Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

GeoAds - adware

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

GeoAds - adware

#1 Příspěvek od Vojta7 »

Často se mi při otevření nějakého odkazu napřed ukáže reklama od GeoAds, nezávisle na prohlížeči. Projel jsem PC několika antiviry, našly jiný bordel, ale s tímto nic neudělaly. Spybot mi v IE pokaždé najde nějaké 4 "tracking cookie", ale jak už jsem uvedl, reklamy jsou i v jiných prohlížečích. Přikládám log:

Kód: Vybrat vše

Logfile of random's system information tool 1.09 (written by random/random)
Run by vojta at 2011-08-21 21:11:17
Microsoft Windows 7 Ultimate  Service Pack 1
System drive C: has 31 GB (39%) free of 80 GB
Total RAM: 3063 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:12:02, on 21.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Luxand\Blink!\LuxandBlinkTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Comodo\COMODO Internet Security\cfp.exe
C:\Program Files\USB Safely Remove\USBSafelyRemove.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\vojta\Downloads\winometer.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\ScreenshotCaptor\ScreenshotCaptor.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\ManyCam\Bin\ManyCam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\20Dollars2Surf\20dollars2surf.exe
C:\Program Files\Synaptics\Scrybe\scrybe.exe
C:\Users\vojta\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
D:\Wlipper\Wlipper.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
G:\PortableApps\ThunderbirdPortable\ThunderbirdPortable.exe
G:\PortableApps\ThunderbirdPortable\ThunderbirdPortable.exe
G:\PortableApps\ThunderbirdPortable\App\thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
G:\PortableApps\PortableApps.com\PortableAppsPlatform.exe
G:\PortableApps\GoogleChromePortable\GoogleChromePortable.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
G:\PortableApps\GoogleChromePortable\App\Chrome-bin\chrome.exe
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\vojta\Downloads\RSIT.exe
C:\Program Files\trend micro\vojta.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CGBHO - {2AAE80CE-5D5E-4AD2-B722-E9E0A506CE52} - C:\Users\vojta\AppData\Roaming\CashGopher\cashgopherbho.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPBar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPBar.dll
O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.90.dll (file missing)
O3 - Toolbar: HopSurf toolbar - {E9FAB13D-4600-49E1-90D1-EE961C859D39} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Luxand Blink!] C:\Program Files\Luxand\Blink!\LuxandBlinkTray.exe /s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [USB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WinOMeter] "C:\Users\vojta\Downloads\winometer.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Screenshot Captor] "C:\Program Files\ScreenshotCaptor\ScreenshotCaptor.exe" /autorun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [CashGopher] C:\Users\vojta\AppData\Roaming\CashGopher\CashGopher.exe
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam\Bin\ManyCam.exe" /silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = vojta\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Wlipper.exe.lnk = D:\Wlipper\Wlipper.exe
O4 - Global Startup: 20Dollars2Surf.lnk = C:\Program Files\20Dollars2Surf\20dollars2surf.exe
O4 - Global Startup: Scrybe.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: LastPass - file://C:\Program Files\LastPass\context.html?cmd=lastpass
O8 - Extra context menu item: LastPass vyplňování formulářů - file://C:\Program Files\LastPass\context.html?cmd=fillforms
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPBar.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: HopSurf - {ED98F8D1-09AC-4107-B2FF-91DBE011B0C5} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://93.99.120.34:10000/VatDec.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
O16 - DPF: {79DA2FED-7618-4A84-8E79-35FDC3CA61B5} (CamSpaceActiveX Class) - http://c212729.r29.cf1.rackcdn.com/CamSpaceActiveX186.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD1C908B-B323-473C-A865-F3FDAFA71BBA}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D101527D-84B3-4433-B735-8DEAE744C4B9}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GO36F4~1.DLL C:\Windows\system32\guard32.dll
O22 - SharedTaskScheduler: ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockFree\ODMenu.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\avgwdsvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EASEUS Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP3\RpcAgentSrv.exe
O23 - Service: Scrybe Updater (ScrybeUpdater) - Synaptics, Inc. - C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Program Files\USB Safely Remove\USBSRService.exe

--
End of file - 12304 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default

prefs.js - "browser.search.useDBForOrder" -  true
prefs.js - "browser.startup.homepage" -  "http://giveawayoftheday.com/|http://game.giveawayoftheday.com/|about:home"

"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\Firefox4\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa 3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.10]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
GoogleDesktopMozilla.dll
GoogleDesktopMozillaStub.js
GoogleDesktopMozillaStub.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
avg_igeared.xml
google.xml
googledesktop.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default\extensions\
formhistory@yahoo.com
jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
support@lastpass.com
webrunner@salsitasoft.com
{0b457cAA-602d-484a-8fe7-c1d894a011ba}
{1018e4d6-728f-4b20-ad56-37578a4de76b}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

C:\Users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default\searchplugins\
doplky-pro-firefox.xml
google-.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2AAE80CE-5D5E-4AD2-B722-E9E0A506CE52}]
CashGopher BHO - C:\Users\vojta\AppData\Roaming\CashGopher\cashgopherbho.dll [2011-01-18 36352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\avgssie.dll [2011-08-05 2274144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95D9ECF5-2A4D-4550-BE49-70D42F71296E}]
LastPass Browser Helper Object - C:\Program Files\LastPass\LPBar.dll [2011-06-07 7321800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - LastPass Toolbar - C:\Program Files\LastPass\LPBar.dll [2011-06-07 7321800]
{6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - FireShot - C:\Users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.90.dll []
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2011-08-21 1331392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"Luxand Blink!"=C:\Program Files\Luxand\Blink!\LuxandBlinkTray.exe [2010-02-10 6844728]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-01-07 2049320]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"VoiceFlux"= []
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-04-09 2029456]
"USB Safely Remove"=C:\Program Files\USB Safely Remove\USBSafelyRemove.exe [2011-08-04 1839448]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"WinOMeter"=C:\Users\vojta\Downloads\winometer.exe [2011-05-17 98304]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"Screenshot Captor"=C:\Program Files\ScreenshotCaptor\ScreenshotCaptor.exe [2011-06-07 6510080]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"CashGopher"=C:\Users\vojta\AppData\Roaming\CashGopher\CashGopher.exe [2011-06-08 69632]
"ManyCam"=C:\Program Files\ManyCam\Bin\ManyCam.exe [2011-05-13 1756232]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-07-29 17361032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AquaSnap]
C:\Program Files\AquaSnap\AquaSnap.Daemon.exe [2010-09-21 741376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY]
C:\Program Files\AVG\avgtray.exe [2011-04-18 2334560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EaseUs Tray]
C:\Program Files\EASEUS\Todo Backup\bin\TrayNotify.exe [2011-04-25 733576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EaseUs Watch]
C:\Program Files\EASEUS\Todo Backup\bin\EuWatch.exe [2011-04-22 69000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-20 30192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Users\vojta\AppData\Roaming\Google\Google Talk\googletalk.exe [2007-01-01 3739648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2011-05-13 4283256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetSoftware]
C:\Program Files\NetSoftware\Starter.exe /path=C:\Program Files\NetSoftware []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^20Dollars2Surf.lnk]
C:\PROGRA~1\20DOLL~1\20DOLL~1.EXE [2010-01-28 89088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk]
C:\PROGRA~1\RAINME~1\RAINME~1.EXE [2011-02-06 99840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Game Alarm.lnk]
C:\Games\GAMEAL~1\GAMEAL~1.EXE [2011-08-06 19661312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^KatMouse.lnk]
C:\PROGRA~1\KatMouse\KatMouse.exe [2005-09-24 50176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
C:\PROGRA~1\Stardock\OBJECT~1\OBJECT~1.EXE [2010-10-06 3768176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Verbatim GREEN BUTTON.lnk]
C:\PROGRA~1\VERBAT~1\GREENB~1.EXE [2010-08-23 442640]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
20Dollars2Surf.lnk - C:\Program Files\20Dollars2Surf\20dollars2surf.exe
Scrybe.lnk - C:\Windows\Installer\{5772FC28-D1DD-4D9D-8D7F-97C542162A41}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe

C:\Users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\vojta\AppData\Roaming\Dropbox\bin\Dropbox.exe
HDDlife.lnk - C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
OpenOffice.org 3.3.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Wlipper.exe.lnk - D:\Wlipper\Wlipper.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~2\GO36F4~1.DLL C:\Windows\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockFree\ODMenu.dll [2010-10-04 511344]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"DontSetAutoplayCheckbox"=1
"NoAutorun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"VIDC.IV31"=ir32_32.dll
"VIDC.IV32"=ir32_32.dll
"VIDC.IV41"=ir41_32.ax
"VIDC.IV50"=ir50_32.dll
"VIDC.MP43"=mpg4c32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"msacm.siren"=sirenacm.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-08-21 21:11:17 ----D---- C:\rsit
2011-08-21 21:11:17 ----D---- C:\Program Files\trend micro
2011-08-21 12:26:58 ----HD---- C:\VritualRoot
2011-08-21 12:26:25 ----D---- C:\ProgramData\COMODO
2011-08-21 12:25:29 ----A---- C:\Windows\system32\drivers\sfi.dat
2011-08-21 08:34:47 ----D---- C:\Users\vojta\AppData\Roaming\Comodo
2011-08-21 08:34:47 ----D---- C:\Program Files\Comodo
2011-08-21 08:33:14 ----D---- C:\ProgramData\Comodo Downloader
2011-08-21 08:23:17 ----D---- C:\Program Files\Common Files\PCSuite
2011-08-21 08:23:13 ----D---- C:\Program Files\Common Files\Nokia
2011-08-21 08:19:49 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2011-08-21 08:19:25 ----D---- C:\Program Files\PC Connectivity Solution
2011-08-20 20:53:40 ----D---- C:\Program Files\ESET
2011-08-20 19:48:31 ----A---- C:\Windows\system32\iconv.dll
2011-08-20 19:48:29 ----D---- C:\Program Files\Aimersoft
2011-08-20 17:36:06 ----RASH---- C:\MSDOS.SYS
2011-08-20 17:36:06 ----RASH---- C:\IO.SYS
2011-08-19 21:48:24 ----D---- C:\Program Files\proXPN
2011-08-18 20:54:24 ----D---- C:\Program Files\Speccy
2011-08-18 20:45:51 ----D---- C:\Users\vojta\AppData\Roaming\BinarySense
2011-08-18 20:45:30 ----D---- C:\Program Files\Common Files\BinarySense
2011-08-18 20:45:29 ----D---- C:\Program Files\BinarySense
2011-08-18 20:44:25 ----D---- C:\Users\vojta\AppData\Roaming\TrustPort
2011-08-17 16:25:07 ----A---- C:\Windows\system32\EuEpmGdi.dll
2011-08-17 16:25:07 ----A---- C:\Windows\system32\BootMan.exe
2011-08-17 16:24:51 ----A---- C:\Windows\system32\setupempdrv03.exe
2011-08-17 16:24:51 ----A---- C:\Windows\system32\EuGdiDrv.sys
2011-08-17 16:24:51 ----A---- C:\Windows\system32\epmntdrv.sys
2011-08-17 13:39:53 ----D---- C:\Windows\ehome
2011-08-17 13:30:03 ----A---- C:\Windows\system32\wmpcore.dll
2011-08-17 13:30:03 ----A---- C:\Windows\system32\wmpcd.dll
2011-08-17 13:29:49 ----D---- C:\WMP32Backup
2011-08-15 15:19:06 ----D---- C:\Program Files\fishsim2
2011-08-14 18:11:21 ----D---- C:\ProgramData\Kaspersky Lab
2011-08-14 12:20:09 ----D---- C:\Program Files\FolderSize
2011-08-12 10:01:33 ----D---- C:\Users\vojta\AppData\Roaming\ManyCam
2011-08-12 10:01:01 ----D---- C:\Program Files\ManyCam
2011-08-11 22:31:01 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-11 22:31:00 ----A---- C:\Windows\system32\iertutil.dll
2011-08-11 22:30:59 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-11 22:30:59 ----A---- C:\Windows\system32\jscript9.dll
2011-08-11 22:30:59 ----A---- C:\Windows\system32\jscript.dll
2011-08-11 22:30:59 ----A---- C:\Windows\system32\ieui.dll
2011-08-11 22:30:58 ----A---- C:\Windows\system32\wininet.dll
2011-08-11 22:30:58 ----A---- C:\Windows\system32\urlmon.dll
2011-08-11 22:30:58 ----A---- C:\Windows\system32\url.dll
2011-08-11 22:30:58 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 22:30:56 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 07:39:05 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 07:38:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 07:38:58 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-11 07:38:54 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 07:38:49 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 07:38:44 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 07:38:44 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 07:38:44 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 07:38:44 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 07:38:44 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 07:38:43 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 07:38:09 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 07:38:09 ----A---- C:\Windows\system32\odbcjt32.dll
2011-08-11 07:38:09 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 07:38:09 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 07:38:09 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 07:38:01 ----A---- C:\Windows\system32\fsutil.exe
2011-08-11 07:38:01 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-08-11 07:38:01 ----A---- C:\Windows\system32\drivers\storport.sys
2011-08-11 07:38:01 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-08-11 07:38:01 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-08-11 07:38:01 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-08-11 07:38:00 ----A---- C:\Windows\system32\esent.dll
2011-08-11 07:38:00 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-08-11 07:38:00 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-08-11 07:38:00 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-08-09 19:07:15 ----D---- C:\Program Files\Graph
2011-08-08 20:44:42 ----D---- C:\Users\vojta\AppData\Roaming\ProfiCAD
2011-08-08 20:44:41 ----D---- C:\Program Files\ProfiCAD
2011-08-08 19:45:04 ----D---- C:\Program Files\GameHitZone.com
2011-08-08 19:28:41 ----D---- C:\Program Files\Bus Simulator 2008 Demo
2011-08-08 17:39:47 ----D---- C:\Users\vojta\AppData\Roaming\DraftSight
2011-08-08 17:39:40 ----D---- C:\ProgramData\Dassault Systemes
2011-08-08 17:39:34 ----D---- C:\Program Files\Dassault Systemes
2011-08-08 16:08:18 ----D---- C:\Windows\en
2011-08-08 16:01:57 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-08-08 15:59:49 ----D---- C:\Windows\PCHEALTH
2011-08-08 15:57:22 ----D---- C:\Program Files\Windows Live
2011-08-08 15:54:28 ----D---- C:\Program Files\Microsoft Silverlight
2011-08-08 15:52:19 ----D---- C:\Program Files\Common Files\Windows Live
2011-08-08 14:49:05 ----D---- C:\Program Files\Scorpions WinCheater
2011-08-07 21:31:07 ----D---- C:\ProgramData\ScreenVCR
2011-08-07 21:30:45 ----D---- C:\Program Files\TotalScreenRecorder_Gold
2011-08-07 21:18:26 ----D---- C:\Users\vojta\AppData\Roaming\NCH Software
2011-08-07 20:21:17 ----HDC---- C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
2011-08-07 20:20:36 ----A---- C:\Windows\system32\imageres.dll
2011-08-07 20:18:10 ----D---- C:\ProgramData\Stardock
2011-08-07 20:16:11 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-08-06 20:10:36 ----D---- C:\ProgramData\NCH Software
2011-08-06 20:10:11 ----D---- C:\Program Files\NCH Software
2011-08-06 19:17:29 ----D---- C:\ProgramData\LightScribe
2011-08-06 18:01:18 ----D---- C:\Program Files\MozBackup
2011-08-06 17:58:41 ----D---- C:\Program Files\DiskInternals
2011-08-05 21:33:04 ----D---- C:\Users\vojta\AppData\Roaming\IcoFX
2011-08-05 21:32:59 ----D---- C:\Program Files\IcoFX 1.6
2011-08-02 18:11:12 ----D---- C:\Program Files\Voice Flux Pro
2011-07-29 19:45:55 ----D---- C:\Program Files\LightScribe Template Labeler
2011-07-29 15:50:11 ----D---- C:\Program Files\ICQ Banner Remover
2011-07-29 15:49:39 ----D---- C:\Users\vojta\AppData\Roaming\Opera
2011-07-29 15:49:24 ----D---- C:\Users\vojta\AppData\Roaming\OCS
2011-07-29 15:43:33 ----D---- C:\Users\vojta\AppData\Roaming\ICQ
2011-07-29 15:43:17 ----D---- C:\Program Files\ICQ7.5
2011-07-29 12:04:46 ----D---- C:\Program Files\HDD Regenerator
2011-07-28 22:26:31 ----D---- C:\Users\vojta\AppData\Roaming\hpqLog
2011-07-28 22:25:55 ----D---- C:\Users\vojta\AppData\Roaming\Hewlett-Packard
2011-07-27 21:58:01 ----D---- C:\Users\vojta\AppData\Roaming\Thunderbird
2011-07-26 21:07:30 ----A---- C:\Windows\avisplitter.ini
2011-07-26 21:07:29 ----A---- C:\Windows\system32\yv12vfw.dll
2011-07-26 21:07:29 ----A---- C:\Windows\system32\xvidvfw.dll
2011-07-26 21:07:29 ----A---- C:\Windows\system32\xvidcore.dll
2011-07-26 21:07:29 ----A---- C:\Windows\system32\ff_vfw.dll
2011-07-26 21:07:26 ----D---- C:\Program Files\K-Lite Codec Pack
2011-07-25 20:32:44 ----A---- C:\Windows\system32\LogVss.txt
2011-07-25 20:32:44 ----A---- C:\Windows\system32\LogMsg.txt
2011-07-24 19:34:34 ----D---- C:\Program Files\Tipard Studio
2011-07-22 10:18:21 ----D---- C:\Users\vojta\AppData\Roaming\Solveig Multimedia

======List of files/folders modified in the last 1 month======

2011-08-21 21:11:17 ----RD---- C:\Program Files
2011-08-21 21:01:59 ----D---- C:\Users\vojta\AppData\Roaming\Skype
2011-08-21 21:01:46 ----D---- C:\Users\vojta\AppData\Roaming\Dropbox
2011-08-21 20:50:36 ----SD---- C:\Users\vojta\AppData\Roaming\Microsoft
2011-08-21 20:50:13 ----D---- C:\Windows
2011-08-21 16:31:20 ----D---- C:\Windows\system32\config
2011-08-21 16:23:52 ----D---- C:\Windows\Temp
2011-08-21 16:21:01 ----AD---- C:\ProgramData\TEMP
2011-08-21 12:32:34 ----SHD---- C:\Windows\Installer
2011-08-21 12:32:20 ----D---- C:\Windows\system32\Tasks
2011-08-21 12:32:11 ----RD---- C:\Program Files\Skype
2011-08-21 12:32:10 ----D---- C:\ProgramData\Skype
2011-08-21 12:26:25 ----HD---- C:\ProgramData
2011-08-21 12:25:34 ----D---- C:\Program Files\AVG
2011-08-21 12:25:29 ----D---- C:\Windows\system32\drivers
2011-08-21 12:24:36 ----D---- C:\Windows\system32\catroot
2011-08-21 11:24:36 ----D---- C:\Windows\System32
2011-08-21 09:37:26 ----D---- C:\Program Files\NetSoftware
2011-08-21 09:22:13 ----D---- C:\Windows\inf
2011-08-21 09:21:59 ----D---- C:\Windows\system32\DriverStore
2011-08-21 08:38:50 ----SHD---- C:\System Volume Information
2011-08-21 08:38:12 ----D---- C:\Windows\system32\drivers\AVG
2011-08-21 08:24:33 ----D---- C:\Windows\ModemLogs
2011-08-21 08:23:17 ----D---- C:\Program Files\Common Files
2011-08-21 08:23:13 ----D---- C:\Program Files\Nokia
2011-08-21 08:19:48 ----DC---- C:\Windows\system32\DRVSTORE
2011-08-21 08:18:53 ----D---- C:\Windows\system32\catroot2
2011-08-21 08:11:25 ----D---- C:\ProgramData\Installations
2011-08-19 22:04:09 ----A---- C:\Windows\win.ini
2011-08-17 16:24:36 ----D---- C:\Program Files\EASEUS
2011-08-17 14:06:40 ----D---- C:\Program Files\Mozilla Firefox
2011-08-17 13:49:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-17 13:48:03 ----D---- C:\Windows\Microsoft.NET
2011-08-17 13:47:50 ----RSD---- C:\Windows\assembly
2011-08-17 13:44:21 ----D---- C:\Windows\winsxs
2011-08-17 13:43:11 ----D---- C:\Program Files\Game Cam V2
2011-08-17 13:39:54 ----D---- C:\Program Files\Windows Media Player
2011-08-17 13:39:53 ----D---- C:\Windows\system32\migration
2011-08-17 13:39:53 ----D---- C:\Windows\system32\en-US
2011-08-17 13:39:53 ----D---- C:\Windows\system32\cs-CZ
2011-08-17 13:39:52 ----D---- C:\Windows\system32\wbem
2011-08-17 13:39:50 ----D---- C:\Windows\PolicyDefinitions
2011-08-17 13:30:39 ----D---- C:\Windows\rescache
2011-08-11 22:35:52 ----D---- C:\Program Files\Internet Explorer
2011-08-11 22:27:10 ----D---- C:\Windows\debug
2011-08-11 22:27:09 ----A---- C:\Windows\system32\MRT.exe
2011-08-11 10:00:14 ----D---- C:\Windows\pss
2011-08-10 09:12:04 ----RSD---- C:\Windows\Fonts
2011-08-10 09:12:04 ----D---- C:\Windows\AppPatch
2011-08-08 20:29:04 ----D---- C:\Program Files\USB Safely Remove
2011-08-08 19:24:01 ----D---- C:\Games
2011-08-08 15:59:57 ----SD---- C:\ProgramData\Microsoft
2011-08-08 15:59:51 ----D---- C:\Program Files\Common Files\microsoft shared
2011-08-08 15:55:29 ----D---- C:\Windows\Logs
2011-08-07 21:45:30 ----D---- C:\Program Files\InfraX
2011-08-07 21:42:59 ----D---- C:\Program Files\Free Screen To Video
2011-08-07 21:42:58 ----D---- C:\Users\vojta\AppData\Roaming\FreeScreenToVideo
2011-08-07 21:41:40 ----D---- C:\Program Files\CCleaner
2011-08-07 20:21:19 ----D---- C:\Users\vojta\AppData\Roaming\Stardock
2011-08-07 20:21:15 ----D---- C:\Program Files\Stardock
2011-08-06 18:14:58 ----D---- C:\Users\vojta\AppData\Roaming\vlc
2011-08-04 21:52:10 ----D---- C:\Windows\system32\NDF
2011-07-29 17:08:01 ----D---- C:\Program Files\Tanks Testing Tool
2011-07-29 15:49:44 ----D---- C:\Windows\Prefetch
2011-07-29 15:43:57 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-29 08:52:26 ----D---- C:\Windows\system32\wdi
2011-07-28 22:25:53 ----D---- C:\SWSETUP
2011-07-26 10:19:13 ----D---- C:\ProgramData\NetSoftware
2011-07-24 19:34:34 ----D---- C:\ProgramData\Tipard Studio

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
R0 EUBAKUP;EUBAKUP; C:\Windows\system32\drivers\eubakup.sys [2011-04-22 31112]
R0 EUBKMON;EUBKMON; C:\Windows\system32\drivers\EUBKMON.sys [2011-04-22 37256]
R0 EUFS;EUFS; C:\Windows\system32\drivers\eufs.sys [2011-04-22 21896]
R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2010-12-18 21696]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2011-04-05 297168]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2010-04-09 16744]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-04-09 218560]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-04-09 30112]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 EUDSKACS;EUDSKACS; \??\C:\Windows\system32\drivers\eudskacs.sys [2011-04-22 15240]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-04-09 74408]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 48128]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 296064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-30 16640]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2010-04-14 45736]
R3 CamSpaceBus;CamSpace Virtual Joystick Bus device driver; C:\Windows\system32\drivers\CamSpaceBus.sys [2008-08-24 14848]
R3 CamSpaceJoy;CamSpace Virtual Joystick device driver; C:\Windows\system32\drivers\CamSpaceJoy.sys [2008-08-24 30464]
R3 EUDISK;EASEUS Disk Enumerator; \??\C:\Windows\system32\drivers\eudisk.sys [2011-04-22 188808]
R3 HBtnKey;HP Hotkey Device; C:\Windows\system32\DRIVERS\cpqbttn.sys [2010-02-25 15544]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\Windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\Windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-01-07 1324208]
R3 tap0901;tap0901; C:\Windows\system32\DRIVERS\tap0901.sys [2011-06-07 26112]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 172416]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 78336]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 epmntdrv;epmntdrv; \??\C:\Windows\system32\epmntdrv.sys [2011-07-29 14216]
S3 EuGdiDrv;EuGdiDrv; \??\C:\Windows\system32\EuGdiDrv.sys [2011-07-29 8456]
S3 FreshIO;FreshIO; \??\C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys [2004-10-26 2410]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2010-08-16 16472]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2010-08-16 11104]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP3\WNt500x86\Sandra.sys [2009-08-07 23112]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\Windows\system32\DRIVERS\irstusb.sys [2008-01-19 30208]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 vpcuxd;USB Virtualization Stub Service; C:\Windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 12800]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\avgwdsvc.exe [2011-02-08 269520]
R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-19 148744]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-09 1769216]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 EASEUS Agent;EASEUS Agent; C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe [2011-04-22 56200]
R2 FolderSize;Folder Size; C:\Program Files\FolderSize\FolderSizeSvc.exe [2010-04-06 116224]
R2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2011-02-18 841544]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 ScrybeUpdater;Scrybe Updater; C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2010-12-07 1294848]
R2 USBSafelyRemoveService;USB Safely Remove Assistant; C:\Program Files\USB Safely Remove\USBSRService.exe [2011-08-04 257880]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-16 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-20 30192]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-16 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP3\RpcAgentSrv.exe [2009-08-10 93848]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------
Naposledy upravil(a) Vojta7 dne 22 srp 2011 07:46, celkem upraveno 1 x.
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#2 Příspěvek od Rudy »

Log vypadá OK. Nejprve zkuste smazat cache prohlížeče. Pokud se problém neodstraní, nainstalujte SuperAntispyware: http://www.studna.cz/superantispyware-free-p-6217.html , updatujte, spusťte a pak smažte vše, co najde.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#3 Příspěvek od Vojta7 »

Ještě běží Spybot, až skončí tak sem dám screenshot.
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#4 Příspěvek od Rudy »

OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#5 Příspěvek od Vojta7 »

Obevuje se to i když IE ani nebyl spuštěný...

Obrázek
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#6 Příspěvek od Rudy »

OK, smažte. Jedná se o tento problém: http://translate.google.cz/translate?hl ... rmd%3Divns ?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#7 Příspěvek od Vojta7 »

Tohle mi to vkládá do příspěvku, když chci napsat na fórum Nokie:

Kód: Vybrat vše

<script type="text/javascript">// var geo_Partner = 'eac0a05e-565c-44fb-ad66-05e6159c91d0'; var geo_isCG = true; // </script> <script type="text/javascript" src="http://js.geoads.com/geoLink.js"></script> 
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#8 Příspěvek od Rudy »

Pokud je to ten problém, na nějž jsem dal odkaz, pak se jedná o legitimní věc. Budete muset zjistit, s čím (s jakou aplikací) se nainstaloval.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#9 Příspěvek od Vojta7 »

Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#10 Příspěvek od Rudy »

Vojta7 píše:Je to z http://www.geoads.com/
Pokud to nelze normálně odinstalovat, dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#11 Příspěvek od Vojta7 »

Aaale...GeoAds jsou ty reklamy, nevím, co je "přineslo".
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#12 Příspěvek od Rudy »

Pak si nainstalujte nějaký PopUpBlocker a bude vyřešeno.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#13 Příspěvek od Vojta7 »

A co s tím kódem, který mi to vkládá do příspěvků?
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119514
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: GeoAds - adware

#14 Příspěvek od Rudy »

Z logu RSIT není patrné, kde se to uložilo. Tak chci vědět, kde to je, abych to mohl vyhodit.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Vojta7
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 12 dub 2010 18:47
Bydliště: Františkovy Lázně
Kontaktovat uživatele:

Re: GeoAds - adware

#15 Příspěvek od Vojta7 »

Zde je log:

Kód: Vybrat vše

ComboFix 11-08-23.01 - vojta 23.08.2011   9:20.1.2 - x86
Microsoft Windows 7 Ultimate   6.1.7601.1.1250.420.1033.18.3063.1221 [GMT 2:00]
Spuštěný z: c:\users\vojta\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: COMODO Antivirus *Enabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Ostatní výmazy   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Downloaded Installers
c:\program files\Downloaded Installers\{85734060-4F8B-477D-9FBD-44DEAC824BE2}\setup.msi
c:\users\Public\MOTORM4Xv1.0.821.1_English.exe
c:\users\Public\Setup_English.exe
c:\users\vojta\AppData\Local\Temp\nsk40C.tmp\newadvsplash.dll
c:\users\vojta\AppData\Local\Temp\nsk40C.tmp\registry.dll
c:\users\vojta\AppData\Local\Temp\nsk40C.tmp\System.dll
c:\users\vojta\AppData\Local\Temp\nsp5FF.tmp\FindProcDLL.dll
c:\users\vojta\AppData\Local\Temp\nsp5FF.tmp\newadvsplash.dll
c:\users\vojta\AppData\Local\Temp\nsp5FF.tmp\registry.dll
c:\users\vojta\AppData\Local\Temp\nsp5FF.tmp\System.dll
c:\users\vojta\AppData\Roaming\Microsoft\bass.dll
c:\users\vojta\AppData\Roaming\Microsoft\engine_vx.dll
c:\users\vojta\AppData\Roaming\Microsoft\mjcriu.dll
c:\users\vojta\AppData\Roaming\Microsoft\qwadjb.dll
.
.
(((((((((((((((((((((((((   Soubory vytvořené od 2011-07-23 do 2011-08-23  )))))))))))))))))))))))))))))))
.
.
2011-08-23 07:39 . 2011-08-23 07:39	--------	d-----w-	c:\users\Default\AppData\Local\temp
2011-08-22 07:24 . 2011-08-23 07:52	--------	d-----w-	c:\users\vojta\AppData\Roaming\BatteryBar
2011-08-22 07:23 . 2011-08-22 07:25	--------	d-----w-	c:\program files\BatteryBar
2011-08-21 19:54 . 2011-08-22 07:14	--------	d-----w-	c:\program files\Prime95
2011-08-21 19:22 . 2011-08-21 19:27	--------	d-----w-	c:\program files\Core Temp
2011-08-21 19:11 . 2011-08-21 19:12	--------	d-----w-	C:\rsit
2011-08-21 19:11 . 2011-08-21 19:12	--------	d-----w-	c:\program files\trend micro
2011-08-21 10:26 . 2011-08-21 10:26	--------	d-----w-	C:\VritualRoot
2011-08-21 10:26 . 2011-08-23 07:13	--------	d-----w-	c:\programdata\COMODO
2011-08-21 10:25 . 2011-08-23 07:48	1474832	----a-w-	c:\windows\system32\drivers\sfi.dat
2011-08-21 06:34 . 2011-08-21 06:39	--------	d-----w-	c:\program files\Comodo
2011-08-21 06:34 . 2011-08-21 06:34	--------	d-----w-	c:\users\vojta\AppData\Roaming\Comodo
2011-08-21 06:33 . 2011-08-21 06:34	--------	d-----w-	c:\programdata\Comodo Downloader
2011-08-21 06:23 . 2011-08-21 06:23	--------	d-----w-	c:\program files\Common Files\PCSuite
2011-08-21 06:23 . 2011-08-21 06:23	--------	d-----w-	c:\program files\Common Files\Nokia
2011-08-21 06:19 . 2008-08-26 08:26	18816	----a-w-	c:\windows\system32\drivers\pccsmcfd.sys
2011-08-21 06:19 . 2011-08-21 06:19	--------	d-----w-	c:\program files\PC Connectivity Solution
2011-08-20 18:53 . 2011-08-20 18:53	--------	d-----w-	c:\program files\ESET
2011-08-20 17:48 . 2011-08-18 07:27	892928	----a-w-	c:\windows\system32\iconv.dll
2011-08-20 17:48 . 2011-08-18 07:27	496640	----a-w-	c:\windows\system32\xvid.ax
2011-08-20 17:48 . 2011-08-18 07:27	675840	----a-w-	c:\windows\system32\ac3filter.ax
2011-08-20 17:48 . 2011-08-20 17:48	--------	d-----w-	c:\program files\Aimersoft
2011-08-19 19:48 . 2011-08-19 19:53	--------	d-----w-	c:\program files\proXPN
2011-08-18 18:54 . 2011-08-18 18:54	--------	d-----w-	c:\program files\Speccy
2011-08-18 18:45 . 2011-08-18 18:45	--------	d-----w-	c:\users\vojta\AppData\Roaming\BinarySense
2011-08-18 18:45 . 2011-08-18 18:45	--------	d-----w-	c:\program files\Common Files\BinarySense
2011-08-18 18:45 . 2011-08-18 18:45	--------	d-----w-	c:\program files\BinarySense
2011-08-18 18:44 . 2011-08-21 10:25	--------	d-----w-	c:\users\vojta\AppData\Roaming\TrustPort
2011-08-17 14:25 . 2011-08-02 18:48	2469248	----a-w-	c:\windows\system32\BootMan.exe
2011-08-17 14:25 . 2011-07-29 11:54	19840	----a-w-	c:\windows\system32\EuEpmGdi.dll
2011-08-17 14:24 . 2011-07-29 11:54	86408	----a-w-	c:\windows\system32\setupempdrv03.exe
2011-08-17 14:24 . 2011-07-29 11:54	8456	----a-w-	c:\windows\system32\EuGdiDrv.sys
2011-08-17 14:24 . 2011-07-29 11:54	14216	----a-w-	c:\windows\system32\epmntdrv.sys
2011-08-17 11:39 . 2011-08-17 11:39	--------	d-----w-	c:\windows\ehome
2011-08-17 11:39 . 2011-08-17 11:39	--------	d-----w-	c:\users\Default\AppData\Roaming\Media Center Programs
2011-08-17 11:30 . 2005-01-28 11:44	20480	----a-w-	c:\windows\system32\wmpcore.dll
2011-08-17 11:30 . 2005-01-28 11:44	20480	----a-w-	c:\windows\system32\wmpcd.dll
2011-08-17 11:30 . 2005-01-28 11:44	20480	----a-w-	c:\windows\system32\wmp.ocx
2011-08-17 11:29 . 2011-08-17 11:29	--------	d-----w-	C:\WMP32Backup
2011-08-17 09:49 . 2006-10-18 19:47	96256	----a-w-	c:\program files\Windows Media Player\wmpband.dll
2011-08-15 13:19 . 2011-08-15 13:19	--------	d-----w-	c:\program files\fishsim2
2011-08-14 16:11 . 2011-08-14 16:11	--------	d-----w-	c:\programdata\Kaspersky Lab
2011-08-14 10:20 . 2011-08-14 10:20	--------	d-----w-	c:\program files\FolderSize
2011-08-12 08:01 . 2011-08-12 08:16	--------	d-----w-	c:\users\vojta\AppData\Local\ManyCam
2011-08-12 08:01 . 2011-08-12 08:12	--------	d-----w-	c:\users\vojta\AppData\Roaming\ManyCam
2011-08-12 08:01 . 2011-08-12 08:02	--------	d-----w-	c:\program files\ManyCam
2011-08-11 20:31 . 2011-07-22 02:44	2382848	----a-w-	c:\windows\system32\mshtml.tlb
2011-08-11 20:31 . 2011-07-22 03:00	141104	----a-w-	c:\program files\Internet Explorer\sqmapi.dll
2011-08-11 20:31 . 2011-07-22 02:46	194048	----a-w-	c:\program files\Internet Explorer\IEShims.dll
2011-08-11 20:30 . 2011-07-22 02:54	1797632	----a-w-	c:\windows\system32\jscript9.dll
2011-08-11 20:30 . 2011-07-22 02:48	1126912	----a-w-	c:\windows\system32\wininet.dll
2011-08-09 17:07 . 2011-08-09 17:21	--------	d-----w-	c:\program files\Graph
2011-08-08 18:44 . 2011-08-08 18:50	--------	d-----w-	c:\users\vojta\AppData\Roaming\ProfiCAD
2011-08-08 18:44 . 2011-08-08 18:44	--------	d-----w-	c:\program files\ProfiCAD
2011-08-08 17:45 . 2011-08-08 17:45	--------	d-----w-	c:\program files\GameHitZone.com
2011-08-08 17:28 . 2011-08-08 17:32	--------	d-----w-	c:\program files\Bus Simulator 2008 Demo
2011-08-08 15:39 . 2011-08-08 15:40	--------	d-----w-	c:\users\vojta\AppData\Roaming\DraftSight
2011-08-08 15:39 . 2011-08-08 15:39	--------	d-----w-	c:\programdata\Dassault Systemes
2011-08-08 15:39 . 2011-08-08 15:39	--------	d-----w-	c:\program files\Dassault Systemes
2011-08-08 14:20 . 2011-08-21 19:41	--------	d-----w-	c:\users\vojta\Tracing
2011-08-08 14:08 . 2011-08-08 14:08	--------	d-----w-	c:\windows\en
2011-08-08 14:01 . 2011-08-08 14:01	--------	d-----w-	c:\program files\Microsoft SQL Server Compact Edition
2011-08-08 13:59 . 2011-08-08 13:59	--------	d-----w-	c:\windows\PCHEALTH
2011-08-08 13:57 . 2011-08-08 14:08	--------	d-----w-	c:\program files\Windows Live
2011-08-08 13:54 . 2011-08-09 08:34	--------	d-----w-	c:\program files\Microsoft Silverlight
2011-08-08 13:52 . 2011-08-14 14:01	--------	d-----w-	c:\users\vojta\AppData\Local\Windows Live
2011-08-08 13:52 . 2011-08-08 13:52	--------	d-----w-	c:\program files\Common Files\Windows Live
2011-08-08 12:49 . 2011-08-08 13:01	--------	d-----w-	c:\program files\Scorpions WinCheater
2011-08-07 19:31 . 2011-08-07 19:32	--------	d-----w-	c:\programdata\ScreenVCR
2011-08-07 19:30 . 2011-08-07 19:42	--------	d-----w-	c:\program files\TotalScreenRecorder_Gold
2011-08-07 19:18 . 2011-08-07 19:44	--------	d-----w-	c:\users\vojta\AppData\Roaming\NCH Software
2011-08-07 18:21 . 2011-08-07 18:21	--------	dc-h--w-	c:\programdata\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
2011-08-07 18:20 . 2011-08-07 18:20	34616832	----a-w-	c:\windows\system32\imageres.dll
2011-08-07 18:18 . 2011-08-07 18:18	--------	d-----w-	c:\programdata\Stardock
2011-08-07 18:16 . 2011-08-07 18:16	--------	d-----w-	c:\program files\Common Files\Wise Installation Wizard
2011-08-06 18:10 . 2011-08-07 19:18	--------	d-----w-	c:\programdata\NCH Software
2011-08-06 18:10 . 2011-08-07 19:45	--------	d-----w-	c:\program files\NCH Software
2011-08-06 17:17 . 2011-08-06 17:17	--------	d-----w-	c:\programdata\LightScribe
2011-08-06 16:01 . 2011-08-06 16:01	--------	d-----w-	c:\program files\MozBackup
2011-08-06 15:58 . 2011-08-06 15:58	--------	d-----w-	c:\program files\DiskInternals
2011-08-05 19:33 . 2011-08-05 19:35	--------	d-----w-	c:\users\vojta\AppData\Roaming\IcoFX
2011-08-05 19:32 . 2011-08-05 19:33	--------	d-----w-	c:\program files\IcoFX 1.6
2011-08-05 19:23 . 2011-08-05 19:28	--------	d-----w-	c:\users\vojta\hry
2011-08-02 16:11 . 2011-08-02 16:11	--------	d-----w-	c:\program files\Voice Flux Pro
2011-07-29 17:45 . 2011-07-29 17:45	--------	d-----w-	c:\program files\LightScribe Template Labeler
2011-07-29 13:50 . 2011-07-29 13:50	--------	d-----w-	c:\program files\ICQ Banner Remover
2011-07-29 13:49 . 2011-07-29 13:49	--------	d-----w-	c:\users\vojta\AppData\Roaming\OCS
2011-07-29 13:43 . 2011-08-01 17:15	--------	d-----w-	c:\users\vojta\AppData\Roaming\ICQ
2011-07-29 13:43 . 2011-07-29 13:44	--------	d-----w-	c:\program files\ICQ7.5
2011-07-29 10:04 . 2011-07-29 10:40	--------	d-----w-	c:\program files\HDD Regenerator
2011-07-28 20:26 . 2011-07-28 20:26	--------	d-----w-	c:\users\vojta\AppData\Roaming\hpqLog
2011-07-28 20:25 . 2011-07-28 20:26	--------	d-----w-	c:\users\vojta\AppData\Roaming\Hewlett-Packard
2011-07-27 19:58 . 2011-08-23 07:39	--------	d-----w-	c:\users\vojta\AppData\Roaming\Thunderbird
2011-07-26 19:07 . 2011-07-22 08:00	74752	----a-w-	c:\windows\system32\ff_vfw.dll
2011-07-26 19:07 . 2011-07-16 14:17	151552	----a-w-	c:\windows\system32\ac3acm.acm
2011-07-26 19:07 . 2011-06-24 14:44	243200	----a-w-	c:\windows\system32\xvidvfw.dll
2011-07-26 19:07 . 2011-06-24 14:28	650752	----a-w-	c:\windows\system32\xvidcore.dll
2011-07-26 19:07 . 2010-11-03 18:08	237568	----a-w-	c:\windows\system32\yv12vfw.dll
2011-07-26 19:07 . 2006-10-18 18:05	232448	----a-w-	c:\windows\system32\mp3fhg.acm
2011-07-26 19:07 . 2011-07-26 19:09	--------	d-----w-	c:\program files\K-Lite Codec Pack
2011-07-24 17:34 . 2011-07-24 17:34	--------	d-----w-	c:\program files\Tipard Studio
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M výpis   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-22 09:37 . 2010-04-08 23:25	82400	----a-w-	c:\windows\system32\drivers\inspect.sys
2011-08-22 09:37 . 2010-04-08 23:25	37592	----a-w-	c:\windows\system32\drivers\cmdhlp.sys
2011-08-22 09:37 . 2010-04-08 23:25	19088	----a-w-	c:\windows\system32\drivers\cmderd.sys
2011-08-22 09:37 . 2010-04-08 23:25	238960	----a-w-	c:\windows\system32\drivers\cmdGuard.sys
2011-08-08 13:57 . 2011-03-28 16:36	18328	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-29 15:54 . 2011-05-18 11:38	403616	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-16 18:30 . 2011-07-16 18:30	73216	----a-w-	c:\windows\ST6UNST.EXE
2011-07-16 18:30 . 2011-07-16 18:30	249856	------w-	c:\windows\Setup1.exe
2011-07-08 18:37 . 2011-06-07 12:06	811520	----a-w-	c:\windows\system32\user32.dll.old
2011-06-26 08:49 . 2011-06-29 08:22	73728	----a-w-	c:\windows\system32\TOverlay.ax
2011-06-23 17:16 . 2011-05-16 17:45	413696	----a-w-	c:\windows\system32\wrap_oal.dll
2011-06-23 17:16 . 2011-05-16 17:45	110592	----a-w-	c:\windows\system32\OpenAL32.dll
2011-06-11 02:29 . 2011-07-13 09:44	2334208	----a-w-	c:\windows\system32\win32k.sys
2011-06-08 16:28 . 2009-07-14 02:05	152576	----a-w-	c:\windows\system32\msclmd.dll
2011-06-07 12:44 . 2011-06-07 12:44	26112	----a-w-	c:\windows\system32\drivers\tap0901.sys
2011-08-17 12:06 . 2011-05-26 15:09	134104	----a-w-	c:\program files\mozilla firefox\components\browsercomps.dll
2011-07-20 16:19 . 2011-07-20 16:19	119808	----a-w-	c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((   Spouštěcí body v registru   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AAE80CE-5D5E-4AD2-B722-E9E0A506CE52}]
2011-01-18 19:26	36352	----a-w-	c:\users\vojta\AppData\Roaming\CashGopher\CashGopherBHO.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\vojta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\vojta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\vojta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"WinOMeter"="c:\users\vojta\Downloads\winometer.exe" [2011-05-17 98304]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"Screenshot Captor"="c:\program files\ScreenshotCaptor\ScreenshotCaptor.exe" [2011-06-07 6510080]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"CashGopher"="c:\users\vojta\AppData\Roaming\CashGopher\CashGopher.exe" [2011-06-08 69632]
"ManyCam"="c:\program files\ManyCam\Bin\ManyCam.exe" [2011-05-13 1756232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-07-29 17361032]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 90624]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"Luxand Blink!"="c:\program files\Luxand\Blink!\LuxandBlinkTray.exe" [2010-02-09 6844728]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-01-07 2049320]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-08-22 2554696]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2011-08-04 1839448]
.
c:\users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
BatteryBar.lnk - c:\program files\BatteryBar\BatteryBar.exe [N/A]
Dropbox.lnk - c:\users\vojta\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
HDDlife.lnk - c:\program files\BinarySense\HDDlife 3\HDDlifePro.exe [2011-2-18 2955080]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
Wlipper.exe.lnk - d:\wlipper\Wlipper.exe [2011-7-7 79360]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
20Dollars2Surf.lnk - c:\program files\20Dollars2Surf\20dollars2surf.exe [2011-7-6 89088]
Scrybe.lnk - c:\windows\Installer\{5772FC28-D1DD-4D9D-8D7F-97C542162A41}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe [2011-6-30 45056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"DontSetAutoplayCheckbox"= 1 (0x1)
"NoAutorun"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockFree\ODMenu.dll" [2010-10-04 511344]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^20Dollars2Surf.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\20Dollars2Surf.lnk
backup=c:\windows\pss\20Dollars2Surf.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
backup=c:\windows\pss\Rainmeter.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Game Alarm.lnk]
path=c:\users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Game Alarm.lnk
backup=c:\windows\pss\Game Alarm.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^KatMouse.lnk]
path=c:\users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KatMouse.lnk
backup=c:\windows\pss\KatMouse.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^vojta^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Verbatim GREEN BUTTON.lnk]
path=c:\users\vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verbatim GREEN BUTTON.lnk
backup=c:\windows\pss\Verbatim GREEN BUTTON.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AquaSnap]
2010-09-21 19:18	741376	----a-w-	c:\program files\AquaSnap\AquaSnap.Daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY]
2011-04-18 15:40	2334560	----a-w-	c:\program files\AVG\avgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EaseUs Tray]
2011-04-25 18:27	733576	----a-w-	c:\program files\EASEUS\Todo Backup\bin\TrayNotify.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EaseUs Watch]
2011-04-22 16:26	69000	----a-w-	c:\program files\EASEUS\Todo Backup\bin\EuWatch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2011-07-20 16:19	30192	----a-w-	c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22	3739648	----a-w-	c:\users\vojta\AppData\Roaming\Google\Google Talk\googletalk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2011-05-13 14:03	4283256	----a-w-	c:\program files\Windows Live\Messenger\msnmsgr.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 136176]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-07-29 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-07-29 8456]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2011-07-20 30192]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 136176]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-08-16 16472]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-08-16 11104]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011.SP3\RpcAgentSrv.exe [2009-08-10 93848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 12800]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
S0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2011-04-22 31112]
S0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2011-04-22 37256]
S0 EUFS;EUFS;c:\windows\system32\drivers\eufs.sys [2011-04-22 21896]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-04-04 297168]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2011-08-22 19088]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-08-22 238960]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-08-22 37592]
S1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2011-04-22 15240]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 avgwd;AVG WatchDog;c:\program files\AVG\avgwdsvc.exe [2011-02-08 269520]
S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-19 148744]
S2 EASEUS Agent;EASEUS Agent;c:\program files\EASEUS\Todo Backup\bin\Agent.exe [2011-04-22 56200]
S2 ScrybeUpdater;Scrybe Updater;c:\program files\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2010-12-07 1294848]
S2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [2011-08-04 257880]
S3 ALSysIO;ALSysIO;c:\users\vojta\AppData\Local\Temp\ALSysIO.sys [x]
S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-30 16640]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-13 45736]
S3 CamSpaceBus;CamSpace Virtual Joystick Bus device driver;c:\windows\system32\drivers\CamSpaceBus.sys [2008-08-24 14848]
S3 CamSpaceJoy;CamSpace Virtual Joystick device driver;c:\windows\system32\drivers\CamSpaceJoy.sys [2008-08-24 30464]
S3 EUDISK;EASEUS Disk Enumerator;c:\windows\system32\drivers\eudisk.sys [2011-04-22 188808]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11	451872	----a-w-	c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 15:25]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 15:25]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.cz/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: LastPass - file://c:\program files\LastPass\context.html?cmd=lastpass
IE: LastPass vyplňování formulářů - file://c:\program files\LastPass\context.html?cmd=fillforms
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1 62.240.184.2
TCP: Interfaces\{CD1C908B-B323-473C-A865-F3FDAFA71BBA}: NameServer = 156.154.70.22,156.154.71.22
TCP: Interfaces\{D101527D-84B3-4433-B735-8DEAE744C4B9}: NameServer = 156.154.70.22,156.154.71.22
DPF: {79DA2FED-7618-4A84-8E79-35FDC3CA61B5} - hxxp://c212729.r29.cf1.rackcdn.com/CamSpaceActiveX186.cab
FF - ProfilePath - c:\users\vojta\AppData\Roaming\Mozilla\Firefox\Profiles\c8ysbvo7.default\
FF - prefs.js: browser.search.selectedEngine - Google 
FF - prefs.js: browser.startup.homepage - hxxp://giveawayoftheday.com/|http://game.giveawayoftheday.com/|about:home
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-VoiceFlux - (no file)
MSConfigStartUp-NetSoftware - c:\program files\NetSoftware\Starter.exe
AddRemove-NetSoftware - c:\program files\NetSoftware\rmNetSoftware.exe
AddRemove-Windows Media Player 11 - For Windows 7 11.0.6001.7000 - c:\program files\Windows Media Player\Uninstall.exe
AddRemove-Mozilla Thunderbird (5.0) - g:\portableapps\Mozilla Thunderbird\App\Thunderbird\uninstall\helper.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-644544476-1531262308-3294688208-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A71CC903-F21C-7508-FCCE-0BF019D57BC6}*]
"nahdecjooncnimfdigbfpamhblen"=hex:6a,61,63,6a,69,68,61,65,65,6f,62,66,70,68,
   67,6c,61,64,61,63,00,00
"mandpiibbfapidiiafgdhppbbp"=hex:6a,61,63,6a,69,68,61,65,65,6f,62,66,70,68,67,
   6c,61,64,61,63,00,00
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(536)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'Explorer.exe'(3568)
c:\windows\system32\guard32.dll
c:\users\vojta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll
c:\program files\Stardock\ObjectDockFree\ODMenu.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\AVG\avgnsx.exe
c:\windows\system32\taskhost.exe
c:\program files\Core Temp\Core Temp.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\windows\system32\DllHost.exe
c:\program files\Synaptics\Scrybe\scrybe.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Celkový čas: 2011-08-23  09:58:16 - počítač byl restartován
ComboFix-quarantined-files.txt  2011-08-23 07:58
.
Před spuštěním: 34 256 379 904 bytes free
Po spuštění: 34 238 345 216 bytes free
.
- - End Of File - - D58AD8D4DD423B40ED4FA6DAC13C7346
Nesnáším Facebook = nemám problém, kterého je plné fórum :-)

Odpovědět