Skocz do zawartości

Powazn wirus-Prosze o pomoc


Rekomendowane odpowiedzi

siemka dzis rano pobrałem sobi cheata do gry gta sa dokładniej money hack i przed instalacja moj antywirus avg ostrzegł mnie iz to wirus lecz ja to olałem i normalnie właczyłem tego cheata lecz gdy właczyłem przegladarke strasznie wolno chodziła napisałem na pewnym forum iz ma owy problem i oni mi napisali ze mam jakis wirus Serach Protect i skierowali mnie do was na te forum i prosze was o pomoc bo jezeli mi nie pomozecie to nie wiem kto mi pomoze.

 

Ps. Przepraszam za ewentualne błedy pisze z telefonu.

Odnośnik do komentarza
Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Witam,
zapoznaj się prosze z zasadami działu:
1. https://www.fixitpc.pl/forum-38/announcement-3-wa%C5%BCne-zak%C5%82adanie-tematu-obowi%C4%85zkowe-logi/
2. https://www.fixitpc.pl/forum-38/announcement-2-wa%C5%BCne-oprogramowanie-emuluj%C4%85ce-nap%C4%99dy/
3. https://www.fixitpc.pl/forum-38/announcement-1-wa%C5%BCne-u%C5%BCytkownicy-uprawnieni-do-pomocy/

Przeczytaj wszystko dokładnie przed wykonaniem dzialan.
Postepujac zgodnie z powyzszymi instrukcjami - dołącz do tematu wymagane logi.
Ma być łącznie 6 logów (GMER [recznie wklejasz wynik skanowania do pliku GMER.txt], FRST [FRST.txt, Addition.txt, Shortcut.txt], OTL [OTL.txt i Extras.txt])
Jak coś nie bedzie chciało sie uruchomić/sciagnac - to odpal system w trybie awaryjnym i wtedy spróbuj.

Jeśli z czymś bedzie problem - pisz w poście.
Po wrzuceniu logów nie dokonuj już żadnych zmian na kompie - logi muszą być aktualne.
Przeczytaj dokładnie info na temat GMERa.
Jak coś zmieniasz w poście to używaj opcji EDYTUJ by był porządek.
Czekaj cierpliwie na pomoc. Na forum są opóźnienia przez nieobecność Picasso. Trzeba uzbroić się w cierpliwość.

Odnośnik do komentarza

OTL :

 

OTL Extras logfile created on: 2014-07-29 18:54:10 - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\ppp\Desktop
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
 
2,00 Gb Total Physical Memory | 0,78 Gb Available Physical Memory | 38,97% Memory free
4,00 Gb Paging File | 2,57 Gb Available in Paging File | 64,34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,56 Gb Total Space | 25,75 Gb Free Space | 26,39% Space Free | Partition Type: NTFS
Drive D: | 135,23 Gb Total Space | 67,36 Gb Free Space | 49,81% Space Free | Partition Type: NTFS
Drive E: | 7,87 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive H: | 3,53 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
 
Computer Name: ZACHARY | User Name: ppp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AFAAAD3-94B2-4E30-A699-EB44370AEB2B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{11561BBF-5906-4802-88A8-FF4D45C37CE3}" = lport=7850 | protocol=6 | dir=in | name=war thunder | 
"{17421692-907D-4A13-B8BD-F2AA9B96BB2E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{232FE2A8-42FD-4538-84A4-630FDEA623A1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{27BAD661-FABB-4DB0-B635-645DE57B1BA4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{30BC3AB7-3507-4251-801F-D331E6BF0F22}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{375D6D75-1A0C-491B-9033-50F28A37F4C6}" = lport=20010 | protocol=17 | dir=in | name=war thunder | 
"{39F05B84-7508-4C52-BBE2-353FC181B4A5}" = rport=139 | protocol=6 | dir=out | app=system | 
"{57CFA40E-1538-4DBE-BAE1-2DD106DBBF91}" = lport=80 | protocol=6 | dir=in | name=war thunder | 
"{5B6F95F4-919B-4A83-8776-58333B20DF5A}" = rport=445 | protocol=6 | dir=out | app=system | 
"{67EB04B2-7984-47B1-B05D-D00E08A48213}" = lport=8090 | protocol=6 | dir=in | name=war thunder | 
"{720EDE75-C0E2-429C-BC25-47534CE586DC}" = lport=3478 | protocol=17 | dir=in | name=war thunder | 
"{736C0818-DC6A-44DA-B8A7-BF056377851A}" = lport=33333 | protocol=6 | dir=in | name=war thunder | 
"{7988B4F4-2D34-41E1-88FF-F00A4EC70C31}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{8175E00F-9877-4D3C-8AD8-7EEAC95B1483}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{85843CA1-E7B2-4F87-BB0D-D2721824A643}" = lport=137 | protocol=17 | dir=in | app=system | 
"{8745FCF9-0F9E-4167-9D3C-66E53E3A4A87}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{93A69DCE-F4F9-4090-A46B-CD7BBBA36154}" = rport=137 | protocol=17 | dir=out | app=system | 
"{972129D4-9AF5-4EB4-9593-C453437AAD9D}" = lport=27022 | protocol=6 | dir=in | name=war thunder | 
"{9CC11FEC-7B51-42F7-B6AC-9FF5889A0D25}" = lport=443 | protocol=6 | dir=in | name=war thunder | 
"{A028912B-22E2-4C8E-A176-9BD1988B28BE}" = lport=7853 | protocol=6 | dir=in | name=war thunder | 
"{A0E19AC6-16EE-496E-A9DC-A958CE4D5240}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{A6402F52-7112-4ED8-A105-65F0665DF77A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{AE8BB001-F349-4AAD-B346-9510B82DE77E}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{BEA2F6E2-2B78-4958-AC3A-4D1D0CF75D90}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C3F699DC-B2E1-4471-A705-5544EC136A32}" = lport=6881 | protocol=6 | dir=in | name=war thunder | 
"{C6F0D45E-E23F-43B4-895D-D8DA3F2ABFEB}" = rport=138 | protocol=17 | dir=out | app=system | 
"{DCC275CC-A70B-4B5C-BD72-3B42BAD197BB}" = lport=7852 | protocol=6 | dir=in | name=war thunder | 
"{E852A783-6B39-459C-B645-DC7DD5BB8F37}" = lport=49214 | protocol=6 | dir=in | name=akamai netsession interface | 
"{EABAE542-93F1-47BE-B899-4C8A9589F55A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{F19E8B61-38B9-462F-8F8F-AEF3559E7DFD}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | 
"{F5C931AE-FACF-40C1-B45D-CDC602F8DC95}" = lport=20443 | protocol=6 | dir=in | name=war thunder | 
"{F760C57A-592F-477C-9799-74009E947F61}" = lport=139 | protocol=6 | dir=in | app=system | 
"{FCA38A58-DC60-41C2-97DA-4ECA01A33C3E}" = lport=138 | protocol=17 | dir=in | app=system | 
"{FE9D6F13-00FC-47B1-BB6D-E411659B7D0B}" = lport=445 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{022A9A9B-BC03-4AC4-A7D0-69F05C5E7CCB}" = protocol=17 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{0356ED83-B2B6-44CB-B521-CE01C6575CA0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{03B0C0C2-4D23-4C70-BF5C-BE59C4BEFEB2}" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe | 
"{04B18247-0E87-472E-8987-CAF2A2AEEA24}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | 
"{062DABCC-5261-461A-B59C-7159E5A02998}" = protocol=17 | dir=in | app=c:\program files\avg\avg2014\avgmfapx.exe | 
"{06CF6DC5-6988-4E8A-A886-14D27E218DEA}" = protocol=17 | dir=in | app=c:\program files\avg\avg2014\avgemcx.exe | 
"{09199B62-5D81-4AA0-8927-7B9F3245E8F7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nmrih\sdk\hl2.exe | 
"{1870C33B-C0A0-471E-A964-48D5F51462FB}" = protocol=17 | dir=in | app=c:\program files\avg\avg2014\avgdiagex.exe | 
"{1E1DC626-F269-4C5A-8CD0-5E22E1218327}" = protocol=6 | dir=in | app=d:\program files\heroes & generals\live\hng.exe | 
"{1E4D6076-DE13-4010-A671-BE2E631BC2B9}" = protocol=17 | dir=in | app=c:\program files\avg\avg2014\avgnsx.exe | 
"{239C1961-7896-44DF-8BA4-C23BBC669E99}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{271A87A0-BF0B-4B12-AEFB-D62C0C6D795D}" = protocol=6 | dir=in | app=d:\program files\apb reloaded\binaries\vivoxvoiceservice.exe | 
"{2853CC6B-BA97-46BF-B4C5-DBED68C46469}" = protocol=17 | dir=in | app=c:\program files\nero\km\nmdllhost.exe | 
"{296D150F-E809-4269-9FD8-AD30CC4DB780}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{2B376AF5-9BEA-4B4F-A7BE-851F37E72BCE}" = protocol=17 | dir=in | app=d:\program files\apb reloaded\binaries\apb.exe | 
"{314C47B7-069C-4471-A2B7-DF07EE65351C}" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe | 
"{33565A8C-8E12-4D3F-8EF9-DD2566069068}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{36A0A2A5-4405-442E-8AD8-417BDB0BCFE6}" = protocol=17 | dir=in | app=d:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe | 
"{375999EA-856B-44E3-AB40-578958EA4DD1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{37E67796-9F3F-4F7C-9F9C-CCDEB2918A6B}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{383E400C-A62F-4B47-A234-3C851CF7F00E}" = protocol=6 | dir=in | app=c:\program files\nero\nero blu-ray player\blu-rayplayer.exe | 
"{3A53AA09-C19B-43E4-9754-AA400238B890}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{3CB64C2E-A893-4AB6-AA94-1396509204F1}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | 
"{3D4D2FE2-62C2-454F-8BB0-6EAD70477F94}" = protocol=6 | dir=in | app=d:\program files\steam\steam.exe | 
"{3DF871C7-196C-44A0-AB99-23BDD708E7B1}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\team fortress 2\hl2.exe | 
"{3FF4AB22-0C17-446C-B638-7ADFF18FBA6D}" = protocol=17 | dir=in | app=c:\program files\nero\nero blu-ray player\blu-rayplayer.exe | 
"{41EE8052-A25A-4CDD-B06F-8A3E3009E527}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{4224DF4A-C667-49CA-BDB6-50A50A9363A3}" = protocol=6 | dir=in | app=d:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe | 
"{4439DAF3-219E-4136-9D7D-8DBBBD52E525}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{4465E630-E513-486A-A0CC-98465221442E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{48C9F9A9-F011-4838-B621-09CF8B7BCF65}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{4A5AD8B0-30FA-47BB-BB08-537F7DF578D4}" = protocol=17 | dir=in | app=d:\program files\gsc world publishing\s.t.a.l.k.e.r. - zew prypeci\bin\xrengine.exe | 
"{4D52B79E-F580-47F1-892E-5E8F12AC2144}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | 
"{565B46A2-D247-41EE-AE14-0A3242903005}" = protocol=17 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{576970DD-87B5-4D93-98CC-70A0D7D87644}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{5D04C888-5F98-4924-AD56-D8C9A7D872A9}" = dir=in | app=d:\program files\infestation survivor stories\infestation.exe | 
"{6181883C-E9B0-4021-A02E-D3F7CB8139C0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nmrih\sdk\hl2.exe | 
"{627FB009-BA3D-4AC5-ADDC-B873A34BBC17}" = protocol=17 | dir=in | app=d:\program files\steam\steamapps\common\unturned\unturned.exe | 
"{62F4EDEA-2125-491C-9B85-710814F63479}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{65A6ED6E-EB8C-46E8-A9DA-31EA1E82D819}" = protocol=6 | dir=in | app=c:\program files\avg\avg2014\avgdiagex.exe | 
"{692B1099-438E-4DAC-ABC5-7F436CAEF46D}" = protocol=17 | dir=in | app=d:\program files\steam\steam.exe | 
"{6AED9C0A-615F-4EEF-AFA6-7360397A04C1}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | 
"{6EC15343-E88D-45DF-8A5E-9DFA061E6FC5}" = protocol=17 | dir=in | app=c:\program files\gameforgelive\games\pol_pol\s.k.i.l.l\binaries\win32\sf2.exe | 
"{6F9C8C2A-BD2B-4460-B481-6EFEE8A03740}" = protocol=17 | dir=in | app=d:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe | 
"{75B16F5E-A19B-444A-A1AE-BB9DE1199560}" = protocol=6 | dir=in | app=d:\program files\gsc world publishing\s.t.a.l.k.e.r. - zew prypeci\bin\xrengine.exe | 
"{7BEC8480-DA4E-47B1-A224-9012FE9A52DD}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{82CBA959-CAED-4FF1-A1FD-C9C42DE93017}" = protocol=6 | dir=in | app=c:\program files\nero\km\nmdllhost.exe | 
"{8C310045-EF8C-494B-8A3E-D05416E8637F}" = protocol=6 | dir=in | app=c:\program files\avg\avg2014\avgmfapx.exe | 
"{8E338AE5-19CB-47EB-B712-F764690E4A50}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{8EF71851-9370-4F32-B658-941195DA06AD}" = protocol=6 | dir=in | app=c:\program files\vso\vso downloader\3\vsodownloader.exe | 
"{8F4F2755-294A-458A-87E6-9C1FFD684BF2}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{9148EA68-FD13-4395-8603-5E21CCB35A25}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{98B46E39-AED4-432A-AD86-1CC25B88A1EF}" = protocol=17 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{9B346999-7635-46F2-8FF5-6AFADBF586AF}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{9FA8FC25-3A29-4868-88E3-C30723CBE7AB}" = protocol=6 | dir=out | app=system | 
"{A08A8948-5B8B-433C-A7C6-31B0C1D9D5D9}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{A3D4024D-E6B6-4D45-AE58-CE4D53C911AE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{A73B8322-9990-4B25-B095-CBFC5FBC7AF9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{A746F581-88E4-4FC2-9798-1975F66E5280}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | 
"{AAC7BAD7-2E9E-4D27-A545-1F7A829859FB}" = protocol=6 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | 
"{AE6D503E-FD7D-427A-A422-69CADD2B0B9A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\team fortress 2\hl2.exe | 
"{B355BB49-75E0-4513-B0CA-07A214E66B59}" = protocol=6 | dir=in | app=d:\program files\steam\steamapps\common\unturned\unturned.exe | 
"{B4F2289A-30B6-406F-AA62-5519E46D1976}" = protocol=17 | dir=in | app=d:\program files\gsc world publishing\s.t.a.l.k.e.r. - zew prypeci\bin\dedicated\xrengine.exe | 
"{B5463D83-D322-4C11-AA7B-1967923D357D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{B7F51ED3-F6EF-4291-96D9-408B983ED202}" = protocol=6 | dir=in | app=d:\program files\apb reloaded\binaries\apb.exe | 
"{BA6FF5BC-FA0B-4633-8586-166E3080D724}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | 
"{BF7A733F-9ACE-44A0-9564-FD85CDA925A5}" = protocol=17 | dir=in | app=d:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | 
"{C07F8E04-B32C-4A1D-AB17-D48A9BEE1BC1}" = protocol=17 | dir=in | app=d:\program files\apb reloaded\binaries\vivoxvoiceservice.exe | 
"{C0FA177C-4F8C-4207-9626-9F003245205D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C3BE077A-1E7E-40C3-91A6-DB4B75F63726}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | 
"{CE5C84DE-8947-470A-9B92-2B18478DC489}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | 
"{D05428ED-D633-4CFB-AA35-842C8F4C39BB}" = protocol=6 | dir=in | app=c:\program files\avg\avg2014\avgnsx.exe | 
"{D0882C1B-8D9F-4013-82C6-229454AE7E41}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{D0A612C3-1322-406B-B187-08EC3B9355F5}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{D331BEFD-DD03-4984-8021-9ED5C1FFA9B5}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{D42B2318-1E2A-4151-B88E-76ED5965904B}" = protocol=6 | dir=in | app=c:\program files\gameforgelive\games\pol_pol\s.k.i.l.l\binaries\win32\sf2.exe | 
"{D859BFB2-F066-441B-A44B-029E220363ED}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{D9620A7B-9A63-410E-B57C-C36D33F2C221}" = protocol=6 | dir=in | app=d:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe | 
"{DEBB3861-AEB6-4461-902E-41934E8903D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{DFD2927B-6BAA-4760-AEC2-9DE4F63770BA}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{E10FCF40-C9EE-4A1A-8951-62702AA66623}" = protocol=17 | dir=in | app=d:\program files\heroes & generals\live\hng.exe | 
"{E221BA50-19A8-4896-A9D5-A33735962892}" = protocol=17 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{E2342B5D-1593-4EC2-81E5-4CD0D2C55909}" = protocol=6 | dir=in | app=d:\program files\gsc world publishing\s.t.a.l.k.e.r. - zew prypeci\bin\dedicated\xrengine.exe | 
"{E3466670-D79B-4FBA-BA0C-E31C6A677792}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr_im.exe | 
"{E45491E8-C050-47E1-8575-B08A9DB89233}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | 
"{E7A119F1-AE4A-415F-921D-43C4B865B0B8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{EF7CCF39-5717-4406-A4A2-D7021B551240}" = protocol=6 | dir=in | app=c:\program files\avg\avg2014\avgemcx.exe | 
"{F0482CFA-B607-487B-83D3-09B1A2364FE5}" = protocol=6 | dir=in | app=c:\program files\raptr\raptr.exe | 
"{F20AC959-8430-4A09-9DE2-4F9850A78B32}" = protocol=6 | dir=in | app=c:\users\ppp\appdata\roaming\utorrent\utorrent.exe | 
"{F6851FE8-D91F-4322-94BD-48C72F0D84F7}" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe | 
"{F70964DF-7ECB-47B9-A3C6-3C12C34F5D2F}" = protocol=17 | dir=in | app=c:\program files\vso\vso downloader\3\vsodownloader.exe | 
"{FDB873E4-623F-4AEA-BC20-AFE0F50986A8}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | 
"{FFF712F7-C2DE-43AF-B8AB-97F7FD0337E0}" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe | 
"TCP Query User{032BCBA5-4126-47B2-8A8B-E7C8E8C799DE}C:\users\ppp\desktop\gry\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\gry\pandoramt2\pandoramt2(bez_patchera).exe | 
"TCP Query User{051F52C5-7417-4368-BA70-A5C0180FA99C}C:\users\ppp\desktop\pandoramt2\metin2mod_2011sf.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2mod_2011sf.exe | 
"TCP Query User{0A858BCC-ED47-43F0-B336-ECA03A19D323}D:\program files\metin2 ravia.eu\game" = protocol=6 | dir=in | app=d:\program files\metin2 ravia.eu\game | 
"TCP Query User{14567FF0-A444-4795-AF5D-63A767A06E50}C:\users\ppp\desktop\teamspeak3-server_win32\ts3server_win32.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\teamspeak3-server_win32\ts3server_win32.exe | 
"TCP Query User{178DF97E-E864-4607-A66E-B742FDEC75CD}C:\users\ppp\desktop\pandoramt2\metin2mod_2012sf.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2mod_2012sf.exe | 
"TCP Query User{18E83029-DF9E-4E1E-9231-4C68A9D5895D}C:\users\ppp\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\ppp\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{2D0D1AAF-8B8E-4912-8214-93E57FE57050}C:\users\ppp\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\ppp\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{2DF9C4D2-7CDC-4EC7-B7B7-460E7D1DF79D}C:\program files\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield play4free\bfp4f.exe | 
"TCP Query User{3CEE624C-FEBA-4792-B82E-1D6A10991C7D}C:\users\ppp\desktop\gry\mortyriusz.pl\dzikie_psy.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\dzikie_psy.exe | 
"TCP Query User{46A6E828-E91B-4AE7-9A75-627FA0375DF3}C:\users\ppp\desktop\gry\mortyriusz.pl\zielone_miasta.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\zielone_miasta.exe | 
"TCP Query User{4C3DF501-230E-49BF-8298-5DF7AD7D66AB}D:\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=6 | dir=in | app=d:\pandoramt2\pandoramt2(bez_patchera).exe | 
"TCP Query User{4D635BCA-8B05-4765-99DB-C5773A41C393}D:\killing floor pc full game multiplayer + sp v_1.0.3.9 ^^nosteam^^\killingfloor\system\killingfloor.exe" = protocol=6 | dir=in | app=d:\killing floor pc full game multiplayer + sp v_1.0.3.9 ^^nosteam^^\killingfloor\system\killingfloor.exe | 
"TCP Query User{509851D3-B530-46A2-8C24-245B8F417AD3}D:\program files\perfect world entertainment\neverwinter_en\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=d:\program files\perfect world entertainment\neverwinter_en\neverwinter\live\gameclient.exe | 
"TCP Query User{5BA6F21E-1B24-4BF0-A0C0-A505B5CF61AB}C:\users\ppp\desktop\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\pandoramt2\pandoramt2(bez_patchera).exe | 
"TCP Query User{5D6A1F8E-7126-4508-AB5D-1CE7BE79E1F0}C:\program files\killingfloor\system\killingfloor.exe" = protocol=6 | dir=in | app=c:\program files\killingfloor\system\killingfloor.exe | 
"TCP Query User{5F39B234-BF03-425B-A910-6F7D01ED1B90}C:\users\ppp\desktop\gry\alien2\alien2.pl.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\gry\alien2\alien2.pl.exe | 
"TCP Query User{62F18694-4FE7-42AC-BCF3-FE0A06248CB4}C:\users\ppp\desktop\pandoramt2\metin2.bin" = protocol=6 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2.bin | 
"TCP Query User{6462D06A-F22A-4333-A411-FACC04B8609B}D:\program files\valve\hl.exe" = protocol=6 | dir=in | app=d:\program files\valve\hl.exe | 
"TCP Query User{A33F979B-F7CF-4353-8245-6D90A4E06577}D:\left4dead\left4dead.exe" = protocol=6 | dir=in | app=d:\left4dead\left4dead.exe | 
"TCP Query User{C2BD9918-49C9-4E5E-AD27-367682B1310D}D:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=d:\programdata\electronic arts\need for speed world\data\nfsw.exe | 
"TCP Query User{D463698D-AE48-4D1D-8767-674739805645}C:\users\ppp\desktop\antyda.pl\antyda.pl.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\antyda.pl\antyda.pl.exe | 
"TCP Query User{D4B2583C-83B6-476F-A4B2-98308F8EBF2A}C:\users\ppp\appdata\local\radiosure\radiosure.exe" = protocol=6 | dir=in | app=c:\users\ppp\appdata\local\radiosure\radiosure.exe | 
"TCP Query User{D5004643-FEEC-449C-A883-0F4E6CFAD916}D:\pandoramt2\metin2mod_2011sf.exe" = protocol=6 | dir=in | app=d:\pandoramt2\metin2mod_2011sf.exe | 
"TCP Query User{D9F1861B-8C91-491B-B23B-2AF5C9C6DAA9}C:\users\ppp\desktop\gry\mortyriusz.pl\_mortyriusz.pl.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\_mortyriusz.pl.exe | 
"TCP Query User{E75A911A-71BF-43F7-AE60-0841C32731C2}D:\pandoramt2\metin2mod_2012sf.exe" = protocol=6 | dir=in | app=d:\pandoramt2\metin2mod_2012sf.exe | 
"TCP Query User{E9EC2732-848A-4E75-889B-A7288A71355F}C:\program files\ubisoft\xiii\system\xiii.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\xiii\system\xiii.exe | 
"TCP Query User{EBF5428B-9A27-4FF2-999C-182B2E1D5869}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"TCP Query User{F0C805E5-9EF1-4535-8FFE-DE9BF67110EC}D:\pandoramt2\metin2.bin" = protocol=6 | dir=in | app=d:\pandoramt2\metin2.bin | 
"TCP Query User{F1FDAB31-36EE-4E97-80DE-C6ECE5EFCE6F}C:\users\ppp\desktop\pandoramt2\metin2client.exe" = protocol=6 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2client.exe | 
"TCP Query User{F8533193-FDC1-4C8A-A7E6-09C40369E03A}D:\program files\rockstar games\gta san andreas\proxy_sa.exe" = protocol=6 | dir=in | app=d:\program files\rockstar games\gta san andreas\proxy_sa.exe | 
"TCP Query User{FB0D2A41-F74A-4E40-A718-7DCE55E08671}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe | 
"UDP Query User{17F78BB6-85CE-45E6-9D3F-9BA9211231C9}C:\program files\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield play4free\bfp4f.exe | 
"UDP Query User{1A225CB3-21D7-4C2F-A6ED-6A4A16000689}C:\users\ppp\desktop\gry\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\gry\pandoramt2\pandoramt2(bez_patchera).exe | 
"UDP Query User{299E8814-B3DE-40B7-9CCD-B11FEA3E121A}C:\users\ppp\desktop\pandoramt2\metin2mod_2011sf.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2mod_2011sf.exe | 
"UDP Query User{2E0567E9-AA5C-48B7-B1AB-59E3CED87F3A}D:\program files\perfect world entertainment\neverwinter_en\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=d:\program files\perfect world entertainment\neverwinter_en\neverwinter\live\gameclient.exe | 
"UDP Query User{3C1956CE-6EA0-454A-BC7C-C3FCC730FF8D}D:\pandoramt2\metin2mod_2011sf.exe" = protocol=17 | dir=in | app=d:\pandoramt2\metin2mod_2011sf.exe | 
"UDP Query User{4A27CB81-0EE1-4EDB-BE27-0424C6A82104}C:\users\ppp\desktop\gry\mortyriusz.pl\zielone_miasta.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\zielone_miasta.exe | 
"UDP Query User{4D58181C-15DD-4A83-A2C7-CEA3FCD1A045}D:\pandoramt2\metin2.bin" = protocol=17 | dir=in | app=d:\pandoramt2\metin2.bin | 
"UDP Query User{50DB5504-A207-4813-BF2F-6E18D5FBDBCB}C:\users\ppp\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\ppp\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{5B983A70-61D3-4F2A-A936-AA3E0FA21BE5}D:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=d:\programdata\electronic arts\need for speed world\data\nfsw.exe | 
"UDP Query User{5F0D235E-5ABF-405D-BB62-C6BA5F9EBC8A}C:\users\ppp\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\ppp\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{5F636E3E-5FF3-405E-A4F2-123504D3681B}C:\users\ppp\desktop\gry\mortyriusz.pl\dzikie_psy.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\dzikie_psy.exe | 
"UDP Query User{5FCA6610-1BBD-4604-A401-E8AAB5A1001F}C:\users\ppp\desktop\gry\alien2\alien2.pl.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\gry\alien2\alien2.pl.exe | 
"UDP Query User{7500BD88-CA00-4BF4-A9FB-5AB6AB42E00B}D:\pandoramt2\metin2mod_2012sf.exe" = protocol=17 | dir=in | app=d:\pandoramt2\metin2mod_2012sf.exe | 
"UDP Query User{7B9F7B79-2EF4-474B-847A-1B058B415282}C:\users\ppp\desktop\teamspeak3-server_win32\ts3server_win32.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\teamspeak3-server_win32\ts3server_win32.exe | 
"UDP Query User{7E2A33E0-F105-4E03-8ED9-F4CF574632C2}C:\users\ppp\desktop\pandoramt2\metin2client.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2client.exe | 
"UDP Query User{8085AAAA-38C8-4EE2-BC5C-CFEB4E5AA40C}C:\program files\killingfloor\system\killingfloor.exe" = protocol=17 | dir=in | app=c:\program files\killingfloor\system\killingfloor.exe | 
"UDP Query User{90CA2108-8794-430B-924D-CD314B1CCF97}D:\killing floor pc full game multiplayer + sp v_1.0.3.9 ^^nosteam^^\killingfloor\system\killingfloor.exe" = protocol=17 | dir=in | app=d:\killing floor pc full game multiplayer + sp v_1.0.3.9 ^^nosteam^^\killingfloor\system\killingfloor.exe | 
"UDP Query User{90CAD369-32C6-46DF-B608-E04FBFECCDC7}D:\program files\rockstar games\gta san andreas\proxy_sa.exe" = protocol=17 | dir=in | app=d:\program files\rockstar games\gta san andreas\proxy_sa.exe | 
"UDP Query User{95C31E45-64BD-4BAB-8DB0-2F180E23DAE7}C:\users\ppp\desktop\pandoramt2\metin2.bin" = protocol=17 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2.bin | 
"UDP Query User{A32D24DC-68A8-4E42-9313-2C462FAAC183}C:\users\ppp\desktop\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\pandoramt2\pandoramt2(bez_patchera).exe | 
"UDP Query User{A368ACEE-61D6-466B-A7AE-CFCAA6853DBB}C:\program files\ubisoft\xiii\system\xiii.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\xiii\system\xiii.exe | 
"UDP Query User{B64F1A37-6785-4D95-9595-ABC42F0C7931}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe | 
"UDP Query User{B8240AEB-C88A-4E11-A2BF-0F69D4E1AC5D}D:\left4dead\left4dead.exe" = protocol=17 | dir=in | app=d:\left4dead\left4dead.exe | 
"UDP Query User{C2ECDF6B-34EA-4A52-84B1-71333E28D5ED}C:\users\ppp\desktop\antyda.pl\antyda.pl.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\antyda.pl\antyda.pl.exe | 
"UDP Query User{D7BB6554-4EAD-4070-992B-80D66D7D174C}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"UDP Query User{E2D3B8A2-19B7-4DFD-A949-3827C8E8C537}C:\users\ppp\appdata\local\radiosure\radiosure.exe" = protocol=17 | dir=in | app=c:\users\ppp\appdata\local\radiosure\radiosure.exe | 
"UDP Query User{EDF831B4-5EA6-43A8-A836-AED3E4D73466}D:\program files\metin2 ravia.eu\game" = protocol=17 | dir=in | app=d:\program files\metin2 ravia.eu\game | 
"UDP Query User{EE6DF4AB-3DE2-4064-8593-5753C21C0D54}C:\users\ppp\desktop\gry\mortyriusz.pl\_mortyriusz.pl.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\gry\mortyriusz.pl\_mortyriusz.pl.exe | 
"UDP Query User{EFBB6568-ED36-424E-A13E-C7DEDE6DA553}C:\users\ppp\desktop\pandoramt2\metin2mod_2012sf.exe" = protocol=17 | dir=in | app=c:\users\ppp\desktop\pandoramt2\metin2mod_2012sf.exe | 
"UDP Query User{F769524F-FE6B-4611-A12B-E2E469FC219B}D:\pandoramt2\pandoramt2(bez_patchera).exe" = protocol=17 | dir=in | app=d:\pandoramt2\pandoramt2(bez_patchera).exe | 
"UDP Query User{FC332656-2ECA-4AD8-8B7E-7BE25C1EEECE}D:\program files\valve\hl.exe" = protocol=17 | dir=in | app=d:\program files\valve\hl.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F14E5B-E07A-2A1E-6788-580773CE1486}" = CCC Help English
"{0A036215-0A8D-6FBE-7EA3-7AED4F9E162A}" = CCC Help Turkish
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{15A05AAA-37E7-D516-5BE9-C960C2170403}" = CCC Help Czech
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A4E47DC-6701-4A85-AA16-C1F99A44598C}" = Spellforce 2 - Czas Mrocznych Wojen
"{21E9850E-58C2-FA88-D5AD-B64D253B8F82}" = CCC Help Thai
"{25A7270E-1B63-DFD1-ACBC-88852A305398}" = CCC Help Chinese Traditional
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 55
"{28164BD8-81EA-639A-85E9-E659E3EE6DA7}" = Catalyst Control Center InstallProxy
"{2E69E784-F84A-9A18-7D8E-4EB8504EEE1E}" = CCC Help Danish
"{362614E4-9ABB-E7A7-CDDC-239AB168060A}" = CCC Help Japanese
"{3DF7D356-6225-8717-AFC2-91D5C1521036}" = AMD Media Foundation Decoders
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Zew Prypeci [v1.6.01]
"{4745F6F8-09DA-CC39-EC19-0E8D764CF2B7}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FA31DE2-B613-24BB-1738-B655C00B1C9D}" = CCC Help Hungarian
"{58771CF6-F212-CC4D-61B1-45CC70B6375C}" = CCC Help Dutch
"{5DE67937-45D5-45E4-923C-0B7F7EC929A7}" = League of Legends
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{6D5CE5F1-CBB0-9ED4-1A1E-91DDCD6225FD}" = CCC Help Italian
"{707210B0-29F1-C550-BA96-6ECDA245CF24}" = CCC Help Spanish
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7F644A4B-C9A7-E419-BFD9-75DFA0EE57DB}" = AMD Accelerated Video Transcoding
"{812B956B-37AB-24B9-4527-78A6D3ECE7F8}" = CCC Help Korean
"{83293709-B863-0EF6-00DA-B026D486E8B5}" = CCC Help Polish
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{88B2ABCF-9C00-47C1-8FC4-369B98845DD7}" = Catalyst Control Center - Branding
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D5B19AA-3D3A-5870-C9A0-346EBC5DB21E}" = ccc-utility
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{911904DE-EBB6-BC8E-D5BD-762B7DB42C46}" = CCC Help Greek
"{912A2205-1E54-3CE5-A1EB-997B64A0B539}" = Microsoft .NET Framework 4.5 PLK Language Pack
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Polski pakiet językowy dla programu Microsoft .NET Framework 4.5 PLK
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9903011B-5F1D-A2A1-8078-EE62B3324CCE}" = CCC Help Portuguese
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A7F1628-2126-34A5-852D-2B93328BCF3F}" = CCC Help German
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F612429-4A00-3D44-88CF-146DA2EE1F92}" = Microsoft .NET Framework 4.5
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A8F37EB0-C741-41D7-8CAB-5B40ECEEF094}_is1" = CLEO 4.3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1045-7B44-AA1000000001}" = Adobe Reader X (10.1.10) - Polish
"{ACEF85BD-2489-BE0E-9965-CE2F661260AA}" = AMD Fuel
"{AE6C422B-DADB-D547-411C-E9E56DF03D16}" = CCC Help Russian
"{B09567CC-E43F-10F1-752D-549AC7FB0C43}" = CCC Help Finnish
"{B170B91D-E8E3-A6A3-D129-D8E36FEA8A0B}" = CCC Help Norwegian
"{B26B07BA-A768-4420-844E-771E05F0D965}" = AVG 2014
"{B448BC74-1CB7-7A57-3313-5E075AFB413E}" = AMD Catalyst Install Manager
"{B78FB576-8BB4-4799-B612-A02B74BA0DF0}" = AVG 2014
"{BD96ABD3-D1D4-5513-6C60-11476D6DCFC5}" = Catalyst Control Center Localization All
"{BDA0EB29-8B31-4BF4-8B05-04AA52340AC4}" = LogMeIn Hamachi
"{C330C4F4-FD7C-4821-A210-F8058E1FB81C}" = AVG 2014
"{C39C7876-4D21-8A38-0A42-B5C8858EC6C7}" = CCC Help French
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D4236B82-213F-679E-09A2-9AEB5EF4CADC}" = Catalyst Control Center Graphics Previews Common
"{DBA18992-B9F3-950D-E973-6ED23422EA73}" = AMD Drag and Drop Transcoding
"{E0F07676-2C60-4465-A727-20DE3BFCABAC}" = Tony Hawks Pro Skater 4
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{EBBD4FE6-91DA-C397-6D56-FE85DBF24FCF}" = AMD VISION Engine Control Center
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FCEFDA6B-63CD-BB17-B845-478A42E24D39}" = CCC Help Swedish
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 14 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"AVG" = AVG 2014
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"DAEMON Tools Lite" = DAEMON Tools Lite
"fst_pl_96_is1" = fst_pl_96
"GameSpy Arcade" = GameSpy Arcade
"Google Chrome" = Google Chrome
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.9.0 (Full)
"League of Legends 3.0.1" = League of Legends
"LogMeIn Hamachi" = LogMeIn Hamachi
"Mozilla Firefox 30.0 (x86 pl)" = Mozilla Firefox 30.0 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MTA:SA 1.3" = MTA:SA v1.3.4
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"Opera 23.0.1522.60" = Opera Stable 23.0.1522.60
"Origin" = Origin
"Picasa 3" = Picasa 3
"Postal 2" = Postal 2
"Postal 2 Apocalypse Weekend Expansion Pack" = Postal 2 Apocalypse Weekend Expansion Pack
"Raptr" = Raptr
"Ravia.eu" = Ravia.eu
"S.T.A.L.K.E.R. - Shadow of Chernobyl_is1" = S.T.A.L.K.E.R. - Shadow of Chernobyl
"Sanny Builder 3_is1" = Sanny Builder 3.2.1
"screenSHU" = screenSHU - the fastest screen capture ever.
"SearchProtect" = Search Protect
"ShopperPro" = Shopper-Pro
"Steam" = Steam
"Steam App 304930" = Unturned
"Steam App 440" = Team Fortress 2
"sweet-page uninstaller" = sweet-page uninstaller
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Totalcmd" = Total Commander (Remove or Repair)
"Warrock EU" = WarRock
"webget" = webget
"WinRAR archiver" = WinRAR 5.00 (32-bitowy)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"RadioSure" = RadioSure
"uTorrent" = µTorrent
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 2014-07-27 03:54:49 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
Error - 2014-07-27 05:08:11 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
Error - 2014-07-27 16:32:56 | Computer Name = Zachary | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: gta_sa.exe, wersja: 0.0.0.0, sygnatura
 czasowa: 0x427101ca  Nazwa modułu powodującego błąd: samp.dll_unloaded, wersja: 0.0.0.0,
 sygnatura czasowa: 0x52fc75eb  Kod wyjątku: 0xc0000005  Przesunięcie błędu: 0x0410643d
Identyfikator
 procesu powodującego błąd: 0x10e8  Godzina uruchomienia aplikacji powodującej błąd:
 0x01cfa9d9e8e92e49  Ścieżka aplikacji powodującej błąd: D:\Program Files\Rockstar
 Games\GTA San Andreas\gta_sa.exe  Ścieżka modułu powodującego błąd: samp.dll  Identyfikator
 raportu: 306fbfa6-15cd-11e4-8977-001731f64bf4
 
Error - 2014-07-28 03:18:04 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
Error - 2014-07-29 01:59:27 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
Error - 2014-07-29 06:54:17 | Computer Name = Zachary | Source = MsiInstaller | ID = 11309
Description = 
 
Error - 2014-07-29 07:05:03 | Computer Name = Zachary | Source = MsiInstaller | ID = 11309
Description = 
 
Error - 2014-07-29 07:24:47 | Computer Name = Zachary | Source = MsiInstaller | ID = 11309
Description = 
 
Error - 2014-07-29 10:22:29 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
Error - 2014-07-29 12:50:30 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 2014-07-03 03:19:09 | Computer Name = Zachary | Source = Application Popup | ID = 875
Description = Sterownik atksgt.sys został zablokowany dla ładowania.
 
Error - 2014-07-03 03:19:09 | Computer Name = Zachary | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi atksgt z powodu następującego błędu:   %%1275
 
Error - 2014-07-03 03:20:30 | Computer Name = Zachary | Source = Service Control Manager | ID = 7026
Description = Nie można załadować następujących sterowników startu rozruchowego 
lub systemowego:   sfdrv01  sfsync02
 
Error - 2014-07-03 03:29:58 | Computer Name = Zachary | Source = Service Control Manager | ID = 7034
Description = Usługa Nero Update niespodziewanie zakończyła pracę. Wystąpiło to 
razy: 1.
 
Error - 2014-07-03 03:30:23 | Computer Name = Zachary | Source = Service Control Manager | ID = 7034
Description = Usługa PnkBstrA niespodziewanie zakończyła pracę. Wystąpiło to razy:
 1.
 
Error - 2014-07-03 03:30:32 | Computer Name = Zachary | Source = Service Control Manager | ID = 7034
Description = Usługa vToolbarUpdater18.1.7 niespodziewanie zakończyła pracę. Wystąpiło
 to razy: 1.
 
Error - 2014-07-04 05:55:20 | Computer Name = Zachary | Source = Application Popup | ID = 875
Description = Sterownik sfsync02.sys został zablokowany dla ładowania.
 
Error - 2014-07-04 05:55:22 | Computer Name = Zachary | Source = Application Popup | ID = 875
Description = Sterownik sfdrv01.sys został zablokowany dla ładowania.
 
Error - 2014-07-04 05:56:33 | Computer Name = Zachary | Source = Application Popup | ID = 875
Description = Sterownik atksgt.sys został zablokowany dla ładowania.
 
Error - 2014-07-04 05:56:33 | Computer Name = Zachary | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi atksgt z powodu następującego błędu:   %%1275

 
 
< End of report 
 
Zaraz dodam inne.
Odnośnik do komentarza

Picasso już od 10 miesięcy jest chora, i na razie nie zanosi się na Jej powrót.

 

Niestety, w tym dziale nie ma zapasowego Moderatora, więc pomoc prawie nie istnieje.

 

1) Odinstaluj:

"AVG SafeGuard toolbar" = AVG SafeGuard toolbar

"fst_pl_96_is1" = fst_pl_96

"SearchProtect" = Search Protect
"ShopperPro" = Shopper-Pro

"sweet-page uninstaller" = sweet-page uninstaller

"webget" = webget

Akamai NetSession Interface

 

2) Użyj >Adw-cleaner
najpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.
Pokaż raport z niego C:\AdwCleaner\AdwCleaner.txt

 

3) Użyj  > MBAM
Zaznacz wszystko co wykryje, kliknij na Usuń zaznaczone.
Podaj z tego raport.

 

4) Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:

 

:OTL
DMOD - [2014-06-09 16:48:15 | 002,567,192 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\vprot.exe
MOD - [2014-06-09 16:48:15 | 000,519,704 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll
MOD - [2014-03-20 23:06:14 | 001,603,608 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\TBAPI.dll
RV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe -- (McComponentHostService)
SRV - [2014-07-29 13:24:05 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdatem)
SRV - [2014-07-29 13:24:05 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdate)
SRV - [2014-07-22 09:47:56 | 001,812,992 | ---- | M] (ShopperPro) [Auto | Running] -- C:\Program Files\Common Files\ShopperPro\spbiu.exe -- (SPBIUpd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva409.sys -- (XDva409)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\vtany.sys -- (vtany)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys -- (FairplayKD)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (amne3upc)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (a7eehfst)
DRV - [2014-07-22 09:53:12 | 000,041,320 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.sys -- (SPDRIVER_1.37.0.202)
DRV - [2014-07-22 09:47:10 | 000,025,600 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\ShopperPro\spbiw.sys -- (SPBIUpdd)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll File not found
O2 - BHO: (Apps Hat) - {11111111-1111-1111-1111-110411851159} - C:\Program Files\Apps Hat\Apps Hat-bho.dll (Nero)
O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O2 - BHO: (Shopper Pro) - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O4 - HKLM..\Run: [sPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\ppp\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [AVG-Secure-Search-Update_0214c] C:\Users\ppp\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=93a8d8e39d8147d2ba17d15e7712a207-280eebffd4b62125f56ac22c8758693e69e718be /CMPID=0214c File not found
O4 - HKCU..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found
O4 - HKCU..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" File not found
O4 - HKCU..\Run: [sPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe ()
O4 - HKCU..\Run: [Tiny download manager] "C:\Users\ppp\AppData\Local\DM\TinyDM.exe" /M File not found
O4 - Startup: C:\Users\ppp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FIFA 10 Registration.lnk =  File not found
O20 - AppInit_DLLs: (c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll) - c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (Conduit)
[2014-07-29 12:53:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\YTAHelper
[2014-07-29 12:53:50 | 000,000,000 | ---D | C] -- C:\Users\ppp\AppData\Local\globalUpdate
[2014-07-29 12:53:50 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate
[2014-07-29 12:53:45 | 000,000,000 | ---D | C] -- C:\Program Files\Apps Hat
[2014-07-29 12:52:39 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\GOOBZO
[2014-07-29 12:52:35 | 000,000,000 | ---D | C] -- C:\ProgramData\ShopperPro
[2014-07-29 12:52:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
[2014-07-29 12:52:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ShopperPro
[2014-07-29 12:52:17 | 000,000,000 | ---D | C] -- C:\Program Files\ShopperPro
[2014-07-29 18:55:05 | 000,001,434 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-5_user.job
[2014-07-29 18:54:20 | 000,002,560 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-4.job
[2014-07-29 18:54:19 | 000,001,418 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-5.job
[2014-07-29 18:54:16 | 000,001,532 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-6.job
[2014-07-29 18:54:12 | 000,001,320 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-2.job
[2014-07-29 18:54:11 | 000,001,530 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-1.job
[2014-07-29 18:53:22 | 000,003,778 | ---- | M] () -- C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-11.job
[2014-07-29 18:51:22 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-07-29 18:51:11 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-07-29 13:29:25 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]

:Commands
[emptytemp]

Kliknij w Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom OTL ponownie, tym razem kliknij Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.

 

 

 

==================================================================================

Error - 2014-07-29 12:50:30 | Computer Name = Zachary | Source = WinMgmt | ID = 10
Description =

Aby automatycznie rozwiązać ten problem, kliknij > Fix.it. na stronie http://go.microsoft.com/?linkid=9775756
Następnie kliknij przycisk Uruchom w oknie dialogowym Pobieranie pliku i wykonaj kroki w kreatorze Fix.it.
(Link zapasowy > http://www.mediafire.com/download/6hwcm6b77098cbb/MicrosoftFixit50688.msi )

 

jessi

Odnośnik do komentarza

Powiem tak, widzę znaczną poprawę szybkości mojej przeglądarki, już się tak nie wlecze a idzie szybciej, poniżej podaje logi. Tutaj jeszcze przedstawię to co mi wyskoczyło po restarcie kompa ((daje tak bo pisze że mam uprawnień do wysyłanie takich plików))

 

 

All processes killed

========== OTL ==========
Error: No service named globalUpdatem was found to stop!
Service\Driver key globalUpdatem not found.
File C:\Program Files\globalUpdate\Update\GoogleUpdate.exe not found.
Error: No service named globalUpdate was found to stop!
Service\Driver key globalUpdate not found.
File C:\Program Files\globalUpdate\Update\GoogleUpdate.exe not found.
Error: No service named SPBIUpd was found to stop!
Service\Driver key SPBIUpd not found.
File C:\Program Files\Common Files\ShopperPro\spbiu.exe not found.
Service xhunter1 stopped successfully!
Service xhunter1 deleted successfully!
File C:\Windows\xhunter1.sys not found.
Service XDva409 stopped successfully!
Service XDva409 deleted successfully!
File C:\Windows\system32\XDva409.sys not found.
Service vtany stopped successfully!
Service vtany deleted successfully!
File C:\Windows\vtany.sys not found.
Service VGPU stopped successfully!
Service VGPU deleted successfully!
File System32\drivers\rdvgkmd.sys not found.
Service FairplayKD stopped successfully!
Service FairplayKD deleted successfully!
File C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys not found.
Service EagleXNt stopped successfully!
Service EagleXNt deleted successfully!
File C:\Windows\system32\drivers\EagleXNt.sys not found.
Error: No service named amne3upc was found to stop!
Service\Driver key amne3upc not found.
Error: No service named a7eehfst was found to stop!
Service\Driver key a7eehfst not found.
Service SPDRIVER_1.37.0.202 stopped successfully!
Service SPDRIVER_1.37.0.202 deleted successfully!
File C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.sys not found.
Error: No service named SPBIUpdd was found to stop!
Service\Driver key SPBIUpdd not found.
File C:\Program Files\Common Files\ShopperPro\spbiw.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411851159}\ not found.
File C:\Program Files\Apps Hat\Apps Hat-bho.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\ not found.
File C:\Program Files\SupTab\SupTab.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ not found.
File C:\ProgramData\ShopperPro\ShopperPro.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver not found.
File C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt not found.
File C:\Program Files\AVG SafeGuard toolbar\vprot.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully.
C:\Users\ppp\AppData\Local\Akamai\netsession_win.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ares deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0214c deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LiveSupport not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\RocketDock deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver deleted successfully.
File C:\Program Files\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Tiny download manager deleted successfully.
C:\Users\ppp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FIFA 10 Registration.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll deleted successfully.
File c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll not found.
Folder C:\Users\Public\Documents\YTAHelper\ not found.
Folder C:\Users\ppp\AppData\Local\globalUpdate\ not found.
Folder C:\Program Files\globalUpdate\ not found.
Folder C:\Program Files\Apps Hat\ not found.
Folder C:\Users\Public\Documents\GOOBZO\ not found.
Folder C:\ProgramData\ShopperPro\ not found.
Folder C:\Users\Public\Documents\ShopperPro\ not found.
Folder C:\Program Files\Common Files\ShopperPro\ not found.
Folder C:\Program Files\ShopperPro\ not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-5_user.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-4.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-5.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-6.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-2.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-1.job not found.
File C:\Windows\tasks\030b3de7-1793-48da-9839-f6ab73d18535-11.job not found.
File C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
File C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AMD AVT deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope deleted successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 57472 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: ppp
->Temp folder emptied: 6955232 bytes
->Temporary Internet Files folder emptied: 7513770 bytes
->Java cache emptied: 55025 bytes
->FireFox cache emptied: 5107140 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 2381 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 11145728 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1045009 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 30,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 08052014_112451
 
Files\Folders moved on Reboot...
C:\Users\ppp\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File\Folder C:\Windows\temp\TMP00000002224ACAF83EA1AE6A not found!
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot

OTL.Txt

Protection Logs.txt

Scan Log.txt

Odnośnik do komentarza

Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:

 

:OTL
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe -- (McComponentHostService)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\Program Files\Webzen\Mu\GameGuard\dump_wmimmc.sys -- (dump_wmimmc)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (awiebfhb)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (af50ujwh)
FF - prefs.js..extensions.enabledAddons: faststartff%40gmail.com:4.3.0

:Commands
[emptytemp]

Kliknij w Wykonaj Skrypt.

 

CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahnllbhakmnbcloknbhkhabcnbnhgaim\1.0.3_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.3_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge\2.4_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

 

Znasz te rozszerzenia w Google Chrome?

 

jessi

Odnośnik do komentarza

Nie znam tych rozszerzeń.

 

OTL po wykonaniu skryptu :

 

All processes killed

========== OTL ==========
Service McComponentHostService stopped successfully!
Service McComponentHostService deleted successfully!
File C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe not found.
Service dump_wmimmc stopped successfully!
Service dump_wmimmc deleted successfully!
File D:\Program Files\Webzen\Mu\GameGuard\dump_wmimmc.sys not found.
Error: No service named awiebfhb was found to stop!
Service\Driver key awiebfhb not found.
Error: No service named af50ujwh was found to stop!
Service\Driver key af50ujwh not found.
Prefs.js: faststartff%40gmail.com:4.3.0 removed from extensions.enabledAddons
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: ppp
->Temp folder emptied: 1127440 bytes
->Temporary Internet Files folder emptied: 661724 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 111334773 bytes
->Flash cache emptied: 1943 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 186801952 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 286,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 08062014_122645
 
Files\Folders moved on Reboot...
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...

Odnośnik do komentarza

Skoro nie znasz tych rozszerzeń, to:

Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:

 

:Files
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahnllbhakmnbcloknbhkhabcnbnhgaim
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\ppp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

:Commands
[emptytemp]

Kliknij w Wykonaj Skrypt.

 

>>Google Chrome

> Naciśnij klawisze: lewy Alt+F i kliknij przycisk Ustawienia >
    
> po prawej kliknij na Rozszerzenia >
> kliknij na ikonkę Kosza po prawej od  nieznanych Ci rozszerzeń

 

napisz, jak oceniasz obecną sytuację?

 

jessi

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...