Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

nedobytná háveď v PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

nedobytná háveď v PC

#1 Příspěvek od Kicker »

Zdravím Vás, bolo mi doporučené toto fórum, petože sa neviem nijako zbaviť pliagy čo mám v PC. Neviem odkiaľ, chová sa to tak, že v prehliadači (Firefox v. 19) mi prepisuje adress bar a namiesto google engine mi tam hodí nejaký FastBar.... druhá vec, keď chcem niečo kopírovať na FTP cez totoal commander, tak mi ESET vypíše, že bol zdetekovaný port scanning. Eset mi nič nenašiel, tak isto som skúšal aj spybot. Som bezradný. Niekto nejaký nápad na opravu?

//edit, skúšal som samozrejme v prehliadači aj resetnúť search engine, ale po reštarte prehliadača mi to zase prepíše na ten FastBar...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#2 Příspěvek od vyosek »

Zdravim, pekne odpoledne preji a vitam Vas u nas na foru :welcome:

:arrow: Mohu prosim pro zajimavost vedet, odkud doporuceni na nase forum pochazi :)

:arrow: Jelikoz z kristalove koule se spatne vesti a nejsme vedmy z Delf, budem potrebovat neco, co ukaze kde muze byt chyba :James008:

:arrow: Takze poprosim o log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=105895
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#3 Příspěvek od Kicker »

Dopočul som sa o vás náhodne od kolegu, že už aj jemu ste tu pomohli. Pridávam log a ďakujem za privítanie :)

https://www.dropbox.com/s/s3w9ot447p7i5mz/log.txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#4 Příspěvek od vyosek »

:arrow: No tak Vam mel kolega rici i neco o pravidlech a vy jste si je mel precist
  • Nelegalni Office - pujdou do pryc
  • ESET - pokud neni zakoupen, taktez a bude tam free nahrada
  • Nejvyssi verzi Windows Ultimate - radne zakoupena nebo nekde stahnuta a cinknuta??
:arrow: Nedavejte logy na DB ale primo do tematu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#5 Příspěvek od Kicker »

Office používam zatiaľ free, mám licenciu aj na to, ešte nezaktivovaný. Všetko čo mám nainštalované je legálne zakúpené na firmu.

Log do témy mi pridať nešiel, nie je podporovaný .txt

Takže viete, kde by mohol byť problém?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#6 Příspěvek od vyosek »

:arrow: A proc je tedy v PC crack na Office :?:

:arrow: PC je firemni nebo Vas??

:arrow: Logy davejte jako text do prispevku

:arrow: Poprosim jeste i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#7 Příspěvek od Kicker »

No prišlo mi to podivné riešenie kvli prehľadnosti, ale v poriadku, budem to pridávať do príspevku. Pred tým než som sem nastúpil som nemal všetko legálne, nevidím nikde nič (ten crack) tak neviem odkiaľ to mám odmazať, rád tak ale urobím, pretože chcem mať všetko "košér"

Sme firma, ktorá vyvíja software a weby na produktoch microsoftu, všetko od microsoftu máme teda licencované.

PC je môj ako keby prenajatý na firmu (alebo naopak) aby som mohol používať ten soft.

Som rád, že sa informujete, no potrebujem pracovať a neviem sa s týmto už nejakú dobu vysporiadať, keby ste mi mohli poradiť, tak by som bol vďačný

Tu je ten log:

info.txt logfile of random's system information tool 1.08 2013-03-13 13:29:33

======Uninstall list======

Tools for .Net 3.5-->MsiExec.exe /X{1690CE56-2231-4E59-9006-A0876D949EA8}
-->C:\PROGRA~3\INSTAL~1\{8F2A5~1\Setup.exe /remove /q0
Adobe Creative Suite 6 Master Collection-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="2.0" --mode="Uninstall" --mediaSignature="{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}"
Adobe Flash Player 11 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -maintain activex
Adobe Flash Player 11 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_Plugin.exe -maintain plugin
Adobe Reader XI (11.0.02) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AB0000000001}
Battlefield 2(TM)-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x9 -removeonly
Blend for Visual Studio 2012 ENU resources-->MsiExec.exe /I{532DBCC8-9468-435C-AEF6-30B7F50735A2}
Blend for Visual Studio 2012-->MsiExec.exe /I{57F20F04-014D-453F-B6A3-AE9485C4DFAB}
Broadcom 802.11 Network Adapter-->"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\Driver"
BrowseToSave 1.74-->"C:\Program Files (x86)\BrowseToSave\uninstall.exe" /FULLPATH="C:\Program Files (x86)\BrowseToSave"
Cisco EAP-FAST Module-->MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Cisco LEAP Module-->MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Cisco PEAP Module-->MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
Counter-Strike 1.6 V40-->C:\Program Files (x86)\Counter-Strike 1.6 V40\Uninstal.exe
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{7F9EE107-FB63-4790-8B1B-023B2D69AAAE}" "1051" "0"
Dotfuscator and Analytics Community Edition-->MsiExec.exe /X{372D17F6-A54E-4A01-B264-1314890FFE61}
Entity Framework Designer for Visual Studio 2012 - enu-->MsiExec.exe /X{0A1A1D48-DB23-443A-BC7B-49255D138020}
FastStone Image Viewer 4.6-->C:\Program Files (x86)\FastStone Image Viewer\uninst.exe
Fiddler-->"C:\Program Files (x86)\Fiddler2\uninst.exe"
FileZilla Client 3.5.3-->C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe
Fingerprint Reader-->MsiExec.exe /X{C5BB9380-D729-410A-A440-061EBCADCCB9}
GDR 5512 for SQL Server 2008 (KB2716436) (64-bit)-->"C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2716436\GDR\setup.exe" /Action=RemovePatch /AllInstances
Google Gmail Notifier-->"C:\Program Files (x86)\Google\Gmail Notifier\UninstallGmail.exe"
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
High-Logic FontCreator 6.0-->"C:\Program Files (x86)\High-Logic FontCreator\unins000.exe"
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)-->C:\Windows\SysWOW64\msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)-->C:\Windows\SysWOW64\msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)-->C:\Windows\SysWOW64\msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)-->C:\Windows\SysWOW64\msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)-->C:\Windows\SysWOW64\msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=""
HTC Driver Installer-->MsiExec.exe /X{4CEEE5D0-F905-4688-B9F9-ECC710507796}
HTC Sync Manager-->MsiExec.exe /X{5DC3BFF3-B84F-4CBE-B2BD-FB52B6C247CA}
ICQ7M-->"C:\Program Files (x86)\InstallShield Installation Information\{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
IIS 8.0 Express-->MsiExec.exe /X{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}
IIS Express Application Compatibility Database for x64-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\Custom64\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb"
IIS Express Application Compatibility Database for x86-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb"
Integrated Camera Driver Installer Package Ver.1.2.1.18-->"C:\Program Files (x86)\InstallShield Installation Information\{A78800AF-1779-4AE8-8EBE-16E1BE727C71}\setup.exe" -runfromtemp -l0x001b anything -removeonly
Intel PROSet Wireless-->Intel PROSet Wireless
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed-->MsiExec.exe /X{37EC048A-81A2-452A-8D1F-3BE2018E767D}
Intel(R) USB 3.0 eXtensible Host Controller Driver-->C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Uninstall\setup.exe -uninstall
Intel® PROSet/Wireless WiFi Software-->MsiExec.exe /I{E97F409F-9E1C-42A0-B72D-765A78DF3696}
IPTInstaller-->MsiExec.exe /I{08208143-777D-4A06-BB54-71BF0AD1BB70}
Java 7 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217017FF}
JDownloader 0.9-->C:\Program Files (x86)\JDownloader\JDUninstall.exe
Lenovo Auto Scroll Utility-->rundll32.exe "C:\Program Files\Lenovo\VIRTSCRL\cleanup.dll",InfUninstall DefaultUninstall.LH 132 C:\Program Files\Lenovo\VIRTSCRL\tpdu_vs.inf
Lenovo Patch Utility 64 bit-->MsiExec.exe /X{0369F866-2CE0-4EB9-B426-88FA122C6E82}
Lenovo Patch Utility-->MsiExec.exe /X{6E6E7725-C7BC-4C39-8B3F-14B67331A120}
Lenovo Power Management Driver-->RunDll32.exe tpinspm.dll,Uninstall
LocalESPC-->MsiExec.exe /I{BDBE5D2A-AAB7-77BD-7A0E-5006665CE7C6}
LocalESPCui for en-us-->MsiExec.exe /I{B5DA9D49-9BD8-0F2F-52FC-C7E66BC8D944}
Microsoft .NET Framework 4 Multi-Targeting Pack-->MsiExec.exe /I{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}
Microsoft .NET Framework 4.5 Multi-Targeting Pack-->MsiExec.exe /X{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}
Microsoft .NET Framework 4.5 SDK-->MsiExec.exe /X{1948E039-EC79-4591-951D-9867A8C14C90}
Microsoft .NET Framework 4.5-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5-->MsiExec.exe /X{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}
Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update-->MsiExec.exe /X{2F6CE32A-018D-4656-895B-9E5E20D7740A}
Microsoft ASP.NET MVC 3-->MsiExec.exe /X{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}
Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools-->MsiExec.exe /X{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}
Microsoft ASP.NET MVC 4 Runtime-->MsiExec.exe /X{942CC691-5B98-42A3-8BC5-A246BA69D983}
Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools-->MsiExec.exe /X{6F066545-40A2-4C38-A8F7-78581CC5C442}
Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools-->MsiExec.exe /X{57D782D7-49FD-48DE-AB47-A690A1519A2D}
Microsoft ASP.NET Web Pages 2 Runtime-->MsiExec.exe /X{EA63C5C1-EBBC-477C-9CC7-41454DDFAFF2}
Microsoft ASP.NET Web Pages 2-->"C:\ProgramData\Package Cache\{cb29be6c-39c4-493e-9da7-d585d5353714}\AspNetWebPages2Setup.exe" /uninstall
Microsoft ASP.NET Web Pages-->MsiExec.exe /X{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}
Microsoft Help Viewer 2.0-->MsiExec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft Help Viewer 2.0-->msiexec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft LightSwitch for Visual Studio 2012 Core-->MsiExec.exe /I{7437A4B9-314F-3B8F-827B-22909146E471}
Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU-->MsiExec.exe /I{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}
Microsoft NuGet - Visual Studio 2012-->MsiExec.exe /I{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0015-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0016-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0018-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0019-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001B-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0405-1000-0000000FF1CE}" "{AEC2C00D-1E7E-45E3-9058-81EA2446B3CD}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0407-1000-0000000FF1CE}" "{70A3169E-288F-454F-A08D-20DF66639B50}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0409-1000-0000000FF1CE}" "{0242505C-4E90-407F-9299-B5B275F50D86}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-040E-1000-0000000FF1CE}" "{70A6C738-452C-4999-9780-B2C23339711D}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-041B-1000-0000000FF1CE}" "{4B806706-B352-42E8-8C8B-5CEBCEDBC4E0}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002C-041B-1000-0000000FF1CE}" "{8F7BCAD4-B6E7-485B-AA1A-F1D702A6A0CD}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-041B-1000-0000000FF1CE}" "{D5B1D4C9-AF5A-4653-AB6D-D8AFFBE363AC}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0044-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-041B-1000-0000000FF1CE}" "{4A62DCE9-94CF-491F-B8EF-B5E3396F2421}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00A1-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00BA-041B-1000-0000000FF1CE}" "{81C439F3-C0CB-4E02-B316-EFF566C1701B}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" "1051" "0"
Microsoft Office Access MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0015-041B-1000-0000000FF1CE}
Microsoft Office Excel MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0016-041B-1000-0000000FF1CE}
Microsoft Office Groove MUI (Slovak) 2010-->MsiExec.exe /X{90140000-00BA-041B-1000-0000000FF1CE}
Microsoft Office InfoPath MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0044-041B-1000-0000000FF1CE}
Microsoft Office Office 32-bit Components 2010-->MsiExec.exe /X{90140000-0043-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Slovak) 2010-->MsiExec.exe /X{90140000-00A1-041B-1000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2010-->MsiExec.exe /X{90140000-001A-041B-1000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0018-041B-1000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUSR /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{91140000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-1000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-1000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-1000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2010-->MsiExec.exe /X{90140000-001F-040E-1000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-1000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2010-->MsiExec.exe /X{90140000-002C-041B-1000-0000000FF1CE}
Microsoft Office Publisher MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0019-041B-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0043-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2010-->MsiExec.exe /X{90140000-006E-041B-1000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2010-->MsiExec.exe /X{90140000-001B-041B-1000-0000000FF1CE}
Microsoft Portable Library Multi-Targeting Pack Language Pack - enu-->MsiExec.exe /X{BAD0254F-9BDB-3D14-A5AC-9C0EF51F3D09}
Microsoft Portable Library Multi-Targeting Pack-->MsiExec.exe /X{C4CAD994-6EA2-3121-8352-DA593150B322}
Microsoft Report Viewer Add-On for Visual Studio 2012-->MsiExec.exe /I{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}
Microsoft Silverlight 4 SDK-->MsiExec.exe /X{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}
Microsoft Silverlight 5 SDK-->MsiExec.exe /X{E1FBB3D4-ADB0-4949-B101-855DA061C735}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2008 (64-bit)-->"C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x64\SetupARP.exe"
Microsoft SQL Server 2008 (64-bit)-->"C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x64\SetupARP.exe"
Microsoft SQL Server 2008 BI Development Studio-->MsiExec.exe /I{67C816AF-93F0-4C11-A355-AABC5FC00083}
Microsoft SQL Server 2008 BI Development Studio-->MsiExec.exe /I{AE479CE0-753F-49C0-B8E6-79A37403999F}
Microsoft SQL Server 2008 Browser-->MsiExec.exe /X{C688457E-03FD-4941-923B-A27F4D42A7DD}
Microsoft SQL Server 2008 Common Files-->MsiExec.exe /I{5340A3B5-3853-4745-BED2-DD9FF5371331}
Microsoft SQL Server 2008 Common Files-->MsiExec.exe /I{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}
Microsoft SQL Server 2008 Database Engine Services-->MsiExec.exe /I{FA7394B8-CE65-4F9E-AC99-F372AD365424}
Microsoft SQL Server 2008 Database Engine Services-->MsiExec.exe /I{FBD367D1-642F-47CF-B79B-9BE48FB34007}
Microsoft SQL Server 2008 Database Engine Shared-->MsiExec.exe /I{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}
Microsoft SQL Server 2008 Database Engine Shared-->MsiExec.exe /I{DF167CE3-60E7-44EA-99EC-2507C51F37AE}
Microsoft SQL Server 2008 Full text search-->MsiExec.exe /I{9DFA5914-C275-42E0-810E-C88E46A7F9EA}
Microsoft SQL Server 2008 Management Studio-->MsiExec.exe /I{0C6C4C8A-3B96-4681-90BA-0E15CDE96298}
Microsoft SQL Server 2008 Management Studio-->MsiExec.exe /I{108C8C1D-DA02-4A6C-94CD-5603F6A6FC72}
Microsoft SQL Server 2008 Policies-->MsiExec.exe /I{01C5A10F-AD9B-405B-853A-6659841A1242}
Microsoft SQL Server 2008 R2 Management Objects-->MsiExec.exe /I{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}
Microsoft SQL Server 2008 R2 Native Client-->MsiExec.exe /I{471AAD2C-9078-4DAC-BD43-FA10FB7C3FCE}
Microsoft SQL Server 2008 R2 Setup (English)-->MsiExec.exe /X{6D10FB2C-82A9-40F2-91D0-7BE64CF0DAF2}
Microsoft SQL Server 2008 Reporting Services-->MsiExec.exe /I{0C270C59-8706-42B8-A2AD-6E5EE18BC90B}
Microsoft SQL Server 2008 Reporting Services-->MsiExec.exe /I{2453DBC8-ACC4-4711-BD03-0C15353AA3D8}
Microsoft SQL Server 2008 RsFx Driver-->MsiExec.exe /I{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}
Microsoft SQL Server 2008 Setup Support Files -->MsiExec.exe /X{EE68E48C-4808-4918-BC35-17B1013B93AA}
Microsoft SQL Server 2012 Command Line Utilities -->MsiExec.exe /I{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{36E619BC-A234-4EC3-849B-779A7C865A45}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}
Microsoft SQL Server 2012 Express LocalDB -->MsiExec.exe /I{13D558FE-A863-402C-B115-160007277033}
Microsoft SQL Server 2012 Management Objects (x64)-->MsiExec.exe /I{FA0A244E-F3C2-4589-B42A-3D522DE79A42}
Microsoft SQL Server 2012 Management Objects -->MsiExec.exe /I{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}
Microsoft SQL Server 2012 Native Client -->MsiExec.exe /I{49D665A2-4C2A-476E-9AB8-FCC425F526FC}
Microsoft SQL Server 2012 Transact-SQL Compiler Service -->MsiExec.exe /I{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}
Microsoft SQL Server 2012 Transact-SQL ScriptDom -->MsiExec.exe /I{0E8670B8-3965-4930-ADA6-570348B67153}
Microsoft SQL Server 2012 T-SQL Language Service -->MsiExec.exe /I{6D6D43E5-218C-4B05-92D3-2240810F4760}
Microsoft SQL Server Compact 3.5 SP1 English-->MsiExec.exe /I{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}
Microsoft SQL Server Compact 3.5 SP1 Query Tools English-->MsiExec.exe /I{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}
Microsoft SQL Server Compact 4.0 SP1 Scripting Tools ENU CTP1-->MsiExec.exe /I{82284382-30E3-4DED-980B-746278DA6CC2}
Microsoft SQL Server Compact 4.0 SP1 x64 ENU-->MsiExec.exe /X{78909610-D229-459C-A936-25D92283D3FD}
Microsoft SQL Server Compact 4.0 Web Tools ENU-->MsiExec.exe /I{A51500FE-6408-4305-B071-B961F691A4CE}
Microsoft SQL Server Data Tools - enu (11.1.20627.00)-->MsiExec.exe /X{FA804794-2CCB-4301-954F-2C2894698876}
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)-->MsiExec.exe /X{790E9425-8570-493F-9AE7-81AFC9E46930}
Microsoft SQL Server System CLR Types (x64)-->MsiExec.exe /I{4701DEDE-1888-49E0-BAE5-857875924CA2}
Microsoft SQL Server System CLR Types-->MsiExec.exe /I{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{0826F9E4-787E-481D-83E0-BC6A57B056D5}
Microsoft Sync Framework Runtime v1.0 (x64)-->MsiExec.exe /I{53D7A054-4598-4947-A159-E8FCC77720AB}
Microsoft Sync Services for ADO.NET v2.0 (x64)-->MsiExec.exe /I{817BCC2B-76A8-4C8B-8B55-FD916C6969CC}
Microsoft System CLR Types for SQL Server 2012 (x64)-->MsiExec.exe /I{F1949145-EB64-4DE7-9D81-E6D27937146C}
Microsoft System CLR Types for SQL Server 2012-->MsiExec.exe /I{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727-->MsiExec.exe /X{D9F3D00D-E946-3B3D-A4A6-93D5020DB9F7}
Microsoft Visual C++ 2012 Compilers - ENU Resources-->MsiExec.exe /X{A4366F69-CE22-4DB7-9C8C-46A5845AF997}
Microsoft Visual C++ 2012 Compilers-->MsiExec.exe /X{1F8E06E2-BA93-40DC-B183-E024CBD853A8}
Microsoft Visual C++ 2012 Core Libraries-->MsiExec.exe /X{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}
Microsoft Visual C++ 2012 Extended Libraries-->MsiExec.exe /X{731C183B-86A0-3442-BE55-68A7C92581E9}
Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries-->MsiExec.exe /X{29F259D7-C517-3EED-84B4-237573CFD39C}
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727-->MsiExec.exe /X{2B997E80-3BEC-3222-9114-98DBE1182B2E}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727-->MsiExec.exe /X{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}
Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727-->MsiExec.exe /X{1C163D33-33B3-33EB-A617-0D4D852BE8E1}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual Studio 2008 Shell (integrated mode) - ENU-->MsiExec.exe /I{BA0C9AAF-1327-3F06-B49C-349B4BE8F740}
Microsoft Visual Studio 2010 Office Developer Tools (x64)-->MsiExec.exe /X{572E796D-C52B-3797-A685-2FB6F895D4BE}
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)\install.exe
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->MsiExec.exe /X{B143BE44-8723-315E-9413-011C55873C0E}
Microsoft Visual Studio 2012 Devenv Resources-->MsiExec.exe /I{B1465D1D-6427-4CA1-AE29-8B699209E663}
Microsoft Visual Studio 2012 Devenv-->MsiExec.exe /I{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}
Microsoft Visual Studio 2012 IntelliTrace Core amd64-->MsiExec.exe /I{6AAF4427-3039-4C8A-BE53-D6F01C21AD46}
Microsoft Visual Studio 2012 IntelliTrace Core x86-->MsiExec.exe /I{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}
Microsoft Visual Studio 2012 IntelliTrace Front End x86-->MsiExec.exe /I{D971780F-A609-4F78-92AA-B56FBC3955B9}
Microsoft Visual Studio 2012 Performance Collection Tools - ENU-->MsiExec.exe /I{FE74AC04-F248-4641-B3A9-89C6AA4339CD}
Microsoft Visual Studio 2012 Performance Collection Tools-->MsiExec.exe /I{633AB014-DDE6-403E-A302-8920CC32C543}
Microsoft Visual Studio 2012 Preparation-->MsiExec.exe /I{246B0F46-F84E-4857-8C47-F2A86B598BC5}
Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack-->MsiExec.exe /X{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}
Microsoft Visual Studio 2012 SharePoint Developer Tools-->MsiExec.exe /X{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}
Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies-->MsiExec.exe /I{820C677A-41B2-48C3-8136-FEE35A052E73}
Microsoft Visual Studio 2012 Shell (Minimum) Resources-->MsiExec.exe /I{38FC6E9A-F719-431A-A83D-4C86D5FD6555}
Microsoft Visual Studio 2012 Shell (Minimum)-->MsiExec.exe /I{800F484E-9D69-492D-B656-7BAA32586142}
Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU-->MsiExec.exe /I{E818AE7C-244B-4A50-9C86-C0E4A8B69159}
Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU-->MsiExec.exe /I{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}
Microsoft Visual Studio Team Foundation Server 2012 Object Model-->MsiExec.exe /I{6F07A6C2-9068-3673-A120-DC10012468C6}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU-->MsiExec.exe /I{55EFD1A6-ED8E-3A4C-9581-5E1A1FF244CD}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding-->MsiExec.exe /I{28D85F24-B685-3364-BB7C-284C88C2FFE5}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU-->MsiExec.exe /I{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer-->MsiExec.exe /I{6DAB46E3-D017-3E2B-85D8-F57A230384C0}
Microsoft Visual Studio Tools for Applications 2.0 - ENU-->MsiExec.exe /X{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}
Microsoft Visual Studio Ultimate 2012-->"C:\ProgramData\Package Cache\{e238e1a0-7fbd-4146-a4ac-d48badcdf3ae}\vs_ultimate.exe" /uninstall
Microsoft Web Deploy 3.0-->MsiExec.exe /I{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}
Microsoft Web Deploy dbSqlPackage Provider - enu-->MsiExec.exe /X{E4C33F5B-1B2F-466E-957E-B274F08151A0}
Microsoft Web Developer Tools - Visual Studio 2012-->MsiExec.exe /I{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}
Microsoft Web Platform Installer 4.0-->MsiExec.exe /X{39960E10-3FF7-46BB-A92D-8076C67ABF60}
Microsoft WebMatrix 2-->MsiExec.exe /X{FCBF1750-6A2D-4A4E-AAE2-DDAEA0744DAE}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Mozilla Firefox 19.0.2 (x86 sk)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
Mozilla Maintenance Service-->"C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MySQL Connector Net 6.5.4-->MsiExec.exe /I{92E19B5A-1985-49BF-9022-9CF4AD652C72}
On Screen Display-->rundll32.exe "C:\Program Files\Lenovo\HOTKEY\cleanup.dll",InfUninstall DefaultUninstall.LH 132 C:\Program Files\Lenovo\HOTKEY\tphk_tp.inf
Opera 12.14-->"C:\Program Files (x86)\Opera\Opera.exe" /uninstall
OSCAR Editor-->MsiExec.exe /I{3C2379D2-337A-4FFA-9017-BDFB80EC0931}
PDF Settings CS6-->MsiExec.exe /I{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}
Power Manager-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.exe" -l0x9 -AddRemove
PreEmptive Analytics Visual Studio Components-->MsiExec.exe /X{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}
Prerequisites for SSDT -->MsiExec.exe /I{9169C939-ED01-446A-BD0C-29873BAF4E48}
Rainmeter-->C:\Program Files\Rainmeter\uninst.exe
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek PCIE Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{C1594429-8296-4652-BF54-9DBE4932A44C}\setup.exe" -runfromtemp -removeonly
Search Assistant WebSearch 1.74-->"C:\Program Files (x86)\WebSearch\uninstall.exe" /FULLPATH="C:\Program Files (x86)\WebSearch"
Security Update for Microsoft .NET Framework 4.5 (KB2737083)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {00909A54-CC11-3F00-9279-3CE090432A91}
Security Update for Microsoft .NET Framework 4.5 (KB2742613)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {36E5C79E-06D3-32C3-9251-D284B9F3F7E7}
Security Update for Microsoft .NET Framework 4.5 (KB2789648)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {698F9EB6-6753-318E-8615-53D77414313F}
Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{D2EC0616-5207-48E4-8AC2-478F107EF383}" "1051" "0"
Security Update for Microsoft InfoPath 2010 (KB2687417) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{CE5FC4A7-94EC-40C7-B292-673DBA671209}" "1051" "0"
Security Update for Microsoft InfoPath 2010 (KB2687436) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{5131017A-63D7-4B4D-9A15-C704C91177B2}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2553091)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{527AC538-7A51-40A5-89D7-5C1FEBBEA4C3}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2553096)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{C4BF81CC-3786-4CE4-9D9F-DD393678B9EC}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{0F6C4F72-6084-437B-9B35-F59B09E3C1B0}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{7C04E5C7-C747-43DE-B648-09B97811D93E}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{297E6E47-5F6E-4DD8-B880-75944B5C1C7C}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{2B4B504B-6620-4FFD-94CB-3D640AB3FCD2}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2687501) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{19B568F6-93AF-4C11-A085-7277ADEF8F04}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2687501) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{19B568F6-93AF-4C11-A085-7277ADEF8F04}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2687510) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{9DAE52D2-834F-4743-ABF7-DEBAB9A932E5}" "1051" "0"
Security Update for Microsoft Visio 2010 (KB2687508) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{89993390-4A0D-4351-91E0-B43E20F5617D}" "1051" "0"
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{36B568AE-78F1-45EF-A7BF-EF0419904A21}" "1051" "0"
Security Update for Microsoft Word 2010 (KB2760410) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{000B67CC-2C25-46AA-8D02-752BB0DD6D86}" "1051" "0"
Service Pack 3 for SQL Server 2008 (KB2546951) (64-bit)-->"C:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\setup.exe" /Action=RemovePatch /AllInstances
SimilarSites-->C:\Program Files (x86)\SimilarSites\uninstall.exe
Skype™ 6.1-->MsiExec.exe /X{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
Spybot - Search & Destroy-->"C:\Program Files (x86)\Spybot - Search & Destroy\unins000.exe"
Sql Server Customer Experience Improvement Program-->MsiExec.exe /I{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}
Sublime Text 2.0.1-->"C:\Program Files\Sublime Text 2\unins000.exe"
TeamViewer 8-->C:\Program Files (x86)\TeamViewer\Version8\uninstall.exe
ThinkPad UltraNav Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Total Commander 64-bit (Remove or Repair)-->c:\totalcmd\tcunin64.exe
Update for (KB2504637)-->C:\Windows\SysWOW64\msiexec.exe /package {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE} /uninstall {815F0BC1-7E54-300C-9ACA-C9460FDF6F78} /qb+ REBOOTPROMPT=""
Update for Microsoft .NET Framework 4.5 (KB2750147)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\setup.exe /uninstallpatch {BEBBFEB1-EA1C-3479-A39D-23A76BCB7BFC}
Update for Microsoft Office 2010 (KB2553065)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{57CEB66B-DD29-4883-92A2-671331657B52}" "1051" "0"
Update for Microsoft Office 2010 (KB2553092)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0044-041B-1000-0000000FF1CE}" "{E636FE63-842B-4F4B-9884-DA189ACC0B91}" "1051" "0"
Update for Microsoft Office 2010 (KB2553092)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{E636FE63-842B-4F4B-9884-DA189ACC0B91}" "1051" "0"
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{E24F10E6-7D9B-4E3A-B6CF-4C3257A382CD}" "1051" "0"
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{E24F10E6-7D9B-4E3A-B6CF-4C3257A382CD}" "1051" "0"
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{3E381AC3-30C3-41D7-9B27-B3F3E17BDCB8}" "1051" "0"
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-041B-1000-0000000FF1CE}" "{AB834256-CB7C-46B3-9D53-CF1742BBC21D}" "1051" "0"
Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{CABC3FE9-02BD-47C8-8576-EA3E8BB1BE1A}" "1051" "0"
Update for Microsoft Office 2010 (KB2566458)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{A6C194EA-C6CB-4314-9E43-AD1F4A1E9D74}" "1051" "0"
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0405-1000-0000000FF1CE}" "{2B00A738-659A-4E52-9391-D334FA0E64CB}" "1051" "0"
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0407-1000-0000000FF1CE}" "{2D507B6C-B472-447F-B61F-8EF54D9893A5}" "1051" "0"
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0409-1000-0000000FF1CE}" "{A8EC00BF-EDF5-46F0-B466-C4312722D8F3}" "1051" "0"
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{7750DF63-F5DC-4198-8B8B-AE03B212F462}" "1051" "0"
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{7750DF63-F5DC-4198-8B8B-AE03B212F462}" "1051" "0"
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{B6AD7E27-012A-4B63-82BA-AF62893E5435}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00A1-041B-1000-0000000FF1CE}" "{E48FF507-2CD8-4574-99B1-DC0BE8CC19A0}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2687277) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{A3E1581D-1628-43DB-98B6-84ACE7E74AAD}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2687277) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{A3E1581D-1628-43DB-98B6-84ACE7E74AAD}" "1051" "0"
Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{0977F620-BD31-41EC-B18C-31E341D5935E}" "1051" "0"
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-1000-0000000FF1CE}" "{4E854C1C-590F-4B1C-A524-79782A2D99F8}" "1051" "0"
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-1000-0000000FF1CE}" "{C3F39DA8-301B-4212-B8C1-05FBB5C666B0}" "1051" "0"
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{7861C766-2AA2-4A50-AB75-A57D451CEA76}" "1051" "0"
Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{AF61D314-0E39-485E-A603-2B2F03AB7376}" "1051" "0"
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0043-0000-1000-0000000FF1CE}" "{E1757044-ECB2-4551-B1D5-5E39F7E109CE}" "1051" "0"
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-1000-0000000FF1CE}" "{E1757044-ECB2-4551-B1D5-5E39F7E109CE}" "1051" "0"
Update for Microsoft Visual Studio 2012 (KB2781514)-->"C:\ProgramData\Package Cache\{3786efc1-59ff-4908-8cd6-dc85ec87209e}\patch_KB2781514.exe" /uninstall
VirtualCloneDrive-->"C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive"
Visual Studio 2012 Prerequisites - ENU Language Pack-->MsiExec.exe /X{13417784-A359-3CDD-8DE1-B7108707D647}
Visual Studio 2012 Prerequisites-->MsiExec.exe /X{61862D7C-CDBC-48D5-8AE1-3B8BD1E23BC5}
Visual Studio Extensions for Windows Library for JavaScript-->MsiExec.exe /I{89B4532E-19CE-4FA9-9692-10BFD5A38532}
VLC media player 2.0.5-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
WampServer 2.2-->"c:\wamp\unins000.exe"
WCF Data Services 5.0 (for OData v3) Primary Components-->MsiExec.exe /I{0BCC836F-0B28-4090-B58A-64883BAA3B2F}
WCF Data Services Tools for Microsoft Visual Studio 2012-->MsiExec.exe /I{148878BD-A2A5-4CF1-A103-2BA632F41953}
WCF RIA Services V1.0 SP2-->MsiExec.exe /X{3A523AF9-D32F-4C85-8388-0335731F3405}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows App Certification Kit Native Components-->MsiExec.exe /I{3FA063D7-EDC1-AFA8-54AF-0563C7DEE070}
Windows App Certification Kit x64-->MsiExec.exe /I{02213A81-CB13-7262-5ABE-1FFA2C75559F}
Windows Runtime Intellisense Content - en-us-->MsiExec.exe /I{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}
Windows Software Development Kit DirectX x64 Remote-->MsiExec.exe /I{5FB4C443-6BD6-1514-2717-3827D65AE6FB}
Windows Software Development Kit DirectX x86 Remote-->MsiExec.exe /I{23176E97-26CB-C72A-19EB-BFB21AC1D15A}
Windows Software Development Kit for Windows Store Apps DirectX x64 Remote-->MsiExec.exe /I{27EF252D-800C-ED42-9904-459FE0046225}
Windows Software Development Kit for Windows Store Apps DirectX x86 Remote-->MsiExec.exe /I{42F61556-29ED-8122-F39E-6F04EA5FF279}
Windows Software Development Kit for Windows Store Apps-->MsiExec.exe /I{D11F66FF-82B3-DDB8-1146-525370552BE1}
Windows Software Development Kit-->MsiExec.exe /I{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}
WinRAR 4.20 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
X7 Oscar Editor-->"C:\Program Files (x86)\InstallShield Installation Information\{3C2379D2-337A-4FFA-9017-BDFB80EC0931}\setup.exe" -runfromtemp -l0x0409 -removeonly
XnView 1.99.6-->"C:\Program Files (x86)\XnView\unins000.exe"

======Hosts File======

127.0.0.1 192.150.14.69
127.0.0.1 192.150.18.101
127.0.0.1 192.150.18.108
127.0.0.1 192.150.22.40
127.0.0.1 192.150.8.100
127.0.0.1 192.150.8.118

======System event log======

Computer Name: kicker-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR1.
Record Number: 476
Source Name: Disk
Time Written: 20121225180406.246303-000
Event Type: Error
User:

Computer Name: kicker-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR1.
Record Number: 474
Source Name: Disk
Time Written: 20121225180405.731502-000
Event Type: Error
User:

Computer Name: kicker-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR1.
Record Number: 467
Source Name: Disk
Time Written: 20121225180403.953099-000
Event Type: Error
User:

Computer Name: kicker-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR1.
Record Number: 462
Source Name: Disk
Time Written: 20121225180402.923498-000
Event Type: Error
User:

Computer Name: kicker-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR1.
Record Number: 460
Source Name: Disk
Time Written: 20121225180402.408697-000
Event Type: Error
User:

=====Application event log=====

Computer Name: kicker-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 198
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20121225175609.050657-000
Event Type: Error
User: NT AUTHORITY\SYSTEM

Computer Name: kicker-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.

Record Number: 101
Source Name: Microsoft-Windows-Search
Time Written: 20121225175206.000000-000
Event Type: Warning
User:

Computer Name: 37L4247E29-32
Event Code: 257
Message: Službe Cryptographic Services sa nepodarilo inicializovať databázu katalógu. Chyba ESENT: -546.
Record Number: 7
Source Name: Microsoft-Windows-CAPI2
Time Written: 20121225174459.576921-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (356) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 6
Source Name: ESENT
Time Written: 20121225174459.000000-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (356) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 5
Source Name: ESENT
Time Written: 20121225174459.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: 37L4247E29-32
Event Code: 4735
Message: A security-enabled local group was changed.

Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin

Changed Attributes:
SAM Account Name: -
SID History: -

Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121225174419.126050-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4731
Message: A security-enabled local group was created.

Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7

New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin

Attributes:
SAM Account Name: Backup Operators
SID History: -

Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121225174419.126050-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: The Per-user audit policy table was created.

Number of Elements: 0
Policy ID: 0x2fec0
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121225174418.642449-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 0

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x4
Process Name:

Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121225174416.208845-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20121225174416.162045-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Lenovo Fingerprint Reader\;C:\Program Files\Lenovo Fingerprint Reader\x86;C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\Driver;;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files (x86)\Windows Kits\8.0\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=2a07
"VS110COMNTOOLS"=C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\Tools\

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#8 Příspěvek od vyosek »

My se tu firemnimi PC nezabyvame, od toho jsou ve firme spravci...navic jak pisete, jste IT firma, spravce by mel byt defakto podminkou. Pravidla fora hovori zcela jasne http://forum.viry.cz/viewtopic.php?f=12&t=5601
6. Fórum viry.cz se nezabývá odvirováním firemních PC - na toto jsou ve firmách placení (a někdy až hodně nadstandardně) IT technici, případně si je firma může najmou. My jsme tu zdarma a ve svém volném čase, nehodláme dělat práci za někoho jiného, kdo si pak jen slízne smetánku a plat. Taktéž ani neposkytujeme poradenství v oblasti zabezpečení firemních sítí či nastavení firemních sítí. Zkrátka a jednoduše, naše fórum poskytuje podporu domácím uživatelům.
Takze to predejte IT spravci, pokud jej nemate, tak je to pak veci managementu irmy, jak se k tomu postavi...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#9 Příspěvek od Kicker »

Sme tu živnostníci, PC nie je firemný, ale môj, ja si teoreticky len prenajímam firemný software. Správcu nemáme, dúfal som, že mi budete vedieť pomôcť.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#10 Příspěvek od vyosek »

:arrow: No dobra tedy, vysvetleni beru

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Search
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#11 Příspěvek od Kicker »

# AdwCleaner v2.114 - Logfile created 03/13/2013 at 14:42:45
# Updated 05/03/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : .kicker - KICKER-PC
# Boot Mode : Normal
# Running from : C:\Users\.kicker\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Users\.kicker\AppData\Roaming\Mozilla\Firefox\Profiles\2dewnnbv.default\searchplugins\WebSearch.xml
Folder Found : C:\Program Files (x86)\SimilarSites
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\SimilarSites
Folder Found : C:\Users\.kicker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl
Folder Found : C:\Users\.kicker\AppData\Roaming\Advanced System Protector
Folder Found : C:\Users\.kicker\AppData\Roaming\SimilarSites

***** [Registry] *****

Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\browse~1\sprote~1.dll
Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\websea~1\sprote~1.dll
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{807DF5E0-4EF7-48A8-A405-239F3E29FFA9}
Key Found : HKLM\Software\SimilarSites
Key Found : HKLM\Software\SP Global
Key Found : HKLM\Software\SProtector
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SimilarSites
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Key Found : HKU\S-1-5-21-1483512043-290947922-3062225937-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16464

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK

-\\ Mozilla Firefox v19.0.2 (sk)

File : C:\Users\.kicker\AppData\Roaming\Mozilla\Firefox\Profiles\2dewnnbv.default\prefs.js

Found : user_pref("aol_toolbar.default.homepage.check", false);
Found : user_pref("aol_toolbar.default.search.check", false);
Found : user_pref("browser.search.defaultenginename", "WebSearch");
Found : user_pref("browser.search.defaultenginename,S", "WebSearch");
Found : user_pref("browser.search.defaulturl", "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=2[...]
Found : user_pref("browser.search.order.1", "WebSearch");
Found : user_pref("browser.search.order.1,S", "WebSearch");
Found : user_pref("browser.search.selectedEngine", "WebSearch");
Found : user_pref("browser.search.selectedEngine,S", "WebSearch");
Found : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Found : user_pref("sweetim.toolbar.searchguard.enable", "");

-\\ Google Chrome v25.0.1364.152

File : C:\Users\.kicker\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.31] : icon_url = "hxxp://websearch.pu-results.info/favicon.ico",
Found [l.34] : keyword = "websearch",
Found [l.37] : search_url = "hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK",
Found [l.38] : suggest_url = "hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK"
Found [l.1969] : homepage = "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK",
Found [l.2307] : urls_to_restore_on_startup = [ "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK" ]

-\\ Opera v12.14.1738.0

File : C:\Users\.kicker\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [5813 octets] - [13/03/2013 14:42:45]

########## EOF - C:\AdwCleaner[R1].txt - [5873 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#12 Příspěvek od vyosek »

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Delete
  • PC provede opravu, restartuje se a da Vam log (C:\AdwCleaner [S1].txt) , jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#13 Příspěvek od Kicker »

# AdwCleaner v2.114 - Logfile created 03/13/2013 at 14:51:15
# Updated 05/03/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : .kicker - KICKER-PC
# Boot Mode : Normal
# Running from : C:\Users\.kicker\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Users\.kicker\AppData\Roaming\Mozilla\Firefox\Profiles\2dewnnbv.default\searchplugins\WebSearch.xml
Folder Deleted : C:\Program Files (x86)\SimilarSites
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\SimilarSites
Folder Deleted : C:\Users\.kicker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl
Folder Deleted : C:\Users\.kicker\AppData\Roaming\Advanced System Protector
Folder Deleted : C:\Users\.kicker\AppData\Roaming\SimilarSites

***** [Registry] *****

Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\browse~1\sprote~1.dll
Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\websea~1\sprote~1.dll
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{807DF5E0-4EF7-48A8-A405-239F3E29FFA9}
Key Deleted : HKLM\Software\SimilarSites
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SimilarSites
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16464

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK --> hxxp://www.google.com

-\\ Mozilla Firefox v19.0.2 (sk)

File : C:\Users\.kicker\AppData\Roaming\Mozilla\Firefox\Profiles\2dewnnbv.default\prefs.js

Deleted : user_pref("aol_toolbar.default.homepage.check", false);
Deleted : user_pref("aol_toolbar.default.search.check", false);
Deleted : user_pref("browser.search.defaultenginename", "WebSearch");
Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=2[...]
Deleted : user_pref("browser.search.order.1", "WebSearch");
Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Deleted : user_pref("sweetim.toolbar.searchguard.enable", "");

-\\ Google Chrome v25.0.1364.152

File : C:\Users\.kicker\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.31] : icon_url = "hxxp://websearch.pu-results.info/favicon.ico",
Deleted [l.34] : keyword = "websearch",
Deleted [l.37] : search_url = "hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=726&r=2013/03/06&hid=[...]
Deleted [l.38] : suggest_url = "hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=726&r=2013/03/06&hid[...]
Deleted [l.1969] : homepage = "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24132936&lg=EN&cc=SK",
Deleted [l.2307] : urls_to_restore_on_startup = [ "hxxp://websearch.pu-results.info/?pid=726&r=2013/03/06&hid=24[...]

-\\ Opera v12.14.1738.0

File : C:\Users\.kicker\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [5936 octets] - [13/03/2013 14:42:45]
AdwCleaner[R2].txt - [5930 octets] - [13/03/2013 14:49:36]
AdwCleaner[S1].txt - [319 octets] - [13/03/2013 14:51:03]
AdwCleaner[S2].txt - [5906 octets] - [13/03/2013 14:51:15]

########## EOF - C:\AdwCleaner[S2].txt - [5966 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: nedobytná háveď v PC

#14 Příspěvek od vyosek »

:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kicker
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 13 bře 2013 13:25

Re: nedobytná háveď v PC

#15 Příspěvek od Kicker »

Malwarebytes Anti-Malware (Skúšobná verzia) 1.70.0.1100
www.malwarebytes.org

Verzia databázy: v2013.03.13.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
.kicker :: KICKER-PC [administrátor]

Ochrana: Zapnuté

13. 3. 2013 15:10:05
MBAM-log-2013-03-13 (16-17-18).txt

Typ kontroly: Úplná kontrola (C:\|)
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 492859
Uplynutý čas: 1 hod, 6 min, 36 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 0
(Škodlivé položky neboli zistené)

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 0
(Škodlivé položky neboli zistené)

(koniec)

Zamčeno