Fonts
2012-09-17 19:45:39 ----D---- C:\Windows\ShellNew
2012-09-17 19:45:33 ----D---- C:\Program Files\MSBuild
2012-09-17 19:45:25 ----D---- C:\Program Files\Common Files
2012-09-17 19:44:16 ----D---- C:\Program Files\Common Files\System
2012-09-17 19:44:15 ----A---- C:\Windows\win.ini
2012-09-17 19:43:08 ----SHD---- C:\System Volume Information
2012-09-15 23:50:26 ----D---- C:\Users\Karel\AppData\Roaming\Adobe
2012-09-15 23:46:02 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2012-09-14 10:55:31 ----D---- C:\PROGRAMY
2012-09-14 08:47:54 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-09-14 08:04:03 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-09-14 08:03:36 ----HD---- C:\ProgramData
2012-09-13 08:45:41 ----D---- C:\Windows\system32\DriverStore
2012-09-13 00:41:16 ----A---- C:\Windows\system32\MRT.exe
2012-09-13 00:40:56 ----D---- C:\Windows\system32\catroot
2012-09-12 22:28:04 ----D---- C:\Windows\system32\catroot2
2012-09-10 08:46:05 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-10 06:14:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-09 19:10:32 ----D---- C:\Program Files\Battlelog Web Plugins
2012-09-09 18:58:29 ----D---- C:\Program Files\Origin
2012-08-31 09:59:06 ----D---- C:\Program Files\The KMPlayer
2012-08-25 21:22:02 ----D---- C:\FILM
2012-08-21 11:12:23 ----A---- C:\Windows\system32\aswBoot.exe
2012-08-18 22:11:30 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-08-21 44784]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2012-09-13 27496]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2011-03-30 100880]
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 16384]
R3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-09-07 22856]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-05-31 267880]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 4game;4game; C:\Program Files\4game\4game\4GameService.exe [2012-03-05 767840]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-08 176128]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-07 294400]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-08-21 44808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-07-25 76888]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-09-13 722528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-08 114144]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-23 1343400]
-----------------EOF-----------------
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
odinstaluj program
C:\Program Files\Ask.com
Prikazovy riadok nie je nikde dole,
dole do pola hladat napis cmd
pravy klik na cmd a spust ako spravca.
A tu napis ten prikaz,
Zadaj do prikazoveho riadku chkdsk /f/r
Enter,,Ano,yes, Ano,, restart a nechaj aby chkdsk skontroloval disk.
Potom spust TDSSKILLER.
NAVOD
log vloz sem.
A vloz sem aj log z combofixu
http://www.bleepingcomputer.com/combofi ... t-combofix
C:\Program Files\Ask.com
Prikazovy riadok nie je nikde dole,
dole do pola hladat napis cmd
pravy klik na cmd a spust ako spravca.
A tu napis ten prikaz,
Zadaj do prikazoveho riadku chkdsk /f/r
Enter,,Ano,yes, Ano,, restart a nechaj aby chkdsk skontroloval disk.
Potom spust TDSSKILLER.
NAVOD
log vloz sem.
A vloz sem aj log z combofixu
http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Černej monitor
to jak mam odstranit Ask.com to se mi nejak nedari zastalami tam slozka updater a ne a ne se ji zbavit ani jako administrator. Vkladam log.
17:38:44.0232 3244 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
17:38:44.0777 3244 ============================================================
17:38:44.0777 3244 Current date / time: 2012/09/18 17:38:44.0777
17:38:44.0777 3244 SystemInfo:
17:38:44.0777 3244
17:38:44.0777 3244 OS Version: 6.1.7601 ServicePack: 1.0
17:38:44.0777 3244 Product type: Workstation
17:38:44.0777 3244 ComputerName: KAREL-PC
17:38:44.0778 3244 UserName: Karel
17:38:44.0778 3244 Windows directory: C:\Windows
17:38:44.0778 3244 System windows directory: C:\Windows
17:38:44.0778 3244 Processor architecture: Intel x86
17:38:44.0778 3244 Number of processors: 3
17:38:44.0778 3244 Page size: 0x1000
17:38:44.0778 3244 Boot type: Normal boot
17:38:44.0778 3244 ============================================================
17:38:47.0563 3244 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:38:47.0585 3244 ============================================================
17:38:47.0585 3244 \Device\Harddisk0\DR0:
17:38:47.0587 3244 MBR partitions:
17:38:47.0587 3244 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:38:47.0587 3244 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
17:38:47.0588 3244 ============================================================
17:38:47.0621 3244 C: <-> \Device\Harddisk0\DR0\Partition2
17:38:47.0621 3244 ============================================================
17:38:47.0622 3244 Initialize success
17:38:47.0622 3244 ============================================================
17:39:09.0715 1100 ============================================================
17:39:09.0715 1100 Scan started
17:39:09.0715 1100 Mode: Manual;
17:39:09.0715 1100 ============================================================
17:39:10.0518 1100 ================ Scan system memory ========================
17:39:10.0518 1100 System memory - ok
17:39:10.0519 1100 ================ Scan services =============================
17:39:10.0634 1100 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:39:10.0636 1100 1394ohci - ok
17:39:10.0705 1100 [ 008BD0D672383068E8981D44199E9354 ] 4game C:\Program Files\4game\4game\4GameService.exe
17:39:10.0728 1100 4game - ok
17:39:10.0759 1100 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:39:10.0765 1100 ACPI - ok
17:39:10.0789 1100 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:39:10.0792 1100 AcpiPmi - ok
17:39:10.0840 1100 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:39:10.0842 1100 AdobeARMservice - ok
17:39:10.0869 1100 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:39:10.0878 1100 adp94xx - ok
17:39:10.0904 1100 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:39:10.0911 1100 adpahci - ok
17:39:10.0916 1100 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:39:10.0918 1100 adpu320 - ok
17:39:10.0937 1100 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:39:10.0938 1100 AeLookupSvc - ok
17:39:10.0958 1100 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
17:39:10.0962 1100 AFD - ok
17:39:10.0981 1100 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:39:10.0982 1100 agp440 - ok
17:39:10.0998 1100 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:39:10.0999 1100 aic78xx - ok
17:39:11.0011 1100 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:39:11.0013 1100 ALG - ok
17:39:11.0043 1100 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:39:11.0044 1100 aliide - ok
17:39:11.0069 1100 [ 5320FF0FDEC41FAF9D5CB01318AEFD6A ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:39:11.0073 1100 AMD External Events Utility - ok
17:39:11.0098 1100 AMD FUEL Service - ok
17:39:11.0121 1100 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:39:11.0123 1100 amdagp - ok
17:39:11.0133 1100 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:39:11.0134 1100 amdide - ok
17:39:11.0154 1100 [ FF258424F0B2EF25EB98F04EE386E6E3 ] amdiox86 C:\Windows\system32\DRIVERS\amdiox86.sys
17:39:11.0155 1100 amdiox86 - ok
17:39:11.0159 1100 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:39:11.0160 1100 AmdK8 - ok
17:39:11.0280 1100 [ 335ACE2A8E97439733F0F6A1BBD818D5 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:39:11.0418 1100 amdkmdag - ok
17:39:11.0430 1100 [ 0B1B116D30F133DC918287FD8E212F1E ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
17:39:11.0432 1100 amdkmdap - ok
17:39:11.0457 1100 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:39:11.0457 1100 AmdPPM - ok
17:39:11.0481 1100 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:39:11.0482 1100 amdsata - ok
17:39:11.0491 1100 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:39:11.0493 1100 amdsbs - ok
17:39:11.0502 1100 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:39:11.0503 1100 amdxata - ok
17:39:11.0522 1100 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:39:11.0523 1100 AppID - ok
17:39:11.0543 1100 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:39:11.0544 1100 AppIDSvc - ok
17:39:11.0560 1100 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
17:39:11.0561 1100 Appinfo - ok
17:39:11.0578 1100 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:39:11.0580 1100 AppMgmt - ok
17:39:11.0584 1100 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:39:11.0585 1100 arc - ok
17:39:11.0588 1100 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:39:11.0589 1100 arcsas - ok
17:39:11.0603 1100 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
17:39:11.0603 1100 aswFsBlk - ok
17:39:11.0613 1100 [ F76E51561562AC4105DBBE53FC99BC10 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:39:11.0613 1100 aswMonFlt - ok
17:39:11.0633 1100 [ 924819669AFD0EDF5C067193D371FAB0 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
17:39:11.0634 1100 aswRdr - ok
17:39:11.0664 1100 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:39:11.0670 1100 aswSnx - ok
17:39:11.0682 1100 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:39:11.0685 1100 aswSP - ok
17:39:11.0693 1100 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:39:11.0694 1100 aswTdi - ok
17:39:11.0700 1100 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:39:11.0700 1100 AsyncMac - ok
17:39:11.0703 1100 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:39:11.0704 1100 atapi - ok
17:39:11.0733 1100 [ 45FE74599FBA4070E7C7DAC928896474 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:39:11.0734 1100 AtiHDAudioService - ok
17:39:11.0756 1100 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:39:11.0759 1100 AudioEndpointBuilder - ok
17:39:11.0764 1100 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:39:11.0766 1100 Audiosrv - ok
17:39:11.0787 1100 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:39:11.0788 1100 avast! Antivirus - ok
17:39:11.0810 1100 [ 3001E24F340D400BFF85935E5777FC5B ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
17:39:11.0811 1100 avgtp - ok
17:39:11.0840 1100 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:39:11.0845 1100 AxInstSV - ok
17:39:11.0871 1100 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:39:11.0876 1100 b06bdrv - ok
17:39:11.0893 1100 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:39:11.0896 1100 b57nd60x - ok
17:39:11.0910 1100 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:39:11.0912 1100 BDESVC - ok
17:39:11.0922 1100 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:39:11.0923 1100 Beep - ok
17:39:11.0949 1100 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:39:11.0955 1100 BFE - ok
17:39:11.0979 1100 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:39:11.0989 1100 BITS - ok
17:39:12.0001 1100 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:39:12.0002 1100 blbdrive - ok
17:39:12.0022 1100 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:39:12.0024 1100 bowser - ok
17:39:12.0027 1100 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:39:12.0028 1100 BrFiltLo - ok
17:39:12.0032 1100 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:39:12.0033 1100 BrFiltUp - ok
17:39:12.0062 1100 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:39:12.0063 1100 Browser - ok
17:39:12.0070 1100 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:39:12.0073 1100 Brserid - ok
17:39:12.0077 1100 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:39:12.0078 1100 BrSerWdm - ok
17:39:12.0087 1100 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:39:12.0088 1100 BrUsbMdm - ok
17:39:12.0091 1100 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:39:12.0092 1100 BrUsbSer - ok
17:39:12.0095 1100 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:39:12.0097 1100 BTHMODEM - ok
17:39:12.0103 1100 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:39:12.0105 1100 bthserv - ok
17:39:12.0117 1100 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:39:12.0118 1100 cdfs - ok
17:39:12.0135 1100 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
17:39:12.0137 1100 cdrom - ok
17:39:12.0148 1100 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:39:12.0149 1100 CertPropSvc - ok
17:39:12.0157 1100 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:39:12.0158 1100 circlass - ok
17:39:12.0169 1100 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:39:12.0171 1100 CLFS - ok
17:39:12.0221 1100 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:39:12.0225 1100 clr_optimization_v2.0.50727_32 - ok
17:39:12.0248 1100 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:39:12.0250 1100 clr_optimization_v4.0.30319_32 - ok
17:39:12.0258 1100 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:39:12.0259 1100 CmBatt - ok
17:39:12.0265 1100 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:39:12.0266 1100 cmdide - ok
17:39:12.0292 1100 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
17:39:12.0296 1100 CNG - ok
17:39:12.0300 1100 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:39:12.0301 1100 Compbatt - ok
17:39:12.0316 1100 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:39:12.0317 1100 CompositeBus - ok
17:39:12.0320 1100 COMSysApp - ok
17:39:12.0325 1100 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:39:12.0326 1100 crcdisk - ok
17:39:12.0359 1100 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:39:12.0361 1100 CryptSvc - ok
17:39:12.0384 1100 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:39:12.0388 1100 CSC - ok
17:39:12.0418 1100 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:39:12.0423 1100 CscService - ok
17:39:12.0442 1100 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:39:12.0450 1100 DcomLaunch - ok
17:39:12.0461 1100 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:39:12.0465 1100 defragsvc - ok
17:39:12.0479 1100 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:39:12.0481 1100 DfsC - ok
17:39:12.0500 1100 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:39:12.0506 1100 Dhcp - ok
17:39:12.0515 1100 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:39:12.0517 1100 discache - ok
17:39:12.0530 1100 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:39:12.0533 1100 Disk - ok
17:39:12.0560 1100 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:39:12.0564 1100 Dnscache - ok
17:39:12.0585 1100 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:39:12.0589 1100 dot3svc - ok
17:39:12.0612 1100 [ B5E479EB83707DD698F66953E922042C ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
17:39:12.0614 1100 Dot4 - ok
17:39:12.0635 1100 [ CAEFD09B6A6249C53A67D55A9A9FCABF ] Dot4Print C:\Windows\system32\drivers\Dot4Prt.sys
17:39:12.0636 1100 Dot4Print - ok
17:39:12.0649 1100 [ CF491FF38D62143203C065260567E2F7 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
17:39:12.0650 1100 dot4usb - ok
17:39:12.0667 1100 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:39:12.0670 1100 DPS - ok
17:39:12.0681 1100 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:39:12.0682 1100 drmkaud - ok
17:39:12.0707 1100 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:39:12.0714 1100 DXGKrnl - ok
17:39:12.0735 1100 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:39:12.0738 1100 EapHost - ok
17:39:12.0805 1100 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:39:12.0856 1100 ebdrv - ok
17:39:12.0873 1100 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
17:39:12.0875 1100 EFS - ok
17:39:12.0908 1100 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:39:12.0920 1100 ehRecvr - ok
17:39:12.0938 1100 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:39:12.0940 1100 ehSched - ok
17:39:12.0955 1100 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:39:12.0960 1100 elxstor - ok
17:39:12.0976 1100 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:39:12.0977 1100 ErrDev - ok
17:39:12.0999 1100 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:39:13.0003 1100 EventSystem - ok
17:39:13.0018 1100 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:39:13.0020 1100 exfat - ok
17:39:13.0035 1100 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:39:13.0038 1100 fastfat - ok
17:39:13.0063 1100 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:39:13.0068 1100 Fax - ok
17:39:13.0076 1100 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:39:13.0078 1100 fdc - ok
17:39:13.0088 1100 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:39:13.0091 1100 fdPHost - ok
17:39:13.0097 1100 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:39:13.0099 1100 FDResPub - ok
17:39:13.0110 1100 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:39:13.0111 1100 FileInfo - ok
17:39:13.0121 1100 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:39:13.0122 1100 Filetrace - ok
17:39:13.0126 1100 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:39:13.0127 1100 flpydisk - ok
17:39:13.0141 1100 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:39:13.0143 1100 FltMgr - ok
17:39:13.0185 1100 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
17:39:13.0202 1100 FontCache - ok
17:39:13.0240 1100 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:39:13.0241 1100 FontCache3.0.0.0 - ok
17:39:13.0255 1100 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:39:13.0256 1100 FsDepends - ok
17:39:13.0267 1100 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:39:13.0267 1100 Fs_Rec - ok
17:39:13.0278 1100 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:39:13.0280 1100 fvevol - ok
17:39:13.0290 1100 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:39:13.0291 1100 gagp30kx - ok
17:39:13.0314 1100 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:39:13.0322 1100 gpsvc - ok
17:39:13.0331 1100 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:39:13.0332 1100 hcw85cir - ok
17:39:13.0369 1100 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:39:13.0373 1100 HdAudAddService - ok
17:39:13.0393 1100 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:39:13.0396 1100 HDAudBus - ok
17:39:13.0414 1100 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:39:13.0415 1100 HidBatt - ok
17:39:13.0419 1100 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:39:13.0421 1100 HidBth - ok
17:39:13.0424 1100 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:39:13.0426 1100 HidIr - ok
17:39:13.0436 1100 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:39:13.0439 1100 hidserv - ok
17:39:13.0472 1100 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
17:39:13.0473 1100 HidUsb - ok
17:39:13.0493 1100 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:39:13.0496 1100 hkmsvc - ok
17:39:13.0514 1100 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:39:13.0518 1100 HomeGroupListener - ok
17:39:13.0548 1100 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:39:13.0553 1100 HomeGroupProvider - ok
17:39:13.0563 1100 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:39:13.0565 1100 HpSAMD - ok
17:39:13.0583 1100 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:39:13.0588 1100 HTTP - ok
17:39:13.0597 1100 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:39:13.0597 1100 hwpolicy - ok
17:39:13.0615 1100 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:39:13.0617 1100 i8042prt - ok
17:39:13.0630 1100 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:39:13.0634 1100 iaStorV - ok
17:39:13.0679 1100 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:39:13.0696 1100 idsvc - ok
17:39:13.0704 1100 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:39:13.0706 1100 iirsp - ok
17:39:13.0723 1100 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:39:13.0732 1100 IKEEXT - ok
17:39:13.0755 1100 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:39:13.0757 1100 intelide - ok
17:39:13.0767 1100 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:39:13.0768 1100 intelppm - ok
17:39:13.0803 1100 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:39:13.0809 1100 IPBusEnum - ok
17:39:13.0814 1100 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:39:13.0815 1100 IpFilterDriver - ok
17:39:13.0836 1100 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:39:13.0843 1100 iphlpsvc - ok
17:39:13.0851 1100 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:39:13.0853 1100 IPMIDRV - ok
17:39:13.0860 1100 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:39:13.0861 1100 IPNAT - ok
17:39:13.0874 1100 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:39:13.0875 1100 IRENUM - ok
17:39:13.0884 1100 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:39:13.0886 1100 isapnp - ok
17:39:13.0908 1100 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:39:13.0911 1100 iScsiPrt - ok
17:39:13.0914 1100 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
17:39:13.0915 1100 kbdclass - ok
17:39:13.0928 1100 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:39:13.0929 1100 kbdhid - ok
17:39:13.0940 1100 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
17:39:13.0942 1100 KeyIso - ok
17:39:13.0954 1100 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:39:13.0955 1100 KSecDD - ok
17:39:13.0966 1100 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:39:13.0967 1100 KSecPkg - ok
17:39:13.0987 1100 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:39:13.0992 1100 KtmRm - ok
17:39:13.0996 1100 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:39:14.0000 1100 LanmanServer - ok
17:39:14.0018 1100 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:39:14.0022 1100 LanmanWorkstation - ok
17:39:14.0042 1100 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:39:14.0043 1100 lltdio - ok
17:39:14.0055 1100 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:39:14.0059 1100 lltdsvc - ok
17:39:14.0065 1100 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:39:14.0068 1100 lmhosts - ok
17:39:14.0079 1100 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:39:14.0080 1100 LSI_FC - ok
17:39:14.0083 1100 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:39:14.0084 1100 LSI_SAS - ok
17:39:14.0087 1100 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:39:14.0088 1100 LSI_SAS2 - ok
17:39:14.0096 1100 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:39:14.0097 1100 LSI_SCSI - ok
17:39:14.0108 1100 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:39:14.0109 1100 luafv - ok
17:39:14.0128 1100 [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:39:14.0129 1100 MBAMProtector - ok
17:39:14.0196 1100 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:39:14.0203 1100 MBAMScheduler - ok
17:39:14.0225 1100 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:39:14.0230 1100 MBAMService - ok
17:39:14.0247 1100 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:39:14.0254 1100 Mcx2Svc - ok
17:39:14.0258 1100 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:39:14.0259 1100 megasas - ok
17:39:14.0264 1100 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:39:14.0267 1100 MegaSR - ok
17:39:14.0274 1100 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:39:14.0277 1100 MMCSS - ok
17:39:14.0279 1100 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:39:14.0280 1100 Modem - ok
17:39:14.0288 1100 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:39:14.0289 1100 monitor - ok
17:39:14.0299 1100 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
17:39:14.0301 1100 mouclass - ok
17:39:14.0309 1100 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:39:14.0310 1100 mouhid - ok
17:39:14.0330 1100 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:39:14.0331 1100 mountmgr - ok
17:39:14.0354 1100 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:39:14.0356 1100 MozillaMaintenance - ok
17:39:14.0370 1100 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:39:14.0375 1100 mpio - ok
17:39:14.0384 1100 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:39:14.0387 1100 mpsdrv - ok
17:39:14.0458 1100 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:39:14.0495 1100 MpsSvc - ok
17:39:14.0516 1100 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:39:14.0520 1100 MRxDAV - ok
17:39:14.0552 1100 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:39:14.0556 1100 mrxsmb - ok
17:39:14.0574 1100 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:39:14.0580 1100 mrxsmb10 - ok
17:39:14.0598 1100 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:39:14.0601 1100 mrxsmb20 - ok
17:39:14.0618 1100 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:39:14.0619 1100 msahci - ok
17:39:14.0629 1100 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:39:14.0631 1100 msdsm - ok
17:39:14.0644 1100 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:39:14.0649 1100 MSDTC - ok
17:39:14.0663 1100 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:39:14.0664 1100 Msfs - ok
17:39:14.0679 1100 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:39:14.0680 1100 mshidkmdf - ok
17:39:14.0688 1100 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:39:14.0689 1100 msisadrv - ok
17:39:14.0704 1100 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:39:14.0708 1100 MSiSCSI - ok
17:39:14.0711 1100 msiserver - ok
17:39:14.0730 1100 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:39:14.0731 1100 MSKSSRV - ok
17:39:14.0738 1100 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:39:14.0739 1100 MSPCLOCK - ok
17:39:14.0746 1100 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:39:14.0747 1100 MSPQM - ok
17:39:14.0759 1100 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:39:14.0761 1100 MsRPC - ok
17:39:14.0776 1100 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:39:14.0777 1100 mssmbios - ok
17:39:14.0790 1100 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:39:14.0791 1100 MSTEE - ok
17:39:14.0810 1100 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:39:14.0811 1100 MTConfig - ok
17:39:14.0833 1100 [ CBE71C122434805CB73FFB6619F60598 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
17:39:14.0834 1100 MTsensor - ok
17:39:14.0838 1100 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:39:14.0839 1100 Mup - ok
17:39:14.0859 1100 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:39:14.0866 1100 napagent - ok
17:39:14.0885 1100 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:39:14.0888 1100 NativeWifiP - ok
17:39:14.0912 1100 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:39:14.0919 1100 NDIS - ok
17:39:14.0926 1100 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:39:14.0927 1100 NdisCap - ok
17:39:14.0947 1100 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:39:14.0948 1100 NdisTapi - ok
17:39:14.0969 1100 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:39:14.0971 1100 Ndisuio - ok
17:39:14.0984 1100 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:39:14.0986 1100 NdisWan - ok
17:39:14.0999 1100 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:39:15.0001 1100 NDProxy - ok
17:39:15.0005 1100 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:39:15.0006 1100 NetBIOS - ok
17:39:15.0028 1100 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:39:15.0030 1100 NetBT - ok
17:39:15.0040 1100 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
17:39:15.0043 1100 Netlogon - ok
17:39:15.0059 1100 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:39:15.0065 1100 Netman - ok
17:39:15.0085 1100 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:39:15.0092 1100 netprofm - ok
17:39:15.0119 1100 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:39:15.0121 1100 NetTcpPortSharing - ok
17:39:15.0140 1100 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:39:15.0141 1100 nfrd960 - ok
17:39:15.0165 1100 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:39:15.0170 1100 NlaSvc - ok
17:39:15.0181 1100 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:39:15.0183 1100 Npfs - ok
17:39:15.0187 1100 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:39:15.0191 1100 nsi - ok
17:39:15.0194 1100 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:39:15.0195 1100 nsiproxy - ok
17:39:15.0233 1100 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:39:15.0244 1100 Ntfs - ok
17:39:15.0248 1100 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:39:15.0249 1100 Null - ok
17:39:15.0271 1100 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:39:15.0273 1100 nvraid - ok
17:39:15.0282 1100 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:39:15.0285 1100 nvstor - ok
17:39:15.0299 1100 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:39:15.0301 1100 nv_agp - ok
17:39:15.0321 1100 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:39:15.0323 1100 ohci1394 - ok
17:39:15.0347 1100 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:39:15.0353 1100 p2pimsvc - ok
17:39:15.0384 1100 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:39:15.0399 1100 p2psvc - ok
17:39:15.0449 1100 [ 01907300EB52206B06FACB9608F369A9 ] PanService C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
17:39:15.0459 1100 PanService - ok
17:39:15.0477 1100 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:39:15.0487 1100 Parport - ok
17:39:15.0501 1100 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:39:15.0503 1100 partmgr - ok
17:39:15.0515 1100 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:39:15.0516 1100 Parvdm - ok
17:39:15.0532 1100 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:39:15.0538 1100 PcaSvc - ok
17:39:15.0542 1100 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:39:15.0544 1100 pci - ok
17:39:15.0555 1100 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:39:15.0556 1100 pciide - ok
17:39:15.0566 1100 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:39:15.0568 1100 pcmcia - ok
17:39:15.0576 1100 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:39:15.0577 1100 pcw - ok
17:39:15.0595 1100 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:39:15.0601 1100 PEAUTH - ok
17:39:15.0641 1100 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:39:15.0654 1100 PeerDistSvc - ok
17:39:15.0739 1100 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:39:15.0771 1100 pla - ok
17:39:15.0805 1100 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:39:15.0811 1100 PlugPlay - ok
17:39:15.0846 1100 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:39:15.0849 1100 PnkBstrA - ok
17:39:15.0856 1100 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:39:15.0860 1100 PNRPAutoReg - ok
17:39:15.0864 1100 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:39:15.0868 1100 PNRPsvc - ok
17:39:15.0878 1100 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:39:15.0882 1100 PolicyAgent - ok
17:39:15.0901 1100 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:39:15.0905 1100 Power - ok
17:39:15.0907 1100 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:39:15.0909 1100 PptpMiniport - ok
17:39:15.0911 1100 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:39:15.0912 1100 Processor - ok
17:39:15.0935 1100 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:39:15.0939 1100 ProfSvc - ok
17:39:15.0948 1100 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:39:15.0950 1100 ProtectedStorage - ok
17:39:15.0969 1100 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:39:15.0970 1100 Psched - ok
17:39:15.0995 1100 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:39:16.0006 1100 ql2300 - ok
17:39:16.0009 1100 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:39:16.0011 1100 ql40xx - ok
17:39:16.0023 1100 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:39:16.0028 1100 QWAVE - ok
17:39:16.0030 1100 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:39:16.0031 1100 QWAVEdrv - ok
17:39:16.0034 1100 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:39:16.0035 1100 RasAcd - ok
17:39:16.0050 1100 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:39:16.0051 1100 RasAgileVpn - ok
17:39:16.0062 1100 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:39:16.0066 1100 RasAuto - ok
17:39:16.0079 1100 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:39:16.0080 1100 Rasl2tp - ok
17:39:16.0113 1100 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:39:16.0133 1100 RasMan - ok
17:39:16.0142 1100 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:39:16.0143 1100 RasPppoe - ok
17:39:16.0162 1100 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:39:16.0164 1100 RasSstp - ok
17:39:16.0175 1100 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:39:16.0178 1100 rdbss - ok
17:39:16.0188 1100 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:39:16.0190 1100 rdpbus - ok
17:39:16.0203 1100 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:39:16.0204 1100 RDPCDD - ok
17:39:16.0219 1100 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:39:16.0221 1100 RDPDR - ok
17:39:16.0232 1100 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:39:16.0233 1100 RDPENCDD - ok
17:39:16.0247 1100 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:39:16.0248 1100 RDPREFMP - ok
17:39:16.0297 1100 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:39:16.0315 1100 RdpVideoMiniport - ok
17:39:16.0345 1100 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:39:16.0348 1100 RDPWD - ok
17:39:16.0378 1100 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:39:16.0382 1100 rdyboost - ok
17:39:16.0411 1100 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:39:16.0423 1100 RemoteAccess - ok
17:39:16.0439 1100 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:39:16.0444 1100 RemoteRegistry - ok
17:39:16.0448 1100 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:39:16.0453 1100 RpcEptMapper - ok
17:39:16.0476 1100 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:39:16.0479 1100 RpcLocator - ok
17:39:16.0492 1100 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:39:16.0499 1100 RpcSs - ok
17:39:16.0518 1100 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:39:16.0519 1100 rspndr - ok
17:39:16.0547 1100 [ 0516998076AD894AE7E362C3110AA071 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
17:39:16.0550 1100 RTL8167 - ok
17:39:16.0571 1100 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:39:16.0573 1100 s3cap - ok
17:39:16.0576 1100 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
17:39:16.0579 1100 SamSs - ok
17:39:16.0594 1100 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:39:16.0596 1100 sbp2port - ok
17:39:16.0611 1100 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:39:16.0617 1100 SCardSvr - ok
17:39:16.0624 1100 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:39:16.0626 1100 scfilter - ok
17:39:16.0655 1100 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:39:16.0666 1100 Schedule - ok
17:39:16.0673 1100 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:39:16.0675 1100 SCPolicySvc - ok
17:39:16.0685 1100 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:39:16.0691 1100 SDRSVC - ok
17:39:16.0708 1100 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:39:16.0709 1100 secdrv - ok
17:39:16.0721 1100 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:39:16.0726 1100 seclogon - ok
17:39:16.0741 1100 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:39:16.0746 1100 SENS - ok
17:39:16.0758 1100 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:39:16.0763 1100 SensrSvc - ok
17:39:16.0772 1100 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:39:16.0773 1100 Serenum - ok
17:39:16.0777 1100 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:39:16.0778 1100 Serial - ok
17:39:16.0793 1100 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:39:16.0795 1100 sermouse - ok
17:39:16.0820 1100 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:39:16.0828 1100 SessionEnv - ok
17:39:16.0845 1100 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:39:16.0847 1100 sffdisk - ok
17:39:16.0856 1100 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:39:16.0857 1100 sffp_mmc - ok
17:39:16.0864 1100 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:39:16.0866 1100 sffp_sd - ok
17:39:16.0873 1100 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:39:16.0874 1100 sfloppy - ok
17:39:16.0897 1100 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:39:16.0902 1100 SharedAccess - ok
17:39:16.0919 1100 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:39:16.0926 1100 ShellHWDetection - ok
17:39:16.0945 1100 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:39:16.0947 1100 sisagp - ok
17:39:16.0958 1100 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:39:16.0959 1100 SiSRaid2 - ok
17:39:16.0970 1100 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:39:16.0972 1100 SiSRaid4 - ok
17:39:16.0990 1100 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:39:16.0992 1100 Smb - ok
17:39:17.0010 1100 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:39:17.0015 1100 SNMPTRAP - ok
17:39:17.0028 1100 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:39:17.0029 1100 spldr - ok
17:39:17.0052 1100 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:39:17.0059 1100 Spooler - ok
17:39:17.0129 1100 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:39:17.0184 1100 sppsvc - ok
17:39:17.0195 1100 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:39:17.0201 1100 sppuinotify - ok
17:39:17.0221 1100 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:39:17.0223 1100 srv - ok
17:39:17.0247 1100 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:39:17.0250 1100 srv2 - ok
17:39:17.0266 1100 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:39:17.0268 1100 srvnet - ok
17:39:17.0279 1100 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:39:17.0286 1100 SSDPSRV - ok
17:39:17.0295 1100 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:39:17.0300 1100 SstpSvc - ok
17:39:17.0311 1100 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:39:17.0312 1100 stexstor - ok
17:39:17.0329 1100 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:39:17.0336 1100 StiSvc - ok
17:39:17.0343 1100 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:39:17.0344 1100 storflt - ok
17:39:17.0358 1100 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:39:17.0359 1100 storvsc - ok
17:39:17.0362 1100 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:39:17.0363 1100 swenum - ok
17:39:17.0373 1100 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:39:17.0379 1100 swprv - ok
17:39:17.0381 1100 Synth3dVsc - ok
17:39:17.0409 1100 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:39:17.0422 1100 SysMain - ok
17:39:17.0438 1100 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:39:17.0442 1100 TabletInputService - ok
17:39:17.0462 1100 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:39:17.0467 1100 TapiSrv - ok
17:39:17.0479 1100 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:39:17.0483 1100 TBS - ok
17:39:17.0529 1100 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:39:17.0549 1100 Tcpip - ok
17:39:17.0571 1100 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:39:17.0578 1100 TCPIP6 - ok
17:39:17.0604 1100 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:39:17.0605 1100 tcpipreg - ok
17:39:17.0617 1100 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:39:17.0619 1100 TDPIPE - ok
17:39:17.0634 1100 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:39:17.0635 1100 TDTCP - ok
17:39:17.0652 1100 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:39:17.0654 1100 tdx - ok
17:39:17.0668 1100 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:39:17.0670 1100 TermDD - ok
17:39:17.0694 1100 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:39:17.0703 1100 TermService - ok
17:39:17.0716 1100 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:39:17.0722 1100 Themes - ok
17:39:17.0732 1100 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:39:17.0736 1100 THREADORDER - ok
17:39:17.0749 1100 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:39:17.0755 1100 TrkWks - ok
17:39:17.0784 1100 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:39:17.0786 1100 TrustedInstaller - ok
17:39:17.0807 1100 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:39:17.0809 1100 tssecsrv - ok
17:39:17.0820 1100 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:39:17.0822 1100 TsUsbFlt - ok
17:39:17.0825 1100 tsusbhub - ok
17:39:17.0853 1100 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:39:17.0856 1100 tunnel - ok
17:39:17.0869 1100 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:39:17.0870 1100 uagp35 - ok
17:39:17.0884 1100 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:39:17.0887 1100 udfs - ok
17:39:17.0898 1100 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:39:17.0904 1100 UI0Detect - ok
17:39:17.0915 1100 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:39:17.0917 1100 uliagpkx - ok
17:39:17.0936 1100 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:39:17.0938 1100 umbus - ok
17:39:17.0951 1100 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:39:17.0952 1100 UmPass - ok
17:39:17.0981 1100 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:39:17.0988 1100 UmRdpService - ok
17:39:18.0001 1100 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:39:18.0009 1100 upnphost - ok
17:39:18.0023 1100 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:39:18.0025 1100 usbccgp - ok
17:39:18.0040 1100 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:39:18.0042 1100 usbcir - ok
17:39:18.0045 1100 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:39:18.0047 1100 usbehci - ok
17:39:18.0071 1100 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:39:18.0075 1100 usbhub - ok
17:39:18.0083 1100 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:39:18.0084 1100 usbohci - ok
17:39:18.0104 1100 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:39:18.0106 1100 usbprint - ok
17:39:18.0114 1100 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
17:39:18.0116 1100 USBSTOR - ok
17:39:18.0124 1100 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:39:18.0126 1100 usbuhci - ok
17:39:18.0133 1100 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:39:18.0138 1100 UxSms - ok
17:39:18.0148 1100 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
17:39:18.0151 1100 VaultSvc - ok
17:39:18.0164 1100 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:39:18.0165 1100 vdrvroot - ok
17:39:18.0185 1100 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:39:18.0194 1100 vds - ok
17:39:18.0198 1100 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:39:18.0199 1100 vga - ok
17:39:18.0214 1100 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:39:18.0215 1100 VgaSave - ok
17:39:18.0230 1100 VGPU - ok
17:39:18.0255 1100 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:39:18.0257 1100 vhdmp - ok
17:39:18.0265 1100 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:39:18.0267 1100 viaagp - ok
17:39:18.0278 1100 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:39:18.0280 1100 ViaC7 - ok
17:39:18.0292 1100 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:39:18.0293 1100 viaide - ok
17:39:18.0307 1100 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:39:18.0310 1100 vmbus - ok
17:39:18.0321 1100 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:39:18.0322 1100 VMBusHID - ok
17:39:18.0332 1100 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:39:18.0333 1100 volmgr - ok
17:39:18.0344 1100 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:39:18.0346 1100 volmgrx - ok
17:39:18.0358 1100 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:39:18.0360 1100 volsnap - ok
17:39:18.0383 1100 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:39:18.0385 1100 vsmraid - ok
17:39:18.0415 1100 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:39:18.0426 1100 VSS - ok
17:39:18.0487 1100 [ 40DBA03782BCC10685A8C200C5EBDCD0 ] vToolbarUpdater12.2.6 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
17:39:18.0499 1100 vToolbarUpdater12.2.6 - ok
17:39:18.0507 1100 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:39:18.0513 1100 vwifibus - ok
17:39:18.0529 1100 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:39:18.0537 1100 W32Time - ok
17:39:18.0548 1100 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:39:18.0550 1100 WacomPen - ok
17:39:18.0570 1100 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:39:18.0572 1100 WANARP - ok
17:39:18.0575 1100 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:39:18.0576 1100 Wanarpv6 - ok
17:39:18.0618 1100 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:39:18.0631 1100 WatAdminSvc - ok
17:39:18.0660 1100 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:39:18.0688 1100 wbengine - ok
17:39:18.0705 1100 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:39:18.0712 1100 WbioSrvc - ok
17:39:18.0732 1100 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:39:18.0739 1100 wcncsvc - ok
17:39:18.0747 1100 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:39:18.0753 1100 WcsPlugInService - ok
17:39:18.0763 1100 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:39:18.0764 1100 Wd - ok
17:39:18.0782 1100 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:39:18.0787 1100 Wdf01000 - ok
17:39:18.0791 1100 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:39:18.0797 1100 WdiServiceHost - ok
17:39:18.0800 1100 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:39:18.0805 1100 WdiSystemHost - ok
17:39:18.0827 1100 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:39:18.0832 1100 WebClient - ok
17:39:18.0844 1100 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:39:18.0848 1100 Wecsvc - ok
17:39:18.0859 1100 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:39:18.0863 1100 wercplsupport - ok
17:39:18.0881 1100 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:39:18.0885 1100 WerSvc - ok
17:39:18.0908 1100 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:39:18.0909 1100 WfpLwf - ok
17:39:18.0922 1100 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:39:18.0924 1100 WIMMount - ok
17:39:18.0971 1100 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:39:18.0974 1100 WinDefend - ok
17:39:18.0977 1100 WinHttpAutoProxySvc - ok
17:39:19.0002 1100 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:39:19.0004 1100 Winmgmt - ok
17:39:19.0115 1100 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:39:19.0141 1100 WinRM - ok
17:39:19.0168 1100 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:39:19.0181 1100 Wlansvc - ok
17:39:19.0190 1100 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:39:19.0191 1100 WmiAcpi - ok
17:39:19.0212 1100 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:39:19.0214 1100 wmiApSrv - ok
17:39:19.0260 1100 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:39:19.0284 1100 WMPNetworkSvc - ok
17:39:19.0297 1100 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:39:19.0303 1100 WPCSvc - ok
17:39:19.0318 1100 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:39:19.0324 1100 WPDBusEnum - ok
17:39:19.0336 1100 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:39:19.0338 1100 ws2ifsl - ok
17:39:19.0350 1100 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:39:19.0356 1100 wscsvc - ok
17:39:19.0359 1100 WSearch - ok
17:39:19.0418 1100 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:39:19.0481 1100 wuauserv - ok
17:39:19.0500 1100 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:39:19.0502 1100 WudfPf - ok
17:39:19.0534 1100 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:39:19.0536 1100 WUDFRd - ok
17:39:19.0549 1100 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:39:19.0555 1100 wudfsvc - ok
17:39:19.0572 1100 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:39:19.0580 1100 WwanSvc - ok
17:39:19.0595 1100 ================ Scan global ===============================
17:39:19.0603 1100 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:39:19.0613 1100 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:39:19.0623 1100 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:39:19.0652 1100 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:39:19.0680 1100 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:39:19.0686 1100 [Global] - ok
17:39:19.0687 1100 ================ Scan MBR ==================================
17:39:19.0704 1100 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:39:21.0729 1100 \Device\Harddisk0\DR0 - ok
17:39:21.0729 1100 ================ Scan VBR ==================================
17:39:21.0761 1100 [ F99435C918F388B0C2B7F51CCC558C2D ] \Device\Harddisk0\DR0\Partition1
17:39:21.0794 1100 \Device\Harddisk0\DR0\Partition1 - ok
17:39:21.0817 1100 [ F9724B95D36CFAD6F55744DF78122B12 ] \Device\Harddisk0\DR0\Partition2
17:39:21.0867 1100 \Device\Harddisk0\DR0\Partition2 - ok
17:39:21.0868 1100 ============================================================
17:39:21.0868 1100 Scan finished
17:39:21.0868 1100 ============================================================
17:39:21.0892 0824 Detected object count: 0
17:39:21.0892 0824 Actual detected object count: 0
17:40:42.0065 2464 Deinitialize success
17:38:44.0232 3244 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
17:38:44.0777 3244 ============================================================
17:38:44.0777 3244 Current date / time: 2012/09/18 17:38:44.0777
17:38:44.0777 3244 SystemInfo:
17:38:44.0777 3244
17:38:44.0777 3244 OS Version: 6.1.7601 ServicePack: 1.0
17:38:44.0777 3244 Product type: Workstation
17:38:44.0777 3244 ComputerName: KAREL-PC
17:38:44.0778 3244 UserName: Karel
17:38:44.0778 3244 Windows directory: C:\Windows
17:38:44.0778 3244 System windows directory: C:\Windows
17:38:44.0778 3244 Processor architecture: Intel x86
17:38:44.0778 3244 Number of processors: 3
17:38:44.0778 3244 Page size: 0x1000
17:38:44.0778 3244 Boot type: Normal boot
17:38:44.0778 3244 ============================================================
17:38:47.0563 3244 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:38:47.0585 3244 ============================================================
17:38:47.0585 3244 \Device\Harddisk0\DR0:
17:38:47.0587 3244 MBR partitions:
17:38:47.0587 3244 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:38:47.0587 3244 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
17:38:47.0588 3244 ============================================================
17:38:47.0621 3244 C: <-> \Device\Harddisk0\DR0\Partition2
17:38:47.0621 3244 ============================================================
17:38:47.0622 3244 Initialize success
17:38:47.0622 3244 ============================================================
17:39:09.0715 1100 ============================================================
17:39:09.0715 1100 Scan started
17:39:09.0715 1100 Mode: Manual;
17:39:09.0715 1100 ============================================================
17:39:10.0518 1100 ================ Scan system memory ========================
17:39:10.0518 1100 System memory - ok
17:39:10.0519 1100 ================ Scan services =============================
17:39:10.0634 1100 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:39:10.0636 1100 1394ohci - ok
17:39:10.0705 1100 [ 008BD0D672383068E8981D44199E9354 ] 4game C:\Program Files\4game\4game\4GameService.exe
17:39:10.0728 1100 4game - ok
17:39:10.0759 1100 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:39:10.0765 1100 ACPI - ok
17:39:10.0789 1100 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:39:10.0792 1100 AcpiPmi - ok
17:39:10.0840 1100 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:39:10.0842 1100 AdobeARMservice - ok
17:39:10.0869 1100 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:39:10.0878 1100 adp94xx - ok
17:39:10.0904 1100 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:39:10.0911 1100 adpahci - ok
17:39:10.0916 1100 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:39:10.0918 1100 adpu320 - ok
17:39:10.0937 1100 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:39:10.0938 1100 AeLookupSvc - ok
17:39:10.0958 1100 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
17:39:10.0962 1100 AFD - ok
17:39:10.0981 1100 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:39:10.0982 1100 agp440 - ok
17:39:10.0998 1100 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:39:10.0999 1100 aic78xx - ok
17:39:11.0011 1100 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:39:11.0013 1100 ALG - ok
17:39:11.0043 1100 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:39:11.0044 1100 aliide - ok
17:39:11.0069 1100 [ 5320FF0FDEC41FAF9D5CB01318AEFD6A ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:39:11.0073 1100 AMD External Events Utility - ok
17:39:11.0098 1100 AMD FUEL Service - ok
17:39:11.0121 1100 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:39:11.0123 1100 amdagp - ok
17:39:11.0133 1100 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:39:11.0134 1100 amdide - ok
17:39:11.0154 1100 [ FF258424F0B2EF25EB98F04EE386E6E3 ] amdiox86 C:\Windows\system32\DRIVERS\amdiox86.sys
17:39:11.0155 1100 amdiox86 - ok
17:39:11.0159 1100 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:39:11.0160 1100 AmdK8 - ok
17:39:11.0280 1100 [ 335ACE2A8E97439733F0F6A1BBD818D5 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:39:11.0418 1100 amdkmdag - ok
17:39:11.0430 1100 [ 0B1B116D30F133DC918287FD8E212F1E ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
17:39:11.0432 1100 amdkmdap - ok
17:39:11.0457 1100 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:39:11.0457 1100 AmdPPM - ok
17:39:11.0481 1100 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:39:11.0482 1100 amdsata - ok
17:39:11.0491 1100 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:39:11.0493 1100 amdsbs - ok
17:39:11.0502 1100 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:39:11.0503 1100 amdxata - ok
17:39:11.0522 1100 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:39:11.0523 1100 AppID - ok
17:39:11.0543 1100 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:39:11.0544 1100 AppIDSvc - ok
17:39:11.0560 1100 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
17:39:11.0561 1100 Appinfo - ok
17:39:11.0578 1100 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:39:11.0580 1100 AppMgmt - ok
17:39:11.0584 1100 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:39:11.0585 1100 arc - ok
17:39:11.0588 1100 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:39:11.0589 1100 arcsas - ok
17:39:11.0603 1100 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
17:39:11.0603 1100 aswFsBlk - ok
17:39:11.0613 1100 [ F76E51561562AC4105DBBE53FC99BC10 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:39:11.0613 1100 aswMonFlt - ok
17:39:11.0633 1100 [ 924819669AFD0EDF5C067193D371FAB0 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
17:39:11.0634 1100 aswRdr - ok
17:39:11.0664 1100 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:39:11.0670 1100 aswSnx - ok
17:39:11.0682 1100 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:39:11.0685 1100 aswSP - ok
17:39:11.0693 1100 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:39:11.0694 1100 aswTdi - ok
17:39:11.0700 1100 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:39:11.0700 1100 AsyncMac - ok
17:39:11.0703 1100 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:39:11.0704 1100 atapi - ok
17:39:11.0733 1100 [ 45FE74599FBA4070E7C7DAC928896474 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:39:11.0734 1100 AtiHDAudioService - ok
17:39:11.0756 1100 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:39:11.0759 1100 AudioEndpointBuilder - ok
17:39:11.0764 1100 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:39:11.0766 1100 Audiosrv - ok
17:39:11.0787 1100 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:39:11.0788 1100 avast! Antivirus - ok
17:39:11.0810 1100 [ 3001E24F340D400BFF85935E5777FC5B ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
17:39:11.0811 1100 avgtp - ok
17:39:11.0840 1100 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:39:11.0845 1100 AxInstSV - ok
17:39:11.0871 1100 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:39:11.0876 1100 b06bdrv - ok
17:39:11.0893 1100 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:39:11.0896 1100 b57nd60x - ok
17:39:11.0910 1100 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:39:11.0912 1100 BDESVC - ok
17:39:11.0922 1100 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:39:11.0923 1100 Beep - ok
17:39:11.0949 1100 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:39:11.0955 1100 BFE - ok
17:39:11.0979 1100 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:39:11.0989 1100 BITS - ok
17:39:12.0001 1100 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:39:12.0002 1100 blbdrive - ok
17:39:12.0022 1100 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:39:12.0024 1100 bowser - ok
17:39:12.0027 1100 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:39:12.0028 1100 BrFiltLo - ok
17:39:12.0032 1100 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:39:12.0033 1100 BrFiltUp - ok
17:39:12.0062 1100 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:39:12.0063 1100 Browser - ok
17:39:12.0070 1100 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:39:12.0073 1100 Brserid - ok
17:39:12.0077 1100 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:39:12.0078 1100 BrSerWdm - ok
17:39:12.0087 1100 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:39:12.0088 1100 BrUsbMdm - ok
17:39:12.0091 1100 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:39:12.0092 1100 BrUsbSer - ok
17:39:12.0095 1100 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:39:12.0097 1100 BTHMODEM - ok
17:39:12.0103 1100 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:39:12.0105 1100 bthserv - ok
17:39:12.0117 1100 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:39:12.0118 1100 cdfs - ok
17:39:12.0135 1100 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
17:39:12.0137 1100 cdrom - ok
17:39:12.0148 1100 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:39:12.0149 1100 CertPropSvc - ok
17:39:12.0157 1100 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:39:12.0158 1100 circlass - ok
17:39:12.0169 1100 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:39:12.0171 1100 CLFS - ok
17:39:12.0221 1100 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:39:12.0225 1100 clr_optimization_v2.0.50727_32 - ok
17:39:12.0248 1100 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:39:12.0250 1100 clr_optimization_v4.0.30319_32 - ok
17:39:12.0258 1100 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:39:12.0259 1100 CmBatt - ok
17:39:12.0265 1100 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:39:12.0266 1100 cmdide - ok
17:39:12.0292 1100 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
17:39:12.0296 1100 CNG - ok
17:39:12.0300 1100 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:39:12.0301 1100 Compbatt - ok
17:39:12.0316 1100 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:39:12.0317 1100 CompositeBus - ok
17:39:12.0320 1100 COMSysApp - ok
17:39:12.0325 1100 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:39:12.0326 1100 crcdisk - ok
17:39:12.0359 1100 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:39:12.0361 1100 CryptSvc - ok
17:39:12.0384 1100 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:39:12.0388 1100 CSC - ok
17:39:12.0418 1100 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:39:12.0423 1100 CscService - ok
17:39:12.0442 1100 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:39:12.0450 1100 DcomLaunch - ok
17:39:12.0461 1100 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:39:12.0465 1100 defragsvc - ok
17:39:12.0479 1100 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:39:12.0481 1100 DfsC - ok
17:39:12.0500 1100 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:39:12.0506 1100 Dhcp - ok
17:39:12.0515 1100 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:39:12.0517 1100 discache - ok
17:39:12.0530 1100 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:39:12.0533 1100 Disk - ok
17:39:12.0560 1100 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:39:12.0564 1100 Dnscache - ok
17:39:12.0585 1100 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:39:12.0589 1100 dot3svc - ok
17:39:12.0612 1100 [ B5E479EB83707DD698F66953E922042C ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
17:39:12.0614 1100 Dot4 - ok
17:39:12.0635 1100 [ CAEFD09B6A6249C53A67D55A9A9FCABF ] Dot4Print C:\Windows\system32\drivers\Dot4Prt.sys
17:39:12.0636 1100 Dot4Print - ok
17:39:12.0649 1100 [ CF491FF38D62143203C065260567E2F7 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
17:39:12.0650 1100 dot4usb - ok
17:39:12.0667 1100 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:39:12.0670 1100 DPS - ok
17:39:12.0681 1100 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:39:12.0682 1100 drmkaud - ok
17:39:12.0707 1100 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:39:12.0714 1100 DXGKrnl - ok
17:39:12.0735 1100 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:39:12.0738 1100 EapHost - ok
17:39:12.0805 1100 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:39:12.0856 1100 ebdrv - ok
17:39:12.0873 1100 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
17:39:12.0875 1100 EFS - ok
17:39:12.0908 1100 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:39:12.0920 1100 ehRecvr - ok
17:39:12.0938 1100 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:39:12.0940 1100 ehSched - ok
17:39:12.0955 1100 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:39:12.0960 1100 elxstor - ok
17:39:12.0976 1100 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:39:12.0977 1100 ErrDev - ok
17:39:12.0999 1100 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:39:13.0003 1100 EventSystem - ok
17:39:13.0018 1100 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:39:13.0020 1100 exfat - ok
17:39:13.0035 1100 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:39:13.0038 1100 fastfat - ok
17:39:13.0063 1100 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:39:13.0068 1100 Fax - ok
17:39:13.0076 1100 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:39:13.0078 1100 fdc - ok
17:39:13.0088 1100 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:39:13.0091 1100 fdPHost - ok
17:39:13.0097 1100 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:39:13.0099 1100 FDResPub - ok
17:39:13.0110 1100 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:39:13.0111 1100 FileInfo - ok
17:39:13.0121 1100 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:39:13.0122 1100 Filetrace - ok
17:39:13.0126 1100 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:39:13.0127 1100 flpydisk - ok
17:39:13.0141 1100 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:39:13.0143 1100 FltMgr - ok
17:39:13.0185 1100 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
17:39:13.0202 1100 FontCache - ok
17:39:13.0240 1100 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:39:13.0241 1100 FontCache3.0.0.0 - ok
17:39:13.0255 1100 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:39:13.0256 1100 FsDepends - ok
17:39:13.0267 1100 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:39:13.0267 1100 Fs_Rec - ok
17:39:13.0278 1100 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:39:13.0280 1100 fvevol - ok
17:39:13.0290 1100 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:39:13.0291 1100 gagp30kx - ok
17:39:13.0314 1100 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:39:13.0322 1100 gpsvc - ok
17:39:13.0331 1100 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:39:13.0332 1100 hcw85cir - ok
17:39:13.0369 1100 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:39:13.0373 1100 HdAudAddService - ok
17:39:13.0393 1100 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:39:13.0396 1100 HDAudBus - ok
17:39:13.0414 1100 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:39:13.0415 1100 HidBatt - ok
17:39:13.0419 1100 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:39:13.0421 1100 HidBth - ok
17:39:13.0424 1100 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:39:13.0426 1100 HidIr - ok
17:39:13.0436 1100 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:39:13.0439 1100 hidserv - ok
17:39:13.0472 1100 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
17:39:13.0473 1100 HidUsb - ok
17:39:13.0493 1100 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:39:13.0496 1100 hkmsvc - ok
17:39:13.0514 1100 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:39:13.0518 1100 HomeGroupListener - ok
17:39:13.0548 1100 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:39:13.0553 1100 HomeGroupProvider - ok
17:39:13.0563 1100 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:39:13.0565 1100 HpSAMD - ok
17:39:13.0583 1100 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:39:13.0588 1100 HTTP - ok
17:39:13.0597 1100 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:39:13.0597 1100 hwpolicy - ok
17:39:13.0615 1100 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:39:13.0617 1100 i8042prt - ok
17:39:13.0630 1100 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:39:13.0634 1100 iaStorV - ok
17:39:13.0679 1100 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:39:13.0696 1100 idsvc - ok
17:39:13.0704 1100 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:39:13.0706 1100 iirsp - ok
17:39:13.0723 1100 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:39:13.0732 1100 IKEEXT - ok
17:39:13.0755 1100 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:39:13.0757 1100 intelide - ok
17:39:13.0767 1100 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:39:13.0768 1100 intelppm - ok
17:39:13.0803 1100 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:39:13.0809 1100 IPBusEnum - ok
17:39:13.0814 1100 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:39:13.0815 1100 IpFilterDriver - ok
17:39:13.0836 1100 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:39:13.0843 1100 iphlpsvc - ok
17:39:13.0851 1100 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:39:13.0853 1100 IPMIDRV - ok
17:39:13.0860 1100 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:39:13.0861 1100 IPNAT - ok
17:39:13.0874 1100 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:39:13.0875 1100 IRENUM - ok
17:39:13.0884 1100 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:39:13.0886 1100 isapnp - ok
17:39:13.0908 1100 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:39:13.0911 1100 iScsiPrt - ok
17:39:13.0914 1100 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
17:39:13.0915 1100 kbdclass - ok
17:39:13.0928 1100 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:39:13.0929 1100 kbdhid - ok
17:39:13.0940 1100 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
17:39:13.0942 1100 KeyIso - ok
17:39:13.0954 1100 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:39:13.0955 1100 KSecDD - ok
17:39:13.0966 1100 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:39:13.0967 1100 KSecPkg - ok
17:39:13.0987 1100 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:39:13.0992 1100 KtmRm - ok
17:39:13.0996 1100 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:39:14.0000 1100 LanmanServer - ok
17:39:14.0018 1100 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:39:14.0022 1100 LanmanWorkstation - ok
17:39:14.0042 1100 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:39:14.0043 1100 lltdio - ok
17:39:14.0055 1100 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:39:14.0059 1100 lltdsvc - ok
17:39:14.0065 1100 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:39:14.0068 1100 lmhosts - ok
17:39:14.0079 1100 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:39:14.0080 1100 LSI_FC - ok
17:39:14.0083 1100 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:39:14.0084 1100 LSI_SAS - ok
17:39:14.0087 1100 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:39:14.0088 1100 LSI_SAS2 - ok
17:39:14.0096 1100 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:39:14.0097 1100 LSI_SCSI - ok
17:39:14.0108 1100 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:39:14.0109 1100 luafv - ok
17:39:14.0128 1100 [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:39:14.0129 1100 MBAMProtector - ok
17:39:14.0196 1100 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:39:14.0203 1100 MBAMScheduler - ok
17:39:14.0225 1100 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:39:14.0230 1100 MBAMService - ok
17:39:14.0247 1100 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:39:14.0254 1100 Mcx2Svc - ok
17:39:14.0258 1100 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:39:14.0259 1100 megasas - ok
17:39:14.0264 1100 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:39:14.0267 1100 MegaSR - ok
17:39:14.0274 1100 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:39:14.0277 1100 MMCSS - ok
17:39:14.0279 1100 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:39:14.0280 1100 Modem - ok
17:39:14.0288 1100 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:39:14.0289 1100 monitor - ok
17:39:14.0299 1100 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
17:39:14.0301 1100 mouclass - ok
17:39:14.0309 1100 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:39:14.0310 1100 mouhid - ok
17:39:14.0330 1100 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:39:14.0331 1100 mountmgr - ok
17:39:14.0354 1100 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:39:14.0356 1100 MozillaMaintenance - ok
17:39:14.0370 1100 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:39:14.0375 1100 mpio - ok
17:39:14.0384 1100 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:39:14.0387 1100 mpsdrv - ok
17:39:14.0458 1100 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:39:14.0495 1100 MpsSvc - ok
17:39:14.0516 1100 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:39:14.0520 1100 MRxDAV - ok
17:39:14.0552 1100 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:39:14.0556 1100 mrxsmb - ok
17:39:14.0574 1100 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:39:14.0580 1100 mrxsmb10 - ok
17:39:14.0598 1100 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:39:14.0601 1100 mrxsmb20 - ok
17:39:14.0618 1100 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:39:14.0619 1100 msahci - ok
17:39:14.0629 1100 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:39:14.0631 1100 msdsm - ok
17:39:14.0644 1100 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:39:14.0649 1100 MSDTC - ok
17:39:14.0663 1100 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:39:14.0664 1100 Msfs - ok
17:39:14.0679 1100 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:39:14.0680 1100 mshidkmdf - ok
17:39:14.0688 1100 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:39:14.0689 1100 msisadrv - ok
17:39:14.0704 1100 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:39:14.0708 1100 MSiSCSI - ok
17:39:14.0711 1100 msiserver - ok
17:39:14.0730 1100 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:39:14.0731 1100 MSKSSRV - ok
17:39:14.0738 1100 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:39:14.0739 1100 MSPCLOCK - ok
17:39:14.0746 1100 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:39:14.0747 1100 MSPQM - ok
17:39:14.0759 1100 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:39:14.0761 1100 MsRPC - ok
17:39:14.0776 1100 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:39:14.0777 1100 mssmbios - ok
17:39:14.0790 1100 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:39:14.0791 1100 MSTEE - ok
17:39:14.0810 1100 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:39:14.0811 1100 MTConfig - ok
17:39:14.0833 1100 [ CBE71C122434805CB73FFB6619F60598 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
17:39:14.0834 1100 MTsensor - ok
17:39:14.0838 1100 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:39:14.0839 1100 Mup - ok
17:39:14.0859 1100 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:39:14.0866 1100 napagent - ok
17:39:14.0885 1100 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:39:14.0888 1100 NativeWifiP - ok
17:39:14.0912 1100 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:39:14.0919 1100 NDIS - ok
17:39:14.0926 1100 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:39:14.0927 1100 NdisCap - ok
17:39:14.0947 1100 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:39:14.0948 1100 NdisTapi - ok
17:39:14.0969 1100 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:39:14.0971 1100 Ndisuio - ok
17:39:14.0984 1100 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:39:14.0986 1100 NdisWan - ok
17:39:14.0999 1100 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:39:15.0001 1100 NDProxy - ok
17:39:15.0005 1100 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:39:15.0006 1100 NetBIOS - ok
17:39:15.0028 1100 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:39:15.0030 1100 NetBT - ok
17:39:15.0040 1100 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
17:39:15.0043 1100 Netlogon - ok
17:39:15.0059 1100 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:39:15.0065 1100 Netman - ok
17:39:15.0085 1100 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:39:15.0092 1100 netprofm - ok
17:39:15.0119 1100 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:39:15.0121 1100 NetTcpPortSharing - ok
17:39:15.0140 1100 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:39:15.0141 1100 nfrd960 - ok
17:39:15.0165 1100 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:39:15.0170 1100 NlaSvc - ok
17:39:15.0181 1100 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:39:15.0183 1100 Npfs - ok
17:39:15.0187 1100 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:39:15.0191 1100 nsi - ok
17:39:15.0194 1100 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:39:15.0195 1100 nsiproxy - ok
17:39:15.0233 1100 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:39:15.0244 1100 Ntfs - ok
17:39:15.0248 1100 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:39:15.0249 1100 Null - ok
17:39:15.0271 1100 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:39:15.0273 1100 nvraid - ok
17:39:15.0282 1100 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:39:15.0285 1100 nvstor - ok
17:39:15.0299 1100 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:39:15.0301 1100 nv_agp - ok
17:39:15.0321 1100 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:39:15.0323 1100 ohci1394 - ok
17:39:15.0347 1100 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:39:15.0353 1100 p2pimsvc - ok
17:39:15.0384 1100 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:39:15.0399 1100 p2psvc - ok
17:39:15.0449 1100 [ 01907300EB52206B06FACB9608F369A9 ] PanService C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
17:39:15.0459 1100 PanService - ok
17:39:15.0477 1100 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:39:15.0487 1100 Parport - ok
17:39:15.0501 1100 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:39:15.0503 1100 partmgr - ok
17:39:15.0515 1100 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:39:15.0516 1100 Parvdm - ok
17:39:15.0532 1100 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:39:15.0538 1100 PcaSvc - ok
17:39:15.0542 1100 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:39:15.0544 1100 pci - ok
17:39:15.0555 1100 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:39:15.0556 1100 pciide - ok
17:39:15.0566 1100 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:39:15.0568 1100 pcmcia - ok
17:39:15.0576 1100 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:39:15.0577 1100 pcw - ok
17:39:15.0595 1100 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:39:15.0601 1100 PEAUTH - ok
17:39:15.0641 1100 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:39:15.0654 1100 PeerDistSvc - ok
17:39:15.0739 1100 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:39:15.0771 1100 pla - ok
17:39:15.0805 1100 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:39:15.0811 1100 PlugPlay - ok
17:39:15.0846 1100 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:39:15.0849 1100 PnkBstrA - ok
17:39:15.0856 1100 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:39:15.0860 1100 PNRPAutoReg - ok
17:39:15.0864 1100 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:39:15.0868 1100 PNRPsvc - ok
17:39:15.0878 1100 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:39:15.0882 1100 PolicyAgent - ok
17:39:15.0901 1100 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:39:15.0905 1100 Power - ok
17:39:15.0907 1100 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:39:15.0909 1100 PptpMiniport - ok
17:39:15.0911 1100 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:39:15.0912 1100 Processor - ok
17:39:15.0935 1100 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:39:15.0939 1100 ProfSvc - ok
17:39:15.0948 1100 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:39:15.0950 1100 ProtectedStorage - ok
17:39:15.0969 1100 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:39:15.0970 1100 Psched - ok
17:39:15.0995 1100 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:39:16.0006 1100 ql2300 - ok
17:39:16.0009 1100 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:39:16.0011 1100 ql40xx - ok
17:39:16.0023 1100 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:39:16.0028 1100 QWAVE - ok
17:39:16.0030 1100 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:39:16.0031 1100 QWAVEdrv - ok
17:39:16.0034 1100 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:39:16.0035 1100 RasAcd - ok
17:39:16.0050 1100 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:39:16.0051 1100 RasAgileVpn - ok
17:39:16.0062 1100 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:39:16.0066 1100 RasAuto - ok
17:39:16.0079 1100 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:39:16.0080 1100 Rasl2tp - ok
17:39:16.0113 1100 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:39:16.0133 1100 RasMan - ok
17:39:16.0142 1100 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:39:16.0143 1100 RasPppoe - ok
17:39:16.0162 1100 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:39:16.0164 1100 RasSstp - ok
17:39:16.0175 1100 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:39:16.0178 1100 rdbss - ok
17:39:16.0188 1100 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:39:16.0190 1100 rdpbus - ok
17:39:16.0203 1100 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:39:16.0204 1100 RDPCDD - ok
17:39:16.0219 1100 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:39:16.0221 1100 RDPDR - ok
17:39:16.0232 1100 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:39:16.0233 1100 RDPENCDD - ok
17:39:16.0247 1100 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:39:16.0248 1100 RDPREFMP - ok
17:39:16.0297 1100 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:39:16.0315 1100 RdpVideoMiniport - ok
17:39:16.0345 1100 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:39:16.0348 1100 RDPWD - ok
17:39:16.0378 1100 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:39:16.0382 1100 rdyboost - ok
17:39:16.0411 1100 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:39:16.0423 1100 RemoteAccess - ok
17:39:16.0439 1100 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:39:16.0444 1100 RemoteRegistry - ok
17:39:16.0448 1100 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:39:16.0453 1100 RpcEptMapper - ok
17:39:16.0476 1100 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:39:16.0479 1100 RpcLocator - ok
17:39:16.0492 1100 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:39:16.0499 1100 RpcSs - ok
17:39:16.0518 1100 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:39:16.0519 1100 rspndr - ok
17:39:16.0547 1100 [ 0516998076AD894AE7E362C3110AA071 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
17:39:16.0550 1100 RTL8167 - ok
17:39:16.0571 1100 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:39:16.0573 1100 s3cap - ok
17:39:16.0576 1100 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
17:39:16.0579 1100 SamSs - ok
17:39:16.0594 1100 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:39:16.0596 1100 sbp2port - ok
17:39:16.0611 1100 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:39:16.0617 1100 SCardSvr - ok
17:39:16.0624 1100 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:39:16.0626 1100 scfilter - ok
17:39:16.0655 1100 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:39:16.0666 1100 Schedule - ok
17:39:16.0673 1100 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:39:16.0675 1100 SCPolicySvc - ok
17:39:16.0685 1100 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:39:16.0691 1100 SDRSVC - ok
17:39:16.0708 1100 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:39:16.0709 1100 secdrv - ok
17:39:16.0721 1100 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:39:16.0726 1100 seclogon - ok
17:39:16.0741 1100 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:39:16.0746 1100 SENS - ok
17:39:16.0758 1100 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:39:16.0763 1100 SensrSvc - ok
17:39:16.0772 1100 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:39:16.0773 1100 Serenum - ok
17:39:16.0777 1100 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:39:16.0778 1100 Serial - ok
17:39:16.0793 1100 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:39:16.0795 1100 sermouse - ok
17:39:16.0820 1100 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:39:16.0828 1100 SessionEnv - ok
17:39:16.0845 1100 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:39:16.0847 1100 sffdisk - ok
17:39:16.0856 1100 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:39:16.0857 1100 sffp_mmc - ok
17:39:16.0864 1100 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:39:16.0866 1100 sffp_sd - ok
17:39:16.0873 1100 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:39:16.0874 1100 sfloppy - ok
17:39:16.0897 1100 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:39:16.0902 1100 SharedAccess - ok
17:39:16.0919 1100 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:39:16.0926 1100 ShellHWDetection - ok
17:39:16.0945 1100 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:39:16.0947 1100 sisagp - ok
17:39:16.0958 1100 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:39:16.0959 1100 SiSRaid2 - ok
17:39:16.0970 1100 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:39:16.0972 1100 SiSRaid4 - ok
17:39:16.0990 1100 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:39:16.0992 1100 Smb - ok
17:39:17.0010 1100 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:39:17.0015 1100 SNMPTRAP - ok
17:39:17.0028 1100 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:39:17.0029 1100 spldr - ok
17:39:17.0052 1100 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:39:17.0059 1100 Spooler - ok
17:39:17.0129 1100 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:39:17.0184 1100 sppsvc - ok
17:39:17.0195 1100 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:39:17.0201 1100 sppuinotify - ok
17:39:17.0221 1100 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:39:17.0223 1100 srv - ok
17:39:17.0247 1100 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:39:17.0250 1100 srv2 - ok
17:39:17.0266 1100 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:39:17.0268 1100 srvnet - ok
17:39:17.0279 1100 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:39:17.0286 1100 SSDPSRV - ok
17:39:17.0295 1100 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:39:17.0300 1100 SstpSvc - ok
17:39:17.0311 1100 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:39:17.0312 1100 stexstor - ok
17:39:17.0329 1100 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:39:17.0336 1100 StiSvc - ok
17:39:17.0343 1100 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:39:17.0344 1100 storflt - ok
17:39:17.0358 1100 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:39:17.0359 1100 storvsc - ok
17:39:17.0362 1100 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:39:17.0363 1100 swenum - ok
17:39:17.0373 1100 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:39:17.0379 1100 swprv - ok
17:39:17.0381 1100 Synth3dVsc - ok
17:39:17.0409 1100 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:39:17.0422 1100 SysMain - ok
17:39:17.0438 1100 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:39:17.0442 1100 TabletInputService - ok
17:39:17.0462 1100 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:39:17.0467 1100 TapiSrv - ok
17:39:17.0479 1100 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:39:17.0483 1100 TBS - ok
17:39:17.0529 1100 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:39:17.0549 1100 Tcpip - ok
17:39:17.0571 1100 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:39:17.0578 1100 TCPIP6 - ok
17:39:17.0604 1100 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:39:17.0605 1100 tcpipreg - ok
17:39:17.0617 1100 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:39:17.0619 1100 TDPIPE - ok
17:39:17.0634 1100 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:39:17.0635 1100 TDTCP - ok
17:39:17.0652 1100 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:39:17.0654 1100 tdx - ok
17:39:17.0668 1100 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:39:17.0670 1100 TermDD - ok
17:39:17.0694 1100 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:39:17.0703 1100 TermService - ok
17:39:17.0716 1100 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:39:17.0722 1100 Themes - ok
17:39:17.0732 1100 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:39:17.0736 1100 THREADORDER - ok
17:39:17.0749 1100 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:39:17.0755 1100 TrkWks - ok
17:39:17.0784 1100 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:39:17.0786 1100 TrustedInstaller - ok
17:39:17.0807 1100 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:39:17.0809 1100 tssecsrv - ok
17:39:17.0820 1100 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:39:17.0822 1100 TsUsbFlt - ok
17:39:17.0825 1100 tsusbhub - ok
17:39:17.0853 1100 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:39:17.0856 1100 tunnel - ok
17:39:17.0869 1100 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:39:17.0870 1100 uagp35 - ok
17:39:17.0884 1100 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:39:17.0887 1100 udfs - ok
17:39:17.0898 1100 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:39:17.0904 1100 UI0Detect - ok
17:39:17.0915 1100 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:39:17.0917 1100 uliagpkx - ok
17:39:17.0936 1100 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:39:17.0938 1100 umbus - ok
17:39:17.0951 1100 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:39:17.0952 1100 UmPass - ok
17:39:17.0981 1100 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:39:17.0988 1100 UmRdpService - ok
17:39:18.0001 1100 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:39:18.0009 1100 upnphost - ok
17:39:18.0023 1100 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:39:18.0025 1100 usbccgp - ok
17:39:18.0040 1100 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:39:18.0042 1100 usbcir - ok
17:39:18.0045 1100 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:39:18.0047 1100 usbehci - ok
17:39:18.0071 1100 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:39:18.0075 1100 usbhub - ok
17:39:18.0083 1100 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:39:18.0084 1100 usbohci - ok
17:39:18.0104 1100 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:39:18.0106 1100 usbprint - ok
17:39:18.0114 1100 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
17:39:18.0116 1100 USBSTOR - ok
17:39:18.0124 1100 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:39:18.0126 1100 usbuhci - ok
17:39:18.0133 1100 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:39:18.0138 1100 UxSms - ok
17:39:18.0148 1100 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
17:39:18.0151 1100 VaultSvc - ok
17:39:18.0164 1100 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:39:18.0165 1100 vdrvroot - ok
17:39:18.0185 1100 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:39:18.0194 1100 vds - ok
17:39:18.0198 1100 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:39:18.0199 1100 vga - ok
17:39:18.0214 1100 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:39:18.0215 1100 VgaSave - ok
17:39:18.0230 1100 VGPU - ok
17:39:18.0255 1100 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:39:18.0257 1100 vhdmp - ok
17:39:18.0265 1100 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:39:18.0267 1100 viaagp - ok
17:39:18.0278 1100 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:39:18.0280 1100 ViaC7 - ok
17:39:18.0292 1100 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:39:18.0293 1100 viaide - ok
17:39:18.0307 1100 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:39:18.0310 1100 vmbus - ok
17:39:18.0321 1100 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:39:18.0322 1100 VMBusHID - ok
17:39:18.0332 1100 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:39:18.0333 1100 volmgr - ok
17:39:18.0344 1100 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:39:18.0346 1100 volmgrx - ok
17:39:18.0358 1100 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:39:18.0360 1100 volsnap - ok
17:39:18.0383 1100 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:39:18.0385 1100 vsmraid - ok
17:39:18.0415 1100 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:39:18.0426 1100 VSS - ok
17:39:18.0487 1100 [ 40DBA03782BCC10685A8C200C5EBDCD0 ] vToolbarUpdater12.2.6 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
17:39:18.0499 1100 vToolbarUpdater12.2.6 - ok
17:39:18.0507 1100 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:39:18.0513 1100 vwifibus - ok
17:39:18.0529 1100 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:39:18.0537 1100 W32Time - ok
17:39:18.0548 1100 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:39:18.0550 1100 WacomPen - ok
17:39:18.0570 1100 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:39:18.0572 1100 WANARP - ok
17:39:18.0575 1100 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:39:18.0576 1100 Wanarpv6 - ok
17:39:18.0618 1100 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:39:18.0631 1100 WatAdminSvc - ok
17:39:18.0660 1100 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:39:18.0688 1100 wbengine - ok
17:39:18.0705 1100 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:39:18.0712 1100 WbioSrvc - ok
17:39:18.0732 1100 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:39:18.0739 1100 wcncsvc - ok
17:39:18.0747 1100 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:39:18.0753 1100 WcsPlugInService - ok
17:39:18.0763 1100 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:39:18.0764 1100 Wd - ok
17:39:18.0782 1100 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:39:18.0787 1100 Wdf01000 - ok
17:39:18.0791 1100 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:39:18.0797 1100 WdiServiceHost - ok
17:39:18.0800 1100 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:39:18.0805 1100 WdiSystemHost - ok
17:39:18.0827 1100 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:39:18.0832 1100 WebClient - ok
17:39:18.0844 1100 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:39:18.0848 1100 Wecsvc - ok
17:39:18.0859 1100 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:39:18.0863 1100 wercplsupport - ok
17:39:18.0881 1100 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:39:18.0885 1100 WerSvc - ok
17:39:18.0908 1100 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:39:18.0909 1100 WfpLwf - ok
17:39:18.0922 1100 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:39:18.0924 1100 WIMMount - ok
17:39:18.0971 1100 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:39:18.0974 1100 WinDefend - ok
17:39:18.0977 1100 WinHttpAutoProxySvc - ok
17:39:19.0002 1100 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:39:19.0004 1100 Winmgmt - ok
17:39:19.0115 1100 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:39:19.0141 1100 WinRM - ok
17:39:19.0168 1100 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:39:19.0181 1100 Wlansvc - ok
17:39:19.0190 1100 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:39:19.0191 1100 WmiAcpi - ok
17:39:19.0212 1100 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:39:19.0214 1100 wmiApSrv - ok
17:39:19.0260 1100 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:39:19.0284 1100 WMPNetworkSvc - ok
17:39:19.0297 1100 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:39:19.0303 1100 WPCSvc - ok
17:39:19.0318 1100 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:39:19.0324 1100 WPDBusEnum - ok
17:39:19.0336 1100 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:39:19.0338 1100 ws2ifsl - ok
17:39:19.0350 1100 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:39:19.0356 1100 wscsvc - ok
17:39:19.0359 1100 WSearch - ok
17:39:19.0418 1100 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:39:19.0481 1100 wuauserv - ok
17:39:19.0500 1100 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:39:19.0502 1100 WudfPf - ok
17:39:19.0534 1100 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:39:19.0536 1100 WUDFRd - ok
17:39:19.0549 1100 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:39:19.0555 1100 wudfsvc - ok
17:39:19.0572 1100 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:39:19.0580 1100 WwanSvc - ok
17:39:19.0595 1100 ================ Scan global ===============================
17:39:19.0603 1100 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:39:19.0613 1100 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:39:19.0623 1100 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:39:19.0652 1100 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:39:19.0680 1100 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:39:19.0686 1100 [Global] - ok
17:39:19.0687 1100 ================ Scan MBR ==================================
17:39:19.0704 1100 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:39:21.0729 1100 \Device\Harddisk0\DR0 - ok
17:39:21.0729 1100 ================ Scan VBR ==================================
17:39:21.0761 1100 [ F99435C918F388B0C2B7F51CCC558C2D ] \Device\Harddisk0\DR0\Partition1
17:39:21.0794 1100 \Device\Harddisk0\DR0\Partition1 - ok
17:39:21.0817 1100 [ F9724B95D36CFAD6F55744DF78122B12 ] \Device\Harddisk0\DR0\Partition2
17:39:21.0867 1100 \Device\Harddisk0\DR0\Partition2 - ok
17:39:21.0868 1100 ============================================================
17:39:21.0868 1100 Scan finished
17:39:21.0868 1100 ============================================================
17:39:21.0892 0824 Detected object count: 0
17:39:21.0892 0824 Actual detected object count: 0
17:40:42.0065 2464 Deinitialize success
Re: Černej monitor
ComboFix 12-09-18.06 - Karel 18.09.2012 17:51:44.1.3 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3198.2226 [GMT 2:00]
Spuštěný z: c:\users\Karel\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: avast! antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-18 do 2012-09-18 )))))))))))))))))))))))))))))))
.
.
2012-09-18 15:55 . 2012-09-18 15:55 -------- d-----w- c:\users\Karel\AppData\Local\temp
2012-09-18 15:55 . 2012-09-18 15:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-18 08:00 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\mpengine.dll
2012-09-17 18:44 . 2012-09-17 18:44 -------- d-----w- c:\program files\CCleaner
2012-09-17 17:47 . 2012-09-17 17:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-17 17:47 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-17 13:42 . 2012-09-17 18:59 -------- d-----w- c:\program files\trend micro
2012-09-17 13:42 . 2012-09-17 13:42 -------- d-----w- C:\rsit
2012-09-15 21:50 . 2012-09-15 21:50 -------- d-----w- c:\users\Karel\AppData\Local\Adobe
2012-09-15 21:48 . 2012-09-15 21:48 -------- d-----w- c:\program files\Common Files\Adobe
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\users\Karel\AppData\Local\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\programdata\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\AVG Secure Search
2012-09-13 07:04 . 2012-09-16 13:56 -------- d-----w- c:\users\Karel\AppData\Roaming\.minecraft
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\users\Karel\AppData\Local\Giant Savings
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\Giant Savings
2012-09-13 07:04 . 2012-09-13 07:04 -------- d--h--w- c:\programdata\Common Files
2012-09-12 20:28 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 20:28 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 20:28 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 20:28 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 20:28 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 20:28 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Common Files\Java
2012-09-10 06:46 . 2012-09-10 06:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Java
2012-08-31 07:59 . 2012-08-31 07:59 -------- d-----w- c:\program files\PANDORA.TV
2012-08-31 07:58 . 2012-08-31 07:58 -------- d-----w- c:\programdata\Ask
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 06:48 . 2012-07-25 10:57 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-14 06:47 . 2012-07-25 10:56 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-14 06:47 . 2012-06-23 10:17 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 06:47 . 2012-07-25 10:56 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-14 06:04 . 2012-04-24 05:44 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-14 06:04 . 2012-01-21 18:26 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 06:46 . 2012-07-06 16:34 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2012-01-22 10:04 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-01-21 12:59 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-01-21 12:59 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-03-07 07:51 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2012-01-21 12:59 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-01-21 12:59 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2012-01-22 10:02 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-01-21 12:59 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-18 20:11 . 2012-08-18 20:11 614400 ----a-w- c:\windows\AutoKMS.exe
2012-07-25 10:59 . 2012-07-25 10:56 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-25 10:57 . 2012-05-28 14:07 138056 ----a-w- c:\users\Karel\AppData\Roaming\PnkBstrK.sys
2012-07-18 17:47 . 2012-08-15 08:28 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 08:28 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 08:28 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 11:08 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 11:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 11:08 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 11:08 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 11:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-08 21:59 . 2012-09-08 21:59 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-09-13 07:04 1734240 ----a-w- c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-09-13 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-08-08 1644744]
"4gameTray"="c:\program files\4game\4game\4GameTray.exe" [2012-03-05 813408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-07 336384]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-09-13 947808]
"ROC_ROC_NT"="c:\program files\AVG Secure Search\ROC_ROC_NT.exe" [2012-09-13 856160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S2 4game;4game;c:\program files\4game\4game\4GameService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 86581953
*Deregistered* - 86581953
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-18 c:\windows\Tasks\AutoKMS.job
- c:\windows\AutoKMS.exe [2012-08-18 20:11]
.
.
------- Doplňkový sken -------
.
uStart Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04&v=12.2.5.34&sap=hp
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/firefox?client=firefox-a& ... s:official
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7B83df2293-9537-4a8e-9d34-a2c6407d5f02%7D&mid=6dd65e9e337347d0bdb56de783c521e9-f79ae3bce933d16ce204fdfc9bd3c1f3e541cab3&ds=ft011&v=12.2.5.34&lang=en&pr=sa&d=2012-09-13%2009%3A04%3A37&sap=ku&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Nektra OEAPI - (no file)
HKCU-Run-OEXPRESS - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-18 17:56:55
ComboFix-quarantined-files.txt 2012-09-18 15:56
.
Před spuštěním: Volných bajtů: 874 107 772 928
Po spuštění: Volných bajtů: 874 006 003 712
.
- - End Of File - - F4530612D70F4A52BA7369BF586C74DE
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3198.2226 [GMT 2:00]
Spuštěný z: c:\users\Karel\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: avast! antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-18 do 2012-09-18 )))))))))))))))))))))))))))))))
.
.
2012-09-18 15:55 . 2012-09-18 15:55 -------- d-----w- c:\users\Karel\AppData\Local\temp
2012-09-18 15:55 . 2012-09-18 15:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-18 08:00 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\mpengine.dll
2012-09-17 18:44 . 2012-09-17 18:44 -------- d-----w- c:\program files\CCleaner
2012-09-17 17:47 . 2012-09-17 17:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-17 17:47 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-17 13:42 . 2012-09-17 18:59 -------- d-----w- c:\program files\trend micro
2012-09-17 13:42 . 2012-09-17 13:42 -------- d-----w- C:\rsit
2012-09-15 21:50 . 2012-09-15 21:50 -------- d-----w- c:\users\Karel\AppData\Local\Adobe
2012-09-15 21:48 . 2012-09-15 21:48 -------- d-----w- c:\program files\Common Files\Adobe
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\users\Karel\AppData\Local\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\programdata\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\AVG Secure Search
2012-09-13 07:04 . 2012-09-16 13:56 -------- d-----w- c:\users\Karel\AppData\Roaming\.minecraft
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\users\Karel\AppData\Local\Giant Savings
2012-09-13 07:04 . 2012-09-13 07:04 -------- d-----w- c:\program files\Giant Savings
2012-09-13 07:04 . 2012-09-13 07:04 -------- d--h--w- c:\programdata\Common Files
2012-09-12 20:28 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 20:28 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 20:28 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 20:28 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 20:28 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 20:28 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Common Files\Java
2012-09-10 06:46 . 2012-09-10 06:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Java
2012-08-31 07:59 . 2012-08-31 07:59 -------- d-----w- c:\program files\PANDORA.TV
2012-08-31 07:58 . 2012-08-31 07:58 -------- d-----w- c:\programdata\Ask
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 06:48 . 2012-07-25 10:57 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-14 06:47 . 2012-07-25 10:56 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-14 06:47 . 2012-06-23 10:17 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 06:47 . 2012-07-25 10:56 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-14 06:04 . 2012-04-24 05:44 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-14 06:04 . 2012-01-21 18:26 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 06:46 . 2012-07-06 16:34 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2012-01-22 10:04 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-01-21 12:59 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-01-21 12:59 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-03-07 07:51 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2012-01-21 12:59 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-01-21 12:59 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2012-01-22 10:02 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-01-21 12:59 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-18 20:11 . 2012-08-18 20:11 614400 ----a-w- c:\windows\AutoKMS.exe
2012-07-25 10:59 . 2012-07-25 10:56 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-25 10:57 . 2012-05-28 14:07 138056 ----a-w- c:\users\Karel\AppData\Roaming\PnkBstrK.sys
2012-07-18 17:47 . 2012-08-15 08:28 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 08:28 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 08:28 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 11:08 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 11:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 11:08 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 11:08 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 11:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-08 21:59 . 2012-09-08 21:59 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-09-13 07:04 1734240 ----a-w- c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-09-13 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-08-08 1644744]
"4gameTray"="c:\program files\4game\4game\4GameTray.exe" [2012-03-05 813408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-07 336384]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-09-13 947808]
"ROC_ROC_NT"="c:\program files\AVG Secure Search\ROC_ROC_NT.exe" [2012-09-13 856160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S2 4game;4game;c:\program files\4game\4game\4GameService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 86581953
*Deregistered* - 86581953
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-18 c:\windows\Tasks\AutoKMS.job
- c:\windows\AutoKMS.exe [2012-08-18 20:11]
.
.
------- Doplňkový sken -------
.
uStart Page = https://isearch.avg.com/?cid={2765D727- ... 2012-09-13 09:04&v=12.2.5.34&sap=hp
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/firefox?client=firefox-a& ... s:official
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7B83df2293-9537-4a8e-9d34-a2c6407d5f02%7D&mid=6dd65e9e337347d0bdb56de783c521e9-f79ae3bce933d16ce204fdfc9bd3c1f3e541cab3&ds=ft011&v=12.2.5.34&lang=en&pr=sa&d=2012-09-13%2009%3A04%3A37&sap=ku&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Nektra OEAPI - (no file)
HKCU-Run-OEXPRESS - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-18 17:56:55
ComboFix-quarantined-files.txt 2012-09-18 15:56
.
Před spuštěním: Volných bajtů: 874 107 772 928
Po spuštění: Volných bajtů: 874 006 003 712
.
- - End Of File - - F4530612D70F4A52BA7369BF586C74DE
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
Pri tejto akcii je nutné mať ComboFix na ploche.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log sem.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Kód: Vybrat vše
KILLALL::
Folder::
c:\users\Karel\AppData\Roaming\.minecraft
c:\users\Karel\AppData\Local\Giant Savings
c:\program files\Giant Savings
c:\programdata\Ask
c:\users\Karel\AppData\Local\AVG Secure Search
c:\programdata\AVG Secure Search
c:\program files\Common Files\AVG Secure Search
c:\program files\AVG Secure Search
c:\program files\Ask.com
File::
c:\windows\system32\drivers\avgtpx86.sys
c:\windows\AutoKMS.exe
c:\windows\Tasks\AutoKMS.job
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=-
[-HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[-HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[-HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ApnUpdater"=-
"4gameTray"=-
"SunJavaUpdateSched"=-
"vProt"=-
"ROC_ROC_NT"=-
"Adobe ARM"=-
Driver::
avgtp
vToolbarUpdater12.2.6
86581953
DDS::
uStart Page = https://isearch.avg.com/?cid={2765D727-97AC-46D1-9CEB-5570490A9815}&mid=6dd65e9e337347d0bdb56de783c521e9-f79ae3bce933d16ce204fdfc9bd3c1f3e541cab3&lang=en&ds=ft011&pr=sa&d=2012-09-13 09:04&v=12.2.5.34&sap=hp
FireFox::
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7B8 ... &sap=ku&q=
ClearJavaCache::
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log sem.
Re: Černej monitor
ComboFix 12-09-18.06 - Karel 18.09.2012 19:35:21.2.3 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3198.2212 [GMT 2:00]
Spuštěný z: c:\users\Karel\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Karel\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: avast! antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\AutoKMS.exe"
"c:\windows\system32\drivers\avgtpx86.sys"
"c:\windows\Tasks\AutoKMS.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\AVG Secure Search
c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
c:\program files\AVG Secure Search\about.gif
c:\program files\AVG Secure Search\active-threats18.gif
c:\program files\AVG Secure Search\avguidx.dll
c:\program files\AVG Secure Search\calc.gif
c:\program files\AVG Secure Search\CleanHistory.gif
c:\program files\AVG Secure Search\configuration.xml
c:\program files\AVG Secure Search\current.gif
c:\program files\AVG Secure Search\currently-safe18.gif
c:\program files\AVG Secure Search\Facebook.gif
c:\program files\AVG Secure Search\favicon.ico
c:\program files\AVG Secure Search\feedback.gif
c:\program files\AVG Secure Search\help.gif
c:\program files\AVG Secure Search\icon18.gif
c:\program files\AVG Secure Search\labs.gif
c:\program files\AVG Secure Search\Licenses\Encoding_decoding_base64.txt
c:\program files\AVG Secure Search\Licenses\hmac.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-bsdiff.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-bzip.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-JasonCpp.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-MPL-NPAPI.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-sparsehash.txt
c:\program files\AVG Secure Search\Licenses\PassthruApp.txt
c:\program files\AVG Secure Search\lip.exe
c:\program files\AVG Secure Search\note.gif
c:\program files\AVG Secure Search\PostInstall.exe
c:\program files\AVG Secure Search\PostInstaller.ini
c:\program files\AVG Secure Search\radio\bg.gif
c:\program files\AVG Secure Search\radio\play.gif
c:\program files\AVG Secure Search\radio\play_hover.gif
c:\program files\AVG Secure Search\radio\stop.gif
c:\program files\AVG Secure Search\radio\stop_hover.gif
c:\program files\AVG Secure Search\radio\v_minus.gif
c:\program files\AVG Secure Search\radio\v_minus_1.gif
c:\program files\AVG Secure Search\radio\v_plus.gif
c:\program files\AVG Secure Search\radio\v_plus_1.gif
c:\program files\AVG Secure Search\radio\vol_line_emp.gif
c:\program files\AVG Secure Search\radio\vol_line_full.gif
c:\program files\AVG Secure Search\radio\vol_line_half.gif
c:\program files\AVG Secure Search\remote_configuration.xml
c:\program files\AVG Secure Search\roc_nt.exe
c:\program files\AVG Secure Search\ROC_ROC_NT.exe
c:\program files\AVG Secure Search\search.gif
c:\program files\AVG Secure Search\SecuredSearch.gif
c:\program files\AVG Secure Search\setup.bmp
c:\program files\AVG Secure Search\speed-test.gif
c:\program files\AVG Secure Search\surf-with-caution18.gif
c:\program files\AVG Secure Search\toolbar.zip
c:\program files\AVG Secure Search\Uninstall.exe
c:\program files\AVG Secure Search\uninstall.gif
c:\program files\AVG Secure Search\updating18.gif
c:\program files\AVG Secure Search\vprot.exe
c:\program files\AVG Secure Search\weather.gif
c:\program files\AVG Secure Search\windows.gif
c:\program files\Common Files\AVG Secure Search
c:\program files\Common Files\AVG Secure Search\CommonInstaller\12.2.6\CommonInstaller.exe
c:\program files\Common Files\AVG Secure Search\DNTInstaller\12.2.6\avgdttbx.dll
c:\program files\Common Files\AVG Secure Search\DriverInstaller\12.2.6\DriverInstaller.exe
c:\program files\Common Files\AVG Secure Search\InstalledProducts.ini
c:\program files\Common Files\AVG Secure Search\ScriptHelperInstaller\12.2.6\ScriptHelper.exe
c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\npsitesafety.dll
c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\SiteSafety.dll
c:\program files\Common Files\AVG Secure Search\ToolBandTlb\12.2.6\toolband
c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\UpdaterConfig.ini
c:\program files\Giant Savings
c:\program files\Giant Savings\Giant Savings-bg.exe
c:\program files\Giant Savings\Giant Savings.dll
c:\program files\Giant Savings\Giant Savings.exe
c:\program files\Giant Savings\Giant Savings.ico
c:\program files\Giant Savings\Giant Savings.ini
c:\program files\Giant Savings\Giant SavingsInstaller.log
c:\program files\Giant Savings\Uninstall.exe
c:\programdata\Ask
c:\programdata\Ask\APN-Stub\PTV\Local\APNIC.dll
c:\programdata\AVG Secure Search
c:\programdata\AVG Secure Search\12.2.5.34\components\avg-dnt-policy.js
c:\programdata\AVG Secure Search\12.2.5.34\components\toolbarhomeApi.js
c:\programdata\AVG Secure Search\12.2.5.34\chrome.manifest
c:\programdata\AVG Secure Search\12.2.5.34\chrome\avg.jar
c:\programdata\AVG Secure Search\12.2.5.34\icon.png
c:\programdata\AVG Secure Search\12.2.5.34\install.rdf
c:\programdata\AVG Secure Search\12.2.5.34\locale\en-US\global.dtd
c:\programdata\AVG Secure Search\12.2.5.34\locale\en-US\global.properties
c:\programdata\AVG Secure Search\12.2.5.34\modules\avg-dnt-adapter.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\avg.xml
c:\programdata\AVG Secure Search\12.2.5.34\modules\avgJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\Bindings.xml
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration_0.css
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration_0.xul
c:\programdata\AVG Secure Search\12.2.5.34\modules\HistoryCleaner.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\IOJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\Preferences.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\propertiesJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\about.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\active-threats18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\ajax-loader.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\calc.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\CleanHistory.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\close.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\current.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\currently-safe18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\dnt.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\Facebook.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\feedback.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\feedicon.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\help.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\icon_search.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\icon18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\information-24.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\labs.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\loader.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\note.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\questionmarkIcon.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\search.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\SecuredSearch.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\speed-test.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\surf-with-caution18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\uninstall.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\updating18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\weather.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\window-close.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\windows.png
c:\programdata\AVG Secure Search\ChromeExt\12.2.5.34\avg.crx
c:\users\Karel\AppData\Local\AVG Secure Search
c:\users\Karel\AppData\Local\AVG Secure Search\DNT\dt.dat
c:\users\Karel\AppData\Local\AVG Secure Search\SiteSafety\l_2012_09_15_11_02_16.db
c:\users\Karel\AppData\Local\AVG Secure Search\SiteSafety\l_2012_09_17_10_14_42.db
c:\users\Karel\AppData\Local\Giant Savings
c:\users\Karel\AppData\Local\Giant Savings\Chrome\Giant Savings.crx
c:\users\Karel\AppData\Roaming\.minecraft
c:\users\Karel\AppData\Roaming\.minecraft\bin\__rzi_0.917
c:\users\Karel\AppData\Roaming\.minecraft\bin\bin.rar
c:\users\Karel\AppData\Roaming\.minecraft\bin\jinput.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\lwjgl.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\lwjgl_util.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\minecraft.bak
c:\users\Karel\AppData\Roaming\.minecraft\bin\minecraft.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-dx8.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-dx8_64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-raw.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-raw_64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\lwjgl.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\lwjgl64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\OpenAL32.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\OpenAL64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\version
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\blueprints\index.txt
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\blueprints\St3eT.list
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\config\AdditionalPipes.cfg
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\config\buildcraft.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\forestry\backpacks.conf
c:\users\Karel\AppData\Roaming\.minecraft\config\forestry\base.conf
c:\users\Karel\AppData\Roaming\.minecraft\config\IC2.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\IC2.lang
c:\users\Karel\AppData\Roaming\.minecraft\config\IronChest.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\mod_AdditionalBuildcraftObjects.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\mod_MinecraftForge.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\MorePistons.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\MorePistonsServer.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEIServer.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEISubset.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\language.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\modules.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\railcraft.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\ThermalExpansion.cfg
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-0.log
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-0.log.1
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-1.log
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-1.log.1
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-2.log
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 1-8-2012 at 19.12.27.507.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.0.852.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.12.555.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.254.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.707.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.950.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.14.152.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.14.656.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.28.108.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.4.606.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.4.7.txt
c:\users\Karel\AppData\Roaming\.minecraft\lastlogin
c:\users\Karel\AppData\Roaming\.minecraft\MC-E.exe
c:\users\Karel\AppData\Roaming\.minecraft\MC.exe
c:\users\Karel\AppData\Roaming\.minecraft\Minecraft.exe
c:\users\Karel\AppData\Roaming\.minecraft\MinecraftSP.exe
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-A-core-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-builders-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-energy-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-factory-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-transport-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-DA-additionalpipes-2.1.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\CustomMobSpawner 1.4.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\CustomMobSpawner 1.5.1.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\DrZharks MoCreatures Mod v3.6.2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\forestry-client-A-1.4.8.6_bc2.2.jar
c:\users\Karel\AppData\Roaming\.minecraft\mods\GuiAPI-0.14.2-1.2.5.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\industrialcraft-2-client_1.97.jar
c:\users\Karel\AppData\Roaming\.minecraft\mods\mod_ironchests-client-3.8.0.40.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\More Pistons v1.0.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_ForestryPlugin 1.0.4.15.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_RailCraftPlugin 1.2.2.1.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_RedPowerPlugin 1.2.2.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\Railcraft_Client_5.3.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerControl-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerCore-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerLighting-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerLogic-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerMachine-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerWiring-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerWorld-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\h4.sms-hosting.cz[29930].DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\keyconfig.txt
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\New World.DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\Nový svět2.DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\option.txt
c:\users\Karel\AppData\Roaming\.minecraft\mods\WeaponMod.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\weaponmod\weaponmod.properties
c:\users\Karel\AppData\Roaming\.minecraft\optifog.log
c:\users\Karel\AppData\Roaming\.minecraft\options.txt
c:\users\Karel\AppData\Roaming\.minecraft\optionsof.txt
c:\users\Karel\AppData\Roaming\.minecraft\redpower\redpower.cfg
c:\users\Karel\AppData\Roaming\.minecraft\redpower\redpower.lang
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\nuance1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\nuance2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave10.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave11.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave12.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave13.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave7.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave8.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave9.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beardeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\bearhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\bearhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen2.ogg.sfk
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdwhite1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocjawsnap1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocjawsnap2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocresting1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocresting2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocroll.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cub1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallbig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallbig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallsmall.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerfgrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deergrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerhurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\destroy.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinupset.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckplop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\eating.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\fire\fire.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\fire\ignite.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatdigg.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goateating.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatfemale.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatgrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatkid.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatsmack.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsedying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsemad.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittendying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittengrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittenhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittenhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittydying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittydying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyeatingf.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyeatingm.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittygrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittygrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittypurr1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittypurr2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittytrapped.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liondeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\lava.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\lavapop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\splash.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\water.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micedying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micedying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purreow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purreow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeperdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\portal.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\portal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\stare.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\affectionate scream.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\fireball4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\charge.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan7.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenplop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\throw.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pigdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\kill.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletondeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slimeattack1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slimeattack2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spiderdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\howl1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\howl2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\panting.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\shake.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\whine.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\woodbreak.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiedeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpighurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpighurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bass.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bassattack.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bd.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\harp.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\hat.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\pling.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\snare.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogredying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogrehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichchick.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pegasus.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\portal.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\travel.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\trigger.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pouringfood.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pouringmilk.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbithurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbithurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitland.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitlift.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bow.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\break.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\breath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\burp.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\click.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\door_close.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\door_open.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\drink.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\drr.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\fizz.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\fuse.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\hurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\chestclosed.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\chestopen.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\levelup.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\old_explode.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\orb.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\pop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\splash.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\wood click.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rathurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rathurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\roping.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionclaw.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiondying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionsting1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionsting2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakedying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehiss1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehiss2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakerattle1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakerattle2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakesnap.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeswim.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeupset1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeupset2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\tile\piston\in.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\tile\piston\out.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtledying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtlehissing.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtlehurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumandying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumandying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumanhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumanhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfdying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\whip.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithdying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\pe\humble.png
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\11.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\13.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\13.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\blocks.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\cat.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\cat.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\far.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\chirp.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\mall.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\mellohi.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\stal.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\strad.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\ward.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\where are we now.mus
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI\127.0.0.1~25565\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI\127.0.0.1~25565\NEI.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.1.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.2.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.2.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\players\thorky.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.7.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.17.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.18.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.19.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.20.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.7.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.17.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.18.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.19.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.20.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-2.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-01-21_00.03.53.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-01-28_20.16.20.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-05-02_23.02.02.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.12.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.18.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.20.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-07_14.16.24.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-07_14.16.29.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-23_13.38.02.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-08_00.34.31.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-08_00.34.31_2.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-11_14.57.12.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-23_19.34.27.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-31_23.50.38.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-09-16_02.01.17.png
c:\users\Karel\AppData\Roaming\.minecraft\servers.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats__unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats__unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_matrix012_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_matrix012_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player177_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player177_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player310_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player310_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player386_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player386_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player443_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player443_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player68_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player68_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player724_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player724_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player740_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player740_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player843_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player843_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player913_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player913_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player983_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player983_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player985_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player985_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player986_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player986_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_s_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_s_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_st3et_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_st3et_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_streeet_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_streeet_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_street_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_street_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_thorky_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_thorky_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\texturepacks\faithful32packUpr.zip
c:\windows\AutoKMS.exe
c:\windows\system32\drivers\avgtpx86.sys
c:\windows\Tasks\AutoKMS.job
.
.
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3198.2212 [GMT 2:00]
Spuštěný z: c:\users\Karel\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Karel\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: avast! antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\AutoKMS.exe"
"c:\windows\system32\drivers\avgtpx86.sys"
"c:\windows\Tasks\AutoKMS.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\AVG Secure Search
c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
c:\program files\AVG Secure Search\about.gif
c:\program files\AVG Secure Search\active-threats18.gif
c:\program files\AVG Secure Search\avguidx.dll
c:\program files\AVG Secure Search\calc.gif
c:\program files\AVG Secure Search\CleanHistory.gif
c:\program files\AVG Secure Search\configuration.xml
c:\program files\AVG Secure Search\current.gif
c:\program files\AVG Secure Search\currently-safe18.gif
c:\program files\AVG Secure Search\Facebook.gif
c:\program files\AVG Secure Search\favicon.ico
c:\program files\AVG Secure Search\feedback.gif
c:\program files\AVG Secure Search\help.gif
c:\program files\AVG Secure Search\icon18.gif
c:\program files\AVG Secure Search\labs.gif
c:\program files\AVG Secure Search\Licenses\Encoding_decoding_base64.txt
c:\program files\AVG Secure Search\Licenses\hmac.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-bsdiff.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-bzip.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-JasonCpp.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-MPL-NPAPI.txt
c:\program files\AVG Secure Search\Licenses\LICENSE-sparsehash.txt
c:\program files\AVG Secure Search\Licenses\PassthruApp.txt
c:\program files\AVG Secure Search\lip.exe
c:\program files\AVG Secure Search\note.gif
c:\program files\AVG Secure Search\PostInstall.exe
c:\program files\AVG Secure Search\PostInstaller.ini
c:\program files\AVG Secure Search\radio\bg.gif
c:\program files\AVG Secure Search\radio\play.gif
c:\program files\AVG Secure Search\radio\play_hover.gif
c:\program files\AVG Secure Search\radio\stop.gif
c:\program files\AVG Secure Search\radio\stop_hover.gif
c:\program files\AVG Secure Search\radio\v_minus.gif
c:\program files\AVG Secure Search\radio\v_minus_1.gif
c:\program files\AVG Secure Search\radio\v_plus.gif
c:\program files\AVG Secure Search\radio\v_plus_1.gif
c:\program files\AVG Secure Search\radio\vol_line_emp.gif
c:\program files\AVG Secure Search\radio\vol_line_full.gif
c:\program files\AVG Secure Search\radio\vol_line_half.gif
c:\program files\AVG Secure Search\remote_configuration.xml
c:\program files\AVG Secure Search\roc_nt.exe
c:\program files\AVG Secure Search\ROC_ROC_NT.exe
c:\program files\AVG Secure Search\search.gif
c:\program files\AVG Secure Search\SecuredSearch.gif
c:\program files\AVG Secure Search\setup.bmp
c:\program files\AVG Secure Search\speed-test.gif
c:\program files\AVG Secure Search\surf-with-caution18.gif
c:\program files\AVG Secure Search\toolbar.zip
c:\program files\AVG Secure Search\Uninstall.exe
c:\program files\AVG Secure Search\uninstall.gif
c:\program files\AVG Secure Search\updating18.gif
c:\program files\AVG Secure Search\vprot.exe
c:\program files\AVG Secure Search\weather.gif
c:\program files\AVG Secure Search\windows.gif
c:\program files\Common Files\AVG Secure Search
c:\program files\Common Files\AVG Secure Search\CommonInstaller\12.2.6\CommonInstaller.exe
c:\program files\Common Files\AVG Secure Search\DNTInstaller\12.2.6\avgdttbx.dll
c:\program files\Common Files\AVG Secure Search\DriverInstaller\12.2.6\DriverInstaller.exe
c:\program files\Common Files\AVG Secure Search\InstalledProducts.ini
c:\program files\Common Files\AVG Secure Search\ScriptHelperInstaller\12.2.6\ScriptHelper.exe
c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\npsitesafety.dll
c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\SiteSafety.dll
c:\program files\Common Files\AVG Secure Search\ToolBandTlb\12.2.6\toolband
c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\UpdaterConfig.ini
c:\program files\Giant Savings
c:\program files\Giant Savings\Giant Savings-bg.exe
c:\program files\Giant Savings\Giant Savings.dll
c:\program files\Giant Savings\Giant Savings.exe
c:\program files\Giant Savings\Giant Savings.ico
c:\program files\Giant Savings\Giant Savings.ini
c:\program files\Giant Savings\Giant SavingsInstaller.log
c:\program files\Giant Savings\Uninstall.exe
c:\programdata\Ask
c:\programdata\Ask\APN-Stub\PTV\Local\APNIC.dll
c:\programdata\AVG Secure Search
c:\programdata\AVG Secure Search\12.2.5.34\components\avg-dnt-policy.js
c:\programdata\AVG Secure Search\12.2.5.34\components\toolbarhomeApi.js
c:\programdata\AVG Secure Search\12.2.5.34\chrome.manifest
c:\programdata\AVG Secure Search\12.2.5.34\chrome\avg.jar
c:\programdata\AVG Secure Search\12.2.5.34\icon.png
c:\programdata\AVG Secure Search\12.2.5.34\install.rdf
c:\programdata\AVG Secure Search\12.2.5.34\locale\en-US\global.dtd
c:\programdata\AVG Secure Search\12.2.5.34\locale\en-US\global.properties
c:\programdata\AVG Secure Search\12.2.5.34\modules\avg-dnt-adapter.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\avg.xml
c:\programdata\AVG Secure Search\12.2.5.34\modules\avgJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\Bindings.xml
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration_0.css
c:\programdata\AVG Secure Search\12.2.5.34\modules\configuration_0.xul
c:\programdata\AVG Secure Search\12.2.5.34\modules\HistoryCleaner.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\IOJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\Preferences.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\propertiesJsm.js
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\about.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\active-threats18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\ajax-loader.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\calc.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\CleanHistory.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\close.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\current.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\currently-safe18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\dnt.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\Facebook.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\feedback.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\feedicon.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\help.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\icon_search.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\icon18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\information-24.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\labs.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\loader.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\note.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\questionmarkIcon.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\search.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\SecuredSearch.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\speed-test.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\surf-with-caution18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\uninstall.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\updating18.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\weather.gif
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\window-close.png
c:\programdata\AVG Secure Search\12.2.5.34\modules\skin\windows.png
c:\programdata\AVG Secure Search\ChromeExt\12.2.5.34\avg.crx
c:\users\Karel\AppData\Local\AVG Secure Search
c:\users\Karel\AppData\Local\AVG Secure Search\DNT\dt.dat
c:\users\Karel\AppData\Local\AVG Secure Search\SiteSafety\l_2012_09_15_11_02_16.db
c:\users\Karel\AppData\Local\AVG Secure Search\SiteSafety\l_2012_09_17_10_14_42.db
c:\users\Karel\AppData\Local\Giant Savings
c:\users\Karel\AppData\Local\Giant Savings\Chrome\Giant Savings.crx
c:\users\Karel\AppData\Roaming\.minecraft
c:\users\Karel\AppData\Roaming\.minecraft\bin\__rzi_0.917
c:\users\Karel\AppData\Roaming\.minecraft\bin\bin.rar
c:\users\Karel\AppData\Roaming\.minecraft\bin\jinput.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\lwjgl.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\lwjgl_util.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\minecraft.bak
c:\users\Karel\AppData\Roaming\.minecraft\bin\minecraft.jar
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-dx8.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-dx8_64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-raw.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\jinput-raw_64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\lwjgl.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\lwjgl64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\OpenAL32.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\natives\OpenAL64.dll
c:\users\Karel\AppData\Roaming\.minecraft\bin\version
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\blueprints\index.txt
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\blueprints\St3eT.list
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\config\AdditionalPipes.cfg
c:\users\Karel\AppData\Roaming\.minecraft\buildcraft\config\buildcraft.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\forestry\backpacks.conf
c:\users\Karel\AppData\Roaming\.minecraft\config\forestry\base.conf
c:\users\Karel\AppData\Roaming\.minecraft\config\IC2.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\IC2.lang
c:\users\Karel\AppData\Roaming\.minecraft\config\IronChest.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\mod_AdditionalBuildcraftObjects.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\mod_MinecraftForge.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\MorePistons.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\MorePistonsServer.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEIServer.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\NEISubset.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\language.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\modules.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\railcraft\railcraft.cfg
c:\users\Karel\AppData\Roaming\.minecraft\config\ThermalExpansion.cfg
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-0.log
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-0.log.1
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-1.log
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-1.log.1
c:\users\Karel\AppData\Roaming\.minecraft\ForgeModLoader-2.log
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 1-8-2012 at 19.12.27.507.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.0.852.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.12.555.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.254.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.707.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.13.950.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.14.152.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.14.656.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.28.108.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.4.606.txt
c:\users\Karel\AppData\Roaming\.minecraft\IDMap dump 14-9-2012 at 22.58.4.7.txt
c:\users\Karel\AppData\Roaming\.minecraft\lastlogin
c:\users\Karel\AppData\Roaming\.minecraft\MC-E.exe
c:\users\Karel\AppData\Roaming\.minecraft\MC.exe
c:\users\Karel\AppData\Roaming\.minecraft\Minecraft.exe
c:\users\Karel\AppData\Roaming\.minecraft\MinecraftSP.exe
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-A-core-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-builders-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-energy-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-factory-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-B-transport-2.2.14.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\buildcraft-client-DA-additionalpipes-2.1.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\CustomMobSpawner 1.4.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\CustomMobSpawner 1.5.1.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\DrZharks MoCreatures Mod v3.6.2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\forestry-client-A-1.4.8.6_bc2.2.jar
c:\users\Karel\AppData\Roaming\.minecraft\mods\GuiAPI-0.14.2-1.2.5.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\industrialcraft-2-client_1.97.jar
c:\users\Karel\AppData\Roaming\.minecraft\mods\mod_ironchests-client-3.8.0.40.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\More Pistons v1.0.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_ForestryPlugin 1.0.4.15.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_RailCraftPlugin 1.2.2.1.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\NEI_RedPowerPlugin 1.2.2.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\Railcraft_Client_5.3.3.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerControl-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerCore-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerLighting-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerLogic-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerMachine-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerWiring-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\RedPowerWorld-2.0pr5b2.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\h4.sms-hosting.cz[29930].DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\keyconfig.txt
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\New World.DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\Nový svět2.DIM0.points
c:\users\Karel\AppData\Roaming\.minecraft\mods\rei_minimap\option.txt
c:\users\Karel\AppData\Roaming\.minecraft\mods\WeaponMod.zip
c:\users\Karel\AppData\Roaming\.minecraft\mods\weaponmod\weaponmod.properties
c:\users\Karel\AppData\Roaming\.minecraft\optifog.log
c:\users\Karel\AppData\Roaming\.minecraft\options.txt
c:\users\Karel\AppData\Roaming\.minecraft\optionsof.txt
c:\users\Karel\AppData\Roaming\.minecraft\redpower\redpower.cfg
c:\users\Karel\AppData\Roaming\.minecraft\redpower\redpower.lang
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\music\calm3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\hal4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\nuance1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\nuance2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newmusic\piano3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave10.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave11.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave12.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave13.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave7.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave8.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\cave\cave9.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\rain4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ambient\weather\thunder3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beardeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\beargrunt5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\bearhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\bearhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblack3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdblue4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen2.ogg.sfk
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdgreen3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdred5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdwhite1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\birdyellow5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocjawsnap1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocjawsnap2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocresting1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocresting2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crocroll.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\crochurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cub1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubgrunt5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\cubhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallbig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallbig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\fallsmall.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\damage\hurtflesh3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerfgrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deergrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\deerhurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\destroy.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphin6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphindying3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\dolphinupset.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duck3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\duckplop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\eating.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\fire\fire.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\fire\ignite.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxcall5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\foxhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatdigg.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goateating.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatfemale.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatgrunt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatkid.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\goatsmack.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsedying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsegrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\horsemad.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittendying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittengrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittenhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittenhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittydying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittydying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyeatingf.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyeatingm.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyfood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittygrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittygrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittypurr1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittypurr2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittytrapped.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\kittyupset3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liondeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liongrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\lionhurt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\lava.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\lavapop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\splash.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\liquid\water.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micedying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micedying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micegrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\micehurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\breathe4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\blaze\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hiss3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\hitt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\meow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purr3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purreow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cat\purreow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\cowhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeper4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\creeperdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\idle5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\portal.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\portal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\scream4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\endermen\stare.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\affectionate scream.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\fireball4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\charge.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan6.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\moan7.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\ghast\scream5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chicken3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\chickenplop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\hit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\throw.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem\walk4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\big4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\jump4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube\small5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pig3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\pigdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\sheep3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\hit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\kill.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\say4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish\step4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeleton3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletondeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\skeletonhurt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slime5.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slimeattack1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\slimeattack2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spider4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\spiderdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\bark3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\death.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\growl3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\howl1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\howl2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\hurt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\panting.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\shake.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\wolf\whine.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\metal3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie\woodbreak.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombie3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiedeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiehurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpig4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigangry4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpigdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpighurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig\zpighurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bass.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bassattack.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\bd.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\harp.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\hat.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\pling.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\note\snare.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogre3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogredying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ogrehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichdying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ostrichchick.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pegasus.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\portal.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\travel.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\portal\trigger.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pouringfood.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\pouringmilk.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbithurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbithurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitland.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rabbitlift.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bow.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\bowhit4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\break.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\breath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\burp.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\click.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\door_close.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\door_open.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\drink.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\drr.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\eat3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\explode4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\fizz.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\fuse.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\glass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\hurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\chestclosed.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\chestopen.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\levelup.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\old_explode.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\orb.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\pop.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\splash.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\random\wood click.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\ratgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rathurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\rathurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\roping.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionclaw.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiondying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpiongrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionsting1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\scorpionsting2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakedying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehiss1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehiss2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakehurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakerattle1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakerattle2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakesnap.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeswim.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeupset1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\snakeupset2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\cloth4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\grass4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\gravel4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\sand4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\snow4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\stone4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\step\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\tile\piston\in.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\tile\piston\out.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtledying.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtlehissing.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\turtlehurt.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumandying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumandying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumanhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werehumanhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\weretransform3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfdying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfgrunt4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\werewolfhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\whip.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfdeath.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfgrunt3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfhurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wolfhurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraith3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithdying1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithdying2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithurt1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\newsound\wraithurt2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\pe\humble.png
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\grass4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\gravel4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\stone4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood1.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood2.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood3.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\sound\step\wood4.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\11.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\13.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\13.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\blocks.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\cat.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\cat.ogg
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\far.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\chirp.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\mall.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\mellohi.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\stal.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\strad.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\ward.mus
c:\users\Karel\AppData\Roaming\.minecraft\resources\streaming\where are we now.mus
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI\127.0.0.1~25565\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\NEI\127.0.0.1~25565\NEI.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-----\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World----\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World---\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\region\r.1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World--\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World-\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-3.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-4.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-5.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.-6.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.1.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.2.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\region\r.2.-3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\New World\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\DIM-1\region\r.0.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\players\thorky.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-1.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.7.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-2.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.17.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.18.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.19.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.20.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.6.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.7.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-3.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.10.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.11.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.12.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.13.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.14.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.15.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.16.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.17.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.18.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.19.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.20.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.8.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.-4.9.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.0.5.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.-2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.1.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.2.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.3.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\region\r.2.4.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\Nový svět2\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\level.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\level.dat_old
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\NEI.cfg
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\railcraft.dat
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-1.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-1.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-2.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.-2.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.0.-1.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\region\r.0.0.mca
c:\users\Karel\AppData\Roaming\.minecraft\saves\thorky\session.lock
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-01-21_00.03.53.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-01-28_20.16.20.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-05-02_23.02.02.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.12.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.18.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-03_13.41.20.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-07_14.16.24.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-07_14.16.29.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-06-23_13.38.02.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-08_00.34.31.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-08_00.34.31_2.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-11_14.57.12.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-23_19.34.27.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-07-31_23.50.38.png
c:\users\Karel\AppData\Roaming\.minecraft\screenshots\2012-09-16_02.01.17.png
c:\users\Karel\AppData\Roaming\.minecraft\servers.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats__unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats__unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_matrix012_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_matrix012_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player177_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player177_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player310_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player310_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player386_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player386_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player443_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player443_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player68_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player68_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player724_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player724_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player740_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player740_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player843_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player843_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player913_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player913_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player983_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player983_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player985_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player985_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player986_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_player986_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_s_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_s_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_st3et_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_st3et_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_streeet_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_streeet_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_street_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_street_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_thorky_unsent.dat
c:\users\Karel\AppData\Roaming\.minecraft\stats\stats_thorky_unsent.old
c:\users\Karel\AppData\Roaming\.minecraft\texturepacks\faithful32packUpr.zip
c:\windows\AutoKMS.exe
c:\windows\system32\drivers\avgtpx86.sys
c:\windows\Tasks\AutoKMS.job
.
.
Re: Černej monitor
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_86581953
-------\Legacy_AVGTP
-------\Service_avgtp
-------\Service_vToolbarUpdater12.2.6
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-18 do 2012-09-18 )))))))))))))))))))))))))))))))
.
.
2012-09-18 17:39 . 2012-09-18 17:41 -------- d-----w- c:\users\Karel\AppData\Local\temp
2012-09-18 17:39 . 2012-09-18 17:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-18 15:56 . 2012-09-18 15:56 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\offreg.dll
2012-09-18 08:00 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\mpengine.dll
2012-09-17 18:44 . 2012-09-17 18:44 -------- d-----w- c:\program files\CCleaner
2012-09-17 17:47 . 2012-09-17 17:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-17 17:47 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-17 13:42 . 2012-09-17 18:59 -------- d-----w- c:\program files\trend micro
2012-09-17 13:42 . 2012-09-17 13:42 -------- d-----w- C:\rsit
2012-09-15 21:50 . 2012-09-15 21:50 -------- d-----w- c:\users\Karel\AppData\Local\Adobe
2012-09-15 21:48 . 2012-09-15 21:48 -------- d-----w- c:\program files\Common Files\Adobe
2012-09-13 07:04 . 2012-09-13 07:04 -------- d--h--w- c:\programdata\Common Files
2012-09-12 20:28 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 20:28 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 20:28 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 20:28 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 20:28 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 20:28 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Common Files\Java
2012-09-10 06:46 . 2012-09-10 06:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Java
2012-08-31 07:59 . 2012-08-31 07:59 -------- d-----w- c:\program files\PANDORA.TV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 06:48 . 2012-07-25 10:57 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-14 06:47 . 2012-07-25 10:56 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-14 06:47 . 2012-06-23 10:17 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 06:47 . 2012-07-25 10:56 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-14 06:04 . 2012-04-24 05:44 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-14 06:04 . 2012-01-21 18:26 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 06:46 . 2012-07-06 16:34 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2012-01-22 10:04 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-01-21 12:59 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-01-21 12:59 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-03-07 07:51 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2012-01-21 12:59 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-01-21 12:59 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2012-01-22 10:02 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-01-21 12:59 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-25 10:59 . 2012-07-25 10:56 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-25 10:57 . 2012-05-28 14:07 138056 ----a-w- c:\users\Karel\AppData\Roaming\PnkBstrK.sys
2012-07-18 17:47 . 2012-08-15 08:28 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 08:28 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 08:28 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 11:08 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 11:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 11:08 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 11:08 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 11:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-08 21:59 . 2012-09-08 21:59 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"4gameTray"="c:\program files\4game\4game\4GameTray.exe" [2012-03-05 813408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-07 336384]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 4game;4game;c:\program files\4game\4game\4GameService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/firefox?client=firefox-a& ... s:official
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
HKLM-Run-ROC_ROC_NT - c:\program files\AVG Secure Search\ROC_ROC_NT.exe
AddRemove-AVG Secure Search - c:\program files\AVG Secure Search\UNINSTALL.exe
AddRemove-Giant Savings - c:\program files\Giant Savings\Uninstall.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\taskhost.exe
c:\windows\DAODx.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-18 19:43:59 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-18 17:43
ComboFix2.txt 2012-09-18 15:56
.
Před spuštěním: Volných bajtů: 873 773 944 832
Po spuštění: Volných bajtů: 873 312 514 048
.
- - End Of File - - 7C626894476B9F37423669390BF208FD
.
.
-------\Legacy_86581953
-------\Legacy_AVGTP
-------\Service_avgtp
-------\Service_vToolbarUpdater12.2.6
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-18 do 2012-09-18 )))))))))))))))))))))))))))))))
.
.
2012-09-18 17:39 . 2012-09-18 17:41 -------- d-----w- c:\users\Karel\AppData\Local\temp
2012-09-18 17:39 . 2012-09-18 17:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-18 15:56 . 2012-09-18 15:56 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\offreg.dll
2012-09-18 08:00 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AEF069-4CAF-4DE8-AD72-9CAEF35A34BB}\mpengine.dll
2012-09-17 18:44 . 2012-09-17 18:44 -------- d-----w- c:\program files\CCleaner
2012-09-17 17:47 . 2012-09-17 17:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-17 17:47 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-17 13:42 . 2012-09-17 18:59 -------- d-----w- c:\program files\trend micro
2012-09-17 13:42 . 2012-09-17 13:42 -------- d-----w- C:\rsit
2012-09-15 21:50 . 2012-09-15 21:50 -------- d-----w- c:\users\Karel\AppData\Local\Adobe
2012-09-15 21:48 . 2012-09-15 21:48 -------- d-----w- c:\program files\Common Files\Adobe
2012-09-13 07:04 . 2012-09-13 07:04 -------- d--h--w- c:\programdata\Common Files
2012-09-12 20:28 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 20:28 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 20:28 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 20:28 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 20:28 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 20:28 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Common Files\Java
2012-09-10 06:46 . 2012-09-10 06:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 06:46 . 2012-09-10 06:46 -------- d-----w- c:\program files\Java
2012-08-31 07:59 . 2012-08-31 07:59 -------- d-----w- c:\program files\PANDORA.TV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 06:48 . 2012-07-25 10:57 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-14 06:47 . 2012-07-25 10:56 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-14 06:47 . 2012-06-23 10:17 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 06:47 . 2012-07-25 10:56 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-14 06:04 . 2012-04-24 05:44 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-14 06:04 . 2012-01-21 18:26 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 06:46 . 2012-07-06 16:34 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2012-01-22 10:04 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-01-21 12:59 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-01-21 12:59 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-03-07 07:51 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2012-01-21 12:59 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-01-21 12:59 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2012-01-22 10:02 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-01-21 12:59 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-25 10:59 . 2012-07-25 10:56 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-07-25 10:57 . 2012-05-28 14:07 138056 ----a-w- c:\users\Karel\AppData\Roaming\PnkBstrK.sys
2012-07-18 17:47 . 2012-08-15 08:28 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 08:28 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 08:28 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 11:08 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 11:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 11:08 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 11:08 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 11:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-08 21:59 . 2012-09-08 21:59 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"4gameTray"="c:\program files\4game\4game\4GameTray.exe" [2012-03-05 813408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-07 336384]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 4game;4game;c:\program files\4game\4game\4GameService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\wyei7yx8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/firefox?client=firefox-a& ... s:official
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
HKLM-Run-ROC_ROC_NT - c:\program files\AVG Secure Search\ROC_ROC_NT.exe
AddRemove-AVG Secure Search - c:\program files\AVG Secure Search\UNINSTALL.exe
AddRemove-Giant Savings - c:\program files\Giant Savings\Uninstall.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\taskhost.exe
c:\windows\DAODx.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-18 19:43:59 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-18 17:43
ComboFix2.txt 2012-09-18 15:56
.
Před spuštěním: Volných bajtů: 873 773 944 832
Po spuštění: Volných bajtů: 873 312 514 048
.
- - End Of File - - 7C626894476B9F37423669390BF208FD
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
Otestuj tento subor na
WWW.virustotal.com
c:\program files\4game\4game\4GameTray.exe
Link z testu vloz sem.
WWW.virustotal.com
c:\program files\4game\4game\4GameTray.exe
Link z testu vloz sem.
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Černej monitor
To bude ok, tak ze odinstaluj combofix
Kolega pise:
Kolega pise:
A ak vsetko ok to je vsetko.Odinstalujte Combofix
Prejmenujte ComboFix na Uninstall
Spustte jej
Tohle smaze Combofix a jeho slozky