Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Moc prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Moc prosím o kontrolu logu
Dobrý den, prosím o kontrolu logu, děkuji
Logfile of random's system information tool 1.06 (written by random/random)
Run by PLANEO at 2013-10-07 15:19:53
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 24 GB (16%) free of 153 GB
Total RAM: 3070 MB (54% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WebReg Deskjet F2100 series.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055af109-de93-4160-bcfc-7da70ecaa020}]
diamondata - C:\Program Files\diamondata\diamondatabho.dll [2013-10-03 249632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2013-09-03 68480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29 539888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2013-05-06 194912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}]
PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-07 462248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4c2fb10-84c3-44eb-9f9e-860fa1d9a797}]
Search Assistant BHO - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll [2013-07-03 62864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-07 194640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-07 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d}]
Toolbar BHO - C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbar.dll [2013-07-03 712264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]
{cd1a63ba-a08c-431b-9a34-f240aadc728d} - Allin1Convert - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hbar.dll [2013-07-03 712264]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-07 194640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-12 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-12 1833504]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"ExpressFiles"=C:\Program Files\ExpressFiles\ExpressFiles.exe [2013-10-07 929280]
"TkBellExe"=C:\Program Files\Real\RealPlayer\Update\realsched.exe [2013-03-29 295072]
"SearchProtectAll"=C:\Program Files\SearchProtect\bin\cltmng.exe [2013-05-08 2852640]
"DivXMediaServer"=C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [2013-05-20 450560]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-02-13 1263952]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]
"Allin1Convert Search Scope Monitor"=C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hsrchmn.exe [2013-07-03 44784]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"ICQ"=C:\Program Files\ICQ7.7\ICQ.exe [2012-01-23 127040]
"EADM"=D:\Origin\Origin.exe [2013-10-06 3551576]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-10-07 5706480]
"SearchProtect"=C:\Users\PLANEO\AppData\Roaming\SearchProtect\bin\cltmng.exe [2013-05-08 2852640]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-08-20 39408]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2013-05-08 115440]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2013-10-07 13:27:16 ----D---- C:\Windows\Sun
2013-10-07 13:27:02 ----D---- C:\ProgramData\Oracle
2013-10-07 13:26:42 ----A---- C:\Windows\system32\javaws.exe
2013-10-07 13:25:59 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:25:59 ----A---- C:\Windows\system32\javaw.exe
2013-10-07 13:25:59 ----A---- C:\Windows\system32\java.exe
2013-10-07 13:21:56 ----D---- C:\Program Files\diamondata
2013-10-01 20:28:02 ----D---- C:\Program Files\Mozilla Firefox
2013-09-13 14:25:57 ----A---- C:\Windows\system32\vbscript.dll
2013-09-13 14:25:57 ----A---- C:\Windows\system32\mshtmled.dll
2013-09-13 14:25:55 ----A---- C:\Windows\system32\jsproxy.dll
2013-09-13 14:25:55 ----A---- C:\Windows\system32\ieui.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\wininet.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\msfeeds.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\ieUnatt.exe
2013-09-13 14:25:53 ----A---- C:\Windows\system32\jscript9.dll
2013-09-13 14:25:53 ----A---- C:\Windows\system32\jscript.dll
2013-09-13 14:25:52 ----A---- C:\Windows\system32\url.dll
2013-09-13 14:25:51 ----A---- C:\Windows\system32\iertutil.dll
2013-09-13 14:25:50 ----A---- C:\Windows\system32\urlmon.dll
2013-09-13 14:25:48 ----A---- C:\Windows\system32\mshtml.dll
2013-09-13 14:25:47 ----A---- C:\Windows\system32\ieframe.dll
2013-09-12 20:03:09 ----A---- C:\Windows\system32\themeui.dll
======List of files/folders modified in the last 1 months======
2013-10-07 15:19:55 ----D---- C:\Program Files\trend micro
2013-10-07 15:19:52 ----D---- C:\Windows\temp
2013-10-07 15:11:18 ----D---- C:\Program Files\SUPERAntiSpyware
2013-10-07 15:02:12 ----D---- C:\Windows\system32\Tasks
2013-10-07 14:58:58 ----A---- C:\Windows\system32\acovcnt.exe
2013-10-07 13:45:05 ----SHD---- C:\System Volume Information
2013-10-07 13:27:16 ----D---- C:\Windows
2013-10-07 13:27:02 ----D---- C:\ProgramData
2013-10-07 13:26:59 ----SHD---- C:\Windows\Installer
2013-10-07 13:26:42 ----D---- C:\Windows\System32
2013-10-07 13:25:35 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-10-07 13:25:35 ----A---- C:\Windows\system32\deployJava1.dll
2013-10-07 13:21:59 ----RD---- C:\Program Files
2013-10-07 13:21:04 ----D---- C:\Users\PLANEO\AppData\Roaming\ExpressFiles
2013-10-07 13:20:29 ----D---- C:\Program Files\ExpressFiles
2013-10-07 13:16:10 ----D---- C:\ProgramData\HP
2013-10-07 12:24:18 ----D---- C:\Windows\tracing
2013-10-07 11:45:19 ----D---- C:\Program Files\Opera
2013-10-07 11:34:35 ----D---- C:\Windows\Prefetch
2013-10-07 11:24:13 ----D---- C:\Users\PLANEO\AppData\Roaming\Skype
2013-10-03 09:34:47 ----D---- C:\Windows\system32\drivers
2013-10-03 09:34:46 ----D---- C:\Windows\system32\catroot
2013-10-03 09:34:44 ----D---- C:\Windows\inf
2013-10-03 09:29:19 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-09-25 20:11:29 ----D---- C:\Windows\Tasks
2013-09-19 20:07:36 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-09-13 14:44:46 ----D---- C:\Windows\system32\catroot2
2013-09-13 14:41:11 ----D---- C:\Windows\system32\migration
2013-09-13 14:41:09 ----D---- C:\Program Files\Internet Explorer
2013-09-13 14:30:47 ----D---- C:\ProgramData\Microsoft Help
2013-09-13 14:28:43 ----D---- C:\Windows\winsxs
2013-09-12 23:28:28 ----D---- C:\Windows\system32\MRT
2013-09-12 23:25:06 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2013-05-09 49760]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-06-27 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-06-27 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-05-09 56080]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
R2 cpuz135;cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-06 908800]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-12 2159384]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-06-03 15928]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-08 1050656]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-25 7547552]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-07-22 15872]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-07-23 1772544]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 al95hubt;al95hubt; C:\Windows\system32\drivers\al95hubt.sys []
S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer; \??\E:\I386\AsProcOb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CFcatchme;CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys []
S3 CRFILTER;USB Mass Storage Filter; C:\Windows\system32\DRIVERS\CRFILTER.sys [2008-04-07 6656]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-06-04 84248]
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;Filtr Dot4USB Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-06-04 181912]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-07-14 34944]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2013-05-23 119056]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 Allin1Convert_8hService;Allin1ConvertService; C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbarsvc.exe [2013-07-03 42504]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 BcmSqlStartupSvc;Služba spouštění serveru SQL Server aplikace Business Contact Manager; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 CltMngSvc;Search Protect by Conduit Updater; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [2013-05-08 97056]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-25 196608]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 Update diamondata;Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [2013-10-03 65312]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-28 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-19 257416]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-28 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-09-21 194032]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-01 118680]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2008-10-24 145248]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-04-18 754856]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by PLANEO at 2013-10-07 15:19:53
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 24 GB (16%) free of 153 GB
Total RAM: 3070 MB (54% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WebReg Deskjet F2100 series.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055af109-de93-4160-bcfc-7da70ecaa020}]
diamondata - C:\Program Files\diamondata\diamondatabho.dll [2013-10-03 249632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2013-09-03 68480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29 539888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2013-05-06 194912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}]
PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-07 462248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4c2fb10-84c3-44eb-9f9e-860fa1d9a797}]
Search Assistant BHO - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll [2013-07-03 62864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-07 194640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-07 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d}]
Toolbar BHO - C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbar.dll [2013-07-03 712264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]
{cd1a63ba-a08c-431b-9a34-f240aadc728d} - Allin1Convert - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hbar.dll [2013-07-03 712264]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-07 194640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-12 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-12 1833504]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"ExpressFiles"=C:\Program Files\ExpressFiles\ExpressFiles.exe [2013-10-07 929280]
"TkBellExe"=C:\Program Files\Real\RealPlayer\Update\realsched.exe [2013-03-29 295072]
"SearchProtectAll"=C:\Program Files\SearchProtect\bin\cltmng.exe [2013-05-08 2852640]
"DivXMediaServer"=C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [2013-05-20 450560]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-02-13 1263952]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]
"Allin1Convert Search Scope Monitor"=C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hsrchmn.exe [2013-07-03 44784]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"ICQ"=C:\Program Files\ICQ7.7\ICQ.exe [2012-01-23 127040]
"EADM"=D:\Origin\Origin.exe [2013-10-06 3551576]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-10-07 5706480]
"SearchProtect"=C:\Users\PLANEO\AppData\Roaming\SearchProtect\bin\cltmng.exe [2013-05-08 2852640]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-08-20 39408]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2013-05-08 115440]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2013-10-07 13:27:16 ----D---- C:\Windows\Sun
2013-10-07 13:27:02 ----D---- C:\ProgramData\Oracle
2013-10-07 13:26:42 ----A---- C:\Windows\system32\javaws.exe
2013-10-07 13:25:59 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:25:59 ----A---- C:\Windows\system32\javaw.exe
2013-10-07 13:25:59 ----A---- C:\Windows\system32\java.exe
2013-10-07 13:21:56 ----D---- C:\Program Files\diamondata
2013-10-01 20:28:02 ----D---- C:\Program Files\Mozilla Firefox
2013-09-13 14:25:57 ----A---- C:\Windows\system32\vbscript.dll
2013-09-13 14:25:57 ----A---- C:\Windows\system32\mshtmled.dll
2013-09-13 14:25:55 ----A---- C:\Windows\system32\jsproxy.dll
2013-09-13 14:25:55 ----A---- C:\Windows\system32\ieui.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\wininet.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\msfeeds.dll
2013-09-13 14:25:54 ----A---- C:\Windows\system32\ieUnatt.exe
2013-09-13 14:25:53 ----A---- C:\Windows\system32\jscript9.dll
2013-09-13 14:25:53 ----A---- C:\Windows\system32\jscript.dll
2013-09-13 14:25:52 ----A---- C:\Windows\system32\url.dll
2013-09-13 14:25:51 ----A---- C:\Windows\system32\iertutil.dll
2013-09-13 14:25:50 ----A---- C:\Windows\system32\urlmon.dll
2013-09-13 14:25:48 ----A---- C:\Windows\system32\mshtml.dll
2013-09-13 14:25:47 ----A---- C:\Windows\system32\ieframe.dll
2013-09-12 20:03:09 ----A---- C:\Windows\system32\themeui.dll
======List of files/folders modified in the last 1 months======
2013-10-07 15:19:55 ----D---- C:\Program Files\trend micro
2013-10-07 15:19:52 ----D---- C:\Windows\temp
2013-10-07 15:11:18 ----D---- C:\Program Files\SUPERAntiSpyware
2013-10-07 15:02:12 ----D---- C:\Windows\system32\Tasks
2013-10-07 14:58:58 ----A---- C:\Windows\system32\acovcnt.exe
2013-10-07 13:45:05 ----SHD---- C:\System Volume Information
2013-10-07 13:27:16 ----D---- C:\Windows
2013-10-07 13:27:02 ----D---- C:\ProgramData
2013-10-07 13:26:59 ----SHD---- C:\Windows\Installer
2013-10-07 13:26:42 ----D---- C:\Windows\System32
2013-10-07 13:25:35 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-10-07 13:25:35 ----A---- C:\Windows\system32\deployJava1.dll
2013-10-07 13:21:59 ----RD---- C:\Program Files
2013-10-07 13:21:04 ----D---- C:\Users\PLANEO\AppData\Roaming\ExpressFiles
2013-10-07 13:20:29 ----D---- C:\Program Files\ExpressFiles
2013-10-07 13:16:10 ----D---- C:\ProgramData\HP
2013-10-07 12:24:18 ----D---- C:\Windows\tracing
2013-10-07 11:45:19 ----D---- C:\Program Files\Opera
2013-10-07 11:34:35 ----D---- C:\Windows\Prefetch
2013-10-07 11:24:13 ----D---- C:\Users\PLANEO\AppData\Roaming\Skype
2013-10-03 09:34:47 ----D---- C:\Windows\system32\drivers
2013-10-03 09:34:46 ----D---- C:\Windows\system32\catroot
2013-10-03 09:34:44 ----D---- C:\Windows\inf
2013-10-03 09:29:19 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-09-25 20:11:29 ----D---- C:\Windows\Tasks
2013-09-19 20:07:36 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-09-13 14:44:46 ----D---- C:\Windows\system32\catroot2
2013-09-13 14:41:11 ----D---- C:\Windows\system32\migration
2013-09-13 14:41:09 ----D---- C:\Program Files\Internet Explorer
2013-09-13 14:30:47 ----D---- C:\ProgramData\Microsoft Help
2013-09-13 14:28:43 ----D---- C:\Windows\winsxs
2013-09-12 23:28:28 ----D---- C:\Windows\system32\MRT
2013-09-12 23:25:06 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2013-05-09 49760]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-06-27 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-06-27 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-05-09 56080]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
R2 cpuz135;cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-06 908800]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-12 2159384]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-06-03 15928]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-08 1050656]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-25 7547552]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-07-22 15872]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-07-23 1772544]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 al95hubt;al95hubt; C:\Windows\system32\drivers\al95hubt.sys []
S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer; \??\E:\I386\AsProcOb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CFcatchme;CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys []
S3 CRFILTER;USB Mass Storage Filter; C:\Windows\system32\DRIVERS\CRFILTER.sys [2008-04-07 6656]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-06-04 84248]
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;Filtr Dot4USB Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-06-04 181912]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-07-14 34944]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2013-05-23 119056]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 Allin1Convert_8hService;Allin1ConvertService; C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbarsvc.exe [2013-07-03 42504]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 BcmSqlStartupSvc;Služba spouštění serveru SQL Server aplikace Business Contact Manager; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 CltMngSvc;Search Protect by Conduit Updater; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [2013-05-08 97056]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-25 196608]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 Update diamondata;Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [2013-10-03 65312]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-28 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-19 257416]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-28 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-09-21 194032]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-01 118680]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2008-10-24 145248]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-04-18 754856]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
-----------------EOF-----------------
Re: Moc prosím o kontrolu logu
Zdravim a pekne odpoledne preji
Tam toho je, jste se dala na chov konicku trojskych ci to Cela zoo i s babkou pokladni
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Tam toho je, jste se dala na chov konicku trojskych ci to Cela zoo i s babkou pokladni
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Moc prosím o kontrolu logu
Netuším co s tím ntbkem ségra s mámou dělaly, já na něm skoro vůbec nejsem takže fakt nevím jednou jsem si ho tu už nechávala čistit a vše bylo ok, a pak ho dostanou do ruky a vyleze z toho takové nadělení :/ ... jen mám pro jistotu dotaz, stáhla jsem to JRT, zmáčkla libovolnou klávesu a teď se to v tý černý tabulce zaseklo a je tam dotaz: A bad module has been detected! A reboot is required to remove modules ... Pres y to reboot now Press n to rebook later ..Reboot now? (y,n) mám zmáčknout yes/no nebo mám čekat??
- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Moc prosím o kontrolu logu
Kolegovi sem s jeho dovolením jednorázově vlezu, aby měl co dělat až přijde - jasně, že reboot. Klikni na yes (y), pak log sem a hned na druhou utilitu.
Re: Moc prosím o kontrolu logu
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.4 (10.06.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by PLANEO on po 07.10.2013 at 17:18:12,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortapp.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escorteng.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\icq service.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{13119113-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1604FC43-3A1E-4C6B-850D-70C8A858C61A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{250B71CD-97CA-40A5-834F-265719A62CAF}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{33119133-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{39D4F1A1-A94D-4B7D-BF1D-7446308800ED}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{443321F7-E46C-42F8-812B-F35E98CBB44F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5CDE4714-32DC-473C-8194-0645E62C2E96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{8F83D657-5993-4FFA-9AEE-DA0B20D828A7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A4C2FB10-84C3-44EB-9F9E-860FA1D9A797}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C8EF8F70-3807-424A-83F7-DA06FD4DACF9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE0F6787-9D1C-42B7-A0B9-EAC630F87902}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E4EF697F-434B-4DC7-A464-4412462206DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF3F28C8-0330-4D18-B901-D24CB83E5AA1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F2C368C5-9F44-4D43-89F3-A1CC87F1DA96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{23119123-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{03119103-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{16976E15-10EA-44FD-804A-6ECBC9EBBFC7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{4BD0FCFF-AD64-4315-9F2C-960EF3C21623}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{507C73BB-FC69-425E-8A49-9204F886B328}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{6EC57031-1740-4151-93C5-C465D6063DD2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{76FC1003-0825-48BD-B59B-3B7A5754972C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9D217B94-6FC9-44FE-94B1-30C711871266}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{B48AC2CD-9662-47E0-A3C0-3B01BB3F463E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BE698E51-830B-447A-954D-901D6E05DDE2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BFCF748F-A56E-451F-AA45-0D7EB699E416}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D09139AB-0ACB-4F22-B9AE-816E6838A814}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D617CF84-B0BC-441F-9984-B676AFBA1E8D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\mediafinder
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\allin1convert_8h
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\download with &media finder
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\allin1convert_8h
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.dynamicbarbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.dynamicbarbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.feedmanager
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.feedmanager.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlmenu
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlmenu.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlpanel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlpanel.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.multiplebutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.multiplebutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.pseudotransparentplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.pseudotransparentplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radio
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radio.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radiosettings
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radiosettings.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.scriptbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.scriptbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.settingsplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.settingsplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.skinlauncher
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.skinlauncher.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.thirdpartyinstaller
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.thirdpartyinstaller.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.urlalertbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.urlalertbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.xmlsessionplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.xmlsessionplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\b
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\mf
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53F6A516-3DCC-48F4-835C-6C670CB39CEA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E58CDA9-3B21-4611-A859-26EE28950E61}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C5561B6-3DD2-46B5-83BE-EAE744366046}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88E44198-D164-4EC0-B2C0-F679D866C6DA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F671C1B3-9776-426D-A350-55FB2D9B53F7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall firefox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall internet explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\icqtoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3288691
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{59A72932-E467-4538-825F-AFFE63E04238}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{98267538-FF4E-4317-B2A7-DA5A6E18C219}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4C2FB10-84C3-44EB-9F9E-860FA1D9A797}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBCBC43A-DCA9-4192-A4C8-B57FD0F77D4D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055af109-de93-4160-bcfc-7da70ecaa020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{055af109-de93-4160-bcfc-7da70ecaa020}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
~~~ Files
Successfully deleted: [File] "C:\Windows\system32\roboot.exe"
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\premium"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\media finder"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\searchprotect"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\download and sa"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\shopperreports3"
Failed to delete: [Folder] "C:\Program Files\allin1convert_8h"
Successfully deleted: [Folder] "C:\Program Files\daemon tools toolbar"
Failed to delete: [Folder] "C:\Program Files\diamondata"
Successfully deleted: [Folder] "C:\Program Files\icq6toolbar"
Successfully deleted: [Folder] "C:\Program Files\searchprotect"
Successfully deleted: [Folder] "C:\Program Files\ask.com"
Successfully deleted: [Folder] "C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Failed to delete: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml"
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\user.js
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\firefox@diamondata.net.xpi
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\searchplugins\askcom.xml
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\searchplugins\conduit.xml
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\smartbar
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\8hffxtbr@Allin1Convert_8h.com
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\{77e8143b-6759-416e-b521-82cfed75150b}
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\8hffxtbr@Allin1Convert_8h.com
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Allin1Convert_8h.com/Plugin
Successfully deleted the following from C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\prefs.js
user_pref("CT3288691.CONDUIT_UPDATE_converterVersion.enc", "OS4yLjAuMTY=");
user_pref("CT3288691.CONDUIT_UPDATE_lastTimeUpdateChecked.enc", 1898094073);
user_pref("CT3288691.CONDUIT_UPDATE_playerVersion.enc", "MTEuMC4xLjUy");
user_pref("CT3288691.CONDUIT_UPDATE_streamerVersion.enc", "MS4yLjEuMjc=");
user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.FF19Solved", "true");
user_pref("CT3288691.FirstTime", "true");
user_pref("CT3288691.FirstTimeFF3", "true");
user_pref("CT3288691.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("CT3288691.UserID", "UN10647529152296171");
user_pref("CT3288691.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3288691.autoDisableScopes", -1);
user_pref("CT3288691.browser.search.defaultthis.engineName", "true");
user_pref("CT3288691.countryCode", "CZ");
user_pref("CT3288691.defaultSearch", "true");
user_pref("CT3288691.enableAlerts", "true");
user_pref("CT3288691.enableFix404ByUser", "TRUE");
user_pref("CT3288691.enableSearchFromAddressBar", "true");
user_pref("CT3288691.firstTimeDialogOpened", "true");
user_pref("CT3288691.fixPageNotFoundError", "true");
user_pref("CT3288691.fixPageNotFoundErrorByUser", "true");
user_pref("CT3288691.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3288691.fixUrls", true);
user_pref("CT3288691.fullUserID", "UN10647529152296171.IN.20130623134639");
user_pref("CT3288691.homepageuserchanged", true);
user_pref("CT3288691.installDate", "23/06/2013 13:46:46");
user_pref("CT3288691.installId", "stub.exe");
user_pref("CT3288691.installSessionId", "{FD03482E-8EDB-4DC6-9153-B8DEC7BEB691}");
user_pref("CT3288691.installSp", "true");
user_pref("CT3288691.installType", "conduitnsisintegration");
user_pref("CT3288691.installUsage", "2013-06-23T16:04:12.7471228+03:00");
user_pref("CT3288691.installUsageEarly", "2013-06-23T16:03:53.9490023+03:00");
user_pref("CT3288691.installerVersion", "1.4.3.3");
user_pref("CT3288691.isCheckedStartAsHidden", true);
user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.isFirstTimeToolbarLoading", "false");
user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3288691.keyword", "true");
user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=15&CUI=UN1064752915229617
user_pref("CT3288691.lastVersion", "10.20.1.508");
user_pref("CT3288691.mam_gk_installer_preapproved.enc", "dHJ1ZQ==");
user_pref("CT3288691.migrateAppsAndComponents", true);
user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Ablank\",\"EB_MAIN_FRAME_TITLE\":\"Obnoven%C3%AD%20relace\",\"EB_TOOLBAR_
user_pref("CT3288691.openThankYouPage", "false");
user_pref("CT3288691.openUninstallPage", "true");
user_pref("CT3288691.originalHomepage", "hxxp://seznam.cz/");
user_pref("CT3288691.originalSearchAddressUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=");
user_pref("CT3288691.originalSearchEngine", "Google");
user_pref("CT3288691.originalSearchEngineName", "Google");
user_pref("CT3288691.revertSettingsEnabled", "false");
user_pref("CT3288691.search.searchAppId", "10000002");
user_pref("CT3288691.search.searchCount", "0");
user_pref("CT3288691.searchFromAddressBarEnabledByUser", "true");
user_pref("CT3288691.searchInNewTabEnabledByUser", "true");
user_pref("CT3288691.searchInNewTabEnabledInHidden", "true");
user_pref("CT3288691.searchRevert", "false");
user_pref("CT3288691.searchSuggestEnabledByUser", "true");
user_pref("CT3288691.searchUserMode", "2");
user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT3288691.serviceLayer_services_Configuration_lastUpdate", "1381115508695");
user_pref("CT3288691.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1371992643018");
user_pref("CT3288691.serviceLayer_services_appsMetadata_lastUpdate", "1371992643038");
user_pref("CT3288691.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1371992642420");
user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1371992624961");
user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1371992646161");
user_pref("CT3288691.serviceLayer_services_location_lastUpdate", "1372319283149");
user_pref("CT3288691.serviceLayer_services_login_10.16.2.10_lastUpdate", "1372021752182");
user_pref("CT3288691.serviceLayer_services_login_10.16.2.510_lastUpdate", "1372203613379");
user_pref("CT3288691.serviceLayer_services_login_10.16.4.519_lastUpdate", "1373314538159");
user_pref("CT3288691.serviceLayer_services_login_10.16.7.524_lastUpdate", "1374523215121");
user_pref("CT3288691.serviceLayer_services_login_10.16.70.505_lastUpdate", "1377084741408");
user_pref("CT3288691.serviceLayer_services_login_10.19.2.505_lastUpdate", "1379007803308");
user_pref("CT3288691.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379625312311");
user_pref("CT3288691.serviceLayer_services_login_10.20.1.508_lastUpdate", "1381115508301");
user_pref("CT3288691.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1371992642745");
user_pref("CT3288691.serviceLayer_services_searchAPI_lastUpdate", "1381115508515");
user_pref("CT3288691.serviceLayer_services_serviceMap_lastUpdate", "1381115508703");
user_pref("CT3288691.serviceLayer_services_toolbarContextMenu_lastUpdate", "1371992641821");
user_pref("CT3288691.serviceLayer_services_toolbarSettings_lastUpdate", "1381122708813");
user_pref("CT3288691.serviceLayer_services_translation_lastUpdate", "1381115508569");
user_pref("CT3288691.settingsINI", true);
user_pref("CT3288691.shouldFirstTimeDialog", "false");
user_pref("CT3288691.showToolbarPermission", "false");
user_pref("CT3288691.smartbar.CTID", "CT3288691");
user_pref("CT3288691.smartbar.Uninstall", "0");
user_pref("CT3288691.smartbar.homepage", "true");
user_pref("CT3288691.smartbar.isHidden", true);
user_pref("CT3288691.smartbar.toolbarName", "DivX Browser Bar ");
user_pref("CT3288691.startPage", "true");
user_pref("CT3288691.toolbarBornServerTime", "23-6-2013");
user_pref("CT3288691.toolbarCurrentServerTime", "7-10-2013");
user_pref("CT3288691.toolbarLoginClientTime", "Sun Jun 23 2013 15:04:04 GMT+0200");
user_pref("CT3288691.versionFromInstaller", "10.16.2.10");
user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1381159054337,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN10647529152296171&UM=2&UP=SP938480DB-6D39-45C1-98B8
user_pref("Smartbar.ConduitSearchEngineList", "DivX Browser Bar Customized Web Search");
user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=");
user_pref("Smartbar.keywordURLSelectedCTID", "CT3288691");
user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?babsrc=NT_ss&mntr ... 0&tsp=5028");
user_pref("browser.search.defaultenginename", "DivX Browser Bar Customized Web Search");
user_pref("browser.search.defaultthis.engineName", "DivX Browser Bar Customized Web Search");
user_pref("extensions.506d493294740.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.top==window.self){new function(){if(!do
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109980");
user_pref("extensions.BabylonToolbar_i.hardId", "2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.id", "2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.instlDay", "15443");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.newTab", false);
user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=109980&babsrc=NT_ss&mntrId=2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1711:31:59");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("smartbar.addressBarOwnerCTID", "CT3288691");
user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3288691&CUI=UN10647529152296171&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3288691&oct
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=,hxxp://search.condui
user_pref("smartbar.defaultSearchOwnerCTID", "CT3288691");
user_pref("smartbar.homePageOwnerCTID", "CT3288691");
user_pref("smartbar.machineId", "3TEJH0LHLOWQ4OAIV2YZYSK4NXYA/ZK5WPGWXV3DLJJDSPCY4LDGQLZS7KKVX/EDOU+PPNGAUHYGBZPLSY79VA");
user_pref("smartbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3288691&CUI=UN10647529152296171&UM=2&SearchSource=13");
Emptied folder: C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\minidumps [103 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\PLANEO\appdata\local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 07.10.2013 at 17:25:02,74
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.4 (10.06.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by PLANEO on po 07.10.2013 at 17:18:12,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortapp.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escorteng.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\icq service.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{13119113-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1604FC43-3A1E-4C6B-850D-70C8A858C61A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{250B71CD-97CA-40A5-834F-265719A62CAF}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{27F49273-DE3A-4111-90F9-6C474C37AEFB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{33119133-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{39D4F1A1-A94D-4B7D-BF1D-7446308800ED}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{443321F7-E46C-42F8-812B-F35E98CBB44F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5CDE4714-32DC-473C-8194-0645E62C2E96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7CAEFAFC-9A1E-4BCC-94DD-BC7D8D52717A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7EB7381C-FB01-47FC-9C42-ED64122C1B92}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{889F49D2-6CEA-40BE-BE5F-7217485F9745}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{8F83D657-5993-4FFA-9AEE-DA0B20D828A7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A4C2FB10-84C3-44EB-9F9E-860FA1D9A797}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C8EF8F70-3807-424A-83F7-DA06FD4DACF9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{CD1A63BA-A08C-431B-9A34-F240AADC728D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE0F6787-9D1C-42B7-A0B9-EAC630F87902}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E4EF697F-434B-4DC7-A464-4412462206DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF3F28C8-0330-4D18-B901-D24CB83E5AA1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F2C368C5-9F44-4D43-89F3-A1CC87F1DA96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F99DDD9A-07D0-47AB-86F1-193533DD2C60}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{23119123-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{03119103-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{16976E15-10EA-44FD-804A-6ECBC9EBBFC7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{2561FD25-FE31-4E56-A120-AF7FEAAE3124}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{4BD0FCFF-AD64-4315-9F2C-960EF3C21623}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{507C73BB-FC69-425E-8A49-9204F886B328}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{6EC57031-1740-4151-93C5-C465D6063DD2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{76FC1003-0825-48BD-B59B-3B7A5754972C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9D217B94-6FC9-44FE-94B1-30C711871266}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{B48AC2CD-9662-47E0-A3C0-3B01BB3F463E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BE698E51-830B-447A-954D-901D6E05DDE2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BFCF748F-A56E-451F-AA45-0D7EB699E416}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D09139AB-0ACB-4F22-B9AE-816E6838A814}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D617CF84-B0BC-441F-9984-B676AFBA1E8D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\mediafinder
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\allin1convert_8h
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\download with &media finder
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\allin1convert_8h
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.dynamicbarbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.dynamicbarbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.feedmanager
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.feedmanager.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlmenu
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlmenu.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlpanel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.htmlpanel.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.multiplebutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.multiplebutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.pseudotransparentplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.pseudotransparentplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radio
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radio.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radiosettings
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.radiosettings.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.scriptbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.scriptbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.settingsplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.settingsplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.skinlauncher
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.skinlauncher.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.thirdpartyinstaller
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.thirdpartyinstaller.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.urlalertbutton
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.urlalertbutton.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.xmlsessionplugin
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\allin1convert_8h.xmlsessionplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\b
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\mf
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{248B3E95-17A4-482D-A8A8-6B3DF4D05C35}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53F6A516-3DCC-48F4-835C-6C670CB39CEA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E58CDA9-3B21-4611-A859-26EE28950E61}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6C5561B6-3DD2-46B5-83BE-EAE744366046}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88E44198-D164-4EC0-B2C0-F679D866C6DA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F671C1B3-9776-426D-A350-55FB2D9B53F7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall firefox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\allin1convert_8hbar uninstall internet explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\icqtoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3288691
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{59A72932-E467-4538-825F-AFFE63E04238}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{98267538-FF4E-4317-B2A7-DA5A6E18C219}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4C2FB10-84C3-44EB-9F9E-860FA1D9A797}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBCBC43A-DCA9-4192-A4C8-B57FD0F77D4D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055af109-de93-4160-bcfc-7da70ecaa020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{055af109-de93-4160-bcfc-7da70ecaa020}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
~~~ Files
Successfully deleted: [File] "C:\Windows\system32\roboot.exe"
Successfully deleted: [File] "C:\end"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\premium"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\media finder"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\searchprotect"
Successfully deleted: [Folder] "C:\Users\PLANEO\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\download and sa"
Successfully deleted: [Folder] "C:\Users\PLANEO\appdata\locallow\shopperreports3"
Failed to delete: [Folder] "C:\Program Files\allin1convert_8h"
Successfully deleted: [Folder] "C:\Program Files\daemon tools toolbar"
Failed to delete: [Folder] "C:\Program Files\diamondata"
Successfully deleted: [Folder] "C:\Program Files\icq6toolbar"
Successfully deleted: [Folder] "C:\Program Files\searchprotect"
Successfully deleted: [Folder] "C:\Program Files\ask.com"
Successfully deleted: [Folder] "C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Failed to delete: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml"
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\user.js
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\firefox@diamondata.net.xpi
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\searchplugins\askcom.xml
Successfully deleted: [File] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\searchplugins\conduit.xml
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\smartbar
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\8hffxtbr@Allin1Convert_8h.com
Successfully deleted: [Folder] C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\extensions\{77e8143b-6759-416e-b521-82cfed75150b}
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\8hffxtbr@Allin1Convert_8h.com
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Allin1Convert_8h.com/Plugin
Successfully deleted the following from C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\prefs.js
user_pref("CT3288691.CONDUIT_UPDATE_converterVersion.enc", "OS4yLjAuMTY=");
user_pref("CT3288691.CONDUIT_UPDATE_lastTimeUpdateChecked.enc", 1898094073);
user_pref("CT3288691.CONDUIT_UPDATE_playerVersion.enc", "MTEuMC4xLjUy");
user_pref("CT3288691.CONDUIT_UPDATE_streamerVersion.enc", "MS4yLjEuMjc=");
user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.FF19Solved", "true");
user_pref("CT3288691.FirstTime", "true");
user_pref("CT3288691.FirstTimeFF3", "true");
user_pref("CT3288691.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("CT3288691.UserID", "UN10647529152296171");
user_pref("CT3288691.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3288691.autoDisableScopes", -1);
user_pref("CT3288691.browser.search.defaultthis.engineName", "true");
user_pref("CT3288691.countryCode", "CZ");
user_pref("CT3288691.defaultSearch", "true");
user_pref("CT3288691.enableAlerts", "true");
user_pref("CT3288691.enableFix404ByUser", "TRUE");
user_pref("CT3288691.enableSearchFromAddressBar", "true");
user_pref("CT3288691.firstTimeDialogOpened", "true");
user_pref("CT3288691.fixPageNotFoundError", "true");
user_pref("CT3288691.fixPageNotFoundErrorByUser", "true");
user_pref("CT3288691.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3288691.fixUrls", true);
user_pref("CT3288691.fullUserID", "UN10647529152296171.IN.20130623134639");
user_pref("CT3288691.homepageuserchanged", true);
user_pref("CT3288691.installDate", "23/06/2013 13:46:46");
user_pref("CT3288691.installId", "stub.exe");
user_pref("CT3288691.installSessionId", "{FD03482E-8EDB-4DC6-9153-B8DEC7BEB691}");
user_pref("CT3288691.installSp", "true");
user_pref("CT3288691.installType", "conduitnsisintegration");
user_pref("CT3288691.installUsage", "2013-06-23T16:04:12.7471228+03:00");
user_pref("CT3288691.installUsageEarly", "2013-06-23T16:03:53.9490023+03:00");
user_pref("CT3288691.installerVersion", "1.4.3.3");
user_pref("CT3288691.isCheckedStartAsHidden", true);
user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.isFirstTimeToolbarLoading", "false");
user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3288691.keyword", "true");
user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=15&CUI=UN1064752915229617
user_pref("CT3288691.lastVersion", "10.20.1.508");
user_pref("CT3288691.mam_gk_installer_preapproved.enc", "dHJ1ZQ==");
user_pref("CT3288691.migrateAppsAndComponents", true);
user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Ablank\",\"EB_MAIN_FRAME_TITLE\":\"Obnoven%C3%AD%20relace\",\"EB_TOOLBAR_
user_pref("CT3288691.openThankYouPage", "false");
user_pref("CT3288691.openUninstallPage", "true");
user_pref("CT3288691.originalHomepage", "hxxp://seznam.cz/");
user_pref("CT3288691.originalSearchAddressUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=");
user_pref("CT3288691.originalSearchEngine", "Google");
user_pref("CT3288691.originalSearchEngineName", "Google");
user_pref("CT3288691.revertSettingsEnabled", "false");
user_pref("CT3288691.search.searchAppId", "10000002");
user_pref("CT3288691.search.searchCount", "0");
user_pref("CT3288691.searchFromAddressBarEnabledByUser", "true");
user_pref("CT3288691.searchInNewTabEnabledByUser", "true");
user_pref("CT3288691.searchInNewTabEnabledInHidden", "true");
user_pref("CT3288691.searchRevert", "false");
user_pref("CT3288691.searchSuggestEnabledByUser", "true");
user_pref("CT3288691.searchUserMode", "2");
user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}");
user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT3288691.serviceLayer_services_Configuration_lastUpdate", "1381115508695");
user_pref("CT3288691.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1371992643018");
user_pref("CT3288691.serviceLayer_services_appsMetadata_lastUpdate", "1371992643038");
user_pref("CT3288691.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1371992642420");
user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1371992624961");
user_pref("CT3288691.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1371992646161");
user_pref("CT3288691.serviceLayer_services_location_lastUpdate", "1372319283149");
user_pref("CT3288691.serviceLayer_services_login_10.16.2.10_lastUpdate", "1372021752182");
user_pref("CT3288691.serviceLayer_services_login_10.16.2.510_lastUpdate", "1372203613379");
user_pref("CT3288691.serviceLayer_services_login_10.16.4.519_lastUpdate", "1373314538159");
user_pref("CT3288691.serviceLayer_services_login_10.16.7.524_lastUpdate", "1374523215121");
user_pref("CT3288691.serviceLayer_services_login_10.16.70.505_lastUpdate", "1377084741408");
user_pref("CT3288691.serviceLayer_services_login_10.19.2.505_lastUpdate", "1379007803308");
user_pref("CT3288691.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379625312311");
user_pref("CT3288691.serviceLayer_services_login_10.20.1.508_lastUpdate", "1381115508301");
user_pref("CT3288691.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1371992642745");
user_pref("CT3288691.serviceLayer_services_searchAPI_lastUpdate", "1381115508515");
user_pref("CT3288691.serviceLayer_services_serviceMap_lastUpdate", "1381115508703");
user_pref("CT3288691.serviceLayer_services_toolbarContextMenu_lastUpdate", "1371992641821");
user_pref("CT3288691.serviceLayer_services_toolbarSettings_lastUpdate", "1381122708813");
user_pref("CT3288691.serviceLayer_services_translation_lastUpdate", "1381115508569");
user_pref("CT3288691.settingsINI", true);
user_pref("CT3288691.shouldFirstTimeDialog", "false");
user_pref("CT3288691.showToolbarPermission", "false");
user_pref("CT3288691.smartbar.CTID", "CT3288691");
user_pref("CT3288691.smartbar.Uninstall", "0");
user_pref("CT3288691.smartbar.homepage", "true");
user_pref("CT3288691.smartbar.isHidden", true);
user_pref("CT3288691.smartbar.toolbarName", "DivX Browser Bar ");
user_pref("CT3288691.startPage", "true");
user_pref("CT3288691.toolbarBornServerTime", "23-6-2013");
user_pref("CT3288691.toolbarCurrentServerTime", "7-10-2013");
user_pref("CT3288691.toolbarLoginClientTime", "Sun Jun 23 2013 15:04:04 GMT+0200");
user_pref("CT3288691.versionFromInstaller", "10.16.2.10");
user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1381159054337,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN10647529152296171&UM=2&UP=SP938480DB-6D39-45C1-98B8
user_pref("Smartbar.ConduitSearchEngineList", "DivX Browser Bar Customized Web Search");
user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=");
user_pref("Smartbar.keywordURLSelectedCTID", "CT3288691");
user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?babsrc=NT_ss&mntr ... 0&tsp=5028");
user_pref("browser.search.defaultenginename", "DivX Browser Bar Customized Web Search");
user_pref("browser.search.defaultthis.engineName", "DivX Browser Bar Customized Web Search");
user_pref("extensions.506d493294740.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.top==window.self){new function(){if(!do
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109980");
user_pref("extensions.BabylonToolbar_i.hardId", "2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.id", "2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.instlDay", "15443");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.newTab", false);
user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=109980&babsrc=NT_ss&mntrId=2e9ec95c00000000000000224351a545");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1711:31:59");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=");
user_pref("smartbar.addressBarOwnerCTID", "CT3288691");
user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3288691&CUI=UN10647529152296171&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3288691&oct
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3288691&SearchSource=2&CUI=UN10647529152296171&UM=2&q=,hxxp://search.condui
user_pref("smartbar.defaultSearchOwnerCTID", "CT3288691");
user_pref("smartbar.homePageOwnerCTID", "CT3288691");
user_pref("smartbar.machineId", "3TEJH0LHLOWQ4OAIV2YZYSK4NXYA/ZK5WPGWXV3DLJJDSPCY4LDGQLZS7KKVX/EDOU+PPNGAUHYGBZPLSY79VA");
user_pref("smartbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3288691&CUI=UN10647529152296171&UM=2&SearchSource=13");
Emptied folder: C:\Users\PLANEO\AppData\Roaming\mozilla\firefox\profiles\h9ndpdpu.default\minidumps [103 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\PLANEO\appdata\local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 07.10.2013 at 17:25:02,74
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Moc prosím o kontrolu logu
# AdwCleaner v3.006 - Report created 07/10/2013 at 17:42:15
# Updated 01/10/2013 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : PLANEO - PLANEO-PC
# Running from : C:\Users\PLANEO\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : Allin1Convert_8hService
[#] Service Deleted : CltMngSvc
[#] Service Deleted : ICQ Service
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
Folder Deleted : C:\Program Files\Allin1Convert_8h
Folder Deleted : C:\Program Files\ExpressFiles
Folder Deleted : C:\Users\PLANEO\AppData\LocalLow\DivX_Browser_Bar
Folder Deleted : C:\Users\PLANEO\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\ask-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-10.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-9.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD937C23-9304-4E9E-9FD3-0E00B88E2C2E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6CB61354-F253-44C2-9A9E-D7864E893D57}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{608F9BF6-3053-46C4-BD0D-EED098F6977D}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}]
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Deleted : HKCU\Software\AppDataLow\Software\DivX_Browser_Bar
Key Deleted : HKLM\Software\DeviceVM
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\DivX_Browser_Bar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ExpressFiles
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{20E7BC40-33F6-4A81-9D52-B58349326206}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\daemon tools toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ExpressFiles
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ICQToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DivX_Browser_Bar Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16506
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\prefs.js ]
Line Deleted : user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=15&CUI=UN10647529152296171&SSPV=&Lay=1&UM=2\"}");
Line Deleted : user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Ablank\",\"EB_MAIN_FRAME_TITLE\":\"Obnoven%C3%AD%20relace\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://Div[...]
Line Deleted : user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1381159054337,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("extensions.506d493294740.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.top==window.self){new function(){if(!document.getElementById(\"_[...]
Line Deleted : user_pref("extensions.enabledItems", "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19,belle.starr.colt@gmx.com:3.9,DTToolbar@toolbarnet.com:1.1.1.0014,{20a8[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", false);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1348219291);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "hxxp%3A%2F%2Fwww.primat.cz%2Fjcu-prf%2Fpredmety%2Fkapitoly-z-dejin-estetiky-ii-q18625%2Festetika-m81585%2Fdownload%2F||hxxp%3A%2F%2Fwww.primat.cz%2Fstredniskoly%2Fpred[...]
Line Deleted : user_pref("icqtoolbar.icqgeo", 42);
Line Deleted : user_pref("icqtoolbar.installTime", "1333009304");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "13.0.1");
Line Deleted : user_pref("icqtoolbar.showPc", true);
Line Deleted : user_pref("icqtoolbar.skip_default_search", "yes");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "125665118512566511851256732060892");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1348219348);
Line Deleted : user_pref("icqtoolbar.version", "1.4.7");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
[ File : C:\Users\Asined\AppData\Roaming\Mozilla\Firefox\Profiles\jp1tyico.default\prefs.js ]
-\\ Google Chrome v30.0.1599.69
[ File : C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
Deleted : homepage
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [11107 octets] - [07/10/2013 17:41:28]
AdwCleaner[S0].txt - [11019 octets] - [07/10/2013 17:42:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11080 octets] ##########
# Updated 01/10/2013 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : PLANEO - PLANEO-PC
# Running from : C:\Users\PLANEO\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : Allin1Convert_8hService
[#] Service Deleted : CltMngSvc
[#] Service Deleted : ICQ Service
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
Folder Deleted : C:\Program Files\Allin1Convert_8h
Folder Deleted : C:\Program Files\ExpressFiles
Folder Deleted : C:\Users\PLANEO\AppData\LocalLow\DivX_Browser_Bar
Folder Deleted : C:\Users\PLANEO\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\ask-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-10.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-9.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD937C23-9304-4E9E-9FD3-0E00B88E2C2E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6CB61354-F253-44C2-9A9E-D7864E893D57}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{608F9BF6-3053-46C4-BD0D-EED098F6977D}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{77E8143B-6759-416E-B521-82CFED75150B}]
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Deleted : HKCU\Software\AppDataLow\Software\DivX_Browser_Bar
Key Deleted : HKLM\Software\DeviceVM
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\DivX_Browser_Bar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ExpressFiles
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{20E7BC40-33F6-4A81-9D52-B58349326206}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\daemon tools toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ExpressFiles
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ICQToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DivX_Browser_Bar Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16506
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\prefs.js ]
Line Deleted : user_pref("CT3288691.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3288691.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=15&CUI=UN10647529152296171&SSPV=&Lay=1&UM=2\"}");
Line Deleted : user_pref("CT3288691.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Ablank\",\"EB_MAIN_FRAME_TITLE\":\"Obnoven%C3%AD%20relace\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://Div[...]
Line Deleted : user_pref("CT3288691.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3288691\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DivXBrowserBar.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DivX Browser Bar \"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3288691.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3288691_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1381159054337,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("extensions.506d493294740.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.top==window.self){new function(){if(!document.getElementById(\"_[...]
Line Deleted : user_pref("extensions.enabledItems", "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19,belle.starr.colt@gmx.com:3.9,DTToolbar@toolbarnet.com:1.1.1.0014,{20a8[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", false);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1348219291);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "hxxp%3A%2F%2Fwww.primat.cz%2Fjcu-prf%2Fpredmety%2Fkapitoly-z-dejin-estetiky-ii-q18625%2Festetika-m81585%2Fdownload%2F||hxxp%3A%2F%2Fwww.primat.cz%2Fstredniskoly%2Fpred[...]
Line Deleted : user_pref("icqtoolbar.icqgeo", 42);
Line Deleted : user_pref("icqtoolbar.installTime", "1333009304");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "13.0.1");
Line Deleted : user_pref("icqtoolbar.showPc", true);
Line Deleted : user_pref("icqtoolbar.skip_default_search", "yes");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "125665118512566511851256732060892");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1348219348);
Line Deleted : user_pref("icqtoolbar.version", "1.4.7");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
[ File : C:\Users\Asined\AppData\Roaming\Mozilla\Firefox\Profiles\jp1tyico.default\prefs.js ]
-\\ Google Chrome v30.0.1599.69
[ File : C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
Deleted : homepage
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [11107 octets] - [07/10/2013 17:41:28]
AdwCleaner[S0].txt - [11019 octets] - [07/10/2013 17:42:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11080 octets] ##########
Re: Moc prosím o kontrolu logu
Dekuji kolegovi za vstup
Nyni poprosim o log z FRSTL http://forum.viry.cz/viewtopic.php?f=13&t=133100
Nyni poprosim o log z FRSTL http://forum.viry.cz/viewtopic.php?f=13&t=133100
Re: Moc prosím o kontrolu logu
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by PLANEO (administrator) on PLANEO-PC on 07-10-2013 18:46:23
Running from C:\Users\PLANEO\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(diamondata) C:\Program Files\diamondata\updatediamondata.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ATK0100) C:\Program Files\ATK Hotkey\Hcontrol.exe
() C:\Program Files\ATK Hotkey\MsgTranAgt.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
( ) C:\Program Files\ASUS\ATK Media\GPSWATCH.EXE
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
() C:\Program Files\ATK Hotkey\WDC.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(ICQ, LLC.) C:\Program Files\ICQ7.7\ICQ.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\system32\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6265376 2008-08-12] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1833504 2008-08-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ExpressFiles] - "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.)
HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3551576 2013-10-06] (Electronic Arts)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5706480 2013-10-07] (SUPERAntiSpyware)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-20] (Google Inc.)
HKU\Asined\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Asined\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [ 2013-10-07] (SUPERAntiSpyware)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain ... &bmod=ASUS
URLSearchHook: (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll (Tracker Software Products (Canada) Ltd.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll (Tracker Software Products (Canada) Ltd.)
Toolbar: HKLM - No Name - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.0.282 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Download and Sa - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\506d493294695@506d4932946ce.com
FF Extension: The Saloon Bar - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\belle.starr.colt@gmx.com
FF Extension: Seznam lištička - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: No Name - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\google\chrome\application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\google\chrome\application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\google\chrome\application\30.0.1599.69\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.170.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U19) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.190.4) - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll No File
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (RealDownloader) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0
CHR HKLM\...\Chrome\Extension: [hendmekoldfacfhlojkjcnbjegkahclb] - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM\...\Chrome\Extension: [niinpihegnkddnddpndlojcpecicmcpf] - C:\ProgramData\Download and Sa\niinpihegnkddnddpndlojcpecicmcpf.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [119056 2013-05-23] (SUPERAntiSpyware.com)
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-03] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
R2 Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [65312 2013-10-03] (diamondata)
==================== Drivers (Whitelisted) ====================
R0 Achernar; C:\Windows\System32\Drivers\Achernar.sys [18432 2007-02-05] (NewSoft Technology Corporation)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] ()
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
S3 CRFILTER; C:\Windows\System32\DRIVERS\CRFILTER.sys [6656 2008-04-07] (Generic)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-07-23] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-03-09] ()
U3 arx243nf; C:\Windows\System32\Drivers\arx243nf.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 ASUSProcObsrv; \??\E:\I386\AsProcOb.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-07 18:44 - 2013-10-07 18:44 - 00000000 ____D C:\FRST
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 18:43 - 2013-10-07 18:42 - 00112128 _____ (forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
2013-10-07 18:40 - 2013-10-07 18:40 - 01087213 _____ (Farbar) C:\Users\PLANEO\Desktop\FRST.exe
2013-10-07 17:40 - 2013-10-07 17:43 - 00000000 ____D C:\AdwCleaner
2013-10-07 17:40 - 2013-10-07 17:40 - 01045226 _____ C:\Users\PLANEO\Downloads\adwcleaner.exe
2013-10-07 17:25 - 2013-10-07 17:25 - 00030368 _____ C:\Users\PLANEO\Desktop\JRT.txt
2013-10-07 15:37 - 2013-10-07 15:37 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 15:36 - 2013-10-07 15:36 - 01032220 _____ (Thisisu) C:\Users\PLANEO\Downloads\JRT.exe
2013-10-07 15:36 - 2013-10-07 15:36 - 00000000 ____D C:\ProgramData\SummerSoft
2013-10-07 15:35 - 2013-10-07 15:34 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\Windows\Sun
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\ProgramData\Oracle
2013-10-07 13:26 - 2013-10-07 13:25 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:21 - 2013-10-07 17:19 - 00000000 ____D C:\Program Files\diamondata
2013-10-07 13:20 - 2013-10-07 13:20 - 00001741 _____ C:\Users\Public\Desktop\Express Files.lnk
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-13 14:25 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 14:25 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 14:25 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 14:25 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 14:25 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-13 14:25 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 14:25 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-13 14:25 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-13 14:25 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 14:25 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 14:25 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 14:25 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-13 14:25 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 20:03 - 2013-08-08 03:45 - 02049536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 20:03 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
==================== One Month Modified Files and Folders =======
2013-10-07 18:44 - 2013-10-07 18:44 - 00000000 ____D C:\FRST
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 18:42 - 2013-10-07 18:43 - 00112128 _____ (forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
2013-10-07 18:41 - 2011-10-23 16:05 - 00000000 ____D C:\Users\PLANEO\Desktop\aajinka
2013-10-07 18:41 - 2010-01-05 12:43 - 00000000 ____D C:\Users\PLANEO\Desktop\Vejška
2013-10-07 18:40 - 2013-10-07 18:40 - 01087213 _____ (Farbar) C:\Users\PLANEO\Desktop\FRST.exe
2013-10-07 18:32 - 2013-02-19 11:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-07 18:32 - 2009-05-05 06:57 - 01054885 _____ C:\Windows\WindowsUpdate.log
2013-10-07 18:31 - 2010-09-28 20:42 - 00001356 _____ C:\Users\PLANEO\AppData\Local\d3d9caps.dat
2013-10-07 18:31 - 2009-10-04 21:34 - 00027934 _____ C:\ProgramData\nvModes.001
2013-10-07 17:58 - 2009-11-11 23:15 - 00000000 ____D C:\Users\PLANEO\AppData\Roaming\Skype
2013-10-07 17:50 - 2010-01-28 17:02 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-07 17:46 - 2010-01-28 17:02 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-07 17:46 - 2009-10-05 20:34 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-10-07 17:46 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-07 17:46 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-07 17:46 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-07 17:44 - 2006-11-02 15:01 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-07 17:43 - 2013-10-07 17:40 - 00000000 ____D C:\AdwCleaner
2013-10-07 17:42 - 2009-10-28 14:13 - 00000000 ____D C:\ProgramData\ICQ
2013-10-07 17:40 - 2013-10-07 17:40 - 01045226 _____ C:\Users\PLANEO\Downloads\adwcleaner.exe
2013-10-07 17:25 - 2013-10-07 17:25 - 00030368 _____ C:\Users\PLANEO\Desktop\JRT.txt
2013-10-07 17:19 - 2013-10-07 13:21 - 00000000 ____D C:\Program Files\diamondata
2013-10-07 17:17 - 2009-10-01 22:09 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2013-10-07 17:15 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\tracing
2013-10-07 17:14 - 2013-07-01 22:11 - 00007356 _____ C:\Windows\PFRO.log
2013-10-07 15:37 - 2013-10-07 15:37 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 15:36 - 2013-10-07 15:36 - 01032220 _____ (Thisisu) C:\Users\PLANEO\Downloads\JRT.exe
2013-10-07 15:36 - 2013-10-07 15:36 - 00000000 ____D C:\ProgramData\SummerSoft
2013-10-07 15:36 - 2012-10-04 10:25 - 00000000 ____D C:\ProgramData\InstallMate
2013-10-07 15:34 - 2013-10-07 15:35 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:19 - 2013-07-01 16:50 - 00000000 ____D C:\Program Files\trend micro
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
2013-10-07 15:11 - 2013-07-01 18:59 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\Windows\Sun
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\ProgramData\Oracle
2013-10-07 13:25 - 2013-10-07 13:26 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:25 - 2013-06-23 14:44 - 00868264 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-10-07 13:25 - 2013-06-23 14:44 - 00790440 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-10-07 13:20 - 2013-10-07 13:20 - 00001741 _____ C:\Users\Public\Desktop\Express Files.lnk
2013-10-07 13:16 - 2009-11-03 19:30 - 00000000 ____D C:\ProgramData\HP
2013-10-07 11:45 - 2011-10-29 09:54 - 00000000 ____D C:\Program Files\Opera
2013-10-05 20:31 - 2013-07-01 21:49 - 00000550 _____ C:\Users\PLANEO\Desktop\ComboFix – zástupce.lnk
2013-10-05 17:52 - 2012-02-20 02:04 - 00001978 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-03 09:34 - 2013-07-01 18:44 - 00002643 _____ C:\Windows\setupact.log
2013-10-03 09:29 - 2012-04-25 18:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-19 20:07 - 2013-02-19 11:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-19 20:07 - 2012-11-03 13:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-13 14:44 - 2006-11-02 14:47 - 00417144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-13 14:30 - 2009-05-05 07:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-12 23:28 - 2013-07-16 03:02 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 23:25 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
Some content of TEMP:
====================
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-07 17:54
==================== End Of Log ============================
Ran by PLANEO (administrator) on PLANEO-PC on 07-10-2013 18:46:23
Running from C:\Users\PLANEO\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
() C:\Program Files\ATK Hotkey\ASLDRSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(diamondata) C:\Program Files\diamondata\updatediamondata.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ATK0100) C:\Program Files\ATK Hotkey\Hcontrol.exe
() C:\Program Files\ATK Hotkey\MsgTranAgt.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
( ) C:\Program Files\ASUS\ATK Media\GPSWATCH.EXE
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
() C:\Program Files\ATK Hotkey\WDC.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(ICQ, LLC.) C:\Program Files\ICQ7.7\ICQ.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\system32\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6265376 2008-08-12] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1833504 2008-08-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ExpressFiles] - "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.)
HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3551576 2013-10-06] (Electronic Arts)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5706480 2013-10-07] (SUPERAntiSpyware)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-20] (Google Inc.)
HKU\Asined\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Asined\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [ 2013-10-07] (SUPERAntiSpyware)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain ... &bmod=ASUS
URLSearchHook: (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll (Tracker Software Products (Canada) Ltd.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll (Tracker Software Products (Canada) Ltd.)
Toolbar: HKLM - No Name - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.0.282 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Download and Sa - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\506d493294695@506d4932946ce.com
FF Extension: The Saloon Bar - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\belle.starr.colt@gmx.com
FF Extension: Seznam lištička - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: No Name - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\google\chrome\application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\google\chrome\application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\google\chrome\application\30.0.1599.69\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.170.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U19) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.190.4) - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll No File
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (RealDownloader) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0
CHR HKLM\...\Chrome\Extension: [hendmekoldfacfhlojkjcnbjegkahclb] - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM\...\Chrome\Extension: [niinpihegnkddnddpndlojcpecicmcpf] - C:\ProgramData\Download and Sa\niinpihegnkddnddpndlojcpecicmcpf.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [119056 2013-05-23] (SUPERAntiSpyware.com)
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-03] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
R2 Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [65312 2013-10-03] (diamondata)
==================== Drivers (Whitelisted) ====================
R0 Achernar; C:\Windows\System32\Drivers\Achernar.sys [18432 2007-02-05] (NewSoft Technology Corporation)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] ()
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
S3 CRFILTER; C:\Windows\System32\DRIVERS\CRFILTER.sys [6656 2008-04-07] (Generic)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-07-23] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-03-09] ()
U3 arx243nf; C:\Windows\System32\Drivers\arx243nf.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 ASUSProcObsrv; \??\E:\I386\AsProcOb.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-07 18:44 - 2013-10-07 18:44 - 00000000 ____D C:\FRST
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 18:43 - 2013-10-07 18:42 - 00112128 _____ (forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
2013-10-07 18:40 - 2013-10-07 18:40 - 01087213 _____ (Farbar) C:\Users\PLANEO\Desktop\FRST.exe
2013-10-07 17:40 - 2013-10-07 17:43 - 00000000 ____D C:\AdwCleaner
2013-10-07 17:40 - 2013-10-07 17:40 - 01045226 _____ C:\Users\PLANEO\Downloads\adwcleaner.exe
2013-10-07 17:25 - 2013-10-07 17:25 - 00030368 _____ C:\Users\PLANEO\Desktop\JRT.txt
2013-10-07 15:37 - 2013-10-07 15:37 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 15:36 - 2013-10-07 15:36 - 01032220 _____ (Thisisu) C:\Users\PLANEO\Downloads\JRT.exe
2013-10-07 15:36 - 2013-10-07 15:36 - 00000000 ____D C:\ProgramData\SummerSoft
2013-10-07 15:35 - 2013-10-07 15:34 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\Windows\Sun
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\ProgramData\Oracle
2013-10-07 13:26 - 2013-10-07 13:25 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:21 - 2013-10-07 17:19 - 00000000 ____D C:\Program Files\diamondata
2013-10-07 13:20 - 2013-10-07 13:20 - 00001741 _____ C:\Users\Public\Desktop\Express Files.lnk
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-13 14:25 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 14:25 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 14:25 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 14:25 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 14:25 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-13 14:25 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 14:25 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-13 14:25 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-13 14:25 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-13 14:25 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 14:25 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 14:25 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 14:25 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-13 14:25 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 20:03 - 2013-08-08 03:45 - 02049536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 20:03 - 2013-07-16 06:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
==================== One Month Modified Files and Folders =======
2013-10-07 18:44 - 2013-10-07 18:44 - 00000000 ____D C:\FRST
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 18:42 - 2013-10-07 18:43 - 00112128 _____ (forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
2013-10-07 18:41 - 2011-10-23 16:05 - 00000000 ____D C:\Users\PLANEO\Desktop\aajinka
2013-10-07 18:41 - 2010-01-05 12:43 - 00000000 ____D C:\Users\PLANEO\Desktop\Vejška
2013-10-07 18:40 - 2013-10-07 18:40 - 01087213 _____ (Farbar) C:\Users\PLANEO\Desktop\FRST.exe
2013-10-07 18:32 - 2013-02-19 11:08 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-07 18:32 - 2009-05-05 06:57 - 01054885 _____ C:\Windows\WindowsUpdate.log
2013-10-07 18:31 - 2010-09-28 20:42 - 00001356 _____ C:\Users\PLANEO\AppData\Local\d3d9caps.dat
2013-10-07 18:31 - 2009-10-04 21:34 - 00027934 _____ C:\ProgramData\nvModes.001
2013-10-07 17:58 - 2009-11-11 23:15 - 00000000 ____D C:\Users\PLANEO\AppData\Roaming\Skype
2013-10-07 17:50 - 2010-01-28 17:02 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-07 17:46 - 2010-01-28 17:02 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-07 17:46 - 2009-10-05 20:34 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-10-07 17:46 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-07 17:46 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-07 17:46 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-07 17:44 - 2006-11-02 15:01 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-07 17:43 - 2013-10-07 17:40 - 00000000 ____D C:\AdwCleaner
2013-10-07 17:42 - 2009-10-28 14:13 - 00000000 ____D C:\ProgramData\ICQ
2013-10-07 17:40 - 2013-10-07 17:40 - 01045226 _____ C:\Users\PLANEO\Downloads\adwcleaner.exe
2013-10-07 17:25 - 2013-10-07 17:25 - 00030368 _____ C:\Users\PLANEO\Desktop\JRT.txt
2013-10-07 17:19 - 2013-10-07 13:21 - 00000000 ____D C:\Program Files\diamondata
2013-10-07 17:17 - 2009-10-01 22:09 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2013-10-07 17:15 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\tracing
2013-10-07 17:14 - 2013-07-01 22:11 - 00007356 _____ C:\Windows\PFRO.log
2013-10-07 15:37 - 2013-10-07 15:37 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 15:36 - 2013-10-07 15:36 - 01032220 _____ (Thisisu) C:\Users\PLANEO\Downloads\JRT.exe
2013-10-07 15:36 - 2013-10-07 15:36 - 00000000 ____D C:\ProgramData\SummerSoft
2013-10-07 15:36 - 2012-10-04 10:25 - 00000000 ____D C:\ProgramData\InstallMate
2013-10-07 15:34 - 2013-10-07 15:35 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:19 - 2013-07-01 16:50 - 00000000 ____D C:\Program Files\trend micro
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
2013-10-07 15:11 - 2013-07-01 18:59 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\Windows\Sun
2013-10-07 13:27 - 2013-10-07 13:27 - 00000000 ____D C:\ProgramData\Oracle
2013-10-07 13:25 - 2013-10-07 13:26 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-07 13:25 - 2013-10-07 13:25 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-07 13:25 - 2013-06-23 14:44 - 00868264 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-10-07 13:25 - 2013-06-23 14:44 - 00790440 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-10-07 13:20 - 2013-10-07 13:20 - 00001741 _____ C:\Users\Public\Desktop\Express Files.lnk
2013-10-07 13:16 - 2009-11-03 19:30 - 00000000 ____D C:\ProgramData\HP
2013-10-07 11:45 - 2011-10-29 09:54 - 00000000 ____D C:\Program Files\Opera
2013-10-05 20:31 - 2013-07-01 21:49 - 00000550 _____ C:\Users\PLANEO\Desktop\ComboFix – zástupce.lnk
2013-10-05 17:52 - 2012-02-20 02:04 - 00001978 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-03 09:34 - 2013-07-01 18:44 - 00002643 _____ C:\Windows\setupact.log
2013-10-03 09:29 - 2012-04-25 18:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-19 20:07 - 2013-02-19 11:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-19 20:07 - 2012-11-03 13:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-13 14:44 - 2006-11-02 14:47 - 00417144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-13 14:30 - 2009-05-05 07:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-12 23:28 - 2013-07-16 03:02 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 23:25 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
Some content of TEMP:
====================
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-07 17:54
==================== End Of Log ============================
- Přílohy
-
- Addition.rar
- (7.99 KiB) Staženo 66 x
Re: Moc prosím o kontrolu logu
Tvorba fixlistu pro FRST
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [ExpressFiles] - "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.) HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) KCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd) HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.) HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3551576 2013-10-06] (Electronic Arts) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5706480 2013-10-07] (SUPERAntiSpyware) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-20] (Google Inc.) HKU\Asined\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [ 2013-10-07] (SUPERAntiSpyware) Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain ... &bmod=ASUS URLSearchHook: (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll No File SearchScopes: HKLM - DefaultScope value is missing. Toolbar: HKLM - No Name - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - No File FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup CHR RestoreOnStartup: "urls_to_restore_on_startup": [ CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR HKLM\...\Chrome\Extension: [hendmekoldfacfhlojkjcnbjegkahclb] - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION R2 Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [65312 2013-10-03] (diamondata) S3 ASUSProcObsrv; \??\E:\I386\AsProcOb.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] 2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE 2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat 2013-10-07 15:35 - 2013-10-07 15:34 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe 2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe 2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe C:\Program Files\Allin1Convert_8h\bar C:\Program Files\diamondata C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe C:\Users\PLANEO\AppData\Local\temp\update23863472.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\WebReg Deskjet F2100 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: Moc prosím o kontrolu logu
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013
Ran by PLANEO at 2013-10-07 19:09:07 Run:1
Running from C:\Users\PLANEO\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ExpressFiles] - "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
KCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.)
HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3551576 2013-10-06] (Electronic Arts)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5706480 2013-10-07] (SUPERAntiSpyware)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-20] (Google Inc.)
HKU\Asined\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [ 2013-10-07] (SUPERAntiSpyware)
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain ... &bmod=ASUS
URLSearchHook: (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKLM - No Name - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - No File
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR HKLM\...\Chrome\Extension: [hendmekoldfacfhlojkjcnbjegkahclb] - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [65312 2013-10-03] (diamondata)
S3 ASUSProcObsrv; \??\E:\I386\AsProcOb.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 15:35 - 2013-10-07 15:34 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
C:\Program Files\Allin1Convert_8h\bar
C:\Program Files\diamondata
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WebReg Deskjet F2100 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ExpressFiles => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\APSDaemon => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EADM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\Asined\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => Value deleted successfully.
C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} => Value deleted successfully.
HKCR\CLSID\{5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{cd1a63ba-a08c-431b-9a34-f240aadc728d} => Value deleted successfully.
HKCR\CLSID\{cd1a63ba-a08c-431b-9a34-f240aadc728d} => Key not found.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup => Moved successfully.
CHR RestoreOnStartup: "urls_to_restore_on_startup": [ ==> The Chrome "Settings" can be used to fix the entry.
HKLM\SOFTWARE\Google\Chrome\Extensions\hendmekoldfacfhlojkjcnbjegkahclb => Key deleted successfully.
"C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm => Key deleted successfully.
C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx => Moved successfully.
HKCU\SOFTWARE\Policies\Google => Key deleted successfully.
Update diamondata => Service deleted successfully.
ASUSProcObsrv => Service deleted successfully.
catchme => Service deleted successfully.
CFcatchme => Service deleted successfully.
IpInIp => Service deleted successfully.
ipswuio => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
"C:\Users\PLANEO\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\PLANEO\Desktop\LM.bat" => File/Directory not found.
C:\Users\PLANEO\Downloads\setup(1).exe => Moved successfully.
C:\Users\PLANEO\Downloads\RSIT(4).exe => Moved successfully.
C:\Users\PLANEO\Downloads\RSIT(3).exe => Moved successfully.
"C:\Program Files\Allin1Convert_8h\bar" => File/Directory not found.
C:\Program Files\diamondata => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\WebReg Deskjet F2100 series.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
The system needs a manual reboot.
==== End of Fixlog ====
Ran by PLANEO at 2013-10-07 19:09:07 Run:1
Running from C:\Users\PLANEO\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ExpressFiles] - "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
KCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [ICQ] - C:\Program Files\ICQ7.7\ICQ.exe [127040 2012-01-23] (ICQ, LLC.)
HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3551576 2013-10-06] (Electronic Arts)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5706480 2013-10-07] (SUPERAntiSpyware)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-20] (Google Inc.)
HKU\Asined\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [ 2013-10-07] (SUPERAntiSpyware)
Startup: C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain ... &bmod=ASUS
URLSearchHook: (No Name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - C:\Program Files\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKLM - No Name - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - No File
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml
FF SearchPlugin: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup
CHR RestoreOnStartup: "urls_to_restore_on_startup": [
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR HKLM\...\Chrome\Extension: [hendmekoldfacfhlojkjcnbjegkahclb] - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [65312 2013-10-03] (diamondata)
S3 ASUSProcObsrv; \??\E:\I386\AsProcOb.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\PLANEO\AppData\Local\Temp\CFcatchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
2013-10-07 18:43 - 2013-10-07 18:43 - 00029696 _____ C:\Users\PLANEO\AppData\Local\MSGBOX.EXE
2013-10-07 18:43 - 2013-10-07 18:43 - 00015327 _____ C:\Users\PLANEO\Desktop\LM.bat
2013-10-07 15:35 - 2013-10-07 15:34 - 00308928 _____ (SummerSoft) C:\Users\PLANEO\Downloads\setup(1).exe
2013-10-07 15:19 - 2013-10-07 15:19 - 00781909 _____ C:\Users\PLANEO\Downloads\RSIT(4).exe
2013-10-07 15:15 - 2013-10-07 15:15 - 00781383 _____ C:\Users\PLANEO\Downloads\RSIT(3).exe
C:\Program Files\Allin1Convert_8h\bar
C:\Program Files\diamondata
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WebReg Deskjet F2100 series.job => C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ExpressFiles => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\APSDaemon => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EADM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\Asined\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => Value deleted successfully.
C:\Users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} => Value deleted successfully.
HKCR\CLSID\{5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{cd1a63ba-a08c-431b-9a34-f240aadc728d} => Value deleted successfully.
HKCR\CLSID\{cd1a63ba-a08c-431b-9a34-f240aadc728d} => Key not found.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-11.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-12.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-13.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-14.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-15.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-16.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-17.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-18.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-19.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-20.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-21.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\icqplugin-22.xml => Moved successfully.
C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\searchplugins\searchplugins-backup => Moved successfully.
CHR RestoreOnStartup: "urls_to_restore_on_startup": [ ==> The Chrome "Settings" can be used to fix the entry.
HKLM\SOFTWARE\Google\Chrome\Extensions\hendmekoldfacfhlojkjcnbjegkahclb => Key deleted successfully.
"C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm => Key deleted successfully.
C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx => Moved successfully.
HKCU\SOFTWARE\Policies\Google => Key deleted successfully.
Update diamondata => Service deleted successfully.
ASUSProcObsrv => Service deleted successfully.
catchme => Service deleted successfully.
CFcatchme => Service deleted successfully.
IpInIp => Service deleted successfully.
ipswuio => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
"C:\Users\PLANEO\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\PLANEO\Desktop\LM.bat" => File/Directory not found.
C:\Users\PLANEO\Downloads\setup(1).exe => Moved successfully.
C:\Users\PLANEO\Downloads\RSIT(4).exe => Moved successfully.
C:\Users\PLANEO\Downloads\RSIT(3).exe => Moved successfully.
"C:\Program Files\Allin1Convert_8h\bar" => File/Directory not found.
C:\Program Files\diamondata => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\htmlayout.dll => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\Quarantine.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmp7B86.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmp7ED0.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpE189.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpEC90.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\tmpF585.tmp.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\toolbar23943220.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\toolbar23948041.exe => Moved successfully.
C:\Users\PLANEO\AppData\Local\temp\update23863472.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\WebReg Deskjet F2100 series.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
The system needs a manual reboot.
==== End of Fixlog ====
Re: Moc prosím o kontrolu logu
Tak jeste uklidime
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
TFC http://oldtimer.geekstogo.com/TFC.exe
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
A pokud nejsou problemy ci dotazy, je to z me strany vse
Re: Moc prosím o kontrolu logu
Stáhla jsem a provedla všechny uvedené kroky, tak snad je vše ok. Jenom to TFC mi nějak nešlo, dala jsem start a nic to nedělalo, jen se napsalo že se něco vymazalo ... nechala jsem to asi hodinu a nikde už nic nenabíhalo, pak to bylo jakoby seklý a když jsem dala ukončit tak ntbk přestal ragovat, musela jsem vyndat baterku a znovu zapnout, zkusila jsem to ještě jednou ale stalo se to samý, akorát mi to psalo smazáno 0 a když jsem to chtěla zase zrušit tak se to zase seklo, tak jsem to přskočila a přešla na ten poslední čistič tak snad je to ok, v těchto věcech se vůbec nevyznám
Re: Moc prosím o kontrolu logu
TFC obcas takhle zlobi
Pokracovala jste spravne
Je nyni tedy vse v poradku?
Pokracovala jste spravne
Je nyni tedy vse v poradku?
Re: Moc prosím o kontrolu logu
Dobrý den, vše zatím funguje bez problému. Strašně moc Vám děkuji za pomonc ... Chtěla bych se ještě zeptat, zda je možné si nechat zkontrolovat ještě jeden počítač nebo je pomoc omezená (aby se dostalo na všechny apod.). Děkuji
Re: Moc prosím o kontrolu logu
Klidne muzete nechat zkontolovat dalsi PC, zalozte si na nej prosim ale nove tema, aby se nam to tu nepletlo...
Nemate zac, rad jsem pomohl Zase nekdy
A na zaklade Pravidla o zamykani temat
Nemate zac, rad jsem pomohl Zase nekdy
A na zaklade Pravidla o zamykani temat