Odpowiedz

Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia

 
pypciu
Wdrażany
Liczba postów: 25
Post: #1
Lightbulb 

Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Witam!

Mam problem z windowsem od 2 tygodni co jakiś czas. Zawiesza się na parę sekund co chwila i odwiesza na parę sekund. Niestety przywracanie systemu pomaga tylko na jakiś czas, z resztą mam bardzo "młode" punkt przywracania, które już mogą obejmować usterkę. Wczoraj wieczorem już nie dało się pracować ka kompie. Dzisiaj z kolei jest ok, ale wiem, że za jakiś czas znowu zaczną się zawieszki. Proszę o pomoc, wklejam logo z HijackThis, mam nadzieje że dobrze:


Kod:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10: 43: 00, on 2012-07-31
Platform:  Windows 7 SP1 (WinNT 6.00.3505)
MSIE:  Unable to get Internet Explorer version!
Boot mode:  Normal

Running processes:
C: \Program Files (x86)\ASRock Utility\IES\AsrIes.exe
C: \Users\Pusz\Local Settings\Apps\F.lux\flux.exe
C: \Program Files (x86)\RadeonPro\RadeonPro.exe
C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe
C: \Program Files (x86)\KatMouse\KatMouse.exe
C: \Program Files (x86)\AVG\AVG2012\avgtray.exe
C: \Program Files (x86)\AVG Secure Search\vprot.exe
C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C: \Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C: \Program Files (x86)\Mozilla Firefox\firefox.exe
C: \Program Files (x86)\Mozilla Firefox\plugin-container.exe
C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C: \Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http: //go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG: system.ini:  UserInit=userinit.exe,
O2 - BHO:  HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C: \Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO:  WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C: \Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO:  Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\Microsoft Office\Office14\GROOVEEX.DLL
O2 - BHO:  Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO:  Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C: \Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO:  AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C: \Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O2 - BHO:  URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO:  Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO:  HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C: \Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar:  AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C: \Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run:  [VIAJDS] C: \Program Files (x86)\VIA\VIAudioi\HDADeck\VIAJDS.exe
O4 - HKLM\..\Run:  [AVG_TRAY] "C: \Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run:  [HDAudDeck] C: \Program Files (x86)\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run:  [vProt] "C: \Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run:  [Malwarebytes' Anti-Malware] "C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run:  [StartCCC] "C: \Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run:  [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C: \Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKCU\..\Run:  [F.lux] "C: \Users\Pusz\Local Settings\Apps\F.lux\flux.exe" /noshow
O4 - HKCU\..\Run:  [RadeonPro] "C: \Program Files (x86)\RadeonPro\RadeonPro.exe"
O4 - HKCU\..\Run:  [DriverMax] "C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -agent
O4 - HKCU\..\Run:  [DriverMax_RESTART] "C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -RESTART
O4 - HKCU\..\Run:  [HydraVisionDesktopManager] "C: \Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\RunOnce:  [Flags] 
O4 - HKUS\S-1-5-19\..\Run:  [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce:  [mctadmin] C: \Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run:  [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce:  [mctadmin] C: \Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce:  [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce:  [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f (User 'Default user')
O4 - Startup:  KatMouse.lnk = C: \Program Files (x86)\KatMouse\KatMouse.exe
O8 - Extra context menu item:  Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200
O8 - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //C: \PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item:  E&xport to Microsoft Excel - res: //C: \PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item:  Se&nd to OneNote - res: //C: \PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button:  @C: \Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C: \Windows\WindowsMobile\INetRepl.dll
O9 - Extra button:  (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem:  @C: \Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \Windows\WindowsMobile\INetRepl.dll
O9 - Extra button:  Pokaż lub ukryj HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C: \Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP:  c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP:  c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group:  [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{B421F2EC-F5E5-4625-ABBA-4DA02E3123D6}:  NameServer = 95.158.95.95,95.158.95.96
O18 - Protocol:  linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C: \Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol:  viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C: \Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
O18 - Filter hijack:  text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C: \Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service:  Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service:  @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C: \Windows\System32\alg.exe (file missing)
O23 - Service:  AMD External Events Utility - Unknown owner - C: \Windows\system32\atiesrxx.exe (file missing)
O23 - Service:  AMD FUEL Service - Advanced Micro Devices, Inc. - C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service:  AODService - Unknown owner - C: \Program Files (x86)\AMD\OverDrive\AODAssist.exe
O23 - Service:  Zapora AVG (avgfws) - AVG Technologies CZ, s.r.o. - C: \Program Files (x86)\AVG\AVG2012\avgfws.exe
O23 - Service:  AVGIDSAgent - AVG Technologies CZ, s.r.o. - C: \Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service:  AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C: \Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service:  @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C: \Windows\System32\lsass.exe (file missing)
O23 - Service:  FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C: \Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service:  Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C: \Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service:  Google Updater Service (gusvc) - Google - C: \Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service:  @keyiso.dll,-100 (KeyIso) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  KMService - Unknown owner - C: \Windows\system32\srvany.exe
O23 - Service:  MBAMService - Malwarebytes Corporation - C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service:  Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C: \Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service:  @comres.dll,-2797 (MSDTC) - Unknown owner - C: \Windows\System32\msdtc.exe (file missing)
O23 - Service:  @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C: \Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
O23 - Service:  PnkBstrA - Unknown owner - C: \Windows\system32\PnkBstrA.exe
O23 - Service:  @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  RadeonPro Support Service - Mr. John aka japamd - C: \Program Files (x86)\RadeonPro\RadeonProSupport.exe
O23 - Service:  @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C: \Windows\system32\locator.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C: \Windows\System32\snmptrap.exe (file missing)
O23 - Service:  Soluto PCGenome Core Service (SolutoService) - Soluto - C: \Program Files\Soluto\SolutoService.exe
O23 - Service:  @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C: \Windows\System32\spoolsv.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C: \Windows\system32\sppsvc.exe (file missing)
O23 - Service:  TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C: \Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
O23 - Service:  @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C: \Windows\system32\UI0Detect.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C: \Windows\System32\vds.exe (file missing)
O23 - Service:  VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C: \Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service:  @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C: \Windows\system32\vssvc.exe (file missing)
O23 - Service:  vToolbarUpdater11.1.0 - Unknown owner - C: \Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
O23 - Service:  @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C: \Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service:  @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C: \Windows\system32\wbengine.exe (file missing)
O23 - Service:  @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C: \Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 11900 bytes

Konfiguracja:
Win7 Ultimate 64
AMD Athlon II x4 630
HDD SAMSUNG DH103SI 1TB
Radeon HD 4850 1GB
8GB DDR III Kingstone'a (1600MHz)

Dzięki za jakąkolwiek pomoc!
Notatka została dodana 31.07.2012 10:36. Ostatnia edycja dokonana 31.07.2012 10:36 przez peciaq:

Logi łapiemy w znaczniki [CODE].
Wątek przenoszę do poddziału Logi w dziale Bezpieczeństwo Windows 7.

31.07.2012 09:51

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #2

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Logi wykonane dobrze,mimo wszystko poprosiłbym jeszcze o logo z programu "OTL",a to dlatego że jest to program bardziej precyzyjny i szczegółowy niż "HijackThis".W programie "HijackThis" zaznacz następujące logi:

Kod:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //home.sweetim.com
O4 - HKCU\..\RunOnce:  [Flags] 
O23 - Service:  @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C: \Windows\System32\alg.exe (file missing)
O23 - Service:  AMD External Events Utility - Unknown owner - C: \Windows\system32\atiesrxx.exe (file missing)
O23 - Service:  @keyiso.dll,-100 (KeyIso) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C: \Windows\system32\locator.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C: \Windows\System32\snmptrap.exe (file missing)
O23 - Service:  @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C: \Windows\System32\spoolsv.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C: \Windows\system32\sppsvc.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C: \Windows\system32\UI0Detect.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C: \Windows\System32\vds.exe (file missing)
O23 - Service:  VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C: \Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service:  @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C: \Windows\system32\vssvc.exe (file missing)
O23 - Service:  vToolbarUpdater11.1.0 - Unknown owner - C: \Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
O23 - Service:  @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C: \Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service:  @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C: \Windows\system32\wbengine.exe (file missing)
O23 - Service:  @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C: \Windows\system32\wbem\WmiApSrv.exe (file missing)

Po czym naciśnij "Fix Checked".Potem przeskanuj system programem "Malwaresbytes Anti -Malware" i jeśli zostanie coś znalezione to usuń infekcję.Po tej akcji podaj logi z "OTL".


(Ten post był ostatnio modyfikowany: 01.08.2012 01:35 przez Illidan.)

01.08.2012 01:32

Róża Podziękowania od: pypciu
Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
pypciu
Wdrażany
Liczba postów: 25
Post: #3

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Dzięki za odpowiedz, zrobiłem tak jak mówiłeś i zapodaję logi z programu OTL:

Kod:
OTL logfile created on:  2012-08-02 00: 30: 44 - Run 1
OTL by OldTimer - Version 3.2.55.0     Folder = C: \Users\Pusz\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale:  00000415 | Country:  Polska | Language:  PLK | Date Format:  yyyy-MM-dd

8,00 Gb Total Physical Memory | 5,73 Gb Available Physical Memory | 71,65% Memory free
31,99 Gb Paging File | 28,71 Gb Available in Paging File | 89,75% Paging File free
Paging file location(s):  [Binary data over 100 bytes]

%SystemDrive% = C:  | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C:  | 247,92 Gb Total Space | 196,52 Gb Free Space | 79,27% Space Free | Partition Type:  NTFS
Drive D:  | 341,70 Gb Total Space | 18,46 Gb Free Space | 5,40% Space Free | Partition Type:  NTFS
Drive E:  | 341,80 Gb Total Space | 23,71 Gb Free Space | 6,94% Space Free | Partition Type:  NTFS
Drive G:  | 1,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type:  CDFS
Drive I:  | 596,02 Gb Total Space | 514,35 Gb Free Space | 86,30% Space Free | Partition Type:  FAT32

Computer Name:  PUSZ-PC | User Name:  Pusz | Logged in as Administrator.
Boot Mode:  Normal | Scan Mode:  Current user | Include 64bit Scans
Company Name Whitelist:  Off | Skip Microsoft Files:  Off | No Company Name Whitelist:  On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012-08-02 00: 09: 57 | 000,597,504 | ---- | M] (OldTimer Tools) -- C: \Users\Pusz\Desktop\OTL.exe
PRC - [2012-08-01 11: 48: 33 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C: \Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012-07-31 11: 49: 37 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
PRC - [2012-06-27 11: 58: 22 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012-06-27 11: 58: 22 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012-06-19 18: 46: 36 | 011,324,352 | ---- | M] (Innovative Solutions) -- C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe
PRC - [2012-06-12 17: 31: 08 | 001,104,440 | ---- | M] () -- C: \Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2012-06-12 17: 31: 08 | 000,935,480 | ---- | M] () -- C: \Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
PRC - [2012-04-17 17: 19: 40 | 003,671,872 | ---- | M] (DT Soft Ltd) -- C: \Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2012-01-29 17: 22: 26 | 000,075,136 | ---- | M] () -- C: \Windows\SysWOW64\PnkBstrA.exe
PRC - [2012-01-24 18: 24: 26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C: \Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2011-11-23 03: 36: 24 | 002,391,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C: \Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011-10-12 07: 25: 22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C: \Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011-08-02 07: 09: 08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C: \Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011-07-13 08: 33: 08 | 004,615,064 | ---- | M] (Almico Software (www.almico.com)) -- C: \Program Files (x86)\SpeedFan\speedfan.exe
PRC - [2011-02-10 02: 00: 16 | 000,012,800 | ---- | M] (Mr. John aka japamd) -- C: \Program Files (x86)\RadeonPro\RadeonProSupport.exe
PRC - [2011-02-10 02: 00: 14 | 001,832,448 | ---- | M] (Mr. John aka japamd) -- C: \Program Files (x86)\RadeonPro\RadeonPro.exe
PRC - [2010-11-20 14: 17: 41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C: \Program Files (x86)\Windows Sidebar\sidebar.exe
PRC - [2010-06-04 12: 13: 00 | 007,989,768 | ---- | M] (ASRock Incorporation) -- C: \Program Files (x86)\ASRock Utility\IES\AsrIes.exe
PRC - [2007-05-30 14: 14: 22 | 000,050,688 | ---- | M] () -- C: \Program Files (x86)\KatMouse\KatMouse.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012-08-01 22: 34: 43 | 000,192,512 | ---- | M] () -- C: \Users\Pusz\AppData\Local\Temp\sfamcc00001.dll
MOD - [2012-08-01 22: 34: 43 | 000,172,032 | ---- | M] () -- C: \Users\Pusz\AppData\Local\Temp\sfareca00001.dll
MOD - [2012-08-01 11: 48: 33 | 002,249,696 | ---- | M] () -- C: \Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012-07-31 11: 49: 37 | 009,465,032 | ---- | M] () -- C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
MOD - [2012-06-14 18: 13: 14 | 000,008,648 | ---- | M] () -- C: \Program Files (x86)\Innovative Solutions\DriverMax\sync.dll
MOD - [2012-06-13 17: 43: 19 | 000,212,992 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\S​ystem.ServiceProcess.ni.dll
MOD - [2012-06-13 17: 43: 13 | 011,833,344 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.​ni.dll
MOD - [2012-06-13 17: 42: 52 | 012,436,480 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\S​ystem.Windows.Forms.ni.dll
MOD - [2012-06-13 17: 42: 46 | 001,591,808 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.​Drawing.ni.dll
MOD - [2012-06-12 17: 31: 09 | 000,132,664 | ---- | M] () -- C: \Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll
MOD - [2012-06-12 17: 31: 08 | 001,104,440 | ---- | M] () -- C: \Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2012-05-10 01: 13: 51 | 001,051,136 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\Syst​em.Management.ni.dll
MOD - [2012-05-10 01: 11: 10 | 000,771,584 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\S​ystem.Runtime.Remoting.ni.dll
MOD - [2012-05-10 01: 10: 40 | 000,025,600 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessib​ility.ni.dll
MOD - [2012-05-10 01: 10: 31 | 003,347,968 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBas​e.ni.dll
MOD - [2012-05-10 01: 10: 27 | 005,452,800 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.​ni.dll
MOD - [2012-05-10 01: 10: 23 | 007,967,232 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dl​l
MOD - [2012-05-10 01: 10: 19 | 011,492,864 | ---- | M] () -- C: \Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.d​ll
MOD - [2011-03-17 01: 11: 16 | 004,297,568 | ---- | M] () -- C: \PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2010-11-13 04: 03: 59 | 000,425,984 | ---- | M] () -- C: \Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_pl_b77a5c561934e089\System.Windows​.Forms.resources.dll
MOD - [2010-11-13 04: 03: 49 | 000,311,296 | ---- | M] () -- C: \Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010-11-06 13: 31: 36 | 001,132,032 | ---- | M] () -- C: \Program Files (x86)\RadeonPro\V8.Net.dll
MOD - [2010-10-20 16: 45: 26 | 008,801,120 | ---- | M] () -- C: \PROGRA~2\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009-06-10 15: 10: 44 | 000,032,768 | ---- | M] () -- C: \Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_pl_b77a5c561934e089\System.Runt​ime.Remoting.resources.dll
MOD - [2008-12-30 18: 23: 28 | 000,214,528 | ---- | M] () -- C: \Program Files (x86)\KatMouse\KatMouseH.dll
MOD - [2007-06-22 16: 48: 58 | 000,044,032 | ---- | M] () -- C: \Program Files (x86)\KatMouse\KatMouseS.dll
MOD - [2007-05-30 14: 14: 22 | 000,050,688 | ---- | M] () -- C: \Program Files (x86)\KatMouse\KatMouse.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV: [b]64bit: [/b] - [2012-05-25 01: 07: 32 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C: \Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV: [b]64bit: [/b] - [2012-04-24 17: 32: 38 | 000,584,224 | ---- | M] (Soluto) [Auto | Stopped] -- C: \Program Files\Soluto\SolutoService.exe -- (SolutoService)
SRV: [b]64bit: [/b] - [2012-04-05 13: 08: 24 | 000,035,648 | ---- | M] (TuneUp Software) [Auto | Running] -- C: \Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV: [b]64bit: [/b] - [2012-03-12 17: 07: 56 | 000,204,792 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C: \Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe -- (NitroReaderDriverReadSpool2)
SRV: [b]64bit: [/b] - [2012-02-17 20: 56: 20 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C: \Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV: [b]64bit: [/b] - [2011-12-05 23: 15: 08 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV: [b]64bit: [/b] - [2011-06-29 17: 25: 12 | 003,246,920 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C: \Program Files\OO Software\Defrag\oodag.exe -- (OODefragAgent)
SRV: [b]64bit: [/b] - [2009-07-14 03: 41: 27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV: [b]64bit: [/b] - [2009-07-14 03: 40: 01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012-08-01 11: 48: 33 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C: \Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-07-31 11: 49: 37 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-06-27 11: 58: 22 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012-06-12 17: 31: 08 | 000,935,480 | ---- | M] () [Auto | Running] -- C: \Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe -- (vToolbarUpdater11.1.0)
SRV - [2012-04-05 13: 08: 34 | 002,143,552 | ---- | M] (TuneUp Software) [Auto | Running] -- C: \Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012-04-05 13: 08: 24 | 000,028,992 | ---- | M] (TuneUp Software) [Auto | Running] -- C: \Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2012-01-29 17: 22: 26 | 000,075,136 | ---- | M] () [Auto | Running] -- C: \Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011-11-23 03: 36: 24 | 002,391,832 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C: \Program Files (x86)\AVG\AVG2012\avgfws.exe -- (avgfws)
SRV - [2011-10-12 07: 25: 22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C: \Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011-08-02 07: 09: 08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C: \Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-03-01 23: 17: 54 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C: \Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2011-02-10 02: 00: 16 | 000,012,800 | ---- | M] (Mr. John aka japamd) [Auto | Running] -- C: \Program Files (x86)\RadeonPro\RadeonProSupport.exe -- (RadeonPro Support Service)
SRV - [2010-03-18 14: 16: 28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-09-20 12: 55: 20 | 001,037,824 | ---- | M] (Hewlett-Packard Co.) [On_Demand | Running] -- C: \Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2009-06-10 23: 23: 09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C: \Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009-05-05 05: 45: 50 | 000,124,256 | ---- | M] () [Auto | Stopped] -- C: \Program Files (x86)\AMD\OverDrive\AODAssist.exe -- (AODService)
SRV - [2007-05-31 17: 11: 54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C: \Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 17: 11: 46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C: \Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV: [b]64bit: [/b] - [2012-08-01 23: 32: 16 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV: [b]64bit: [/b] - [2012-06-27 11: 58: 24 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C: \Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV: [b]64bit: [/b] - [2012-05-25 22: 23: 14 | 000,438,376 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\Rtenic64.sys -- (RTLE8023x64)
DRV: [b]64bit: [/b] - [2012-05-25 01: 27: 42 | 011,175,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV: [b]64bit: [/b] - [2012-05-25 01: 27: 42 | 011,175,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV: [b]64bit: [/b] - [2012-05-24 23: 54: 34 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV: [b]64bit: [/b] - [2012-05-16 08: 22: 10 | 000,678,544 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV: [b]64bit: [/b] - [2012-04-24 17: 13: 24 | 000,054,728 | ---- | M] (Soluto LTD.) [File_System | Boot | Stopped] -- C: \Windows\SysNative\drivers\Soluto.sys -- (Soluto)
DRV: [b]64bit: [/b] - [2012-04-10 07: 40: 58 | 000,082,560 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV: [b]64bit: [/b] - [2012-04-10 07: 40: 58 | 000,042,624 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV: [b]64bit: [/b] - [2012-03-16 16: 02: 54 | 000,685,672 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV: [b]64bit: [/b] - [2012-03-01 08: 46: 16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C: \Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV: [b]64bit: [/b] - [2012-01-19 22: 33: 40 | 000,530,488 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV: [b]64bit: [/b] - [2011-12-29 13: 37: 44 | 000,035,120 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter)
DRV: [b]64bit: [/b] - [2011-12-17 16: 43: 28 | 000,011,904 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdide64.sys -- (amdide64)
DRV: [b]64bit: [/b] - [2011-12-08 06: 22: 38 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ssudserd.sys -- (ssudserd)
DRV: [b]64bit: [/b] - [2011-12-08 06: 22: 38 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV: [b]64bit: [/b] - [2011-12-08 06: 22: 38 | 000,098,616 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV: [b]64bit: [/b] - [2011-10-27 03: 25: 56 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\sscemdm.sys -- (sscemdm)
DRV: [b]64bit: [/b] - [2011-10-27 03: 25: 56 | 000,129,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ssceserd.sys -- (ssceserd)
DRV: [b]64bit: [/b] - [2011-10-27 03: 25: 56 | 000,127,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\sscebus.sys -- (sscebus)
DRV: [b]64bit: [/b] - [2011-10-27 03: 25: 56 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\sscemdfl.sys -- (sscemdfl)
DRV: [b]64bit: [/b] - [2011-10-20 11: 24: 06 | 000,157,696 | ---- | M] (Matrox Graphics Inc.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\MxEFUF64.sys -- (MxEFUF)
DRV: [b]64bit: [/b] - [2011-10-17 19: 40: 50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV: [b]64bit: [/b] - [2011-10-07 07: 23: 46 | 000,283,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV: [b]64bit: [/b] - [2011-09-13 07: 30: 08 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C: \Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV: [b]64bit: [/b] - [2011-08-08 07: 08: 58 | 000,046,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C: \Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV: [b]64bit: [/b] - [2011-07-11 02: 14: 36 | 000,375,376 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV: [b]64bit: [/b] - [2011-07-11 02: 14: 08 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV: [b]64bit: [/b] - [2011-07-11 02: 14: 06 | 000,120,400 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV: [b]64bit: [/b] - [2011-07-11 02: 14: 06 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV: [b]64bit: [/b] - [2011-06-24 07: 31: 02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV: [b]64bit: [/b] - [2011-05-23 02: 03: 28 | 000,048,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV: [b]64bit: [/b] - [2011-01-15 18: 21: 04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV: [b]64bit: [/b] - [2010-11-20 15: 33: 35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV: [b]64bit: [/b] - [2010-11-20 13: 07: 05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV: [b]64bit: [/b] - [2010-11-20 13: 03: 42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV: [b]64bit: [/b] - [2010-11-06 23: 24: 34 | 000,024,176 | ---- | M] () [Kernel | On_Demand | Stopped] -- C: \Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV: [b]64bit: [/b] - [2010-10-25 11: 10: 22 | 000,020,552 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\dgderdrv.sys -- (dgderdrv)
DRV: [b]64bit: [/b] - [2010-07-01 19: 11: 24 | 000,012,352 | ---- | M] () [Kernel | "Start" not found. | Unknown] -- C: \Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV: [b]64bit: [/b] - [2010-05-06 05: 21: 46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV: [b]64bit: [/b] - [2010-02-18 09: 18: 24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV: [b]64bit: [/b] - [2009-10-07 11: 13: 34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV: [b]64bit: [/b] - [2009-10-07 11: 13: 34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV: [b]64bit: [/b] - [2009-09-01 16: 29: 56 | 000,157,712 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\kl1.sys -- (kl1)
DRV: [b]64bit: [/b] - [2009-07-14 03: 52: 20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV: [b]64bit: [/b] - [2009-07-14 03: 48: 04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV: [b]64bit: [/b] - [2009-07-14 03: 45: 55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV: [b]64bit: [/b] - [2009-07-14 02: 09: 02 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C: \Windows\SysNative\drivers\irda.sys -- (irda)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV: [b]64bit: [/b] - [2009-06-10 22: 31: 59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV: [b]64bit: [/b] - [2009-04-08 19: 44: 58 | 000,232,464 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV: [b]64bit: [/b] - [2008-12-19 05: 43: 30 | 001,120,768 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV: [b]64bit: [/b] - [2008-02-14 08: 12: 00 | 001,854,976 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\monfilt.sys -- (monfilt)
DRV: [b]64bit: [/b] - [2008-01-19 06: 36: 12 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\irsir.sys -- (irsir)
DRV: [b]64bit: [/b] - [2007-06-19 07: 50: 54 | 000,143,400 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s816mdm.sys -- (s816mdm)
DRV: [b]64bit: [/b] - [2007-06-19 07: 50: 54 | 000,124,968 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s816mgmt.sys -- (s816mgmt)
DRV: [b]64bit: [/b] - [2007-06-19 07: 50: 54 | 000,121,896 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s816obex.sys -- (s816obex)
DRV: [b]64bit: [/b] - [2007-06-19 07: 50: 48 | 000,018,472 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s816mdfl.sys -- (s816mdfl)
DRV: [b]64bit: [/b] - [2007-06-19 07: 50: 46 | 000,107,048 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s816bus.sys -- (s816bus)
DRV: [b]64bit: [/b] - [2007-04-03 14: 57: 40 | 000,130,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116unic.sys -- (s116unic)
DRV: [b]64bit: [/b] - [2007-04-03 14: 57: 38 | 000,031,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116nd5.sys -- (s116nd5)
DRV: [b]64bit: [/b] - [2007-04-03 13: 57: 40 | 000,123,656 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116obex.sys -- (s116obex)
DRV: [b]64bit: [/b] - [2007-04-03 13: 57: 38 | 000,126,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116mgmt.sys -- (s116mgmt)
DRV: [b]64bit: [/b] - [2007-04-03 13: 57: 36 | 000,144,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116mdm.sys -- (s116mdm)
DRV: [b]64bit: [/b] - [2007-04-03 13: 57: 36 | 000,019,720 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116mdfl.sys -- (s116mdfl)
DRV: [b]64bit: [/b] - [2007-04-03 13: 57: 34 | 000,108,296 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\s116bus.sys -- (s116bus)
DRV - [2011-11-08 22: 25: 24 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C: \Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2011-02-05 16: 00: 18 | 000,021,712 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
DRV - [2010-10-25 11: 03: 52 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009-07-14 03: 19: 10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http: //www.msn.com/
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}:  "URL" = http: //isearch.avg.com/search?cid={5445E9E2-9937-4FDB-844D-E42375B08F1E}&mid=e52a6837447347d1a107d16c64e053cb-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&ds=gm011&pr=sa&d=2012-03-26 21: 24: 58&v=10.2.0.3&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}:  "URL" = http: //www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}:  "URL" = http: //search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:  "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename:  "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine:  "Google"
FF - prefs.js..browser.startup.homepage:  "about: home"
FF - prefs.js..extensions.enabledItems:  {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}: 1.3.2
FF - prefs.js..extensions.enabledItems:  linkfilter@kaspersky.ru: 9.0.0.736
FF - prefs.js..extensions.enabledItems:  smartwebprinting@hp.com: 4.51
FF - prefs.js..extensions.enabledItems:  {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}: 6.0.20
FF - prefs.js..extensions.enabledItems:  {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}: 6.0.22
FF - prefs.js..extensions.enabledItems:  {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}: 6.0.23
FF - prefs.js..extensions.enabledItems:  2020Player@2020Technologies.com: 4.5.4.0
FF - prefs.js..extensions.enabledItems:  {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}: 6.0.24
FF - prefs.js..extensions.enabledItems:  {BBDA0591-3099-440a-AA10-41764D9DB4DB}: 2.0
FF - prefs.js..extensions.enabledItems:  {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: 5.5
FF - prefs.js..keyword.URL:  "http: //www.google.pl/search?hl=pl&q="


FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  C: \Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0:  C: \Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0:  C: \Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  disabled File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0:  c: \Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  C: \PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin:  C: \Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0:  C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive:  C: \ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1:  C: \Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1:  C: \Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  disabled File not found
FF - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0:  c: \Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  C: \PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:  C: \PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF:  C: \Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\@vividas.com/npVividasPlayer:  C: \Program Files (x86)\Vividas\Player\npVividasPlayer.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3:  C: \Users\Pusz\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9:  C: \Users\Pusz\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com:  C: \Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-03-23 17: 24: 32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}:  C: \Program Files (x86)\AVG\AVG2012\Firefox4\ [2012-02-09 16: 38: 11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar:  C: \ProgramData\AVG Secure Search\11.1.0.7\ [2012-06-12 17: 31: 12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com:  C: \Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012-05-03 10: 13: 04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components:  C: \Program Files (x86)\Mozilla Firefox\components [2012-08-01 19: 34: 39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins:  C: \Program Files (x86)\Mozilla Firefox\plugins [2012-08-01 19: 34: 39 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com:  C: \Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-03-23 17: 24: 32 | 000,000,000 | ---D | M]

[2012-03-21 13: 12: 04 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Pusz\AppData\Roaming\mozilla\Extensions
[2012-03-21 13: 12: 04 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Pusz\AppData\Roaming\mozilla\Extensions\prism@developer.mozilla.org
[2012-07-31 11: 08: 03 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Pusz\AppData\Roaming\mozilla\Firefox\Profiles\awbtheky.default\extensions
[2011-01-26 15: 22: 08 | 000,000,000 | ---D | M] (20-20 3D Viewer) -- C: \Users\Pusz\AppData\Roaming\mozilla\Firefox\Profiles\awbtheky.default\extensions\2020Player@2020Tech​nologies.com
[2012-05-17 18: 28: 43 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C: \Users\Pusz\AppData\Roaming\mozilla\Firefox\Profiles\awbtheky.default\extensions\ich@maltegoetz.d​e
[2011-12-21 12: 31: 33 | 000,000,000 | ---D | M] (Open in Private Browsing Mode) -- C: \Users\Pusz\AppData\Roaming\mozilla\Firefox\Profiles\awbtheky.default\extensions\jid1-0FHdJAAQ7Nb73Q@jetpack
[2012-07-31 11: 09: 33 | 000,000,000 | ---D | M] (rein) -- C: \Users\Pusz\AppData\Roaming\mozilla\Firefox\Profiles\awbtheky.default\extensions\rein@notiz.jp
[2010-08-20 01: 17: 07 | 000,002,059 | ---- | M] () -- C: \Users\Pusz\AppData\Roaming\Mozilla\Firefox\Profiles\awbtheky.default\searchplugins\daemon-search.xml
[2012-03-12 21: 53: 17 | 000,000,000 | ---D | M] (No name found) -- C: \Program Files (x86)\mozilla firefox\extensions
[2010-03-11 19: 06: 38 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C: \Program Files (x86)\mozilla firefox\extensions\linkfilter@kaspersky.ru
[2012-08-01 11: 48: 34 | 000,000,000 | ---D | M] (No name found) -- C: \Program Files (x86)\mozilla firefox\distribution\extensions
[2012-05-31 06: 44: 40 | 000,505,801 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE30}.XPI
[2011-04-06 18: 37: 12 | 000,079,135 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
[2012-07-25 08: 28: 44 | 000,276,167 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\{64161300-E22B-11DB-8314-0800200C9A66}.XPI
[2012-07-10 23: 00: 14 | 000,177,357 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\{C36177C0-224A-11DA-8CD6-0800200C9A91}.XPI
[2012-04-03 21: 22: 40 | 000,140,964 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\FIREGESTURES@XULDEV​.ORG.XPI
[2012-04-13 20: 17: 32 | 000,049,306 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\MP4DOWNLOADER@JEFF.​NET.XPI
[2012-03-23 19: 46: 36 | 001,184,804 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZI​LLA.COM.XPI
[2012-07-25 08: 28: 44 | 000,234,654 | ---- | M] () (No name found) -- C: \USERS\PUSZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AWBTHEKY.DEFAULT\EXTENSIONS\THUMBNAILZOOM@DADLE​R.GITHUB.COM.XPI
[2012-08-01 11: 48: 34 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C: \Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010-11-30 16: 11: 52 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C: \Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011-11-10 22: 35: 18 | 000,002,105 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
[2012-08-01 11: 48: 31 | 000,002,767 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2012-07-10 23: 28: 12 | 000,003,769 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-08-01 11: 48: 31 | 000,001,406 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2012-08-01 11: 48: 31 | 000,000,917 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2012-08-01 11: 48: 31 | 000,000,858 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2012-08-01 11: 48: 31 | 000,001,183 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2012-08-01 11: 48: 31 | 000,001,683 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome  ==========[/color]

CHR - homepage:  http: //home.sweetim.com/
CHR - default_search_provider:  Google (Enabled)
CHR - default_search_provider:  search_url = {google: baseURL}search?{google: RLZ}{google: acceptedSuggestion}{google: originalQueryForSuggestion}{google: searchFieldtrialParameter}{google: instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider:  suggest_url = {google: baseSuggestURL}search?{google: searchFieldtrialParameter}{google: instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:  http: //home.sweetim.com/
CHR - plugin:  Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin:  Native Client (Enabled) = C: \Users\Pusz\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin:  Chrome PDF Viewer (Enabled) = C: \Users\Pusz\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin:  Shockwave Flash (Enabled) = C: \Users\Pusz\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin:  Shockwave Flash (Enabled) = C: \Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin:  Java Deployment Toolkit 6.0.290.11 (Enabled) = C: \Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin:  Java(TM) Platform SE 6 U29 (Enabled) = C: \Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin:  Winamp Application Detector (Enabled) = C: \Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin:  DivX Web Player (Enabled) = C: \Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin:  Picasa (Enabled) = C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin:  Vividas Player Plugin (Enabled) = C: \Program Files (x86)\Vividas\Player\npVividasPlayer.dll
CHR - plugin:  QUAKE LIVE (Enabled) = C: \ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin:  Google Update (Enabled) = C: \Users\Pusz\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin:  Silverlight Plug-In (Enabled) = c: \Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin:  Default Plug-in (Enabled) = default_plugin
CHR - Extension:  YouTube = C: \Users\Pusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension:  Szukaj w Google = C: \Users\Pusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension:  Freemake Video Converter = C: \Users\Pusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
CHR - Extension:  AVG Safe Search = C: \Users\Pusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension:  Gmail = C: \Users\Pusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File:  ([2011-12-24 17: 34: 57 | 000,001,240 | ---- | M]) - C: \Windows\SysNative\drivers\etc\hosts
O1 - Hosts:  127.0.0.1 localhost
O2: [b]64bit: [/b] - BHO:  (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C: \Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2: [b]64bit: [/b] - BHO:  (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2: [b]64bit: [/b] - BHO:  (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO:  (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C: \Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO:  (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO:  (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO:  (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C: \Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO:  (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO:  (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3: [b]64bit: [/b] - HKLM\..\Toolbar:  (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar:  (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C: \Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser:  (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run:  [APSDaemon] C: \Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run:  [AVG_TRAY] C: \Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run:  [Malwarebytes' Anti-Malware] C: \Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run:  [StartCCC] C: \Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run:  [VIAJDS] C: \Program Files (x86)\VIA\VIAudioi\HDADeck\VIAJDS.exe (TODO:  <Company name>)
O4 - HKLM..\Run:  [vProt] C: \Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run:  [DAEMON Tools Lite] C: \Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run:  [DriverMax] C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKCU..\Run:  [DriverMax_RESTART] C: \Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O4 - HKCU..\Run:  [F.lux] C: \Users\Pusz\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKCU..\Run:  [RadeonPro] C: \Program Files (x86)\RadeonPro\RadeonPro.exe (Mr. John aka japamd)
O4 - Startup:  C: \Users\Pusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KatMouse.lnk = C: \Program Files (x86)\KatMouse\KatMouse.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoDriveTypeAutoRun = 145
O8: [b]64bit: [/b] - Extra context menu item:  Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200 File not found
O8: [b]64bit: [/b] - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //C: \PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8: [b]64bit: [/b] - Extra context menu item:  E&xport to Microsoft Excel - res: //C: \PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000 File not found
O8: [b]64bit: [/b] - Extra context menu item:  Se&nd to OneNote - res: //C: \PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item:  Add to Google Photos Screensa&ver - C: \Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //C: \PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item:  E&xport to Microsoft Excel - res: //C: \PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item:  Se&nd to OneNote - res: //C: \PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button:  @C: \Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C: \Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem :  @C: \Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C: \Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O13[b]64bit: [/b] - gopher Prefix:  missing
O13 - gopher Prefix:  missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B421F2EC-F5E5-4625-ABBA-4DA02E3123D6}:  NameServer = 95.158.95.95,95.158.95.96
O18: [b]64bit: [/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C: \Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18: [b]64bit: [/b] - Protocol\Handler\ms-help - No CLSID value found
O18: [b]64bit: [/b] - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C: \Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C: \Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20: [b]64bit: [/b] - HKLM Winlogon:  Shell - (explorer.exe) - C: \Windows\explorer.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon:  UserInit - (C: \Windows\system32\userinit.exe) - C: \Windows\SysNative\userinit.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon:  UserInit - (C: \Program Files\Soluto\soluto.exe /userinit) - C: \Program Files\Soluto\soluto.exe (Soluto)
O20: [b]64bit: [/b] - HKLM Winlogon:  VMApplet - (SystemPropertiesPerformance.exe) - C: \Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon:  VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon:  Shell - (explorer.exe) - C: \Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon:  UserInit - (userinit.exe) - C: \Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon:  VMApplet - (/pagefile) -  File not found
O21: [b]64bit: [/b] - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22: [b]64bit: [/b] - SharedTaskScheduler:  {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C: \Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O27: [b]64bit: [/b] - HKLM IFEO\excel.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\groove.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\infopath.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\misc.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\msaccess.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\msoxmled.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\mspub.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\mstore.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\ois.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\onenote.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\outlook.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\powerpnt.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\setup.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27: [b]64bit: [/b] - HKLM IFEO\Winword.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\excel.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\groove.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\infopath.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\misc.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msaccess.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mspub.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\ois.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\onenote.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\outlook.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\powerpnt.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\setup.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\Winword.exe:  Debugger - C: \Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks:  {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C: \PROGRA~2\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom:  AutoRun - 1
O32 - AutoRun File - [2012-07-27 23: 50: 03 | 000,000,115 | R--- | M] () - G: \autorun.inf -- [ CDFS ]
O33 - MountPoints2\{2b028388-fdef-11df-b80c-00252204ba38}\Shell - "" = AutoRun
O33 - MountPoints2\{2b028388-fdef-11df-b80c-00252204ba38}\Shell\AutoRun\command - "" = H: \LaunchU3.exe -a
O33 - MountPoints2\{4ebc14fe-e131-11df-885e-00252204ba38}\Shell - "" = AutoRun
O33 - MountPoints2\{4ebc14fe-e131-11df-885e-00252204ba38}\Shell\AutoRun\command - "" = G: \autorun.exe
O33 - MountPoints2\{cc429a75-103a-11df-8b80-00252204ba38}\Shell - "" = AutoRun
O33 - MountPoints2\{cc429a75-103a-11df-8b80-00252204ba38}\Shell\AutoRun\command - "" = G: \Autoplay.exe
O33 - MountPoints2\{f63422a1-4fd7-11e1-9197-00252204ba38}\Shell - "" = AutoRun
O33 - MountPoints2\{f63422a1-4fd7-11e1-9197-00252204ba38}\Shell\AutoRun\command - "" = J: \LaunchU3.exe -a
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H: \autorun.exe
O34 - HKLM BootExecute:  (autocheck autochk *)
O34 - HKLM BootExecute:  (OODBS)
O34 - HKLM BootExecute:  (C: \PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35: [b]64bit: [/b] - HKLM\..comfile [open] -- "%1" %*
O35: [b]64bit: [/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows:  (ServerDll=winsrv: UserServerDllInitialization,3)
O38 - SubSystems\\Windows:  (ServerDll=winsrv: ConServerDllInitialization,2)
O38 - SubSystems\\Windows:  (ServerDll=sxssrv,4)

Malwerbytes nie znalazł nic, tak samo jak AVG. Czekam na pomoc i dzięki!
(Log podzieliłem na dwa posty)


Kod:
[2012-08-02 00: 09: 57 | 000,597,504 | ---- | C] (OldTimer Tools) -- C: \Users\Pusz\Desktop\OTL.exe
[2012-08-01 23: 46: 21 | 000,000,000 | ---D | C] -- C: \Users\Pusz\Documents\Activision
[2012-08-01 23: 32: 37 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012-08-01 23: 32: 16 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C: \Windows\SysNative\drivers\dtsoftbus01.sys
[2012-08-01 23: 32: 07 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\DAEMON Tools Lite
[2012-08-01 19: 34: 33 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-08-01 19: 34: 27 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\QuickTime
[2012-08-01 19: 34: 27 | 000,000,000 | ---D | C] -- C: \ProgramData\Apple Computer
[2012-08-01 19: 33: 49 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Common Files\Apple
[2012-08-01 19: 33: 43 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Local\Apple
[2012-08-01 19: 33: 42 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Apple Software Update
[2012-08-01 19: 33: 42 | 000,000,000 | ---D | C] -- C: \ProgramData\Apple
[2012-08-01 19: 31: 37 | 039,483,256 | ---- | C] (Apple Inc.) -- C: \Users\Pusz\Desktop\QuickTimeInstaller.exe
[2012-08-01 11: 56: 58 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\qdvd.dll
[2012-08-01 11: 56: 58 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\qdvd.dll
[2012-07-31 17: 01: 32 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012-07-31 11: 40: 06 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Roaming\Canneverbe Limited
[2012-07-31 11: 40: 06 | 000,000,000 | ---D | C] -- C: \ProgramData\Canneverbe Limited
[2012-07-31 11: 39: 55 | 000,000,000 | ---D | C] -- C: \Program Files\CDBurnerXP
[2012-07-31 11: 26: 27 | 005,659,648 | ---- | C] (Canneverbe Limited                                          ) -- C: \Users\Pusz\Desktop\cdbxp_setup_4.4.1.3243_x64.exe
[2012-07-31 11: 18: 37 | 003,907,920 | ---- | C] (Piriform Ltd) -- C: \Users\Pusz\Desktop\ccsetup321.exe
[2012-07-31 10: 42: 29 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Trend Micro
[2012-07-30 19: 03: 32 | 000,000,000 | ---D | C] -- C: \Users\Pusz\Desktop\Nowy folder
[2012-07-26 22: 31: 18 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Common Files\MAGIX Services
[2012-07-26 17: 40: 59 | 000,000,000 | ---D | C] -- C: \Program Files\K-Lite Codec Pack x64
[2012-07-25 09: 51: 12 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Roaming\MAGIX
[2012-07-25 09: 50: 58 | 000,000,000 | ---D | C] -- C: \ProgramData\mufin
[2012-07-25 09: 50: 58 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\mufin
[2012-07-25 09: 50: 50 | 000,000,000 | ---D | C] -- C: \ProgramData\MAGIX
[2012-07-25 08: 58: 14 | 000,000,000 | ---D | C] -- C: \ProgramData\ATI
[2012-07-25 08: 58: 12 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\AMD AVT
[2012-07-23 23: 25: 27 | 000,000,000 | ---D | C] -- C: \Windows\SysNative\temp
[2012-07-23 23: 25: 27 | 000,000,000 | ---D | C] -- C: \ProgramData\PassMark
[2012-07-23 23: 25: 26 | 000,000,000 | ---D | C] -- C: \Users\Pusz\Documents\PassMark
[2012-07-23 23: 25: 26 | 000,000,000 | ---D | C] -- C: \Program Files\BurnInTest
[2012-07-16 19: 49: 06 | 000,000,000 | ---D | C] -- C: \ProgramData\OO Software
[2012-07-16 19: 49: 03 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\OO Software
[2012-07-16 19: 46: 25 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Local\O&O
[2012-07-11 15: 40: 30 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\url.dll
[2012-07-11 15: 40: 30 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\url.dll
[2012-07-11 15: 40: 30 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\mshtmled.dll
[2012-07-11 15: 40: 30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\mshtmled.dll
[2012-07-11 15: 40: 29 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\ieui.dll
[2012-07-11 15: 40: 29 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\ieui.dll
[2012-07-11 15: 40: 29 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\ieUnatt.exe
[2012-07-11 15: 40: 29 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\ieUnatt.exe
[2012-07-11 15: 40: 28 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\inetcpl.cpl
[2012-07-11 15: 40: 28 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\inetcpl.cpl
[2012-07-11 15: 40: 27 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\jscript9.dll
[2012-07-11 15: 40: 27 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\jscript.dll
[2012-07-11 15: 40: 27 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\jscript.dll
[2012-07-11 15: 39: 08 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\ncrypt.dll
[2012-07-11 15: 39: 08 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\msxml3r.dll
[2012-07-11 15: 39: 08 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\msxml3r.dll
[2012-07-11 15: 39: 06 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysNative\cdosys.dll
[2012-07-11 15: 39: 06 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C: \Windows\SysWow64\cdosys.dll
[2012-07-05 18: 40: 06 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Roaming\Comodo
[2012-07-04 16: 05: 59 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Local\Comodo
[2012-07-04 16: 05: 50 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Comodo
[2012-07-04 00: 03: 00 | 000,955,840 | ---- | C] (Oracle Corporation) -- C: \Windows\SysNative\npDeployJava1.dll
[2012-07-04 00: 03: 00 | 000,839,096 | ---- | C] (Oracle Corporation) -- C: \Windows\SysNative\deployJava1.dll
[2012-07-04 00: 03: 00 | 000,268,720 | ---- | C] (Oracle Corporation) -- C: \Windows\SysNative\javaws.exe
[2012-07-04 00: 02: 51 | 000,189,360 | ---- | C] (Oracle Corporation) -- C: \Windows\SysNative\javaw.exe
[2012-07-04 00: 02: 51 | 000,188,840 | ---- | C] (Oracle Corporation) -- C: \Windows\SysNative\java.exe
[2012-07-04 00: 02: 44 | 000,000,000 | ---D | C] -- C: \Program Files\Java
[2012-07-03 23: 59: 05 | 021,869,488 | ---- | C] (Oracle Corporation) -- C: \Users\Pusz\Desktop\jre-7u5-windows-x64.exe
[2012-07-03 23: 57: 21 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Common Files\Java
[2012-07-03 23: 56: 49 | 000,227,720 | ---- | C] (Oracle Corporation) -- C: \Windows\SysWow64\javaws.exe
[2012-07-03 23: 56: 42 | 000,174,064 | ---- | C] (Oracle Corporation) -- C: \Windows\SysWow64\javaw.exe
[2012-07-03 23: 56: 42 | 000,174,064 | ---- | C] (Oracle Corporation) -- C: \Windows\SysWow64\java.exe
[2012-07-03 23: 56: 34 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Java
[2012-07-03 23: 54: 52 | 000,894,448 | ---- | C] (Oracle Corporation) -- C: \Users\Pusz\Desktop\jxpiinstall.exe
[2012-07-03 23: 46: 17 | 003,889,704 | ---- | C] (Piriform Ltd) -- C: \Users\Pusz\Desktop\ccsetup320.exe
[2012-07-03 22: 59: 29 | 029,467,048 | ---- | C] (COMODO) -- C: \Users\Pusz\Desktop\DragonSetup.exe
[2012-07-03 20: 10: 58 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012-07-03 20: 10: 58 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012-07-03 20: 10: 57 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbam.sys
[2012-07-03 20: 10: 57 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Malwarebytes' Anti-Malware
[2012-07-03 19: 55: 07 | 000,000,000 | ---D | C] -- C: \Users\Pusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2012-08-02 00: 09: 57 | 000,597,504 | ---- | M] (OldTimer Tools) -- C: \Users\Pusz\Desktop\OTL.exe
[2012-08-01 23: 49: 00 | 000,000,930 | ---- | M] () -- C: \Windows\tasks\Adobe Flash Player Updater.job
[2012-08-01 23: 44: 19 | 000,000,697 | ---- | M] () -- C: \Users\Pusz\Desktop\prototype2.exe — skrót.lnk
[2012-08-01 23: 32: 41 | 000,001,958 | ---- | M] () -- C: \Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012-08-01 23: 32: 16 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C: \Windows\SysNative\drivers\dtsoftbus01.sys
[2012-08-01 23: 17: 01 | 000,001,209 | ---- | M] () -- C: \Users\Pusz\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2012-08-01 23: 17: 01 | 000,001,185 | ---- | M] () -- C: \Users\Public\Desktop\GOM Player.lnk
[2012-08-01 19: 38: 11 | 000,014,192 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-08-01 19: 38: 11 | 000,014,192 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-08-01 19: 32: 12 | 039,483,256 | ---- | M] (Apple Inc.) -- C: \Users\Pusz\Desktop\QuickTimeInstaller.exe
[2012-08-01 15: 09: 53 | 102,697,338 | ---- | M] () -- C: \Windows\SysNative\drivers\AVG\incavi.avm
[2012-08-01 14: 49: 25 | 000,067,584 | --S- | M] () -- C: \Windows\bootstat.dat
[2012-08-01 14: 49: 22 | 2146,148,351 | -HS- | M] () -- C: \hiberfil.sys
[2012-08-01 14: 49: 19 | 000,897,028 | ---- | M] () -- C: \Windows\SysNative\oodbs.lor
[2012-07-31 17: 01: 32 | 000,003,003 | ---- | M] () -- C: \Users\Pusz\Desktop\HiJackThis.lnk
[2012-07-31 17: 00: 50 | 001,402,880 | ---- | M] () -- C: \Users\Pusz\Desktop\HiJackThis.msi
[2012-07-31 11: 49: 37 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C: \Windows\SysWow64\FlashPlayerApp.exe
[2012-07-31 11: 49: 37 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C: \Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012-07-31 11: 39: 56 | 000,001,750 | ---- | M] () -- C: \Users\Public\Desktop\CDBurnerXP.lnk
[2012-07-31 11: 26: 31 | 005,659,648 | ---- | M] (Canneverbe Limited                                          ) -- C: \Users\Pusz\Desktop\cdbxp_setup_4.4.1.3243_x64.exe
[2012-07-31 11: 19: 11 | 000,000,824 | ---- | M] () -- C: \Users\Public\Desktop\CCleaner.lnk
[2012-07-31 11: 18: 38 | 003,907,920 | ---- | M] (Piriform Ltd) -- C: \Users\Pusz\Desktop\ccsetup321.exe
[2012-07-23 23: 24: 02 | 000,069,043 | ---- | M] () -- C: \Users\Pusz\Desktop\memtest86+-4.20.iso.zip
[2012-07-11 15: 46: 41 | 000,441,648 | ---- | M] () -- C: \Windows\SysNative\FNTCACHE.DAT
[2012-07-08 11: 37: 17 | 000,767,072 | ---- | M] () -- C: \Users\Pusz\Desktop\green 038.jpg
[2012-07-04 00: 02: 45 | 000,955,840 | ---- | M] (Oracle Corporation) -- C: \Windows\SysNative\npDeployJava1.dll
[2012-07-04 00: 02: 45 | 000,839,096 | ---- | M] (Oracle Corporation) -- C: \Windows\SysNative\deployJava1.dll
[2012-07-04 00: 02: 45 | 000,268,720 | ---- | M] (Oracle Corporation) -- C: \Windows\SysNative\javaws.exe
[2012-07-04 00: 02: 45 | 000,189,360 | ---- | M] (Oracle Corporation) -- C: \Windows\SysNative\javaw.exe
[2012-07-04 00: 02: 45 | 000,188,840 | ---- | M] (Oracle Corporation) -- C: \Windows\SysNative\java.exe
[2012-07-03 23: 59: 18 | 021,869,488 | ---- | M] (Oracle Corporation) -- C: \Users\Pusz\Desktop\jre-7u5-windows-x64.exe
[2012-07-03 23: 56: 36 | 000,174,064 | ---- | M] (Oracle Corp
(Ten post był ostatnio modyfikowany: 02.08.2012 00:01 przez pypciu.)

01.08.2012 23:41

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #4

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


W "OTL" w pole "Własne opcje skanowania/skrypt" wklej poniższą zawartość po czym "Wykonaj skrypt":

Kod:
: OTL
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}:  "URL" = http: //isearch.avg.com/search?cid={5445E9E2-9937-4FDB-844D-E42375B08F1E}&mid=e52 a6837447347d1a107d16c64e053cb-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&d s=gm011&pr=sa&d=2 012-03-26 21: 24: 58&v=10.2.0.3&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}:  "URL" = http: //www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}:  "URL" = http: //search.sweetim.com/search.asp?src=6&q={searchTerms}
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  disabled File not found
CHR - homepage:  http: //home.sweetim.com/
O3 - HKCU\..\Toolbar\WebBrowser:  (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O8: [b]64bit: [/b] - Extra context menu item:  Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200 File not found
O8: [b]64bit: [/b] - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //C: \PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8: [b]64bit: [/b] - Extra context menu item:  E&xport to Microsoft Excel - res: //C: \PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000 File not found
O8: [b]64bit: [/b] - Extra context menu item:  Se&nd to OneNote - res: //C: \PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //C: \PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item:  E&xport to Microsoft Excel - res: //C: \PROGRA~2\Microsoft Office\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item:  Se&nd to OneNote - res: //C: \PROGRA~2\Microsoft Office\Office14\ONBttnIE.dll/105 File not found
O18: [b]64bit: [/b] - Protocol\Handler\ms-help - No CLSID value found
O18: [b]64bit: [/b] - Protocol\Handler\viprotocol - No CLSID value found
O20: [b]64bit: [/b] - HKLM Winlogon:  VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon:  VMApplet - (/pagefile) - File not found
O21: [b]64bit: [/b] - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom:  AutoRun - 1

: Commands
[emptytemp]

A gdzie zawartość drugiego loga "Extras"?Po wykonaniu skryptu pokaż raport z usuwania który pokaże Ci się po ponownym uruchomieniu komputera.


(Ten post był ostatnio modyfikowany: 02.08.2012 03:20 przez Illidan.)

02.08.2012 03:20

Róża Podziękowania od: pypciu
Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Deron
User systemu

Liczba postów: 281
Post: #5

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Miałem podobny problem, a ustąpił po wymianie jednej kości RAM-u na inną.

Teoria bez praktyki jest martwa, praktyka bez teorii - głupia.
Włodzimierz Ilicz Uljanow (Lenin)


02.08.2012 05:20

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
pypciu
Wdrażany
Liczba postów: 25
Post: #6

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Skrypt z OLT po ponownym rozruchu kompa:
Kod:
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E :  value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E :  value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E :  value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Use Chrome's Settings page to change the HomePage.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&ksportuj do programu Microsoft Excel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Se&nd to OneNote\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet: /pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD: 1 /E :  value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User:  All Users

User:  Default
->Temp folder emptied:  0 bytes
->Temporary Internet Files folder emptied:  33170 bytes

Zastanawiałem się na początku, czy to nie problem z pamięcią, ale chyba wtedy żadne przywracanie systemu by nie pomagało? Narazie 3 dzień i jest ok. Wczoraj chwilową zawieszkę system załapał i się uspokoił. Jak sprawdzam użycie procesora i pamięci w menadżerze, to w czasie tych właśnie problemów nic nie skacze do góry i wygląda normalnie.

02.08.2012 12:09

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #7

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Raport z usuwania "ok".Nadal czekam na log "Extras".Przeskanuj system tez gruntownie jeszcze "Malwaresbytes Anti- Malware" i jak coś znajdzie usuń.Posprzątaj też i zoptymalizuj system "CCleaner" lub "SlimCleaner".Program "SlimCleaner" ma opcję rekomendacji,wiec łatwo możesz dzięki temu wyłączyć zbędne obciążające programy i usługi systemu.Zaktualizuj też wszystkie sterowniki w komputerze, pościągaj je ze stron producentów podzespołów komputera ,lub skorzystaj z darmowego programu "SlimDrivers".Po tych zabiegach zobacz czy jest poprawa.Pamięć RAM możesz sprawdzić jak chcesz programem "MemTest86+".


02.08.2012 18:31

Róża Podziękowania od: pypciu
Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Deron
User systemu

Liczba postów: 281
Post: #8

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Program MemTest86 nic nie daje. U mnie wskazywał, że kości są ok, a jednak "gryzły" się i to obie Kingstona.

Teoria bez praktyki jest martwa, praktyka bez teorii - głupia.
Włodzimierz Ilicz Uljanow (Lenin)


02.08.2012 20:47

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #9

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Deron ,to że kości się gryzły to nie znaczy ze są uszkodzone,jeśli testowałeś je pojedynczo to program nie mógł tego wykryć że nie współpracowały z sobą,Zależy jak test przeprowadzałeś,mi na przykład sypnęło błędami dopiero przy 6 cyklu.Program dobrze wykrywa nie pasujące kości do siebie,czy do płyty głównej jeśli testujesz je razem.Zawsze można też użyć "Diagnostyki pamięci RAM" w systemie Windows 7,ustawić tam test cykliczny i po paru godzinach zobaczyć wyniki :-).


02.08.2012 21:16

Róża Podziękowania od: pypciu
Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
pypciu
Wdrażany
Liczba postów: 25
Post: #10

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Log z Extras:

Kod:
OTL Extras logfile created on:  2012-08-02 00: 30: 44 - Run 1
OTL by OldTimer - Version 3.2.55.0     Folder = C: \Users\Pusz\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale:  00000415 | Country:  Polska | Language:  PLK | Date Format:  yyyy-MM-dd

8,00 Gb Total Physical Memory | 5,73 Gb Available Physical Memory | 71,65% Memory free
31,99 Gb Paging File | 28,71 Gb Available in Paging File | 89,75% Paging File free
Paging file location(s):  [Binary data over 100 bytes]

%SystemDrive% = C:  | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C:  | 247,92 Gb Total Space | 196,52 Gb Free Space | 79,27% Space Free | Partition Type:  NTFS
Drive D:  | 341,70 Gb Total Space | 18,46 Gb Free Space | 5,40% Space Free | Partition Type:  NTFS
Drive E:  | 341,80 Gb Total Space | 23,71 Gb Free Space | 6,94% Space Free | Partition Type:  NTFS
Drive G:  | 1,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type:  CDFS
Drive I:  | 596,02 Gb Total Space | 514,35 Gb Free Space | 86,30% Space Free | Partition Type:  FAT32

Computer Name:  PUSZ-PC | User Name:  Pusz | Logged in as Administrator.
Boot Mode:  Normal | Scan Mode:  Current user | Include 64bit Scans
Company Name Whitelist:  Off | Skip Microsoft Files:  Off | No Company Name Whitelist:  On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C: \Program Files\Opera x64\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C: \Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C: \Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C: \Program Files\Opera x64\Opera.exe (Opera Software)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C: \Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error:  Key error.
htmlfile [edit] -- Reg Error:  Key error.
htmlfile [open] -- Reg Error:  Key error.
htmlfile [opennew] -- Reg Error:  Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C: \Program Files\Opera x64\Opera.exe" "%1" (Opera Software)
https [open] -- "C: \Program Files\Opera x64\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error:  Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error:  Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [napiprojekt] -- "C: \Program Files (x86)\NAPI-PROJEKT\napisy.exe" "%1" ()
Directory [napiprojekt0] -- "C: \Program Files (x86)\NAPI-PROJEKT\napisy.exe" "%1" -pobierz_ang ()
Directory [Winamp.Bookmark] -- "C: \Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C: \Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C: \Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error:  Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error:  Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error:  Key error.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error:  Key error.
htmlfile [edit] -- Reg Error:  Key error.
htmlfile [open] -- Reg Error:  Key error.
htmlfile [opennew] -- Reg Error:  Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C: \Program Files\Opera x64\Opera.exe" "%1" (Opera Software)
https [open] -- "C: \Program Files\Opera x64\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error:  Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error:  Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [napiprojekt] -- "C: \Program Files (x86)\NAPI-PROJEKT\napisy.exe" "%1" ()
Directory [napiprojekt0] -- "C: \Program Files (x86)\NAPI-PROJEKT\napisy.exe" "%1" -pobierz_ang ()
Directory [Winamp.Bookmark] -- "C: \Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C: \Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C: \Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error:  Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error:  Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error:  Key error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainPr​ofile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Standard​Profile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicPr​ofile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Standard​Profile\AuthorizedApplications\List]
"C: \Program Files (x86)\Preme for Windows 7\preme.exe" = C: \Program Files (x86)\Preme for Windows 7\preme.exe: *: Enabled: Preme for Windows 7
"C: \Program Files (x86)\Preme for Windows 7\preme.exe" = C: \Program Files (x86)\Preme for Windows 7\preme.exe: *: Enabled: Preme for Windows 7


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Firewall​Rules]
"{3329870A-1D08-45F0-9A74-D3F2A23E07A9}" = lport=6004 | protocol=17 | dir=in | app=c: \program files (x86)\microsoft office\office14\outlook.exe |
"{6BB1AAA1-7C5B-49D5-A6AA-5BD9BEADF32C}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c: \windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Firewall​Rules]
"{0313FD37-95AD-48FF-B053-C8AAE80D1EF7}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{04DD20ED-29DD-49AC-AA28-0CA590E444B1}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{05BFAD07-0697-49C2-84A2-07F8D3AEB417}" = protocol=17 | dir=in | app=c: \program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe |
"{0B8B2844-5F2F-4258-85F4-339FF23197C5}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{114B103F-FD36-452A-BBCD-448C0AE19C00}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{15937B8F-85D2-4783-8701-23040999D718}" = protocol=17 | dir=in | app=c: \program files (x86)\microsoft office\office14\groove.exe |
"{17F1AB71-BF8C-4869-AA1A-02F6B0D46863}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{25B31D8D-6142-4909-B4D8-F99F2031E921}" = protocol=6 | dir=in | app=c: \windows\syswow64\pnkbstrb.exe |
"{272E9388-71EB-421B-A46D-3834006FCA6A}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{27B1E058-577A-4589-A98A-BC3883715846}" = dir=in | app=c: \program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{2DC62D67-F7BB-4C0A-9262-ADDDD8F9C73B}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{2E00C5C3-BD6B-4B45-99F8-38EB4A57C263}" = protocol=17 | dir=in | app=d: \gry - zainstalowane\max payne 3\playmaxpayne3.exe |
"{2FC9AB7F-B3AA-4148-A718-4AD68374DEA8}" = protocol=17 | dir=in | app=c: \program files (x86)\avg\avg2012\avgmfapx.exe |
"{3656D778-11B2-4A7C-B4E6-2AEF3F7C8C5B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{370A85CF-FD57-4C81-B44E-E38D6E287C05}" = protocol=17 | dir=in | app=c: \windows\syswow64\muzapp.exe |
"{3CBCBB1B-BD47-4F48-AF1D-DBE4C999F745}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{43AFD52E-8ACC-4A5A-9665-4A1DB99AD21B}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{49B3DB88-71EB-4866-863C-B461B52FEE6F}" = protocol=6 | dir=in | app=c: \windows\syswow64\pnkbstra.exe |
"{519BF640-7AB6-426C-9F19-218615527981}" = protocol=17 | dir=in | app=c: \program files (x86)\avg\avg2012\avgemca.exe |
"{55B38137-94D8-45D6-B2BC-5D150BF2DAB2}" = protocol=6 | dir=in | app=c: \program files (x86)\avg\avg2012\avgemca.exe |
"{562D508B-246A-4612-BB84-1E0C03D0E8BC}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{564F720F-A4A4-4BC4-82B6-095A85FB2605}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{56CE5A3C-571B-427F-B3D7-3FF58C92767C}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |
"{595FB129-2799-47F9-85E5-C0BA97CDADAB}" = protocol=17 | dir=in | app=c: \program files\soluto\solutoservice.exe |
"{5A7E1F37-A7A1-49CD-847B-F47F5A3C236C}" = protocol=17 | dir=in | app=c: \program files (x86)\avg\avg2012\avgdiagex.exe |
"{65BA28CE-85F5-48DF-87E6-050C825DCC47}" = protocol=17 | dir=in | app=c: \program files (x86)\opera\opera.exe |
"{672AABFE-3DA3-46CA-A18E-4B96F4D74E03}" = protocol=17 | dir=in | app=c: \program files\opera x64\opera.exe |
"{7E4EC3EB-63CC-4673-BD79-56861C204E43}" = protocol=6 | dir=in | app=c: \program files\soluto\solutoupdateservice.exe |
"{8330CD1E-BBC6-4310-A76E-01F4AA498DFB}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{87A2CC97-485A-498D-976B-4182B9DF9B54}" = protocol=6 | dir=in | app=c: \windows\syswow64\muzapp.exe |
"{8D013FB2-6E5A-4544-A976-BFF04B7DFDB1}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{8E769F2A-BC0E-40B8-8654-2D5765B294E2}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{8F6F3B65-52F7-4FE2-94A1-DA2B24C368D6}" = protocol=6 | dir=in | app=c: \program files\soluto\solutoconsole.exe |
"{9210B887-B153-4B89-9584-17A3F28B706A}" = protocol=6 | dir=in | app=c: \program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{9627F727-E1B3-48BC-ADCB-DA5BF403F5FD}" = protocol=17 | dir=in | app=c: \program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{994EEDBB-54D0-4FE3-9921-21B8EBC6312C}" = dir=in | app=c: \program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{9D2065EF-8CC3-49F1-9F41-41F155954C5F}" = protocol=17 | dir=in | app=c: \program files (x86)\utorrent\utorrent.exe |
"{9D4A862A-0515-4B07-9865-EA029B12FCC6}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{9D86D4E6-3613-4E72-8B7F-3FAD70972C51}" = protocol=17 | dir=in | app=c: \program files\soluto\solutoconsole.exe |
"{A168DE69-36B8-4F2E-A38E-2A718F19AC37}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{A3BE8129-1F8E-4F4A-A7F5-70A9D2561E35}" = protocol=6 | dir=in | app=c: \program files\opera x64\opera.exe |
"{A3F432B3-A0F3-4D5A-9861-F375A19E6CC9}" = protocol=17 | dir=in | app=c: \windows\syswow64\pnkbstrb.exe |
"{A5580E18-C9F1-4125-BC8D-F3F08CAF3051}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{A74AD66D-5C23-42DF-986F-228043A96023}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{B0D79BF7-B37D-4407-8D29-EA917FA34370}" = dir=in | app=c: \program files (x86)\hp\hp software update\hpwucli.exe |
"{B0DD0004-30CF-400F-BC68-25C33CD75692}" = protocol=6 | dir=in | app=c: \program files\opera x64\pluginwrapper\opera_plugin_wrapper.exe |
"{B581D36D-B757-481F-BEDA-9EBBBA298C90}" = protocol=6 | dir=in | app=d: \gry - zainstalowane\max payne 3\playmaxpayne3.exe |
"{BA0BD686-FAB9-4DAD-A2F0-D6015A7593B8}" = protocol=17 | dir=in | app=c: \program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe |
"{BA43CCA8-282B-4BA0-B55B-8138E030E901}" = protocol=6 | dir=in | app=c: \program files (x86)\utorrent\utorrent.exe |
"{C0DCF92D-053C-49E3-AF5D-646A8CD5A34F}" = protocol=17 | dir=in | app=c: \program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe |
"{C7257204-9A52-4D25-985F-3728D8B61764}" = protocol=17 | dir=in | app=c: \program files (x86)\avg\avg2012\avgnsa.exe |
"{CC85F318-E51C-4AFC-9CE2-7ED1EE9B4FFA}" = protocol=6 | dir=in | app=c: \program files (x86)\microsoft office\office14\groove.exe |
"{CFE3CC3C-DECC-4DCA-A5DF-DF4B2EF41837}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{D29ACB25-ACB3-44B6-AE98-97E521BC1F7B}" = protocol=6 | dir=in | app=c: \program files\soluto\solutoservice.exe |
"{D36D98F6-48B1-4056-B91C-DEA28118D34C}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{D96F91D0-3BD5-4A91-95C1-685338E14A79}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqnrs08.exe |
"{DCB67CD2-D68A-4703-84DF-EE5A36AD7F43}" = protocol=6 | dir=in | app=c: \program files (x86)\avg\avg2012\avgdiagex.exe |
"{DE608EEB-DCD0-48CE-9692-F5B0A77BF5B6}" = protocol=17 | dir=in | app=c: \windows\syswow64\pnkbstra.exe |
"{DEE9297B-2C51-4202-8BEE-52CEBFBEA51F}" = protocol=6 | dir=in | app=c: \program files\opera x64\pluginwrapper\opera_plugin_wrapper_32.exe |
"{E2C8832E-FB9F-442F-BB4D-B5877E12B498}" = protocol=17 | dir=in | app=c: \program files\soluto\solutoupdateservice.exe |
"{E3D48053-064E-48FB-B067-C63782CDE87A}" = protocol=6 | dir=in | app=c: \program files (x86)\avg\avg2012\avgmfapx.exe |
"{E3F6C5A2-111B-4AA4-8589-B4BEFD8179B5}" = protocol=6 | dir=in | app=c: \program files\soluto\soluto.exe |
"{E72B05C6-CB6A-4825-A613-4FF7FF2ACC3D}" = protocol=6 | dir=in | app=c: \program files (x86)\avg\avg2012\avgnsa.exe |
"{EF0497CB-797C-43D8-B186-269CF68E7441}" = dir=in | app=c: \program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{EF9C33BF-D5A4-48BD-B1BF-9B20ACAE1745}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EFFE6776-0DCC-40EA-B613-4C7E84E4F049}" = dir=in | app=c: \program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{F8137496-4490-4D03-BE43-524612121650}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{F8D70712-7917-44E7-9A35-A72BF276B51E}" = protocol=6 | dir=in | app=c: \program files (x86)\opera\opera.exe |
"{FB1A2835-1BBD-41E5-8EA0-FD2FFD5FBB3A}" = protocol=6 | dir=in | app=c: \program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{FCCB8B5A-E8A6-4A01-A6E5-BDB57C48A52E}" = protocol=17 | dir=in | app=c: \program files\soluto\soluto.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit:  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{012C87CF-282E-4142-84F8-DCDD07F54182}" = Soluto
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C8159DD-1890-4625-A5B2-E3D8D78D4486}" = AVG 2012
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5149C938-5BBE-4E14-8F40-C33FB11C2156}" = Nitro Reader 2
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5EA12CF3-8162-47F6-ACAF-45AD03EFB08F}" = Adobe PDF iFilter 9 for 64-bit platforms
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center
"{7A98574D-B3EA-2A5C-CF11-02EF1D1DB500}" = ATI AVIVO64 Codecs
"{7D088FD6-67B8-4186-947C-5FB4CC7227B5}" = O&O Defrag Professional
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack
"{8F110B6A-60A2-4542-BB19-AD6234E2969D}" = SAMSUNG Moblie USB Driver
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9E3B2120-0BD8-9865-0387-E9BAC2A53AD3}" = ccc-utility64
"{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ABE286AE-C65D-B7DE-C8D1-DF79584169B4}" = AMD Fuel
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BE882A12-5A45-3DFF-9FD0-306DE65EB8A5}" = AMD Catalyst Install Manager
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{D050583D-5CEC-47B1-88AA-8B328CAA8621}" = AVG 2012
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{EF393943-0CCE-9CD9-6181-96DF4E4428EF}" = AMD Media Foundation Decoders
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F809FFB5-6F9B-AFDE-6048-5D9E95A85505}" = AMD Drag and Drop Transcoding
"AVG" = AVG 2012
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.59
"DriverAgent.exe" = DriverAgent by eSupport.com
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended
"Opera 12.00.1467" = Opera 12.00
"Shop for HP Supplies" = Shop for HP Supplies
"Speccy" = Speccy
"Unlocker" = Unlocker 1.9.1-x64
"WinRAR archiver" = WinRAR 4.01 (64-bitowy)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0D97F8D1-2102-53D2-5633-C992D6086801}" = CCC Help Chinese Traditional
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0EA00EA7-42C0-ED9C-9110-2C04B8EDBA66}" = CCC Help Italian
"{0EB86B70-91FF-39BF-633C-785DF2218CC6}" = CCC Help French
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1686C07D-C2BB-A8B2-C5ED-32C4EE1A3E62}" = CCC Help Spanish
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18B6A9F8-25BC-5978-6B42-A50FA2CABC18}" = CCC Help English
"{1AA94747-3BF6-4237-9E1A-7B3067738FE1}" = Max Payne 3
"{1D301950-EA2F-4882-9AA0-49467756842A}" = SweetIM for Messenger 3.3
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20AEA7B1-6155-44A2-B58E-430F2C9F4ABD}" = AMD OverDrive
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{298C6691-46B2-2065-0DD7-1E7B3B669A47}" = CCC Help Finnish
"{2E87F4AB-99BF-421C-AF7B-365A9C08549A}" = F300
"{2ECA81CA-D932-4AD3-AD59-BF5CCF099C83}" = Catalyst Control Center - Branding
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{400C5445-1AE8-1A41-CAC6-AB114341F65D}" = CCC Help Swedish
"{40719211-D09A-11DF-BA30-0013D3D69929}" = MSVCRT Redists
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{448B1C6D-02C2-7681-66B2-624E58B25375}" = CCC Help Turkish
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46EB9D45-FC1A-2635-1693-176E6FA1C672}" = CCC Help Portuguese
"{48F95CE7-69D9-4967-81F7-D763CABFBD53}" = Debugging Tools for Windows (x86)
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{651F43AA-3F06-9277-6F1B-8E8155017463}" = CCC Help Polish
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{68DE32E1-292B-6A02-6A53-935BFAE70C99}" = CCC Help Chinese Standard
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{818212BA-7F8C-DDF9-64BE-F6D0B6F46D29}" = CCC Help German
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84F4542C-ED64-28AC-49B3-1A9BAB395AB4}" = CCC Help Hungarian
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{915726DF-7891-444A-AA03-0DF1D64F561A}" = L.A. Noire
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C41195F-11B3-8EEC-6634-7183BE6CB1B1}" = CCC Help Japanese
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{A1A9A33E-F1E5-FBF4-8D72-E90BEAC7108A}" = HydraVision
"{A33A89D0-2F48-FD1C-A243-9073EE0592E0}" = Catalyst Control Center InstallProxy
"{A66FB6C7-B689-AFD5-21BA-7CAF8E44E6E6}" = Catalyst Control Center Graphics Previews Common
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{AE136F7F-7DC6-600F-9DF9-BFA0DF516135}" = Catalyst Control Center Localization All
"{B42A6552-1A83-4D79-9137-AB0C9036249A}" = Quake Live Mozilla Plugin
"{B4CF00AE-2622-7BC6-24EC-4E5A0A8C9135}" = CCC Help Czech
"{BAE1C0A8-634D-CFF1-0E0C-893092427D34}" = CCC Help Danish
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C2DEC505-79A9-E952-32B0-31B67B83E231}" = CCC Help Korean
"{C2FB14FB-DF6B-287D-BDC3-C7BEC86F539E}" = AMD VISION Engine Control Center
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEFAE22-4D01-0084-D1CA-AC14AA743A97}" = CCC Help Greek
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DE460826-5E72-2357-154F-E376F9926008}" = CCC Help Norwegian
"{E21FFD29-D231-3BD3-6941-15710E44BED4}" = CCC Help Dutch
"{E3E313C7-0AE2-7F44-52E8-528D4EDC74B2}" = CCC Help Thai
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F07A6316-3EF3-4F36-87BA-5C0FD2AFBE68}" = SanDisk ® Media Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX
"{F9929777-7B6E-F53D-3105-1C06E5120CA1}" = CCC Help Russian
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v1.50
"Alan Wake_is1" = Alan Wake
"ASRock IES_is1" = ASRock IES v2.0.84
"AVG Secure Search" = AVG Security Toolbar
"CrystalDiskInfo_is1" = CrystalDiskInfo 4.3.0a
"DAEMON Tools Lite" = DAEMON Tools Lite
"DMX5_is1" = DriverMax 6
"Fences" = Fences
"foobar2000" = foobar2000 v1.1.11
"Freemake Video Converter_is1" = Freemake Video Converter wersja 3.0.2
"Gadu-Gadu 10" = Gadu-Gadu 10
"GoldWave v5.67" = GoldWave v5.67
"GOM Player" = GOM Player
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platforma Menedżera urządzeń
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"IrfanView" = IrfanView (remove only)
"KatMouse" = KatMouse (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.7.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.62.0.1100
"Mozilla Firefox 15.0 (x86 pl)" = Mozilla Firefox 15.0 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyFreeCodec" = MyFreeCodec
"NapiProjekt_is1" = NapiProjekt (2.0.0.2151)
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"Odkurzacz 12.6_is1" = Odkurzacz 12.6
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OpenAL" = OpenAL
"Opera 12.00.1467" = Opera 12.00
"Picasa 3" = Picasa 3
"PunkBusterSvc" = PunkBuster Services
"RadeonPro_is1" = RadeonPro 1.0 (Build 1.1.0.6)
"Revo Uninstaller" = Revo Uninstaller 1.94
"Rockstar Games Social Club" = Rockstar Games Social Club
"Saints Row The Third_is1" = Saints Row The Third
"SpeedFan" = SpeedFan (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"uTorrent" = µTorrent
"Vividas Player Plugin_is1" = Vividas Player Plugin v4.1
"Winamp" = Winamp

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Flux" = F.lux
"Google Chrome" = Google Chrome
"MyFreeCodec" = MyFreeCodec
"Winamp Detect" = Winamp Detector Plug-in

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2011-05-12 11: 59: 34 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
PhotoSnap\PhotoSnapViewer.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu
.  Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika,
która jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 2011-05-12 12: 01: 08 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c: \program files (x86)\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe".  Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2011-05-14 15: 06: 38 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
Toolkit\DiscSpeed.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu .
Wersja
składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która
jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 2011-05-14 15: 06: 40 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
PhotoSnap\PhotoSnap.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu
.  Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika,
która jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 2011-05-14 15: 06: 40 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
PhotoSnap\PhotoSnapViewer.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu
.  Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika,
która jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 2011-05-14 15: 08: 39 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c: \program files (x86)\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe".  Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2011-05-16 06: 23: 37 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
Toolkit\DiscSpeed.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu .
Wersja
składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która
jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 2011-05-16 06: 23: 38 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
PhotoSnap\PhotoSnap.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu
.  Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika,
która jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 2011-05-16 06: 23: 38 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842832
Description = Nie można wygenerować kontekstu aktywacji dla „C: \Program Files (x86)\Nero\Nero8\Nero
PhotoSnap\PhotoSnapViewer.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu
.  Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika,
która jest już aktywna.  Składniki powodujące konflikt:   Składnik 1:  C: \Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Składnik
2:  C: \Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 2011-05-16 06: 25: 14 | Computer Name = Pusz-PC | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c: \program files (x86)\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe".  Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

[ System Events ]
Error - 2012-07-30 15: 52: 59 | Computer Name = Pusz-PC | Source = Service Control Manager | ID = 7043
Description = Usługa Windows Update nie została poprawnie zamknięta po odebraniu
kodu sterującego przed zamknięciem.

Error - 2012-07-30 15: 54: 33 | Computer Name = Pusz-PC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AODDriver4.1 z powodu następującego błędu:
   %%2

Error - 2012-07-30 16: 17: 19 | Computer Name = Pusz-PC | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 2012-07-30 17: 18: 13 | Computer Name = Pusz-PC | Source = EventLog | ID = 6008
Description = Poprzednie zamknięcie systemu przy 23: 16: 18 na ?2012-?07-?30 było
nieoczekiwane.

Error - 2012-07-30 17: 18: 18 | Computer Name = Pusz-PC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AODDriver4.1 z powodu następującego błędu:
   %%2

Error - 2012-07-31 04: 05: 58 | Computer Name = Pusz-PC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AODDriver4.1 z powodu następującego błędu:
   %%2

Error - 2012-07-31 05: 04: 24 | Computer Name = Pusz-PC | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 2012-07-31 06: 37: 08 | Computer Name = Pusz-PC | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 2012-07-31 08: 30: 31 | Computer Name = Pusz-PC | Source = volsnap | ID = 393229
Description = Kopia w tle woluminu D:  nie może powiększyć magazynu kopii w tle na
woluminie D: .

Error - 2012-07-31 08: 31: 21 | Computer Name = Pusz-PC | Source = volsnap | ID = 393251
Description = Wykonywanie kopii w tle woluminu D:  zostało przerwane, ponieważ nie
można powiększyć magazynu kopii w tle.


< End of report >

Programem Malwarebytes posługuję się na codzień i regularnie skanuję. Wszystko jest ok, nic nie znalazł, tak samo jak AVG. CCleanerem też bawię się co jakiś czas, skanuję rejestr i usuwam śmieci, czasem też używam Odkurzacza. Do aktualizacji sterowników używałem DriverMax, ale spróbuję z tym nowym SlimDrivers. Sterowniki, prócz najnowszych do karty sieciowej mam zaktualizowane Uśmiechnięty Pytanie co do programu Memtest86+:

http://www.stahurski.fora.pl/bootowalny-...in,18.html

Zgodnie z tą instrukcją próbowałem przeprowadzić ten test, natomiast zupełnie nie wiem jak edytować ten plik syslinux.cfg. W biosie ustawiam botowanie jak trzeba, odpala mi się obraz z pendrive'a, ale na ekranie wyświetla mi sie napis "Press [TAB] to edit options" oraz pod spodem "Automatis bot in 10 seconds" z czego nic się nie zmienia, ja nie moge nic zrobić, test nie dochodzi do skutku. Sądzę, że źle edytuję ten plik w notatniku, z resztą z tego co widzę tutorial jest oparty na XP...
Pozdrawiam!

PS. Jak do tej pory wszystko działa ok już dłuższy czas. Dzięki Illidan za pomoc, chyba coś się ustabilizowało bo tych paru manewrach. Diagnostyka pamięci w siódemce nie wykazała błędów. Jeżeli masz bądź macie jeszcze jakieś wskazówki co do loga z Extras, to z chęcią przeczytam i się zastosuję!
(Ten post był ostatnio modyfikowany: 03.08.2012 16:08 przez pypciu.)

03.08.2012 15:10

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #11

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Co do "Memtest86+" to pobierz wersje na "Pendrive",nie przerabiaj wersję "ISO" :-).Na tej stronie ją znajdziesz.Ale jak diagnostyka pamięci systemu Windows nie wykazała błędów to możesz raczej pominąć diagnostykę "Memtest",chodź uważam że nie zaszkodzi ją przeprowadzić.A co do logu "Extras" to już do niczego się nie stosuj,tylko zamieść mi go do wglądu,masz go pewnie na pulpicie,czy w innym katalogu gdzie jest program "OTL" obok logu "OTL.txt":-). Jeśli wszystko jest już "ok" to uruchom "OTL" raz jeszcze i uruchom opcję "Sprzątanie",usunie to program wraz z jego kwarantanną.

EDIT.Przepraszam!!Teraz widzę że zamieściłeś ten log "Extras".Na starość ślepnę...Już przeglądam go...


(Ten post był ostatnio modyfikowany: 03.08.2012 23:39 przez Illidan.)

03.08.2012 23:36

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Illidan
Ekspert

Liczba postów: 1.024
Post: #12

RE: Windows 7 x64 Ultimate zacina się co 2 dni: log z HijackThis do sprawdzenia


Co do logu "Extras" to masz tam jakiś konflikt z programem "Drivermax" i "'Nero 8".Co do "DriverMax" to radze usunąć skoro masz "SlimDriver" teraz,moim zdaniem jest lepszy,ale to tylko moje zdanie;-).Nero tez bym usunął dedykowanym de-instalatorem td tego celu ze strony Nero i i zainstalował coś darmowego lżejszego,jak "CDBurnerXP" itp..No i kończy Ci się miejsce na dysku "D" na kopię zapasową systemu, wyłącz tą usługę jak nie masz miejsca,lub aktywuj ją ręcznie tylko kiedy chcesz ją wykonać,albo opróżnij miejsce na dysku, przenosząc stare kopie lub usuwając je. Mogę Ci też polecić alternatywę na Kopie Windows,jeśli chcesz,wydaje mi się że narzędzie jest lepsze.,ale to jak będziesz chciał.
Jeśli chodzi o resztę to już w zasadzie wszystko.Jak jest już "OK" to możesz włączyć "OTL" i w nim uruchomić opcję "Sprzątanie". usunie to program i jego kwarantannę.


(Ten post był ostatnio modyfikowany: 04.08.2012 14:52 przez Illidan.)

04.08.2012 14:49

Znajdź wszystkie posty użytkownika
Odpowiedz cytując ten post
Odpowiedz

Podobne wątki
Wątek: Autor Odpowiedzi: Wyświetleń: Ostatni post
Logi do sprawdzenia (nie działają niektóre strony internetowe) crusio 0 1.725 23.04.2015 20:28
Ostatni post: crusio
svchost.exe oraz logi do sprawdzenia D3jvid 3 2.377 18.04.2015 22:20
Ostatni post: Illidan
Komputer muli, bardzo wolny start Windows 7, logi do sprawdzenia. kotletowygrajek 0 1.897 18.11.2014 09:05
Ostatni post: kotletowygrajek
Windows powolny start, logi do sprawdzenia Jareq41 11 3.073 26.04.2014 23:13
Ostatni post: Illidan
Prośba o sprawdzenie logów z HijackThis 8element 1 1.564 19.01.2013 17:33
Ostatni post: Illidan
Prośba o sprawdzenie loga hijackthis zakwas 3 1.889 05.11.2012 12:30
Ostatni post: peciaq
« Starszy wątek | Nowszy wątek »

Temat został oceniony na 0 w skali 1-5 gwiazdek.
Zebrano 2 głosów.