Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Automatické otevírání nových záložek s reklamami

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Automatické otevírání nových záložek s reklamami

#1 Příspěvek od Blicek »

Dobrý den,

nedávno (asi tak před třemi dny) se mi začaly otevírat nové záložky, víceméně jen reklamního typu. Je to docela otravné, moc byste mi pomohli :-)

Předem děkuji

. Logfile of random's system information tool 1.10 (written by random/random)
Run by HONZA at 2014-11-16 17:42:42
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 56 GB (12%) free of 477 GB
Total RAM: 12287 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:42:54, on 16.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\LuckyTab\LuckyTab.exe
C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\HONZA.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5193
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (file missing)
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss
O4 - HKCU\..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
O4 - HKCU\..\Run: [Google Update] "C:\Users\HONZA\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Remote Control.lnk = C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11111 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
taskeng.exe {9736A810-F665-415C-A684-DB65249EC4DE}
"C:\Program Files (x86)\LuckyTab\LuckyTab.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\wuauclt.exe"
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3592.0.718717650\1078727814" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.2.482898606\973140415" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.4.1569862924\486551061" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.5.647056719\1290875154" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.11.1758706136\34952811" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.17.2041229923\160709974" /prefetch:673131151

"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.30.1385361178\540334093" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3592.31.526908793\1661379805" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
taskeng.exe {6217041B-E555-401E-B2B5-933CC5D0B306}
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.36.36141809\434114657" /prefetch:673131151
"C:\Users\HONZA\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group11 pct:1b stable:r1 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3592.37.2044769097\595195992" /prefetch:673131151
"C:\Users\HONZA\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job - C:\Users\HONZA\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job - C:\Users\HONZA\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-11-15 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-29 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-15 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-11 3672384]
"SpeedUpMyComputer"=C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss []
"FixMyRegistry"=C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss []
"Google Update"=C:\Users\HONZA\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-16 116648]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2010-03-05 411864]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-11-15 5225064]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotSnD"=C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 5365592]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Remote Control.lnk - C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe

C:\Users\HONZA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2014-11-16 17:42:42 ----D---- C:\rsit
2014-11-16 17:42:42 ----D---- C:\Program Files\trend micro
2014-11-16 14:18:08 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-11-16 14:18:08 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2014-11-15 00:04:06 ----D---- C:\Users\HONZA\AppData\Roaming\AVAST Software
2014-11-15 00:03:30 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-11-15 00:03:29 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2014-11-15 00:03:29 ----A---- C:\Windows\system32\drivers\aswSP.sys
2014-11-15 00:03:28 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2014-11-15 00:03:27 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2014-11-15 00:03:25 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-11-15 00:03:25 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-11-15 00:03:22 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2014-11-15 00:03:19 ----A---- C:\Windows\system32\aswBoot.exe
2014-11-15 00:03:14 ----A---- C:\Windows\avastSS.scr
2014-11-15 00:01:13 ----D---- C:\Program Files\AVAST Software
2014-11-15 00:00:12 ----D---- C:\ProgramData\AVAST Software
2014-10-26 09:31:06 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-10-26 09:31:00 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-10-26 09:31:00 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-10-26 09:31:00 ----A---- C:\Windows\SYSWOW64\java.exe
2014-10-23 19:05:19 ----D---- C:\Program Files (x86)\LuckyTab

======List of files/folders modified in the last 1 month======

2014-11-16 17:42:54 ----D---- C:\Windows\Prefetch
2014-11-16 17:42:48 ----D---- C:\Windows\Temp
2014-11-16 17:42:42 ----RD---- C:\Program Files
2014-11-16 16:25:30 ----D---- C:\Windows\system32\NDF
2014-11-16 15:07:10 ----D---- C:\Users\HONZA\AppData\Roaming\uTorrent
2014-11-16 15:07:10 ----D---- C:\Program Files (x86)\Steam
2014-11-16 15:06:53 ----D---- C:\Windows\inf
2014-11-16 15:06:51 ----D---- C:\Windows\Logs
2014-11-16 15:06:51 ----D---- C:\Windows
2014-11-16 14:18:08 ----RD---- C:\Program Files (x86)
2014-11-16 14:18:08 ----HD---- C:\ProgramData
2014-11-16 10:47:25 ----D---- C:\Windows\system32\config
2014-11-16 10:37:00 ----D---- C:\Windows\System32
2014-11-16 10:37:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-15 23:01:23 ----D---- C:\Windows\Tasks
2014-11-15 09:45:02 ----SHD---- C:\Windows\Installer
2014-11-15 09:07:09 ----D---- C:\ProgramData\MFAData
2014-11-15 00:10:31 ----SHD---- C:\System Volume Information
2014-11-15 00:09:58 ----D---- C:\Windows\system32\drivers
2014-11-15 00:06:33 ----D---- C:\Windows\SYSWOW64\drivers
2014-11-15 00:03:41 ----D---- C:\Windows\system32\Tasks
2014-11-15 00:03:20 ----D---- C:\Windows\winsxs
2014-11-14 21:43:37 ----D---- C:\Users\HONZA\AppData\Roaming\TS3Client
2014-11-12 18:26:48 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-11-11 23:38:35 ----D---- C:\Windows\SysWOW64
2014-10-31 16:53:42 ----D---- C:\Program Files (x86)\Hearthstone
2014-10-31 14:05:02 ----D---- C:\Users\HONZA\AppData\Roaming\Dropbox
2014-10-28 10:31:40 ----D---- C:\Users\HONZA\AppData\Roaming\Skype
2014-10-26 09:31:21 ----D---- C:\ProgramData\Oracle
2014-10-26 09:31:16 ----D---- C:\Program Files (x86)\Common Files
2014-10-26 09:30:55 ----D---- C:\Program Files (x86)\Java
2014-10-25 09:19:10 ----D---- C:\Windows\system32\catroot2
2014-10-24 14:07:27 ----D---- C:\Program Files (x86)\StarCraft II
2014-10-24 14:03:39 ----D---- C:\Program Files (x86)\Battle.net
2014-10-20 21:05:14 ----D---- C:\ProgramData\Skype
2014-10-20 21:05:11 ----RD---- C:\Program Files (x86)\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-15 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-15 267632]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-15 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-15 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-15 436624]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-05-18 283200]
R2 AODDriver4.01;AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-15 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-15 83280]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-15 116728]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 626176]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-07-06 2419176]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
R3 Ph3xIB64;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB64.sys [2009-06-10 1627520]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
S2 sbapifs;sbapifs; C:\Windows\system32\DRIVERS\sbapifs.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552]
S3 gfiark;gfiark; C:\Windows\system32\drivers\gfiark.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\system32\drivers\Synth3dVsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VGPU;VGPU; C:\Windows\system32\drivers\VGPU.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-15 50344]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-02-17 4915040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-02 116648]
S2 SBSDWSCService;SBSD Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-12 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-02 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-07-02 529232]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2013-11-06 758224]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#2 Příspěvek od Rudy »

Zdravím!
Jak je na tom váš oper. systém s legalitou?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#3 Příspěvek od Blicek »

Operační systém mi instaloval známý a ukazuje mi to, že to mám legální.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#4 Příspěvek od Rudy »

OK. Zkusíme následující postup:

Stáhněte a spusťte OTL: http://oldtimer.geekstogo.com/OTL.exe . Spusťte, zaškrněte "Pro všechny uživatele", Kontrola na havěť LOP" a Kontrola na hvěť PURITY" a do dolního bílého okna zkopírujte:
CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
services.exe
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s

%PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
%PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
%PROGRAMFILES%\Opera\opera.exe /md5
%PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5

%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
a klikněte na >Prohledat<. Dejte oba logy.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#5 Příspěvek od Blicek »

OTL Extras logfile created on: 18.11.2014 21:18:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HONZA\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

12,00 Gb Total Physical Memory | 9,46 Gb Available Physical Memory | 78,82% Memory free
18,00 Gb Paging File | 15,10 Gb Available in Paging File | 83,94% Paging File free
Paging file location(s): C:\pagefile.sys 6142 6142 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 54,27 Gb Free Space | 11,65% Space Free | Partition Type: NTFS
Drive F: | 5,13 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: HONZA-PC | User Name: HONZA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{009FE8C2-1632-42CA-8A45-CCCD07D92416}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{115896F9-92D6-4B9F-8889-DB9E877E495E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{16FB659E-36D0-425F-8116-2085174367ED}" = rport=139 | protocol=6 | dir=out | app=system |
"{1D19FAC7-23B5-41B3-B3A4-DAB2F7FDEAF6}" = lport=445 | protocol=6 | dir=in | app=system |
"{206BA5A0-7B27-417B-8AE9-47E9CE9C6155}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{212F71E0-9C7C-4BBB-91BE-1ADA5045E10C}" = lport=139 | protocol=6 | dir=in | app=system |
"{29D02B2B-AA54-4C35-93B2-1030490F29B9}" = rport=80 | protocol=6 | dir=out | app=c:\users\honza\appdata\local\warframe\downloaded\public\tools\launcher.exe |
"{2C46D8BD-D111-4825-9F96-6E3BB95DEDD0}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\warframe\downloaded\public\warframe.x64.exe |
"{3373190B-314C-4493-AB46-920145616C7E}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{3B36CFA5-FC85-4756-A417-1042F51E647D}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\warframe\downloaded\public\warframe.exe |
"{443422D5-FCC8-44B6-B44F-6F14E14C358E}" = lport=138 | protocol=17 | dir=in | app=system |
"{4600F608-7372-44F7-B096-1D245AE7B249}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4DC2E0B8-498E-4D83-8CA9-AFB69DB2B7EE}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5005FEF6-FAB8-4CDB-AE9E-CCA2EA2FBF64}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{50373F2A-F831-4720-9948-73F9EEF400C3}" = rport=138 | protocol=17 | dir=out | app=system |
"{5312397A-7E8E-46A9-9AE5-43B2AADB5F25}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{5449EF47-8A32-4795-9BB3-9A5BEABE5C97}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5592CF17-2151-4FAC-824A-BEB9FABD1BD5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{58B2489F-49FC-4414-80F1-5D08075B14F4}" = rport=137 | protocol=17 | dir=out | app=system |
"{58F3AF80-4665-45FC-977F-2A5D71F26FAA}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5CD11E62-2424-4EB1-B605-874955DA7E31}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{63B58ED6-60D1-4D34-B93E-4AF4584CB606}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{6ACBBCC4-C0FE-492C-89F2-5228D715A1CE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6CD4C6AD-FF06-4E4C-8CC1-67D2FF2EA39A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{71B17E3E-72BB-46F6-8032-BA2E1FF114C7}" = rport=2869 | protocol=6 | dir=out | app=system |
"{76412588-92BC-49FD-B6CE-4D7FA5C75BF1}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7C23E899-5758-4E25-B9E8-6FB77913BA02}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7CCCEEA0-2799-4AA8-AFE4-4448EA87A8C3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{7E2155A8-4644-45A7-9A18-8D4D2E20C60C}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7EF18D95-FEF2-434F-AB7A-A7BF5C1AE5EE}" = rport=80 | protocol=6 | dir=out | app=c:\users\honza\appdata\local\warframe\downloaded\public\tools\remotecrashsender.exe |
"{7F70257A-193D-4209-A1B3-5065E6BD5BBE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{82740793-87F5-4485-B102-24001CBFD910}" = rport=2869 | protocol=6 | dir=out | app=system |
"{85EC2D52-890C-438C-A389-AB210148A580}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{89FA73B7-6D5B-4058-BE9C-3DB3D47AE200}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{95459860-34BD-4E83-B8A2-3904B5739BF6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9E09B0D2-FC04-44F1-81EC-4243FCF90BB9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9FA0BF54-45ED-4BDF-A2E0-A5D81D07DDA4}" = rport=445 | protocol=6 | dir=out | app=system |
"{A3B6328A-7749-47BB-B907-5D3318CD8019}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A67F4B0D-1234-4CA4-AAE0-598620B6809A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A8E7118F-55BA-414F-822E-AC473DE4C78A}" = lport=5353 | protocol=17 | dir=in | app=c:\users\honza\appdata\local\google\chrome\application\chrome.exe |
"{A9D668F2-C1C1-44E4-93B0-983C03A54486}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B07FF4EB-C581-405C-894C-1533808E961A}" = rport=2869 | protocol=6 | dir=out | app=system |
"{B2C869FA-7852-4486-8786-9F536164D66C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C0F659E3-2963-447F-B83E-9F645CCA8123}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{C49B7EFC-DE8D-4A91-8213-484E3239D3D8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CBC6E4E0-6DBE-47F3-9F69-1638E6CE0770}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CEFDBC9F-00C1-4403-9E73-3AB74E6306FD}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{D33EEC88-FE59-4A8D-A6F5-4843DE93149A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E847978E-5053-48FC-8C4B-61C9871BDE4D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EC8A03DD-9E74-4EC9-9A08-5D9C45E577D9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F10426A6-A771-458D-8053-9BA5EE165EB7}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{F5708009-4E5A-47BF-9B61-BD3FE8B89A3E}" = lport=137 | protocol=17 | dir=in | app=system |
"{F5AEBC03-7CDC-4F5E-A12B-ED1591ED609F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FABAA229-4F0F-4957-9467-EB7777F95EF1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B950F5-6B1F-436C-840A-63AFAB5221E2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe |
"{0103B362-977E-48B0-84ED-A58878F9D921}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{0228AF59-6407-4836-AC70-3BAE42A773F2}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{03458D72-D7CA-4BFD-90FA-7D2E1EA8D82F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{03A7223F-DEA7-43F4-9052-037C1F491EA5}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{041243F7-D691-4C83-8704-95DB99A889B6}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{0497DFFB-BA3A-4E93-80FE-08C62C3F4B77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{04D02395-E95C-47EC-9456-84CC93532253}" = protocol=17 | dir=out | app=c:\program files (x86)\warframe\downloaded\public\warframe.x64.exe |
"{05C645E9-9AC2-4726-92FC-74771A8CC5F5}" = protocol=17 | dir=in | app=c:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe |
"{073C0B7F-48BF-4B2D-B8FB-D22633EC12EA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{09A75832-2A0B-4981-9D94-D50DBC857524}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{0B7D6FCB-7F3A-4A12-9BB7-E7244C41ED34}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\crysis 3\bin32\crysis3.exe |
"{0C6ED098-32DC-442C-9AB1-A02009838A8F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{0CC024EA-F520-4230-8081-300248626B0C}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"{0DE9C014-46FB-489F-AF71-D6218B4623AC}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{0FCE9933-C048-4027-8794-B1CFCECE3131}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{0FE4F62B-D628-4D08-BF71-7D8C0AA6D398}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{10989EF4-CBF3-49DA-8E5D-F5A3F39F57A1}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{129D0ED0-78AC-4E2D-A57B-B9F457F73AA7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{14B9B09A-1FB1-420F-B979-8040B309365E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{16F08815-7E18-4E8E-B472-44026C93E3DD}" = protocol=17 | dir=in | app=c:\users\honza\downloads\advanced_trainer_six_practice_tests_with_answers_download_downloader.exe |
"{17B7BFA4-1099-4263-AF99-4BB7088C9116}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{17D12930-FEF0-4F42-84C4-3922DEAAEEC8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{19E85E17-59E3-46EB-A156-5CA242C8C55B}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{1AA561C3-5A7F-4D79-BE11-7DE7C20E0A26}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"{1B4C533E-BEB6-4758-BED9-78F6532BCFB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{1BC1CC97-FB1C-48C1-B540-AB470A568E7E}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{1E753087-3C72-411B-A0B4-B2A04EC3EA59}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{1F3B6F77-D9F8-488B-9D2E-012084EF38CF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{206914EF-6AA1-48D4-98A2-68881D3FF5D1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{21817D33-1978-4A6E-AE55-CB4C83B1366D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{256C3171-264F-4F90-B0A0-F1AED9DEC3AB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3478\agent.exe |
"{264F1EF2-9581-476F-81B0-156B05B19530}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcher2.exe |
"{27801268-E90A-4BE4-8C21-0463546003AC}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{27C20F9D-ADEB-48F6-9ACC-C75EC59914D0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{286E7452-615D-4DB9-BAA5-3626C19FDFAE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{29B87CB5-A3E9-4DE4-825B-1BBCC60045B8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe |
"{2AFCD07D-C839-4927-8BB6-A4AAFFCC1458}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe |
"{2B61077B-41E3-4FD1-8C04-3B0EE72ECBDC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{2BBD0CAB-2D71-4ED1-924D-D2DD6E45FA34}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe |
"{2C352E43-03EF-4423-A9D2-ED2685E24E4A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{2C76434E-7064-492A-A374-936754458609}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{2D1ED166-A308-43B9-BC5E-F9853C213F12}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{2D56336A-A933-413A-BCF0-69CCCFCAE139}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2FB95CDF-A6FF-4CC0-A88B-68975EB3BCE1}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{2FC29C12-2869-43DD-A43B-3577CF357C2A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{2FCF6EF4-46F5-4546-AAF8-5A3144880A0A}" = protocol=6 | dir=in | app=c:\games\warcraft iii\war3.exe |
"{3067519A-D7F2-4F3C-89F0-048F8DAD5B9E}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{30982386-BE6E-4450-839E-803712A0F93D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{314889E2-615E-4E25-9AD5-1C09404A0FA4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{315501FC-44C9-4C58-A921-742F076B8481}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{3240DD30-1B42-4025-9C41-FBBE1F525A10}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\crysis 3\bin32\crysis3.exe |
"{34989010-9493-4162-B403-223002620FD1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aom.exe |
"{350DF79D-A042-4DE0-A861-A8691B31D91D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3y.exe |
"{35404BE7-70EE-40C7-B45D-1ED5BA0804A7}" = protocol=17 | dir=in | app=c:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe |
"{3692EBE6-76E8-4DDB-82B1-19E0BA3978A9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{36A2E624-BE7A-4010-B1FE-8BE82885754C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{36A94D1D-A16B-4400-88F1-F343D652AC05}" = protocol=17 | dir=in | app=c:\program files (x86)\warframe\downloaded\public\warframe.exe |
"{39659950-BAD9-4840-9BFA-AD07C034130A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe |
"{39F68AFC-EA64-442E-A943-032BCD9D5E15}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{3F0E612F-BE68-4A1A-9BD0-F69DE0456997}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3F6AB0FF-73F3-4593-B6B3-154122CBE4FB}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe |
"{4374CB44-43A1-4F20-913D-326F91AD216D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{44A7F6CA-6954-41BE-88BD-106A2F043704}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{45402BF3-FB84-48AA-B8E0-0D5416D42DDC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe |
"{45B6E96F-8505-4EF7-9FA3-52DB3CF7E095}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{46249AC7-890B-4250-B934-9D3E74D317B9}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{473A5472-CADF-47CC-A0BA-0A029B3AF22A}" = protocol=17 | dir=in | app=c:\games\warcraft iii\war3.exe |
"{49A78F0F-BB08-4734-8424-FAAF1404E09A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{49FA2C9C-C171-4EB4-9D46-DB7B571F7447}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{4B404B56-AC0F-4CC7-A775-ACDECC2BF1AC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{4D02CF70-5801-4E2C-B8AB-D5E84E716FA8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe |
"{4DBD149E-A097-4023-814F-2EECD4C14C41}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{4DFF37CF-ECD8-4C75-9900-68CC9111EB01}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4EED1424-CF3A-4126-8386-30DB0959BF98}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4F3A6FBA-E6B0-458A-987B-B8E75C36EA5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{5083BA96-C49F-48F0-BD39-DDDAE59062D9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{526E1E0B-B3C6-46EB-AD71-3D0D18AF8BF6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe |
"{52CC5B1A-F709-4548-A3D8-112BDE24C82D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{52D5CF48-2A14-4F0F-97E1-B84F1F598D5D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{53370293-6D57-4D27-9053-FFDCC1E7ABAA}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{53501F4C-C9AA-47CB-8115-654B98EB745F}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{53E55428-8C03-40E1-9619-7D0B59267382}" = protocol=17 | dir=in | app=c:\program files (x86)\i am alive\src\system\iamalive_game.exe |
"{5488CC66-AE8A-44A6-9C13-AFB71C154C81}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{54C8B3CF-B0EF-48BC-8E3E-0E3EF6589926}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3323\agent.exe |
"{56049BF8-E7DE-4739-8FFF-DC0FFA215F81}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aom.exe |
"{57A93012-4437-47FC-B459-0C41DF8A24F5}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{5860AD2B-C128-4210-BB9B-8F55E498E69D}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{59AD05C3-A1A4-4369-89C5-DD674170B4EC}" = protocol=6 | dir=in | app=c:\users\honza\desktop\aoeii\age2_x1.exe |
"{5C2ECDE8-624E-4538-893E-6B3BF4291006}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"{5CA5CF4F-AA87-474F-8ABC-F3CD2239D24D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{5E4E401F-172E-4F32-AE2E-FE1D4DEB6781}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{5EC9989D-B92A-41B4-8999-670225D51DF8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe |
"{5EFECBE2-3793-4954-8166-C4D7BB385B3A}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{606899F9-4BBE-46EC-A7AB-D2AE55604DA9}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe |
"{61FA1D90-5069-45B2-8DA7-F60B7B4AA331}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{63A3CBBC-F2FA-4A5B-8178-71F6A6C9965B}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"{68212EAD-A91C-4D53-9E1C-8009BB6EC0FD}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"{68484603-D8F2-4675-8EA6-A22591653C20}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcher2.exe |
"{6896EA40-BA17-4506-A81D-C095851569A6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe |
"{68FA3FDC-094F-4E23-8EF0-51EA8A2189F9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{693DC6E5-5A23-4841-969F-1E2D4C6102E9}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{695A430C-EA07-488C-97F6-9A29883AD97F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |
"{698BE5A9-66F4-42F5-9F10-7E55B0811511}" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"{6A59747A-9FDC-4600-810B-DA2CEFDC9690}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe |
"{6B44708C-79D2-46F0-8267-B1174801079C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{6C503F04-FFBD-4C66-B405-4E5C347E92DB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{6C592DDC-08C6-4209-BB86-D51F3A5B66E5}" = dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{6FD45848-E4C1-43DA-B759-452099DD6E6F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{70E72857-9900-4F8C-87B1-D360521D85B4}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe |
"{7106614A-5885-4D7E-AEF4-9F5B7BA242FC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe |
"{72C91057-A7CE-4E0A-BAE4-C9FFBADD8161}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{740FBA0B-3815-4050-8062-886FFB283328}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe |
"{753ABE74-71DF-44B9-9F55-B8A8DBC981C0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3454\agent.exe |
"{75A241C2-3729-4B93-8A28-1E2808B005A0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{763F862F-F380-4A31-B45A-B1EE682E5717}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe |
"{7678FD17-CA24-4A32-BB81-37A34082B1D9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{76B41B07-4B76-4D8E-B38E-80D3E6D0EE91}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe |
"{76DEB865-A4F1-4359-987E-5FF1A0D05B95}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{778F4967-A1CA-40F7-B55C-A3F93B983684}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe |
"{779FEF9B-7573-4A45-8B26-FCB1937BD9EC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{781C2BB1-25D6-4D5B-86B6-B80826392F69}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe |
"{7A254076-0533-45B8-93C4-CF30A93D0823}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{7ADDE7DD-C647-4946-9DFB-D16FD95282F9}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{7B39B5C9-1A01-40C4-A65A-D63D2BE433EE}" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"{7CB2F0E9-0803-44EA-B0FC-AF22043E9F00}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3x.exe |
"{7CF35881-16AD-49C9-952F-5A4448CB82BC}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"{7DCBA654-00A0-4F87-85A7-A6978A66BB27}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{7E930D1A-01A3-4C8A-B675-1E805CFCDA62}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{8260C396-174F-45AA-8A04-C291123ED388}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{82AB98BF-6585-45DA-B537-9A867E8C1904}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{83418830-1D12-428D-84F1-4ABADFBC7D1D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe |
"{85B5FA5A-3916-4C43-8081-72C34A98B7D4}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{85FC8681-BBE7-4ED3-9569-7BBCA2782A67}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aomx.exe |
"{87DDEC95-A703-4DB5-BCEA-A52F094383C8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe |
"{888007AC-72D2-4370-8EA2-CEE95CEEE3A7}" = protocol=6 | dir=out | app=system |
"{8966A33C-8FEF-4259-9FC0-5A139D4139E7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{89B806E3-F897-452F-9838-685C7BD889D0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{89CECE9B-38DD-4743-A643-D7921F6D29BE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{8C31BFD3-B65A-45A0-A570-BBCF951817DC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8D323570-C3AE-4BCE-9249-0477DB2B5EB4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{8E73010F-B3A8-42BE-B8C4-E158660D0E91}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{8EE6E58E-30F7-4151-9D71-8025FB2156D9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcher.exe |
"{8F8BAE83-4369-4131-B4DB-1149B0F6F405}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{903A9C83-DE6F-4608-A5A3-5C676637FDE4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3334\agent.exe |
"{90523BDB-DB76-472D-877E-B773D37F3458}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3x.exe |
"{9103FCBE-C49F-48A0-BA64-0A97773FC146}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{917E976A-9609-40A5-BEE1-B97B9F92F3F7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\blicek\source sdk base 2007\hl2.exe |
"{9364392C-9665-46C0-A467-70AA051AA243}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{93DDF6CB-4C44-4CD7-80B4-65CCEB7B2A53}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{94257A3B-27A2-4B5A-A475-A3231A822927}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{94B1ED46-B4E8-439E-82E6-E90DB3AE45A6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9559D6E2-B4DD-4FEA-8A93-BBF92CF75C6D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3y.exe |
"{97485897-D23E-4A75-9026-9877D35C0015}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe |
"{985591DF-76E1-4AD4-B771-562119FFD6A0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3334\agent.exe |
"{995795CD-2D0F-4018-8549-4E705995F937}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfiledownloader.exe |
"{9A3C7B8F-8A4D-4093-BA5D-19C755BB9AA4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{9B34873C-B8F4-45F7-BC7A-07A8C84652F1}" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"{9B7D64F1-8D82-4F75-BEA1-21626A61EC5F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C349391-5268-453E-ABCC-BFB26FA2ED10}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{9DBBAC33-0F83-4978-BBEB-B6181539EAD3}" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"{9E36FFD2-D535-4EA2-8B90-9486F1D13F4E}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{9F6FE867-6837-456C-AE96-7D87862F667F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{A18C43C5-F6B3-49B3-B81B-EDA80F674E4E}" = protocol=6 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe |
"{A23F509F-D28C-4AAF-8B5E-C9B8EA491367}" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"{A34E9F67-948A-4BE0-9FE1-B3F7CFF41CCC}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A49912E8-F274-471E-A714-1E8CFDB1A438}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{A533B2C9-EB99-49FA-BCD5-CCD9A0E966BF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A623D618-AA55-4294-B140-04BADD7AE976}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{A7CA8E07-E21A-4C87-B97B-2BA182315758}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe |
"{A80B699E-EC60-4B1E-97EE-E9D6437BBD97}" = protocol=17 | dir=in | app=c:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe |
"{A8C93965-00E4-4566-9FF5-71244940A756}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB47F3C1-6F0D-4BE8-9A53-420C382E0916}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{AC63BBB8-DD16-457F-815C-9B3CD4402AA5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{AD30AF26-D236-42FF-B673-858F8A4FC744}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{ADF83F14-1F95-4FF4-9A8C-B3BCC690C3AB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3454\agent.exe |
"{AE3D3DEE-D3EC-4E9A-9E93-E0C5F49D6EF0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{AEC0A826-7018-4223-A502-F9D5AFFD3D16}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatchery.exe |
"{B07D7D2B-61A6-4C49-A252-1D9ACE53148C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{B105B3DB-E64D-495E-93B6-4B3CAAE84A46}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3323\agent.exe |
"{B1C1E7DD-D04E-4795-9FDB-D2BFD144111B}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"{B2CF262F-3D44-497E-98FB-0F2CD9449964}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatchery.exe |
"{B38A8D1A-DC52-4ADA-B099-31A9E5AD18B2}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe |
"{B462D813-6F4C-4A0F-A97D-D578E13EDB35}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\blicek\source sdk base 2007\hl2.exe |
"{B71EA000-27C6-4CF1-A470-7ECC7C186B09}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{B7B397F8-12C1-4A7A-8CF1-DA44D950286F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{B7EAC078-1B73-41F3-8D4D-A392B7052921}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{B8D3799B-A28C-436C-9C18-FC81A98E605E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{B98B03C4-D695-4007-A119-D864CDC2A40A}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{BA4A2B8E-3001-445C-9890-20CED207EAC5}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{BA896EFB-4DFC-467C-BEA0-340ECA16C9A4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe |
"{BB5D83D1-82FE-4131-8386-336525F50761}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aomx.exe |
"{BC03B741-865C-4A96-BD4E-54B9AB9FF036}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{BC964408-4837-4206-8221-6B0681253FF8}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{BDD480F7-8818-40D7-B4C1-4BDAA99BA641}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{BEA05419-0534-4C11-842A-5E8336BBFD11}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe |
"{BEC784CE-3168-434A-98D2-01450C883D4F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcherx.exe |
"{C15D1CEA-8972-46D1-AF81-C48509A6213D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{C225C34E-AEA0-44A0-B553-D83B8B640637}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe |
"{C2CDCF4A-6F53-4895-92B6-E29133235C60}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{C4EF7EDA-F8B7-462E-BA97-50EE4618A9B2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{C5C57A05-00BF-43B5-8C49-4F819A2F5A5D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |
"{C6488CFE-E7EB-4093-B25E-9108139EEF16}" = protocol=6 | dir=in | app=c:\users\honza\desktop\garry's mod\garrysmod.exe |
"{C6D3ABE0-CE24-4704-985E-DDC7A3DFBD6F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{C6E76F42-BB17-464E-A937-9167C4172234}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{C963A675-59AC-4E72-8373-890681E27858}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe |
"{C9D90B3D-D2EF-4829-9A05-2E0344FADB39}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcher.exe |
"{C9E5C026-4CBE-4236-8848-60B11A92FE5A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3427\agent.exe |
"{CBBB4EA8-BF73-460C-A4C4-1826D191D792}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CC9874B4-4247-4766-AA63-BC662AE869B6}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{CCC2B133-3C1F-451C-B879-9A7D78110E0F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CDCF6774-2061-44CC-843C-725C8C153D0A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{CE28B5B5-6E17-4646-96DB-2DD7DF6037F7}" = protocol=17 | dir=in | app=c:\program files (x86)\warframe\downloaded\public\warframe.x64.exe |
"{CEE04153-3881-4EAB-ACD9-A81E72910AAB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{CFEEE15D-6344-4819-8507-B65EF714FB96}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3427\agent.exe |
"{D0A08691-9897-43E1-8BA6-D6F09F2368F0}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{D0B847CE-B05D-4542-B92D-B05BB78AA7B7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe |
"{D0F6BE15-EBD0-42A5-80FA-8E6B3302F196}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{D20FDEFF-865E-4F5C-B766-2910C5B0CBB7}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe |
"{D2622682-C7DC-42B0-92EF-273E71B9EDC4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe |
"{D3201FFE-4463-471B-B7FE-315C7A3772BA}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe |
"{D39F854C-01FA-45FF-AE5A-D06F8C132E8C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe |
"{D3EF9DA4-FC98-4F5C-A074-49814DACDCBE}" = protocol=17 | dir=out | app=c:\program files (x86)\warframe\downloaded\public\warframe.exe |
"{D45AE14E-5F5B-486A-A3C8-C7F34B2824D2}" = dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{D4DA6ADD-0A91-4647-9798-8C0BE79C510A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{D52A59A5-3CB2-4413-909C-2BD7622B056B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\autopatcherx.exe |
"{D58AE2EF-7F5E-452E-8C24-8B55932600F5}" = protocol=17 | dir=in | app=c:\users\honza\desktop\garry's mod\garrysmod.exe |
"{D6074F41-A220-4F58-8173-8AADD31B6579}" = protocol=6 | dir=in | app=c:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe |
"{D6718F6B-FB90-4F3A-B0F1-08C67E7F81F5}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{D80F7CA9-9D0D-44A2-A1D2-D8C6EB0C1D6E}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{D884406D-DF64-4888-96CB-C9022F54F408}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{D8C4A234-4C06-49AD-BDFE-AE3ABCD02140}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{D9537558-5063-4033-97BF-26CC870A3FDB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{DB4E8968-7577-478E-A5E7-D62DBB8C74C1}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{DBB92D35-4B24-413D-B782-0CE78A7EEC83}" = protocol=17 | dir=in | app=c:\users\honza\desktop\aoeii\age2_x1.exe |
"{DED83E49-F7BA-4142-8017-A21CAFF52C74}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe |
"{DF793E13-E54B-4A4B-AEF5-53E3B8DA47E3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{E01AC39A-DF5B-4E8F-A621-84150056DF09}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfiledownloader.exe |
"{E0A738F2-BC55-4E71-9A02-3A35BA30D222}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{E3456F57-F524-450D-96CB-BDE043C697E1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{E49727DA-4472-4275-9760-80D0353A9832}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3478\agent.exe |
"{E4B59DE2-F703-44C3-9FBB-B58D7C2AE861}" = protocol=6 | dir=in | app=c:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe |
"{E56577E8-B202-4D86-A5A8-BCACE9063B31}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{E6BCE68D-C1F6-4A7F-84E6-BF0BAADCC44D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{E8A0B9CB-A1A5-43ED-B786-94407C1CDB66}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{E940DFEC-07AB-45C0-91CA-8D57DA839B6F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{E9CB4547-4CDA-4DAC-A835-FA1FADA92824}" = protocol=6 | dir=in | app=c:\program files (x86)\i am alive\src\system\iamalive_game.exe |
"{EA2D74CC-C4DE-4BDF-B0AD-CA9ABC34850F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{EA43D471-965E-4A1E-8249-9F4B1191C139}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{EB6EE1D0-4318-4CF2-88E3-F0D77E6431A9}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe |
"{ECC0DD4A-0C37-4256-AF8C-6E8006BE8FB2}" = protocol=58 | dir=in | app=system |
"{ECD403C9-4683-4D82-85AE-00FE4C9C27A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EDCF182C-E932-4CAA-9AEC-973B23E6DFD0}" = protocol=17 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe |
"{EE1DBDBC-C68C-49B8-8982-4FF74848781B}" = protocol=6 | dir=in | app=c:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe |
"{EF132E0B-A5EC-407D-A5EA-63E84AF7CDC0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe |
"{F174EC87-6BE8-45C0-B590-6A4E8F6BFB0E}" = protocol=6 | dir=in | app=c:\users\honza\downloads\advanced_trainer_six_practice_tests_with_answers_download_downloader.exe |
"{F37FB942-B4B8-48CD-B053-887F3DBCC168}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{F38C0688-DA75-4FDC-BB4C-679C17BC9F68}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F3E70594-48E0-47B0-AD5E-2A9FB4B0F6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{F3EA1838-9421-4DBA-80E7-752077012B59}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe |
"{F3F5B99F-ED6A-4CB5-86EB-149E4F4C7B2F}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{F42DAE20-6A7D-4EBC-AEA7-474C2D650804}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{F6B7C224-4D04-424F-9327-6C4179BDA2AA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{F6D8B417-D612-4691-B0A0-442CEBDE6DAC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{F6F41523-CCE5-469C-B5F5-3D87668EAEF6}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"{F81161BB-0E65-4065-AD51-94868EBC5068}" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"{F8219B06-3C3D-47B2-A15F-648DBE067E65}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe |
"{F96DE569-BF2E-4E20-89B6-10F52B44F92D}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"{FB9D4666-0CF6-409B-AE1A-B254F150C934}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe |
"{FC553E1E-1540-43B8-A731-2273E76A9F02}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{FD118D99-D356-46EB-83EB-4049D94DF48B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{FD5C7668-220C-4976-A7C7-BC45835B4EF7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{FE67DA7E-81AD-42B6-9B37-CB166EB7B83F}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"TCP Query User{05566C94-CF34-4299-BDE1-250EE87F520F}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"TCP Query User{13174DA0-AF3B-448D-87B1-B0B16E03220D}C:\program files (x86)\microsoft games\age of mythology\aomx.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aomx.exe |
"TCP Query User{1A77B464-93D3-4183-8C96-F1520C2128E9}C:\program files (x86)\war thunder\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"TCP Query User{1C8D0A19-9C93-44F7-A133-8D39C6BB5351}C:\program files (x86)\war thunder\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"TCP Query User{21A1D364-215F-4E4C-B729-70C15C0AA27D}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"TCP Query User{2DA02BBE-73D5-411A-BC82-5364B5826FFB}C:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe |
"TCP Query User{2E137D8C-CF7B-4555-BE96-787CF0ED8010}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{330922A6-F1F5-4BC5-92D7-2BD90308BC22}C:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe |
"TCP Query User{3782C9B2-805D-469C-B938-B37A8CA9CE29}C:\program files (x86)\i am alive\src\system\iamalive_game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\i am alive\src\system\iamalive_game.exe |
"TCP Query User{38DC38AB-C5F1-4414-825A-895DE1FA6B14}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{3AAEC6B9-72BF-4BE0-890E-9502E3D61A43}C:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{3BE7EC0D-A110-48AE-8C82-1A16EBC4FFC0}C:\users\honza\desktop\garry's mod\garrysmod.exe" = protocol=6 | dir=in | app=c:\users\honza\desktop\garry's mod\garrysmod.exe |
"TCP Query User{3F30B17D-DB7F-4958-B303-12B24CDE6466}C:\users\honza\desktop\aoe 2\empires2.exe" = protocol=6 | dir=in | app=c:\users\honza\desktop\aoe 2\empires2.exe |
"TCP Query User{424459E0-81A5-49C3-88BC-1CBC6BC060AD}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{4B5E7F3A-BFB9-44F8-9C40-4F099158CDFB}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{56DF4773-483C-493D-8BA7-BB4A8918464A}C:\games\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\games\warcraft iii\war3.exe |
"TCP Query User{6322C779-61D0-4D8F-8526-E8C977F70D33}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe |
"TCP Query User{7C5DB3AB-3E7B-471D-8A4D-5F9ED89C67F9}C:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"TCP Query User{83F06163-D189-4861-84F6-9EDC45DA35FB}C:\program files (x86)\3do\heroes 3 complete\heroes3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\3do\heroes 3 complete\heroes3.exe |
"TCP Query User{849FD5D2-B42C-4270-9AB7-723096EF2E01}C:\users\honza\desktop\aoeii\age2_x1.exe" = protocol=6 | dir=in | app=c:\users\honza\desktop\aoeii\age2_x1.exe |
"TCP Query User{8B4F8BC7-F762-494C-B10E-D2CBA950A9CC}C:\program files (x86)\microsoft games\age of mythology\aom.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aom.exe |
"TCP Query User{934CDB86-EFFB-487D-B035-578063BE72B4}C:\program files (x86)\the witcher 2 (cz)\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\the witcher 2 (cz)\bin\witcher2.exe |
"TCP Query User{991BDB2C-E3D1-47EE-860E-A29D3F3FBADA}C:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=6 | dir=in | app=c:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe |
"TCP Query User{A8153E3A-74EB-4060-8D0B-46C9731BF843}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe |
"TCP Query User{AE68E51B-08B2-4E84-9498-62085D159F32}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"TCP Query User{B0710F6F-8EB4-4AC7-9972-50839A946CDA}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe |
"TCP Query User{B2DB0773-F320-4AD9-88C1-BA5C0CD71B2A}C:\users\honza\desktop\wow(wotlk)\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe" = protocol=6 | dir=in | app=c:\users\honza\desktop\wow(wotlk)\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"TCP Query User{BD363671-8107-4EF1-B5F5-EFA5A74B1425}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"TCP Query User{C5DA3254-0C28-4A85-81C9-86E5477B688F}C:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"TCP Query User{D9075817-71A4-4B6C-8C22-E7D09C245F20}C:\program files (x86)\war thunder\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"TCP Query User{DB4E9CEC-CBAA-4E20-8ADD-4890301CA37D}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{F1F0D185-C220-49D7-889F-7542A60F2E52}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe |
"TCP Query User{F6C0D97B-FCC3-4782-A53F-85BAAF4CF189}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{06F39CC7-D667-4930-AECB-36D66D94051F}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"UDP Query User{13144783-660E-42C1-B5E3-2C86EDC37285}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{1452F924-5103-4D30-A5FC-8B78021ABF8A}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"UDP Query User{145968C8-FD70-4D34-9F73-12574CA6EAF2}C:\program files (x86)\3do\heroes 3 complete\heroes3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\3do\heroes 3 complete\heroes3.exe |
"UDP Query User{1655494D-6825-4E44-B531-281495E29B22}C:\program files (x86)\the witcher 2 (cz)\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\the witcher 2 (cz)\bin\witcher2.exe |
"UDP Query User{223667FA-660C-4731-B702-A57B0C81EB83}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe |
"UDP Query User{255767B8-23C4-4985-9CBB-2E4FD94D55EF}C:\program files (x86)\war thunder\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"UDP Query User{319715DA-2F3F-46F8-93CA-D08D45ACE89C}C:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"UDP Query User{31BA2ACA-F7B9-4F17-A040-70135FD426C2}C:\program files (x86)\microsoft games\age of mythology\aom.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aom.exe |
"UDP Query User{31CFAB95-DD5D-4C26-B001-3B2EFCFF7D88}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{32252A6B-DBC4-4BD3-AA9F-36CF93A227CF}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{339F8BD5-FE75-457C-B08B-9A357BACAC6A}C:\program files (x86)\war thunder\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"UDP Query User{38BD6D44-05C3-4D66-9004-561A1B60DAF4}C:\users\honza\desktop\aoeii\age2_x1.exe" = protocol=17 | dir=in | app=c:\users\honza\desktop\aoeii\age2_x1.exe |
"UDP Query User{4520E51D-67C6-440C-9114-C2359B5D2AAE}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe |
"UDP Query User{45D4EEDE-37CB-4453-AEB8-5D150D26054C}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe |
"UDP Query User{4AB372FB-0B46-4609-829E-E17889D8C96E}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{4ED20B8B-AE10-4174-948E-953D7DA1C614}C:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\jendis5\source sdk base 2007\hl2.exe |
"UDP Query User{57C01AEF-9253-4740-B23E-4930ED80B16B}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"UDP Query User{5808CA15-6C29-483B-B31A-568C71A2351F}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"UDP Query User{6D9B716C-A898-4C9A-AF56-ACC434250CCE}C:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"UDP Query User{715B8CC2-808B-4F81-9173-3E2D69AF3C6A}C:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=17 | dir=in | app=c:\users\honza\appdata\roaming\gameranger\gameranger\gameranger.exe |
"UDP Query User{71BDBF60-DD7E-4D1E-8973-E4021EA3804E}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe |
"UDP Query User{79185AAD-2D93-4F1D-A52A-6715939C5FA5}C:\users\honza\desktop\wow(wotlk)\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe" = protocol=17 | dir=in | app=c:\users\honza\desktop\wow(wotlk)\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"UDP Query User{7AEE1F59-9312-4256-B97F-BD0678D69A18}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"UDP Query User{7C782AA4-76E4-4A98-80ED-FFE58B367810}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{819EB6D9-FFCA-4A4D-B0EE-DD5CBF1EA3AF}C:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\honza\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{8F798486-DE9F-48D0-803F-C82C0DB80162}C:\games\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\games\warcraft iii\war3.exe |
"UDP Query User{99894B49-3C13-4AC2-97C9-96C611033F31}C:\users\honza\desktop\garry's mod\garrysmod.exe" = protocol=17 | dir=in | app=c:\users\honza\desktop\garry's mod\garrysmod.exe |
"UDP Query User{D53E0A5D-9A94-403B-8CDD-700566FCA91A}C:\program files (x86)\microsoft games\age of mythology\aomx.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of mythology\aomx.exe |
"UDP Query User{DC5834BA-3700-4CFA-82C2-23BA9E7F69DF}C:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\thq\dawn of war - soulstorm\soulstorm.exe |
"UDP Query User{DE176CFC-8BBE-42C1-9C64-0F0976EA93D6}C:\users\honza\desktop\aoe 2\empires2.exe" = protocol=17 | dir=in | app=c:\users\honza\desktop\aoe 2\empires2.exe |
"UDP Query User{E1073DFF-4F04-4AFD-9F4D-910BC6B1218F}C:\program files (x86)\i am alive\src\system\iamalive_game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\i am alive\src\system\iamalive_game.exe |
"UDP Query User{FDCBA2E6-FD2A-487F-82BB-2046800FC4A0}C:\program files (x86)\war thunder\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series" = Canon MG5100 series MP Drivers
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{26A24AE4-039D-4CA4-87B4-2F86416029FF}" = Java(TM) 6 Update 29 (64-bit)
"{308051DA-0048-7A07-FE8B-9B6EC119A9E8}" = AMD Catalyst Install Manager
"{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}" = AMD Steady Video Plug-In
"{44AAA767-F540-F091-4571-ADCBC10B0C92}" = AMD Fuel
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6109059C-2784-4546-A353-7100A6882DF4}" = Ruská - rozložení jako latinka (0.9.1)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AEF57B06-B494-8180-AFC7-05EFB1DB2B64}" = ccc-utility64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BD1BCEF8-5CD6-D8ED-7D36-31C2172076EA}" = AMD Media Foundation Decoders
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{ED273D26-E354-1A5B-A0D0-CB5258D43BD2}" = AMD Wireless Display v3.0
"{F55458B0-DCA9-38C9-6C8D-829F22463A55}" = AMD Drag and Drop Transcoding
"{FCC4426F-0296-D30D-729C-E76C8E7252C7}" = AMD Accelerated Video Transcoding
"CCleaner" = CCleaner
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{046B79EE-7ED3-37A4-621A-FE297EF484C2}" = CCC Help Greek
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{10CB5DDD-38E1-2EB2-F62C-C1948A99943E}" = AMD Catalyst Control Center
"{1194740D-0DB8-A508-31BA-E722597B4516}" = Catalyst Control Center Graphics Previews Common
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks v.0.7.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FB16E3B-3AFB-46CB-6E83-2F5A0CF4ED16}" = Catalyst Control Center Localization All
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.20
"{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71
"{2E3A81FB-7952-F8CB-9AD5-50544E2F4838}" = CCC Help Czech
"{4172E797-CE12-AC47-05B7-0E48BDB33E75}" = CCC Help Russian
"{4198AE83-A3C6-4C41-85C8-EC63E990696E}" = Crysis®3
"{4428AEE6-FA5E-2913-8D12-B410E85E11AA}" = CCC Help Spanish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4FF1533E-FF2C-A04A-25DD-A8AEC6FA106B}" = CCC Help Chinese Standard
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
"{6071CB80-DABC-B10D-F244-7F410FB3B150}" = CCC Help Polish
"{6343B6BA-F97F-B336-9ED8-FFD43776E84D}" = CCC Help Finnish
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8D3A11D0-D925-FA0F-43F3-242E49975CD2}" = CCC Help Danish
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{8EF39A9F-6A57-9706-86A5-9312D9ED8016}" = CCC Help Portuguese
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92352C97-C657-DB89-5F3A-E8C3789D9C89}" = CCC Help Chinese Traditional
"{95545E55-3309-1929-FF41-2908A9706742}" = CCC Help Turkish
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA5F712-9CAA-B3CB-02D3-7134DFC8801E}" = CCC Help French
"{A128A816-FD3F-990E-DD80-E1735BD718AE}" = CCC Help Italian
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.9) - Czech
"{AEA498F4-42E6-47B6-85BB-3F6F5B0F6AEB}" = Jetway Hybrid Tera-vision Receiver Utilities
"{AFC9ECA9-6A4E-1370-98F3-002B63B5AF8E}" = CCC Help Thai
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B88F2045-CF9A-996C-1670-6F7D65F1D18A}" = CCC Help Norwegian
"{BA88EE67-8974-459D-A1DB-C8281D9AC6F6}" = Browser Configuration Utility
"{BED96D0C-7743-3CE3-F7DF-A0A4475FBF2F}" = CCC Help Hungarian
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1" = aTube Catcher verze 3.8
"{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}" = NVIDIA PhysX v8.10.29
"{D5AD72DF-2A19-4164-8D8B-6127A66C582A}" = Warframe
"{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E297492A-E114-CAE0-502E-5F36C386DD30}" = CCC Help Dutch
"{E6533A85-ED92-F897-2B68-58AC3BD87F94}" = CCC Help English
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{EBAC163A-588E-1E5A-3CE8-826E9A449244}" = CCC Help Korean
"{ED65BD75-CEF3-C0C2-9E9C-FA567484FF60}" = CCC Help Japanese
"{ed8defa4-19fa-3932-9612-e2122d8a62d9}}_is1" = War Thunder Launcher 1.0.1.89
"{EEB34D84-92A1-7BE3-6DB7-ABD1C4912D6B}" = Catalyst Control Center InstallProxy
"{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}" = The Witcher 2 (CZ)
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F1289D68-1C48-930F-51CF-577BDB371252}" = CCC Help Swedish
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3F340A5-64EC-AEEC-4BDF-DC537D390BF5}" = CCC Help German
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"aTube Catcher" = aTube Catcher
"Avast" = Avast Free Antivirus
"Battle.net" = Battle.net
"CanonMyPrinter" = Canon My Printer
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DAEMON Tools Lite" = DAEMON Tools Lite
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Foxit Reader_is1" = Foxit Reader 5.1
"Hearthstone" = Hearthstone
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III Complete
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"I Am Alive_is1" = I Am Alive verzia 1.01
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty(R) - World at War(TM) 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"Mozilla Firefox 33.1.1 (x86 cs)" = Mozilla Firefox 33.1.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"Raptr" = Raptr
"Registrace uživatele zařízení Canon MG5100 series" = Registrace uživatele zařízení Canon MG5100 series
"StarCraft II" = StarCraft II
"Steam App 15620" = Warhammer® 40,000™: Dawn of War® II
"Steam App 218" = Source SDK Base 2007
"Steam App 49520" = Borderlands 2
"Steam App 72850" = The Elder Scrolls V: Skyrim
"TeamViewer 9" = TeamViewer 9
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"ZMBV" = Zip Motion Block Video codec (Remove Only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"GameRanger" = GameRanger
"Google Chrome" = Google Chrome
"TeamSpeak 3 Client" = TeamSpeak 3 Client

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 30.3.2013 11:04:43 | Computer Name = HONZA-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: SniperEliteV2.exe, verze: 0.0.0.0, časové
razítko: 0x4f9aad4a Název chybujícího modulu: steam.dll, verze: 2.0.1678.491, časové
razítko: 0x5126992f Kód výjimky: 0xc0000005 Posun chyby: 0x00163179 ID chybujícího
procesu: 0xb40 Čas spuštění chybující aplikace: 0x01ce2d51d24137bb Cesta k chybující
aplikaci: C:\Program Files (x86)\Rebellion\SniperEliteV2\bin\SniperEliteV2.exe Cesta
k chybujícímu modulu: C:\Program Files (x86)\Steam\steam.dll ID zprávy: 26bc52be-994b-11e2-ae03-bcaec582aeb1

Error - 1.4.2013 7:15:59 | Computer Name = HONZA-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Skype.exe, verze: 6.2.0.106, časové razítko:
0x5113a7cf Název chybujícího modulu: Skype.exe, verze: 6.2.0.106, časové razítko:
0x5113a7cf Kód výjimky: 0xc0000005 Posun chyby: 0x001a940e ID chybujícího procesu:
0x12e0 Čas spuštění chybující aplikace: 0x01ce2eb67d081aca Cesta k chybující aplikaci:
C:\Program Files (x86)\Skype\Phone\Skype.exe Cesta k chybujícímu modulu: C:\Program
Files (x86)\Skype\Phone\Skype.exe ID zprávy: 8724729b-9abd-11e2-b3b5-bcaec582aeb1

Error - 1.4.2013 7:16:41 | Computer Name = HONZA-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: Skype.exe, verze: 6.2.0.106, časové razítko:
0x5113a7cf Název chybujícího modulu: Skype.exe, verze: 6.2.0.106, časové razítko:
0x5113a7cf Kód výjimky: 0xc0000005 Posun chyby: 0x0000bdc2 ID chybujícího procesu:
0x12e0 Čas spuštění chybující aplikace: 0x01ce2eb67d081aca Cesta k chybující aplikaci:
C:\Program Files (x86)\Skype\Phone\Skype.exe Cesta k chybujícímu modulu: C:\Program
Files (x86)\Skype\Phone\Skype.exe ID zprávy: a09e4649-9abd-11e2-b3b5-bcaec582aeb1

Error - 3.5.2013 12:01:15 | Computer Name = HONZA-PC | Source = Application Hang | ID = 1002
Description = Program WorldOfTanks.exe verze 0.8.5.0 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
153c Čas spuštění: 01ce481764ae277a Čas ukončení: 36 Cesta k aplikaci: C:\GAMES\World_of_Tanks\WorldOfTanks.exe

ID
hlášení: ac9291b2-b40a-11e2-b68f-bcaec582aeb1

Error - 30.5.2013 11:59:34 | Computer Name = HONZA-PC | Source = Application Hang | ID = 1002
Description = Program WorldOfTanks.exe verze 0.8.5.0 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
17a4 Čas spuštění: 01ce5d4ea1bb67e4 Čas ukončení: 10 Cesta k aplikaci: C:\GAMES\World_of_Tanks\WorldOfTanks.exe

ID
hlášení: e94a36ca-c941-11e2-997d-bcaec582aeb1

Error - 25.6.2013 9:35:07 | Computer Name = HONZA-PC | Source = Application Hang | ID = 1002
Description = Program WorldOfTanks.exe verze 0.8.6.0 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
1678 Čas spuštění: 01ce71a8bb07a28b Čas ukončení: 41 Cesta k aplikaci: C:\GAMES\World_of_Tanks\WorldOfTanks.exe

ID
hlášení: 0a3a1f15-dd9c-11e2-94bf-bcaec582aeb1

Error - 27.6.2013 8:34:48 | Computer Name = HONZA-PC | Source = Application Hang | ID = 1002
Description = Program Skype.exe verze 6.5.0.158 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
103c Čas spuštění: 01ce732ec481f3ab Čas ukončení: 43 Cesta k aplikaci: C:\Program
Files (x86)\Skype\Phone\Skype.exe ID hlášení: f23e7ad0-df25-11e2-9714-bcaec582aeb1


Error - 29.6.2013 6:49:58 | Computer Name = HONZA-PC | Source = MsiInstaller | ID = 11334
Description =

Error - 29.6.2013 6:51:00 | Computer Name = HONZA-PC | Source = MsiInstaller | ID = 11334
Description =

Error - 1.7.2013 15:48:56 | Computer Name = HONZA-PC | Source = Application Hang | ID = 1002
Description = Program SC2.exe verze 2.0.9.26147 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
11c8 Čas spuštění: 01ce763ef0358e02 Čas ukončení: 145 Cesta k aplikaci: C:\Program
Files (x86)\StarCraft II\Versions\Base24944\SC2.exe ID hlášení: 42758015-e287-11e2-bb36-bcaec582aeb1


[ OSession Events ]
Error - 31.12.2013 13:53:01 | Computer Name = HONZA-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 19580
seconds with 6420 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 17.11.2014 4:45:26 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba sbapifs neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 17.11.2014 4:45:51 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba AODDriver4.2.0 neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 17.11.2014 4:45:54 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba PnkBstrA neuspěla při spuštění v důsledku následující chyby:
%%3

Error - 17.11.2014 4:45:54 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba PnkBstrB neuspěla při spuštění v důsledku následující chyby:
%%3

Error - 17.11.2014 4:48:16 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7024
Description = Služba Windows Search ukončena s chybou %%-1073473535, specifickou
pro službu.

Error - 17.11.2014 4:48:16 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7031
Description = Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát.
Následující opravná akce bude spuštěna za 30000 milisekund: Restart the service.

Error - 18.11.2014 16:00:26 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba sbapifs neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 18.11.2014 16:00:33 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba AODDriver4.2.0 neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 18.11.2014 16:00:37 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba PnkBstrA neuspěla při spuštění v důsledku následující chyby:
%%3

Error - 18.11.2014 16:00:37 | Computer Name = HONZA-PC | Source = Service Control Manager | ID = 7000
Description = Služba PnkBstrB neuspěla při spuštění v důsledku následující chyby:
%%3


< End of report >

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#6 Příspěvek od Blicek »

Log OTL se mi sem celý nešel, rozdělím ho na dvě části

OTL logfile created on: 18.11.2014 21:18:48 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HONZA\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

12,00 Gb Total Physical Memory | 9,46 Gb Available Physical Memory | 78,82% Memory free
18,00 Gb Paging File | 15,10 Gb Available in Paging File | 83,94% Paging File free
Paging file location(s): C:\pagefile.sys 6142 6142 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 54,27 Gb Free Space | 11,65% Space Free | Partition Type: NTFS
Drive F: | 5,13 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: HONZA-PC | User Name: HONZA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014.11.18 21:17:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HONZA\Downloads\OTL.exe
PRC - [2014.11.15 00:03:13 | 005,225,064 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014.11.15 00:03:13 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.10.23 19:05:18 | 001,409,984 | ---- | M] (http://lucky-tab.com/) -- C:\Program Files (x86)\LuckyTab\LuckyTab.exe
PRC - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2013.12.18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010.11.20 13:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010.04.27 09:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.03.05 09:15:12 | 000,235,752 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010.03.05 09:15:04 | 000,411,864 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2005.04.18 16:49:38 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe


========== Modules (No Company Name) ==========

MOD - [2014.11.15 00:03:13 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014.11.06 00:57:02 | 014,910,280 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\PepperFlash\pepflashplayer.dll
MOD - [2014.11.06 00:57:01 | 008,911,176 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\pdf.dll
MOD - [2014.11.06 00:56:57 | 001,042,760 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\libglesv2.dll
MOD - [2014.11.06 00:56:55 | 000,211,272 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\libegl.dll
MOD - [2014.11.06 00:56:54 | 001,681,224 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\ffmpegsumo.dll
MOD - [2009.07.31 20:39:08 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2005.04.18 16:49:38 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe


========== Services (SafeList) ==========

SRV:64bit: - [2014.11.15 00:03:13 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2013.12.06 21:52:10 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2013.12.06 16:06:06 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.11.12 18:26:48 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2013.12.18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.11.06 17:30:44 | 000,758,224 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2013.06.29 11:16:00 | 000,107,832 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWow64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012.07.02 12:44:54 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.06.14 23:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011.06.13 19:22:33 | 000,066,872 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWow64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.03.05 09:15:12 | 000,235,752 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2014.11.15 00:03:15 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2014.11.15 00:03:15 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014.11.15 00:03:15 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014.11.15 00:03:14 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014.11.15 00:03:14 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014.11.15 00:03:14 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014.11.15 00:03:14 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014.11.15 00:03:11 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.12.06 22:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2013.12.06 22:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.12.06 21:21:44 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.09.24 15:53:50 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2.0)
DRV:64bit: - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2012.05.18 19:47:04 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.06.23 10:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.04.27 08:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.04.27 08:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.02.18 08:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.09.16 07:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t)
DRV:64bit: - [2009.08.23 23:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2009.07.16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:32:37 | 001,627,520 | ---- | M] (NXP Semiconductors) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ph3xIB64.sys -- (Ph3xIB64)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5193
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes,DefaultScope = {6905ACDE-7F92-4e73-BDCB-439196EB6C7B}
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{5D836038-8946-4636-B371-69AF13033DD5}: "URL" = http://www.google.com/custom?client=pub ... earchTerms}
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6905ACDE-7F92-4e73-BDCB-439196EB6C7B}: "URL" = http://uk.search.yahoo.com/search?p={se ... &type=EGMB
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{9001BA8A-679D-4922-88D4-94BE02ED450C}: "URL" = http://websearch.ask.com/redirect?clien ... F705034330
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Seznam"
FF - prefs.js..browser.search.defaultenginename: "Seznam"
FF - prefs.js..browser.search.defaultthis.engineName: "Seznam"
FF - prefs.js..browser.search.defaulturl: "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
FF - prefs.js..browser.search.order.1: "Seznam"
FF - prefs.js..browser.search.selectedEngine: "Seznam"
FF - prefs.js..browser.startup.homepage: "https://www.seznam.cz/?clid=22668"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1.1
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\HONZA\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\HONZA\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.11.15 00:03:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014.11.17 09:47:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011.05.31 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HONZA\AppData\Roaming\Mozilla\Extensions
[2014.11.15 00:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\extensions
[2011.11.23 18:00:38 | 000,002,401 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\askcom.xml
[2014.03.21 18:08:04 | 000,006,226 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\buenosearch.xml
[2013.03.30 14:25:23 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-1.xml
[2011.08.28 15:08:45 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-2.xml
[2011.09.01 20:17:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-3.xml
[2011.09.10 20:10:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-4.xml
[2011.09.28 20:10:15 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-5.xml
[2011.10.02 12:07:10 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-6.xml
[2011.11.08 18:12:40 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-7.xml
[2011.08.15 18:28:43 | 000,001,056 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin.xml
[2014.11.17 12:27:47 | 000,002,427 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\seznam-avast.xml
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.02 08:26:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib\4.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfgdmpfihlmdekaclngibpjhdebndhdj\1.16_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\

O1 HOSTS File: ([2014.11.14 22:08:49 | 000,000,860 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll File not found
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll File not found
O3 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss File not found
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4C31E73E-AD0A-452F-9D6B-BC6B29F48C88}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\syswow64\userinit.exe) - c:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.01.05 20:22:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation) - F:\autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:27 | 000,058,601 | R--- | M] () - F:\autorun.ico -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:27 | 000,000,047 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:44 | 000,000,382 | R--- | M] () - F:\autorun.ini -- [ UDF ]
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell - "" = AutoRun
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\Windows\SysWow64\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.ZMBV - C:\Windows\SysWow64\zmbv.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2014.11.16 17:42:42 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.11.16 17:42:42 | 000,000,000 | ---D | C] -- C:\rsit
[2014.11.16 14:18:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2014.11.16 14:18:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2014.11.16 14:18:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2014.11.15 00:04:06 | 000,000,000 | ---D | C] -- C:\Users\HONZA\AppData\Roaming\AVAST Software
[2014.11.15 00:03:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014.11.15 00:03:30 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.11.15 00:03:29 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.11.15 00:03:27 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014.11.15 00:03:25 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.11.15 00:03:22 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014.11.15 00:03:19 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.11.15 00:03:14 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.11.15 00:01:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014.11.15 00:00:12 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014.11.01 10:11:45 | 000,000,000 | ---D | C] -- C:\Users\HONZA\Desktop\ČZU
[2014.10.31 14:43:54 | 000,000,000 | ---D | C] -- C:\Users\HONZA\Desktop\Učebnice
[2014.10.26 09:31:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014.10.26 09:31:06 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.10.26 09:31:00 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.10.26 09:31:00 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.10.26 09:31:00 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.10.23 19:05:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LuckyTab
[2014.10.20 21:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014.10.20 21:05:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HONZA\Desktop\*.tmp files -> C:\Users\HONZA\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014.11.18 21:21:17 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.18 21:06:09 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job
[2014.11.18 21:05:39 | 001,624,214 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.11.18 21:05:39 | 000,681,538 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2014.11.18 21:05:39 | 000,667,180 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.11.18 21:05:39 | 000,148,562 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2014.11.18 21:05:39 | 000,128,112 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.11.18 21:05:38 | 000,010,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.11.18 21:05:38 | 000,010,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.18 21:00:37 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.11.18 21:00:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.11.18 21:00:20 | 1073,090,558 | -HS- | M] () -- C:\hiberfil.sys
[2014.11.17 23:06:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
[2014.11.17 22:45:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.17 22:38:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.11.17 18:15:37 | 000,408,788 | ---- | M] () -- C:\Users\HONZA\Desktop\Substituenty.png
[2014.11.17 12:27:47 | 000,001,118 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014.11.17 11:45:28 | 000,160,173 | ---- | M] () -- C:\Users\HONZA\Desktop\Bez názvu.jpg
[2014.11.16 21:18:58 | 000,002,008 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.11.16 14:18:12 | 000,001,282 | ---- | M] () -- C:\Users\HONZA\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2014.11.16 14:18:12 | 000,001,258 | ---- | M] () -- C:\Users\HONZA\Desktop\Spybot - Search & Destroy.lnk
[2014.11.15 00:16:36 | 000,002,364 | ---- | M] () -- C:\Users\HONZA\Desktop\Google Chrome.lnk
[2014.11.15 00:04:29 | 000,050,280 | ---- | M] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014.11.15 00:03:15 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.11.15 00:03:15 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.11.15 00:03:15 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.11.15 00:03:14 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.11.15 00:03:14 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.11.15 00:03:14 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014.11.15 00:03:14 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.11.15 00:03:14 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.11.15 00:03:14 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.11.15 00:03:11 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014.11.12 18:26:48 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.11.12 18:26:48 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.11.01 15:01:50 | 477,818,178 | ---- | M] () -- C:\Users\HONZA\Desktop\blbosti.zip
[2014.10.26 09:30:56 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.10.26 09:30:55 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.10.26 09:30:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.10.26 09:30:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.10.20 21:05:11 | 000,002,533 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HONZA\Desktop\*.tmp files -> C:\Users\HONZA\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014.11.18 21:21:17 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.11.17 18:15:37 | 000,408,788 | ---- | C] () -- C:\Users\HONZA\Desktop\Substituenty.png
[2014.11.17 11:45:28 | 000,160,173 | ---- | C] () -- C:\Users\HONZA\Desktop\Bez názvu.jpg
[2014.11.16 14:18:12 | 000,001,282 | ---- | C] () -- C:\Users\HONZA\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2014.11.16 14:18:12 | 000,001,258 | ---- | C] () -- C:\Users\HONZA\Desktop\Spybot - Search & Destroy.lnk
[2014.11.15 00:03:52 | 000,002,008 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.11.15 00:03:29 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.11.15 00:03:28 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.11.15 00:03:25 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.11.14 22:09:13 | 000,050,280 | ---- | C] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014.11.01 14:50:43 | 477,818,178 | ---- | C] () -- C:\Users\HONZA\Desktop\blbosti.zip
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.xp070105.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.px050107.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.ex010705.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.ex010507.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.bx050107.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.ax010705.dat
[2014.03.17 19:09:34 | 000,522,796 | ---- | C] () -- C:\Windows\SysWow64\scrypt130511Pitcairnglg2tc4032w256l4.bin
[2014.03.16 09:45:18 | 000,000,067 | ---- | C] () -- C:\Users\HONZA\rgmnr
[2014.01.28 22:00:51 | 000,026,900 | ---- | C] () -- C:\Users\HONZA\AppData\Local\dt.dat
[2013.12.06 22:38:38 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.12.06 22:38:38 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.12.06 16:44:26 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013.11.25 20:30:58 | 000,000,000 | -HS- | C] () -- C:\Users\HONZA\AppData\Local\LumaEmu
[2013.07.21 09:11:15 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2013.07.08 16:27:46 | 000,003,584 | ---- | C] () -- C:\Users\HONZA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.drv190904.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.drv120405.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.drv120205.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data211204.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data211004.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data110704.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.data001.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.data000.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.dat000002.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.dat000001.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.app190905.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.addit001.dat
[2011.12.20 20:05:00 | 000,010,374 | ---- | C] () -- C:\Users\HONZA\OTMData.xml
[2011.06.14 15:43:04 | 000,000,093 | ---- | C] () -- C:\Users\HONZA\AppData\Local\fusioncache.dat
[2011.04.12 18:05:42 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013.01.30 17:05:39 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013.01.30 17:05:39 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012.04.05 14:53:38 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\.minecraft
[2014.11.15 00:04:06 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\AVAST Software
[2014.01.06 22:07:54 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Battle.net
[2014.09.18 12:52:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Bioshock
[2014.03.21 21:09:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\BSplayer
[2011.04.27 09:39:24 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Canon
[2014.07.14 22:39:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DAEMON Tools Lite
[2011.04.11 18:00:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DeviceVm
[2014.10.31 14:05:02 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Dropbox
[2012.03.03 15:31:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Foxit Software
[2011.08.03 08:51:29 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GameRanger
[2011.08.03 08:44:11 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GetRightToGo
[2014.03.14 19:24:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\library_dir
[2013.06.14 14:55:41 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\OpenCandy
[2013.02.21 17:48:46 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Origin
[2014.03.21 21:23:01 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Raptr
[2014.03.21 21:24:18 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Seznam.cz
[2014.03.21 21:49:34 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TeamViewer
[2014.11.14 21:43:37 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TS3Client
[2014.07.14 22:33:31 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TuneUp Software
[2014.05.25 23:11:05 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Tunngle
[2014.03.26 21:08:32 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Ubisoft
[2014.11.16 15:07:10 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\uTorrent
[2011.08.13 19:49:58 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\wargaming.net

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,616 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.05.02 20:20:59 | 000,000,948 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.05.02 20:21:01 | 000,000,952 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.09.03 11:43:06 | 000,000,910 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
[2012.09.03 11:43:07 | 000,000,962 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job
[2012.09.04 15:29:09 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< MD5 for: ATAPI.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows.old\Windows\system32\drivers\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows.old\Windows\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows.old\Windows\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2004.08.17 14:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\Windows.old\Windows\system32\autochk.exe
[2004.08.17 14:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\Windows.old\Windows\system32\dllcache\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2004.08.03 21:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\Windows.old\Windows\system32\drivers\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\Windows.old\Windows\explorer.exe
[2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\Windows.old\Windows\system32\dllcache\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
[2004.08.03 21:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\Windows.old\Windows\system32\hal.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\Windows.old\Windows\system32\dllcache\scecli.dll
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\Windows.old\Windows\system32\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2004.08.17 14:49:28 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\Windows.old\Windows\system32\dllcache\services.exe
[2004.08.17 14:49:28 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\Windows.old\Windows\system32\services.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2004.08.17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\Windows.old\Windows\system32\dllcache\svchost.exe
[2004.08.17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\Windows.old\Windows\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2011.04.25 06:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
[2011.09.29 18:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010.11.20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011.06.21 07:16:55 | 001,888,128 | ---- | M] (Microsoft Corporation) MD5=5279D4DD69C7C71524B8E7A5746D15CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_0f8ed978993fa916\tcpip.sys
[2010.06.14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2012.03.30 11:19:17 | 001,877,872 | ---- | M] (Microsoft Corporation) MD5=5EFD096DEF47F8B88EF591DA92143440 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_0faa5514992a39a7\tcpip.sys
[2011.04.25 06:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
[2012.03.30 12:09:53 | 001,895,280 | ---- | M] (Microsoft Corporation) MD5=624C5B3AA4C99B3184BB922D9ECE3FF0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_0f140fa780164fde\tcpip.sys
[2012.08.22 19:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2012.03.30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2011.04.25 06:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2004.08.03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\Windows.old\Windows\system32\dllcache\tcpip.sys
[2004.08.03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\Windows.old\Windows\system32\drivers\tcpip.sys
[2011.06.21 07:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
[2011.09.29 17:17:51 | 001,886,064 | ---- | M] (Microsoft Corporation) MD5=AC3E29880DB5659532A1AA3439304A43 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_0fad20ca992955d7\tcpip.sys
[2012.03.30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011.04.25 07:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011.06.21 07:27:14 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=B9D87C7707F058AC652A398CD28DE14B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_0f4d1e3b7feb1307\tcpip.sys
[2011.06.21 07:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
[2011.09.29 17:24:44 | 001,897,328 | ---- | M] (Microsoft Corporation) MD5=F18F56EFC0BFB9C87BA01C37B27F4DA5 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_0f170e9f80139ebc\tcpip.sys
[2012.08.22 19:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\SysNative\drivers\tcpip.sys
[2012.08.22 19:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
[2011.09.29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2004.08.17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\Windows.old\Windows\system32\dllcache\userinit.exe
[2004.08.17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\Windows.old\Windows\system32\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2004.08.17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\Windows.old\Windows\system32\dllcache\winlogon.exe
[2004.08.17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\Windows.old\Windows\system32\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< >

< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[4 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[13 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2011.02.10 18:37:17 | 024,758,792 | ---- | M] (Microsoft Corporation) -- C:\Net-Framework-2-0_2.0_Service_Pack 1.exe

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.04.05 14:53:38 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\.minecraft
[2013.01.07 20:21:04 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Adobe
[2013.01.16 23:01:11 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Apple Computer
[2011.08.02 15:07:11 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\ATI
[2014.11.15 00:04:06 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\AVAST Software
[2014.01.06 22:07:54 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Battle.net
[2014.09.18 12:52:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Bioshock
[2014.03.21 21:09:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\BSplayer
[2011.04.27 09:39:24 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Canon
[2014.07.14 22:39:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DAEMON Tools Lite
[2011.04.11 18:00:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DeviceVm
[2014.10.31 14:05:02 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Dropbox
[2012.03.03 15:31:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Foxit Software
[2011.08.03 08:51:29 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GameRanger
[2011.08.03 08:44:11 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GetRightToGo
[2011.08.03 15:08:54 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Hamachi
[2011.04.11 17:52:27 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Identities
[2014.03.26 20:35:28 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\InstallShield
[2014.03.14 19:24:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\library_dir
[2011.04.12 17:31:34 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Macromedia
[2009.07.14 08:45:14 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Media Center Programs
[2012.10.11 18:30:21 | 000,000,000 | --SD | M] -- C:\Users\HONZA\AppData\Roaming\Microsoft
[2011.05.31 15:50:06 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Mozilla
[2013.06.14 14:55:41 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\OpenCandy
[2013.02.21 17:48:46 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Origin
[2014.03.21 21:23:01 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Raptr
[2011.06.13 19:46:04 | 000,000,000 | RH-D | M] -- C:\Users\HONZA\AppData\Roaming\SecuROM
[2014.03.21 21:24:18 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Seznam.cz
[2014.11.16 21:36:13 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Skype
[2011.05.28 08:55:05 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\skypePM
[2014.03.21 21:49:34 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TeamViewer
[2014.11.14 21:43:37 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TS3Client
[2014.07.14 22:33:31 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TuneUp Software
[2014.05.25 23:11:05 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Tunngle
[2014.03.26 21:08:32 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Ubisoft
[2014.11.16 15:07:10 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\uTorrent
[2011.08.13 19:49:58 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\wargaming.net
[2011.07.09 10:04:42 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2010.09.19 04:58:42 | 000,232,504 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\.minecraft\Minecraft.exe
[2014.09.13 01:52:04 | 036,414,624 | ---- | M] (Dropbox, Inc.) -- C:\Users\HONZA\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2014.09.13 01:55:10 | 000,262,160 | ---- | M] (Dropbox, Inc.) -- C:\Users\HONZA\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe
[2014.09.13 01:52:08 | 000,225,256 | ---- | M] (Dropbox, Inc.) -- C:\Users\HONZA\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2014.06.09 00:55:55 | 001,820,832 | ---- | M] (GameRanger Technologies) -- C:\Users\HONZA\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
[2013.01.10 22:54:29 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\HONZA\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.10.11 18:30:21 | 000,010,134 | R--- | M] () -- C:\Users\HONZA\AppData\Roaming\Microsoft\Installer\{338CE2A1-7BD6-AC18-0069-4A90F7C3D836}\ARPPRODUCTICON.exe
[2014.07.22 15:48:09 | 000,011,502 | R--- | M] () -- C:\Users\HONZA\AppData\Roaming\Microsoft\Installer\{D5AD72DF-2A19-4164-8D8B-6127A66C582A}\Launcher.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2014.11.18 21:38:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2014.11.18 21:00:37 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014.11.17 22:45:00 | 000,000,952 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2014.11.17 23:06:00 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
[2014.11.18 21:06:09 | 000,000,962 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >

< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2011.02.10 18:37:17 | 024,758,792 | ---- | M] (Microsoft Corporation) -- C:\Net-Framework-2-0_2.0_Service_Pack 1.exe

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.04.11 10:54:22 | 003,672,384 | ---- | M] (DT Soft Ltd)
"SpeedUpMyComputer" = C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss
"FixMyRegistry" = C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
"Google Update" = "C:\Users\HONZA\AppData\Local\Google\Update\GoogleUpdate.exe" /c -- [2012.07.16 15:26:26 | 000,116,648 | ---- | M] (Google Inc.)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2014.11.17 09:47:32 | 000,275,568 | ---- | M] (Mozilla Corporation) MD5=7115853FF96289DF7F65FB6B68E095ED -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2010.11.20 13:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.11.18 21:21:17 | 000,000,512 | ---- | M] () MD5=741BF4C6E23C1DCCA606808B9C72D54A -- C:\PhysicalMBR.bin

< >

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#7 Příspěvek od Blicek »

< *crack* /s >
[2014.02.05 18:41:19 | 000,213,184 | ---- | M] () -- \GAMES\World_of_Tanks\res\audio\objects_ice_crack.fsb
[2011.11.13 03:28:50 | 000,000,152 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\nmrih\materials\nmrih\decals\BU_cracks001.vmt
[2011.11.13 03:28:48 | 000,349,760 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\nmrih\materials\nmrih\decals\BU_cracks001.vtf
[2011.11.13 03:28:48 | 000,000,152 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\nmrih\materials\nmrih\decals\BU_cracks002.vmt
[2011.11.13 03:28:46 | 000,349,760 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\sourcemods\nmrih\materials\nmrih\decals\BU_cracks002.vtf
[2013.03.10 13:46:17 | 000,000,100 | ---- | M] () -- \Users\HONZA\Desktop\Garry's Mod\garrysmod\addons\CSS Content Addon\materials\concrete\prodwllecracked.vmt
[2013.03.10 13:46:17 | 000,174,968 | ---- | M] () -- \Users\HONZA\Desktop\Garry's Mod\garrysmod\addons\CSS Content Addon\materials\concrete\prodwllecracked.vtf
[2013.06.05 17:55:10 | 000,036,360 | ---- | M] () -- \Users\HONZA\Desktop\Garry's Mod\garrysmod\sound\phx\eggcrack.wav

< *keygen* /s >
[2002.06.14 00:00:00 | 000,061,440 | ---- | M] () -- \GAMES\Warcraft III\warcraft3 keygen.exe

< *loader* /s >
[2010.08.27 19:43:08 | 000,071,008 | ---- | M] () -- \GAMES\Mafia IIinstalovano\pc\PhysXLoader.dll
[2011.03.31 18:20:33 | 000,109,330 | ---- | M] () -- \GAMES\StarCraft II\Logs\Downloader.log
[2011.03.31 18:19:26 | 002,639,424 | ---- | M] () -- \GAMES\StarCraft II\Support\BlizzardDownloader.exe
[2010.07.05 14:30:50 | 000,071,208 | ---- | M] () -- \GAMES\World_of_Tanks\PhysXLoader.dll
[2014.06.04 10:31:51 | 000,001,508 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\eulaversionloader.pyc
[2014.02.05 18:41:19 | 000,002,209 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\graphicspresetsloader.pyc
[2014.02.05 18:41:19 | 000,007,130 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\guicolorsloader.pyc
[2014.02.05 18:41:19 | 000,003,955 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\guisoundsloader.pyc
[2014.02.05 18:41:19 | 000,006,579 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\logindataloader.pyc
[2014.02.05 18:41:19 | 000,002,753 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\doc_loaders\windowsstoreddataloader.pyc
[2014.10.29 15:57:08 | 000,001,502 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\Scaleform\framework\entities\abstract\loadermanagermeta.pyc
[2014.10.29 15:57:08 | 000,006,833 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\gui\Scaleform\framework\managers\loaders.pyc
[2014.09.17 12:48:49 | 000,003,415 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\helpers\rssdownloader.pyc
[2014.10.29 15:57:08 | 000,007,582 | ---- | M] () -- \GAMES\World_of_Tanks\res\scripts\client\tutorial\loader.pyc
[2014.02.05 18:41:19 | 000,011,286 | ---- | M] () -- \GAMES\World_of_Tanks\res_bw\scripts\common\Lib\unittest\loader.pyc
[2013.05.31 18:21:46 | 000,000,147 | ---- | M] () -- \Program Files (x86)\Common Files\Blizzard Entertainment\BlizzardDownloader.ini
[2006.10.26 12:40:34 | 000,057,344 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.dll
[2006.10.26 12:40:34 | 000,005,120 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\coloader.tlb
[2014.01.22 22:58:36 | 000,791,552 | ---- | M] () -- \Program Files (x86)\Raptr\amddriverdownloader.exe
[2010.11.22 23:57:34 | 000,009,216 | ---- | M] () -- \Program Files (x86)\Raptr\_win32sysloader.pyd
[2012.09.11 22:32:10 | 000,182,405 | ---- | M] () -- \Program Files (x86)\StarCraft II\Logs\Downloader.log
[2013.10.23 21:07:40 | 000,007,825 | ---- | M] () -- \Program Files (x86)\Steam\remoteui\static\libs\images\ajax-loader.gif
[2012.09.25 16:16:32 | 000,058,880 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\PhysXLoader.dll
[2014.03.15 22:21:11 | 000,001,444 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\DEU\GD_Allium_LootMidgetLoaderBUL.DEU
[2014.03.15 22:21:05 | 000,000,764 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\DEU\GD_Allium_LootMidget_LoaderJET.DEU
[2014.03.15 22:20:53 | 000,000,710 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\DEU\GD_HolidayLoader.DEU
[2014.03.15 22:21:22 | 000,001,396 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ESN\GD_Allium_LootMidgetLoaderBUL.ESN
[2014.03.15 22:20:51 | 000,000,788 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ESN\GD_Allium_LootMidget_LoaderJET.ESN
[2014.03.15 22:20:51 | 000,000,734 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ESN\GD_HolidayLoader.ESN
[2014.03.15 22:20:53 | 000,001,414 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\FRA\GD_Allium_LootMidgetLoaderBUL.FRA
[2014.03.15 22:20:53 | 000,000,738 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\FRA\GD_Allium_LootMidget_LoaderJET.FRA
[2014.03.15 22:20:53 | 000,000,684 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\FRA\GD_HolidayLoader.FRA
[2014.03.15 22:20:52 | 000,001,440 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ITA\GD_Allium_LootMidgetLoaderBUL.ITA
[2014.03.15 22:20:52 | 000,000,784 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ITA\GD_Allium_LootMidget_LoaderJET.ITA
[2014.03.15 22:20:58 | 000,000,730 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\ITA\GD_HolidayLoader.ITA
[2014.03.15 22:20:59 | 000,001,270 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\JPN\GD_Allium_LootMidgetLoaderBUL.JPN
[2014.03.15 22:20:59 | 000,000,722 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\JPN\GD_Allium_LootMidget_LoaderJET.JPN
[2014.03.15 22:20:58 | 000,000,668 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\JPN\GD_HolidayLoader.JPN
[2014.07.15 19:31:32 | 000,001,250 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\KOR\GD_Allium_LootMidgetLoaderBUL.KOR
[2014.07.15 19:31:31 | 000,000,722 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\KOR\GD_Allium_LootMidget_LoaderJET.KOR
[2014.07.15 19:31:31 | 000,000,668 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Allium\Compat\Localization\KOR\GD_HolidayLoader.KOR
[2012.11.18 16:34:20 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderBadass.DEU
[2012.11.18 16:34:20 | 000,000,916 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderBUL.DEU
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderEXP.DEU
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderGUN.DEU
[2012.11.18 16:34:20 | 000,000,916 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderHOT.DEU
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderJET.DEU
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderPWR.DEU
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_LoaderRPG.DEU
[2012.11.18 16:34:35 | 000,002,656 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\DEU\GD_Iris_Population_Loader.DEU
[2012.11.18 16:34:20 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderBadass.ESN
[2012.11.18 16:34:36 | 000,000,852 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderBUL.ESN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderEXP.ESN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderGUN.ESN
[2012.11.18 16:34:21 | 000,000,852 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderHOT.ESN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderJET.ESN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderPWR.ESN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_LoaderRPG.ESN
[2012.11.18 16:34:21 | 000,002,868 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ESN\GD_Iris_Population_Loader.ESN
[2012.11.18 16:34:20 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderBadass.FRA
[2012.11.18 16:34:58 | 000,000,876 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderBUL.FRA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderEXP.FRA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderGUN.FRA
[2012.11.18 16:34:58 | 000,000,876 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderHOT.FRA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderJET.FRA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderPWR.FRA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_LoaderRPG.FRA
[2012.11.18 16:34:37 | 000,002,706 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\FRA\GD_Iris_Population_Loader.FRA
[2012.11.18 16:34:20 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderBadass.ITA
[2012.11.18 16:34:22 | 000,000,856 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderBUL.ITA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderEXP.ITA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderGUN.ITA
[2012.11.18 16:34:22 | 000,000,856 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderHOT.ITA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderJET.ITA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderPWR.ITA
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_LoaderRPG.ITA
[2012.11.18 16:34:41 | 000,002,754 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\ITA\GD_Iris_Population_Loader.ITA
[2012.11.18 16:34:20 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderBadass.JPN
[2012.11.18 16:35:01 | 000,000,748 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderBUL.JPN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderEXP.JPN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderGUN.JPN
[2012.11.18 16:34:42 | 000,000,748 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderHOT.JPN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderJET.JPN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderPWR.JPN
[2012.11.18 16:34:20 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_LoaderRPG.JPN
[2012.11.18 16:34:22 | 000,002,636 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\JPN\GD_Iris_Population_Loader.JPN
[2013.10.27 11:42:35 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderBadass.KOR
[2013.10.27 11:46:49 | 000,000,728 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderBUL.KOR
[2013.10.27 11:42:35 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderEXP.KOR
[2013.10.27 11:42:35 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderGUN.KOR
[2013.10.27 11:46:49 | 000,000,728 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderHOT.KOR
[2013.10.27 11:42:35 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderJET.KOR
[2013.10.27 11:42:35 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderPWR.KOR
[2013.10.27 11:42:35 | 000,000,222 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_LoaderRPG.KOR
[2013.10.27 11:42:35 | 000,002,636 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Iris\Compat\Localization\KOR\GD_Iris_Population_Loader.KOR
[2013.10.27 11:45:11 | 000,001,144 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\DEU\GD_BigLoaderTurret_Digi.DEU
[2013.10.27 11:46:58 | 000,000,570 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\DEU\GD_LoaderUltimateBadass_Digi.DEU
[2013.10.27 11:44:48 | 000,001,102 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\ESN\GD_BigLoaderTurret_Digi.ESN
[2013.10.27 11:47:01 | 000,000,572 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\ESN\GD_LoaderUltimateBadass_Digi.ESN
[2013.10.27 11:46:04 | 000,001,128 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\FRA\GD_BigLoaderTurret_Digi.FRA
[2013.10.27 11:45:13 | 000,000,574 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\FRA\GD_LoaderUltimateBadass_Digi.FRA
[2013.10.27 11:46:04 | 000,001,108 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\ITA\GD_BigLoaderTurret_Digi.ITA
[2013.10.27 11:46:58 | 000,000,570 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\ITA\GD_LoaderUltimateBadass_Digi.ITA
[2013.10.27 11:46:09 | 000,000,990 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\JPN\GD_BigLoaderTurret_Digi.JPN
[2013.10.27 11:46:58 | 000,000,570 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\JPN\GD_LoaderUltimateBadass_Digi.JPN
[2014.07.15 19:32:19 | 000,000,956 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\KOR\GD_BigLoaderTurret_Digi.KOR
[2014.07.15 19:31:31 | 000,000,570 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Lobelia\Compat\Localization\KOR\GD_LoaderUltimateBadass_Digi.KOR
[2014.03.15 22:22:30 | 000,000,434 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\DEU\GD_BlingLoader.DEU
[2014.03.15 22:22:36 | 000,000,466 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\DEU\GD_BlingLoader_Mini.DEU
[2014.03.15 22:21:45 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\DEU\GD_Nast_BadassJunkLoader.DEU
[2014.03.15 22:25:12 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\DEU\GD_Nast_Girl_Loader.DEU
[2014.03.15 22:21:59 | 000,000,440 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ESN\GD_BlingLoader.ESN
[2014.03.15 22:21:59 | 000,000,472 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ESN\GD_BlingLoader_Mini.ESN
[2014.03.15 22:21:45 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ESN\GD_Nast_BadassJunkLoader.ESN
[2014.03.15 22:25:12 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ESN\GD_Nast_Girl_Loader.ESN
[2014.03.15 22:21:58 | 000,000,438 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\FRA\GD_BlingLoader.FRA
[2014.03.15 22:21:46 | 000,000,470 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\FRA\GD_BlingLoader_Mini.FRA
[2014.03.15 22:21:45 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\FRA\GD_Nast_BadassJunkLoader.FRA
[2014.03.15 22:25:12 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\FRA\GD_Nast_Girl_Loader.FRA
[2014.03.15 22:22:32 | 000,000,442 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ITA\GD_BlingLoader.ITA
[2014.03.15 22:24:19 | 000,000,474 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ITA\GD_BlingLoader_Mini.ITA
[2014.03.15 22:21:45 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ITA\GD_Nast_BadassJunkLoader.ITA
[2014.03.15 22:25:12 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\ITA\GD_Nast_Girl_Loader.ITA
[2014.03.15 22:22:30 | 000,000,434 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\JPN\GD_BlingLoader.JPN
[2014.03.15 22:22:36 | 000,000,466 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\JPN\GD_BlingLoader_Mini.JPN
[2014.03.15 22:21:45 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\JPN\GD_Nast_BadassJunkLoader.JPN
[2014.03.15 22:25:12 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\JPN\GD_Nast_Girl_Loader.JPN
[2014.07.15 19:31:32 | 000,000,434 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\KOR\GD_BlingLoader.KOR
[2014.07.15 19:31:32 | 000,000,466 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\KOR\GD_BlingLoader_Mini.KOR
[2014.07.15 19:31:32 | 000,000,446 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\KOR\GD_Nast_BadassJunkLoader.KOR
[2014.07.15 19:31:32 | 000,000,426 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Nasturtium\Compat\Localization\KOR\GD_Nast_Girl_Loader.KOR
[2012.10.12 23:02:44 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderBadass.DEU
[2012.10.12 23:02:36 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderBoss.DEU
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderBUL.DEU
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderEXP.DEU
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderGUN.DEU
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderHOT.DEU
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderION.DEU
[2012.10.12 23:03:12 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderJunk.DEU
[2012.10.12 23:02:41 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderPirate.DEU
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderPWR.DEU
[2012.10.12 23:02:41 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderRPG.DEU
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_LoaderWAR.DEU
[2012.10.12 23:02:37 | 000,004,418 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_Pop_Loader.DEU
[2012.10.12 23:02:44 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\DEU\GD_Orchid_Pop_LoaderBoss.DEU
[2012.10.12 23:02:44 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderBadass.ESN
[2012.10.12 23:02:36 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderBoss.ESN
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderBUL.ESN
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderEXP.ESN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderGUN.ESN
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderHOT.ESN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderION.ESN
[2012.10.12 23:03:12 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderJunk.ESN
[2012.10.12 23:02:41 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderPirate.ESN
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderPWR.ESN
[2012.10.12 23:02:41 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderRPG.ESN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_LoaderWAR.ESN
[2012.10.12 23:03:14 | 000,004,550 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_Pop_Loader.ESN
[2012.10.12 23:02:44 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ESN\GD_Orchid_Pop_LoaderBoss.ESN
[2012.10.12 23:02:44 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderBadass.FRA
[2012.10.12 23:02:36 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderBoss.FRA
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderBUL.FRA
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderEXP.FRA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderGUN.FRA
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderHOT.FRA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderION.FRA
[2012.10.12 23:03:12 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderJunk.FRA
[2012.10.12 23:02:41 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderPirate.FRA
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderPWR.FRA
[2012.10.12 23:02:41 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderRPG.FRA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_LoaderWAR.FRA
[2012.10.12 23:02:44 | 000,004,486 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_Pop_Loader.FRA
[2012.10.12 23:02:44 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\FRA\GD_Orchid_Pop_LoaderBoss.FRA
[2012.10.12 23:02:44 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderBadass.ITA
[2012.10.12 23:02:36 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderBoss.ITA
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderBUL.ITA
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderEXP.ITA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderGUN.ITA
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderHOT.ITA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderION.ITA
[2012.10.12 23:03:12 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderJunk.ITA
[2012.10.12 23:02:41 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderPirate.ITA
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderPWR.ITA
[2012.10.12 23:02:41 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderRPG.ITA
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_LoaderWAR.ITA
[2012.10.12 23:03:19 | 000,004,558 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_Pop_Loader.ITA
[2012.10.12 23:02:44 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\ITA\GD_Orchid_Pop_LoaderBoss.ITA
[2012.10.12 23:02:44 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderBadass.JPN
[2012.10.12 23:02:36 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderBoss.JPN
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderBUL.JPN
[2012.10.12 23:02:40 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderEXP.JPN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderGUN.JPN
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderHOT.JPN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderION.JPN
[2012.10.12 23:03:12 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderJunk.JPN
[2012.10.12 23:02:41 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderPirate.JPN
[2012.10.12 23:02:44 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderPWR.JPN
[2012.10.12 23:02:41 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderRPG.JPN
[2012.10.12 23:03:12 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_LoaderWAR.JPN
[2012.10.12 23:02:37 | 000,004,418 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_Pop_Loader.JPN
[2012.10.12 23:02:44 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\JPN\GD_Orchid_Pop_LoaderBoss.JPN
[2013.10.27 11:42:38 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderBadass.KOR
[2013.10.27 11:42:38 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderBoss.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderBUL.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderEXP.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderGUN.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderHOT.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderION.KOR
[2013.10.27 11:42:38 | 000,000,228 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderJunk.KOR
[2013.10.27 11:42:38 | 000,000,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderPirate.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderPWR.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderRPG.KOR
[2013.10.27 11:42:38 | 000,000,226 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_LoaderWAR.KOR
[2013.10.27 11:42:38 | 000,004,418 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_Pop_Loader.KOR
[2013.10.27 11:42:38 | 000,000,216 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Orchid\Compat\Localization\KOR\GD_Orchid_Pop_LoaderBoss.KOR
[2012.12.13 19:42:30 | 000,000,892 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Sage\Compat\Localization\ESN\GD_Sage_Pop_Loader.ESN
[2012.12.13 19:42:33 | 000,000,874 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Sage\Compat\Localization\FRA\GD_Sage_Pop_Loader.FRA
[2012.12.13 19:42:32 | 000,000,898 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Sage\Compat\Localization\ITA\GD_Sage_Pop_Loader.ITA
[2013.10.27 11:46:32 | 000,000,866 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\DLC\Sage\Compat\Localization\KOR\GD_Sage_Pop_Loader.KOR
[2012.09.25 16:08:23 | 003,465,909 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\CookedPCConsole\Boss_Cliffs_CombatLoader.upk
[2012.09.25 16:11:03 | 000,032,232 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\CookedPCConsole\Loader.upk
[2012.09.25 16:17:23 | 000,001,140 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\DEU\GD_BigLoaderTurret.DEU
[2012.09.25 16:17:24 | 000,000,504 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\DEU\GD_LootMidget_LoaderGUN.DEU
[2012.09.25 16:16:52 | 000,009,492 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\DEU\GD_Population_Loader.DEU
[2012.09.25 16:16:53 | 000,001,072 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ESN\GD_BigLoaderTurret.ESN
[2012.09.25 16:17:27 | 000,000,518 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ESN\GD_LootMidget_LoaderGUN.ESN
[2012.09.25 16:17:27 | 000,009,746 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ESN\GD_Population_Loader.ESN
[2012.09.25 16:17:28 | 000,001,098 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\FRA\GD_BigLoaderTurret.FRA
[2012.09.25 16:17:39 | 000,000,514 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\FRA\GD_LootMidget_LoaderGUN.FRA
[2012.09.25 16:17:39 | 000,009,610 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\FRA\GD_Population_Loader.FRA
[2012.09.25 16:17:31 | 000,001,068 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ITA\GD_BigLoaderTurret.ITA
[2012.09.25 16:17:31 | 000,000,530 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ITA\GD_LootMidget_LoaderGUN.ITA
[2012.09.25 16:17:00 | 000,009,798 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\ITA\GD_Population_Loader.ITA
[2012.09.25 16:17:02 | 000,000,946 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\JPN\GD_BigLoaderTurret.JPN
[2012.09.25 16:17:43 | 000,000,502 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\JPN\GD_LootMidget_LoaderGUN.JPN
[2012.09.25 16:17:43 | 000,009,486 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Borderlands 2\WillowGame\Localization\JPN\GD_Population_Loader.JPN
[2011.04.22 02:03:50 | 000,022,574 | R--- | M] () -- \Program Files (x86)\The Witcher 2 (CZ)\CookedPC\globals\gui\loadingscreens\loader.swf
[2014.11.15 00:03:13 | 000,072,480 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
[2014.11.15 00:03:13 | 000,085,376 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader64.exe
[2011.05.28 21:04:04 | 000,054,784 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2014.11.16 14:44:01 | 000,001,043 | ---- | M] () -- \ProgramData\Spybot - Search & Destroy\Recovery\WinDownloadergen.zip
[2014.11.16 14:44:01 | 000,010,189 | ---- | M] () -- \ProgramData\Spybot - Search & Destroy\Recovery\WinDownloadergen1.zip
[2014.11.16 14:44:01 | 000,000,337 | ---- | M] () -- \ProgramData\Spybot - Search & Destroy\Recovery\WinDownloadergen2.zip
[2014.11.16 14:44:01 | 000,317,103 | ---- | M] () -- \ProgramData\Spybot - Search & Destroy\Recovery\WinDownloadergen3.zip
[2014.11.16 14:44:00 | 000,000,825 | ---- | M] () -- \ProgramData\Spybot - Search & Destroy\Recovery\YourFileDownloader.zip
[2014.11.16 14:44:01 | 000,001,043 | ---- | M] () -- \Users\All Users\Spybot - Search & Destroy\Recovery\WinDownloadergen.zip
[2014.11.16 14:44:01 | 000,010,189 | ---- | M] () -- \Users\All Users\Spybot - Search & Destroy\Recovery\WinDownloadergen1.zip
[2014.11.16 14:44:01 | 000,000,337 | ---- | M] () -- \Users\All Users\Spybot - Search & Destroy\Recovery\WinDownloadergen2.zip
[2014.11.16 14:44:01 | 000,317,103 | ---- | M] () -- \Users\All Users\Spybot - Search & Destroy\Recovery\WinDownloadergen3.zip
[2014.11.16 14:44:00 | 000,000,825 | ---- | M] () -- \Users\All Users\Spybot - Search & Destroy\Recovery\YourFileDownloader.zip
[2013.06.22 07:50:29 | 000,000,723 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\img\ajax-loader.gif
[2013.06.22 07:50:29 | 000,000,018 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\js\newtab_loader.js
[2013.06.22 07:50:29 | 000,000,343 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\js\setup_loader.js
[2014.10.28 17:09:30 | 000,000,300 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\build\js\cs-loader.js
[2014.10.28 17:09:30 | 000,000,214 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\build\js\js-loader.js
[2014.08.13 13:14:30 | 000,009,418 | ---- | M] () -- \Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\img\gifloader.gif
[2012.05.18 19:48:14 | 000,057,728 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png
[2012.05.18 19:48:14 | 000,057,728 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png
[2012.05.18 19:48:14 | 000,057,728 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png
[2012.05.18 19:48:14 | 000,057,728 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin3\dt_dadget_loader.png
[2012.05.18 19:48:15 | 000,057,728 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin4\dt_dadget_loader.png
[2012.05.18 19:48:15 | 000,061,770 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin5\dt_dadget_loader.png
[2012.05.18 19:48:15 | 000,061,770 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin6\dt_dadget_loader.png
[2014.11.16 21:36:07 | 000,001,980 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CG1GP6L4\AdLoader[1].htm
[2014.11.16 21:36:07 | 000,019,075 | ---- | M] () -- \Users\HONZA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XN755HIU\AdLoader-1e2a66f59d6cdbb4b88978ac4dfd3746.min[1].js
[2014.07.24 14:53:16 | 000,072,638 | ---- | M] () -- \Users\HONZA\AppData\Local\Skype\Apps\login\images\loader.gif
[2014.07.24 14:53:16 | 000,003,032 | ---- | M] () -- \Users\HONZA\AppData\Local\Skype\Apps\login\images\loader.png
[2014.07.24 14:53:16 | 000,006,012 | ---- | M] () -- \Users\HONZA\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2014.07.24 14:53:16 | 000,021,956 | ---- | M] () -- \Users\HONZA\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2014.07.24 14:53:16 | 000,009,772 | ---- | M] () -- \Users\HONZA\AppData\Local\Skype\Apps\login\images\retina\loader@2x.png
[2014.11.16 12:07:54 | 000,000,022 | ---- | M] () -- \Users\HONZA\AppData\Local\Temp\avastBCLTMP\oneclickdownloader@oneclickdownloader.com.zip
[2011.08.03 08:44:03 | 000,000,000 | ---- | M] () -- \Users\HONZA\AppData\Roaming\GetRightToGo\Brothersoftdownloader_for_Hamachi.data
[2012.06.07 20:16:16 | 000,010,145 | ---- | M] () -- \Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\conduitCommon\modules\3.13.0.6\ExternalLibraryLoader.jsm
[2012.08.27 16:56:10 | 000,010,145 | ---- | M] () -- \Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\conduitCommon\modules\3.15.1.0\ExternalLibraryLoader.jsm
[2013.03.27 15:36:26 | 000,010,145 | ---- | M] () -- \Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\conduitCommon\modules\3.18.0.7\ExternalLibraryLoader.jsm
[2008.02.18 00:02:54 | 000,253,691 | ---- | M] () -- \Users\HONZA\Desktop\Audiosurf\engine\Preloader.cgr
[2008.02.18 00:02:44 | 000,000,878 | ---- | M] () -- \Users\HONZA\Desktop\Audiosurf\engine\Preloader_config.xml
[2008.02.18 00:02:26 | 000,016,384 | ---- | M] () -- \Users\HONZA\Desktop\Audiosurf\engine\channels\FileLoader.dll
[2013.06.05 17:49:48 | 000,009,136 | ---- | M] () -- \Users\HONZA\Desktop\Garry's Mod\garrysmod\materials\spawnicons\models\props_trainyard\train_loader001.png
[2010.01.28 21:52:11 | 010,750,324 | ---- | M] () -- \Users\HONZA\Desktop\New Windows 7 Activator [2010]\7Loader Release 5.exe
[2010.09.18 14:25:42 | 010,750,324 | ---- | M] () -- \Users\HONZA\Desktop\New Windows 7 Activator [2010]\New Windows 7 Activator [2010]\7Loader Release 5.exe
[2007.06.02 09:27:24 | 000,084,930 | ---- | M] () -- \Users\HONZA\Desktop\StarCraft Brood War\scloader2b.exe
[2007.06.02 11:20:24 | 000,008,783 | ---- | M] () -- \Users\HONZA\Desktop\StarCraft Brood War\scloader2b.txt
[2010.09.29 14:30:20 | 002,639,424 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\BackgroundDownloader.exe
[2010.09.29 14:29:40 | 002,705,537 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\wow-2.1.1.1897-enGB-tools-downloader.exe
[2010.09.01 14:01:32 | 002,400,032 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.2.2.10505-to-3.3.0.10958-enGB-downloader.exe
[2010.09.01 15:13:24 | 002,336,112 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.0.10958-to-3.3.0.11159-enGB-downloader.exe
[2010.09.01 15:14:10 | 002,350,144 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.0.11159-to-3.3.2.11403-enGB-downloader.exe
[2010.09.01 15:36:08 | 002,654,392 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.2.11403-to-3.3.3.11685-enGB-downloader.exe
[2010.09.01 15:54:40 | 002,640,192 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.3.11685-to-3.3.3.11723-enGB-downloader.exe
[2010.09.01 15:56:16 | 002,711,048 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.3.11723-to-3.3.5.12213-enGB-downloader.exe
[2010.09.29 14:32:54 | 002,710,448 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.5.12213-to-3.3.5.12340-enGB-downloader.exe
[2010.11.16 17:10:34 | 003,075,979 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-3.3.5.12340-x86-Win-enGB-BKGND-downloader.exe
[2011.05.21 09:45:43 | 002,070,207 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe
[2009.10.11 07:42:28 | 000,003,026 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\Data\enGB\Documentation\Troubleshooting\(Mac)BlizzardDownloaderProblems.html
[2009.10.11 07:42:28 | 000,004,261 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\Data\enGB\Documentation\Troubleshooting\(PC)BlizzardDownloaderProblems.html
[2013.05.31 18:21:47 | 000,066,328 | ---- | M] () -- \Users\HONZA\Desktop\WoW(wotlk)\Logs\Downloader.log
[2014.10.23 19:04:02 | 003,601,992 | ---- | M] () -- \Users\HONZA\Downloads\Advanced_Trainer_Six_Practice_Tests_With_Answers_Download_downloader.exe
[2011.05.21 09:46:03 | 000,002,003 | ---- | M] () -- \Users\Public\Documents\Blizzard Entertainment\World of Warcraft\Logs\Downloader.log
[2011.01.08 22:09:22 | 000,006,820 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\0FAMDD1O\ajax-loader-big[1].gif
[2011.01.08 22:09:34 | 000,010,819 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\0FAMDD1O\ajax-loader[1].gif
[2011.01.25 18:27:29 | 000,106,490 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\5EXI6NKJ\Preloader.25615[1].htm
[2011.01.21 20:07:58 | 000,000,124 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\9YOZOIEO\iframes_api_loader[1].html
[2011.01.22 09:46:39 | 000,106,490 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\E2DY3V76\Preloader.25433[1].htm
[2011.01.27 17:44:28 | 000,002,041 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\K053CVCX\loader[1].js
[2011.01.24 22:40:22 | 000,003,932 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\X3KGG7W8\uploaderapi2[2].swf
[2011.01.22 21:07:58 | 000,106,490 | ---- | M] () -- \Windows.old\Documents and Settings\HONZA\Local Settings\Temporary Internet Files\Content.IE5\YPIQ2LT7\Preloader.25440[1].htm
[2003.12.24 12:26:40 | 000,004,960 | ---- | M] () -- \Windows.old\Program Files\Zuma Deluxe\images\loaderbar.gif
[2003.12.24 12:26:40 | 000,001,064 | ---- | M] () -- \Windows.old\Program Files\Zuma Deluxe\images\_loaderbar.gif
[2011.01.05 21:15:21 | 000,082,784 | ---- | M] () -- \Windows.old\Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2004.08.17 14:49:06 | 000,035,840 | ---- | M] () -- \Windows.old\Windows\system32\dmloader.dll
[1 \Windows.old\Windows\system32\*.tmp files -> \Windows.old\Windows\system32\*.tmp -> ]
[2004.08.17 14:49:06 | 000,035,840 | ---- | M] () -- \Windows.old\Windows\system32\dllcache\dmloader.dll
[2011.05.03 15:53:37 | 000,082,784 | ---- | M] () -- \Windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2014.11.15 00:03:48 | 000,013,898 | ---- | M] () -- \Windows\Prefetch\ASWWRCIELOADER32.EXE-F211C07F.pf
[2014.11.15 00:03:49 | 000,011,234 | ---- | M] () -- \Windows\Prefetch\ASWWRCIELOADER64.EXE-49148940.pf
[2011.02.05 14:09:31 | 000,005,745 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.02.05 14:04:44 | 000,005,745 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2011.02.05 18:34:23 | 000,005,745 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.02.05 14:09:57 | 000,005,745 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2011.02.05 14:09:50 | 000,005,799 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_9c05f879842e1792.manifest
[2011.02.05 14:05:03 | 000,005,799 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_9c6455949d6c2720.manifest
[2011.02.05 18:34:40 | 000,005,799 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_9deb553581556a27.manifest
[2011.02.05 14:10:12 | 000,005,799 | ---- | M] () -- \Windows\SoftwareDistribution\Download\d639f7376b627c8f37f9acbbf7c6234a\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_9e73f1b69a73f09a.manifest
[2011.07.16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2008.10.29 08:03:06 | 000,070,936 | ---- | M] () -- \Windows\System32\PhysXLoader.dll
[2011.07.16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2008.10.29 08:03:06 | 000,070,936 | ---- | M] () -- \Windows\SysWOW64\PhysXLoader.dll
[2009.07.14 02:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 02:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.02 07:23:09 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16823_none_66e5ca0f95521152\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:04:54 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_66c2596d956d1920\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 07:39:29 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.20978_none_673e58b0ae93bb84\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:06:43 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_67770e0aae6a7c68\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 07:44:53 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_68ce27a99276afec\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:21:03 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 07:40:10 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_694ff566ab99b7ac\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 06:12:44 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.04.11 19:02:16 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2011.04.11 19:02:16 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.efi.mui_35ee487d
[2011.04.11 19:02:16 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.exe.mui_3bc5b827
[2011.04.11 19:02:16 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.efi.mui_f412814e
[2011.04.11 19:02:16 | 000,030,288 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.exe.mui_ff8b5358
[2009.07.14 06:37:37 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2009.07.14 06:37:37 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.efi.mui_35ee487d
[2009.07.14 06:37:37 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winload.exe.mui_3bc5b827
[2009.07.14 06:37:37 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.efi.mui_f412814e
[2009.07.14 06:37:37 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a_winresume.exe.mui_ff8b5358
[2011.10.23 18:04:52 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.10.23 18:04:52 | 000,642,944 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.efi_75834aa0
[2011.10.23 18:04:52 | 000,605,552 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winload.exe_75835076
[2011.10.23 18:04:52 | 000,566,208 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.efi_85cd069f
[2011.10.23 18:04:53 | 000,518,672 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb_winresume.exe_85cd1215
[2009.07.14 03:57:50 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 03:57:50 | 000,019,008 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59_spldr.sys_98bd87a0
[2009.07.13 18:18:36 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2009.07.14 03:44:20 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d28dabacfdb4dd1a.manifest
[2009.07.14 03:13:42 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef.manifest
[2011.02.05 14:09:31 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16757_none_b73e23c9863dba66.manifest
[2011.02.05 14:04:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.20897_none_b79c80e49f7bc9f4.manifest
[2010.11.20 05:12:44 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_b94cbfa183466a89.manifest
[2011.02.05 18:34:23 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17556_none_b923808583650cfb.manifest
[2011.02.05 14:09:57 | 000,005,745 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.21655_none_b9ac1d069c83936e.manifest
[2009.07.14 03:18:27 | 000,002,896 | ---- | M] () -- \Windows\winsxs\Manifests\amd64_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_c72819e06acceb59.manifest
[2009.07.14 02:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 02:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.02 06:45:50 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16823_none_0ac72e8bdcf4a01c\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:19:58 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16850_none_0aa3bde9dd0fa7ea\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 06:50:16 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.20978_none_0b1fbd2cf6364a4e\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:12:45 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.21010_none_0b587286f60d0b32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 06:47:28 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_0caf8c25da193eb6\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:15:45 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_0c8b1b39da352d2d\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 07:56:06 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_0d3159e2f33c4676\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 05:36:48 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_0d001876f3621e30\api-ms-win-core-libraryloader-l1-1-0.dll

< End of report >

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#8 Příspěvek od Rudy »

Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text:
:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5193
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes,DefaultScope = {6905ACDE-7F92-4e73-BDCB-439196EB6C7B}
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{9001BA8A-679D-4922-88D4-94BE02ED450C}: "URL" = http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=UJ&apn_dtid=YYYYYYYYCZ&apn_uid=5f1cb5c7-08ae-4ae3-a5ba-dffd7cc16f00&apn_sauid=AC8580DA-0551-4872-B0B8-A4F705034330
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253
[2011.11.23 18:00:38 | 000,002,401 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\askcom.xml
[2014.03.21 18:08:04 | 000,006,226 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\buenosearch.xml
[2013.03.30 14:25:23 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-1.xml
[2011.08.28 15:08:45 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-2.xml
[2011.09.01 20:17:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-3.xml
[2011.09.10 20:10:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-4.xml
[2011.09.28 20:10:15 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-5.xml
[2011.10.02 12:07:10 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-6.xml
[2011.11.08 18:12:40 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-7.xml
[2011.08.15 18:28:43 | 000,001,056 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin.xml
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib\4.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfgdmpfihlmdekaclngibpjhdebndhdj\1.16_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell - "" = AutoRun
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation)

:files
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#9 Příspěvek od Blicek »

OTL logfile created on: 18.11.2014 22:55:19 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HONZA\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

12,00 Gb Total Physical Memory | 8,26 Gb Available Physical Memory | 68,80% Memory free
18,00 Gb Paging File | 14,12 Gb Available in Paging File | 78,46% Paging File free
Paging file location(s): C:\pagefile.sys 6142 6142 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 54,33 Gb Free Space | 11,66% Space Free | Partition Type: NTFS
Drive F: | 5,13 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: HONZA-PC | User Name: HONZA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014.11.18 21:17:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HONZA\Downloads\OTL.exe
PRC - [2014.11.15 00:03:13 | 005,225,064 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014.11.15 00:03:13 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.10.23 19:05:18 | 001,409,984 | ---- | M] (http://lucky-tab.com/) -- C:\Program Files (x86)\LuckyTab\LuckyTab.exe
PRC - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2013.12.18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010.11.20 13:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010.04.27 09:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.03.05 09:15:12 | 000,235,752 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010.03.05 09:15:04 | 000,411,864 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2005.04.18 16:49:38 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe


========== Modules (No Company Name) ==========

MOD - [2014.11.15 00:03:13 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014.11.06 00:57:01 | 008,911,176 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\pdf.dll
MOD - [2014.11.06 00:56:57 | 001,042,760 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\libglesv2.dll
MOD - [2014.11.06 00:56:55 | 000,211,272 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\libegl.dll
MOD - [2014.11.06 00:56:54 | 001,681,224 | ---- | M] () -- C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\ffmpegsumo.dll
MOD - [2009.07.31 20:39:08 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2005.04.18 16:49:38 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Jetway Multimedia\Hybrid Tera-vision Receiver Utilities\HMP3XCtl.exe


========== Services (SafeList) ==========

SRV:64bit: - [2014.11.15 00:03:13 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2013.12.06 21:52:10 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2013.12.06 16:06:06 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.11.12 18:26:48 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2013.12.18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.11.06 17:30:44 | 000,758,224 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2013.06.29 11:16:00 | 000,107,832 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWow64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012.07.02 12:44:54 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.06.14 23:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011.06.13 19:22:33 | 000,066,872 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWow64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.11.20 13:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010.03.05 09:15:12 | 000,235,752 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2014.11.15 00:03:15 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2014.11.15 00:03:15 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014.11.15 00:03:15 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014.11.15 00:03:14 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014.11.15 00:03:14 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014.11.15 00:03:14 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014.11.15 00:03:14 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014.11.15 00:03:11 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.12.06 22:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2013.12.06 22:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.12.06 21:21:44 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.09.24 15:53:50 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2.0)
DRV:64bit: - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2012.05.18 19:47:04 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.06.23 10:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.04.27 08:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.04.27 08:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.02.18 08:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.09.16 07:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t)
DRV:64bit: - [2009.08.23 23:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2009.07.16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:32:37 | 001,627,520 | ---- | M] (NXP Semiconductors) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ph3xIB64.sys -- (Ph3xIB64)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5193
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes,DefaultScope = {6905ACDE-7F92-4e73-BDCB-439196EB6C7B}
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{5D836038-8946-4636-B371-69AF13033DD5}: "URL" = http://www.google.com/custom?client=pub ... earchTerms}
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6905ACDE-7F92-4e73-BDCB-439196EB6C7B}: "URL" = http://uk.search.yahoo.com/search?p={se ... &type=EGMB
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{9001BA8A-679D-4922-88D4-94BE02ED450C}: "URL" = http://websearch.ask.com/redirect?clien ... F705034330
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Seznam"
FF - prefs.js..browser.search.defaultenginename: "Seznam"
FF - prefs.js..browser.search.defaultthis.engineName: "Seznam"
FF - prefs.js..browser.search.defaulturl: "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
FF - prefs.js..browser.search.order.1: "Seznam"
FF - prefs.js..browser.search.selectedEngine: "Seznam"
FF - prefs.js..browser.startup.homepage: "https://www.seznam.cz/?clid=22668"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1.1
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\HONZA\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\HONZA\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.11.15 00:03:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014.11.17 09:47:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011.05.31 15:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HONZA\AppData\Roaming\Mozilla\Extensions
[2014.11.15 00:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\extensions
[2011.11.23 18:00:38 | 000,002,401 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\askcom.xml
[2014.03.21 18:08:04 | 000,006,226 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\buenosearch.xml
[2013.03.30 14:25:23 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-1.xml
[2011.08.28 15:08:45 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-2.xml
[2011.09.01 20:17:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-3.xml
[2011.09.10 20:10:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-4.xml
[2011.09.28 20:10:15 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-5.xml
[2011.10.02 12:07:10 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-6.xml
[2011.11.08 18:12:40 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-7.xml
[2011.08.15 18:28:43 | 000,001,056 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin.xml
[2014.11.17 12:27:47 | 000,002,427 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\seznam-avast.xml
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.02 08:26:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014.11.17 09:47:34 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\Application\38.0.2125.122\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib\4.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfgdmpfihlmdekaclngibpjhdebndhdj\1.16_0\
CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\

O1 HOSTS File: ([2014.11.14 22:08:49 | 000,000,860 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll File not found
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll File not found
O3 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss File not found
O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4C31E73E-AD0A-452F-9D6B-BC6B29F48C88}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\syswow64\userinit.exe) - c:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.01.05 20:22:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation) - F:\autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:27 | 000,058,601 | R--- | M] () - F:\autorun.ico -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:27 | 000,000,047 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2008.02.22 17:08:44 | 000,000,382 | R--- | M] () - F:\autorun.ini -- [ UDF ]
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell - "" = AutoRun
O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[CREATERESTOREPOINT]
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2014.11.16 17:42:42 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.11.16 17:42:42 | 000,000,000 | ---D | C] -- C:\rsit
[2014.11.16 14:18:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2014.11.16 14:18:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2014.11.16 14:18:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2014.11.15 00:04:06 | 000,000,000 | ---D | C] -- C:\Users\HONZA\AppData\Roaming\AVAST Software
[2014.11.15 00:03:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014.11.15 00:03:30 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.11.15 00:03:29 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.11.15 00:03:27 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014.11.15 00:03:25 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.11.15 00:03:22 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014.11.15 00:03:19 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.11.15 00:03:14 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.11.15 00:01:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014.11.15 00:00:12 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014.11.01 10:11:45 | 000,000,000 | ---D | C] -- C:\Users\HONZA\Desktop\ČZU
[2014.10.31 14:43:54 | 000,000,000 | ---D | C] -- C:\Users\HONZA\Desktop\Učebnice
[2014.10.26 09:31:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014.10.26 09:31:06 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.10.26 09:31:00 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.10.26 09:31:00 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.10.26 09:31:00 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.10.23 19:05:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LuckyTab
[2014.10.20 21:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014.10.20 21:05:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HONZA\Desktop\*.tmp files -> C:\Users\HONZA\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014.11.18 22:45:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.18 22:38:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.11.18 22:06:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job
[2014.11.18 21:21:17 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.18 21:05:39 | 001,624,214 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.11.18 21:05:39 | 000,681,538 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2014.11.18 21:05:39 | 000,667,180 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.11.18 21:05:39 | 000,148,562 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2014.11.18 21:05:39 | 000,128,112 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.11.18 21:05:38 | 000,010,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.11.18 21:05:38 | 000,010,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.18 21:00:37 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.11.18 21:00:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.11.18 21:00:20 | 1073,090,558 | -HS- | M] () -- C:\hiberfil.sys
[2014.11.17 23:06:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
[2014.11.17 18:15:37 | 000,408,788 | ---- | M] () -- C:\Users\HONZA\Desktop\Substituenty.png
[2014.11.17 12:27:47 | 000,001,118 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014.11.17 11:45:28 | 000,160,173 | ---- | M] () -- C:\Users\HONZA\Desktop\Bez názvu.jpg
[2014.11.16 21:18:58 | 000,002,008 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.11.16 14:18:12 | 000,001,282 | ---- | M] () -- C:\Users\HONZA\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2014.11.16 14:18:12 | 000,001,258 | ---- | M] () -- C:\Users\HONZA\Desktop\Spybot - Search & Destroy.lnk
[2014.11.15 00:16:36 | 000,002,364 | ---- | M] () -- C:\Users\HONZA\Desktop\Google Chrome.lnk
[2014.11.15 00:04:29 | 000,050,280 | ---- | M] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014.11.15 00:03:15 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.11.15 00:03:15 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.11.15 00:03:15 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.11.15 00:03:14 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.11.15 00:03:14 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.11.15 00:03:14 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014.11.15 00:03:14 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.11.15 00:03:14 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.11.15 00:03:14 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.11.15 00:03:11 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014.11.12 18:26:48 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.11.12 18:26:48 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.11.01 15:01:50 | 477,818,178 | ---- | M] () -- C:\Users\HONZA\Desktop\blbosti.zip
[2014.10.26 09:30:56 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.10.26 09:30:55 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.10.26 09:30:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.10.26 09:30:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.10.20 21:05:11 | 000,002,533 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HONZA\Desktop\*.tmp files -> C:\Users\HONZA\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014.11.18 21:21:17 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.11.17 18:15:37 | 000,408,788 | ---- | C] () -- C:\Users\HONZA\Desktop\Substituenty.png
[2014.11.17 11:45:28 | 000,160,173 | ---- | C] () -- C:\Users\HONZA\Desktop\Bez názvu.jpg
[2014.11.16 14:18:12 | 000,001,282 | ---- | C] () -- C:\Users\HONZA\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2014.11.16 14:18:12 | 000,001,258 | ---- | C] () -- C:\Users\HONZA\Desktop\Spybot - Search & Destroy.lnk
[2014.11.15 00:03:52 | 000,002,008 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.11.15 00:03:29 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.11.15 00:03:28 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.11.15 00:03:25 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.11.14 22:09:13 | 000,050,280 | ---- | C] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2014.11.01 14:50:43 | 477,818,178 | ---- | C] () -- C:\Users\HONZA\Desktop\blbosti.zip
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.xp070105.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.px050107.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.ex010705.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.ex010507.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.bx050107.dat
[2014.07.31 15:00:44 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.ax010705.dat
[2014.03.17 19:09:34 | 000,522,796 | ---- | C] () -- C:\Windows\SysWow64\scrypt130511Pitcairnglg2tc4032w256l4.bin
[2014.03.16 09:45:18 | 000,000,067 | ---- | C] () -- C:\Users\HONZA\rgmnr
[2014.01.28 22:00:51 | 000,026,900 | ---- | C] () -- C:\Users\HONZA\AppData\Local\dt.dat
[2013.12.06 22:38:38 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.12.06 22:38:38 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.12.06 16:44:26 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013.11.25 20:30:58 | 000,000,000 | -HS- | C] () -- C:\Users\HONZA\AppData\Local\LumaEmu
[2013.07.21 09:11:15 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2013.07.08 16:27:46 | 000,003,584 | ---- | C] () -- C:\Users\HONZA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.drv190904.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.drv120405.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.drv120205.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data211204.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data211004.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.data110704.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.data001.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.data000.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.dat000002.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Program Files (x86)\.dat000001.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.app190905.dat
[2012.11.19 21:31:32 | 000,000,008 | -HS- | C] () -- C:\Users\HONZA\AppData\Roaming\.addit001.dat
[2011.12.20 20:05:00 | 000,010,374 | ---- | C] () -- C:\Users\HONZA\OTMData.xml
[2011.06.14 15:43:04 | 000,000,093 | ---- | C] () -- C:\Users\HONZA\AppData\Local\fusioncache.dat
[2011.04.12 18:05:42 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013.01.30 17:05:39 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013.01.30 17:05:39 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012.04.05 14:53:38 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\.minecraft
[2014.11.15 00:04:06 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\AVAST Software
[2014.01.06 22:07:54 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Battle.net
[2014.09.18 12:52:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Bioshock
[2014.03.21 21:09:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\BSplayer
[2011.04.27 09:39:24 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Canon
[2014.07.14 22:39:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DAEMON Tools Lite
[2011.04.11 18:00:15 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\DeviceVm
[2014.10.31 14:05:02 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Dropbox
[2012.03.03 15:31:22 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Foxit Software
[2011.08.03 08:51:29 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GameRanger
[2011.08.03 08:44:11 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\GetRightToGo
[2014.03.14 19:24:52 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\library_dir
[2013.06.14 14:55:41 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\OpenCandy
[2013.02.21 17:48:46 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Origin
[2014.03.21 21:23:01 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Raptr
[2014.03.21 21:24:18 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Seznam.cz
[2014.03.21 21:49:34 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TeamViewer
[2014.11.14 21:43:37 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TS3Client
[2014.07.14 22:33:31 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\TuneUp Software
[2014.05.25 23:11:05 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Tunngle
[2014.03.26 21:08:32 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\Ubisoft
[2014.11.16 15:07:10 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\uTorrent
[2011.08.13 19:49:58 | 000,000,000 | ---D | M] -- C:\Users\HONZA\AppData\Roaming\wargaming.net

========== Purity Check ==========



========== Custom Scans ==========

< :OTL >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,616 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.05.02 20:20:59 | 000,000,948 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.05.02 20:21:01 | 000,000,952 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.09.03 11:43:06 | 000,000,910 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job
[2012.09.03 11:43:07 | 000,000,962 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job
[2012.09.04 15:29:09 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} >

< IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC >

< IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} >

< IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC >

< IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253 >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5193 >
Invalid Switch: ?babsrc=HP_s ... 3&tsp=5193

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: - No CLSID value found >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.) >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes,DefaultScope = {6905ACDE-7F92-4e73-BDCB-439196EB6C7B} >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{9001BA8A-679D-4922-88D4-94BE02ED450C}: "URL" = http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=UJ&apn_dtid=YYYYYYYYCZ&apn_uid=5f1cb5c7-08ae-4ae3-a5ba-dffd7cc16f00&apn_sauid=AC8580DA-0551-4872-B0B8-A4F705034330 >

< IE - HKU\S-1-5-21-43973838-2708954722-2285227966-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253 >

< [2011.11.23 18:00:38 | 000,002,401 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\askcom.xml >

< [2014.03.21 18:08:04 | 000,006,226 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\buenosearch.xml >

< [2013.03.30 14:25:23 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-1.xml >

< [2011.08.28 15:08:45 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-2.xml >

< [2011.09.01 20:17:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-3.xml >

< [2011.09.10 20:10:53 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-4.xml >

< [2011.09.28 20:10:15 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-5.xml >

< [2011.10.02 12:07:10 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-6.xml >

< [2011.11.08 18:12:40 | 000,000,950 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-7.xml >

< [2011.08.15 18:28:43 | 000,001,056 | ---- | M] () -- C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin.xml >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib\4.2_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhapeiiedfleakkilafdkgdnmnpkgkna\0.9.7.0_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dljbcjbfojhlfhgenhepllagfecdpchb\1.38.7.4074_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfgdmpfihlmdekaclngibpjhdebndhdj\1.16_0\ >

< CHR - Extension: No name found = C:\Users\HONZA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ >

< O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found. >

< O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found. >

< O4 - HKU\S-1-5-21-43973838-2708954722-2285227966-1000..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss File not found >
Invalid Switch: ss File not found

< O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found >

< O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found >

< O18:64bit: - Protocol\Handler\ms-help - No CLSID value found >

< O18:64bit: - Protocol\Handler\skype4com - No CLSID value found >

< O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found >

< O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. >

< O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. >

< O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell - "" = AutoRun >

< O33 - MountPoints2\{b7f22dd3-a0a4-11e1-b178-bcaec582aeb1}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2008.03.27 00:59:25 | 000,131,720 | R--- | M] (InstallShield Software Corporation) >

< >

< :files >

< C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job >
[2014.11.18 22:06:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000UA.job

< C:\Windows\tasks\GoogleUpdateTaskMachineCore.job >
[2014.11.18 21:00:37 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

< C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job >
[2014.11.17 23:06:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-43973838-2708954722-2285227966-1000Core.job

< C:\Windows\tasks\GoogleUpdateTaskMachineUA.job >
[2014.11.18 22:45:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

< %windir%\system32\*.tmp.dll /s >

< %windir%\system32\SET*.tmp /s >

< %windir%\*.tmp >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< >

< :commands >

< [EMPTYTEMP] >

< [EMPTYFLASH] >

< [Purity] >

< End of report >

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#10 Příspěvek od Rudy »

OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#11 Příspěvek od Blicek »

Bohužel ne... záložky se pořád otevírají... :/

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#12 Příspěvek od Rudy »

Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#13 Příspěvek od Blicek »

# AdwCleaner v4.101 - Report created 19/11/2014 at 19:42:01
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : HONZA - HONZA-PC
# Running from : C:\Users\HONZA\Downloads\adwcleaner_4.101.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : BCUService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\DeviceVM
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\DeviceVM
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SmartTweak
Folder Deleted : C:\Program Files (x86)\LuckyTab
Folder Deleted : C:\Users\HONZA\AppData\Local\cool_mirage
Folder Deleted : C:\Users\HONZA\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\HONZA\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\HONZA\AppData\Local\WhiteListing
Folder Deleted : C:\Users\HONZA\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\HONZA\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\HONZA\AppData\Roaming\DeviceVM
Folder Deleted : C:\Users\HONZA\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\HONZA\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\Askcom.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\buenosearch.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\HONZA\AppData\Roaming\Mozilla\Firefox\Profiles\7ica0a6j.default\searchplugins\icqplugin-7.xml

***** [ Scheduled Tasks ] *****

Task Deleted : LuckyTab

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SpeedUpMyComputer]
Key Deleted : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook
Key Deleted : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BCU]
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3072253
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{77AA6435-2488-4A94-9FE5-49519DD2ED9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9001BA8A-679D-4922-88D4-94BE02ED450C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DeviceVM
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DeviceVM
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\LuckyTab

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7601.17514

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v33.1.1 (x86 cs)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [8808 octets] - [19/11/2014 19:38:44]
AdwCleaner[S0].txt - [7823 octets] - [19/11/2014 19:42:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7883 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Automatické otevírání nových záložek s reklamami

#14 Příspěvek od Rudy »

Změnilo se nyní něco?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Blicek
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 16 lis 2014 17:04

Re: Automatické otevírání nových záložek s reklamami

#15 Příspěvek od Blicek »

Vypadá to, že už to přestalo... od posledního úkonu se neotevřela zatím žádná záložka :) Moc děkuju za pomoc!

Zamčeno